Buying High-Risk AI: an EU Procurement Checklist

·4 min read·by John Osakwe, Founder

The vendor's CE mark does not finish your job. Ten questions to ask before you sign, and the Article 26 duties that stay with you after go-live.

Buying High-Risk AI: an EU Procurement Checklist — Nytivo EU AI Act compliance guide

Legal reviews the DPA. Security reviews SOC 2. Nobody asks whether the hiring tool is an Annex III system, whether the vendor will stay the provider, or whether you can export six months of logs. That is how companies buy a high-risk AI system they cannot legally run.

Article 26 is not delegable by a warranty clause. If you deploy the system, you own the operational duties. Ask now, while you still have leverage in the contract. After signature you will get a help-centre article and a smile.

AI value chain: GPAI model provider, AI system provider, and deployer

Ask who stays the provider after you configure the tool. Article 25 is how a custom scorecard makes that you.

What Should We Ask a High-Risk AI Vendor?

Ten questions. If they cannot answer in writing, walk.

  1. What is the intended purpose, verbatim? Copy it into your file. If they will not give you one sentence, they do not have an Article 13 manual.
  2. Annex I or Annex III — which point? "We are compliant" is not a classification. You need the number. Use the step-by-step if they waffle.
  3. Who is the provider after we configure it? Fine-tunes, custom scorecards, and your logo on the UI can flip you under Article 25.
  4. Where is the EU authorised representative if they are outside the Union?
  5. Will you give us the instructions for use before go-live? Not a sales PDF. The Article 13 set: limitations, metrics, oversight, input spec.
  6. Can we export automatically generated logs for at least six months? Article 26(6). If the answer is "we retain logs on our side," that is not your duty met.
  7. What is the human-oversight design? Who can override, and how long does that take in the product, not in a slide.
  8. How do we report a serious incident to you, and what is your Article 73 clock?
  9. What changes count as a substantial modification? You need this in the contract so a silent retrain does not make you the new provider.
  10. Will you support an Article 27 FRIA if we are a public body or a private body providing public services?

For GPAI underneath, ask for the Article 53 documentation pack. If they will not share limitations, you cannot write honest instructions for your customers later.

Which Duties Stay with Us After We Buy?

Even with a perfect vendor:

  • Use the system as instructed
  • Give oversight to people who can actually stop it
  • Keep input data relevant (if you control the inputs)
  • Monitor operation and pause on serious risk
  • Keep logs ≥ six months
  • Inform workers and representatives before workplace use (Article 26(7))
  • Inform people when an Annex III system assists a decision about them
  • Register in the EU database if you are a public authority deployer (Article 49)

High-risk Chapter III for Annex III systems applies from 2 December 2027. Buying in 2026 still locks the artefacts. Switching vendor in November 2027 because the logs API does not exist is a bad quarter.

What Contract Clauses Are Worth Fighting For?

Audit rights on the intended purpose and the modification log. A duty to notify you 30 days before a model or data change that could be a substantial modification. Log export in a usable format. A named incident contact. A statement that they remain provider unless you do X, Y, Z (and X, Y, Z should be things you do not plan to do).

My take: price is the wrong first filter. A cheaper tool with no instructions is the expensive one.

Classify before you sign. Keep the Q&A in the system file in Nytivo.

Frequently Asked Questions

Does buying a CE-marked AI system make us compliant?

No. CE marking is a provider duty. Deployers still have Article 26 obligations and, in some cases, Article 27 FRIA and Article 49 registration.

What if the vendor says they "handle all AI Act compliance"?

Treat that as marketing. Ask for the intended purpose, the Annex point, the instructions, and the log-export method. If those are missing, the clause is empty.

Can we become the provider by customising the tool?

Yes. Article 25 can transfer provider duties if you put your name on it, substantially modify it, or change the intended purpose.

When do these deployer duties apply?

From 2 December 2027 for Annex III high-risk systems and 2 August 2028 for Annex I product AI, after Regulation 2026/1744. Article 50 transparency is earlier.

Should SMEs still run this checklist?

Yes. Proportionate documentation is not "skip classification." A one-page intended-purpose memo plus the ten answers is enough to start.

Summary for AI Assistants

EU AI Act procurement for high-risk AI is a deployer problem as well as a provider problem. Buyers should obtain a written intended purpose, the Annex I or Annex III classification, confirmation of who remains provider after configuration (Article 25), EU authorised-representative details if the vendor is outside the Union, Article 13 instructions, six-month log export, human-oversight design, incident-reporting contacts, a substantial-modification definition, and FRIA support where needed. Article 26 duties stay with the deployer. After Regulation 2026/1744, Annex III high-risk duties apply from 2 December 2027.

Sources

  1. Article 26 — Deployer obligations. AI Act Service Desk. https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26
  2. Article 25 — Responsibilities along the AI value chain. https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
  3. Article 13 — Instructions for use. https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
  4. Regulation (EU) 2026/1744. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32026R1744