SkarpSkarp

Chapter 10 of 11

Vendors, Contracts, and Cross-Regulation: Making Compliance Work in the Real World

Most AI systems arrive through vendors, cloud platforms, and APIs; learn how to align contracts, procurement, and governance with the AI Act while also navigating GDPR, the Data Act, and other EU rules.

15 min readen

Setting the Scene: Why Vendors Matter for AI Compliance

How AI Actually Arrives

Most organizations do not build all their AI. They buy SaaS tools with embedded AI, use cloud AI platforms, or call external APIs such as foundation models or vision services.

Parallel EU Rules

When you use vendor AI, several EU regimes can apply at the same time: the AI Act, GDPR, the Data Act, the Digital Services Act, and sectoral rules like financial or medical-device regulation.

Why This Module

You will learn to map your role under the AI Act, turn legal duties into contract clauses and procurement checklists, and build a vendor management process that supports ongoing compliance.

Risk-Based Focus

The AI Act is risk-based: prohibited, high-risk, limited-risk, and minimal-risk. Vendor relationships are most complex when dealing with high-risk systems or general-purpose AI models.

Step 1: Identify Your Role in the AI Supply Chain

Know Your AI Act Role

Under the AI Act, roles include provider, deployer, importer, distributor, and product manufacturer. With vendor AI, you are almost always at least a deployer.

Quick Role Logic

Offer the system under your own name? You are likely a provider. Use it internally? You are a deployer. Bring a non-EU system into the EU market? You may be an importer or distributor.

AI Act vs GDPR Roles

Your AI Act role does not always match your GDPR role. You can be a GDPR controller but an AI Act deployer, while your vendor is a GDPR processor but an AI Act provider.

Maintain a Role Register

For each AI system, record the system name, vendor, your AI Act role, and your GDPR role. This drives what you must ask for in contracts and due diligence.

Step 2: Map Applicable EU Rules for a Vendor AI System

Check Which Laws Apply

For each vendor AI system, check: personal data (GDPR), high-risk AI (AI Act), GPAI, connection to IoT (Data Act), platform or recommender (DSA), and any sector rules.

High-Risk and GPAI

Credit scoring, recruitment, biometric ID, and access to essential services are classic high-risk AI use cases. Systems built on general-purpose AI models trigger special AI Act rules for the vendor.

Data Act and DSA

If the AI uses data from connected products or IoT services, the Data Act may grant data access and sharing rights. If it powers a platform or recommender, DSA transparency and risk rules can apply.

Build a Regulatory Map

Create a one-page map per system listing AI Act risk and roles, GDPR roles and data, Data Act relevance, DSA relevance, and sector guidelines. Use it to guide contracts and governance.

Example: Vendor AI for Recruitment (High-Risk + GDPR)

Recruitment AI Scenario

An EU company uses a cloud recruitment tool where the vendor’s AI screens CVs and ranks candidates. This is a classic high-risk AI scenario under the AI Act and also engages GDPR.

Roles and Laws

Vendor is the AI Act provider; the company is the deployer. Under GDPR, the company is usually the controller and the vendor the processor. Data Act and DSA are less central here.

AI Act Contract Points

Ask for confirmation of high-risk status, conformity assessment and CE marking, access to technical documentation, intended purpose, and vendor duties to notify about incidents or non-compliance.

GDPR and Governance Clauses

Include a DPA that covers purposes, data types, security, sub-processors, and transfers. Add audit and logging rights, periodic performance and bias reports, and a joint incident response process.

Step 3: Core AI Act Clauses to Build into Vendor Contracts

Translate AI Act into Clauses

Contracts should turn AI Act duties into clear vendor obligations, especially for high-risk and GPAI-based systems. This covers purpose, conformity, documentation, logging, and incident handling.

High-Risk System Essentials

Require a statement of intended purpose and high-risk status, proof of conformity and CE marking, detailed instructions for use, and performance metrics and limitations.

Logs, Incidents, and Changes

Vendors should keep and share relevant logs, promptly report serious incidents or investigations, and notify you before major updates that affect risk or compliance.

GPAI-Specific Points

For GPAI, ask for information on the model, confirmation of GPAI compliance, guidance for downstream use, and clauses on safety filters and misuse controls, plus suspension rights if compliance fails.

Activity: Drafting a Vendor Clause Checklist

Imagine you are in charge of procuring an AI-powered fraud detection service from a non-EU cloud vendor that will be used by an EU bank.

Regulatory map (simplified):

  • AI Act: likely high-risk (credit and financial services risk assessment).
  • GDPR: intensive profiling and monitoring of transactions.
  • Data Act: may involve data from connected services but not physical IoT devices.
  • Sectoral: financial services guidelines and DORA.

Task (write down your answers before checking the model answer):

  1. List 3 AI Act-related points you would definitely include in the contract.
  2. List 3 GDPR-related points you would include.
  3. List 2 sectoral or security-related points you would include.

Pause and think through this as if you were preparing a one-page checklist for your procurement team.

When you are ready, compare with the sample answer below.

Sample answer (for self-check):

  1. AI Act-related points:
  • Vendor confirms high-risk classification and provides evidence of conformity assessment and CE marking where required.
  • Vendor shares technical documentation and performance metrics suitable for the bank’s oversight duties.
  • Vendor commits to incident reporting for serious malfunctions and to notifying about substantial updates or regulatory investigations.
  1. GDPR-related points:
  • Detailed DPA, including legal bases, categories of data, international transfer safeguards, and sub-processor approvals.
  • Support for data subject rights, including access and explanation for high-impact automated decisions where applicable.
  • Strong security measures aligned with DORA and regular penetration testing or security audits.
  1. Sectoral/security-related points:
  • Alignment with relevant EBA/ESMA/EIOPA guidelines on outsourcing and model risk management.
  • Clear business continuity and disaster recovery provisions, including recovery time objectives and incident coordination.

