Your AI Act obligations as a deployer depend on information only the provider has. 32 questions to send before you sign, the scoring to read the answers, and eight clauses for the contract.
Delivered by email immediately after payment. Excel file, one named user.
Your obligations as a deployer depend on information you do not hold. The Annex IV documentation, the bias examination, the accuracy figures per segment, the log format — all of it sits with the provider. Ask for it after signing and you are negotiating from zero leverage.
On the sister site's DORA work, contract remediation is consistently the longest workstream in a programme. The AI Act version will be no different, and it has the same fix: ask before you sign.
Thirty-two questions in eight groups — identification, classification, documentation, data, performance, oversight, logging, change, incidents, cooperation and exit — written to be sent to a supplier as-is. Each has a slot for their answer and an adequacy verdict that colours itself.
Some of them are uncomfortable on purpose:
Not every "No" weighs the same. The scoring tab names the five that are deal-breakers rather than negotiating points — starting with a refusal of the Art. 25(4) cooperation duty, which is the one to walk away over. Without it, if you ever become the provider under Art. 25, you cannot meet the obligations you have just inherited.
Eight clauses covering cooperation, Annex IV documentation, change notification, log export and retention, serious incidents, bias and data governance, use of your data for training, and exit. Square brackets mark the numbers you set.
They are drafted to be dropped into your own paper, not to replace your counsel.
Procurement and legal teams buying AI, and the compliance officer who will be asked to sign off on a system whose internals they have never seen.
Is your organisation subject to both the AI Act and DORA? The two regulations intersect on the operational resilience of financial AI systems. Our sister site regulation-dora.eu covers DORA in depth — including what the AI Act adds on top of an existing DORA programme.
The AI Act for financial institutions ↗ Explore regulation-dora.eu ↗Where a deployer becomes a provider under Art. 25, the original provider must cooperate and supply the information and technical access reasonably needed to comply. Get it in the contract before you need it: a provider that has already been paid has little incentive to help you assume its obligations.
Art. 25 lists three triggers: putting your own name or trademark on a high-risk system already on the market, making a substantial modification to it, or changing its intended purpose so that it becomes high-risk.
A refusal to accept the Art. 25(4) cooperation duty. Without it you cannot meet your own obligations if you ever become the provider, and no commercial term compensates for that.