EU AI Act Contracts: What the Law Requires (2026 Guide)
Regulation (EU) 2024/1689 mandates specific written contract terms between AI suppliers. Here is what the EU AI Act requires in your vendor agreements by article.
Generate a data processing agreement in 60 seconds
Describe what you need in plain English. A panel of AI agents (Researcher, Drafter, Critic, Validator, Adversary) writes a review-ready draft you can edit, sign, and send.
What does the EU AI Act require in your contracts?
Regulation (EU) 2024/1689 directly mandates written contract terms between commercial parties. Article 25(4) requires providers of high-risk AI systems and their component suppliers to enter into a written agreement covering information access, technical capabilities, and compliance assistance. Article 26 imposes deployer obligations that no vendor contract can transfer away. Standard MSAs and SaaS agreements do not contain these clauses.
Key takeaways
- Article 25(4) of Regulation (EU) 2024/1689 makes a written supplier agreement legally mandatory for every high-risk AI supply relationship — this is a contract term the law requires, not a best practice.
- Article 26 deployer obligations — human oversight, log retention, incident reporting — cannot be contractually shifted to a vendor; the regulatory exposure stays with the deployer.
- Prohibited AI practices (Article 5) have been enforceable since 2 February 2025; Article 50 transparency obligations took effect 2 August 2026; high-risk Annex III standalone obligations apply from 2 December 2027 (Digital Omnibus, Council final adoption 29 June 2026).
- Fines under Article 99 reach €35 million or 7% of global annual turnover for prohibited-practice violations — exceeding the GDPR maximum.
- The European Commission published free Model Contractual Clauses for AI (MCC-AI) on 5 March 2025; private companies may use them as a drafting baseline.
Why does the EU AI Act mandate contract terms between private parties?
Most data regulations govern behavior internally. The EU AI Act goes further — it dictates what private commercial parties must put in their agreements with each other.
Article 25(4) is the clearest example. It states that the provider of a high-risk AI system and any third party supplying tools, services, components, or processes used in that system shall, by written agreement, specify the necessary information, capabilities, technical access, and other assistance to enable the provider to fully comply with the Regulation. This is not a drafting suggestion. It is a statutory requirement embedded in Regulation (EU) 2024/1689.
The parallel to GDPR is exact. Just as GDPR Article 28 required data controllers and processors to document their relationship in a Data Processing Agreement, the EU AI Act requires a new category of written agreement across the AI supply chain. The two instruments often apply simultaneously: an AI system that processes personal data triggers both a GDPR Article 28 DPA and an Article 25(4) supply-chain agreement. Neither alone is sufficient.
Article 25 also reshuffles who counts as a "provider" — and therefore who inherits the contract obligation. Under Article 25(1)(a), any party that puts its own name or trademark on a high-risk AI system already on the market becomes a provider, with full Article 16 obligations. A SaaS company reselling a foundation model under its own brand does not escape provider status because it did not train the model. That reclassification triggers a mandatory written cooperation agreement with the original developer under Article 25(2).
How does the provider/deployer split change your AI vendor agreements?
Regulation (EU) 2024/1689 Article 3 defines the two primary roles. A provider (Article 3(3)) develops or places an AI system on the market under its own name. A deployer (Article 3(4)) uses an AI system in a professional context without having built it. The distinction determines which obligations attach — and which a contract can or cannot redistribute.
Most enterprises buying vendor AI software are deployers. Most SaaS platforms selling AI-powered products are providers. The line blurs in three classic situations: white-labelling (deployer becomes provider under Article 25(1)(a)), substantial modification (Article 25(1)(b)), and repurposing a general AI system for a high-risk use case (Article 25(1)(c)).
