DEV Community

Rajiv Iyer
Rajiv Iyer

Posted on

UK-only QMS shops with EU customers: does the AI Act's chatbot disclosure duty reach you?

I spent a couple of hours last month trying to get a straight answer on this, and ended up with partial references, a forum thread from 2023, and a vendor FAQ that said "contact your legal counsel." That's not quite satisfying when you're the one signing off on a QMS tool's feature rollout.

So let me lay out the question as cleanly as I can, because I think there are a few UK-based QMS managers and supplier-quality leads who are sitting on the same ambiguity.

The setup

Your organisation is UK-only. You develop or manufacture a Class I or IIa medical device, or you sit on the supplier side like I do. You use a QMS platform — it might be qmsWrapper, it might be something else — and that platform has recently added an AI chatbot feature. Your EU customers can use it to ask questions about CAPA status, document revisions, change controls.

Article 50 of the EU AI Act requires providers and deployers of AI systems that interact with natural persons to disclose — clearly and beforehand — that they are interacting with an AI system, unless this is obvious from the circumstances.

The EU entity in this scenario is your customer. They're the one who "placed it on the market" in EU terms, or at least the one who deployed it for EU users. The disclosure duty sits with them, right?

Maybe. But there are at least two reasons this isn't fully settled in practice.

The deployer question

The EU AI Act's obligations don't only fall on the provider who builds the AI system. They also attach to deployers — essentially, the entities that use the AI system in their own operations or offer it to end users.

If your QMS tool is hosted by you, and your EU customers access it, you may be the deployer in the eyes of the Regulation. The AI system isn't being placed on the market by your EU customer — it's being placed in front of them by you. The extraterritorial logic of the AI Act does reach non-EU providers if they're making an AI system available to EU users.

This matters because the Article 50 disclosure isn't just a nice-to-have. For certain AI system categories under Annex VIII, it's a conformity assessment prerequisite. Even for lower-risk systems, it's an obligation.

The vendor-of-a-vendor layer

The complication I keep running into is this: if you didn't build the AI chatbot — if your QMS vendor embedded a third-party model — then you're already two steps removed from the conformity assessment chain.

In a CMO context, we deal with this kind of thing all the time. You audit your supplier's supplier, and eventually you find a gap that no one owns. The AI Act's provider-deployer chain has a similar feel. Your QMS vendor might tell you the AI feature is "GDPR compliant" or "built responsibly," but that doesn't tell you whether they've mapped the Article 50 disclosure obligation upstream or whether they've assumed you're handling it.

What the UK picture adds

The UK hasn't implemented the EU AI Act. The current government has signalled intent to develop a UK AI regulatory framework, but it's not in force. For UK-only operations, there's no domestic equivalent disclosure requirement that I'm aware of.

This creates an odd asymmetry: you're probably not thinking about Article 50 for your own users, because nothing in UK law requires it yet. But the moment one of your EU customers asks you to confirm that your tool meets AI Act requirements — perhaps as part of their own conformity assessment — you're suddenly on the hook for an answer you may not have prepared.

Where I've landed for now

I've asked our team to flag any AI feature in our QMS stack that touches EU users, and to request documentation from the vendor on where the Article 50 disclosure is implemented and who the responsible provider is. That's a low-effort first step.

For my own qmsWrapper context: it's built primarily for device makers and the toolchain they manage, and I think the AI feature set is still maturing. If you're evaluating it as a CMO-side supplier quality tool and you're also serving EU customers, I'd want to have a direct conversation with their team about where the AI disclosure obligations land in your deployment model.

I'd stop short of claiming I've solved this. I haven't. And I suspect the answer depends heavily on contract structure, data residency, and how the AI system is actually deployed — none of which are universal.

So here's the question I'm still sitting with, and I'd genuinely like to hear how others have navigated it: if you're a UK entity and your QMS tool has EU users accessing an AI feature, what's the minimal due diligence your organisation should be able to point to before the next notified-body review lands on your desk — and whose responsibility is it to define that standard?

I lead QA at a CMO and work on qmsWrapper. This is my honest read on a genuinely unresolved question, and I'm not your legal counsel.

Top comments (0)