The AI Act questions you can now ask your supplier

· · AI Security Commentary

If your business uses an AI tool, and by now most do, you have probably wondered what you are actually responsible for. The honest answer for a UK small business has mostly been "nobody has told us yet", which is an uncomfortable place to sit when a client asks how you use AI on their data.

That has shifted slightly, and in a more useful direction than the headlines suggest. New obligations now sit on the companies that build the models, and one of them is a duty to hand information down the chain to businesses like yours.

What has actually happened

The EU AI Act became enforceable on 2 August 2026, when the Commission's AI Office and national authorities began enforcing it. Late in August the Commission took its first formal step, sending requests for information to a number of general-purpose model providers, asking about model security, independent external evaluations, and how models are monitored once they are on the market.

Two things arrived on that August date that matter more to an ordinary business than the enforcement theatre.

The first is transparency. Chatbots have to identify themselves as automated systems. Content that a machine generated or edited has to carry a marker that software can detect. Deepfakes need labelling. Penalties for ignoring this run to €15 million or 3% of worldwide turnover, whichever is larger.

The second is quieter and more useful. In the Commission's words, all providers of general-purpose models "must document certain information and provide it to competent authorities or downstream providers". A downstream provider is you: the business building a product or a process on somebody else's model. They must also keep a copyright policy and publish a summary of what their model was trained on.

Why this is not your compliance problem

It is worth saying plainly, because plenty of people will spend the next year telling you otherwise. If you are a UK company using ChatGPT, Copilot, or Claude to draft emails and summarise documents, the AI Act's obligations for model providers are not yours. You are not a provider of a general-purpose model. The UK has not adopted the AI Act, and the Act's reach into a UK business is narrow and mostly about selling into the EU.

Expect that distinction to get blurred. "AI Act compliant" will start appearing on vendor websites next to the other badges, and some of it will be meaningful while much of it will be decoration. We have written before about how easily a wall of compliance logos substitutes for an actual answer.

So the value here is not a new obligation to discharge. It is a better position from which to ask.

The questions worth asking

Because the model providers now have to document these things and pass them down, you can ask for them and expect a straight answer. That was not reliably true before. Four questions, none of which needs a lawyer.

What model sits underneath this, and who provides it? A surprising number of tools cannot answer this cleanly, because they route to whichever model is cheapest that week. You cannot judge anything else until you know.

Can you show me the provider's documentation for it? The downstream duty means it should exist. A supplier who cannot produce it, or who has never looked, is telling you something about how carefully they built on top of it.

What happens to what we type in? Whether it trains the model, how long it is retained, and where it is processed. This has always been the question that matters most for client confidentiality, and it is the one most often answered with a shrug.

Does the tool tell people they are talking to a machine? If you put a chatbot in front of customers, this is now an explicit expectation for EU users, and frankly a reasonable one everywhere.

Write the answers down. Not for a regulator, but because the next client security questionnaire will ask, and because you will not remember in six months which tool was configured which way.

What to do this quarter

Start with the list, not the law. Write down every AI tool the business actually uses, including the ones that arrived inside something else: the meeting recorder, the CRM's summarise button, the helpdesk suggested reply. Most businesses find more than they expected, which is the same problem we keep meeting in other guises.

Then ask the four questions of the two or three that touch client data, and leave the rest. A supplier who answers well is worth keeping. A supplier who cannot answer at all has just told you where you sit in their priorities.

The regulation itself will keep moving, and the parts that reach a UK SME will arrive through contracts and client questionnaires long before they arrive through law. That is the practical reason to have the answers ready.

How Steelwise can help

Building an honest list of the AI tools your business relies on, and working out which of them handle information you would not want repeated, is a short piece of work. Get in touch.

Further reading

← All filings