| Your scenario | Your role | Key contract action required by the Regulation |
|---|---|---|
| Building a high-risk AI product using third-party APIs | Provider | Article 25(4) written agreement with API vendor; Article 11 technical documentation clause |
| Buying a vendor's high-risk HR screening tool | Deployer | Verify Article 13 instructions are contractually supplied; Article 26 duties remain yours |
| White-labelling a vendor's AI system under your brand | Becomes Provider (Art. 25(1)(a)) | Article 25(4) written cooperation agreement with original vendor; full Article 16 obligations |
| Integrating a GPAI model via API into a new product | Provider of resulting system | Article 53 GPAI documentation from upstream; your own downstream instructions for use |
| Substantially modifying an existing high-risk AI system | Becomes Provider (Art. 25(1)(b)) | Must receive documentation from original provider; full Article 16 obligations |
| Distributing or importing a high-risk AI system into the EU | Importer/Distributor | Article 23/24 written verification of conformity documentation before EU market entry |
Understanding this table is the prerequisite to drafting any AI-related agreement. A party that misidentifies its role — signing a deployer-style contract when it is legally a provider — is exposed to Article 99 penalties regardless of what the contract says. This is one reason AI's growing role in the legal industry includes contract risk classification, not just document generation.
What must an EU AI Act-compliant AI vendor contract contain?
Here is what specific articles of Regulation (EU) 2024/1689 require to appear in written agreements — confirmed against the official text.
Article 25(4) — mandatory for every high-risk AI supply relationship:
- Specification of the information the upstream supplier must deliver (training data provenance, accuracy benchmarks, known failure modes)
- The technical access and capabilities the upstream supplier must provide to support conformity assessment
- Assistance obligations to enable the downstream provider's full compliance
- Protections for intellectual property and trade secrets within these disclosures
Article 13 — pass-through obligations the provider must contractually deliver to the deployer:
- Instructions for use covering the system's intended purpose, accuracy levels, and known limitations
- Human oversight implementation guidance
- Conditions under which the AI system should not be deployed
Article 26 — obligations the deployer cannot shift to the vendor (but which the vendor contract must support):
- Access to the system's automatically generated logs (Article 26(6) — minimum retention period defined in the Regulation)
- A working incident notification channel (Article 26(5))
- Updated instructions upon any substantial modification to the system
Article 25(2) — for reclassified-provider situations:
- The original provider's continuing cooperation obligation
- A written statement if the original provider specifies the system must not be reclassified as high-risk
The European Commission's MCC-AI (published 5 March 2025) adds further clauses around AI system description annexes, data use and dataset ownership, audit rights, conformity documentation warranties, and incident notification timelines. These clauses are not mandatory for private parties but align directly with Chapter III of the Act and serve as the best available drafting template. When creating a master services agreement for any AI-enabled product relationship, these elements should form a dedicated AI addendum.
What does an EU AI Act-compliant contract clause actually look like?
Here is a concrete before/after comparison showing how a standard SaaS warranty clause must change for a high-risk AI system.
Before — standard SaaS MSA language:
"Vendor warrants that the Services will conform to the Documentation in all material respects during the subscription term."
This clause does nothing for Article 25(4). It specifies no information access, no technical documentation, no instructions for use, no modification notification, and no logging access. A deployer operating under this clause has no contractual mechanism to discharge its Article 26(1) obligation to use the system according to the provider's instructions — because those instructions are not contractually guaranteed to exist.
After — Article 25(4) and Article 13-aligned addendum language:
"For any component of the Services that is, or becomes classifiable as, a high-risk AI system under Annex III of Regulation (EU) 2024/1689, Vendor shall: (a) supply technical documentation satisfying Article 11, including training data provenance, accuracy and robustness benchmarks, and known limitations; (b) supply instructions for use meeting Article 13, including human oversight requirements and conditions under which the system must not be deployed; (c) notify Customer in writing within 15 calendar days of any substantial modification as defined in Article 6(3) of the Regulation; (d) confirm that the system generates automatic logs as required by Article 12, and grant Customer access to those logs on request for the retention period specified in Article 26(6); and (e) cooperate with Customer's conformity assessment process, including provision of technical access to test environments on reasonable request."
This is structural guidance, not legal advice. A qualified attorney should adapt this language to your specific supply relationship. But it illustrates the gap between a generic warranty and what Article 25(4) actually requires. When reviewing any AI vendor contract, run each of the five items above as a checklist against the existing text.
