ISHIGHRISK AI
Analysis

What to ask an AI vendor before you sign

Twelve questions that establish whether a vendor is the provider, what documentation exists, and which obligations land on you the moment you sign.

Published Regulation (EU) 2024/1689, as amended by the Digital Omnibus
In short

The Act allocates duties by role, not by who wrote the code, so the procurement conversation is where your exposure is actually fixed. Twelve questions establish whether the vendor accepts provider status under Article 3, what intended purpose it has declared, whether Annex IV documentation exists today rather than on a roadmap, and which Article 50 limbs ship in the product rather than land on you. Article 50(1), 50(3) and 50(4) apply on 2 August 2026, so a contract signed this week spends almost its entire life inside the transparency regime. The answers, written down and dated, are the cheapest evidence a deployer will ever produce, and the cheapest moment to get them is before signature.

Why the vendor's answers become your evidence

Buying instead of building removes less exposure than procurement teams expect. The Act allocates obligations by role, not by authorship, and the roles turn on facts one meeting can settle: who places the system on the market, under whose name, and for what declared purpose. Those facts are cheap now and expensive to reconstruct later. The boundary is worked through on the provider and deployer roles page.

Article 50(1), 50(3) and 50(4) apply on 2 August 2026, and AI Office enforcement begins the same day, so a contract signed this week will be days old when the first transparency duties attach. The Digital Omnibus, Regulation (EU) 2026/1744, entered into force on 27 July 2026, so the amended text is settled and there is nothing left to wait for.

2 Aug 2026Article 50(1), 50(3) and 50(4) apply. Article 50(2) marking applies to generative systems placed on the market on or after this date. AI Office enforcement begins.
2 Dec 2026Article 50(2) marking applies to generative systems placed on the EU market before 2 August 2026, a four-month transitional period under recital 38 of Regulation (EU) 2026/1744.

Note how much of the split below sits with the vendor, and how little of it you can verify without asking.

DutySits withApplies from
Article 50(1) interaction disclosure, by designProvider2 August 2026
Article 50(2) machine-readable output markingProvider2 August 2026, or 2 December 2026 if placed before 2 August 2026
Article 50(3) emotion and biometric categorisation noticeDeployer2 August 2026
Article 50(4) deepfake and public-interest text disclosureDeployer2 August 2026
Annex IV documentation, Article 13 instructions, Articles 9 to 15Provider2 December 2027, or 2 August 2028 for Annex I products
Article 4 AI literacy of staffProvider and deployerApplied on 2 February 2025

Questions 1 to 4: who is who, and what is it for

1. Are you the provider, and will you say so in the contract?

The provider develops the system and places it on the market or puts it into service under its own name or trademark, and Article 16 hangs the whole obligation set off that word. Everything else here depends on the answer. Art 3, Art 16

Good answer: yes, named legal entity, in a clause rather than a slide. Bad answer:"we are a technology partner", or a refusal to write down what they will happily say out loud.

2. Where are you established, and does the Act reach this deal?

Article 2 reaches providers placing systems on the Union market wherever they are established, and providers and deployers in third countries where the output produced by the system is used in the Union. A vendor with no EU entity is not out of scope, and neither are you. Art 2

Good answer: the establishment, plus a reasoned view on why Article 2 does or does not bite. Bad answer:"we are a US company, the AI Act is a European law".

3. What is the declared intended purpose, in words you would put to a regulator?

Intended purpose is the hinge: classification, documentation and instructions are all written against it. Under Article 25, modifying the intended purpose of any system, including a general-purpose AI system, so that it becomes high-risk turns you into the provider. Putting your own name on a high-risk system does the same, as does a substantial modification that keeps it high-risk. Art 3, Art 25

Good answer: a purpose specific enough to be wrong, and a named process for changing it. Bad answer: a marketing sentence, or a purpose so broad it covers uses nobody has assessed.

