The new reality of AI procurement under the EU AI Act
For the modern Chief Technology Officer, the process of acquiring third-party software has fundamentally shifted. Previously, procurement focused on uptime SLAs, feature parity, and cost-per-seat. However, the entry into force of the EU AI Act (Regulation (EU) 2024/1689) introduces a new layer of complexity: inherited liability. Conducting a thorough AI vendor due diligence process is no longer a best practice; it is a regulatory necessity to ensure that an enterprise does not inadvertently become a ‘provider’ of a high-risk system or fail in its obligations as a ‘deployer’ under Article 26.
When integrating AI into existing cloud ecosystems, the boundary between the software vendor’s responsibility and the enterprise’s liability is often blurred. If your organization implements a third-party tool for automated recruitment or credit scoring, you are deploying a high-risk AI system as defined in Annex III. In these scenarios, the due diligence process must move beyond basic security questionnaires and into the rigorous auditing of model cards, data lineage, and bias mitigation strategies. At CONAIS, we help organizations navigate these complexities through our Our Services which bridge the gap between technical implementation and regulatory compliance.

Understanding your role: Provider vs. Deployer
The first step in any diligence process is determining the legal classification of both the vendor and your organization. Under the AI Act, a ‘provider’ (Article 3(2)) is the entity that develops an AI system and places it on the market under its own name. A ‘deployer’ (Article 3(4)) is the entity using the system under its authority. Most enterprises act as deployers. However, Article 25 warns that a deployer can be reclassified as a provider—inheriting all the heavy compliance burdens of Articles 16 through 24—if they make a ‘substantial modification’ to the system or repurpose a general-purpose AI model for a high-risk application.
Effective AI vendor due diligence requires verifying that the vendor has fulfilled their specific obligations. For high-risk systems, this includes the establishment of a risk management system (Article 9) and the creation of technical documentation (Article 11). If a vendor cannot provide proof of these internal controls, the enterprise risks deploying a non-compliant system, which carries significant financial and reputational penalties. Organizations should start by assessing their current status via an AI Readiness Test to identify where their procurement processes may fall short of these new requirements.
The core pillars of AI vendor due diligence
To build an audit-grade governance framework, procurement and IT teams should focus their diligence on four critical technical and legal pillars. These pillars align with the requirements set forth in the EU AI Act official text and ensure a robust defense against operational failure.
1. Technical documentation and transparency (Article 13)
Transparency is a cornerstone of the AI Act. Article 13 requires that high-risk AI systems be designed and developed in a way that their operation is sufficiently transparent to enable deployers to interpret the system’s output and use it appropriately. During the diligence phase, you must demand ‘Instructions for Use’ from the vendor. These instructions should detail the system’s capabilities, its limitations, the level of accuracy it achieves, and any known circumstances under which the system may malfunction or exhibit biased behavior.
2. Data governance and training sets (Article 10)
High-risk AI systems must be trained on data that is relevant, representative, and, to the best extent possible, free of errors. You must query the vendor on their data sourcing and preparation processes. Are the datasets used for training, validation, and testing subject to appropriate data governance and management practices? For enterprise retail or financial services, understanding the ‘data lineage’ is essential to avoid inheriting systemic biases that could lead to discriminatory outcomes and legal challenges.
3. Accuracy, robustness, and cybersecurity (Article 15)
An AI system’s performance is not static. Article 15 mandates that high-risk systems achieve an appropriate level of accuracy, robustness, and cybersecurity throughout their entire lifecycle. Your technical team should review the vendor’s testing protocols. This includes resilience against ‘adversarial attacks’—where malicious actors attempt to manipulate the model’s behavior by providing deceptive inputs. A vendor who cannot provide metrics on model robustness is a high-risk partner.