For SaaS agreements involving AI features, the AI addendum should be a standalone schedule rather than an amendment to the general warranty clause — this keeps AI-specific obligations clearly visible during audits and reduces the risk of an update to the standard terms silently overriding compliance provisions.
When do EU AI Act contract obligations come into force?
The Digital Omnibus on AI received final Council approval on 29 June 2026, after the European Parliament endorsed it on 16 June 2026. The revised enforcement calendar is:
| Obligation | Status as of 2 August 2026 |
|---|---|
| Prohibited AI practices — Article 5 | In force since 2 February 2025 |
| AI literacy obligation | In force since 2 February 2025 |
| GPAI model obligations — Articles 51–55 | In force since 2 August 2025 |
| Article 50 transparency obligations (AI interaction disclosure) | In force as of today, 2 August 2026 |
| Article 50(2) watermarking (for legacy systems) | Applies 2 December 2026 |
| High-risk Annex III standalone systems | Applies 2 December 2027 (Digital Omnibus) |
| High-risk Annex I embedded systems (medical devices, machinery) | Applies 2 August 2028 (Digital Omnibus) |
Update — 2 August 2026: Article 50 transparency obligations are now in force. Any AI system that interacts with a natural person must disclose that it is AI, and AI-generated or manipulated audio, image, video, or text content must carry a machine-readable marking. This obligation was not touched by the Digital Omnibus delay — it applies today, on schedule. Two points matter for contract planning right now. First, your services agreement with any vendor deploying a customer-facing AI system should require written confirmation that a compliant disclosure mechanism is live, not just planned. Second, GPAI model obligations already apply — if your product is built on a foundation model API, obligations under Articles 51–55 have applied since August 2025, making upstream GPAI documentation terms an immediate, not future, contract requirement.
Fines under Article 99 reach €35 million or 7% of global annual turnover for prohibited-practice violations. Violations involving high-risk AI systems carry up to €15 million or 3% of global turnover. These ceilings exceed GDPR's maximums. For a company with €1 billion in revenue, a single prohibited-practice fine could reach €70 million.
Common mistakes to avoid
- Treating Article 26 as a vendor obligation. Deployer duties cannot be transferred. A contract requiring the vendor to "ensure AI Act compliance" gives you financial recourse, not regulatory protection. The Article 26 obligation to assign trained human oversight sits with the deployer, always.
- Rebranding AI without reading Article 25(1)(a). Putting your trademark on a third-party AI system makes you the provider. The vendor's standard license terms do not document this reclassification, and most do not include the Article 25(2) cooperation framework required once reclassification occurs.
- Using a DPA as the only AI contract. A GDPR Data Processing Agreement governs personal data flows. It does not satisfy Article 25(4) supply-chain documentation obligations. Both instruments are typically required simultaneously for any high-risk AI system handling personal data.
- Ignoring the GPAI track. GPAI obligations under Articles 51–55 have applied since 2 August 2025. Contracts with foundation model providers must address downstream-use permissions, copyright compliance, and — for systemic-risk models — incident notification obligations.
- No substantial-modification clause. If a vendor significantly updates a model, Article 6(3) defines this as a potential substantial modification that resets conformity obligations. Contracts should require advance written notice — 15 to 30 days is a practical standard — before any model update that materially changes capability or risk profile.
- Missing the August 2026 transparency deadline. Article 50 took effect on 2 August 2026 and was not covered by the Omnibus extension. If you haven't already, review every customer-facing AI tool in your stack now to confirm compliant disclosure is in place or contractually required.
