Governed AI clears procurement: trust is an inventory
Since 2 August 2025, any provider of a general-purpose AI model placed on the EU market has had to publish a summary of the data it was trained on. That is a document a buyer’s lawyer can ask you to produce, and either you have it or you do not.
The person who decides whether your AI gets bought is increasingly the customer’s security and legal function, and they do not grade intent. I build the systems I lead. I keep a hand-built MCP data-hub that serves governed commercial datasets into AI assistants, so I have watched this from the vendor side of the table. I have seen which questions stall a deal, and which ones a well-built system answers before they are asked. The pattern is consistent: governance you can show is a commercial asset, and governance you can only describe is a delay.
What actually unblocks an AI deal now?
Evidence, not intent. A buyer’s security review does not clear because your deck says you take AI seriously. It clears when you can produce the register on demand: which models you run, where the data came from, what you tested, what gets logged, who can overrule the machine. The gatekeeper has moved from the buyer’s champion to their security and legal team, and that reader wants a paper trail.
A champion wants the outcome; a security reviewer wants the evidence. A missing artifact is rarely a hard no; it is a hold, and a hold is where deals quietly die of slowness while someone assembles proof that should have existed already. Industry bodies now hand buyers the exact script. ISACA tells procurement teams to ask a vendor for a software bill of materials and an AI bill of materials, plus a “transparency pack” of documentation, training-data sources and dependencies. It also says to secure “explicit audit rights so you can verify fairness, performance, and security rather than simply taking the vendor’s word.” That questionnaire now sits on the other side of the table. Governance is now something the buyer procures, not something you assert.
Why did AI trust become a buying criterion in 2026?
Because the calendar forced it and the analysts named it. The EU AI Act is landing in stages, buyers have written its questions into their procurement, and the research firms have turned “AI trust” from a compliance line item into a purchase criterion.
Those staged dates matter. Prohibited practices and AI-literacy duties have applied since 2 February 2025, the obligations on general-purpose AI models since 2 August 2025, and most of the Act still switches on 2 August 2026. High-risk was the date everyone circled, and here the ground moved. In July 2026 the Digital Omnibus on AI entered into force, postponing the high-risk obligations: stand-alone systems move to 2 December 2027, product-embedded ones to 2 August 2028. The delay is real. It is a date, not a reprieve.
Analysts turned trust into a market. Gartner has named it “AI TRiSM,” for trust, risk and security management, and published a buyer’s Market Guide for it.
Forrester calls 2026 the year business buying runs on “proof over promises,” and projects that ungoverned generative AI will destroy more than $10 billion in enterprise value through incidents, settlements and fines. McKinsey’s read points the same way: in its 2026 survey of around 500 organizations, those with a clearly accountable AI-governance function scored materially higher on responsible-AI maturity than those without.
What goes in the inventory?
Seven artifacts, and buyers now ask for them by name. Cross the AI Act’s high-risk requirements with what security teams and industry bodies request, and the list converges on the same register:
- AI system inventory: every model and AI service in use, with provider, version and hosting.
- Risk tiering: which of those decisions are high-stakes, classified before anyone argues about it.
- Data lineage: where the training and fine-tuning data came from, and under what license.
- Evaluation results: what you tested for, including prompt injection and data leakage, and what broke.
- Logging: an audit trail complete enough to reconstruct what the system did.
- Human-in-the-loop: an override path that actually triggers, not one that lives on a slide.
- Vendor assurance: the bill of materials, the certifications and the audit rights that let a stranger check the first six.
Each maps to a question a buyer is now trained to ask, and to where that question is codified:
| What the buyer asks | The artifact that answers it | Where it is codified |
|---|---|---|
| Which models are in here, and whose? | AI system inventory | CISA + G7 AI-SBOM; ISO/IEC 42001 |
| Where did the training data come from? | Data lineage | AI Act Art. 10; GPAI training-data summary (Art. 53) |
| How high-risk is this decision? | Risk tiering | AI Act classification (Annex III) |
| What did you test, and what broke? | Evaluation results | NIST AI RMF (Measure); model cards |
| Can you reconstruct what it did? | Logging / audit trail | AI Act Art. 12 |
| Can a human stop it? | Human-in-the-loop override | AI Act Art. 14 |
| Why should I take your word? | Vendor assurance | ISACA guidance; ISO/IEC 42001 |
None of this is exotic. The AI Act’s high-risk controls are Articles 9 to 15: a risk-management system, data governance, technical documentation, record-keeping, transparency to deployers, human oversight, and accuracy and robustness. The inventory itself is now a government artifact, published by CISA and its G7 partners as minimum elements for an AI bill of materials in seven clusters. Even model cards, the humblest item on the list, trace to a 2019 research paper. The register is just the paper trail of a carefully built system, written down — not a new burden invented by lawyers.
