Back to blog

Blog / Enterprise procurement

EU AI Act Vendor Questionnaire for Buyers and Sellers

Published 21 July 2026·Last updated 21 July 2026·9 min read
Author: ActBrief Editorial·Reviewer: Methodology pending external legal review

Not legal advice. This article is a preliminary technical guide for AI SaaS teams. Always confirm classification and obligations with qualified counsel. Effective dates reflect the Digital Omnibus updates as of July 2026.

Changelog
Updated 21 July 2026: Annex III standalone high-risk obligations deferred to 2 December 2027; Annex I embedded high-risk to 2 August 2028 (Council approval 29 June 2026). Art. 50 transparency remains 2 August 2026.

Why questionnaires replaced “trust us”

Enterprise buyers no longer accept a homepage badge. They send vendor questionnaires covering role under the AI Act, high-risk signals, transparency, oversight, subprocessors, and documentation.

If you buy AI SaaS: use this as a diligence baseline.
If you sell AI SaaS: prepare answers before the RFP lands — empty cells kill deals.

Questionnaire (copy into your RFP)

A. Identity & role

  1. Legal entity name and country of establishment
  2. Are you a provider, deployer, both, or GPAI provider for the offered system?
  3. Do you place the system on the EU market or is output used in the EU?

B. System description

  1. Intended purpose (one paragraph)
  2. List of AI features in scope of this contract
  3. Output nature: determines / ranks / preparatory / assistive
  4. Does the system materially influence decisions about people?
  5. Does it profile natural persons?

C. Classification hypothesis

  1. Annex III category candidates (if any)
  2. Art. 6(3) facts you rely on (if claiming not high-risk)
  3. Effective dates you are planning to: Art. 50 2 August 2026; Annex III 2 December 2027

D. Transparency (Art. 50)

  1. How are users informed they interact with AI?
  2. How is AI-generated content labelled (if applicable)?
  3. Link or screenshot of in-product disclosure

E. Human oversight & logging

  1. Describe human review / override path
  2. What is logged (input ref, model version, output, human decision)?
  3. Is logging treated as legal (high-risk) or recommended practice?

F. Models & subprocessors

  1. Model providers and versions
  2. Personal data sent to each vendor
  3. DPA / training opt-out / region of processing
  4. Subprocessor list and change notice process

G. Documentation pack

  1. System card available? (Y/N + attach)
  2. Human oversight SOP available?
  3. Vendor inventory available?
  4. Open legal questions remaining?

H. Incidents & changes

  1. Material change notification SLA
  2. Incident contact and last review date

How sellers should answer without overclaiming

Ready artefacts

Close the gaps before the RFP

Get a free readiness brief for your product — then answer the questionnaire with sources, confidence, and missing facts instead of marketing language.


Not legal advice. Questionnaire answers are diligence inputs; classification remains fact- and counsel-specific.

Official sources

Ready for legal review?

Get a free readiness brief for your product — not a commodity risk label.

Get a free readiness brief for your product