Geneva AI Dialogue: Compliance Roadmap for AI Companies

Quick summary

What changed?
The Geneva Dialogue did not adopt a new binding law or create an immediate compliance deadline.

Why does it matter?
It brought governments and other stakeholders together on recurring AI governance priorities, including safety, interoperability, transparency, accountability, capacity building, and human oversight.

What should companies do?
Document where AI is used, confirm how responsibilities are allocated across contracts, and ensure customer-facing governance claims can be supported by evidence.

Most founders tune out international AI governance forums. Many compliance commentators overreact to them. Neither approach is particularly useful.

On July 6–7, 2026, the United Nations held the inaugural session of its Global Dialogue on AI Governance in Geneva. The Dialogue was established as a forum where all 193 UN Member States and other stakeholders - including companies, researchers, civil-society organizations, and international institutions - can discuss international cooperation on AI governance.

A week earlier, on July 1, the UN’s Independent International Scientific Panel on AI released its preliminary report. The Panel then presented its findings during the Geneva event, giving participants a shared scientific foundation for discussing the opportunities, risks, and impacts of AI.

The Dialogue did not create a new law. It introduced no filing deadline, enforcement mechanism, or fine for companies that take no immediate action.

Its significance is more indirect.

International forums help establish the concepts and language that may later influence technical standards, government policy, procurement frameworks, investor diligence, and contract negotiations. For AI and SaaS companies selling to enterprise customers, the practical question is therefore not:

What new law did Geneva create?

It is: What expectations should we prepare to address before they become blockers in a customer or investor review?

What the UN Scientific Panel’s Report Signals for AI Companies

The Scientific Panel was established to provide an independent, evidence-based assessment of AI capabilities, opportunities, risks, and impacts. Its 40 members serve in their personal capacities and independently of governments, companies, institutions, and the UN itself.

One of the Panel’s central concerns is that existing safeguards are struggling to keep pace with advances in AI capabilities. Its preliminary report also highlights limitations in current evaluation practices, including the continued dependence on evidence and assessments produced by AI developers themselves.

The report does not require every AI company to obtain an independent audit. It does, however, reinforce a broader governance direction: important claims about AI safety, privacy, fairness, reliability, and oversight will increasingly need to be supported by documentation and evidence.

For companies selling AI products into enterprise environments, that evidence may include:

  • A clear description of the models and vendors used by each product feature.
  • Records showing what data enters the system and how it is processed.
  • Contractual terms governing model training and product improvement.
  • Testing documentation for material performance or fairness claims.
  • Human-oversight procedures.
  • Logging and incident-response processes.
  • Records of model updates and material product changes.

A policy statement may explain what a company intends to do. Enterprise customers will also want to understand what controls actually exist and how the company verifies that they work.

From Governance Claims to Procurement Evidence

Many early AI governance programs relied heavily on self-attestation.

A vendor might state that its product was secure, privacy-preserving, unbiased, or subject to human oversight. Those statements were often accepted without extensive supporting material, particularly while buyers were still developing their AI review processes.

That environment is changing.

Sophisticated enterprise customers are building more structured AI vendor reviews. The questions vary by industry and use case, but they increasingly focus on the same factual areas:

  • Which AI models power the product?
  • Which features use those models?
  • Is customer data used for training or fine-tuning?
  • Which third-party AI and infrastructure providers are involved?
  • What happens when a model is upgraded?
  • What logs and records are maintained?
  • How are incidents identified and reported?
  • Where is human review required?
  • What claims has the vendor made about safety, accuracy, fairness, or privacy?
  • What evidence supports those claims?

The Geneva Dialogue did not create these questions. It reflects the same governance priorities that are making them more commercially important.

For founders, the lesson is straightforward: a company that can answer diligence questions clearly and consistently is less likely to delay an enterprise sale while its legal, security, product, and engineering teams reconstruct the answers.

Interoperability and Cross-Border AI Contracts

Interoperability was one of the stated themes of the Geneva Dialogue.

In this context, interoperability means improving compatibility between governance approaches rather than allowing every jurisdiction to develop entirely disconnected requirements.

That goal matters because AI companies rarely operate under only one legal framework.

A US-based SaaS company may use a third-party foundation model, serve customers in the European Union, process personal data from several countries, and sell into regulated industries. Its contracts may need to address privacy law, AI-specific obligations, security requirements, sector rules, and customer procurement standards at the same time.

The answer is not to insert every regulation into the main services agreement.

A more workable contract structure separates stable commercial terms from regulatory and technical schedules that can be updated or added when necessary. Depending on the company, product, jurisdiction, and use case, the contract suite may include:

  • A master services agreement.
  • A data processing agreement.
  • An information-security schedule.
  • An AI-specific schedule or addendum.
  • Subprocessor disclosures.
  • Sector-specific terms.
  • Documentation describing model use, oversight, and data practices.

This modular structure allows the parties to address particular regulatory or procurement requirements without reopening every commercial provision in the main agreement.

Why Enterprise Customers Push Requirements Down the AI Supply Chain

Under laws such as the EU AI Act, legal responsibilities depend on a party’s role and activities.

A company may qualify as a provider, deployer, importer, distributor, authorised representative, or another regulated actor. A software vendor is not automatically a “provider,” and a customer is not subject to every deployer obligation merely because it uses an AI-enabled product.

The analysis depends on the system, use case, risk classification, contractual structure, branding, modifications, and how the technology is placed on the market or used.

For certain high-risk AI systems, however, deployers may have obligations involving human oversight, monitoring, recordkeeping, input data, and incident reporting. Fulfilling those obligations may require information, instructions, documentation, and technical capabilities supplied by a provider or another party in the AI supply chain.

That is one reason enterprise customers seek contractual commitments from vendors.

