EUAIACTUS.COM

AI procurement & supply chain

AI vendor due diligence for EU AI Act and GDPR procurement

Buying an AI tool does not outsource your regulatory role. Procurement should establish the vendor's AI Act role, system/model documentation, personal-data processing, transfer mechanisms, change controls, monitoring and the evidence your organisation needs after deployment.

A service provided by Lexara Advisory LLC · Reviewed by Constantin Razvan Gospodin.

Direct answer

What should an AI vendor due-diligence review cover?

A practical review should cover system/model identity, intended purpose, AI Act role allocation and classification, GDPR controller/processor position, subprocessors and international transfers, documentation, performance/testing, security, incident handling, material-change notices and contractual evidence rights.

Due diligence domains

Questions to answer before contracting

System and model identity

What AI system/model is being supplied? Which version? Which upstream models/components? What is the intended purpose and what use restrictions apply?

Role allocation

Is the vendor a provider? Are you a deployer? Could configuration, rebranding, substantial modification or integration change the role analysis?

EU AI Act classification

Has the vendor documented prohibited-practice, Article 50, GPAI and high-risk classification? What facts support the conclusion?

Documentation access

What instructions, system documentation, performance information, limitations, logging capabilities and downstream compliance information will be available?

Testing & monitoring

What testing supports the claimed performance? How are incidents, vulnerabilities, drift, model updates and material changes detected and communicated?

Data & privacy

What data is processed, where, for what purpose, with what retention, training use, subprocessors, transfer mechanism and security controls?

GDPR procurement

What should AI procurement due diligence cover under GDPR?

Where an AI vendor processes personal data on behalf of your organisation as a processor, GDPR Article 28 requires the controller to use processors providing sufficient guarantees to implement appropriate technical and organisational measures. Due diligence should therefore cover processing purposes, subprocessors, security, retention, international transfers, assistance obligations and the contract — alongside the separate EU AI Act role and system analysis.

Contracting

The contract should preserve the evidence you need after go-live.

Change notification

Require notice of material model, intended-purpose, performance, architecture, subprocessor or compliance-status changes.

Documentation obligations

Specify what compliance/performance documentation must be supplied and updated, including downstream information needed for your role.

Incident interface

Set escalation, notification, cooperation and evidence-preservation expectations for incidents and regulator/customer requests.

Audit/evidence rights

Use proportionate information, assurance and audit rights where necessary to validate material controls without inventing access that the commercial model cannot support.

High-risk value chain

Article 25 makes supply-chain cooperation important.

For high-risk AI systems, the AI Act addresses responsibilities along the value chain and requires written arrangements in specified circumstances so providers can obtain necessary information, capabilities, technical access and assistance from suppliers of relevant components/services. Procurement should anticipate those dependencies before the high-risk regime applies.

Red flags

Vendor statements that are not enough

  • “EU AI Act compliant” with no role or system-level analysis.
  • “Not high-risk” with no intended-purpose rationale.
  • “Human in the loop” with no description of authority, timing or override capability.
  • “No personal data” where prompts, logs, telemetry or account data are still processed.
  • “Certified” without identifying the certification, scope and legal significance.
  • “We use a leading model provider” as a substitute for system-level governance.

Frequently asked

AI procurement and vendor due-diligence questions

What should AI procurement due diligence cover under GDPR?

Where the vendor acts as a processor, review whether it provides sufficient guarantees under Article 28, including security, subprocessors, transfers, retention, assistance duties and contract terms.

Does buying an AI tool transfer EU AI Act responsibility to the vendor?

No. Responsibilities depend on the legal role and system facts. Contracting can allocate tasks, but it does not erase statutory responsibilities imposed on providers, deployers or other actors.

Make procurement part of the AI governance system.