Chapter 10 of 11
Vendors, Contracts, and Cross-Regulation: Making Compliance Work in the Real World
Most AI systems arrive through vendors, cloud platforms, and APIs; learn how to align contracts, procurement, and governance with the AI Act while also navigating GDPR, the Data Act, and other EU rules.
Setting the Scene: Why Vendors Matter for AI Compliance
How AI Actually Arrives
Most organizations do not build all their AI. They buy SaaS tools with embedded AI, use cloud AI platforms, or call external APIs such as foundation models or vision services.
Parallel EU Rules
When you use vendor AI, several EU regimes can apply at the same time: the AI Act, GDPR, the Data Act, the Digital Services Act, and sectoral rules like financial or medical-device regulation.
Why This Module
You will learn to map your role under the AI Act, turn legal duties into contract clauses and procurement checklists, and build a vendor management process that supports ongoing compliance.
Risk-Based Focus
The AI Act is risk-based: prohibited, high-risk, limited-risk, and minimal-risk. Vendor relationships are most complex when dealing with high-risk systems or general-purpose AI models.
Step 1: Identify Your Role in the AI Supply Chain
Know Your AI Act Role
Under the AI Act, roles include provider, deployer, importer, distributor, and product manufacturer. With vendor AI, you are almost always at least a deployer.
Quick Role Logic
Offer the system under your own name? You are likely a provider. Use it internally? You are a deployer. Bring a non-EU system into the EU market? You may be an importer or distributor.
AI Act vs GDPR Roles
Your AI Act role does not always match your GDPR role. You can be a GDPR controller but an AI Act deployer, while your vendor is a GDPR processor but an AI Act provider.
Maintain a Role Register
For each AI system, record the system name, vendor, your AI Act role, and your GDPR role. This drives what you must ask for in contracts and due diligence.
Step 2: Map Applicable EU Rules for a Vendor AI System
Check Which Laws Apply
For each vendor AI system, check: personal data (GDPR), high-risk AI (AI Act), GPAI, connection to IoT (Data Act), platform or recommender (DSA), and any sector rules.
High-Risk and GPAI
Credit scoring, recruitment, biometric ID, and access to essential services are classic high-risk AI use cases. Systems built on general-purpose AI models trigger special AI Act rules for the vendor.
Data Act and DSA
If the AI uses data from connected products or IoT services, the Data Act may grant data access and sharing rights. If it powers a platform or recommender, DSA transparency and risk rules can apply.
Build a Regulatory Map
Create a one-page map per system listing AI Act risk and roles, GDPR roles and data, Data Act relevance, DSA relevance, and sector guidelines. Use it to guide contracts and governance.
Example: Vendor AI for Recruitment (High-Risk + GDPR)
Recruitment AI Scenario
An EU company uses a cloud recruitment tool where the vendor’s AI screens CVs and ranks candidates. This is a classic high-risk AI scenario under the AI Act and also engages GDPR.
Roles and Laws
Vendor is the AI Act provider; the company is the deployer. Under GDPR, the company is usually the controller and the vendor the processor. Data Act and DSA are less central here.
AI Act Contract Points
Ask for confirmation of high-risk status, conformity assessment and CE marking, access to technical documentation, intended purpose, and vendor duties to notify about incidents or non-compliance.
GDPR and Governance Clauses
Include a DPA that covers purposes, data types, security, sub-processors, and transfers. Add audit and logging rights, periodic performance and bias reports, and a joint incident response process.
Step 3: Core AI Act Clauses to Build into Vendor Contracts
Translate AI Act into Clauses
Contracts should turn AI Act duties into clear vendor obligations, especially for high-risk and GPAI-based systems. This covers purpose, conformity, documentation, logging, and incident handling.
High-Risk System Essentials
Require a statement of intended purpose and high-risk status, proof of conformity and CE marking, detailed instructions for use, and performance metrics and limitations.
Logs, Incidents, and Changes
Vendors should keep and share relevant logs, promptly report serious incidents or investigations, and notify you before major updates that affect risk or compliance.
GPAI-Specific Points
For GPAI, ask for information on the model, confirmation of GPAI compliance, guidance for downstream use, and clauses on safety filters and misuse controls, plus suspension rights if compliance fails.
Activity: Drafting a Vendor Clause Checklist
Imagine you are in charge of procuring an AI-powered fraud detection service from a non-EU cloud vendor that will be used by an EU bank.
Regulatory map (simplified):
- AI Act: likely high-risk (credit and financial services risk assessment).
- GDPR: intensive profiling and monitoring of transactions.
- Data Act: may involve data from connected services but not physical IoT devices.
- Sectoral: financial services guidelines and DORA.
Task (write down your answers before checking the model answer):
- List 3 AI Act-related points you would definitely include in the contract.
- List 3 GDPR-related points you would include.
- List 2 sectoral or security-related points you would include.
Pause and think through this as if you were preparing a one-page checklist for your procurement team.
When you are ready, compare with the sample answer below.
Sample answer (for self-check):
- AI Act-related points:
- Vendor confirms high-risk classification and provides evidence of conformity assessment and CE marking where required.
- Vendor shares technical documentation and performance metrics suitable for the bank’s oversight duties.
- Vendor commits to incident reporting for serious malfunctions and to notifying about substantial updates or regulatory investigations.
- GDPR-related points:
- Detailed DPA, including legal bases, categories of data, international transfer safeguards, and sub-processor approvals.
- Support for data subject rights, including access and explanation for high-impact automated decisions where applicable.
- Strong security measures aligned with DORA and regular penetration testing or security audits.
