The AI Act imposes strict obligations on AI system deployers, some of which can be contractually transferred to the provider. This article details the 10 essential clauses to integrate into your AI contracts, with examples and red flags.
The AI Act regulation imposes numerous strict obligations on those who deploy artificial intelligence systems. However, it provides for the possibility of transferring some of these responsibilities to your provider, provided it is done explicitly by contract. This contractual lever, governed by Article 26 and Article 25(1), helps clarify the distribution of roles and legally secure your AI solution purchases.
For procurement managers, DPOs, and legal counsel, this approach offers three major benefits:
Why formalize AI Act obligations with your AI provider
- **Reduce legal risk exposure**: Liability can be shared or transferred, limiting your exposure in case of non-compliance.
- **Facilitate compliance**: The provider handles technical documentation, updates, and specific monitoring obligations.
- **Control costs**: By formalizing audit, maintenance, and incident management, you avoid unforeseen additional costs.
According to the EDPB recommendations from January 2025, this contractual formalization is essential, especially for high-risk systems. Without an explicit clause, the burden of compliance rests entirely on the deployer.
The 10 essential clauses to include in your AI contracts
To ensure the compliance and security of your AI projects, systematically integrate these ten clauses into your contracts with providers. Each clause is accompanied by its legal basis, an example of wording, and red flags to watch for.
1. Delivery of complete technical documentation (Annex IV)
**Issue**: Article 11 requires the provision of exhaustive technical documentation, compliant with Annex IV. This documentation is essential to prove compliance and respond to authorities.
**Example clause**:
> "The Provider shall deliver to the Deployer, prior to any commissioning, complete technical documentation meeting Annex IV of Regulation (EU) 2024/1689, including:
> - general description of the AI system;
> - instructions for use;
> - characteristics, capabilities, and limitations;
> - post-market monitoring measures;
> - residual risks and mitigation actions.
> The Provider guarantees the accuracy and updating of this documentation throughout the duration of the contract."
**Red flags**:
- Refusal to provide detailed documentation under the pretext of trade secrets.
- Documentation that is too generic and not specific to the delivered system.
- Lack of commitment to updates in case of system evolution.
2. Obligation to notify serious incidents within 72 hours
**Issue**: Article 73 requires the rapid notification of serious incidents. This requirement must be extended to the deployer to allow for an appropriate response.
**Example clause**:
> "The Provider undertakes to inform the Deployer of any serious incident, as defined in Article 3(44) of Regulation (EU) 2024/1689, within a maximum period of 72 hours. The notification shall include:
> - description of the incident;
> - identified or suspected causes;
> - corrective measures taken or planned;
> - residual risks for users.
> The Provider shall keep the Deployer informed of follow-up actions with competent authorities."
**Red flags**:
- Notification delay exceeding 72 hours.
- Vague or non-existent notification procedure.
- Refusal to share incident details with the deployer.
3. Annual audit right for the system and compliance
**Issue**: Article 26(5) requires compliance monitoring. An audit right allows for verifying adherence to contractual and legal obligations.
**Example clause**:
> "The Deployer, or a mandated third party, may conduct an annual audit of the AI system and its documentation to verify compliance with Regulation (EU) 2024/1689 and the contract. The audit shall cover, in particular:
> - technical documentation;
> - risk management;
> - data and decision traceability;
> - incident management.
> The Provider shall provide the necessary access and information. Results will be shared, and the Provider shall have 30 days to correct any identified non-compliance."
**Red flags**:
- Audit right limited to a frequency of less than once per year.
- Restricted access to documentation or certain features.
- Absence of a deadline for post-audit compliance.
4. Obligation of information and prior agreement in case of substantial modification
**Issue**: Article 14 requires a re-evaluation of compliance in the event of a major modification. The deployer must be informed and able to validate any significant evolution.
**Example clause**:
> "The Provider shall notify the Deployer of any substantial modification to the AI system (within the meaning of Article 3(23)), at least 30 days before its implementation, specifying:
> - the nature of the modification;
> - the impact on compliance;
> - the planned corrective measures.
> The Deployer shall have 15 days to approve or request adjustments. Without a response, the modification may be deployed subject to legal compliance."
**Red flags**:
- Modification of the system without prior notification.
- No defined deadline for informing the deployer.
- Absence of an impact assessment transmitted to the client.
5. Explicit declaration of the AI system risk level
**Issue**: Article 6 requires the classification of the system according to the risk level. The provider must specify this classification and justify it.
**Example clause**:
> "The Provider declares the risk level of the provided AI system in accordance with Article 6 of Regulation (EU) 2024/1689:
> - [ ] Prohibited system (Article 5)
> - [ ] High-risk system (Annex III)
> - [ ] Limited-risk system (Article 50)
> - [ ] Minimal-risk system
> A written justification for this classification shall be provided. In case of disagreement, the parties shall seek an opinion from the AI Office or a competent authority."
**Red flags**:
- Refusal by the provider to declare the risk level.
- Absence of written justification.
- Attempt to under-classify the system to avoid obligations.
6. Certificate of CE marking compliance before any commissioning
**Issue**: Article 48 requires CE marking for high-risk systems. The deployer must demand proof of this compliance.
**Example clause**:
> "The Provider certifies that the AI system complies with Regulation (EU) 2024/1689 and bears the CE marking, in accordance with Article 48. It shall provide the EU declaration of conformity (Article 47) before any commissioning. In case of non-compliance detected after deployment, the Provider shall take all corrective measures within 15 days."
