Supplier checklist: what must your AI provider deliver?
A supplier checklist for AI procurement verifies what a provider must deliver before you can comply as a deployer: the instructions for use (Art. 13.3), the conformity declaration, the risk classification, update notification, and cooperation in a supervisory investigation.
Updated: June 2026
Introduction: the deployer's due diligence right
Art. 26.1 requires deployersdeployerAn organization using an AI system under its own authority in its activities. It carries the operator duties: use per instructions, oversight, input relevance, monitoring, notices.Open full entry → to use high-risk AI systemshigh-risk AI systemAn AI system that falls under the EU AI Act's strictest requirements, following Article 6. There are two routes in: a system that is a product or safety component covered by the Union harmonization legislation in Annex I and subject to third-party conformity assessment, or a system used in one of the areas listed in Annex III, such as employment, education, or access to essential services. Article 6(3) contains a filter: an Annex III system is not high-risk if it does not pose a significant risk of harm to health, safety, or fundamental rights, although a system that profiles natural persons is always high-risk. See EU AI Act, Annex III, conformity assessment.Open full entry → in accordance with the providerproviderThe actor who develops an AI system (or has it developed) and places it on the market or into service under its own name. It carries manufacturer-style duties: design controls, documentation, conformity.Open full entry →'s instructions. But before you can comply with instructions, you need to receive them. The EU AI ActEU AI ActRegulation (EU) 2024/1689, the European Union's law on artificial intelligence. It takes a risk-based approach: prohibited practices, requirements for high-risk AI systems, transparency obligations for specific uses, and a separate regime for general-purpose AI models. Obligations are divided between providers and deployers. See general-purpose AI, conformity assessment.Open full entry → creates a chain of documentation obligations that flow from provider to deployer, and deployers have a legitimate right to demand that documentation.
This guide provides a complete checklist of what deployers should demand from AI suppliers, with practical advice on how to request, verify, and file this documentation.
The complete supplier documentation request
1. EU declaration of conformity (Art. 47)
Providers of high-riskriskIn the EU AI Act's terms, the combination of the likelihood that a harm occurs and the severity of it if it does. The link between a principle (via the harm that would breach it) and a control (the measure that reduces it). Naming the harm and assessing its risk is required by Art. 9 before any mitigation measure is chosen. See harm, control, residual risk.Open full entry → AI systemsAI systemA machine-based system that, for explicit or implicit objectives, infers from input how to generate outputs (predictions, content, recommendations or decisions) that can influence physical or virtual environments. The OECD-style definition followed by the EU AI Act.Open full entry → must draw up a written EU declaration of conformitydeclaration of conformityThe provider's signed statement that a high-risk AI system meets the AI Act's requirements, drawn up before the system is placed on the market.Open full entry → that states the system meets all applicable requirements of the EU AI Act. The declaration must include:
- Provider identity
- System name, version, and intended purpose
- Statement of conformity with all applicable requirements
- Reference to the conformity assessmentconformity assessmentThe pre-market process demonstrating a high-risk AI system meets the EU AI Act's requirements, leading to CE marking and registration.Open full entry → procedure used
- Date and signature of the authorized representativeauthorized representativeA person established in the EU, appointed in writing by a non-EU provider to carry out the provider's obligations under the AI Act.Open full entry →
Red flag: A supplier who cannot or will not provide a declaration of conformity may not have achieved compliance.
2. instructions for use (Art. 13)
The instructions for use must be comprehensive and must include: the intended purpose; performance metrics and accuracy; known limitations and foreseeable failure modes; required input data specifications; human oversighthuman oversightDesigned-in human ability to monitor, intervene in, override or shut down an AI system. It is meaningful only when the human has authority, information and time to act. One of the seven pillars of responsible AI, and under the EU AI Act a requirement for high-risk AI systems: Article 14 requires that those systems are designed so natural persons can effectively oversee them. Oversight that exists on paper but amounts to confirming in practice does not meet that bar. See override rate, automation bias, high-risk AI system, fairness, safety and reliability, privacy, security and robustness, transparency and explainability, accountability, responsible AI. In the IAPP AIGP body of knowledge, this principle appears as human-centricity, with human oversight as one of its elements.Open full entry → requirements; and maintenance and monitoring requirements. Obtain these in writing before deployment.
3. technical documentation summary
The full technical documentationtechnical documentationRecords a provider must compile and keep for a high-risk AI system to demonstrate conformity, covering its design, data, testing, risk management and monitoring.Open full entry → (Annex IV) is the provider's internal compliance record. Deployers are not entitled to the full documentation, it contains proprietary information, but should request a summary covering: system architecture overview, training datatraining dataThe data used to fit an AI model's parameters; its quality, lawful rights and representativeness are central governance concerns.Open full entry → description, performance validation results, and risk management summary.
4. EU database registration number (Art. 49)
Providers must register high-risk AI systems in the EU database before market placement. Request the registration number and verify it against the public database.
5. post-market monitoring plan
Under Art. 72, providers must have a post-market monitoringpost-market monitoringProvider-side duty to systematically collect and act on experience from systems in use, the product-regulation half of continuous monitoring.Open full entry → plan. Request a summary that describes how the provider monitors system performance over time and what their procedure is for updating the system when performance issues are identified.
6. incident notification procedure
Your supplier contract should include a bilateral incident notification obligation. The provider must notify you of any serious incidentserious incidentAn AI incident causing (or nearly causing) death, serious harm to health, property, fundamental rights or infrastructure. It triggers regulatory reporting duties for high-risk systems.Open full entry →, malfunction, or significant performance change that could affect your compliance. Define response time SLAs contractually.
Supplier compliance red flags
- Cannot provide a declaration of conformity
- Refuses to provide instructions for use in writing
- Cannot provide a EU database registration number
- Responds to documentation requests with generic privacyprivacyThe principle that personal data used by or produced through an AI system stays within the purpose and the legal basis it was collected for. Three routes cause most of the trouble: personal data in training material that was never intended for it, model output that reproduces what the model retained, and purpose creep, where a system built for one use drifts into another the original basis never covered. The GDPR governs this in full, and the EU AI Act adds data governance duties for high-risk systems (Article 10). See DPIA, purpose limitation, responsible AI.Open full entry →/confidentiality objections
- Instructions for use are vague about intended purpose limitationspurpose limitationPersonal data collected for one purpose may not be processed for incompatible others. This principle makes repurposing operational data into training data a legal question.Open full entry →
- No defined incident notification procedure
Contractual provisions to include
Beyond documentation, your procurement contracts for high-risk AI should include:
- Representations that the system complies with the EU AI Act
- Obligations to notify you of system updates that affect compliance
- Obligations to notify you of serious incidents within a defined timeframe
- Access rights to updated technical documentation and instructions upon request
- Indemnity provisions for provider non-compliance that causes deployer liability
Compliance checklist
- Have you sent a formal documentation request to every high-risk AI supplier?
- Have you received and filed the EU declaration of conformity?
- Have you received and reviewed the instructions for use?
- Have you verified the EU database registration number?
- Do your supplier contracts include the compliance provisions listed above?
- Is there a named supplier relationship owner responsible for maintaining documentation?