By Simran Sethi, Senior Industry Solutions Consultant, Global Trade Intelligence, Descartes

AI is already embedded in many organizations and is no longer a future consideration. Today AI is actively supporting trade compliance teams with classification decision from assigning HS codes to assessing whether products fall under dual-use controls.
Due to this increasing reliance on AI, a structural shift is now underway. From 2nd August 2026, the EU Artificial Intelligence Act came into enforcement. Organizations must now be able to prove how the AI made the decision, where the data came from and who (human) checked and approved the decision. This means the trade compliance teams must keep clear documentation, are transparent and that there is always human oversight to ensure decisions are backed by expertise. This shift brings a fundamental change in expectations: classification must not only be correct, but explainable, traceable, and defensible.
Key Takeaways
- Being correct is no longer sufficient, organizations must demonstrate how the decision was made.
- Classification decisions must be reproducible, including inputs, logic, and reasoning.
- Review cannot be assumed, it must be defined, applied, and documented.
- High-confidence outputs do not replace legal justification.
- AI does not transfer liability, accountability remains with the organization and classification decisions stays with the declarant and exporter.
- Competitive advantage will come from building classification processes that can withstand scrutiny at scale.
A Regulation That Changes How Decisions Are Judged
The EU AI Act introduces a single set of rules aimed at governing the development and use of AI across the Union. While people often focus on how the regulation is there to categorize AI based on risk levels. It’s actual day-to-day impact on trade compliance changes how we judge whether an AI’s decision is acceptable.
There is no denying AI speeds up processes, but trade compliance has always been about legal proof and not speed. For example, classification has always been a legal determination, so whether assigning a tariff code or assessing export control obligations the ability to justify the decision has been at the core.
AI allows companies to classify a high quantity of products in seconds but because AI decisions are made at such scale, any mistakes it make are also scaled up.
Now, the AI Act changes the standard by which they are judged. Many organizations are using AI to speed things up without building a way to explain how the AI came to that conclusion. This creates a dangerous gap where companies can’t legally defend these automated decisions if challenged.
Why This Is Not Just a European Issue
The EU AI Act is often viewed as a regional regulation but in practice, its reach is broader- much like the infamous GDPR regulations. If an AI tool creates a result and that output is used inside the EU, then that AI tool must follow the EU AI Act, no matter where in the world the company is actually based.
For trade compliance, this has direct implications. For example, a U.S. or Canadian organisation may fall within scope where:
- AI-supported classifications are used in EU customs declarations
- Goods are classified for export into the EU
- AI outputs influence regulatory determinations within the EU
At the same time, North America does not operate in a regulatory vacuum. In the U.S., existing frameworks administered by U.S. Customs and Border Protection (CBP), Bureau of Industry and Security (under the U.S. Department of Commerce) (BIS), and Office of Foreign Assets Control (under the U.S. Department of the Treasury) (OFAC) already require classification decisions to be supported by:
- documented reasoning
- auditability
- reproducibility
These expectations apply regardless of whether decisions are made manually or supported by AI. The EU AI Act isn’t creating a new concept but simply reinforcing an existing principle. The act formalizes how AI-supported decisions must be governed and evidenced.
While this comes into place in Europe, North America is also tightening its rules too. Frameworks such as the National Institute of Standards and Technology (NIST) AI Risk Management Framework, increasing regulatory scrutiny from agencies such as the Federal Trade Commission (FTC), and policy developments at the federal level all point in a consistent direction: if AI contributes to a business decision, the organisation must be able to explain and substantiate it.
In Canada, proposed legislation such as the Artificial Intelligence and Data Act (AIDA) and it focuses on the same issues, a focus on accountability, human oversight, and risk-based classification of AI systems.
The legal setups in both regions may differ but the all have the same goal. If your organisation is using AI in trade compliance then you can no longer treat AI as black box. You must have the ability to demonstrate, clearly and consistently, how decisions are made.
What This Means for North American Organizations
Regulators such as U.S. Customs Border Patrol, Bureau of Industry and Security (BIS), and Office of Foreign Assets Control (OFAC) have long expected companies to justify how determinations are made. They do not assess decisions based on how quickly they are produced, or whether they are supported by advanced technology.
For North American organizations, this creates two parallel realities:
- Direct exposure, where AI-supported classifications influence EU regulatory outcomes
- Rising indirect pressure as global standards for AI governance converge around transparency, traceability, and oversight.
AI may accelerate classification, but accountability remains anchored in the ability to reconstruct, explain, and defend how that classification was made.
