EU AI Act, AI procurement compliance
The EU AI Act classifies AI systems by risk tier and sets binding obligations on deployers. Know what your use case requires before you procure.
Regulation (EU) 2024/1689 (the EU AI Act) entered into force on 1 August 2024, making the European Union the first major jurisdiction to impose a binding legal framework on artificial intelligence. The Act applies to any organisation that places an AI system into service within the EU market, regardless of where the developer or deployer is based. For buyers commissioning AI-implementation work, the most important single step before procurement is establishing the risk tier of the intended system, it determines the obligations on the provider and, separately, the obligations on you as deployer.
What the EU AI Act is
The Act classifies AI systems into four risk tiers based on the potential harm they pose. Most enterprise AI builds fall into the limited- or minimal-risk categories, but any system touching certain protected domains, employment decisions, access to education, credit scoring, biometric identification, critical infrastructure management, or law enforcement, may be high-risk, with substantially heavier compliance obligations.
Unacceptable-risk systems are prohibited outright. These include systems that manipulate people through subliminal or deceptive techniques, that exploit the vulnerabilities of specific groups, and most real-time remote biometric identification in publicly accessible spaces.
High-risk AI systems fall into two categories. The first covers AI components in products already regulated under EU harmonisation legislation (medical devices, machinery, aviation safety equipment) where CE marking obligations apply. The second covers stand-alone AI applications listed in Annex III: biometric categorisation, management of critical infrastructure, access to education and vocational training, employment and worker management, access to essential private services such as credit scoring, law enforcement and judicial risk assessment, and migration and asylum decisions.
For high-risk systems, the obligations before market placement are substantial. Providers must implement a risk management system, use training data that meets defined quality criteria, maintain detailed technical documentation, enable automatic logging, provide transparency information to deployers, enable human oversight, and demonstrate accuracy and robustness. Deployers of high-risk systems carry their own obligations, including conducting a fundamental rights impact assessment in certain cases.
The Act also introduces obligations for providers of general-purpose AI (GPAI) models, large foundation models that can be used across many tasks. All GPAI providers must supply technical documentation and comply with copyright transparency requirements. Providers of GPAI models with systemic risk (defined by a training compute threshold of 10²⁵ floating-point operations) face additional obligations including model evaluation, adversarial testing, and incident reporting to the European AI Office.
What it means for buyers choosing a provider
The Act places obligations on both providers (those who develop AI systems) and deployers, those who put them into use. If you commission a system and then operate it within the EU, you are the deployer. High-risk deployers must use the system in accordance with the provider's instructions, implement human oversight where required, and suspend use if the system presents a risk that the provider has not addressed.
Risk classification should happen before procurement, not after contract signature. A provider who cannot classify your intended use case by risk tier, naming the relevant Annex III category if it may be high-risk, either has not examined the use case or does not know the Act. Either is a procurement signal.
The timeline matters: the prohibition on unacceptable-risk systems applied from 2 February 2025; GPAI model obligations from 2 August 2025; high-risk system obligations under Annex III from 2 August 2026. If you are procuring a system that will be in operation past those dates, the obligations apply to the system as deployed, not only as originally built.
Questions that separate informed providers from uninformed ones
A provider who has delivered EU AI Act-relevant work answers risk-tier questions precisely. A provider who classifies every use case as minimal-risk without examining the use case, or who conflates EU AI Act compliance with GDPR compliance, has not done this before. The questions below are simple to ask and difficult to fake a substantive answer to.
How Trustgent's verification relates
Trustgent's provider profiles include an EU AI Act readiness attribute populated from cross-referenced evidence rather than self-declaration. A provider listed as AI Act-ready at L2 cross-reference level or above has had that attribute checked against sources the provider does not control, documentation, case studies, regulatory filings, third-party publications. We do not certify legal compliance; that is the role of notified bodies and national market surveillance authorities. What we do is distinguish, using our verification spectrum, between a claimed badge and an evidenced one.
Procurement checklist
Before signing a contract for an AI system that may be in scope of the EU AI Act, confirm in writing:
Risk tier classification
Ask the provider to classify your use case by risk tier and, if high-risk, name the specific Annex III category. A correct classification takes minutes for an informed team. A vague or evasive answer is a signal.
Technical documentation
For high-risk systems, Article 11 requires technical documentation before the system is placed on the market. Ask what documentation they produce and whether it follows the format in Annex IV.
Human oversight design
Article 14 requires that high-risk AI systems be designed so deployers can effectively oversee them. Ask how the provider has implemented this for comparable systems they have shipped.
GPAI model compliance chain
If the system uses a GPAI foundation model, the compliance obligations of that model's provider affect the build. Ask how the provider verifies and documents the compliance posture of any GPAI model in the pipeline.
Post-market monitoring provisions
Article 72 requires deployers of high-risk systems to monitor performance after deployment. Ask how the provider builds in the logging and monitoring infrastructure this requires, and who owns it after handover.
How Trustgent's verification relates
Trustgent's earned-verification model means that EU AI Act readiness on a provider profile reflects checked evidence, not a self-asserted badge. We do not issue compliance certificates. We do make the distinction between claimed and evidenced readiness visible to buyers.
Buyer questions
- What is the EU AI Act?
- The EU AI Act (Regulation (EU) 2024/1689) is the European Union's binding legal framework for artificial intelligence, in force from 1 August 2024. It classifies AI systems by risk tier and sets proportionate obligations on providers and deployers, with the heaviest requirements on systems posing significant risks to health, safety, or fundamental rights.
- Which AI systems are high-risk under the EU AI Act?
- High-risk AI systems include those used for biometric identification and categorisation, management of critical infrastructure, access to education, employment and worker management, access to essential private services such as credit scoring, law enforcement risk assessment, migration and asylum processing, and administration of justice. The complete list is in Annex III of the Act.
- Does the EU AI Act apply to organisations based outside the EU?
- Yes. The Act applies to any provider that places an AI system on the EU market and any deployer that operates an AI system within the EU, regardless of where those organisations are headquartered.
- What obligations does the Act place on deployers of high-risk AI systems?
- Deployers must use high-risk systems only in accordance with the provider's instructions, implement human oversight, monitor performance and risks post-deployment, and in certain cases conduct a fundamental rights impact assessment before use under Article 27.
- When do the different EU AI Act provisions take effect?
- The prohibition on unacceptable-risk systems applied from 2 February 2025. GPAI model obligations applied from 2 August 2025. High-risk system obligations under Annex III apply from 2 August 2026.
- Is GDPR compliance the same as EU AI Act compliance?
- No. GDPR governs data protection; the EU AI Act governs the design, development, and deployment of AI systems. They overlap in areas such as data governance for high-risk systems, but each has distinct obligations and compliance with one does not imply compliance with the other.
Editorial guidance, not legal advice. Trustgent is a verified reference index, not a legal adviser. Consult a qualified practitioner for advice specific to your circumstances. Official source: Regulation (EU) 2024/1689 (EUR-Lex).
Regulatory readiness