The myth of the compliant vendor
This Sunday marks a quiet but expensive deadline for anyone running an AI chatbot in the EU. Under the AI Act, disclosure requirements regarding the nature of these bots now apply directly to the users and API builders. The crucial bit—the part that usually gets buried in the sales deck—is that your vendor cannot comply for you.
If you've bought a "compliant" solution from a third party, you've likely been told that the heavy lifting is handled. It isn't. The regulator cares about who is presenting the AI to the citizen, not which subcontractor wrote the code. If the disclosure isn't there by Sunday, the liability sits with the firm that deployed the bot, regardless of what the service level agreement claims.
It’s a recurring theme this week: the gap between outsourced technicality and actual legal responsibility.
We see it most clearly in health data. DentaQuest has just confirmed a theft affecting some 15 million patients. While the press releases will focus on the "sophisticated" nature of the attack—likely the work of ShinyHunters, given current trends—the regulatory question is simpler. Who owned the risk?
The US Senate committee recently voted 22-0 to expand HIPAA protections to cover data that previously fell through the cracks. This suggests a growing impatience with the idea that if data lives in a "non-covered" entity's cloud, it's suddenly fair game for hackers. The law is moving toward the reality that health data is health data, no matter which vendor is hosting the server.
Some will argue this places an impossible burden on smaller providers. They'll claim they can't be expected to audit every line of a vendor's API or verify encryption standards that require a PhD to understand.
That may be true, but regulators aren't in the business of empathy; they are in the business of filings. If you choose to outsource your core compliance obligations, you aren't transferring the risk—you're just paying someone else to manage it poorly on your behalf.
The second-order effect here will hit professional indemnity insurers next. When the first wave of EU AI Act fines lands or the expanded HIPAA rules trigger a series of audits, firms will point to their vendors. Insurers, who have spent years pricing risk based on these "certified" vendor stacks, will find themselves exposed. We can expect a sharp tightening of terms for any firm that cannot produce an independent verification of their third-party controls.
The Big 4 aren't helping. The FCA has already expressed irritation that high-risk audit work is being offshored, likely to the same regions where the "compliant" software is being built and maintained. It’s a closed loop of plausible deniability.
Whether it's a chatbot disclosure or a patient database, the pattern holds: the vendor provides the tool, but the user provides the neck for the noose.
The question now is whether any firm actually has a current, signed-off register of every AI touchpoint they’ve deployed across their business. Most don't. They have a list of invoices from vendors who promised it was all sorted.