AI Act · Supply contracts

Your AI vendor has already pushed its obligations onto you

Standard contracts for software with artificial intelligence are written to protect the party selling it. The AI Act, however, places on you as the deploying company obligations you can only discharge with the vendor's cooperation: and that cooperation, if it is not written into the contract, does not exist.

Standard contracts for software with artificial intelligence are written to protect the party selling it. The AI Act, however, places on you as the deploying company a series of obligations you can only discharge with the vendor's cooperation. And that cooperation, if it is not written into the contract, does not exist.

In the first note I singled out the renegotiation of supplier contracts as the point most often neglected. I come back to it because it also has the most favourable cost-benefit ratio: today it is settled with a contract review, later it takes an emergency fix, if not a dispute to manage.

The regulation assigns you obligations — informing people, keeping logs, reporting incidents, cooperating with the authority — but the material means of meeting them all sit inside somebody else's system. The vendor generates the logs. The vendor holds the technical documentation. The vendor decides how the model behaves. You have the obligation, they have the means. The contract is the only place where the two are brought back together.

A clarification on deadlines, before anything else.

The obligations under Article 26 of Regulation (EU) 2024/1689 — the AI Act — which require the deployer of a high-risk system to provide human oversight, keep the logs and report incidents, become applicable on 2 December 2027 for Annex III systems, following the postponement introduced by Regulation (EU) 2026/1744, the Digital Omnibus. Some will conclude that the subject can wait a year.

It cannot, for a reason that is not legal but contractual: the contract you sign today expires after that date. A software supply contract normally runs for three or five years, with automatic renewal. What you sign this quarter will still be in force when the obligation bites, and by then you will no longer obtain the clauses you need, because negotiating leverage exists before signature and not after.

Some obligations, moreover, are already yours now. The transparency duties under Article 50 of the AI Act have applied since 2 August 2026 regardless of risk classification, and they cover the ordinary chatbot on your website too.

The clause already in the draft, working against you.

Article 25 of the AI Act provides that, where a deployer becomes a provider — because it puts its own brand on the system, changes its intended purpose or intervenes substantially — the original provider must cooperate with it, making available the information and technical access reasonably needed. This is an important protection. It has, however, an exception: that cooperation is not owed if the initial provider has clearly specified that its system is not to be turned into a high-risk system.

A clause to that effect is beginning to appear in standard contracts. It is drafted as a restriction on use. Its practical effect is that the vendor releases itself in advance from the duty to cooperate in precisely the scenario where you would need it most. It should be read, and negotiated together with the scope of use you actually need.

The six clauses that are almost always missing.

The instructions for use, not the declaration of conformity. These are two different documents and they are constantly confused. Article 13 of the AI Act requires the provider of high-risk systems to supply instructions setting out the intended purpose, the levels of accuracy and robustness, the foreseeable circumstances that degrade performance, the human oversight measures in place, the requirements for input data and the predetermined changes to the system. A declaration in which the vendor states that it complies with the regulation is none of these things: it is a self-certification. Ask for the document, not for the certificate.

Logs: access, export, retention. If the system is high-risk, the obligation to keep the automatically generated logs for at least six months is yours (Article 26(6) of the AI Act). The system that generates them is theirs. Three things therefore need to be in writing: continuous access to the logs, export in a readable and reusable format, and guaranteed retention for a period at least equal to the one the regulation imposes on you, including the period after the relationship ends. A contract that leaves your logs inside a console you lose access to on the day of termination puts you in an untenable position.

Incident notification, with a deadline in hours. You must immediately inform the provider and the market surveillance authority when you identify a serious incident (Article 26(5) of the AI Act). But in most cases the vendor sees the malfunction first, from its own monitoring systems. The contract must provide for a mirror obligation on their side, with a numerical deadline: twenty-four or forty-eight hours. The formula "without undue delay", on its own, will not defend you in a dispute.

Transparency towards your own users. The obligation to design the system so that whoever interacts with it knows they are talking to a machine, and the obligation to mark generated content in a machine-readable format, fall on the provider (Article 50(1) and (2) of the AI Act). The chatbot, though, sits on your website and carries your name: the reputational damage and the request for clarification reach you. Turn it into a contractual obligation, with an express warranty and an indemnity for the consequences of their failure.

Use of your data. You need an express prohibition on using your inputs, the documents you upload and the outputs generated to train or improve models, save under separate written and revocable authorisation. Sub-processors, the countries where the data are processed and the conditions for transfers must then be identified. Where personal data are involved, all of this is added to the processing agreement required by Article 28 of Regulation (EU) 2016/679 — the GDPR — and does not replace it: they are two distinct layers, and having only one leaves the other uncovered.

Notice of a change of model. This is the most neglected clause and perhaps the most insidious. A vendor that replaces the underlying language model, or changes its version, alters the behaviour of the system without a single word of the contract changing and without your noticing. You need advance notice, a description of the expected impact on performance and a right to terminate or renegotiate if performance degrades beyond an agreed threshold.

Cooperation in the event of an inspection.

One obligation deserves a clause of its own because it is always discovered too late: the deployer must cooperate with the competent authorities (Article 26(12) of the AI Act). In practice that means handing over, within the deadline the authority sets, documents you only have if the vendor gives them to you.

