← Back

Wire · regulatory

EU AI Act Article 26: What Third-Party Risk Management Programs Miss About AI Vendors

Published

11 September 2026

Topic

regulatory

Sectors

Enterprise Software

Geography

Europe

Source

Read at jdsupra.com

Verified

Fusion42 · 11 September 2026 · Fusion42 review

The EU AI Act Article 26 introduces responsibilities for organisations to monitor high-risk AI tools, particularly highlighting gaps in traditional Third-Party Risk Management (TPRM) processes which fail to detect AI tools that enter organisations without vendor review, known as 'shadow AI'. Article 26's monitoring duties have been delayed to December 2027, but immediate disclosure requirements remain, creating new compliance demands on companies using AI that interacts with customers.

This Wire brief sits within Fusion42's coverage of Enterprise Software.

◆ The Wire takeaway

You must fix unseen AI risks in your vendor process now as the EU is shifting liability for AI features beyond contracts to active monitoring. Shadow AI risks that bypass procurement are no longer optional blind spots but compliance failures you can address this week.

Coverage

1 source · 11 Sep 2026

Related on Wire

Topics

Enterprise Softwareai-actvendor-riskshadow-aicompliancethird-party-risk