- Sectoral/security-related points:
- Alignment with relevant EBA/ESMA/EIOPA guidelines on outsourcing and model risk management.
- Clear business continuity and disaster recovery provisions, including recovery time objectives and incident coordination.
Quiz: Matching Obligations to Regulations
Check your understanding of how AI Act, GDPR, and other rules interact in vendor contracts.
You are buying an AI-based customer support chatbot that handles personal data and sometimes decides whether to escalate complaints. Which combination best matches the **minimum** regulatory focus for your vendor contract?
- AI Act only, because it is an AI system; GDPR does not apply to chatbots.
- AI Act (likely limited or high-risk depending on use) plus GDPR controller–processor clauses; possibly DSA if it is integrated into a platform.
- GDPR only, because the vendor is outside the EU and the AI Act does not apply extraterritorially.
Show Answer
Answer: B) AI Act (likely limited or high-risk depending on use) plus GDPR controller–processor clauses; possibly DSA if it is integrated into a platform.
The chatbot processes personal data, so GDPR applies. Depending on how decisions affect customers, the AI Act may impose limited or high-risk obligations. If the chatbot is part of a platform or recommender, DSA may also be relevant. The AI Act can apply to non-EU vendors offering systems in the EU, so option 3 is incorrect.
Step 4: Documentation, Audit Rights, and the AI Supply Chain
Traceability Across the Chain
Regulators expect traceability across the AI supply chain. As a deployer, you depend on vendor documentation, logging, and cooperation to show compliance.
Documentation Package
Ask vendors for a system description, intended purpose, main components, performance metrics and limitations, and clear human oversight instructions for your operators.
Logs, Audits, and Sub-suppliers
Define what logs exist, how long they are kept, and when you can access them. Include rights to compliance reports or audits, and require transparency about key sub-suppliers.
Data Act Considerations
If data comes from connected products or services, contracts should clarify data access rights, respect the Data Act’s user access and sharing rules, and avoid unlawful restrictions.
Step 5: Cross-Border and Non-EU Vendor Considerations
Non-EU Vendors Still Face EU Rules
AI Act and GDPR can apply to non-EU vendors when their AI systems are used in the EU or target EU users. Cross-border status does not remove EU compliance duties.
AI Act and GDPR Reach
The AI Act applies when systems are placed on or used in the EU market. GDPR applies when vendors offer services to or monitor people in the EU, even from abroad.
Contracts and Law
Contracts pick governing law and courts, but EU public law still applies if its scope is met. Include clauses on EU representatives, regulator cooperation, and data transfer safeguards.
Risk-Based Vendor Choice
If a non-EU vendor will not align with EU rules, you may need extra technical controls, alternative vendors, or to limit the use case to lower-risk scenarios.
Step 6: Building a Vendor Management and Procurement Process
From One-Off to Process
Compliance works best as a repeatable vendor management process, not one-off contract reviews. Build AI checks into procurement and onboarding.
Key Steps in the Flow
Steps: intake and risk classification, regulatory mapping, due diligence, contracting with standard clauses, onboarding with controls, and ongoing monitoring.
Intake and Mapping
Start with a simple intake form: what the tool does, what data it uses, and who uses it. Then build a one-page Regulatory Map for non-trivial systems.
Assign Ownership and Monitor
Give each AI system an internal owner accountable for compliance. Require vendor reports and review whether your use still matches the intended purpose over time.
Key Term Review
Flip the cards to review important concepts for vendor and cross-regulation compliance.
- Provider (AI Act)
- An entity that develops an AI system or has it developed and places it on the market or puts it into service under its own name or trademark.
- Deployer (AI Act)
- An entity that uses an AI system under its authority, except when using it for personal non-professional activity.
- High-risk AI system
- An AI system listed or falling under categories in the AI Act that pose significant risks to health, safety, or fundamental rights, such as recruitment, credit scoring, or biometric identification.
- General-purpose AI (GPAI) model
- An AI model that can be used for a wide range of tasks and is not designed for a specific narrow purpose; subject to specific AI Act rules when placed on the EU market.
- Data processing agreement (DPA)
- A GDPR-required contract between controller and processor that sets out how personal data is processed, secured, and transferred.
- Regulatory Map
- A concise overview for a given AI system showing applicable laws (AI Act, GDPR, Data Act, DSA, sectoral rules), roles, and main obligations.
Key Terms
- GDPR
- EU General Data Protection Regulation governing personal data processing, including profiling and automated decision-making.
- AI Act
- EU regulation on artificial intelligence that introduces a risk-based framework and obligations for providers, deployers, and other actors in the AI value chain.
- Data Act
- EU regulation on fair access to and use of data from connected products and related services, entering main application from 2025.
- Deployer
- Under the AI Act, the entity that uses an AI system under its authority, except for personal non-professional use.
- Provider
- Under the AI Act, the entity that places an AI system on the market or puts it into service under its own name or trademark.
- High-risk AI system
- An AI system identified by the AI Act as posing significant risks to health, safety, or fundamental rights, subject to strict requirements.
- Conformity assessment
- A process to demonstrate that an AI system meets AI Act requirements, often resulting in CE marking for high-risk systems.
- Digital Services Act (DSA)
- EU regulation setting obligations for online intermediaries and platforms, including transparency for recommender systems and systemic risk management for very large platforms.
- Data processing agreement (DPA)
- A contract required by GDPR between a controller and a processor that sets out roles, purposes, security, and conditions for processing personal data.
- General-purpose AI model (GPAI)
- An AI model capable of performing a wide range of tasks, which may be subject to specific AI Act obligations when placed on or used in the EU market.