EU AI Act Compliance: Why Vendor Claims Aren’t Enough

The News

The EU AI Act officially entered enforcement on August 2, and enterprise organizations are discovering a compliance gap they didn’t anticipate. According to Druid AI CEO Joe Kim, vendor claims of being “AI Act–ready” do not automatically satisfy the disclosure and transparency obligations that fall on the companies actually deploying AI in customer-facing experiences. The core issue is a regulatory distinction between “providers” (those who build AI systems) and “deployers” (those who use AI in their own products and services), with many enterprises functioning as both simultaneously. Commonly overlooked exposure points include auto-drafted content, embedded generative features, and emotion or tone recognition capabilities that are not marketed as AI products but still trigger disclosure duties under the Act.

Analyst Take

The compliance gap hiding in plain sight

The EU AI Act creates a layered accountability structure that most enterprise procurement processes are not built to navigate. When a vendor certifies that its platform “supports AI Act compliance,” that statement is almost always scoped to the provider’s own obligations: model cards, conformity assessments, and technical documentation. The deployer’s obligations, specifically informing end users that they are interacting with an AI system and maintaining records of those disclosures, belong entirely to the enterprise running the customer experience. A vendor certification cannot transfer those obligations away. This is not a loophole or an ambiguity in the regulation; it is the explicit architecture of the Act.

The practical exposure is broader than most legal and compliance teams realize. Enterprises have spent years embedding AI capabilities into customer service workflows, content generation tools, HR screening platforms, and sentiment analysis dashboards, often by enabling features within existing SaaS subscriptions rather than procuring dedicated AI products. Those embedded capabilities rarely came with a compliance brief. Under the EU AI Act, “I didn’t know it was an AI feature” is not a defensible position once enforcement has begun.

The audit problem for enterprise IT

For ITDMs, the immediate priority is conducting a full inventory of AI touchpoints across the organization, including features that are bundled into CRM platforms, customer support suites, and productivity tools. The question to ask of every vendor is specific: “What disclosures does your platform make to end users when AI is generating or substantially influencing content, and where is the audit trail?” If a vendor cannot answer that with documentation, the enterprise is exposed.

Developers face a parallel problem. Many generative AI integrations were built quickly during the 2023–2024 wave of internal AI tooling, often without explicit disclosure mechanisms in the user interface. Retrofitting compliant disclosure flows into production applications is non-trivial, particularly in multi-tenant or white-labeled environments where the AI layer is abstracted several steps from the user. The audit log requirement compounds this: enterprises need to demonstrate, to a regulator’s satisfaction, that disclosures were actually delivered to specific users at specific times.

Why this will repeat

Enforcement actions under the EU AI Act will not arrive all at once. They will arrive in waves, and the first wave will almost certainly target the most visible consumer-facing deployments. But the second wave will go after enterprises that assumed their vendor’s compliance posture was sufficient. ECI Research’s 2026 Kubernetes Operations Benchmark Study found that 41.8% of respondents cited “complexity of orchestrating data pipelines with container infrastructure” as the primary obstacle to scaling AI infrastructure, which signals how rapidly organizations have been building AI workloads into production environments without necessarily building the governance scaffolding alongside them. Separately, ECI Research’s Nutanix Kubernetes Operations Benchmark Study found that 47.1% of respondents manage AI training data governance in a “semi-manual” way, handled independently by each project. That kind of fragmented data governance is precisely the environment in which disclosure obligations fall through the cracks.

The competitive dynamic here favors vendors who build deployer-side compliance tooling, not just provider-side certifications. Enterprises will increasingly ask for audit trails, disclosure templates, and consent management capabilities as procurement requirements, not nice-to-haves.

Looking Ahead

The EU AI Act’s enforcement posture will harden over the next 12–18 months as national supervisory authorities in Germany, France, and the Netherlands (the most active early enforcers) develop case precedent. Enterprises that act now to map their AI deployments, segment provider versus deployer obligations, and retrofit disclosure mechanisms will be positioned to demonstrate good-faith compliance even if their initial implementations were imperfect. Those that wait for a formal inquiry to prompt the audit will find themselves in a much weaker position, both legally and reputationally.

The vendor market will respond. Expect a new category of AI governance and compliance tooling to emerge over 2025–2026 that sits between the AI platform layer and the enterprise application layer, automating disclosure delivery and generating tamper-evident audit logs. Established players in GRC (governance, risk, and compliance) software will make acquisitions in this space, and cloud hyperscalers will bundle lightweight versions into their AI services. The enterprises that define their compliance requirements clearly and early will have the most leverage in that purchasing cycle.

Authors

  • Paul Nashawaty

    Paul Nashawaty, Practice Leader and Lead Principal Analyst, specializes in application modernization across build, release and operations. With a wealth of expertise in digital transformation initiatives spanning front-end and back-end systems, he also possesses comprehensive knowledge of the underlying infrastructure ecosystem crucial for supporting modernization endeavors. With over 25 years of experience, Paul has a proven track record in implementing effective go-to-market strategies, including the identification of new market channels, the growth and cultivation of partner ecosystems, and the successful execution of strategic plans resulting in positive business outcomes for his clients.

    View all posts
  • With over 15 years of hands-on experience in operations roles across legal, financial, and technology sectors, Sam Weston brings deep expertise in the systems that power modern enterprises such as ERP, CRM, HCM, CX, and beyond. Her career has spanned the full spectrum of enterprise applications, from optimizing business processes and managing platforms to leading digital transformation initiatives.

    Sam has transitioned her expertise into the analyst arena, focusing on enterprise applications and the evolving role they play in business productivity and transformation. She provides independent insights that bridge technology capabilities with business outcomes, helping organizations and vendors alike navigate a changing enterprise software landscape.

    View all posts