Auditen
enforcement wrap

The API Is Compliant. The Customer Is Not.

If you think your SaaS agreement is a shield against regulatory fines, you’re in for a very expensive surprise.

The EU Commission made it clear this week that the AI Act's chatbot disclosure rules hit API builders and their users simultaneously this Sunday. Here is the part that will keep your legal team awake: vendors cannot comply for you. If you’ve plugged a third-party LLM into your customer service portal and forgot to tell the user they’re talking to a machine, the regulator isn't going after the API provider. They're coming for you.

This is a classic failure of control design. Most firms treat "compliance" as a checkbox provided by a vendor in a SOC 2 report. They see a "Compliant" stamp on a PDF and assume the risk has been transferred. It hasn't. Liability for user disclosure sits with the entity controlling the user interface, not the entity providing the plumbing.

The argument from the middle-management layer is always the same: "Our contract says the vendor is responsible for ensuring the technology meets EU standards."

That doesn't matter. A contract is a private agreement between two companies; it isn't a license to ignore public law. The regulator cares about the person being deceived by a chatbot, not your indemnification clause. If you didn't build the disclosure into the frontend, you don't have a control. You have a piece of paper that allows you to sue your vendor after you've already been fined.

The second-order effect here is an immediate spike in liability for the consultants who signed off on these AI implementations. When the first wave of fines hits, the question won't be why the API failed, but why the internal control framework didn't account for the disclosure requirement.

I remember the early days of SOX back in '03 when people thought a "management representation letter" was a substitute for actually testing a control. It wasn't then, and it isn't now with AI.

Speaking of things that cost you at year-end: DentaQuest just leaked data on 15 million patients.

When you see a number like 15 million, stop looking at the technical "how" and start looking at the balance sheet. Between mandatory notifications, legal counsel, and the inevitable OCR investigation, this isn't just a security breach; it's a capital event. This is exacerbated by the fact that ShinyHunters is actively ramping up attacks on healthcare data.

The failure here is usually a lack of basic hygiene—over-privileged accounts or legacy silos that should have been purged years ago. We see "compliance" reports saying the data is encrypted at rest, which is great for the auditor's checklist but useless if the attacker has the keys to the kingdom.

If you’re running healthcare data and your primary defense is a vendor-provided security guide from AWS, you aren't secure. You've just outsourced your ignorance.

On the regulatory front, the Senate Committee voted 22 to 0 to expand health data protections beyond the original scope of HIPAA. It was a clean sweep. For those of you who’ve spent a decade narrowing your compliance perimeter to "only what HIPAA strictly requires," the walls just moved. You are now likely collecting data that is suddenly under the microscope.

Then we have the FCA in the UK, which is currently annoyed that the Big 4 are offshoring high-risk audit work.

As someone who has spent twenty years in the trenches of SOC and SOX, this makes me sick. High-risk audit work requires nuance, skepticism, and an understanding of the client's actual business operations. When you offshore that to a low-cost center where the goal is "efficiency" (read: ticking boxes as fast as possible), you lose the ability to spot when a control is just theatre.

The danger isn't that the work won't get done; it's that it will be done perfectly on paper while the actual risks go unmanaged. The auditor in the offshore center doesn't have to live with the consequences of a failed year-end audit. They just need to clear their queue.

We’re seeing this same disconnect in the markets. Nasdaq flagged Core AI Holdings because its bid price dipped under $1.00. Meanwhile, the SEC stayed Nasdaq's proposed $5 million market value requirement pending further review.

It's a reminder that while you're worrying about your "AI strategy," the basic financial controls and listing requirements are what actually keep the lights on.

You can buy the most expensive tools in the world, but they don't replace a functioning control environment. You either have a design that mitigates risk, or you have a collection of expensive licenses and a prayer.

I want to know who is actually reviewing your AI disclosure workflow this week. If the answer is "our vendor handles it," you’ve already failed.