EU AI Act Disclosure Rules Hit API Builders Sunday
If you think your AI compliance is a checkbox in a vendor's SOC 2 report, you're about to have a very expensive conversation with your board.
The EU Commission is making it clear: as of this Sunday, the requirement to disclose that a user is interacting with a chatbot falls squarely on the person building the application, not just the entity providing the API. In plain English, if you've plugged an LLM into your customer service portal and didn't tell the users they're talking to a machine, you can't point at OpenAI or Google and say they're responsible for the disclosure.
I've seen this movie before. Back in the early days of SOX, we had firms thinking that because their outsourced payroll provider was "compliant," the company's own financial controls were automatically fine. They weren't. The auditor didn't care about the vendor's certificate; he cared why there wasn't a reviewer signing off on the final payroll run before the cash left the building. That's control design versus control theatre.
Right now, most firms are practicing theatre. They have a contract that says "Vendor will comply with all applicable laws," and they think that's a control. It isn't. A contract is a legal instrument for recovering losses after you've been fined; it isn't a preventative control.
The actual control here is the UI/UX. The evidence is a screenshot of the disclosure appearing to the user before the interaction begins. If that disclosure isn't there, the design has failed.
What does this cost you at year-end? For those under the EU AI Act, it’s not just a slap on the wrist. We're talking about potential fines that can reach north of 35 million euros or a significant percentage of global turnover. That is a material hit to the bottom line that no "shared responsibility model" will erase.
The common pushback I hear from the middle-management layer is that the API provider should build the disclosure into the stream. They argue that the technology should be self-regulating.
That's nonsense. The API provider doesn't know where your bot lives, who it's talking to, or what language they're speaking. Expecting a vendor to manage your end-user transparency is like expecting a tire manufacturer to make sure you've put gas in the car. You own the interface; you own the risk.
The second-order effect here will hit the auditors first. We’ll see a surge of "AI compliance" audits that are purely superficial, focusing on policy documents rather than technical validation. But the regulators aren't looking for policies. They're looking for the disclosure. When the first few fines land—and they will, likely alongside the fallout from breaches like the DentaQuest hack which exposed just under 15 million patients—the auditors who signed off on "policy-based compliance" will be the ones in the hot seat.
You can spend your Monday morning updating a spreadsheet, or you can actually check if there's a label on your bot. I'd suggest the latter.
Keep an eye on how the Luxembourg privacy watchdog handles its enforcement delays. If they get their powers sorted quickly, they’ll likely use these API disclosures as the lowest-hanging fruit to prove they have teeth.