Depending on the arrangement, those commitments may address:

  • Access to required documentation.
  • Model and system-change notifications.
  • Recordkeeping and logging.
  • Incident cooperation.
  • Human-oversight functionality.
  • Subprocessor and foundation-model information.
  • Data-use restrictions.
  • Regulatory cooperation.
  • Allocation of responsibility for intellectual-property or output-related claims.

Companies should not assume that standard SaaS language adequately addresses these issues.

The EU AI Act entered into force on August 1, 2024, but its obligations apply in phases. Prohibited AI practices and AI-literacy provisions took effect in February 2025, while the rules for general-purpose AI models took effect in August 2025. Other provisions continue to apply in stages.

Following the EU’s 2026 agreement on implementation changes, rules for certain high-risk systems are expected to apply from December 2, 2027, while rules for AI systems integrated into products covered by specified EU product-safety legislation are expected from August 2, 2028. The European Commission’s AI Act materials should therefore be checked when determining which obligations apply to a particular company and system.

Three Steps to Strengthen Your AI Compliance Roadmap

The Geneva Dialogue is not a reason to panic. It is a reason to organise information that will be difficult and expensive to reconstruct during a live enterprise deal or regulatory review.

These steps are not a substitute for a jurisdiction- and use-case-specific legal analysis. They provide the factual foundation that such an analysis requires.

1. Build an AI Use Inventory

Create a clear map of where AI appears across the business.

The inventory should cover customer-facing products as well as internal tools used in areas such as hiring, marketing, customer support, software development, fraud detection, analytics, or decision-making.

At a minimum, record:

  • System and purpose: What does the system do?
  • Owner: Which team is responsible for it?
  • Model source: Is it proprietary, open source, or supplied through a third-party API?
  • AI vendor: Which external provider is involved?
  • Data inputs: What information enters the system?
  • Personal or sensitive data: Does the system process protected information?
  • Training and fine-tuning: Is customer or company data used to train or improve a model?
  • Outputs: What decisions, recommendations, or content does the system produce?
  • Human oversight: Who reviews or can override the output?
  • Logging: What records are created and retained?
  • Material risks: What could go wrong, and who could be affected?
  • Potential legal classification: Which legal roles and risk categories may apply?

The objective is not to produce a 50-page policy. It is to make sure the company can accurately answer a basic question:

What AI systems do you use, and how are they governed?

Companies looking for a structured starting point can also use the voluntary NIST AI Risk Management Framework, which organises AI risk-management activities around four functions: govern, map, measure, and manage.

2. Review Contracts for AI-Specific Gaps

Review the company’s customer agreements, data-processing terms, vendor contracts, subprocessors, and AI-provider terms together.

Pay particular attention to:

  • Whether customer data may be used for training or product improvement.
  • Whether customer commitments match the terms offered by upstream AI providers.
  • Whether subcontractors and subprocessors are properly disclosed.
  • Who is responsible for evaluating outputs before they are used.
  • Whether the contract promises a level of accuracy, fairness, safety, or compliance the company cannot substantiate.
  • How model or vendor changes are communicated.
  • What happens when an AI-related incident occurs.
  • Whether liability provisions address output errors, intellectual-property claims, data leakage, and prohibited uses.
  • Whether customers receive the documentation needed for their own compliance obligations.

The most dangerous gap is often not a missing clause. It is a mismatch between what the company promises customers and what its technology or upstream vendors actually provide.

3. Match Governance Claims to Evidence

Review the company’s:

  • Privacy policy.
  • Security whitepaper.
  • Product documentation.
  • AI policy.
  • Sales materials.
  • Procurement responses.
  • Investor materials.
  • Terms of service.
  • Customer-facing FAQs.

For each material statement, ask:

What evidence would we provide if a customer, regulator, or investor challenged this claim?

Examples include:

  • If the company says customer data is not used for training, do its internal practices and upstream contracts support that statement?
  • If it promises human review, is human review actually required and documented?
  • If it claims its system is unbiased or fair, what testing supports that claim?
  • If it says data is encrypted, does that description cover the relevant data flows and vendors?
  • If it says the system is monitored, what is monitored, by whom, and how frequently?
  • If it claims compliance with a legal framework, has the product and use case actually been assessed under that framework?

The goal is not to make every public document highly technical. It is to ensure that public claims, contractual commitments, and operational reality are aligned.

Preparing for an enterprise AI diligence review?

General Legal can review your AI inventory, customer-facing documentation, vendor terms, and contract templates before they reach procurement. Speak with our team →

What the Geneva Dialogue Does and Does Not Change

The Geneva Dialogue created a recurring international forum for AI governance cooperation. It did not create a new compliance deadline for private companies.

Its immediate legal effect is therefore limited.

Its strategic relevance is that it reinforces a set of governance priorities already appearing across regulation, standards, procurement frameworks, and enterprise diligence:

  • Documented AI use.
  • Clear allocation of responsibility.
  • Transparency about models and data.
  • Meaningful human oversight.
  • Evidence supporting safety and governance claims.
  • Better compatibility between governance approaches.

Companies do not need to rewrite their entire compliance program because of a two-day UN event.

They should use the event as a reason to test whether they can answer the questions enterprise customers, investors, regulators, and business partners are increasingly likely to ask.

The companies that prepare those answers before a deal reaches procurement will be in a better position than those trying to reconstruct their AI governance practices under deadline pressure.

General Legal helps AI and SaaS companies map AI use, update customer and vendor contracts, review governance claims, and prepare the documentation requested in enterprise diligence.

Request an AI contract and documentation review →

This briefing is for general informational purposes only and does not constitute legal advice. Legal requirements depend on the relevant jurisdiction, system, use case, risk classification, and the role of each party. For advice specific to your organization, contact your General Legal attorney.