**Red flags**:
- Inability to provide the EU declaration of conformity.
- CE marking without technical basis.
- No commitment to the rapid correction of non-compliance.
7. Log retention according to Article 12
**Issue**: Article 12 requires the retention of logs for 6 months for high-risk systems. These logs are essential for traceability and investigations.
**Example clause**:
> "The Provider shall retain the AI system logs for at least 6 months, in accordance with Article 12 of Regulation (EU) 2024/1689. The logs shall include:
> - input and output data;
> - operating parameters;
> - decisions or predictions;
> - errors or anomalies.
> They shall be secured and accessible to the Deployer upon request, in an actionable format."
**Red flags**:
- Refusal to retain logs for 6 months.
- Inaccessibility or unreadable format of logs.
- Absence of security measures for logs.
8. Provision of training materials and sessions (Article 4)
**Issue**: Article 4 requires user training. The provider must provide materials and, if possible, offer training.
**Example clause**:
> "The Provider undertakes to provide the Deployer with training materials adapted for safe and compliant use of the AI system, including:
> - detailed user manual;
> - practical guides by use case;
> - online or in-person training modules, if available.
> Upon request, the Provider shall offer training sessions at its standard rates."
**Red flags**:
- Absence of specific training materials.
- Materials that are too generic or incomplete.
- Training sessions at excessive rates.
9. Termination clause for repeated non-compliance
**Issue**: In case of repeated breaches by the provider, the deployer must be able to terminate the contract without fees.
**Example clause**:
> "In the event of recurring failure to comply with contractual or legal obligations, particularly those of Regulation (EU) 2024/1689, the Deployer may terminate the contract with 30 days' notice, without penalty, after two formal notices remain ineffective. The Provider shall refund any sums paid for the period following termination."
**Red flags**:
- Absence of a specific termination clause.
- Financial penalties or excessive notice periods for termination.
- Vague or inapplicable termination procedure.
10. Clear definition of applicable law and competent court
**Issue**: To avoid complex litigation, the contract must specify the applicable law and the competent jurisdiction.
**Example clause**:
> "This contract is governed by French law. Any dispute shall be subject to the exclusive jurisdiction of the courts of Paris, even in the event of multiple parties or third-party claims."
**Red flags**:
- Foreign law imposed without justification.
- Jurisdiction located outside of France or in a third country.
- Absence of a clause on applicable law or jurisdiction.
Global clause template to integrate into your AI contracts
Here is an example of a clause covering the major obligations of the AI Act regulation. Customize it with your legal department:
"The Provider guarantees the compliance of the provided AI system with Regulation (EU) 2024/1689, including:
- technical documentation (Annex IV);
- risk management (Article 9);
- transparency and traceability (Article 12);
- incident notification (Article 73);
- CE marking and EU declaration of conformity (Articles 47 and 48).
The Provider undertakes to:
- transmit complete and up-to-date technical documentation before commissioning;
- notify any serious incident within 72 hours;
- authorize an annual audit of the system and documentation;
- notify any substantial modification at least 30 days before deployment;
- retain system logs for at least 6 months;
- provide necessary training materials.
In case of breach, the Deployer may terminate the contract with 30 days' notice, without penalty. French law applies and any dispute shall be brought before the courts of Paris."
Practical tips for negotiating these clauses with your AI provider
Providers, especially the largest ones, may be reluctant to integrate all these clauses. Here are strategies to defend your interests:
Anticipate main objections
- **Trade secret**: Propose an NDA or an anonymized version for technical documentation.
- **Administrative burden**: Limit the frequency of audits and propose a concerted organization.
- **Additional costs**: Negotiate a flat fee or preferential rates for training.
Leverage business arguments
- **Risk reduction** for all parties thanks to the termination clause.
- **Competitive advantage**: a compliant provider can better market its offerings.
- **Access to public procurement**: compliance is often required to respond to European tenders.
Distinguish non-negotiable and adaptable clauses
- Non-negotiable clauses: technical documentation (Annex IV), notification within 72h, annual audit, termination for non-compliance.
- Adaptable clauses: frequency of audits, log format, training modalities.
Articulation with GDPR and other regulatory texts
AI Act clauses must be articulated with the GDPR and other sectoral regulations to avoid duplication and contradictions.
Complementarity with GDPR
The GDPR already provides for contractual obligations for processors (Article 28). AI Act clauses complement them, for example:
- **Breach notification**: GDPR and AI Act both impose a 72h deadline (Article 33 GDPR, Article 73 AI Act). A single clause may suffice.
- **Audit**: GDPR provides for an audit right, to be supplemented by specific AI Act requirements.
- **Logs**: logs required by the AI Act can also be used to respond to access or explanation rights provided by the GDPR.
Coordination with other sectoral regulations
Depending on your sector, other texts may apply:
- **DORA** (financial sector): requirements on operational resilience and AI risk management.
- **MDR** (medical devices): additional requirements for AI in health.
- **DSA** (digital services): transparency obligations for AI platforms.
To ensure global compliance, designate a lead responsible for coordinating all regulatory requirements, including those of the AI Act regulation.
---
For more details, consult the official text of Regulation (EU) 2024/1689 and its annexes:
For any questions, contact your legal department or an AI compliance specialist.