4. Human oversight (Article 14)
The AI Act rejects ‘black box’ decision-making for high-risk systems. Article 14 requires that these systems can be effectively overseen by natural persons. In your due diligence, examine the user interface and the decision-making workflow. Does the system allow a human operator to override or disable the AI? Is there a clear mechanism for the operator to intervene? If the vendor’s tool is fully autonomous with no ‘kill switch’ or override capability, it likely fails the compliance test for high-risk applications.

Operationalizing the audit: A practitioner’s framework
Knowing what to look for is only half the battle; the other half is operationalizing the audit within your existing procurement cycles. We recommend a tiered approach based on the risk level of the AI application. For low-risk or minimal-risk AI (such as spam filters), a standard security review may suffice. However, for systems that interact with employees or customers in a significant way, a deeper dive is required. This often involves cross-functional teams comprising legal counsel, data scientists, and IT infrastructure leads.
- Identify the use case: Map the vendor’s solution against the AI Act’s risk categories.
- Request a Model Card: A standardized document summarizing the model’s performance and training data.
- Verify CE Marking: For high-risk systems, check if the vendor has the required CE marking indicating conformity with EU standards.
- Review the Quality Management System: Ensure the vendor has a documented process for post-market monitoring (Article 61).
By following this framework, organizations can build a portfolio of AI Solutions that are not only innovative but also defensible. This proactive stance is particularly important when using modern architectures like Azure OpenAI or agentic automation, where the interaction between the base model and the proprietary data layer creates complex shared responsibilities.
Contractual protections and the right to audit
The final stage of AI vendor due diligence happens in the contract. Traditional SaaS agreements are often insufficient for AI. Specific clauses should be inserted to protect the enterprise from regulatory shifts. These include indemnification for non-compliance with the AI Act, requirements for the vendor to notify the deployer of any discovered biases or malfunctions, and a ‘right to audit’ clause that allows the enterprise (or a third party) to verify the vendor’s compliance claims periodically.
Furthermore, ensure that the vendor commits to providing updates that align with the evolving guidelines of the European AI Office. As the AI Act is a ‘living’ regulation with secondary legislation expected, your vendors must demonstrate the agility to adapt their technical documentation and risk management processes accordingly. This long-term alignment is what separates a mere tool provider from a strategic AI partner.
Moving from compliance to competitive advantage
While the focus of this guide has been on risk mitigation, it is important to recognize that robust diligence is a competitive advantage. Enterprises that can confidently prove the safety and fairness of their AI systems will find it easier to gain employee trust and customer loyalty. They will also be better positioned to scale their AI initiatives without the fear of sudden regulatory shutdowns or massive fines. In the context of the EU market, governance is the foundation of innovation.
At CONAIS, we specialize in the intersection of high-performance AI architecture and rigorous EU AI Act governance. We understand that for a CTO, the goal is not just to avoid risk, but to enable the business to move faster. By embedding compliance into the procurement and development lifecycle, you ensure that your transition to an AI-native enterprise is both sustainable and secure. If you are currently evaluating AI vendors or modernizing legacy IT with intelligent workflows, let us help you build a framework that stands up to the highest standards of scrutiny.
To discuss your specific AI governance needs or to audit your current vendor pipeline, we invite you to Contact our team of senior practitioners today.
Frequently asked questions
What is the primary goal of AI vendor due diligence under the EU AI Act?
The goal is to ensure that purchased AI systems meet transparency, safety, and data governance standards, preventing the enterprise from inheriting legal liability or being reclassified as a system provider.
Does the EU AI Act apply to AI vendors outside of Europe?
Yes, the AI Act applies to any provider placing AI systems on the market in the EU, regardless of where the provider is located, and to deployers using those systems within the EU.
What are the requirements for high-risk AI systems under Article 13?
High-risk systems must be designed for transparency, providing deployers with clear instructions for use, information on accuracy, and details on known limitations or potential biases.
How can an enterprise avoid being classified as an AI ‘provider’?
An enterprise can avoid provider status by ensuring they do not make substantial modifications to the system or repurpose general-purpose AI for high-risk use cases without fulfilling provider obligations.
![]()