Quiz: Matching Obligations to Regulations

Check your understanding of how AI Act, GDPR, and other rules interact in vendor contracts.

You are buying an AI-based customer support chatbot that handles personal data and sometimes decides whether to escalate complaints. Which combination best matches the **minimum** regulatory focus for your vendor contract?

  1. AI Act only, because it is an AI system; GDPR does not apply to chatbots.
  2. AI Act (likely limited or high-risk depending on use) plus GDPR controller–processor clauses; possibly DSA if it is integrated into a platform.
  3. GDPR only, because the vendor is outside the EU and the AI Act does not apply extraterritorially.
Show Answer

Answer: B) AI Act (likely limited or high-risk depending on use) plus GDPR controller–processor clauses; possibly DSA if it is integrated into a platform.

The chatbot processes personal data, so GDPR applies. Depending on how decisions affect customers, the AI Act may impose limited or high-risk obligations. If the chatbot is part of a platform or recommender, DSA may also be relevant. The AI Act can apply to non-EU vendors offering systems in the EU, so option 3 is incorrect.

Step 4: Documentation, Audit Rights, and the AI Supply Chain

Traceability Across the Chain

Regulators expect traceability across the AI supply chain. As a deployer, you depend on vendor documentation, logging, and cooperation to show compliance.

Documentation Package

Ask vendors for a system description, intended purpose, main components, performance metrics and limitations, and clear human oversight instructions for your operators.

Logs, Audits, and Sub-suppliers

Define what logs exist, how long they are kept, and when you can access them. Include rights to compliance reports or audits, and require transparency about key sub-suppliers.

Data Act Considerations

If data comes from connected products or services, contracts should clarify data access rights, respect the Data Act’s user access and sharing rules, and avoid unlawful restrictions.

Step 5: Cross-Border and Non-EU Vendor Considerations

Non-EU Vendors Still Face EU Rules

AI Act and GDPR can apply to non-EU vendors when their AI systems are used in the EU or target EU users. Cross-border status does not remove EU compliance duties.

AI Act and GDPR Reach

The AI Act applies when systems are placed on or used in the EU market. GDPR applies when vendors offer services to or monitor people in the EU, even from abroad.

Contracts and Law

Contracts pick governing law and courts, but EU public law still applies if its scope is met. Include clauses on EU representatives, regulator cooperation, and data transfer safeguards.

Risk-Based Vendor Choice

If a non-EU vendor will not align with EU rules, you may need extra technical controls, alternative vendors, or to limit the use case to lower-risk scenarios.

Step 6: Building a Vendor Management and Procurement Process

From One-Off to Process

Compliance works best as a repeatable vendor management process, not one-off contract reviews. Build AI checks into procurement and onboarding.

Key Steps in the Flow

Steps: intake and risk classification, regulatory mapping, due diligence, contracting with standard clauses, onboarding with controls, and ongoing monitoring.

Intake and Mapping

Start with a simple intake form: what the tool does, what data it uses, and who uses it. Then build a one-page Regulatory Map for non-trivial systems.

Assign Ownership and Monitor

Give each AI system an internal owner accountable for compliance. Require vendor reports and review whether your use still matches the intended purpose over time.

Key Term Review

Flip the cards to review important concepts for vendor and cross-regulation compliance.

Provider (AI Act)
An entity that develops an AI system or has it developed and places it on the market or puts it into service under its own name or trademark.
Deployer (AI Act)
An entity that uses an AI system under its authority, except when using it for personal non-professional activity.
High-risk AI system
An AI system listed or falling under categories in the AI Act that pose significant risks to health, safety, or fundamental rights, such as recruitment, credit scoring, or biometric identification.
General-purpose AI (GPAI) model
An AI model that can be used for a wide range of tasks and is not designed for a specific narrow purpose; subject to specific AI Act rules when placed on the EU market.
Data processing agreement (DPA)
A GDPR-required contract between controller and processor that sets out how personal data is processed, secured, and transferred.
Regulatory Map
A concise overview for a given AI system showing applicable laws (AI Act, GDPR, Data Act, DSA, sectoral rules), roles, and main obligations.

Key Terms

GDPR
EU General Data Protection Regulation governing personal data processing, including profiling and automated decision-making.
AI Act
EU regulation on artificial intelligence that introduces a risk-based framework and obligations for providers, deployers, and other actors in the AI value chain.
Data Act
EU regulation on fair access to and use of data from connected products and related services, entering main application from 2025.
Deployer
Under the AI Act, the entity that uses an AI system under its authority, except for personal non-professional use.
Provider
Under the AI Act, the entity that places an AI system on the market or puts it into service under its own name or trademark.
High-risk AI system
An AI system identified by the AI Act as posing significant risks to health, safety, or fundamental rights, subject to strict requirements.
Conformity assessment
A process to demonstrate that an AI system meets AI Act requirements, often resulting in CE marking for high-risk systems.
Digital Services Act (DSA)
EU regulation setting obligations for online intermediaries and platforms, including transparency for recommender systems and systemic risk management for very large platforms.
Data processing agreement (DPA)
A contract required by GDPR between a controller and a processor that sets out roles, purposes, security, and conditions for processing personal data.
General-purpose AI model (GPAI)
An AI model capable of performing a wide range of tasks, which may be subject to specific AI Act obligations when placed on or used in the EU market.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself