# Contractual allocation of AI duties across the supply chain

- **Record type**: Control
- **Kind**: Contractual term
- **Owner**: Legal counsel
- **Frequency**: Once per AI system
- **Duties served**: 8

## What the control achieves

Writes into supplier and customer agreements who does what on documentation, testing, notification, data rights and cooperation, so that legal duties do not fall into the gap between organisations.

## How it is typically implemented

Legal maintains a set of AI clauses for supplier, customer and partner agreements. Supplier terms cover the information and documentation to be provided, notice of material changes and incidents, cooperation with regulators, audit rights and restrictions on repurposing data. Customer and deployer terms cover permitted uses, the instructions to be followed, feedback channels and the logs and records each side keeps. Deal teams select clauses based on the system's risk tier and the counterparty's role, deviations are approved by legal, and signed clauses are indexed against the register entry for the system.

## Evidence it produces

- AI supplier clause set (contract_clause): Agreed terms on documentation, change and incident notice, cooperation, audit and data use.
- AI customer or deployer clause set (contract_clause)
- Contract clause index against the AI register (register_entry)

## Legal duties this control serves

- Provide contestability, supply-chain transparency and records (guardrails 7 to 9) — Australian Voluntary AI Safety Standard, Australia (satisfies): https://aipolicytracker.org/obligations/australia-vaiss-contestability-supply-chain-records
- Provide deployers with clear instructions for use — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-transparency-to-deployers
- Verify conformity before importing or distributing high-risk AI — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-importer-distributor-obligations
- Non-EU providers must appoint an EU authorised representative for high-risk AI — EU AI Act, European Union (satisfies): https://aipolicytracker.org/obligations/eu-ai-act-art-22-authorised-representative
- Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-art-25-value-chain-becoming-provider
- Providers of high-risk AI must have written agreements with suppliers of components, tools and services — EU AI Act, European Union (satisfies): https://aipolicytracker.org/obligations/eu-ai-act-art-25-4-written-agreements-with-component-suppliers
- Non-EU providers of GPAI models must appoint an EU authorised representative — EU AI Act, European Union (satisfies): https://aipolicytracker.org/obligations/eu-ai-act-art-54-gpai-authorised-representative
- Foreign AI business operators above the threshold must designate a domestic representative in Korea — Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, South Korea (satisfies): https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-36-domestic-representative

## Standards clauses it corresponds to (clause numbers only)

- ISO/IEC 42001:2023: Annex A.10.2, A.10.3, A.10.4
- NIST AI RMF 1.0: GOVERN 6.1; MANAGE 3.1

## MIT AI Risk Repository subdomains addressed

6.5, 6.4

## Provenance

- **Record page**: https://aipolicytracker.org/controls/contractual-allocation-of-ai-duties
- **Official source**: none recorded — this record is incomplete, see https://aipolicytracker.org/gaps
- **Review status**: pending review
- **Confidence**: medium
- **Facts last confirmed**: never confirmed against the official source
- **Retrieved**: 2026-09-24
- **Licence**: https://creativecommons.org/licenses/by/4.0/

> This record is a structured summary with a link to the official text. It is not legal advice. Open the official source before relying on any date or duty. How current each record type must be is published at https://aipolicytracker.org/verification; what a record must carry at all is published at https://aipolicytracker.org/coverage.
