Trustgent
regulatory

Regulatory readiness for AI procurement.

AI Act, GDPR, HIPAA, SOC 2, none are a tickbox, and none are interchangeable. A procurement-grade summary of what to verify per regime.

AI Act, GDPR, HIPAA, SOC 2, none of these is a tickbox, and none is interchangeable with another. A vendor who is SOC 2 compliant may have done nothing about the EU AI Act; a team strong on GDPR may have no HIPAA experience at all. This is a procurement-grade summary of what to verify, per regime, before you sign.

EU AI Act, classify first, then ask

The AI Act is risk-tiered, so the first question is *what risk tier does this system fall into?* Most enterprise builds are limited- or minimal-risk, but anything touching hiring, credit, biometric identification, or critical infrastructure can be high-risk, which brings substantial obligations: risk management, data governance, logging, human oversight, and conformity assessment. Ask a prospective partner to classify your use case and name the obligations that follow. A partner who cannot do this has not done it before.

GDPR, data flows, not certificates

GDPR has no certification you can wave; what matters is the data-flow detail. For an AI build, the sharp questions are: *What personal data enters the model or the retrieval layer? Where is it processed and stored? Is anything used for training, and on what legal basis? How is a deletion request honoured when data may sit in an index or an embedding store?* The answers reveal whether a team has actually shipped under GDPR or only read about it.

HIPAA, for protected health information

If the system touches US protected health information, HIPAA is non-negotiable and specific. Verify that the partner will sign a Business Associate Agreement, that any model or API in the pipeline is covered by one, and that PHI is not silently sent to a third-party endpoint that has not signed up to the same obligations. The most common failure is an LLM API call that routes PHI somewhere outside the BAA boundary.

SOC 2, necessary, not sufficient

A SOC 2 Type II report is good evidence of operational security maturity, and you should ask for the report (under NDA), not just the badge. But SOC 2 is about how a company runs its controls, it says nothing about whether the AI system itself is safe, evaluated, or AI-Act compliant. Treat it as a baseline for trusting the vendor as an operator, not as coverage for the model.

A procurement checklist

Before signing, confirm in writing:

  • The AI Act risk tier of your use case and the obligations it triggers.
  • A data-flow map: what personal or sensitive data the system ingests, where it is processed, and whether anything is used for training.
  • Deletion and retention behaviour across the model, the retrieval index, and any logs.
  • A BAA if PHI is involved, covering every third-party endpoint in the pipeline.
  • The SOC 2 report itself, and the date of the most recent audit.

None of these is exotic, and a partner who has shipped regulated AI will answer them without flinching. The ones who improvise are the ones to worry about.

Newsletter

Stay ahead of the AI services market.

One email a month: what's actually being delivered, verified outcomes, rate benchmarks, AI-analysed builds, category shifts. No vendor PR.

By subscribing you agree to our privacy notice. Unsubscribe in one click at any time.