LinkedInInstagramXTikTok

Buying AI systems: what your business needs to know

Why AI procurement affects more businesses than many think

On 29 June 2026 the Council of the European Union gave its final approval to the Digital Omnibus on AI, the first package of amendments to Regulation (EU) 2024/1689, the AI Act. Most of the attention has gone to the postponed deadlines for high-risk AI systems. That has fed a misconception: that companies buying AI can now lean back and let the vendor carry the compliance burden.

The opposite is closer to the truth. The Omnibus sharpens the rules on how obligations travel through the AI value chain, and it backs the information duties between suppliers and business customers with fines of up to 15 million euros or 3 percent of worldwide annual turnover. For every company that buys, integrates or adapts AI, the contract has become the central compliance document.

What is the AI value chain and why does it matter?

The AI Act does not only regulate the technology companies that build AI. It allocates duties along the entire chain, from the developer of a model to the business that uses the finished system. Article 25 of the AI Act governs that allocation, and it answers a question every buyer should ask before signing: when does my company stop being a customer and become a provider in the meaning of the regulation?

The rule is that a distributor, importer or business user is treated as the provider of a high-risk AI system if it puts its own name or trademark on the system, makes a substantial modification to it, or changes its intended purpose so that the system becomes high-risk. Provider status carries the heaviest obligations in the regulation, including conformity assessment, technical documentation and registration. Many companies cross that line without noticing, for example by white labelling a vendor tool or by repurposing a general system for recruitment decisions.

What does the Omnibus change in vendor relationships?

The amended Article 25(2) spells out what the original provider must give a company that takes over provider responsibility: technical documentation sufficient to assess compliance, information about known limitations and failure modes, and targeted technical access for testing and validation.

The amended Article 25(4) adds AI models to the list of components that, when supplied by a third party for use in a high-risk AI system, must be covered by a written agreement specifying the necessary information, capabilities, technical access and other assistance. Under the amended Article 99(4), breaches of these duties can be fined up to 15 million euros or 3 percent of worldwide annual turnover, whichever is higher.

One important caveat: the Omnibus takes legal effect only once it has been published in the Official Journal of the European Union, which is expected during July 2026. Until then, the amended provisions and dates remain provisional.

What still applies from 2 August 2026?

The postponement of the high-risk obligations, to 2 December 2027 for stand-alone systems under Annex III and to 2 August 2028 for AI embedded in regulated products, does not postpone everything. The transparency obligations in Article 50 were not deferred and have applied since 2 August 2026. If your company uses a chatbot, users must be told they are interacting with AI, and if you publish AI-generated images, audio or video, the content must be labelled.

GDPR also continues to apply in full. When an AI vendor processes personal data on your behalf, Regulation (EU) 2016/679 requires a data processing agreement under Article 28, and you remain controller for the data you feed into the system. An AI contract that ignores data protection is incomplete regardless of what the AI Act says.

A practical example: a growing company buys a screening tool

Picture a Swedish logistics company with 300 employees that licenses an AI tool to screen job applications. Recruitment systems fall under Annex III, so the full high-risk regime will apply from 2 December 2027. The company configures the tool, keeps the vendor branding and uses it as intended, so it remains a business user and does not take over the provider role.

The contract still needs to do real work. The company will need the vendor to cooperate so it can meet its own duties as the user of a high-risk system from December 2027, including instructions for use, human oversight and logging. It needs a data processing agreement for the applicants’ personal data today. And if it later retrains the model on its own data or markets the tool under its own name, it may take over provider responsibility under Article 25, with a right to documentation and technical access from the vendor. A well drafted contract anticipates all three situations.

Common mistakes companies make

The most common mistake is treating AI procurement as ordinary software procurement. Standard SaaS terms rarely cover documentation duties, failure modes or technical access for testing. Another frequent error is assuming that the postponed high-risk dates mean nothing needs to happen before 2027, even though the transparency rules, GDPR and the AI literacy requirement already apply. A third mistake is customising or rebranding a vendor system without checking whether the change triggers provider status. Many companies also sign multi-year AI contracts without a clause on regulatory change and end up locked into terms written for a legal landscape that no longer exists.

Recommended actions

Map every AI system your business buys or plans to buy and note which ones could fall under Annex III, for example tools for recruitment, credit scoring or education. Review your vendor agreements against the amended Article 25 and make sure they secure documentation, information about limitations and technical access. Add a data processing agreement wherever personal data is involved. Decide deliberately whether you want to remain a business user or accept the provider role, and document that decision. Build a regulatory change clause into new agreements so that responsibilities and costs are allocated when the rules evolve. Finally, deal with the transparency duties, which have applied since 2 August 2026, instead of waiting for the high-risk dates.

Frequently asked questions

Do the postponed deadlines mean we can wait until 2027?

No. The transparency obligations in Article 50 have applied since 2 August 2026, the AI literacy requirement and the prohibitions already apply, and GDPR covers all processing of personal data. The postponement to 2 December 2027 concerns only the specific obligations for high-risk AI systems under Annex III.

What should an AI vendor contract always include?

At a minimum, technical documentation, information about known limitations and failure modes, technical access for testing, data protection terms under Article 28 GDPR, a clear allocation of responsibility if your use triggers provider status, and a mechanism for adapting the contract when the regulatory framework changes.

When do the new Article 25 rules take effect?

The Omnibus was adopted on 8 July 2026, published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744, and entered into force on 27 July 2026. It is binding law, not a proposal. The underlying rules on providers and business users in the AI Act already apply.

Conclusion

Many have read the Digital Omnibus as pure relief, but for companies buying AI it is better understood as a reallocation of responsibility. The information duties in the AI value chain now carry real financial consequences, and the contract is where those duties are secured or lost. Companies that review their AI agreements during 2026 will meet the 2027 and 2028 deadlines with far less friction than those that wait. At Lawgent, we help companies design AI vendor contracts, assess provider and user roles and build practical compliance ahead of every AI Act milestone. Get in touch if you would like a review of your AI agreements before the new rules start to apply.

Leave a Reply

Your email address will not be published. Required fields are marked *


0Cart0,00 

No products in the cart.

Return to shop