Providers of high-risk AI must have written agreements with suppliers of components, tools and services
Context fileUnder EU AI Act, Article 25(4)
What does it require?
A provider of a high-risk AI system and any third party that supplies AI systems, tools, services, components or processes used in or integrated into it must set out, in a written agreement, the information, capabilities, technical access and other assistance needed for the provider to meet its obligations, based on the generally acknowledged state of the art. Suppliers of free and open-source tools and components other than general-purpose AI models are outside this duty. The AI Office may publish voluntary model terms.
Practical action
Insert AI Act information, access and assistance clauses into contracts with model, data and component suppliers.
Who does it apply to?
Providers of high-risk AI systems and their third-party suppliers of components, models, tools, services or processes.
- Actors
- Provider / developer
- Sectors
- Cross-sector / all sectors
Applies from:
Which controls meet this duty?
Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.
-
satisfiesContractual termLegal counsel · once per ai systemContractual allocation of AI duties across the supply chain
Serves 8 recorded duties · evidence: AI supplier clause set, AI customer or deployer clause set, Contract clause index against the AI register
The written agreement itself.
-
supportsProcessProcurement or vendor risk lead · once per ai systemVendor and third-party AI due diligence
Serves 6 recorded duties · evidence: AI supplier due-diligence assessment, AI supplier and component register, Supplier onboarding decision
Identifies which suppliers fall within Article 25(4).
What evidence would a reviewer expect?
| Evidence | Type | Notes |
|---|---|---|
| Supplier agreement with AI Act information and access clauses | document | |
| Supplier register with agreement status | register |
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
See every European Union duty mapped this way →
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001:2023 | Annex A.10.3 | Supplier relationships aligned with the organisation's AI responsibilities. | high |
| NIST AI RMF 1.0 | GOVERN 6.1 | Policies for third-party AI risks. | high |
Cite this record
AIPolicyTracker (2026). “Providers of high-risk AI must have written agreements with suppliers of components, tools and services (EU AI Act)”. https://aipolicytracker.org/obligations/eu-ai-act-art-25-4-written-agreements-with-component-suppliers (accessed 24 September 2026). Data licensed CC BY 4.0.
Cite the official text alongside it: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, Official Journal of the European Union, https://eur-lex.europa.eu/eli/reg/2024/1689/oj.
Similar obligations in other instruments
- Verify conformity before importing or distributing high-risk AI — EU AI Act, European Union
- Provide contestability, supply-chain transparency and records (guardrails 7 to 9) — Australian Voluntary AI Safety Standard, Australia (voluntary)
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.