The clause to insert provides for assistance in the event of an inspection or an authority request, with a response deadline, at no additional cost and without making the commitment subject to elastic formulas such as "using all reasonable endeavours". In a contract drafted by the other side, that formula exists to leave the vendor room to step back.

The standard liability cap is not calibrated for this risk.

In software contracts the liability cap is normally set at twelve months' fees. That is a measure calibrated for ordinary commercial risk. The penalty risk introduced by the regulation is of a different order of magnitude.

The delicate point is allocation. Penalties strike whoever breached the obligation: if the obligation was yours and the failure was theirs, the penalty reaches you and you can recover from them only if the contract allows it and if the cap covers it. Demanding unlimited liability is pointless, because no vendor grants it. The request that has some chance of being accepted is to carve out of the cap breaches concerning personal data and AI Act compliance, or to set a separate and higher cap for those.

It is also worth saying what does not exist: there is no special European regime on civil liability for artificial intelligence. The dedicated proposal for a directive, COM(2022) 496, was withdrawn by the Commission. In the absence of that layer, the contract remains the main instrument for allocating risk, which is why it is worth spending time on.

If instead the AI sits inside what you sell. From 9 December 2026 Directive (EU) 2024/2853 on liability for defective products includes software in the definition of product and applies to what is placed on the market after that date. If you substantially modify a system supplied by someone else, Article 8(2) of that directive treats you as a manufacturer towards the injured party, in the same way as Article 25 of the AI Act treats you as a provider. And that liability cannot be limited by contract (Article 15 of the same directive): the cap you accept from your vendor decides how much you can recover, not how much you are exposed to.

The gap no clause closes.

Generative tools in free or personal versions, switched on by individual departments on their own — the assistant used to rewrite a quotation, the translator grinding through contracts, the extension installed in the ERP — have no negotiated contract. They have consumer terms of use, in which none of the guarantees described above exists, and in which use of the content submitted for training purposes is often the default setting.

Here the contract is missing, so the clause to renegotiate is missing too. What remains is a decision to take: prohibit those tools on company data, or move to business versions that do come with a contract. This is why the inventory of systems has to be done before the contract review, not after.

A free starting point.

The European Commission makes model contractual clauses available for the procurement of artificial intelligence systems, updated in March 2025 to align them with the regulation, in a full version for high-risk systems and a lighter version for the others, together with a commentary explaining how to adapt them.

Two honest caveats. They were designed for public procurement and are mandatory for no one. And they need adapting: applied to the letter to a private contract they produce demands that a commercial vendor will never accept, and cost you credibility in the negotiation. As a checklist for working out what is missing from the text on your table, however, they work better than any commercial guide.

Six questions to put to the vendor.

Before bringing a lawyer in on the text, these six questions, sent in writing, already say a great deal. They cost one email.

  1. What is the declared intended purpose of the system and what risk classification do you assign to it under the AI Act?
  2. Will you supply the complete instructions for use, or only a declaration of conformity?
  3. How do we access the logs, in what format do we export them, how long do you retain them and what happens when the contract ends?
  4. Within how many hours do you inform us of a significant malfunction or a serious incident?
  5. Are our inputs, the documents we upload and the outputs generated used to train models, yours or third parties'?
  6. If you replace the underlying model, how much notice do we get and what can we do if performance changes?

A serious vendor answers all six in writing within a few days. If the answers do not come, or come only verbally, you have obtained useful information about the other side all the same.

A contract that does not mention the AI Act is not a neutral contract for that reason: it is a contract in which the obligations stay yours and the means stay theirs.

Ugo Bruno Gambardella
Ugo Bruno Gambardella

Avvocato (Italian lawyer). He works on AI Act and AI governance, data protection and the DPO function, Legislative Decree 231/2001 compliance models and internal controls. Track record.

Sources

  • Regulation (EU) 2024/1689 — the AI Act, consolidated text on EUR-Lex, updated to 27 July 2026; in particular Articles 13, 25, 26 (paragraphs 5, 6 and 12) and 50 (paragraphs 1 and 2).
  • Regulation (EU) 2026/1744 — the Digital Omnibus on AI, 8 July 2026, published in the Official Journal of the European Union on 24 July 2026, in force since 27 July 2026. It postpones to 2 December 2027 the obligations for the high-risk systems of Annex III and to 2 August 2028 those under Article 6(1); the transparency deadlines are left unchanged.
  • Regulation (EU) 2016/679 — the GDPR, Article 28 on processors.
  • Directive (EU) 2024/2853 — liability for defective products. Relevant here are Article 2 (it applies to products placed on the market after 9 December 2026), Article 4 of the directive, which includes software in the definition of product, and Articles 8(2) and 15 of the same directive.
  • EU model contractual AI clauses — Community of Practice on Public Procurement of AI, European Commission; updated version of March 2025.
  • On the withdrawal of the proposal for a directive on artificial intelligence liability, COM(2022) 496: European Commission work programme for 2025.

Legal position as at 29 August 2026, verified against the primary sources listed above. This note is published for general information and does not constitute advice on a specific case.

All notes Get in touch