Buying AI services after 2 August 2026: the three axes for vetting suppliers
From summer 2026 you buy AI services on AI Act conformity, ISO/IEC 42001 governance and contractual audit rights. Learn how to build these criteria.
From 2 August 2026, you must vet AI service suppliers on three axes: their conformity with the EU AI Act for the service's risk category, a demonstrable AI governance system such as ISO/IEC 42001, and contractually fixed audit rights, data provenance and incident response procedures. Request the supporting documents at the RFP stage and make them selection knock-outs.
An analysis of 10 September 2026 of AI Act obligations for high-risk systems and general-purpose AI in procurement argues that from 2 August 2026, these obligations become enforceable and can be reflected directly in procurement documents through model contract clauses. The Community of Practice on Public Procurement of AI has produced ready-made contract text for transparency, risk management, data governance and human oversight. In our assessment, this marks the point at which AI procurement shifts from a feature question to an evidence question: suppliers who cannot provide substantiation now drop out at selection stage.
What changes in your procurement process?
The shift is operational, not rhetorical. Suppliers must now produce three categories of evidence before you sign. First, they must demonstrate conformity with the AI Act for the specific risk category of the service you are buying. For high-risk systems—AI used in recruitment, credit assessment or healthcare—this means CE marking, registration and full documentation. For lower-risk services such as knowledge assistants or internal tooling, the bar is lower but not zero. Second, they must hold or be able to evidence ISO/IEC 42001 certification at the scope that covers the service you are procuring, not merely at organisational level. Third, they must accept contractual audit rights, data provenance documentation and defined incident response procedures.
Make these three layers a single scorecard with explicit knock-out criteria. This prevents a service from appearing legally compliant while offering no contractual audit right, and aligns governance for privacy, cyber and AI into one framework rather than separate silos.
Which governance artefacts must you request?
Do not ask only for the ISO/IEC 42001 certificate. Request the underlying artefacts that demonstrate the standard's requirements:
- Scope and policy documentation — confirmation that the certification scope covers the specific service you are procuring, not another part of the organisation.
- Role allocation and responsibility matrices — evidence of defined roles for AI governance, risk management and oversight.
- Risk analysis and lifecycle controls — documented risk assessments and controls across the model's development, deployment and monitoring phases.
- Data management procedures — records of data provenance, retention policies and third-party model handling.
- Monitoring and audit logs — systems for ongoing performance monitoring and internal audit trails.
- Incident response procedures — defined processes for detecting, reporting and remediating failures or breaches.
What contractual terms must you fix?
The procurement documents must specify audit rights and evidence availability before you sign. Establish these as numbered requirements:
- Right to audit the supplier's AI governance system — contractual entitlement to inspect ISO/IEC 42001 artefacts and controls on demand or on a defined schedule.
- Right to access AI Act compliance documentation — access to risk assessments, conformity declarations and CE marking records where applicable.
- Data provenance and lineage records — the supplier must provide documented evidence of where training data came from, how it was processed and what retention periods apply.
- Incident notification and response timelines — defined procedures for the supplier to notify you of failures, security incidents or regulatory breaches, with specified response times.
- Right to audit logs and model outputs — access to system logs, decision records and model outputs for verification and audit purposes.
- Exit and portability procedures — documented processes for data return, model transfer or service discontinuation if the contract ends.
How does risk category affect your selection criteria?
The AI Act imposes heavier requirements on high-risk systems. If you are procuring AI for recruitment, credit assessment, healthcare or other Annex III uses, suppliers must meet full documentation and registration requirements before you can proceed. For non-high-risk services, the governance bar is lower but audit rights and data provenance remain constant across both categories. The distinction determines which evidence you demand, not whether you demand evidence.
What tooling can and cannot do
Once you have selected and contracted according to these criteria, a verification layer can help make visible which certified service runs in which workflow, which ISO/IEC 42001 artefacts apply to it, and which logs are available for inspection. Such a tool can route tasks through selected models and expose verification steps, corrections and sources for review. It cannot guarantee correctness or assure that models are error-free. The final judgement about a supplier and about every output remains yours. Governance tooling supports your review; it does not replace your professional assessment.
Sources: This article draws on reporting and guidance from Jorpex, AI Workplace Tools, AgentMode AI, NQA and ISO.
Written by
Marit Halversen
Covers AI governance and regulatory design, with a focus on how compliance obligations land on architecture rather than on paperwork.