The API Is Ready. The User Is Exposed.
Companies are treating the EU AI Act as a vendor management problem. They believe that if they buy from a compliant provider, the compliance flows downstream like a software update. It doesn’t.
The deadline for chatbot disclosure requirements hit this past Sunday. For any firm using an API to power their customer-facing bots, the reality is stark: your vendor cannot comply for you. The Act requires that users be informed they're interacting with an AI. While the API builder provides the engine, the deployer—the company whose logo is on the website—is responsible for the disclosure.
This is where 'privacy by design' usually turns into a lie. Most firms haven’t designed anything; they've just plugged in a key and hoped for the best. They point to a SOC2 report or a contractual clause where the vendor promises "regulatory alignment."
That isn't evidence.
If you're the person tasked with proving compliance, stop looking at the contract. A contract is a promise; a control is a fact. To satisfy a regulator, you don't need a PDF from your vendor. You need a timestamped screenshot of the disclosure appearing to the end-user before the interaction begins. You need logs showing that this notice was served.
The strongest objection here is usually that the vendor has a "compliance toggle" in the settings that handles the disclaimer automatically.
That’s a trap. Relying on a vendor's toggle means you have no independent way to verify the control is actually functioning across all sessions. If the toggle glitches or an update resets it, you're the one who'll be paying the fine, not the API provider. The regulator isn't going to chase a trillion-dollar tech giant for a missing sentence on your landing page; they'll go after the entity that owns the customer relationship.
When controls are this hollow, the risk shifts from the legal department to the auditors and insurers. We're seeing a gap where internal audit teams sign off on "AI Governance" based on vendor questionnaires rather than actual deployment checks. When the first wave of AI Act enforcement hits, these auditors will find their signatures on certifications that were essentially guesswork.
Insurers are already twitchy. Look at the DentaQuest breach affecting just under 15 million patients; it’s a reminder that when "systems" are trusted over verified controls, the fallout is massive. While a missing chatbot disclosure isn't a data theft event, it's a signal of systemic negligence.
If you can't produce a log showing exactly when and how a user was notified they were speaking to a bot, you aren't compliant. You're just lucky.
The question for the next internal audit is simple: did we actually test the UI, or are we just trusting a checkbox in a vendor portal?