All articles
EU AI Act
Product Management
Compliance

Your AI PM Tools Probably Don't Comply with the EU AI Act

What CPOs and DPOs need to know before legal makes it a procurement blocker.

5 min read·10 July 2026·Fredrik Göth

Your legal team just asked whether your AI-powered PM stack complies with the EU AI Act. And the honest answer — the one you can't say out loud in that meeting — is that you don't know. And neither does your vendor.

I've seen this play out in a few organizations already. The question comes from procurement or legal, usually triggered by an enterprise deal or a DPO audit. The CPO looks at their toolstack — Productboard, Aha!, Amplitude, Dovetail, whatever the company is running — and realizes they have no compliance documentation to point to. Not because they were careless. Because the vendors haven't published any.

This is the gap. And it's going to get more uncomfortable before it gets easier.

"The PM is often the last person to get credit and the first person to get blamed."

— Shreyas Doshi

Every AI feature in your PM stack is now in scope

The EU AI Act applies extraterritorially. If you are a European company using a US-based tool with AI features, that tool is within scope. Where the vendor is headquartered is irrelevant. What matters is where the deployer operates — and that is you.

Most AI-powered PM features — automated synthesis of user feedback, AI-generated roadmap suggestions, predictive usage analytics, onboarding recommendations — will qualify as limited risk AI systems at minimum under the Act's classification framework. That classification triggers concrete obligations: transparency requirements, data governance documentation, and accountability trails. These are not optional once the system is in use.

The Act places responsibility on deployers, not just providers. That word should land clearly. If you are using an AI feature inside your PM tooling, you are a deployer under the Act. Your vendor being US-based, or being a well-known brand, does not transfer that accountability away from you.

No major vendor has published compliance documentation

As of mid-2026, I am not aware of a single major PM tool vendor that has published EU AI Act compliance documentation for their AI-powered features. Not a risk classification. Not a transparency disclosure. Not a data processing addendum that addresses AI risk specifically.

This is not a minor gap. It means that if legal or procurement asks you to demonstrate due diligence on your toolstack, you currently have nothing to show them except a pricing page and a feature changelog.

Shreyas Doshi put it plainly in a post on the reality of PM accountability: "The PM is often the last person to get credit and the first person to get blamed." That dynamic applies here too. When regulators or enterprise customers start asking questions, it will not be the vendor on the hook in your organization. It will be the product leader who approved the tooling.

The voluntary compliance window is open now

The EU AI Act's voluntary AI Pact gave organizations an early compliance window before mandatory enforcement kicks in. That window is still open. CPOs who audit their toolstack now, document their decisions, and start requesting proper data processing agreements from vendors can get ahead of the mandatory deadlines — and can demonstrate that due diligence to enterprise procurement teams who are already starting to ask.

This is a genuine procurement advantage. The first company in a competitive deal that can hand over a clean AI toolstack audit and vendor DPA documentation will close faster than the one scrambling to explain what Productboard does with GPT-4 under the hood.

Three things you can do this week

These are not theoretical. They are the steps I would take immediately in any organization I am advising right now.

First, contact each vendor whose tools have AI features and request a data processing addendum that specifically addresses AI risk classification under the EU AI Act. Most will not have one ready. That response itself is information you need.

Second, check whether AI features in your stack can be scoped to EU-only data residency. Some tools have regional data controls buried in enterprise settings that most teams have never configured. Turn them on or document why they are not available.

Third, build a decision trail. The Act places accountability on deployers, which means you need to be able to show that you assessed the AI systems you deployed, understood the risk classification, and took reasonable steps to address obligations. An internal document that records what tools you use, what their AI features do, and what steps you took is a legal shield that costs almost nothing to create.

Do not wait for your vendors to solve this for you. My experience is that vendor compliance documentation will follow enterprise customer pressure, not regulatory deadlines. You need to start creating that pressure now — and while you are doing it, protect yourself.

The legal team asked the question. Now you have a place to start.

Fredrik Göth is a CPO and product leadership consultant working with product teams across Europe.

References

  • European Parliament and Council of the European Union — EU AI Act: Regulation (EU) 2024/1689 of the European Parliament and of the Council (2024)
  • European Commission — EU AI Pact: Voluntary commitments ahead of mandatory enforcement (2024)
  • Shreyas Doshi — Post on PM accountability and blame dynamics (2023)

Ready to try it yourself?

Sign up free and start connecting strategy to impact today.