Sources
- Regulation (EU) 2024/1689 of the European Parliament and of the Council — the EU AI Act, Official Journal: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689
- EU AI Act Article 25 — Responsibilities along the AI value chain, AI Act Service Desk (European Commission): https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-25
- EU AI Act Article 26 — Obligations of deployers of high-risk AI systems, AI Act Service Desk (European Commission): https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26
- Model Contractual Clauses for AI Procurement (MCC-AI), European Commission Public Buyers Community (updated 5 March 2025): https://public-buyers-community.ec.europa.eu/communities/procurement-ai/resources/updated-eu-ai-model-contractual-clauses
- Guidelines for providers of general-purpose AI models, European Commission (18 July 2025): https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers
- Artificial Intelligence: Council gives final green light to simplify and streamline rules (Digital Omnibus final adoption), Council of the EU (29 June 2026): https://www.consilium.europa.eu/en/press/press-releases/2026/06/29/artificial-intelligence-council-gives-final-green-light-to-simplify-and-streamline-rules/
- EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes, Gibson Dunn: https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/
- EU model contractual clauses for AI procurement: A practical guide, IAPP: https://iapp.org/news/a/eu-model-contractual-clauses-for-ai-procurement-a-practical-guide
This article is general information, not legal advice. Laws vary by jurisdiction. Pactlio generates professional drafts for review — have a licensed attorney review anything important.
Frequently Asked Questions
Does the EU AI Act require written contracts between AI suppliers?▾
Yes. Article 25(4) of Regulation (EU) 2024/1689 mandates that providers of high-risk AI systems and their third-party component suppliers enter into a written agreement. The agreement must specify the information, technical access, and assistance needed for the provider to meet its obligations under the Act.
Can you shift EU AI Act liability to your AI vendor by contract?▾
No. Article 26 obligations fall on the deployer directly and cannot be transferred by contract. A contractual indemnity can create financial recourse against a vendor, but the regulatory duty to implement human oversight, maintain logs, and follow instructions for use remains with the deployer regardless of what the agreement says.
What is the difference between a provider and deployer under the EU AI Act?▾
A provider (Article 3(3)) develops or places an AI system on the market under its own name. A deployer (Article 3(4)) uses an AI system in a professional context without building it. Most enterprises buying vendor AI are deployers. SaaS vendors reselling AI under their own brand are typically providers.
When do EU AI Act contract obligations apply?▾
Prohibited AI practices (Article 5) apply since 2 February 2025. GPAI model obligations (Articles 51–55) apply since 2 August 2025. Article 50 transparency obligations took effect on 2 August 2026. High-risk Annex III standalone system obligations now apply from 2 December 2027 following the Digital Omnibus (Council adoption 29 June 2026).
Is the EU AI Act Article 50 transparency obligation in effect now?▾
Yes. Article 50 of Regulation (EU) 2024/1689 took effect on 2 August 2026 and was not delayed by the Digital Omnibus. Any AI system that interacts with a natural person must now disclose that fact, and AI-generated or manipulated content must be machine-readably marked. Vendor contracts signed or renewed after this date should require written confirmation that disclosure mechanisms are active.
What is the MCC-AI and should private companies use it?▾
The Model Contractual Clauses for AI (MCC-AI) were published by the European Commission on 5 March 2025, primarily for public sector procurement. They come in High-Risk and Light versions and follow Chapter III of the EU AI Act. Private companies can use them as a useful baseline when drafting or auditing AI vendor agreements.
If I rebrand a vendor's AI tool, what happens to my contract obligations?▾
Under Article 25(1)(a), putting your name or trademark on a vendor's high-risk AI system makes you the provider — with full Article 16 obligations. Your contracts must then include an Article 25(4) written cooperation agreement with the original vendor, covering technical documentation, conformity documentation, and modification notification.
What log retention does the EU AI Act require deployers to maintain?▾
Article 26(6) requires deployers to retain automatically generated logs of high-risk AI systems for the period specified in the Regulation. Multiple regulatory analyses cite six months as the baseline. Deployers must verify at contract stage that their vendor's system generates logs by default and that deployer-side access is contractually guaranteed.
Does a standard SaaS agreement cover EU AI Act compliance automatically?▾
No. Standard SaaS or MSA agreements do not contain the role declarations, instructions-for-use warranties, conformity documentation requirements, substantial-modification notifications, or incident-reporting obligations required under the EU AI Act. Each must be added to existing agreements or addressed in an AI-specific addendum.