The AI Act Addendum Scores Intake, Not Model Cards

The high-risk obligations in the EU AI Act became applicable on August 2, 2026, the 24-month mark after the regulation entered into force. That date is showing up this week in U.S. Q4 vendor packets. Legal is attaching AI-risk addenda and ISO/IEC 42001 asks to the same social-content shortlists that have to freeze before Labor Day.

Labor Day 2026 is September 7. You have roughly ten days. After the PO is signed, the addendum is a diary entry.

Most coverage of the Act is still stuck on watermarks, disclosure labels, and generator risk class. That is not the question on the paper in front of counsel. The live question is: who is the attributable author of the public-facing business representation, and can you produce the source artifact?

A stack that starts from an owner-shot photo, video, or voice note and keeps a chain of custody can answer in one line. A stack that starts from a generated plan cannot, no matter how polished the policy PDF. Score the intake path, not the model.

The addendum is a source-path test

If you have opened one of these questionnaires in the last two weeks, you have already seen the mismatch. The vendor deck leads with a model card, a residual-risk matrix, and a paragraph about human review. The addendum from counsel asks something more primitive:

  • Who originated the asset the public will treat as the business speaking?
  • Can you retrieve that original, dated, attributable file on demand?
  • What did the model change, and under whose authority?

Those are chain-of-custody questions. A model card tells you how a vendor wants the system classified. It does not identify last Tuesday's storefront photo. Counsel is not buying a classification. Counsel is buying a source path an auditor can inspect.

We have seen buyers score the screenshot instead of the system before. In An Agent With the Password Is Not a Publishing Stack the failure was treating a live demo as a control plane. This week's failure is treating a model card as evidence of authorship. Different attachment. Same error.

ISO/IEC 42001 does not paper over a missing original. A management system that cannot retrieve the input is documenting a process you do not run.

What most teams get wrong

The attractive read of August 2 is that you need a warning-label policy and a risk memo. That debate lives in a PDF. Vendors are ready for it because they already wrote the PDF.

The Act's high-risk duties, GPAI transparency obligations, and the 42001 asks riding along in U.S. packets share a practical requirement: you must be able to explain the system you actually operate. Explanation starts at intake, not at the finished caption.

If the workflow begins with a generated content plan, the attributable author of the public-facing representation is ambiguous on day one. The model proposed the claim. Someone may have edited the text. The image may have no owner. When counsel asks who said this, and from what source, you reconstruct. Reconstruction is not evidence.

If the workflow begins with a field asset from the business (a photo of today's job, a voice note from the owner, a clip of the special), the author is named at intake. The model can still draft, crop, or adapt. That is an assistive role on a bounded input. You can show the original file, the sender, the timestamp, and the transformations. That is a source path.

The difference is not philosophical. It is whether you can answer the addendum without scheduling a meeting.

Local operators already create the raw material. A plumber photographs the repair. A salon owner records the result. A restaurant texts the board. The operational failure is dropping that origin the moment the file enters a tool that only retains the finished copy. The same gap is now a line item on a legal questionnaire. We already treated field origin as a scoreable rule in Gemini Answers Near Me. Score Today's Truck Photo. The addendum adds the legal clause: produce the file, name the sender, show the transformations.

Three questions to paste into the RFP

Do not add a sixth appendix about AI ethics. Put three questions on the vendor addendum and require a sample evidence pack, not a narrative.

1. What is the attributable origin of a public-facing item, and can you produce it?

Ask for one recent item plus the source artifact: original file, sender identity, intake timestamp, and storage location. Pass if a named person or business account sent a photo, video, or voice note and the vendor can retrieve that object in the session. Fail if the item began as a generated suggestion, a stock pack, or a plan slot with no retrievable original.

2. What did the model touch, and who authorized the change?

Ask for a transformation log: input, outputs, which model or loop ran, and who approved the public version. Pass if the model is bounded to an owner-originated input and the approval is a named person. Fail if the vendor can show a prompt template but not the input file, or if approval is "the system sent it."

3. Can you revoke the automation without losing the source?

Ask what happens when you suspend the model, the vendor, or a connected account. Pass if the original assets and the custody record remain in a store you can export. Fail if turning off the generator orphans the evidence, or if the only copy of the source lives in a prompt history you cannot produce later.

Those three map to the addendum's actual demand: attributable author, inspectable artifact, and a system you can still explain after someone leaves. They also survive a counsel who has never logged into a social dashboard.

If a vendor answers with watermarks, disclosure badges, or a model-card annex and cannot produce the source file, they failed question one. Stop scoring the rest.

Lock the evidence pack before Labor Day

The procurement calendar is the constraint. Q4 social-content addenda are locking now so the shortlist can freeze around Labor Day. After that you inherit the intake path you signed. Score a simple test: does the stack start from an owner-originated asset, or from a generated plan you hope to reverse-engineer later?

A useful evidence pack for this week looks like this:

  • One owner-originated intake: an email or text of a field photo, video, or voice note
  • The stored original, with sender and timestamp
  • The model or loop that adapted it
  • The approved public version
  • An export of that chain that legal can file without a vendor login

If the vendor cannot assemble that pack from a live account in a working session, they do not have a source path. They have a story about one.

We keep the model in a bounded assistive role on purpose: the owner texts or emails the field asset to a dedicated address, the original is stored first, and adaptation happens after that source exists.

Put the three questions in the RFP this week. Require the evidence pack before anyone demos generated copy. If the source artifact is missing, the addendum already has its answer.

Stop scrolling.
Start posting.

Your social media is not your job. Let us handle it.