You are buying an AI system.
You asked the vendor whether it is compliant with the EU AI Act, and they said yes.
The security questionnaire came back clean. The data processing agreement is signed.
But somehow you still cannot answer the question whether the EU AI Act treats you as the provider of this system or the deployer of it.
At some point you start to wonder whether you are asking it wrong.
You are not. But there are five specific questions you can ask any AI vendor to find out where you stand.
Why Ask Now
Article 113, as the Digital Omnibus amended it, defers Chapter III Sections 1, 2 and 3 to December 2, 2027 for the AI systems classified as high-risk under Annex III, and to August 2, 2028 for the ones caught through product legislation in Annex I. Those sections run from Article 6 to Article 27. They contain the classification rules, the requirements for high-risk systems, and the obligations of providers and deployers.
So the instructions for use, the written agreement, the documentation handover, your own duties as a deployer: none of them apply to anyone today.
But you should start asking sooner rather than later.
A vendor who cannot answer these questions in September 2026 is not breaching anything. They also have no obligation to improve, no deadline forcing them to build the documentation, and no reason to volunteer any of it. What they do have is a commercial motive to close, which will not be there again for next couple of years.
Sign a three-year agreement this month and it runs to September 2029. December 2027 arrives before the halfway point, at which time every answer below stops being a courtesy and starts being an obligation, on an AI system you have already bought, under a contract that has already been signed.
One part of the role question is already applicable. The transparency rules in Article 50 started on August 2, 2026, and they split by role: the duty to build in disclosure and machine-readable marking sits with the provider, the duty to tell people they are looking at a deepfake or an emotion recognition system sits with the deployer. So question one below has a live answer this year, even though most of what the answer decides is still fifteen months out.
The Commission is required to publish guidelines on the practical implementation of Articles 8 to 15 and Articles 25 and 26, which is where the value chain lives, and separately on what counts as a substantial modification. Neither carries a deadline.
Question No. 1: Who Is the Provider
Under the EU AI Act, are you the provider of this AI system, or are we?
You are the provider if you develop an AI system, or have one developed, and place it on the market under your own name or trademark. That second part is the white-label case: somebody else builds it, your logo goes on it, and the AI Act reads that as you. You are the deployer if you use a system under your own authority.
Two other roles displace the obvious answer. Where a high-risk system is a safety component of a product covered by the legislation in Section A of Annex I, the product manufacturer is the provider. And a supplier established outside the EU has to appoint an authorized representative here before making a high-risk system available on the Union market.
A good answer names one role and explains why. An evasive answer is “we’re fully compliant,” which answers a question you did not ask.
Then there is the part of Article 25(1) where three things turn a customer into a provider:
putting your name or trademark on the AI system,
making a substantial modification to a high-risk AI system, or
changing the intended purpose so that a AI system which was not high-risk becomes high-risk.
The first of those, and only the first, is expressed “without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated.”
That the allocation works between the parties is clear from the text. Whether it would bind a market surveillance authority deciding who to pursue is not stated anywhere, and there is no case law. Write the clause. Do not build a position on it.
Get the answer in writing either way. If they are wrong, you want to know when they said it.
Question No. 2: What the System Is For
What is the intended purpose of this AI system, as you have declared it?
For the Annex III categories, high-risk classification runs through the declared intended purpose rather than through raw capability. The same AI system is in or out depending on what it is put in front of. That is not the whole picture, because a AI system caught through Annex I is classified by the product it sits inside, and because changing the purpose yourself has consequences of its own, below. For an Annex III AI system, though, the declared purpose is where classification starts.
Article 3(12) defines intended purpose as the use the provider intends, “as specified in the information supplied by the provider in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation.”
Sales materials are inside the definition. If the deck says the AI system screens applicants and the contract says it performs a narrow procedural task, both are in scope, and the vendor has a problem they may not know about.
A good answer is a sentence you could paste into your AI governance documentation. An evasive answer describes features.
