Skip to content
Annuaire
Sections
Business

AI Act: When Compliance Becomes a Selling Point

AI Act: When Compliance Becomes a Selling Point
L’essentiel

In AI procurement, performance is no longer enough: customers also want evidence that risks are under control. As the European framework rolls out, robust compliance can help secure contracts—without, on its own, guaranteeing commercial success.

À retenir

In AI procurement, performance is no longer enough: customers also want evidence that risks are under control. As the European framework rolls out, robust compliance can help secure contracts—without, on its own, guaranteeing commercial success.

An impressive demonstration opens the door. A solid documentation package can seal the deal. For companies selling artificial intelligence in Europe, the shift is profound: they must show what a system can do, but also explain its limitations, document its uses and establish accountability in the event of an incident. Looking ahead to September 2026, the AI Act therefore raises a distinctly commercial question: can compliance become something other than a cost centre? Yes, provided it is turned into evidence that buyers can use, rather than a stack of procedures.

The regulatory timeline enters the negotiations

The European Union’s Artificial Intelligence Act, which entered into force on 1 August 2024, provides for phased implementation. Under the timetable adopted in 2024, bans on certain practices and the obligation to take AI literacy measures have applied since February 2025. Provisions concerning general-purpose AI models begin to apply in August 2025, with specific transitional arrangements, particularly for models already on the market.

Under that original timetable, 2 August 2026 is the general application deadline, including for some high-risk systems. Certain obligations relating to systems linked to regulated products are scheduled for August 2027. This outlook for September 2026 is based on adopted legislation and known trends; any subsequent adjustments to the timetable or implementation arrangements must be checked. The commercial trend nevertheless appears robust: buyers have an interest in anticipating their own obligations.

Not all software incorporating AI is necessarily “high-risk”. Classification depends in particular on its intended purpose and the context in which it is used. A recruitment tool designed to screen applications does not face the same requirements as a rephrasing assistant. The first capability to sell, then, is the ability to explain precisely which category an offering falls into, and why.

In tenders, evidence joins performance

Imagine a tender for a recruitment support tool. This scenario is illustrative, but the questions are concrete. Two suppliers present comparable results. The first promises faster screening. The second also presents its evaluation protocols, identified limitations, human oversight mechanisms and the information the customer needs to understand the results. For a procurement department supported by legal and IT security teams, the second proposal is easier to defend.

Compliance then becomes a way to reduce uncertainty. Who steps in if results drift? What model change requires a new evaluation? What records will be available to analyse a disputed decision? Buyers are not just looking for technology: they want to avoid an opaque dependency, a stalled deployment or a crisis they cannot explain.

This shift builds on practices already established in technology procurement: cybersecurity questionnaires, GDPR requirements and subcontractor audits. The AI Act adds a specific layer addressing AI risks. It does not replace data protection, employment law or sector-specific rules. A credible supplier coordinates these frameworks rather than presenting a single form of compliance supposedly covering everything.

Three commercial assets to build

Documentation that is genuinely usable

The first asset is a documentation package that customers can use without tying up a team for weeks: the system’s purpose, conditions of use, measured performance, known limitations, responsibilities and monitoring arrangements. For high-risk systems, some documents are subject to specific regulatory obligations. Elsewhere, proportionate documentation can still be good commercial practice. Not everything needs to be public: information owed to users, material intended for authorities and confidential elements must be distinguished.

Demonstrable risk management

A promise of reliability is no substitute for a protocol. Tests must match the use being sold, rather than a general performance claim displayed in a presentation. A document assistant, for example, should be evaluated on its ability to represent sources faithfully and flag uncertainty. In sensitive contexts, the conditions for human intervention, alert thresholds and suspension procedures must also be specified.

Traceability designed in from the outset

Identifying the model version, retaining relevant information about changes and enabling incident analysis: these functions have operational value. They support maintenance as much as governance. But traceability does not mean indefinite retention. Logs may contain personal data or trade secrets. Their contents, access permissions and retention periods must be governed by clear rules.

The model provider cannot do everything

For software vendors combining a third-party model, a document repository and a business interface, it is tempting to leave compliance to the model developer. That is not enough. The regulation distinguishes, among others, between model providers, system providers and deployers. Obligations vary by role; certain modifications or changes of purpose can shift responsibilities.

Commercially, this means securing the contractual chain. What information does the upstream provider supply? How does it announce changes? What commitments does it make on support and the availability of documentation? A start-up may have an excellent interface yet remain vulnerable if it does not control the dependencies needed to deliver on its promises. Transparency across this chain becomes a selection criterion.

A real advantage, but neither free nor automatic

Compliance comes at a cost: legal expertise, engineering, evaluations, monitoring and documentation updates. For an SME, this effort can be a heavy burden even before the first contract is signed. Large companies generally have more resources to absorb it. But a smaller business can make its offering easier to assess through a focused product, clearly defined uses and consistent evidence.

Beware, however, of seal-of-approval marketing. There is no universal “AI Act compliant” certificate valid for every use. ISO/IEC 42001, the standard dedicated to AI management, can help structure an organisation; it does not, on its own, demonstrate the compliance of every system. Similarly, CE marking, where required, is not a general award for ethical AI. The wording used in sales proposals must remain precise.

The commercial return is therefore measured less by the volume of documentation than by its effects: questions resolved faster, responsibilities allocated more clearly and fewer delayed deployments. It remains a hypothesis to be tested company by company. A mediocre product does not become competitive thanks to impeccable documentation; where performance is comparable, however, the ability to demonstrate control can make the difference.

What next? The most plausible scenario is one in which compliance is gradually integrated into the product: accessible documentation, version histories, oversight and clear contractual commitments. Suppliers that build these capabilities early could reduce purchasing friction and strengthen customer loyalty. The challenge will not be to promise risk-free AI, but to make its risks understandable and manageable. In tenders, that distinction could become decisive.

Sur votre appareil

Comprendre cet article

L’analyse utilise l’intelligence locale du navigateur lorsqu’elle existe, sinon un résumé extractif. Le texte n’est envoyé à aucun service extérieur.

Facebook X LinkedIn

Ensuite A lire aussi