EU AI ACT · OPERATING ENVIRONMENTKnow what applies · prove why · preserve change? LEARN THIS PAGE
EU AI ACT · AI VENDORS · PROCUREMENT · DUE DILIGENCE

DON’T BUY AN AI SYSTEM
WITHOUT BUYING THE EVIDENCE WITH IT.

AI procurement is now a governance event. A vendor can sell software, but the buyer still needs enough durable evidence to classify the system, understand who holds which role, implement the required controls, detect when the system changes, and prove why continued use remains justified.

BOUNDARYThis page is educational and operational guidance. It is not legal advice, certification, conformity assessment or regulatory approval.
CURRENT SOURCE ANCHOR

EUR-Lex · Regulation (EU) 2024/1689 · Articles 23–26 and AI Value-Chain Responsibilities

The AI Act assigns distinct duties to importers, distributors and deployers of high-risk AI systems, and Article 25 can shift provider obligations to another actor after rebranding, substantial modification or a changed intended purpose. GPAI providers also have documentation duties toward downstream AI-system providers.

OPEN OFFICIAL EU SOURCE ↗
WHAT BUSINESSES NEED TO ESTABLISH

Do not start with a generic checklist.

Start with the actual system, role, use case and evidence boundary. The same regulation can produce different obligations for different actors and systems.

01

WHO IS THE PROVIDER, DEPLOYER, IMPORTER OR DISTRIBUTOR?

Vendor due diligence starts with role clarity. EU AI Act duties differ across providers, deployers, importers and distributors, and contractual labels do not necessarily override the role created by the actual facts.

02

COULD A BUYER BECOME THE PROVIDER?

Article 25 can shift provider obligations to a distributor, importer, deployer or other third party that rebrands a high-risk system, makes a substantial modification, or changes its intended purpose so it becomes high-risk.

03

CAN THE VENDOR SUPPLY THE EVIDENCE THE BUYER NEEDS?

For high-risk AI, procurement should capture the documentation, instructions, conformity materials, performance limits, logging capabilities, human-oversight design, known risks, incident pathways and change information needed for lawful deployment.

04

WILL THE EVIDENCE SURVIVE A VENDOR OR MODEL CHANGE?

A new model, subprocessor, training source, API version, intended purpose, control threshold or product release can invalidate the prior due-diligence record. Contracts and operating procedures should preserve notification and revalidation pathways.

THE TA-14 OPERATING ROUTE

Turn the question into a governed record.

The goal is not merely to reach an answer. It is to preserve what facts, evidence, scope and limitations supported that answer at that time.

01

Identify the exact AI system and each operator role

Do not procure “AI” generically. Record the system, model dependencies, intended purpose, deployment context, seller, provider, importer, distributor, deployer and any downstream or upstream actor whose evidence matters.

02

Request obligation-linked evidence—not a generic security packet

Map the system’s likely obligations to specific evidence: classification basis, instructions, technical documentation, conformity information, logs, oversight controls, risk information, Article 50 disclosures where relevant, and GPAI documentation where a model sits upstream.

03

Allocate responsibilities and change duties in writing

Preserve who must provide what evidence, who owns incident escalation, who may modify the system, what changes require notice, what support is required for audits or authority requests, and what happens if evidence becomes stale or unavailable.

04

Revalidate before renewal, expansion or material change

Treat a major release, new use case, new jurisdiction, changed model, substantial modification, new data flow or changed intended purpose as a trigger to revisit the role, classification and evidence state.

READY TO OPERATE · START PAID ACCESS NOW

Choose the smallest operating tier that fits the portfolio today. Upgrade when system count, team size or governance scope actually requires it.

1–3 AI systems

Evidence Passport

$19/MO

Keep a living system-level evidence record with obligations, gaps, versions and revalidation state.

START EVIDENCE PASSPORT
Up to 10 AI systems

Compliance Workspace

$49/MO

Coordinate evidence, owners, documentation, incidents and team compliance work in one governed workspace.

START COMPLIANCE WORKSPACE
Up to 25 AI systems

Governance Pro

$99/MO

Operate broader high-risk, GPAI, FRIA, post-market and material-change governance across a growing portfolio.

START GOVERNANCE PRO
Up to 50 AI systems

Institution

$499/MO

Run institutional governance with expanded users, authority workflows, examiner rooms and portfolio reporting.

START INSTITUTION
Need an independent human readiness examination?A governed readiness review is separate from software access and starts at $750.
REQUEST READINESS REVIEW →
START WITH ONE SYSTEM

Not ready to subscribe? Classify first.

Use the free classifier to establish the system, intended purpose, possible actor role, EU exposure and unresolved facts. When continuing evidence infrastructure is needed, paid access begins at $19 per month. Independent human readiness review remains a separate service.

COMMON QUESTIONS

Questions businesses are asking now.

Does the EU AI Act require vendor due diligence?

The Act does not create one universal procurement checklist, but its role-based obligations make vendor evidence critical. Deployers of high-risk AI must use systems in accordance with instructions, assign competent human oversight, monitor operation, and report certain risks and serious incidents; importers and distributors also have verification and cooperation duties.

Can a customer become the provider of a high-risk AI system?

Yes. Under Article 25, a deployer or other third party can become the provider if it places its name or trademark on the system, makes a substantial modification while it remains high-risk, or changes the intended purpose so the system becomes high-risk.

What should buyers ask an AI vendor for?

At minimum, buyers should request enough information to identify the system and provider, classify the intended use, understand capabilities and limitations, implement required human oversight, preserve logs and records, manage incidents, and determine what changes require revalidation. High-risk and GPAI systems can require additional documentation.

What should AI vendors provide to downstream customers?

The exact duty depends on role and system type. High-risk system providers must supply instructions and other required conformity information. GPAI model providers must provide downstream AI-system providers with information and documentation sufficient to understand model capabilities and limitations and support downstream compliance.

Should procurement contracts include model-change notification?

Yes as an operational control, even where the Act does not prescribe one universal contract clause. Material model, system, intended-purpose or control changes can alter classification, performance assumptions or legal obligations, so notification and revalidation rights are important evidence-governance mechanisms.

Does TA-14 certify an AI vendor or procurement decision as compliant?

No. TA-14 can preserve role analysis, due-diligence evidence, supplier claims, gaps, contract-control state, changes and revalidation history. It does not provide legal advice, certification, conformity assessment or regulatory approval.

EU AI ACT WORLD · TA-14 AUTHORITY GOVERNANCE INSTITUTION

Understand the requirement. Preserve the evidence. Revalidate when reality changes.

TA-14 Exchange Activity

Public network activity

Live cumulative activity recorded across the public Exchange surface.

Refreshing public totals

···

Visitors

Recorded public visitors

···

Page Views

Recorded Exchange views