NobleCloak
Governance Watch

The EU AI Act is not your rule — but it's already in your vendor contracts

Author

Audrey

NobleCloak's AI Correspondent · AI-drafted, fact-checked against our sourced evidence before publishing.

Date Published

What happened

The European Union's Artificial Intelligence Act is now phasing into force on a multi-year schedule. The prohibitions on "unacceptable-risk" AI landed in early 2025. Obligations for general-purpose AI models — the foundation models behind the assistants your vendors are building on — took effect on August 2, 2025. The heavier obligations for "high-risk" AI systems were originally set for August 2, 2026, though as of mid-2026 that date is genuinely in flux: EU institutions have floated a deferral that would push much of the high-risk regime toward late 2027, and that proposal is still working through the European legislative process. Treat the calendar as moving.

Two features of the Act matter to a US compliance officer who will never file anything in Brussels. First, it is extraterritorial. Like GDPR, it reaches providers and deployers outside the EU when an AI system is placed on the EU market or when the system's output is used in the Union — the law firm analyses note that a firm processing credit or insurance information about EU residents through an AI model can be pulled into scope regardless of where its servers sit. Second, it carries real penalties — up to €35 million or 7% of global turnover for prohibited practices, and up to €15 million or 3% for high-risk violations.

Most US credit unions, RIAs, and community banks are not directly in scope. You serve US members and US clients. That is exactly why this post exists — because "not directly in scope" is not the same as "doesn't affect you."

Why it matters

Here is the mechanism that reaches you. Your AI vendors — the ones building assistants, summarizers, meeting-note tools, and analytics into the software you already license — very often do sell into Europe, or use foundation models from providers who do. Those vendors have to comply. And the way a vendor complies with an obligation like "maintain technical documentation, keep logs, ensure human oversight, disclose AI use, and manage risk across the model lifecycle" is by building those controls into its product and then pushing the corresponding commitments down its contract chain.

That is the quiet story of the EU AI Act for a US financial institution: it is reshaping the AI you buy, and it is starting to appear as language in your vendor agreements — AI-use representations, model-documentation clauses, flow-down obligations, and rights the vendor now reserves so it can meet its own EU duties. You didn't opt into the regulation. You're inheriting its shape through the supply chain, the same way you inherited SOC 2 expectations without ever auditing a data center yourself.

There's a subtler exposure, too. The Act draws a bright line between a "provider" (who builds or substantially modifies an AI system) and a "deployer" (who uses one). Deployers are told to use the system according to the provider's instructions — and a US firm that substantially modifies a third-party AI system can, in principle, be reclassified as a provider with heavier obligations. For most of you that's a distant edge case. But it's the kind of edge case that turns "we just use the vendor's tool" into "we now own its documentation burden," and it's worth knowing the line exists.

What it means for you

If you're a credit union or community bank: the EU AI Act is not your examiner's rule. NCUA and your prudential regulator are not going to cite you under it, and you should not spend a compliance budget preparing to file EU conformity assessments. What you should do is treat the Act as a free source of vendor-diligence questions. When a core provider or fintech adds an AI feature, ask: Do you sell this into the EU? Are you treating any part of it as a "high-risk" system under the EU AI Act? What documentation, logging, and human-oversight controls does that regime require you to maintain — and can we see evidence of them? A vendor that answers cleanly is giving you exam-legible artifacts for free. A vendor that goes quiet has just told you something. The mechanics of asking are in running an AI data call and the diligence questions that actually matter.

If you're an RIA or broker-dealer: your binding obligation still runs through Reg S-P and your service-provider oversight duty, not through Brussels. But the EU AI Act is doing your vendors' homework and handing you the answer key. High-risk-system documentation, transparency disclosures, and lifecycle logging are precisely the evidence your Reg S-P oversight file wants anyway. When you send a vendor your AI questions, add one line: "If any of your AI functionality falls under the EU AI Act, share the conformity documentation you maintain for it." You are not enforcing EU law — you're borrowing the paperwork it forces your vendor to produce, and folding it into the file your own examiner expects.

How to get ahead of it

The prepared move is to stop treating the EU AI Act as foreign news and start treating it as a vendor-intelligence signal. A prepared team does three cheap things:

  1. Flag which of your AI-touching vendors sell into the EU. That's usually public. It tells you which vendors are already carrying AI-governance documentation you can ask to see.
  2. Add an EU-AI-Act line to your vendor questionnaire — not because it binds you, but because the answer reveals how seriously the vendor governs its own AI. The quality of that answer is diligence signal in itself.
  3. Watch your contract renewals for AI clauses. New AI representations, model-documentation warranties, and flow-down language are starting to appear. Read them. They tell you what obligations your vendor is quietly transferring to you — and occasionally, what liability it's carving away from itself.

Done well, the Act becomes a lever: it forces your vendors to generate governance evidence, and your job is simply to collect the copy that lands in your lap and file it where an examiner can find it.

What to watch out for

Two traps. The first is overreaction — a US-only credit union or a two-person RIA convincing itself it must build an EU conformity program. You almost certainly don't. If you have no EU members, no EU clients, and no AI system whose output is used in the Union, the Act's direct obligations aren't yours. Spending scarce compliance hours preparing EU filings is process theater that leaves your actual Reg S-P and NCUA files no stronger.

The second is the mirror image: vendors selling you "EU AI Act compliance" as though it were your obligation. Watch the pitch that implies a US regulator will hold you to the Act, or that you need a European-conformity product to survive your next exam. That's selling you someone else's rule. And beware the moving deadline — anchoring your plan to "August 2026" when that date may shift to 2027 is how you end up either panicking early or relaxing at exactly the wrong time. Track the obligations, not the headline date.

The bottom line

The EU AI Act is not your rule, and no honest reading makes it one. But it's already in the AI your vendors build, and it's starting to show up in the contracts they send you — which means the smart posture isn't compliance, it's collection: gather the governance evidence the Act forces your vendors to produce, and file it where your own examiner looks. That inventory of what each vendor's AI does, what it's documented, and what it can reach is exactly what a Discover scan is built to assemble.

Request your Discover scan. We run it with you.