The Quiet Shift: When Product Data Became a Legal Necessity
A few months ago, I was reading a set of proposed AI agent use cases from a manufacturer/distributor client. Three agents, three different audiences. Halfway through the document I stopped and said we need to have legal on the next call.
The three audiences told the story. One agent was meant to put detailed product information in front of internal sales reps fielding technical questions from licensed intermediaries. A second was for those intermediaries directly – where some of what the internal reps could see was not information the company could surface outside its own walls. A third was a consumer-facing product finder, where the company was no longer speaking through a licensed intermediary at all, and the rules shifted again.
Same product. Same SKU. Same underlying compliance data. Three different versions of the truth depending on who was asking.
In twenty-plus years of commerce & content work, I can count on one hand the number of times legal has joined a scoping call. It is happening now because the product content being published is no longer just marketing copy. It is the company’s public position on what it’s legally selling, to whom, and under what conditions. AI is making that position addressable in ways most companies have not built the governance for yet – and that’s something many organizations haven’t prepared for.
What Has Actually Changed
Product compliance is not new. Safety Data Sheets have been required under OSHA HazCom since 1983. Certificates of Analysis, UL listings, Lacey Act chain-of-custody records, and country-of-origin markings have been part of a distributor’s job for decades. The job has not changed. The surface on which it is performed has.
Four things shifted at roughly the same time – and they reinforced each other in ways nobody quite planned for.
The buying journey moved online. Over 80% of B2B buyers now start on a supplier’s website or a search engine, not a phone call. The product page is often the only thing the buyer sees before committing. A compliance field that used to live on a physical label – read when the box arrived – now has to live on the page the customer reads before the box is ordered.
The expectation shifted from “have the document” to “publish the structured data.” Ten years ago, a buyer asking for an SDS or an Environmental Product Declaration got a PDF by email. Today, that same buyer’s procurement system expects to filter a catalog by “products with verified EPDs under LEED v5” or “products compliant with California’s packaging program.” Having the document no longer satisfies the requirement. The attribute has to be published in a structured form that filters, APIs, and procurement integrations can actually read.
Something quieter happened at the same time. AI systems – LLM search, agentic buyers, marketplace integrations, AI procurement assistants – started consuming product attributes as authoritative truth and passing them to buyers as fact. The sales rep who used to catch a stale attribute on a phone call is no longer in the loop. A wrong field fails silently, at machine speed, with no one to intercept it.
Regulatory velocity picked up sharply. New rules have arrived in near-simultaneous waves over the last two years, and they have not slowed. Section 232 tariffs on steel and aluminum were restructured four times between February 2025 and April 2026 – each change altering which attributes a single SKU must carry to be priced correctly at the border. That is not an edge case. It is the new baseline.
A Partial View of the Regulatory Wave
The shift is not limited to one segment. Across distribution, the attributes each SKU must now carry have grown in ways we see in every audit we run:
- HVAC: A2L refrigerant classifications took effect for manufacture and import on January 1, 2025, adding safety classification, flammability labeling, and regional eligibility flags to every product. SEER2 standards and Inflation Reduction Act rebate tiers added more attribute layers on top.
- Building products: State-level Buy Clean policies now apply in thirteen states. Paired with LEED v4.1 and v5 credit structures, Environmental Product Declarations have moved from marketing materials into procurement requirements on public works projects.
- Europe-bound goods: The EU Ecodesign for Sustainable Products Regulation launches its Digital Product Passport registry on July 19, 2026, with phased implementation through 2030 covering batteries, iron and steel, textiles, and more.
- Packaging: California SB 54 requires all single-use packaging sold in the state to be recyclable or compostable by 2032. Producer registration opened in September 2025; the Extended Producer Responsibility program goes live in January 2027.
And then there are the tariff-related changes, which carry their own complexity entirely.
- Metals: Section 232 tariffs on steel, aluminum, and copper now sit at 50% with country exemptions eliminated. An August 2025 expansion added 407 derivative product codes; an April 2026 overhaul applies tariffs to the full customs value rather than just the metal content. Every affected SKU needs a current HTS classification and a verifiable country of melt and pour or smelt and cast.
- Softwood lumber: Combined antidumping, countervailing, and Section 232 duties on Canadian softwood reach approximately 45% for many products, making origin and HTS data a pricing-accuracy requirement, not a back-office afterthought.
Any one of these is manageable in isolation. All of them at once, published through digital channels that buyers and AI systems treat as authoritative, is not.
Three Challenges Hiding in Plain Sight
Three things keep showing up – and they do not vary much by vertical, by company size, or by how sophisticated the technology stack already is. None of them are primarily about tooling.
The source documents are a mess, and they move. The compliance data exists – in product specification guides, certification databases, supplier emails, test reports, and manufacturer PDFs. But it rarely exists in one place or in a consistent format, and almost never in a form that can be matched cleanly to a SKU. A product specification guide may be forty pages long and exist in regional variants. A LEED-qualifying certification may live on a third-party portal that sends updates by email.
