RAIDS AI on why an AI label means nothing without a record

Nik Kairinos says chatbots now say they are chatbots, but the machine-readable marking the EU AI Act actually asks for is where firms fall short.

Digital file passing between platforms with its AI provenance marker fading away

Article 50 of the EU AI Act, the transparency obligation, has applied since 2 August. People have to be told when they are dealing with an AI system, and AI-generated or AI-manipulated content has to be marked as such.

Nik Kairinos, chief executive and co-founder of RAIDS AI, answered questions from The Datatech Times in writing on what has actually changed since. RAIDS AI sells behavioural monitoring for AI systems, so his argument that disclosure is only the beginning is also his product's argument, and the questions were written with that in mind.

His account of the first weeks is unflattering but specific. “Most of what has changed is at the surface,” he said. “Chatbots say they are chatbots, and a lot of content now carries a line saying AI was involved somewhere in the making of it.”

The harder obligation, and the one he says most organisations have not met, is the machine-readable marking of synthetic content. The technical problem is durability. “Watermarks and provenance metadata survive badly once a file is cropped, re-encoded or passed through someone else's platform, so a marker that was present when the content was created is often gone by the time anyone sees it.”

That gives him a test for telling a real disclosure from a footer. “If a company can show which system produced a piece of content, when and under what settings, the label means something. If it cannot, the label is a statement of intent. Most of what I see today is the second.”

Where disclosure is hardest, on his account, is where the AI is not the company's own. Third-party models, vendor features switched on quietly and multi-step agent chains all produce the same problem: “you cannot disclose what you cannot see”, and few organisations hold a reliable inventory of where AI is running inside their operations. Live settings make it worse. In voice calls and customer service, he said, commercial pressure pushes firms to shorten disclosures until they stop telling the customer anything.

Readiness by sector tracks existing regulatory habit rather than technical sophistication. Financial services and pharmaceuticals are furthest along, because their regulators already demand evidence and documentation and AI disclosure becomes one more item in a compliance system that exists. “Recruitment, marketing and publishing are the furthest behind, since AI adoption in these fields happened quickly and with little oversight.” The public sector sits between the two: the intent is there, but slow procurement means much of the AI already in use arrived bundled inside software bought years before anyone was thinking about disclosure.

The argument he wants to make is that transparency is a feature of oversight rather than a substitute for it, and that pre-launch testing has the same limitation. His answer to what meaningful post-deployment oversight looks like is narrower than the question invited: a continuous audit trail, audited monitoring, and the ability to identify and report incidents. “These incidents are going to happen, no matter how thorough the pre-launch testing is,” he said. “A successful deployment is one where the organisation responsible can provide proof on an ongoing basis that their system is behaving as intended and that all deviations are detected quickly.”

On the delayed timetable for high-risk systems, Kairinos was blunter than he was precise. The categories he judges most exposed are the ones where an AI decision reaches a person's rights directly: biometrics, credit, employment and justice. “So many systems are currently live in real operational environments that these are not hypothetical risks or consequences,” he said. “Delaying the timetable for high-risk systems is more than just a bureaucratic decision designed to give organisations a little breathing space, it's a gamble being played with people's wellbeing.”

Asked what monitoring for bias, hallucination, drift and unintended behaviour actually costs in data, tooling and people, his answer starts with a baseline. A monitoring system needs full visibility of how the model is used in the real world and a description of what expected behaviour looks like. “In short, they need to know what rogue activity looks like and have the means to spot it when it happens.” The output that matters is a live audit trail that logs behaviour so an issue can be traced once it is reported. His caveat is the one that decides whether any of it works: “the strength of your monitoring systems is irrelevant if they don't have full access to the AI's output, as most deviations and failures become near impossible to investigate if you can't prove what the model did once it went live.”

The distinction he draws between a firm doing this seriously and one that has written a policy is between a document and a practice. “An AI policy is a good foundation for a successful deployment, but it can't reflect the complexity and volatility of live AI use,” he said. What he would expect to find inside a serious organisation is knowledge of where AI is running, a named owner for each system, and a defined response when something goes wrong.

The commercial question is what persuades a board to spend if the compliance deadline keeps moving. Kairinos put the regulatory driver second. A system that produces a discriminatory outcome, exposes sensitive data, misleads a customer or takes an action nobody can explain creates consequences whether or not a deadline has passed. The argument he thinks is landing is a sales one: “procurement teams are making AI governance a key part of their purchasing process”, so being able to evidence a monitored deployment is becoming a condition of selling.

Kairinos has worked in AI and deep learning for more than 40 years, and his reading of what is different now is about the gap between the pace of the technology and the pace of the law. Progress was slow enough for most of the last two decades that fixed regulation could keep up. “They aren't trying to regulate the AI of today, they're trying to regulate what AI might become in just a matter of years, or even months,” he said of regulators, adding that what strikes him is their hesitancy in the face of deployment at scale.

On the next dates, he named 2 December 2026 as a transitional deadline for providers whose systems were already on the market before 2 August, and pointed further out to 2 December 2027 and 2 August 2028 for high-risk systems under Annex III and for high-risk systems embedded in regulated products. Those dates are his, and the desk has not stood them up against the regulation. His argument is that working to them is the wrong posture in any case. “AI vendors have a responsibility to ensure that their products are safe and to be able to prove it.”