Why the vendor's answers become your evidence
Buying instead of building removes less exposure than procurement teams expect. The Act allocates obligations by role, not by authorship, and the roles turn on facts one meeting can settle: who places the system on the market, under whose name, and for what declared purpose. Those facts are cheap now and expensive to reconstruct later. The boundary is worked through on the provider and deployer roles page.
Article 50(1), 50(3) and 50(4) apply on 2 August 2026, and AI Office enforcement begins the same day, so a contract signed this week will be days old when the first transparency duties attach. The Digital Omnibus, Regulation (EU) 2026/1744, entered into force on 27 July 2026, so the amended text is settled and there is nothing left to wait for.
Note how much of the split below sits with the vendor, and how little of it you can verify without asking.
| Duty | Sits with | Applies from |
|---|---|---|
| Article 50(1) interaction disclosure, by design | Provider | 2 August 2026 |
| Article 50(2) machine-readable output marking | Provider | 2 August 2026, or 2 December 2026 if placed before 2 August 2026 |
| Article 50(3) emotion and biometric categorisation notice | Deployer | 2 August 2026 |
| Article 50(4) deepfake and public-interest text disclosure | Deployer | 2 August 2026 |
| Annex IV documentation, Article 13 instructions, Articles 9 to 15 | Provider | 2 December 2027, or 2 August 2028 for Annex I products |
| Article 4 AI literacy of staff | Provider and deployer | Applied on 2 February 2025 |
Questions 1 to 4: who is who, and what is it for
1. Are you the provider, and will you say so in the contract?
The provider develops the system and places it on the market or puts it into service under its own name or trademark, and Article 16 hangs the whole obligation set off that word. Everything else here depends on the answer. Art 3, Art 16
Good answer: yes, named legal entity, in a clause rather than a slide. Bad answer:"we are a technology partner", or a refusal to write down what they will happily say out loud.
2. Where are you established, and does the Act reach this deal?
Article 2 reaches providers placing systems on the Union market wherever they are established, and providers and deployers in third countries where the output produced by the system is used in the Union. A vendor with no EU entity is not out of scope, and neither are you. Art 2
Good answer: the establishment, plus a reasoned view on why Article 2 does or does not bite. Bad answer:"we are a US company, the AI Act is a European law".
3. What is the declared intended purpose, in words you would put to a regulator?
Intended purpose is the hinge: classification, documentation and instructions are all written against it. Under Article 25, modifying the intended purpose of any system, including a general-purpose AI system, so that it becomes high-risk turns you into the provider. Putting your own name on a high-risk system does the same, as does a substantial modification that keeps it high-risk. Art 3, Art 25
Good answer: a purpose specific enough to be wrong, and a named process for changing it. Bad answer: a marketing sentence, or a purpose so broad it covers uses nobody has assessed.
4. Have you classified this against Annex I and Annex III?
Two routes lead into high risk under Article 6: Annex I product safety legislation requiring third-party conformity assessment, and the eight Annex III use cases. If the vendor claims the Article 6(3) derogation, Article 6(4) required it to document that assessment before placing the system on the market, so either the document exists or the derogation was never properly claimed. Profiling of natural persons is an absolute bar. Art 6(3), Art 6(4)
Good answer: the Annex III point considered, the reasoning, and the Article 6(4) document. The high-risk classification page sets out both routes. Bad answer:"it is not high-risk" with nothing behind it, which is worth less than usual since the Commission missed its February 2026 deadline for Article 6 classification guidelines.
Questions 5 to 8: documentation and transparency
5. Does Annex IV technical documentation exist today, or is it planned?
Annex IV runs to nine blocks, is drawn up before the system is placed on the market, kept up to date and retained for around ten years. Article 11(2) allows a simplified form for SMEs. Where the vendor supplies a general-purpose AI model, ask instead about the Annex XI documentation and the Annex XII information for downstream providers. Art 11, Annex IV, Art 53
Good answer: it exists, here is the structure and what we share. The Annex IV page covers the nine blocks. Bad answer:"it is on the roadmap for the 2027 deadline", which treats 2 December 2027 as a date to start from when it is the date by which the file has to be finished.
6. What Article 13 instructions for use will we receive, and when?
Article 13 sits in the Articles 9 to 15 block, applying to standalone Annex III systems from 2 December 2027 and to Annex I product-embedded AI from 2 August 2028. Those dates are not permission to defer the question. Article 26(9) provides that the Article 13 information may be used to help discharge the GDPR data protection impact assessment, and Article 27 requires certain deployers of Annex III systems to run a fundamental rights impact assessment before first use. Both are your work. Art 13, Art 26(9), Art 27
Good answer: a draft you can read now, kept current through the term. Bad answer: the user manual, offered as though it were the same thing.
7. Which Article 50 limbs apply, and which are built into the product?
This one has a deadline two days out. Article 50(1) is a design duty on the provider, phrased "designed and developed in such a way that", so it belongs in the product and not in your terms of service. Article 50(5) requires the information clearly and distinguishably at the latest at the first interaction, meeting applicable accessibility requirements. Article 50(3) and 50(4) are yours whatever the vendor does. Art 50(1), Art 50(5)
Good answer: a limb-by-limb view, a demo of the disclosure inside the product, and a statement of what is left to you. The Article 50 transparency page maps the limbs. Bad answer:"you can add a banner", which is a provider asking a deployer to discharge a design duty from outside.