4. Have you classified this against Annex I and Annex III?

Two routes lead into high risk under Article 6: Annex I product safety legislation requiring third-party conformity assessment, and the eight Annex III use cases. If the vendor claims the Article 6(3) derogation, Article 6(4) required it to document that assessment before placing the system on the market, so either the document exists or the derogation was never properly claimed. Profiling of natural persons is an absolute bar. Art 6(3), Art 6(4)

Good answer: the Annex III point considered, the reasoning, and the Article 6(4) document. The high-risk classification page sets out both routes. Bad answer:"it is not high-risk" with nothing behind it, which is worth less than usual since the Commission missed its February 2026 deadline for Article 6 classification guidelines.

Questions 5 to 8: documentation and transparency

5. Does Annex IV technical documentation exist today, or is it planned?

Annex IV runs to nine blocks, is drawn up before the system is placed on the market, kept up to date and retained for around ten years. Article 11(2) allows a simplified form for SMEs. Where the vendor supplies a general-purpose AI model, ask instead about the Annex XI documentation and the Annex XII information for downstream providers. Art 11, Annex IV, Art 53

Good answer: it exists, here is the structure and what we share. The Annex IV page covers the nine blocks. Bad answer:"it is on the roadmap for the 2027 deadline", which treats 2 December 2027 as a date to start from when it is the date by which the file has to be finished.

6. What Article 13 instructions for use will we receive, and when?

Article 13 sits in the Articles 9 to 15 block, applying to standalone Annex III systems from 2 December 2027 and to Annex I product-embedded AI from 2 August 2028. Those dates are not permission to defer the question. Article 26(9) provides that the Article 13 information may be used to help discharge the GDPR data protection impact assessment, and Article 27 requires certain deployers of Annex III systems to run a fundamental rights impact assessment before first use. Both are your work. Art 13, Art 26(9), Art 27

Good answer: a draft you can read now, kept current through the term. Bad answer: the user manual, offered as though it were the same thing.

7. Which Article 50 limbs apply, and which are built into the product?

This one has a deadline two days out. Article 50(1) is a design duty on the provider, phrased "designed and developed in such a way that", so it belongs in the product and not in your terms of service. Article 50(5) requires the information clearly and distinguishably at the latest at the first interaction, meeting applicable accessibility requirements. Article 50(3) and 50(4) are yours whatever the vendor does. Art 50(1), Art 50(5)

Good answer: a limb-by-limb view, a demo of the disclosure inside the product, and a statement of what is left to you. The Article 50 transparency page maps the limbs. Bad answer:"you can add a banner", which is a provider asking a deployer to discharge a design duty from outside.

8. For generative output, is Article 50(2) marking implemented, and how?

Article 50(2) requires providers of systems generating synthetic audio, image, video or text to mark the output in a machine-readable format detectable as artificially generated or manipulated, using solutions that are effective, interoperable, robust and reliable as far as technically feasible. Ask which technique: signed provenance metadata such as a C2PA manifest, an invisible watermark carried in the content itself, or several layers. The Code of Practice on transparency of AI-generated content, final text published on 10 June 2026, is voluntary, expects multi-layered marking where one technique cannot meet all four criteria, and sets a watermark-detection interoperability obligation from 2 February 2027. Art 50(2)

Good answer: techniques named, evidence the marking survives your export formats and re-encoding, and the placement date that decides whether 2 August 2026 or 2 December 2026 applies. Bad answer:"we add a visible watermark", which is not machine-readable, or a bare claim to the assistive-editing exception with nothing said about why the system does not substantially alter the input data or its semantics.

Questions 9 to 12: what happens after you sign

9. What happens on a model update, and how would we hear about it?

Silent model swaps are the industry's standard operating model and the contract's standard blind spot. A substantial modification that keeps a system high-risk is an Article 25 trigger, and a change of intended purpose is another, so a decision made upstream can move your position without an email. Art 25

Good answer: a change log, advance notice of material changes, and a commitment to flag anything the vendor itself treats as a substantial modification. Bad answer:"we continuously improve the model", with no notification duty attached.

