The classic trap
Recital 90 announces voluntary model contractual terms between providers of high-risk AI systems and their upstream suppliers (foundation models, datasets, MLOps components, annotation services). Pending their publication by the Commission, most current AI vendor contracts are silent on AI Act obligations: transparency on training data, cooperation on serious incidents under Article 73, access to logs under Article 12, technical documentation under Annex IV. When the EU AI Office requests evidence, the high-risk system provider cannot obtain it from upstream suppliers and bears the full sanction alone (up to 15 M EUR or 3% of global turnover for breach of Article 16 obligations).
What your AI vendor contracts must contain today
Without waiting for the Commission's model clauses, your AI value chain must be contractually locked on the following points:
- Obligation for upstream suppliers (foundation model, dataset, component) to deliver documentation needed for Annex IV technical file.
- Cooperation commitment in case of EU AI Office or national authority investigation, with enforceable response deadlines.
- Immediate notification of serious incidents and malfunctions (Article 73) cascaded along the chain.
- Access to logs and training traces needed for Article 12 compliance and Article 14 human oversight.
- Warranty on training data compliance (Article 10) and IP rights, particularly for protected content.
- Articulation with GDPR (Article 28) and with DORA for financial entities using AI in critical outsourcing.
- Audit clause and verification rights on site or remotely, aligned with EDPB standard.
- Technical file transfer mechanism in case of upstream supplier termination.
How Luxgap automates this risk
Our Luxgap AI Supply Chain Contracts turns your AI vendor contracts into an enforceable chain of responsibility, without waiting for the Commission's model terms. The tool ingests your existing contracts from Odoo, DocuSign, SharePoint and your CLM, analyses them via an LLM agent trained on the AI Act and the AI Liability Directive, then produces a line-by-line gap analysis between current clauses and Articles 16, 25, 72 and 73.
- Automatically detects each upstream supplier involved in a high-risk AI system by cross-checking your accounting invoices, API agreements and cloud integrations (Azure OpenAI, AWS Bedrock, Hugging Face, Mistral, Databricks).
- Classifies each relationship along the AI Act grid: general-purpose model provider, component provider, dataset provider, annotation service, inference host.
- Generates ready-to-sign addenda that add missing AI Act clauses to your existing contracts, without full renegotiation.
- Continuously aligns with future Commission model clauses upon their publication, with automatic template updates.
- Cross-references with the GDPR Article 30 register and the DORA register of critical ICT providers for CSSF-regulated financial entities.
- Produces a timestamped PDF report enforceable before the EU AI Office or the future Luxembourg AI market surveillance authority, demonstrating Article 16 due diligence.
Available as an add-on to a Luxgap DPO or CISO mandate or as a standalone SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real AI vendor contracts, with a free 48h blind audit to measure your contractual exposure before any engagement.