8. For generative output, is Article 50(2) marking implemented, and how?
Article 50(2) requires providers of systems generating synthetic audio, image, video or text to mark the output in a machine-readable format detectable as artificially generated or manipulated, using solutions that are effective, interoperable, robust and reliable as far as technically feasible. Ask which technique: signed provenance metadata such as a C2PA manifest, an invisible watermark carried in the content itself, or several layers. The Code of Practice on transparency of AI-generated content, final text published on 10 June 2026, is voluntary, expects multi-layered marking where one technique cannot meet all four criteria, and sets a watermark-detection interoperability obligation from 2 February 2027. Art 50(2)
Good answer: techniques named, evidence the marking survives your export formats and re-encoding, and the placement date that decides whether 2 August 2026 or 2 December 2026 applies. Bad answer:"we add a visible watermark", which is not machine-readable, or a bare claim to the assistive-editing exception with nothing said about why the system does not substantially alter the input data or its semantics.
Questions 9 to 12: what happens after you sign
9. What happens on a model update, and how would we hear about it?
Silent model swaps are the industry's standard operating model and the contract's standard blind spot. A substantial modification that keeps a system high-risk is an Article 25 trigger, and a change of intended purpose is another, so a decision made upstream can move your position without an email. Art 25
Good answer: a change log, advance notice of material changes, and a commitment to flag anything the vendor itself treats as a substantial modification. Bad answer:"we continuously improve the model", with no notification duty attached.
10. What does the system log, who keeps it, and can we get it out?
Record-keeping under Article 12 sits in the Articles 9 to 15 block, on the same 2 December 2027 and 2 August 2028 dates. The practical need arrives earlier than the legal one, because logs are the only way to reconstruct what a system did on a given day, and they sit on the vendor's infrastructure by default. Art 12
Good answer: what is logged, in what format, for how long, whether you can export it, and what happens at termination. Bad answer: thirty-day retention, deletion on termination, no export path.
11. How does an incident reach us, and who tells the authority?
Article 99 sets a dedicated tier of 7,500,000 euro or 1 percent of total worldwide annual turnover for supplying incorrect, incomplete or misleading information to authorities, enforceable since 2 August 2025. If a market surveillance authority designated under Article 70 asks what happened, you will be answering with facts the vendor holds. Where the vendor supplies a general-purpose model with systemic risk, Article 55 already requires it to report serious incidents, so an upstream route exists and the question is whether it reaches you. Art 55, Art 70, Art 99
Good answer: a named contact, a response time, and a duty to notify you of incidents affecting your deployment. Bad answer:"we have a status page".
12. What does the contract actually say about AI Act liability?
Most AI Act exposure is regulatory rather than contractual, and a regulator fines the entity that owes the duty, not the one that promised to cover it. An indemnity is worth having and is not a substitute for the vendor doing the work. Article 99 puts most obligations, including Article 50 and the high-risk regime, at 15,000,000 euro or 3 percent of total worldwide annual turnover, whichever is higher, with SMEs and start-ups paying the lower of the two. Art 99, Art 99(6)
Good answer: role allocation, a documentation and cooperation covenant, an indemnity that survives the liability cap for AI Act penalties attributable to the vendor, and audit rights. Bad answer: a general compliance warranty capped below the applicable penalty tier.
Nine answers that should stop the deal
- "We are not in the EU, so the Act does not apply." Article 2 reaches third-country providers and deployers where the output is used in the Union.
- "We are open source, so we are exempt." The Article 2 exclusion falls away for systems placed on the market as high-risk, for Article 5 and for Article 50, and never applies where the system is monetised.
- "It is not high-risk", with no document. Article 6(4) required that assessment in writing before market placement.
- "Technical documentation is planned." Annex IV is drawn up before market placement, not after the sale.
- "We are already certified against the high-risk regime." Article 43 conformity assessment does not apply to standalone Annex III systems until 2 December 2027, so ask what was assessed and by whom.
- "We are GDPR compliant, so we are covered." Data protection authorities enforce the GDPR, Article 70 market surveillance authorities enforce most of the AI Act. Neither discharges the other.
- "You can add the AI disclosure yourself." Article 50(1) is a design duty on the provider.
- "The marking deadline moved to December." Only for generative systems placed on the EU market before 2 August 2026. Anything placed on or after that date owes marking from placement.
- "Happy to white-label it." Putting your name on a high-risk system is an Article 25 trigger that hands you the Article 16 obligation set.
Keep the answers, and keep them dated
The most valuable output of this exercise is not the deal, it is the file. Write down each answer with the date it was given and who gave it, and keep it with the contract. A dated record of what you asked, what you were told and what you concluded is the cheapest evidence a deployer will ever produce.
It also protects you in the direction people forget. Answering an authority from memory exposes you to the Article 99 tier for supplying incorrect, incomplete or misleading information. Answering from a dated file is a different conversation. The same file feeds the Article 4 AI literacy duty, which has applied since 2 February 2025.
Ask all twelve in one document, so the answers arrive as a set and the gaps are visible. Send it before commercial terms are agreed, because leverage disappears at signature. Re-run questions 3, 7, 9 and 10 at renewal, since intended purpose, transparency, model changes and log retention are the four that drift.
Where the answers leave you unsure which obligations attach at all, the free triage classifier walks the Article 6 and Article 50 tests in order and names the article each result rests on, and the timeline as amended sets out the dates your contract will have to survive.