In a market this young, trust
HASN'T BEEN EARNED
by anyone yet — only by whoever is willing to check.
You can’t tell a good AI vendor from a bad one by asking them, and right now, neither can the law.
In a market this young, trust
HASN'T BEEN EARNED
by anyone yet — only by whoever is willing to check.
Type “AI implementation for small business” into any search engine and count the results before you lose interest. New agencies. New consultancies. New freelancers who ran a chatbot workshop last spring and now sell “AI transformation.” Most of them are earnest. Some of them know exactly what they’re doing. From the outside, looking at a landing page and a sales call, you cannot tell which is which.
That’s not a competence problem on your side. It’s a verification problem, and it has a name. Economists call it a lemons market: a buyer who can’t check quality before buying, a seller who has every reason to claim quality whether or not it’s true, and a market that fills up with sellers the buyer can’t sort. Ask a vendor whether their AI implementation separates instructions from data, whether it gates any real action behind a human check, and you’ll get an answer. What you won’t get is a way to know if the answer is true. A confident right answer and a confident wrong one sound exactly alike from where you’re sitting.
This is a version of a pattern I’ve argued before, on a smaller stage: agencies install what a client asks for, or what’s fashionable, rather than what’s actually needed, because a client asking for Google Analytics doesn’t know what they’re trading away. Swap Google Analytics for an AI agent with access to your inbox and your customer data, and the same failure gets a lot more expensive. Nobody in that transaction is lying. The agency believes it’s helping. The client believes it’s being served. Neither one has the expertise to catch what’s missing.
Arming yourself before the sales call with hard questions is the right instinct. Asking a vendor to classify their own system’s risk, name where your data actually goes, or produce technical documentation tells you something real, and watching how those questions get answered, not just whether, is a genuine signal. But reading that signal still assumes you can tell a well-rehearsed evasion from an honest gap. Most buyers walking into that room can’t, not because they’re careless, but because nobody has taught them what a real answer sounds like. The questions get you most of the way there. The last stretch needs exactly the expertise the questions were meant to stand in for.
The next reasonable assumption is that regulation has already closed this gap. The EU AI Act, after all, has a clause called AI literacy. Article 4 has required providers and deployers to build a sufficient level of AI understanding among their staff since February 2025, regardless of whether the system in question counts as high-risk. Someone in Brussels correctly diagnosed the exact problem this piece is about: organizations operating AI systems they don’t understand is itself a systemic risk.
Then, three weeks ago, on 27 July 2026, the EU’s Digital Omnibus on AI rewrote that clause. The original text required providers and deployers to “ensure, to their best extent, a sufficient level of AI literacy.” The new text requires them only to “take measures to support the development of” it, with an added line clarifying that nobody has to guarantee any individual actually reaches that level. An obligation of result became an obligation of effort.
The article that would have had real teeth, Article 15, covering robustness against exactly the kind of manipulation a prompt injection attack depends on, was never built for this problem anyway. It only binds systems classified as high-risk under Annex III: biometric identification, critical infrastructure, employment, credit, categories an AI email assistant or a customer-facing chatbot doesn’t fall into. And the same Digital Omnibus pushed even that narrow deadline back, from August 2026 to December 2027 for stand-alone systems. So there is no floor here. Not the vendor’s word. Not a reputation the market hasn’t had time to build. And, as of three weeks ago, not the regulator either.
What actually closes a gap like this isn’t a smarter buyer. It’s a third party with nothing to gain from the sale. Financial audits exist because a shareholder can’t verify a balance sheet by asking the company that wrote it. Building inspectors exist because a buyer can’t verify a foundation by asking the seller. Code review exists before an acquisition because nobody trusts the target company to grade its own homework. AI implementation is missing that role right now, not because nobody could fill it, but because the market is too new and moving too fast for anyone to have insisted on it yet.
Trust in a market this young hasn’t been earned by anyone yet, whatever the landing pages say. It gets earned by whoever is willing to check, not by whoever is willing to sell.
A 30-minute discovery call is where we surface what it is. Come with your best strategic position. I'll challenge it.