And the documents a company does own often escape its control. Dealers, content aggregators, and third-party content networks redistribute them as independently uploaded copies. A corrected version on the manufacturer’s site does not propagate to the copy the customer is actually reading. Version control across the ecosystem, as a discipline, does not exist in most catalogs we see.
“AI will fix it” is half the sentence. Modern AI tools can extract attributes from documents, generate descriptions, and enrich product records at impressive speed. What they cannot do is tell you whether the document they are extracting from is the current version for the SKU in front of them. That is a process question, not a model question. It requires document management, version control, SKU-to-document linking, and a review workflow that a human can defend to an auditor. This is typically not the focus of an AI enrichment pilot, and it is rarely how those pilots are sold internally either. The extraction ships. The structural problem stays.
We saw this play out with a client recently – a manufacturer/distributor in a vertical where compliance data is not optional. They had a small team of experts with a narrow but deep focus. They had put real effort into classifying, tracking, and building a taxonomy around their product data. As we worked with them, they decided to cast a wider net and look across the organization for any document that might contain relevant product information. The initial scope had assumed 50,000 to 60,000 documents at most. What they came back with was orders of magnitude larger – millions of documents, sitting in shared drives, inboxes, legacy systems, and team folders nobody had touched in years.
Volume had become the problem. So had scale. So had the assumption that AI could simply process its way through whatever was handed to it.
We asked them one question: have you thought about how you will confirm whether any of these documents actually contain relevant information? The call went quiet for a few seconds. That question forced a different conversation – not about AI, and not about tooling, but about what actually mattered to them and why. What is the source of truth here? What is a duplicate? What is a repackaged marketing asset with no bearing on the compliance record? What is noise, and what is signal?
They worked through it, and the document set came back down into the manageable range – but now with a clear understanding of which data was required, which was supporting, and which was noise. The CEO still got the “we looked under every rock” story. The difference was that the rocks had been sorted.
This is the part of AI-enabled product content work that nobody is selling. But it is the part we spend the most time on with clients.
The knowledge exists, but it is not organized around the problem. The people who actually know which SKUs carry which compliance requirements are almost never centralized. They sit in category management, in marketing, in branch operations, in the product teams that have no clear organizational home, in the sales directors who can tell you which manufacturers will email an updated Safety Data Sheet if you ask nicely, and in the legal group whose job it is to make sure nothing published online creates liability.
None of these people have “product content” in their job title. Most of them have been holding the whole thing together quietly for years. That was manageable when compliance was a marketing caveat. It is not manageable now that product content itself is a legal necessity. The fix is to build an inclusive process around them – and most companies are still working to figure this out.
Process and guardrails are reasonable things for legal to care about. They are also reasonable things for category managers, marketers, branch operations, and sales to care about. The effort is figuring out how all of those perspectives meet in one governed place.
Where the Real Work Lives
What works, in our experience, is starting with the organizational question before the technology question. Someone needs to own product content – not as a project, but as a standing capability – at a level senior enough to push back when compliance shortcuts get proposed. That person needs a working structure around them: category management, marketing, branch or regional operations, sales, and legal as a standing participant on regulated fields rather than someone looped in after the fact.
Once that structure exists, the document side becomes addressable. Source documents have to be treated as versioned first-class data, not as attachments. Every compliance-bearing attribute needs to trace back to a specific document version with a review date and a named owner. AI belongs in the drafting and extraction steps, with human review scoped to the fields that carry real legal or financial consequences. That is how syndication becomes a control plane rather than a PDF dump – and how a company earns a defensible answer to “which version did the customer see?”
The question is not whether the compliance data exists. It usually does. The question is whether the operating model can keep it current, governed, and accurate at the pace that agentic buyers and AI procurement systems now consume it – because those systems do not call the rep to double-check.
None of this requires a platform decision on day one. It requires a coordination decision that drives the tooling choices that follow – a consensus that many organizations have not yet achieved.
The Question That Actually Matters
If an auditor or tariff officer asked you today to produce the current compliance document, with version history, tied to a specific SKU, across every channel where that SKU is published – could you do it in ten minutes?
If the answer is no, the problem is not primarily AI readiness or a platform gap. It is an organizational coordination gap between the people who know the products and the systems that publish them. The regulatory clock is not slowing down, and the AI systems reading your product data are not waiting for you to catch up.
Almost every company we work with answers the ten-minute question with a no. The companies that eventually answer yes are not the ones who started with more resources or better tooling. They are the ones who recognized that the people and the knowledge were already in the building – and spent their early effort on arranging those pieces strategically within the organization. The first move is not a platform. It is a map of who knows what, and where the handoffs need to happen so technology can accelerate and reliably optimize the process.






