← All insights
IndustryMarch 1, 20268 min readAgentWorks Editorial

Evaluating AI Vendors Under EU Rules: A Procurement Checklist

Share
Article cover placeholder

Procurement teams need checklists that legal, security, and data owners can score independently - before contract signature locks you in.

Data processing and subprocessors

Where is data processed? How are subprocessors notified and approved? What happens on region changes?

Model change management

How are material model updates communicated? Is there a notice period compatible with your risk review cadence?

Human oversight and audit rights

Can you export logs in a format your DPA accepts? Are human review paths contractually guaranteed for high-risk flows?

Incident and exit playbooks

What SLA applies to model outages? How do you export prompts, logs, and training data on exit?

Alignment with EU AI Act roles

Clarify whether you deploy as provider, deployer, or both - and how obligations split in the DPA.

If it is not in the contract, assume it is not in the product.

About the author

AgentWorks Editorial

AgentWorks helps European teams deploy governed AI agents with built-in EU AI Act transparency, audit trails, and human-in-the-loop controls.