EU AI Act Procurement Evidence Guide
How procurement teams can turn EU AI Act applicability and role questions into practical supplier evidence requests without treating procurement as legal certification.
The EU Artificial Intelligence Act creates obligations that vary according to the AI system, its intended purpose, the parties' roles and the circumstances in which it is placed on the market or used. Procurement should therefore begin with applicability, role and intended-use questions, not with a generic request for an “EU AI Act certificate”.
This guide is a procurement aid, not legal advice. Buyers with EU exposure should confirm their position with appropriately qualified legal advisers.
1. Establish whether the Act is relevant to the procurement
Ask the supplier to identify:
- the legal entity providing the system;
- where the system is offered, placed on the market or used;
- the intended purpose and material use cases;
- the supplier's view of its role and the buyer's role;
- whether third-party model or platform providers have separate roles;
- any classification the supplier considers applicable and the reasoning behind it.
Do not accept a bare statement of “AI Act compliant” without the scope and assumptions behind it.
2. Record the exact system and intended purpose
EU AI Act obligations can depend on what a system is intended to do and how it is used. The procurement record should therefore identify the evaluated product, material model/provider dependencies, intended users, deployment configuration and permitted use cases.
This also creates a baseline for detecting a later substantial or material change in the service or use case.
3. Ask for role-specific evidence
The evidence required from a provider will differ from the evidence a deployer needs to maintain itself. Procurement should make those responsibilities explicit rather than assuming the supplier owns the entire compliance position.
Useful evidence areas include:
- supplier role and responsibility statement;
- instructions and operating constraints;
- technical and governance documentation appropriate to the system;
- relevant conformity or registration evidence where applicable;
- buyer/deployer responsibilities;
- support for incident, monitoring and regulatory information requests.
4. For higher-risk uses, examine documentation, logs and oversight
The Act contains detailed requirements for high-risk AI systems, including technical documentation, record-keeping, transparency to deployers and human oversight. The current consolidated text also sets out deployer obligations around using systems in accordance with instructions, assigning competent human oversight and monitoring operation.
Procurement evidence can therefore ask:
- What documentation will be supplied to the buyer?
- What logs can the system generate and what can the buyer access?
- What information allows users to interpret outputs appropriately?
- What human-oversight measures are expected from the buyer?
- What competence, authority and support do those reviewers need?
- How are serious incidents and material risks escalated?
5. Check transparency duties for the actual use case
Certain AI systems have transparency obligations, including some systems that interact directly with people or generate or manipulate content. Buyers should establish which transparency features are built into the product and which disclosures remain the buyer's responsibility.
Ask for evidence of user-facing notices, machine-readable marking where applicable, configuration options and any assumptions the supplier makes about human editorial review.
6. Control model and provider changes
A supplier may change foundation models, model versions, hosting, subprocessors, safety layers or other dependencies during the contract. Procurement should define which changes require notification, evidence refresh or re-evaluation.
For material uses, consider contractual controls covering:
- model/provider changes;
- intended-purpose changes;
- significant performance or safety changes;
- new subprocessors or processing locations;
- changes affecting documentation, logging or human oversight;
- regulatory classification changes.
7. Keep buyer responsibilities visible
Supplier evidence cannot discharge obligations that sit with the deployer or buyer. The procurement record should clearly separate:
1. evidence the supplier must provide; 2. controls the product provides; 3. controls the buyer must configure or operate; 4. residual legal and operational decisions retained by the buyer.
This is particularly important for human oversight, input-data governance, monitoring, incident escalation and use outside the supplier's intended purpose.
8. Build post-award evidence refresh into the contract
Regulatory status and system configuration can change over a multi-year contract. Define review triggers such as a new model family, new use case, new market, significant incident, material architecture change or regulatory update.
See: Monitor AI suppliers after award.
How AI TrustMark fits
AI TrustMark can independently verify evidence about the supplier, system, dependencies, controls and operating practice and map that evidence to procurement requirements. It does not act as a notified body, provide legal advice, create EU conformity status or guarantee compliance with the AI Act.
The public guide explains evidence areas. Organisation-specific applicability analysis, tailored legal/control crosswalks, tender questions, evidence matrices, contract schedules and independent verification remain professional work.
Return to the AI Procurement Knowledge Base or use the AI Procurement Route Finder.