Back to all articles

The AI Question That's Killing Your Deals in Procurement

B2B deals stalling at the procurement gate

Here's a pattern I've watched play out four times in the last quarter, across three different industries.

A deal is going well. The champion loves the product, the business case is signed off, the commercials are agreed. Then it goes to security review, and a questionnaire comes back with a section nobody on the vendor side has a ready answer for: Which AI models does your product use? Where does our data go? Do you train on it? Who is accountable if the output is wrong?

Three weeks pass. Then five. The champion goes quiet because they're chasing internally. The quarter closes without the deal.

Nobody logs that as a compliance failure. It gets logged as "timing" or "budget." But it wasn't either.

Why this is happening now, of all times

The counterintuitive part is that this is getting worse in a year when the regulatory pressure was supposed to ease.

On 7 May 2026, EU lawmakers reached political agreement on the Digital Omnibus on AI, which pushed back the AI Act's most demanding deadlines. The high-risk obligations under Annex III — covering things like recruitment, credit scoring and education tools — moved from 2 August 2026 to 2 December 2027. AI embedded in regulated products under Annex I moved to 2 August 2028.

The trade press read that as breathing room. A lot of B2B companies quietly took it as permission to stop preparing.

That's the mistake. The deadline moved. The questionnaire didn't.

Three reasons your buyers are still asking

1. Plenty of the AI Act is already in force

The delay applies to the high-risk tiers, not the whole regulation. The prohibitions on unacceptable-risk practices and the AI literacy obligation have applied since February 2025. The general-purpose AI and governance provisions have applied since August 2025. Those are live, unchanged, and enforceable today.

2. Enterprise compliance programmes were built to the old calendar

Large organisations spent 2025 building AI governance frameworks aimed at an August 2026 deadline. Those frameworks are now embedded in procurement templates, vendor onboarding, and annual audit plans. A policy calendar doesn't unwind because Brussels moved a date — and no risk committee has ever been rewarded for relaxing a control early.

3. The accountability doesn't sit with the regulator, it sits with your buyer

This is the one most vendors miss. Your buyer's CISO, privacy counsel, and procurement lead are each personally accountable if your product misbehaves after signature. Regulatory timelines are almost beside the point. They're asking because they own the consequences.

A necessary caveat: I'm a growth strategist, not a lawyer. Nothing here is legal advice — if the AI Act applies to your product, get proper counsel. What I'm describing is the commercial pattern I see in deals, and what to do about it on the go-to-market side.

The go-to-market problem hiding inside the compliance problem

Most B2B companies treat this as a legal workstream. Legal will get to it before the deadline. Meanwhile the deals keep stalling, because the delay isn't happening in a courtroom — it's happening in your sales cycle.

Three things make it expensive:

The questions arrive at the worst possible moment. Late in the cycle, after the emotional high of the demo has faded, when procurement has leverage and your champion has already spent political capital.

Your champion has to answer for you, and can't. This is exactly the buyer-enablement problem I wrote about in April. The deal doesn't die in front of you. It dies in an internal review you're not invited to, defended by someone armed with nothing but your marketing site.

Slow answers read as risky answers. When a vendor takes two weeks to explain where data goes, the buyer doesn't conclude you're busy. They conclude you don't know — and that's a far more damaging inference.

What the fast-moving companies are doing

The vendors winning these reviews aren't necessarily more compliant. They're more ready. There's a difference, and it's mostly a marketing and enablement difference.

Build the AI disclosure pack before anyone asks

One document, kept current, that answers the standard questions in plain language: which models you use and who provides them, where data is processed and stored, whether customer data is used for training (and how to opt out), your subprocessor list, what human oversight exists, retention and deletion policy, and who is accountable internally. Most of this you already know. The advantage comes from having written it down before the questionnaire lands.

Know which hat you're wearing

The AI Act distinguishes between providers and deployers, with different obligations attached. Most B2B software companies are both — a provider of their own features, a deployer of someone else's models. If you can't say clearly which you are for each part of your product, you can't answer the questionnaire coherently, and incoherence is what triggers escalation.

Clear the table-stakes bar first

Before anyone asks an AI-specific question, they check the basics. SOC 2 Type II and ISO 27001 have effectively become entry requirements in mid-market and enterprise procurement — a large majority of RFPs now screen on them. If you don't have them, the AI conversation never happens, because you've already been filtered out.

Arm the champion, not just the buyer

Give your champion the internal-facing version: a short, forwardable summary written for their security and legal colleagues, not for them. This is the single highest-leverage asset in a modern B2B deal, and almost nobody builds it deliberately.

Put it in public

A trust or AI-transparency page on your website does three jobs at once: it answers the question before it's asked, it shortens the review, and — as I argued back in May — it's readable by the AI tools your buyers now use to research you. Compliance content is unusually well suited to being cited by an answer engine, because it's factual, structured, and specific.

Readiness is a sales asset now

The framing shift worth making is this. For most B2B companies, AI governance sits in a legal folder, treated as a cost centre and a deadline to be survived. That's a category error. In a market where your buyer's security review is the last real gate before signature, the speed and confidence with which you clear it is a commercial capability — one your competitors are mostly bad at.

The winning position isn't "we're compliant." It's "we can answer every question you're about to ask, today, in writing." In a stalled procurement queue, that's not a legal posture. It's a competitive advantage.

The companies that treat the 2027 delay as eighteen months of relief will meet the same questionnaire next quarter, and lose the same deals. The ones that treat it as eighteen months of head start will spend that time turning an awkward late-stage conversation into a reason to choose them.

Are your deals stalling in security review?

Let's find where your sales cycle is leaking time — and build the enablement assets that get you through the gate faster.

Book a free strategy call →