10. What does the system log, who keeps it, and can we get it out?

Record-keeping under Article 12 sits in the Articles 9 to 15 block, on the same 2 December 2027 and 2 August 2028 dates. The practical need arrives earlier than the legal one, because logs are the only way to reconstruct what a system did on a given day, and they sit on the vendor's infrastructure by default. Art 12

Good answer: what is logged, in what format, for how long, whether you can export it, and what happens at termination. Bad answer: thirty-day retention, deletion on termination, no export path.

11. How does an incident reach us, and who tells the authority?

Article 99 sets a dedicated tier of 7,500,000 euro or 1 percent of total worldwide annual turnover for supplying incorrect, incomplete or misleading information to authorities, enforceable since 2 August 2025. If a market surveillance authority designated under Article 70 asks what happened, you will be answering with facts the vendor holds. Where the vendor supplies a general-purpose model with systemic risk, Article 55 already requires it to report serious incidents, so an upstream route exists and the question is whether it reaches you. Art 55, Art 70, Art 99

Good answer: a named contact, a response time, and a duty to notify you of incidents affecting your deployment. Bad answer:"we have a status page".

12. What does the contract actually say about AI Act liability?

Most AI Act exposure is regulatory rather than contractual, and a regulator fines the entity that owes the duty, not the one that promised to cover it. An indemnity is worth having and is not a substitute for the vendor doing the work. Article 99 puts most obligations, including Article 50 and the high-risk regime, at 15,000,000 euro or 3 percent of total worldwide annual turnover, whichever is higher, with SMEs and start-ups paying the lower of the two. Art 99, Art 99(6)

Good answer: role allocation, a documentation and cooperation covenant, an indemnity that survives the liability cap for AI Act penalties attributable to the vendor, and audit rights. Bad answer: a general compliance warranty capped below the applicable penalty tier.

Nine answers that should stop the deal

  • "We are not in the EU, so the Act does not apply." Article 2 reaches third-country providers and deployers where the output is used in the Union.
  • "We are open source, so we are exempt." The Article 2 exclusion falls away for systems placed on the market as high-risk, for Article 5 and for Article 50, and never applies where the system is monetised.
  • "It is not high-risk", with no document. Article 6(4) required that assessment in writing before market placement.
  • "Technical documentation is planned." Annex IV is drawn up before market placement, not after the sale.
  • "We are already certified against the high-risk regime." Article 43 conformity assessment does not apply to standalone Annex III systems until 2 December 2027, so ask what was assessed and by whom.
  • "We are GDPR compliant, so we are covered." Data protection authorities enforce the GDPR, Article 70 market surveillance authorities enforce most of the AI Act. Neither discharges the other.
  • "You can add the AI disclosure yourself." Article 50(1) is a design duty on the provider.
  • "The marking deadline moved to December." Only for generative systems placed on the EU market before 2 August 2026. Anything placed on or after that date owes marking from placement.
  • "Happy to white-label it." Putting your name on a high-risk system is an Article 25 trigger that hands you the Article 16 obligation set.

Keep the answers, and keep them dated

The most valuable output of this exercise is not the deal, it is the file. Write down each answer with the date it was given and who gave it, and keep it with the contract. A dated record of what you asked, what you were told and what you concluded is the cheapest evidence a deployer will ever produce.

It also protects you in the direction people forget. Answering an authority from memory exposes you to the Article 99 tier for supplying incorrect, incomplete or misleading information. Answering from a dated file is a different conversation. The same file feeds the Article 4 AI literacy duty, which has applied since 2 February 2025.

Ask all twelve in one document, so the answers arrive as a set and the gaps are visible. Send it before commercial terms are agreed, because leverage disappears at signature. Re-run questions 3, 7, 9 and 10 at renewal, since intended purpose, transparency, model changes and log retention are the four that drift.

