The US Tech Stack Trap
Auditing AI Vendors in a Patchwork Compliance Environment
US private AI investment crossed one hundred billion dollars in 2024. That figure is not just a market statistic. It is the headline number of a supply chain problem that enterprise buyers are only beginning to come to terms with.
Here is the structural reality facing any organisation that procures AI in the United States today. At the federal level, the Trump administration’s July 2025 AI Action Plan reflects a philosophy of deliberate restraint: accelerate innovation, build infrastructure, lead internationally, and keep the regulatory hand light. Washington’s posture is clear. American AI companies should be free to compete, export and scale without the friction that characterises European conformity assessment or pre-market approval regimes.
State legislatures have taken note of that and moved in the opposite direction. All fifty states have introduced AI-related legislation. Forty-five have enacted or are advancing bills covering algorithmic discrimination, employment AI, deepfakes, biometric data and high-risk automated decision making. California, Colorado, Texas, New York and Illinois have each produced frameworks with distinct definitions, compliance timelines and enforcement mechanisms. None of them align neatly with each other, and none of them align with federal policy.
Enterprise buyers are caught in the middle. Washington is pushing what its AI Action Plan calls a full-stack American AI export agenda, encouraging procurement of domestic AI systems and treating regulatory friction as a competitive disadvantage. Meanwhile, the state laws that govern how those AI systems can actually be deployed are multiplying and tightening. The compliance environment is not a single market. It is a contest between two governance impulses operating simultaneously at different levels of the constitutional order.
This creates a problem that traditional software procurement is not designed to solve.
The limits of conventional vendor due diligence
Standard technology procurement operates on a familiar logic. You review the vendor’s security profile, negotiate service-level agreements, assess their financial stability and satisfy yourself that their data handling meets your internal standards. The deliverable is a contract that allocates risk clearly and gives you remedies if the product fails.
Foundation model procurement does not work this way. When you deploy a third-party AI system, you are not simply licensing software whose behaviour is deterministic and whose provenance is largely irrelevant. You are absorbing a complex legal supply chain. The model’s weights encode decisions that were made months or years before you signed anything: decisions about which data to train on, how to handle protected characteristics, whether synthetic data was used to fill gaps, and how bias in the source material propagated into the model’s outputs.
If those decisions were wrong, or if they violated the legal standards that now apply under expanding state frameworks and federal enforcement theories, the enterprise deploying the system inherits the exposure. California’s Assembly Bill 2013, which came into force on 1 January 2026, requires AI developers to publish training data transparency documentation. Colorado’s AI Act imposes algorithmic impact assessment obligations on deployers of high-risk systems and a ninety-day disclosure clock to the Attorney General in the event of a material algorithmic failure. Texas’s Responsible AI Governance Act, known as TRAIGA, formally structures the AI supply chain into three tiers of accountability, with distinct duties attaching to each.
The deployer, which in most enterprise procurement scenarios means your organisation, sits in the middle of that structure. You did not build the model, but you are the one making consequential decisions with it, and the law increasingly treats that as the moment of accountability.
What Bartz v. Anthropic changes
The June 2025 federal court decision in Bartz v. Anthropic drew a line that vendor marketing materials cannot cross over. The court’s analysis under fair use doctrine distinguished between lawfully acquired training data and shadow library or pirated datasets in ways that have direct consequences for enterprise buyers.
The significance is this: if a vendor cannot demonstrate the lawful provenance of its training data, the copyright exposure from that model does not stay with the developer. It travels downstream into every commercial deployment. Your organisation’s use of a model trained on unlicensed material is not insulated by the fact that someone else did the training. The vendor sheet that says the model was trained on high quality, curated data is not a legal shield. It is a marketing claim, and courts are now in the business of testing those claims against facts.
We know what the statutes say on paper, but how do you actually audit a third-party AI vendor when their underlying model weights and training datasets are guarded as proprietary trade secrets? Below, in this briefing, I set out the five-stage framework compliance teams should mandate before signing an enterprise AI vendor agreement.
AI Without an AI Act
The executive orders, state laws, and agency enforcement frameworks detailed in today’s briefing are drawn from my forthcoming book, AI Without an AI Act: A Practitioner’s Guide to United States Artificial Intelligence Governance (First Edition).
Written for compliance officers, in-house counsel and enterprise risk leads, it maps the distributed legal infrastructure of the world’s most consequential AI market from first principles.
Official release: 19 August 2026.
Secure your copy on Amazon
The next section sets out a practical five-stage audit process for assessing third-party AI vendors under the emerging patchwork of United States AI regulation.
It covers accountability mapping, training data provenance, contractual safeguards, impact assessments, and ongoing governance obligations.
Available to paid subscribers of The Responsible AI Review.



