FinanceGadget
Guide

How to judge an AI provider, as EU enforcement begins

The short answer

Almost everything written about AI companies compares model capability. If you are choosing a provider for professional work, capability is the least durable part of the decision — it changes with every release. What persists is the contract: retention, training use, sub-processors, residency, certifications and who is liable when something goes wrong.

That is the comparison nobody maintains, and from this week it has regulatory teeth.

What changes on 2 August 2026

The EU AI Act applies in stages. Obligations for providers of general-purpose AI models entered into application on 2 August 2025, but providers were given an adjustment year before the Commission could act on them.

That year ends on 2 August 2026. From that date the Commission may exercise its supervision and enforcement powers over GPAI model providers: requesting documentation, conducting evaluations, requiring risk mitigation, and imposing fines. For GPAI providers those fines reach €15 million or 3% of global turnover; other AI Act breaches carry higher ceilings.

Two details that matter for anyone assessing a provider:

  • Models placed on the EU market before 2 August 2025 have until 2 August 2027 to comply. A provider’s older models and newer ones may sit under different deadlines.
  • Signatories to the Commission’s General-Purpose AI Code of Practice were offered a grace period on enforcement. Whether a provider signed is a public, checkable signal of posture.

The Act’s later phases have been amended more than once. Verify current dates against the Commission’s own timeline rather than any secondary source, including this one.

Why this changes the buying question

Until now, “is this provider well governed?” was a matter of trust. From this week there is a documentation trail: providers must maintain technical documentation, publish a summary of training data, and have a copyright policy. A regulator can ask for these.

Which means you can ask for them too. A provider that cannot produce its own AI Act documentation on request is telling you something.

The ten checks

Work through these before committing anything sensitive. Every answer is published or obtainable — the difficulty is that they are scattered across a privacy policy, a DPA, a trust centre, a sub-processor page and a compliance portal.

1. Legal entity and jurisdiction. Which company are you contracting with? Several providers contract EU customers through an Irish or Dutch subsidiary with materially different terms from the US parent.

2. Training use, by tier. Whether inputs train models by default — and note that free, individual, team and enterprise tiers frequently differ. This is the single largest divergence between providers and within them.

3. Retention periods, with numbers. Distinguish conversation history from abuse-monitoring retention. A duration is an answer; “as long as necessary” is not.

4. Sub-processor transparency. Is there a published list? Is there advance notification of changes, and can you object? Absence of a list is itself the finding.

5. Data residency — inference or storage? If a provider offers EU residency, establish whether it covers where inference runs or only where data rests. This distinction defeats a great deal of otherwise careful compliance work.

6. Certifications, and their scope. SOC 2 Type II, ISO 27001, and increasingly ISO/IEC 42001 for AI management systems. Ask for the report, then read the scope section — a certificate covering the corporate network is not a certificate covering the inference platform.

7. DPA availability and terms. Is a data processing agreement offered on your tier? Do you have to request it, and must you actively accept it? An unaccepted DPA protects nobody. Check the standard contractual clauses for transfers outside the EEA.

8. Published incident history. Every provider of scale has had incidents. What you are assessing is disclosure behaviour: were they announced, on what timeline, with what detail. A spotless public record usually means poor disclosure rather than perfect security.

9. Vulnerability disclosure and bug bounty. Is there a published programme, a security contact, a safe-harbour statement? This is a reliable proxy for security maturity and costs nothing to check.

10. AI Act posture. Did they sign the Code of Practice? Is there a public compliance page? Can they produce technical documentation and a training-data summary? From this week, these stop being voluntary signals.

What this framework deliberately does not do

It does not rank providers by intelligence. This site publishes no benchmark scores, no “best model for coding” league table, and no “best AI for medical questions” comparison. Measuring model capability requires evaluation infrastructure this site does not have, and organisations that do run it — independent evaluation labs and academic groups — publish better numbers than a one-person site could.

It also will not tell you which provider to choose. The right answer depends on your data, your obligations and your jurisdiction. The framework gives you the questions; the answers are yours.

How the provider records on this site are maintained

Each provider assessment carries the date its terms were read and the tier they apply to, because providers revise these quietly and an undated claim is worthless within months.

A disclosure that matters here: the drafting of this site is assisted by Claude, an AI assistant made by Anthropic. Anthropic is one of the providers this framework is used to assess. Any assessment of Anthropic on this site is therefore verified independently against primary sources before publication, and readers should weight it accordingly. Applying a framework to the company that helped build the framework is a conflict, and the only honest response is to name it.

Where to start

If you do one thing: find out which tier your organisation is actually on, and whether training use is enabled by default on it. In my experience that single question surprises more teams than the other nine combined.