Where the answers leave you unsure which obligations attach at all, the free triage classifier walks the Article 6 and Article 50 tests in order and names the article each result rests on, and the timeline as amended sets out the dates your contract will have to survive.

Check your own system

The free classifier walks the same tests in order and tells you which of them your system actually trips, with the article each answer rests on.

Run the triage →

Frequently asked questions

What should I ask an AI vendor about the EU AI Act?

Start with role: will the vendor confirm in the contract that it is the provider within the meaning of Article 3, and therefore carries the Article 16 obligation set. Then ask for the declared intended purpose in writing, the classification result against Annex I and Annex III, whether Annex IV technical documentation exists today, what Article 13 instructions for use you will receive, and which Article 50 transparency limbs are implemented in the product rather than left for you to add. Finish on operations: how model updates are notified, what the system logs, how incidents reach you, and what the contract says about AI Act liability. Twelve questions of that kind take one meeting and produce a dated record you can show an authority later.

Does buying an AI system make me the provider under the EU AI Act?

It can. Article 25 turns a deployer, importer or distributor into a provider in three situations: putting your own name or trademark on a high-risk system, making a substantial modification that keeps it high-risk, or modifying the intended purpose of any system, including a general-purpose AI system, so that it becomes high-risk. The consequence is the full Article 16 obligation set, inherited without any of the vendor's documentation unless your contract secured it. White-labelling and repurposing are the two triggers procurement teams hit without noticing.

Can I ask an AI vendor for their Annex IV technical documentation?

Yes, and the answer tells you a great deal. Annex IV technical documentation runs to nine blocks, has to be drawn up before the system is placed on the market, kept up to date and retained for around ten years. For standalone Annex III systems the duty attaches on 2 December 2027, which is the date by which the file has to be finished rather than the date to start it, so a vendor still calling the documentation planned is telling you where it is in the work. Article 11(2) allows a simplified form for SMEs, which is a legitimate answer, and a vendor may reasonably decline to hand over the full file while offering a structured summary and an audit right. A vendor that cannot say whether the documentation exists at all has not done the classification work either.

Does the EU AI Act apply to a US AI vendor?

Article 2 reaches providers that place AI systems on the Union market wherever they are established, and it also reaches providers and deployers established in a third country where the output produced by the system is used in the Union. So a vendor with no EU entity, no EU staff and no EU data centre can still be in scope, and its view that the Act does not apply to it is not a position you can rely on as its customer. Ask anyway, because a vendor that has thought about extraterritorial reach has usually thought about the rest.

Who is responsible for the AI chatbot disclosure, us or the vendor?

Article 50(1) is a design duty on the provider: systems intended to interact directly with natural persons must be designed and developed so that persons are informed they are interacting with an AI system, unless that is obvious to a reasonably well-informed, observant and circumspect person in the circumstances. If you deploy a chat product as shipped, that duty sits with the vendor. The deployer-side limbs are different, Article 50(3) for emotion recognition and biometric categorisation and Article 50(4) for deepfakes and public-interest text, and those sit with you whatever the vendor does. All of these limbs apply on 2 August 2026.

What AI Act clauses should be in an AI vendor contract?

At minimum: an express statement of which party is the provider and which the deployer, the declared intended purpose and a change-control process around it, a commitment to supply Article 13 instructions for use and keep them current, a notification duty for model updates and for anything the vendor treats as a substantial modification, log access and retention terms, an incident notification route with a response time, and an allocation of AI Act liability. Article 99 sets the exposure the clause is really about, up to 15,000,000 euro or 3 percent of total worldwide annual turnover for most obligations, and those penalty provisions have been enforceable since 2 August 2025. A vendor that will confirm compliance in a sales deck but not in the contract has told you what its own lawyers think.

This article is analysis, not legal advice. It reflects Regulation (EU) 2024/1689 as amended by the Digital Omnibus, Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026, as that text stood at the last site review on 4 August 2026. Final classification for ambiguous cases needs qualified counsel.