From December 2027, the sentence you are asking for is one they will owe you. Article 13(3)(b) puts the intended purpose in the instructions for use. Today they owe you nothing, which is the difference between asking and negotiating.
And the catch: put the AI system to a use that makes it high-risk, and the AI Act can make you the provider, with every obligation that carries.
There is also a second half to that, added this summer. Article 25(2) makes the original provider cooperate with the new one, and now itemizes the handover: technical documentation sufficient to assess compliance, information on known limitations and failure modes, and targeted technical access including for testing and validation.
Then the sentence at the end of the paragraph. None of it applies where “the initial provider has clearly specified that its AI system is not to be changed into a high-risk AI system.”
One line in their documentation, and the duty switches off before it ever switches on. It will not stop you becoming the provider, because classification follows the facts and not the paperwork. It stops you getting the three things you would need once you are.
Question No. 3: What Happens If We Change It
If we fine-tune this, or connect it to our own data, does that change your answer about who the provider is?
Ask it in the same breath as the role question. Fine-tuning can move the role, but only on specific routes: a substantial modification to an AI system that is already high-risk, or a change of purpose that makes one high-risk.
For models rather than systems, the Commission’s guidance from July 2025 points at fine-tuning above roughly a third of the compute used to train the original. That figure is indicative and the guidance does not bind. The legal question is still whether the modification significantly changes the model’s generality, capabilities or risk profile, and arithmetic does not answer that.
Feeding it your own data usually does not do it. Retrieval is not training. It can still change what the system is for in practice, and it raises a separate set of questions under data protection law that the AI Act does not touch.
A good answer to this question engages with what you actually plan to do. An evasive answer is “that’s a customer configuration matter,” which means you own it and they would rather not say so.
Question No. 4: When They Change the Model
When you change the model behind this, how will we know, and what changes for us?
It is whoever makes a substantial modification who picks up the provider obligations, so a vendor-side swap usually stays theirs. What it breaks is yours: the assessment you did on the old model, and whatever you built on top of it. From December 2027, Article 26 requires deployers to operate a high-risk AI system in accordance with its instructions for use and to monitor it against them, which assumes the AI system in front of you is the system the instructions describe.
There will be a document that answers this. Article 13(3)(c) puts into the instructions for use “the changes to the high-risk AI system and its performance which have been pre-determined by the provider at the moment of the initial conformity assessment, if any.” Ask for the draft of it now.
There is an open question underneath that. Article 43(4) says pre-determined changes do not amount to a substantial modification, so no fresh conformity assessment is triggered. Its second subparagraph opens with a condition: “For high-risk AI systems that continue to learn after being placed on the market or put into service.”
Read strictly, the relief only reaches systems that keep learning in deployment. Read another way it changes nothing, because Article 3(23) already defines a substantial modification as a change “not foreseen or planned in the initial conformity assessment,” and a pre-determined change is foreseen by definition. On the second reading the subparagraph is confirming what the definition already said.
I do not think that is settled, and it is one of the things the Article 96 guidelines on substantial modification will have to answer. Ask the vendor anyway. Whichever reading wins, they should know which category their AI system is in.
A good answer includes notice, a changelog and a named person. An evasive answer is “we continuously improve the product,” which is basically a yes.
Question No. 5: Will You Put It in the Contract
Will you give us what we need to meet our own obligations, and will you put it in the contract?
Where a system is high-risk, Article 25(4) makes the provider and the third parties supplying into it set out in writing what information, capabilities and technical access get handed over. The Digital Omnibus widened it this summer: the list used to read “an AI system, tools, services, components, or processes,” and it now reads “an AI system, AI model, tools, services, components, or processes.” The model is listed now.
The same amendment did something else. Article 99 sets the penalty tiers, and the Omnibus added a new point to paragraph 4 covering Article 25(2) and Article 25(4). Fifteen million euro or three percent of worldwide annual turnover, whichever is higher.
Not today. Article 25 applies from December 2027. From then, not having the written agreement is the infringement.
