AI procurement & supply chain
AI vendor due diligence for EU AI Act and GDPR procurement
Buying an AI tool does not outsource your regulatory role. Procurement should establish the vendor's AI Act role, system/model documentation, personal-data processing, transfer mechanisms, change controls, monitoring and the evidence your organisation needs after deployment.
A service provided by Lexara Advisory LLC · Reviewed by Constantin Razvan Gospodin.
Direct answer
What should an AI vendor due-diligence review cover?
A practical review should cover system/model identity, intended purpose, AI Act role allocation and classification, GDPR controller/processor position, subprocessors and international transfers, documentation, performance/testing, security, incident handling, material-change notices and contractual evidence rights.
Due diligence domains
Questions to answer before contracting
System and model identity
What AI system/model is being supplied? Which version? Which upstream models/components? What is the intended purpose and what use restrictions apply?
Role allocation
Is the vendor a provider? Are you a deployer? Could configuration, rebranding, substantial modification or integration change the role analysis?
EU AI Act classification
Has the vendor documented prohibited-practice, Article 50, GPAI and high-risk classification? What facts support the conclusion?
Documentation access
What instructions, system documentation, performance information, limitations, logging capabilities and downstream compliance information will be available?
Testing & monitoring
What testing supports the claimed performance? How are incidents, vulnerabilities, drift, model updates and material changes detected and communicated?
Data & privacy
What data is processed, where, for what purpose, with what retention, training use, subprocessors, transfer mechanism and security controls?
GDPR procurement
What should AI procurement due diligence cover under GDPR?
Where an AI vendor processes personal data on behalf of your organisation as a processor, GDPR Article 28 requires the controller to use processors providing sufficient guarantees to implement appropriate technical and organisational measures. Due diligence should therefore cover processing purposes, subprocessors, security, retention, international transfers, assistance obligations and the contract — alongside the separate EU AI Act role and system analysis.
Contracting
The contract should preserve the evidence you need after go-live.
Change notification
Require notice of material model, intended-purpose, performance, architecture, subprocessor or compliance-status changes.
Documentation obligations
Specify what compliance/performance documentation must be supplied and updated, including downstream information needed for your role.
Incident interface
Set escalation, notification, cooperation and evidence-preservation expectations for incidents and regulator/customer requests.
Audit/evidence rights
Use proportionate information, assurance and audit rights where necessary to validate material controls without inventing access that the commercial model cannot support.
High-risk value chain
Article 25 makes supply-chain cooperation important.
For high-risk AI systems, the AI Act addresses responsibilities along the value chain and requires written arrangements in specified circumstances so providers can obtain necessary information, capabilities, technical access and assistance from suppliers of relevant components/services. Procurement should anticipate those dependencies before the high-risk regime applies.
Red flags
Vendor statements that are not enough
- “EU AI Act compliant” with no role or system-level analysis.
- “Not high-risk” with no intended-purpose rationale.
- “Human in the loop” with no description of authority, timing or override capability.
- “No personal data” where prompts, logs, telemetry or account data are still processed.
- “Certified” without identifying the certification, scope and legal significance.
- “We use a leading model provider” as a substitute for system-level governance.
Frequently asked
AI procurement and vendor due-diligence questions
What should AI procurement due diligence cover under GDPR?
Where the vendor acts as a processor, review whether it provides sufficient guarantees under Article 28, including security, subprocessors, transfers, retention, assistance duties and contract terms.
Does buying an AI tool transfer EU AI Act responsibility to the vendor?
No. Responsibilities depend on the legal role and system facts. Contracting can allocate tasks, but it does not erase statutory responsibilities imposed on providers, deployers or other actors.
Primary sources
Official legal anchors for procurement
EUR-Lex — consolidated EU AI Act, including Article 25 value-chain responsibilities