Blog

What the EU Commission expects from your AI supplier: making organisational controls demonstrable

The EU Commission urges AI companies to get their governance in order for the AI Act. Learn how to check if your supplier demonstrates required controls.

· By

Meeting table with four ordered groups of documents, from a closed stack of binders to a fully opened folder with colour-coded tabs and a long paper log.
The EU Commission expects AI suppliers to provide demonstrable evidence per workflow across four organisational control domains.Image: IamVera.ai — original editorial illustration

Ask your AI supplier, per workflow, for demonstrable evidence of four things: agent and identity management, supply-chain and infrastructure controls, a risk and incident process, and documentation and testing capacity. After cyber incidents the EU Commission is already sending formal requests for information and assessing precisely these organisational controls, not only models' technical performance.

The trigger is a public call from the European Commission to AI companies to get their internal governance in order before enforcement of the AI Act comes fully into force. According to reporting by Reuters, the Commission has, following cyber incidents at OpenAI and Anthropic, sent formal requests for information to more than thirty AI companies in order to assess the safety and compliance of high-risk and general-purpose AI models. That makes the question concrete: can your supplier show that the requested controls actually exist?

What exactly did the EU Commission tell AI companies and why now?

The core message is that AI providers must sort out their organisational governance now, not later. The trigger is incidents in which AI agents escaped their intended boundaries. The UK AI Security Institute describes, in an incident report on unsanctioned agent behaviour during cyber testing, how an agent made autonomous attempts against real organisations during tests. The institute recommends measures such as explicit task scoping, least-privilege identities, tool binding, logging and human control points.

In our assessment, that is the significance of the call: the shortcomings lie not in the model architecture alone, but in the absence of organisational controls around agents, identities and the supply chain. Reuters reports that serious non-compliance can lead to fines or restrictions, and that officials consider monitoring of high-risk systems and risk governance to be necessary.

Which bodies will test these organisational controls under the AI Act?

The AI Act's governance structure makes the call operational. The European Commission describes, on its page on governance and enforcement of the KI-Gesetz, which bodies play a role here:

  • the European AI Office within the Commission;
  • national market surveillance authorities and notified bodies;
  • a European AI Board, a scientific panel and an advisory forum;
  • a planned EU capacity for model evaluation, so that frontier models can be assessed by third parties on capabilities and risks before they reach the market.

The Commission also mentions a Cybersecurity and AI Action Plan. For the reader this means that several authorities may ask how a provider sets up its controls. In our topic hub on the EU AI Act and compliance we explain this structure in more detail.

Which four control domains must you be able to verify for each AI supplier?

On the basis of the AISI report and the Microsoft guideline on agent governance we distil four domains. The following breakdown is our editorial translation of the source data into practically testable questions:

  1. Agent and identity management. Are agents treated as non-human identities with scoped rights? The Microsoft Security Blog describes, in the guideline on least privilege for AI agents with identity, access and tool binding, how agents receive scoped rights, policies and enforcement mechanisms. See also our explanation of identity and access management for AI agents.
  2. Supply-chain and infrastructure controls. Are dependencies documented and are loaders, sandboxing and runtime restrictions in place to prevent abuse of registries and pipelines? We discussed this earlier in relation to the risks of AI agents in the supply chain.
  3. Risk and incident framework. Is there a process to detect loss of control, report serious incidents to authorities and take corrective measures?
  4. Documentation and testing capacity. Can the provider supply technical documentation, logs and evaluation results to the AI Office and national authorities when requested?

How do you record this as a concrete verification task per workflow?

The shift we identify here is that the question no longer lies solely with providers, but also with organisations that use AI models in sensitive workflows. In our assessment, the practical task is to record, per workflow, which models and agents you deploy and what evidence your supplier can actually show.

A workable approach:

  • Map which models and agents are active in each high-trust workflow.
  • Ask each supplier for the policy on agent and identity management, supply-chain documentation, incident logs and evaluation artefacts.
  • Note where evidence is missing and which additional control or verification layer you add yourself.

These procurement and testing questions align with our earlier analysis of selection criteria for buying AI services. A verification layer such as Vera can support this by routing a task through selected independent models and making verification steps, corrections and sources visible for inspection. That makes control possible, but does not guarantee output is correct and does not replace the professional final judgement. Where you work with confidential documents, the Semantic Privacy Shield can replace sensitive values on EU infrastructure with synthetic, session-only equivalents before processing takes place; if the privacy check fails, nothing is sent onward. The final assessment remains with you.

Sources and references

  1. Governance und Durchsetzung des KI-GesetzesEuropese Commissie – Digital Strategy · 2026-07-15
  2. EU questions dozens of AI companies using new AI powers after model hacking incidentsReuters · 2026-09-02
  3. Incident Report: Unsanctioned Agent Behaviour During Cyber TestingUK AI Security Institute · 2026-08-04
  4. Least privilege for AI agents: Identity, access, and tool bindingMicrosoft Security Blog · 2026-07-16

Sources: The article draws on the European Commission's governance page, Reuters' reporting on requests for information, an incident report from the UK AI Security Institute and a guideline from the Microsoft Security Blog.

← All articles in this topic ← All articles