Skip to main content

EU regulation · European Union

What EU AI Act asks of your vendors

Providers placing AI systems or general-purpose AI models on the EU market, deployers of AI systems located in the EU, and providers and deployers elsewhere whose output is used in the EU (Article 2(1)). In force since 1 August 2024 and applied in phases under Article 113: prohibitions and AI literacy from 2 February 2025 and general-purpose model obligations from 2 August 2025; check the current dates for high-risk systems, which the Commission has proposed to adjust. Regulation (EU) 2024/1689

Check my vendors

3 requirements that reach your vendors

Each provision, the evidence that usually supports it, and how many vendors in the index publish that evidence. Reviewed 21 Sep 2026.

Article 26(1) and Article 13

Use high-risk systems as the provider instructs

Deployers of high-risk AI systems must use them in accordance with the instructions for use, which Article 13 requires providers to supply with the system.

  • AI model and system documentation

    6 vendors in the index

    Model documentation, system cards and training data summaries are what a deployer or integrator reads to use an AI system as intended.

  • AI governance

    144 vendors in the index

    An AI policy, a governance framework or an ISO/IEC 42001 certificate shows the supplier manages AI risk as a system.

Article 53(1)(b)

Documentation from general-purpose model providers

Providers of general-purpose AI models must draw up, keep up to date and make available information and documentation to providers of AI systems who intend to integrate the model.

  • AI model and system documentation

    6 vendors in the index

    Model documentation, system cards and training data summaries are what a deployer or integrator reads to use an AI system as intended.

Article 25(4)

Written terms with suppliers in the AI value chain

The provider of a high-risk AI system and a third party supplying AI systems, tools, services or components used in it must specify by written agreement the information, capabilities, technical access and assistance needed to meet the Regulation.

  • AI governance

    144 vendors in the index

    An AI policy, a governance framework or an ISO/IEC 42001 certificate shows the supplier manages AI risk as a system.

  • Use of customer data for training

    29 vendors in the index

    A published answer on whether customer data trains the supplier’s models.

Vendors publishing the most EU AI Act evidence

Among the most-searched vendors in the index, ranked by how many of the requirements above their public evidence reaches. Open one to see each item with its date and source.

Questions buyers ask

What does EU AI Act require from vendors?

Use high-risk systems as the provider instructs (Article 26(1) and Article 13); Documentation from general-purpose model providers (Article 53(1)(b)); Written terms with suppliers in the AI value chain (Article 25(4)). Each is listed below with the evidence that may support it.

Who does EU AI Act apply to?

Providers placing AI systems or general-purpose AI models on the EU market, deployers of AI systems located in the EU, and providers and deployers elsewhere whose output is used in the EU (Article 2(1)). In force since 1 August 2024 and applied in phases under Article 113: prohibitions and AI literacy from 2 February 2025 and general-purpose model obligations from 2 August 2025; check the current dates for high-risk systems, which the Commission has proposed to adjust.

Is a SOC 2 report enough for EU AI Act?

A SOC 2 report or ISO 27001 certificate may support the security parts of EU AI Act, but use high-risk systems as the provider instructs, documentation from general-purpose model providers, written terms with suppliers in the ai value chain need other evidence. Confirm sufficiency with your counsel or auditor.

Other regulations

All articles

This maps third-party obligations to the vendor evidence that may support them. It is not legal advice and never a statement that a vendor or its customers comply; confirm scope and sufficiency with your counsel or auditor. “No public evidence” means nothing public was found at the last check. Citations link to the official text.