TL;DR: AI regulation now reaches product teams through procurement, questionnaires, and contract evidence, with federal, state, and EU rules pushing model cards, evaluations, acceptable use policies, and incident logging into standard delivery workflows, according to Promptfoo. Documentation is no longer a governance afterthought. It has become a measurable product requirement that reshapes how AI systems are tested, sold, and operated.
NHIMG editorial — based on content published by Promptfoo: AI regulation and procurement requirements for AI builders
By the numbers:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials.
- 96% of technology professionals identify AI agents as a growing security threat, and 66% believe this risk is immediate.
Questions worth separating out
Q: How should security teams document AI systems for procurement and compliance reviews?
A: Security teams should document the deployed AI stack, not just the base model.
Q: Why do AI agents create a governance problem for IAM teams?
A: AI agents create a governance problem because they authenticate and act as autonomous software entities with tool access.
Q: What breaks when AI testing ignores tools, retrieval, and memory?
A: Testing breaks down when it covers only model output and ignores the operational stack.
Practitioner guidance
- Build an AI evidence pack for procurement Create a standard package that includes model cards, evaluation results, acceptable use policies, incident handling steps, and owner contacts before the system is offered to buyers or internal customers.
- Test the deployed stack, not just the model Run evaluations against prompts, retrieval sources, tools, memory, and logging so the review reflects the production configuration rather than a standalone benchmark.
- Review identity and secret scope for every AI action path Map each tool call to the API keys, service accounts, or delegated tokens it depends on, then remove standing privilege wherever the action does not require persistent access.
What's in the full article
Promptfoo's full article covers the operational detail this post intentionally leaves for the source:
- Detailed timeline of US federal, state, and EU AI requirements for 2026 planning
- Specific procurement artefacts agencies are asking for, including model cards and evaluation evidence
- Comparative breakdown of how federal, California, Colorado, and EU obligations differ in practice
- Implementation implications for testing agentic systems across prompts, tools, retrieval, and logging
👉 Read Promptfoo's analysis of AI regulation, procurement, and compliance evidence →
AI procurement compliance: what product teams need to document now?
Explore further
Documentation is becoming the control plane for AI governance. The article shows that model cards, evaluations, acceptable use policies, and feedback workflows are now procurement objects, not optional supporting material. That shifts accountability from informal assurance to auditable proof, which is exactly how governance matures in regulated environments. Practitioners should treat documentation as a first-class operational control, not a paper trail.
A question worth separating out:
Q: Who is accountable when an AI system makes a harmful decision?
A: Accountability should follow the identity chain that authorized, configured, or triggered the action, including the human owner, the platform team, and any delegated agent or tool account. If the organisation cannot name that chain, the governance model is too weak for regulated AI use.
👉 Read our full editorial: AI regulation now reaches product teams through procurement and audits