Where AI Classification Breaks Down in Practice
Companies using AI for trade classification are falling into a comfortable but dangerous routine. Users leverage AI classification tools generate outputs with high confidence, those outputs are accepted into workflows with minimal friction and the process move faster than traditional review cycles ever allowed. But the underlying decision-making process is rarely captured in a way that can be revisited.
When a classification is later questioned, whether during an internal review or by an authority, the organization can see what decision was made, but not always how it was reached. There is often no structured record of:
- which product attributes drove the outcome,
- which legal rules were applied,
- or whether a human reviewer assessed the result.
The actual “thinking” process is lost. In real time, nothing appears incorrect, the issue only surfaces when the decision needs to be explained and at that point, the gap becomes clear:
- The classification exists, but the reasoning behind it does not.
Within a manual process, this would be a documentation weakness but within an AI-driven process, it becomes a systemic risk.
From Output to Evidence
The aim of the EU AI Act is not to prohibit the use of AI in trade compliance nor does it automatically classify all such systems as high-risk. At a fundamental level the act requires that where AI contributes to decisions with regulatory consequences that organizations must be able to demonstrate:
- how the system functions
- how outputs are generated
- where human oversight is applied
- and how decisions can be reconstructed after the fact
These expectations are reflected directly in the EU AI Act’s requirements on:
- technical documentation (Article 11)
- record-keeping and logging (Article 12)
- transparency and instructions for use (Article 13), and
- human oversight (Article 14)
Why Trade Classification Is Uniquely Exposed
Unlike in many use cases where AI affects individuals, for trade compliance professionals it affects legal declarations, customs filings and export control paperwork. This means that the risks go beyond just privacy but directly about financial and legal liability for the business.
The reasons why classification decisions are high stakes they are:
- legally binding,
- subject to retrospective review,
- and directly tied to organizational liability.
An incorrect tariff classification may lead to reassessment and penalties. An incorrect export control determination can escalate into a far more serious regulatory issue. In both cases, authorities will not ask whether AI was used.
If your answer cannot be demonstrated clearly and consistently, supported by documented logic and traceable system outputs, the risk sits with the organization, not the AI system.
The Illusion of Confidence
Many AI classification systems produce a confidence score alongside their output, which provides reassuring feeling to the user and makes the result feel trustworthy. However, under regulation this confidence score carries little weight as it does not provide evidence to support its output.
Under Article 15 of the EU AI Act, systems must achieve appropriate levels of accuracy, robustness, and reliability but they must also be supported by processes that allow outputs to be understood and assessed. If you cannot explain a classification, you cannot defend it, not mater what the confidence score reads.
It’s human nature, as AI tools become more embedded into daily workflows, there is a natural tendency to accept outputs without challenging them, as it all becomes routine. Especially when the AI system looks consistent and authoritative. This is why the EU AI Act aims to ensure organizations keep control over that reliance of AI rather than let the system take over decision making.
Accountability Has Not Shifted
One principle remains unchanged is that the use of AI does not transfer responsibility. The legal obligation for classification, whether in customs declarations or export control assessments, remains with the declarant and the exporting organization.
The EU AI Act does not regulate outcomes in isolation. It regulates how organizations produce and governs those outcomes. If an AI-supported classification leads to a compliance issue, the question will not be whether the tool failed. It will be whether the organization exercised appropriate oversight and whether it can demonstrate, through documentation and records as to how the decision was made.
What Needs to Change Now
Organizations that will be prepared are not those experimenting with the most advanced models. They are the ones addressing more fundamental questions:
- Can classification decisions be reconstructed in full? Including inputs, logic, and outcome?
- Is human oversight clearly defined, consistently applied, and documented in a way that aligns with the Act’s expectations?
- Can the organization explain its classification decisions in terms that would withstand regulatory scrutiny?
If the answer to any of these is uncertain, the challenge is more structural than not technological. It is structural.
A New Standard for Classification
For years, trade compliance has focused on efficiency, reducing manual effort, accelerating processes, and improving consistency, and does AI help organizations realize delivers these objectives. However, the EU AI Act introduces a new requirement: accountability at scale.
Recent regulatory guidance and industry commentary consistently point to the same conclusion, that organizations must be able to evidence and demonstrate how AI-supported decisions are made, not just show the outcomes themselves.
The organizations that will lead in this environment will not be those that automate the fastest. They will be those that build classification processes, supported by AI, that are transparent, controlled, and defensible. Because now classification extends beyond reaching the right answer to demonstrating how that answer was derived.