Your AI vendor
CAN'T PROVE
the system they resold you complies with Article 11.
The EU AI Act's high-risk deadline just moved from August 2026 to December 2027 — the exact moment most AI vendors get comfortable. Five questions to ask before you sign, drawn from watching this same pattern play out with MiFID II.
Your AI vendor
CAN'T PROVE
the system they resold you complies with Article 11.
I've been doing this long enough to remember when the full MiFID II documentation still fit in a briefcase. I watched it get pushed back — the associations complaining loudly that there wasn't enough time, and the regulation slipping just enough to let everyone catch their breath. I got ahead of it anyway, finished early, and ended up as the "super expert" pulled in to rescue the laggards on a second project. Not because I was smarter. Because everyone else was betting the deadline would move again, and it did — until, eventually, it didn't.
The EU AI Act's high-risk deadline just did the same thing: pushed from August 2026 to December 2027. If you're breathing a sigh of relief right now, you're playing the same hand every MiFID II laggard played. Some of them won. Most of them spent the extra time waiting instead of building — and when the deadline finally landed for real, they scrambled exactly as hard as if it had never moved at all.
Here's what almost nobody in that position understood then, and almost nobody selling you AI understands now: regulation isn't just a compliance cost to survive. It's a chance to adapt what you're actually selling — your products, your business model — while your competitors are still complaining about the timeline. Nobody wants to hear that. Regulation always arrives at the wrong time. But "wrong time" and "no advantage available" are not the same sentence.
It's exactly the same pattern with AI vendors today. Look at the job postings — a striking share of them are sales roles, not implementation or compliance roles. The people companies hire to bring AI in the door aren't the ones who understand how it works or what the legal exposure looks like. They're the ones who can trigger the "wow" moment. We used to have a phrase for this: it works great on PowerPoint — what does it look like in the real world?
It's the same dynamic that made ChatGPT feel miraculous a few years ago: a paragraph of text that actually sounded good was new enough that nobody in the corporate world thought it was possible. Today, everyone knows they can't avoid AI and wants to be part of it — and has no idea how. That's the exact gap a demo is built to fill. "Here's Claude Code, here's Copilot — look what it does with your data." Nobody asks what the actual goal was supposed to be.
The questions that matter are unglamorous, which is exactly why they don't come up in a sales meeting. If your data can't leave the company, how does this actually work? How do you keep specific data out of the model entirely? If data is processed internally, how is it prepared — what vector format, what chunk size, which local model is actually right for your case? These aren't decisions that get made the way most business deals get made — in a room where, as a rule, nobody outside it understands how the deal actually came together. They need real answers, not a demo.
Ask these five questions before you sign. Watch closely how they're answered — not whether.
Increasingly, the person answering isn't even the one who built the model. A lot of what gets pitched to you as "our AI solution" is a resold LLM with a UI wrapped around it — "here's Claude Code, here's Copilot, it's great." If your vendor is reselling someone else's model, ask them how they can classify a system's risk when they didn't build it and can't fully explain what's inside it.
I once asked a startup pitching exactly this promise — personal data redacted before anything leaves the building — what they did about trade secrets, IP, business-critical information. Their answer: "we will cover that too." When I asked how they'd even recognize that kind of data as sensitive, the answer was: they'll find a way. That's not a data policy. That's a plan to have a plan.
This happens more than anyone admits. Sometimes it doesn't matter. Sometimes someone notices and isn't heard, or is afraid to say so. Often it's caught too late — because AI produces output faster than any human can verify it, and no organization wants to check everything; that would defeat the point of using AI at all. Most companies are so focused on getting the AI to work that they never build the process to catch it when it doesn't.
Ask this, and watch who gets uncomfortable. The frontier providers — Anthropic, OpenAI, the names everyone's reselling — treat exactly this documentation as protected IP and won't disclose it. Open-source models like Qwen document how to install and run them, not how they actually work. Nobody publishes real documentation of how the model produces what it produces, because that would mean handing over a highly complex mathematical model, not a product manual. And even if they did, the EU Commission itself would need specialized engineers and mathematicians to verify it — which is exactly why "we comply with Article 11" is a much easier sentence to say than to prove.
Go back to the startup from question two. If "no data leaves the building" turns out to be wrong, the damage is severe — and nearly impossible to trace. In finance, we rank risk by how measurable it is: market risk is easiest, because the data is abundant. Operational risk is the hardest, because nobody wants the very data you'd need to calculate it exposed. AI risk is worse than that. Once information is vectorized, you often can't tell where it went or when — you only find out it was there when it surfaces somewhere it should never have been.
If you asked your vendor these five questions today, some of the answers would surprise you — not because your vendor is dishonest, but because almost nobody in this market has been forced to answer them yet. That's not a reason to panic. It's a reason to ask before you sign, not after.
This isn't really about AI vendors. It's about what happens every time an organization adopts something faster than it can understand it — which is most of what's happening in AI right now, and won't stop with your vendor selection. The next wall you hit on this road won't look like this one. It'll look like a different assumption nobody thought to question, at a moment when questioning it costs less than not.
That's the work I do. Not audits on demand — asking the question that's supposed to have been asked already, before it becomes the reason something expensive went wrong.
A 30-minute discovery call is where we surface what it is. Come with your best strategic position. I'll challenge it.