The EU AI Act creates a new category of contract risk that most organisations have not yet addressed. If your vendor uses AI in the services they provide, or if you provide AI-powered services to customers, the AI Act's allocations of responsibility between providers and deployers must be reflected in your contracts. Where they are not, liability exposure sits with the party who cannot demonstrate they met their obligations — which in most current contracts is ambiguous.
The Provider/Deployer Distinction
The AI Act creates two primary roles:
Provider: The entity that develops or places on the market an AI system. For most enterprise software, the SaaS vendor is the provider of the AI system.
Deployer: The entity that uses the AI system in a professional context. For most enterprise software customers, they are deployers of whatever AI the vendor has built into the product.
The AI Act's obligations differ significantly by role. Where a contract does not clearly allocate these roles, both parties may have unclear obligations — and may be unintentionally assuming obligations that the other party should carry.
Key Contract Risks by AI System Category
High-Risk AI Systems
If a vendor's product includes a high-risk AI system (Annex III categories — recruitment, credit scoring, safety-critical systems, biometric identification, education, law enforcement, migration), the contract must address:
Provider obligations that need contractual support:
- Technical documentation must be maintained and available
- Conformity assessment must be completed before deployment
- EU AI database registration must occur
- Post-market monitoring must be in place
Deployer obligations that need contractual support:
- Deployers must use the AI system according to the provider's instructions
- Deployers must implement human oversight as specified by the provider
- Deployers must log system use, with logs retained for at least 6 months (3 years for certain categories)
- Deployers must have a fundamental rights impact assessment (FRIA) for certain uses
- Deployers must report serious incidents to the market surveillance authority
Contract risk: If the vendor's product includes a high-risk AI system and the customer does not know this, the customer is an unknowing deployer with unmet obligations. This risk materialises when the customer is investigated for a deployment of the AI system that caused harm.
General Purpose AI (GPAI) Systems
If a vendor's product is built on a GPAI model (GPT-4, Claude, Gemini, Llama), or the vendor provides a GPAI-based service:
The GPAI provider's obligations:
- Training data transparency documentation (summary publicly available)
- Copyright compliance for training data
- Systemic risk assessment (for models above 10^25 FLOP threshold)
Downstream deployer obligations:
- GPAI model capabilities and limitations must be understood before deployment
- Purpose limitations in training data licences may restrict commercial use
Contract risk: Many SaaS products are built on GPAI APIs (OpenAI, Anthropic). If a vendor builds on these APIs and the customer does not know this, the customer cannot assess whether the deployment is appropriate for regulated use cases (financial advice, healthcare, legal services) where GPAI limitations may create liability.
Limited Transparency AI Systems (Chatbots, Deepfakes)
If a vendor's product includes chatbots or AI that generates content:
Article 50 obligations: Chatbots must disclose they are AI. AI-generated content in certain categories must be labelled. Deepfake content must be labelled as artificially generated.
Contract risk: If a customer deploys a vendor's chatbot without understanding their Article 50 disclosure obligations, the customer is the deployer who is non-compliant — not the vendor. The contract should specify what disclosures are needed and who is responsible for implementing them.
What's Missing from Most AI Vendor Contracts
No AI Classification Disclosure
Most SaaS vendor contracts do not disclose:
- Whether the product contains an AI system
- If so, what AI Act risk category it falls into
- What technical documentation exists
- Whether conformity assessment has been completed
A customer signing a contract with no AI disclosure cannot meet their deployer obligations for any high-risk AI they unknowingly deploy.
No Human Oversight Specification
High-risk AI deployers must implement human oversight. The provider must specify what human oversight mechanisms are required. Most SaaS contracts say nothing about this — leaving the deployer without guidance on a mandatory obligation.
No Incident Reporting Allocation
AI Act Article 73 requires deployers to report serious incidents to market surveillance authorities. Most contracts do not specify:
- What constitutes a serious incident
- How the vendor supports incident investigation
- What information the vendor will provide to the deployer for regulatory reports
No Fundamental Rights Impact Assessment Support
For certain high-risk AI deployments (public sector, healthcare, financial services), deployers must conduct a fundamental rights impact assessment (FRIA). The contract should specify what information the vendor provides to support this — most do not.
Contract Clauses to Add for AI Act Compliance
AI classification disclosure clause: Vendor discloses whether the product contains AI systems, their risk classification under the AI Act, and whether the product is subject to Article 50 transparency requirements.
Technical documentation access: For high-risk AI: vendor commits to provide technical documentation required for deployer obligations; provides access to EU AI database registration.
Human oversight guidance: Vendor specifies the human oversight mechanisms required by the AI system's design and the deployer's implementation obligations.
Incident notification: Vendor notifies customer within a specified timeframe of serious incidents involving the AI system. Customer's reporting obligations to market surveillance authorities are acknowledged.
GPAI provenance disclosure: If the product is built on GPAI APIs, the underlying model(s) are disclosed. Restrictions on use from GPAI providers' terms are passed through.
Training data confirmation: For products involving AI that processes customer data for training: confirmation of whether customer data is used for training, and on what legal basis.