Evaluating AI Vendors Under EU Rules: A Procurement Checklist

Questions legal, security, and data teams should ask before signing - covering DPA, sub-processors, model change notices, and human oversight.
Procurement teams need checklists that legal, security, and data owners can score independently - before contract signature locks you in.
Data processing and subprocessors
Where is data processed? How are subprocessors notified and approved? What happens on region changes?
Model change management
How are material model updates communicated? Is there a notice period compatible with your risk review cadence?
Human oversight and audit rights
Can you export logs in a format your DPA accepts? Are human review paths contractually guaranteed for high-risk flows?
Incident and exit playbooks
What SLA applies to model outages? How do you export prompts, logs, and training data on exit?
Alignment with EU AI Act roles
Clarify whether you deploy as provider, deployer, or both - and how obligations split in the DPA.
If it is not in the contract, assume it is not in the product.
Meer weten over AI?
Neem contact op voor een gratis intakegesprek en ontdek hoe AI jouw bedrijf kan helpen.

