AIPolicyTracker
Legal requirement Vendor and supply-chain governance European Union Partially applicable

Providers of high-risk AI must have written agreements with suppliers of components, tools and services

Context fileUnder EU AI Act, Article 25(4)

Source-linked Open official source

What does it require?

A provider of a high-risk AI system and any third party that supplies AI systems, tools, services, components or processes used in or integrated into it must set out, in a written agreement, the information, capabilities, technical access and other assistance needed for the provider to meet its obligations, based on the generally acknowledged state of the art. Suppliers of free and open-source tools and components other than general-purpose AI models are outside this duty. The AI Office may publish voluntary model terms.

Practical action

Insert AI Act information, access and assistance clauses into contracts with model, data and component suppliers.

Who does it apply to?

Providers of high-risk AI systems and their third-party suppliers of components, models, tools, services or processes.

Applies from:

Which controls meet this duty?

Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.

  • satisfiesContractual termLegal counsel · once per ai system
    Contractual allocation of AI duties across the supply chain

    Serves 8 recorded duties · evidence: AI supplier clause set, AI customer or deployer clause set, Contract clause index against the AI register

    The written agreement itself.

  • supportsProcessProcurement or vendor risk lead · once per ai system
    Vendor and third-party AI due diligence

    Serves 6 recorded duties · evidence: AI supplier due-diligence assessment, AI supplier and component register, Supplier onboarding decision

    Identifies which suppliers fall within Article 25(4).

What evidence would a reviewer expect?

Evidence examples
EvidenceTypeNotes
Supplier agreement with AI Act information and access clausesdocument
Supplier register with agreement statusregister

Framework mappings

Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.

See every European Union duty mapped this way →

Framework mappings
FrameworkReferenceNoteConfidence
ISO/IEC 42001:2023Annex A.10.3Supplier relationships aligned with the organisation's AI responsibilities.high
NIST AI RMF 1.0GOVERN 6.1Policies for third-party AI risks.high

Cite this record

AIPolicyTracker (2026). “Providers of high-risk AI must have written agreements with suppliers of components, tools and services (EU AI Act)”. https://aipolicytracker.org/obligations/eu-ai-act-art-25-4-written-agreements-with-component-suppliers (accessed 24 September 2026). Data licensed CC BY 4.0.

Cite the official text alongside it: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, Official Journal of the European Union, https://eur-lex.europa.eu/eli/reg/2024/1689/oj.

Similar obligations in other instruments

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.