InsightsEU AI Act

Procured AI: you have obligations even if you build nothing.

Most organisations don’t develop AI themselves; they buy it: as a stand-alone tool, as a feature in existing software or as a service. The AI Act then calls you a deployer. That role comes with obligations of its own, and that is exactly where things often go wrong.

Published
Reading time
4 minutes

“Isn’t our supplier responsible?” It’s the question we hear most. The answer: partly. The supplier carries the heaviest obligations for the system itself. But how you use it, who oversees it and whom you inform about it, is up to you.

Provider or deployer

The AI Act divides responsibilities by role. The provider develops an AI system, or has it developed, and places it on the market under its own name. The deployer uses an AI system under its own authority in a professional context. An organisation that buys an AI tool for customer service, recruitment or document processing is a deployer in that sense.

That role is not optional. And it can shift: under Article 25, anyone who offers a system under their own name, substantially modifies it or uses it for a high-risk purpose it was not intended for, becomes the provider.

What you must do as a deployer

For all AI

  • AI literacy (Article 4): measures that ensure the people working with AI know what they are doing. This has applied since February 2025.
  • No prohibited practices (Article 5). Emotion recognition in the workplace, for example, is prohibited except for medical or safety reasons, even if a supplier offers the feature.
  • Transparency (Article 50). You must inform people exposed to emotion recognition or biometric categorisation. Deepfakes you publish must be disclosed as such. The same applies to AI-generated text you publish to inform the public on matters of public interest, unless it is under editorial control.

For high-risk AI

If you use a high-risk system, for example for recruitment, credit scoring or access to essential services, Article 26 asks more. These requirements apply from 2 December 2027.

  • Use the system in line with the provider’s instructions for use.
  • Assign human oversight to people with the necessary competence, training and authority.
  • Ensure input data is relevant and representative, to the extent you control that data.
  • Monitor operation and report risks and serious incidents to the provider and the authority.
  • Keep automatically generated logs for at least six months.
  • Inform employees and their representatives before using the system in the workplace.
  • Inform people when the system makes or supports decisions about them, and on request explain the role the system played (Article 86).

Public bodies, private entities providing public services, and organisations using AI for credit scoring or for pricing life and health insurance must also carry out a fundamental rights impact assessment (Article 27).

Four procurement pitfalls

AI is in there without you knowing

Suppliers add AI features through updates. What was an ordinary HR system at purchase may be ranking applicants a year later. Your register is then out of date without anyone noticing.

You change the purpose

A general-purpose AI assistant that a department starts using to pre-screen applicants or assess customers gets a new purpose. If that purpose is high risk, you have become the provider, with every obligation that comes with it.

The documentation is missing

Providers of high-risk systems must supply instructions for use covering, among other things, the intended purpose, accuracy, known limitations and the measures for human oversight. Without that information you cannot meet your own obligations. So ask for it before the purchase, not after.

Shadow AI

Employees use public AI services with confidential information or personal data because there is no approved alternative. A ban alone rarely works. A clear policy, an approved tool and an explanation of why work better.

What to put in contracts

  • The intended purpose of the system, its limitations and the risk class according to the supplier.
  • The division of roles under the AI Act, and what the supplier provides: instructions for use, technical information and access to logs.
  • A duty to notify you of material changes, new AI features and incidents.
  • Cooperation with your DPIA, fundamental rights impact assessment and audits.
  • Agreements on your data: no training on your data without consent, storage location and sub-processors.
  • An exit arrangement, so you can take your data and configuration with you.

The European Commission has published model contractual clauses for procuring AI. They were drafted for public bodies, but they make a useful checklist for other organisations too.

A workable approach

  1. Inventory. Map all AI, including in SaaS services and existing software. Ask suppliers which AI features their products contain.
  2. Classify. Determine the risk class and your role for each use case. Watch for uses a tool was not originally intended for.
  3. A procurement gate. Put every new AI purchase through a short questionnaire, so you arrange the right documentation and contract terms up front.
  4. Oversight in practice. Assign human oversight, monitoring and incident reporting in the line organisation, not just on paper.

In short

You don’t have to build AI to fall under the AI Act. If you procure AI, you are responsible for how it is used. That starts with knowing what you have.

Sources

  1. Regulation (EU) 2024/1689 (AI Act), EUR-Lex, in particular Articles 3, 4, 5, 13, 25, 26, 27, 50 and 86.
  2. Regulation (EU) 2026/1744 (Digital Omnibus on AI), EUR-Lex.

This article is for information only and is not legal advice. Current as of October 2026.

Anton Dolganov

Founder of AD-Development and IAPP-certified Artificial Intelligence Governance Professional (AIGP). Combines AI governance with hands-on experience in building AI and high-performance computing, including in oncology.

Further reading

Do you know which AI your suppliers have already built in?

The AI Act scan also maps procured AI and AI in existing software, with your role and the matching obligations for each system.

Book an AI Act scan