Back to blog

The AI slowdown lawsuit: your customers still need proof

By Joe Zhou ·

An enterprise customer asks what your AI can do with their data, when a person must approve its actions, and what happens if it gets something wrong.

How much of your answer can you demonstrate inside your own product?

That is the question I would put to founders watching the latest dispute between AI safety and competition law. Whatever happens between the frontier labs, your customers still need answers about the system you are selling them.

What happened—and what the lawsuit does not establish

According to CNN reporting published on 19 September, paid subscribers have brought a proposed class action against Anthropic, OpenAI, SpaceXAI and Google. They allege that coordinating a slowdown in AI development would reduce the value of their subscriptions. The reporting links the allegations to Dario Amodei’s 12 September essay and supportive public responses from Sam Altman, Elon Musk and Demis Hassabis.

These are allegations. The filing itself does not establish an unlawful agreement.

There is also more to Amodei’s proposal than a handshake between CEOs. In We Must Pace the Frontier, he proposes embedded independent evaluators and government involvement, explicitly acknowledging antitrust constraints on coordination. He distinguishes pacing development from halting model training.

Reducing that to “the labs formed a cartel” would miss both the legal uncertainty and the substance of the proposal.

For businesses building with AI, though, the practical issue is already here: a model supplier’s safety commitments do not establish how well your own product is governed.

The governance gap sits inside your product

A model provider can explain how it evaluates its models. It cannot, by itself, explain why your application lets an agent access a customer record, change an account or send a message.

Those decisions depend on your architecture, permissions, contracts and operating processes.

Consider an AI assistant that begins by drafting customer replies. A person reviews each draft before sending it. Later, the team connects it to the CRM and lets it issue refunds automatically.

The underlying model may be unchanged. The authority you have given it has changed substantially.

Who approved that change? What limits apply? How do you detect an incorrect refund? Who can stop the workflow, and how quickly?

If the answers live in separate conversations across product, engineering and sales, a customer review becomes an exercise in reconstructing decisions. That takes time from the people trying to ship the next release.

My view is that this is where practical AI governance earns its place: making those decisions explicit, testing the controls and keeping the evidence usable.

Turn customer questions into evidence

Start with the questions a buyer needs answered before trusting your product. Then identify the evidence that supports each answer.

The examples below are a practical starting point; the right controls depend on the use case and its risks.

Customer question Evidence your team should be able to produce
What data reaches the model, and can it be used for training? A current data flow, relevant supplier terms and verified service settings.
What can the AI do without a person approving it? Defined permissions, approval rules and tests showing those boundaries work.
How have you assessed harm or misuse? A use-case risk and impact assessment, named owners and recorded treatment decisions.
What happens when the model or workflow changes? Change records, relevant evaluation results and a documented release decision.
Can you investigate an incident and stop further actions? Appropriately protected logs, an escalation process and a tested way to disable the affected workflow.

A statement such as “we have human oversight” becomes much more useful when you can show exactly which actions need approval and what happens when approval is missing.

The commercial benefit is straightforward: your team can respond with a consistent answer and supporting evidence, instead of asking engineering to investigate the same question for every prospect.

Where ISO 42001 fits

ISO/IEC 42001 provides requirements for an AI management system. It applies to organisations developing, providing or using AI, and gives them a structured way to manage AI risks and improve their practices over time.

For a growing AI company, it can provide a common structure for responsibilities, risk decisions, reviews and evidence that would otherwise sit across disconnected teams.

Certification concerns the management system within its defined scope. It is not a guarantee that every AI output is correct, and it does not establish compliance with every applicable law or resolve competition-law questions.

You can also begin putting that structure in place before pursuing certification. The immediate priority is to understand your use cases, assign ownership and address the risks that matter to your product and customers.

For an agent with access to sensitive systems, that might mean restricting permissions, enforcing approval for consequential actions and testing whether those restrictions can be bypassed. The management process should make clear who owns those controls and when they are reviewed.

A useful place to start this month

Choose one AI workflow connected to an important customer requirement or upcoming release.

Bring the product owner, an engineer and whoever handles customer assurance together. Trace the data, list the actions the AI can take, identify the most consequential failures and review the controls already in place.

Then try answering the five questions above using evidence you have today.

The gaps become your first action list. Give each action an owner and a deadline. Keep the resulting evidence somewhere the next customer review can reuse it.

This gives you a concrete starting point while the wider debate about frontier AI continues.

Put someone in charge of keeping it working

For many growing teams, the difficult part is sustaining the work between product releases, customer reviews and audits.

That is where Complyd comes in. We run the compliance function for AI and technology companies, covering enterprise security reviews, AI governance and ISO 27001 and ISO 42001 readiness. Our Virtual Compliance Officer service provides ongoing ownership of the agreed programme, evidence and follow-up actions.

We helped healthcare AI company Medow Health achieve BSI ISO certification in eight weeks and now operate its compliance function. Their experience reflects the delivery model: take ownership of the work and keep it operating after the audit.

If your next enterprise review is exposing gaps in your AI answers, bring the requirement to a conversation with us. In a 25-minute strategy call, we can discuss what is driving it and whether a focused roadmap, certification programme or ongoing compliance support is the right starting point.

Book a Compliance Strategy Call →

Still working out what ISO 42001 involves? Download Complyd’s ISO 42001 checklist.

Earn enterprise trust. Keep shipping.