Governance by construction, or the governance tax
Build the controls in and they are free to show; bolt them on and they are the tax that keeps a signed-in-principle deal stuck in security review. Same controls, two costs: one paid once at design time, one paid every time a buyer asks and you assemble the answer under deadline.
I know which is cheaper because I build the systems I lead. On the data-hub, inventory, lineage, logging and a human-in-the-loop path are running code, not a policy PDF. When a buyer’s security team asks where a number came from, the lineage is an artifact I can show, not a promise I make. That is governance by construction: the register exists because the system was built to keep one. It is the same instinct fourteen years in regulated pharma turned into reflex, where model risk, data governance and human oversight are how a thing ships in a high-risk domain, not a layer added at the end. That instinct is portable. An EU AI Act high-risk mindset transfers cleanly to fintech, insurance and healthtech, anywhere an AI decision carries a consequence someone can be held to.
I have argued that the distance from a demo to a shipped system is an operating model. That is the internal version of the problem: why a pilot never reaches production inside your own company. This is the external version: whether the system you did ship can be bought by someone whose lawyers ask hard questions. The governed commercial systems I have led had to survive both.
I will not pretend there is a number here that there is not. No analyst has published a deal-velocity figure for AI governance, and inventing one would be exactly the dishonesty this whole argument is against. But the mechanism is the one SOC 2 has run for a decade: the vendor who can produce the artifact on demand clears the review faster than the one assembling it after the request lands. AI governance is walking the SOC 2 road from nice-to-have to table stakes.
You can show the register, or you can promise you keep one. Only one of those clears the review.
Does the high-risk delay let you relax?
No. The date moved; the demand did not. Most of the AI Act still applies from 2 August 2026, the general-purpose-AI obligations have been live since August 2025, and a buyer’s security questionnaire does not wait for a penalty deadline. It is already in the RFP.
The Digital Omnibus postponed when the high-risk rules apply; it did not touch what they require. The Articles 9-to-15 controls are unchanged, so a company procuring an AI system in 2026 asks for lineage, logging and an override path whether or not a regulator has switched on the fine. Vendors selling into regulated buyers already treat the register as table stakes, because the customer got there before the calendar did. Waiting for the enforcement date optimizes for the regulator and ignores the person actually deciding whether to buy.
Isn’t this just compliance theater?
Only if you produce the charter instead of the register. The test is whether a stranger’s security team can verify your claim without taking your word for it — and a values statement fails that test the moment they ask for the artifact behind it.
The credible trust story in 2026 is not “we are ethical.” It is “here is the inventory, here is where the data came from, here is what we tested, here is the log, here is who can stop it, here are the audit rights.” ISO/IEC 42001 exists to make that kind of claim checkable: a voluntary standard that certifies an organization’s AI management system rather than a single model, and vendors from AWS to Anthropic to KPMG are getting certified because buyers started asking. It is requested, not required, which is how a buying criterion looks in the window before it becomes a floor.
Where to start: make governance a sales asset
Treat the register as a deliverable the system produces, not a document the compliance team writes after the fact. Four moves, in order:
- Build the inventory as running state. Not a spreadsheet someone updates by hand; the system knows which models it runs, where its data came from and what it logged, and can print that on request.
- Wire lineage, logging and an override path into the system itself. These are the artifacts a security review always reaches for, so make them queries, not archaeology.
- Keep the vendor-assurance signals ready. Model cards, an AI bill of materials and, where it fits, an ISO/IEC 42001 posture, so the buyer’s shortcut for “this vendor is serious” is already satisfied.
- Map your controls to the Act, not the reverse. The high-risk requirements in Articles 9 to 15 are the checklist buyers are converging on; build against them and you answer the regulator and the customer with one set of evidence.
Do this and governance stops being the thing that slows the sale and becomes the thing that clears it: the artifact you show while a competitor is still drafting a memo about its values. If your AI program is long on principles and short on the register, that is the operating-model work I do.
Wiring this into how a team builds, documents and sells is the operating-model work I do, and the discipline behind the governance-of-agents problem I have written about. If your AI is long on principles and short on the register, start with the inventory.