There are two limits on the duty. It runs between the provider of the high-risk AI system and its suppliers, so if you are the deployer rather than the provider, your hook is different: the instructions for use the provider will owe you under Article 13, which covers accuracy metrics, known limitations, oversight measures, expected lifetime and how to read the logs. And Article 25(4) does not reach third parties making tools, services, processes or components publicly available under a free and open-source license, unless what they are supplying is a general-purpose model. Some of what is in your stack has no counterparty to sign anything.
Expect Article 25(5) to be quoted back at you, because it preserves intellectual property rights, confidential business information and trade secrets. Read what it is addressed to. It is expressed as without prejudice to paragraphs 2 and 3, which are the handover duties that bite when a role transfers. Paragraph 4 is not in its list, and paragraph 4 is an obligation to agree what will be shared rather than an order to disclose.
A good answer to this question is a clause. An evasive answer is a reassurance.
Either way, ask before signing. After signing it is a favor.
The Five Questions, in One Place
Under the EU AI Act, are you the provider of this system, or are we?
What is the intended purpose of this system, as you have declared it?
If we fine-tune this, or connect it to our own data, does that change your answer about who the provider is?
When you change the model behind this, how will we know, and what changes for us?
Will you give us what we need to meet our own obligations, and will you put it in the contract?
What to Do with the Answers
Send them to the vendor’s legal or compliance contact rather than the account executive. An account executive’s answer is not an answer, and later it will be characterized as sales talk.
Date what comes back and keep it. Not because a wrong answer to you is an offense in itself. It matters because these answers are what you will be repeating when someone (potentially the regulator) eventually asks how you decided, and a dated file showing what you were told is the difference between a decision and a guess.
A refusal to answer is also a finding. It is the one you want on file before the argument rather than after.
If you want somewhere to start on the drafting of the contractual clauses, the Commission’s Public Buyers Community published model contractual clauses for AI procurement in March 2025, in a high-risk version and a lighter one, with commentary. They are not binding on anyone, and they are free.
The Other Fifteen Questions Worth Asking
These five questions settle your role and classification. They are the questions where a wrong answer costs you a reclassification, which is painful and fixable.
The ones I have not published here settle whether you can prove it, which is a different problem, because the moment to fix that one is before signing.
Four of them ask for documents the AI Act will entitle you to from December 2027 and which no vendor has to prepare today. Four are not AI Act questions at all, which is exactly why an AI Act review misses them. One is about the prohibitions, which are the only part of this you could be breaching already. And one is the only question in the set about ending the relationship, which is the part the AI Act says nothing about.
All twenty questions will be available in Scope, which opens this fall.
Scope is where this becomes something you can use in practice: the regulation map, the role assignment, the vendor questions, the AI inventory spreadsheet, the AI policy template, with sources attached and kept current as the law changes.





Question four is the one that doesn't resolve once and stay resolved. A recent industry ledger counted 89 model-ID retirements across ten vendors this year; notice periods were computable for 51 of those and ranged from 39 to 184 days, a spread of over four months between fastest and slowest. Nailing that down at signing settles today's model. That spread means the same question may need a different answer the third time the model changes.
That points at a gap underneath the incentive argument. Vendors answer now partly because the clock hasn't started, but also because most vendor-risk processes are built to ask once, at procurement, with no mechanism to reopen dormant questions when a live contract's underlying model changes. Getting the answer in writing protects the deal you signed. It says nothing about the one three model updates from now.
The role question has one answer no vendor statement can override: Article 25(1) turns a deployer into a provider by operation of law. Putting your own name or trademark on a high-risk system already on the market, making a substantial modification that keeps it high-risk under Article 6, or changing its intended purpose each pulls the full Article 16 provider obligations onto the buyer. Point (a) allows contractual reallocation; (b) and (c) do not. Same 2 December 2027 and 2 August 2028 dates apply, so the wording that matters sits in the signed statement of work, not in the compliance answer.