Writing / 2026

Compliance Fails at the Vendor Handoff

You answer for an AI system you can only partly witness. Build a compliance interface to each vendor, with owners, deadlines, and drills.

Here is a question that sounds legal and is actually architectural: when your regulator, your largest customer, or your insurer asks you to demonstrate that the AI feature you shipped behaves as claimed, how much of the answer lives inside companies you don’t control? For most products the fraction is large. The model is the vendor’s, its safety testing is the vendor’s, the version that served last Tuesday’s traffic is whatever the endpoint was running, and your logs capture your half of the conversation at best. You are accountable for a system you can only partly witness. Until recently that gap was an awkwardness. The EU’s Digital Omnibus turned up the temperature at one edge of that gap. Article 25, as the amendment rewrote it, obliges an original provider to cooperate with a downstream company that becomes a provider itself by rebranding, modifying, or repurposing the system, with fines up to 3% of global turnover or €15 million, whichever is higher. It sits in the high-risk chapter, so it applies on the deferred dates , December 2027 at the earliest, which gives vendors the interval to write their terms. Read the scope carefully. If you deploy a vendor model behind your own product without becoming a provider, Article 25 gives you no claim on the vendor’s evidence; it gives one to the companies that do become providers, and those are the terms vendors will standardize around. What follows is not a paraphrase of the article. It is the no-regret engineering response to the convergent pattern (that statute at the edge, insurers asking for evidence , enterprise customers asking sooner), and it stands on its own if the statutory details land differently for you.

Call the thing you need a compliance interface, because that’s the right mental model: a boundary contract with another system, except the other system is a company. A compliance obligation that requires another company’s logs is exactly as reliable as your interface to those logs. And the procurement objection is the strongest one: your enterprise agreement already has incident-notification and audit clauses. Most do. The gap is between a clause existing and evidence arriving. Does “incident” include model-safety events or only availability? Can the vendor identify which of your requests were affected, or only that something happened? How fast can retained records actually be produced? May you show what you receive to a regulator? Does the escalation route work when tested rather than when diagrammed? Clause existence is what legal review checks. Operational delivery is what an incident checks, and the second check is the one with your name on it.

So run the audit as an engineering register, one row per vendor per interface, five interfaces to start: incident notification, version identity ( an unqualified model change should demote the workflow anyway , so you need the signal regardless of law), log retrieval, evaluation evidence you’re licensed to show onward, and response ownership, meaning your named role and their contractually defined route with an escalation threshold. Each row gets the required output, its contractual basis, the retrieval mechanism, disclosure permission, latency target, an owner, the date last drilled, and a status: absent, promised, implemented, verified. Only a drill moves a row to verified; an escalation route you can’t test is absent with better formatting. Expect the first pass of this register to be uncomfortable. That’s the point of running it on a calm quarter.

The leverage objection is real: a mid-market customer will not extract bespoke telemetry terms from a frontier lab, and vendors may standardize these interfaces under regulatory pressure, which makes waiting defensible. The register handles both, because each gap row forces one of five decisions instead of a shrug. Get the interface at contract. Buy through a tier or intermediary that supplies it. Constrain that vendor to workflows whose evidence burden you can carry alone. Switch. Or accept the risk, in writing, with an owner, an exposure limit, a review date, and a contingency if the request arrives before the interface does. Waiting is a position. Undocumented waiting is the thing the eventual audit finds.

The through-line of this fall’s posts is that accountability stays with humans and their institutions while the machinery is increasingly rented, and this is that argument’s operational floor. The rule fits in one sentence, and it’s the one to leave on the table when the renewal negotiation starts: if evidence must cross a company boundary to answer for your system, that boundary is part of your system. Own it like one.