Legal AI procurement grew a second questionnaire in the 2020s: alongside "where does our data go?" came "is this tool safe to rely on?". The EU AI Act adds a third file, and it is the least familiar: what is this system in regulatory terms, and does its paperwork let us meet our own duties? A vendor's answers now determine how hard your own compliance is - deployer obligations are defined against provider documentation. This spoke of our EU AI Act series gives procurement teams the question set, theme by theme, with the answers that should end a conversation.

Legal information, not legal advice - adapt the question set to your systems and jurisdictions with advice on your own position.

Why AI Act diligence differs from security diligence

Security diligence asks about the vendor's behaviour: encryption, access, retention, training use. AI Act diligence asks about the system's legal identity and the paperwork chain behind it - its intended purpose, its risk tier, the general-purpose model underneath, and whether the documentation flowing down to you supports the duties flowing down with it. A vendor can pass security diligence perfectly and still leave you unable to classify the tool, evidence your oversight, or answer a market surveillance authority.

The two files also age differently. Security posture changes with infrastructure; regulatory posture changes with law and product scope - and the AI Act has already amended itself once via the Digital Omnibus. Build the AI Act file to be re-checked on a cycle, not signed once. Our vendor security and confidentiality questionnaire covers the first file; this article is the second.

Timing sharpens the point. The Act's enforcement machinery goes live on 2 August 2026, high-risk duties follow in December 2027, and contracts signed this year will still be running when both arrive. Diligence done now is cheaper than repapering later - and the vendors who cannot answer today are unlikely to have better answers under deadline.

The question set at a glance

ThemeCore questionsGood answer looks like
Classification and roleIntended purpose? Risk tier, with reasoning? Who is provider if we customise?Written intended purpose; per-tier reasoning; Article 25 boundaries stated
Model chainWhich GPAI models underneath? Provider's AI Act posture? Code of Practice status?Named models; documented compliance route; downstream information flow
Transparency supportDoes the product support Article 50 disclosure and content marking where relevant?Built-in disclosure surfaces; machine-readable marking on generated media
DocumentationInstructions for use? Capability and limitation statements? Update notices?Versioned documentation you may retain and cite
Logging and recordsWhat logs exist? Can we access and retain them? For how long?Exportable activity records supporting six-month-plus retention
Contract termsDuty allocation? Incident notification? Change control on purpose or models?AI Act clauses with notice periods and cooperation duties

Classification and role: what is this system, and who are we in it?

Start where your own file starts: intended purpose. Ask the vendor to state, in writing, what the system is intended to do and in which of the AI Act's tiers it sits - with reasoning, not a bare "not high-risk". A serious vendor can explain why its tools fall outside Annex III (our classification guide shows what that reasoning looks like for legal AI), which uses would change the answer, and whether any feature triggers Article 50 transparency.

Then pin down role boundaries. If your team configures, rebrands, or extends the product, at what point does the vendor say you have become the provider? Article 25's lines - your name on the system, substantial modification, changed intended purpose - should appear in the vendor's own documentation. A vendor that has never considered the question is telling you the regulatory file does not exist yet.

The model chain: GPAI questions

Most legal AI products are built on third-party general-purpose models, so your compliance chain runs through the vendor to model providers you never contracted with. Three questions expose the chain. Which models, and under what terms? - named models and how model switches are notified. What is each model provider's AI Act posture? - GPAI obligations have applied to new models since August 2025, with Commission enforcement from August 2026; signatories of the GPAI Code of Practice (OpenAI, Google, Microsoft, Anthropic, Amazon, Mistral AI, and others) carry a recognised compliance route. What information flows downstream? - the AI Act obliges model providers to equip downstream builders with capability and limitation information; ask how your vendor receives it and what it passes to you.

The point is not to audit OpenAI from a law-firm procurement seat - it is to confirm your vendor knows its own supply chain and has the paperwork to prove it. Vendors that publish their model and methodology choices, as Judicio does on its methodology page, make this the shortest section of the questionnaire.

Transparency and logging: can we meet our own duties?

From 2 August 2026, Article 50 makes disclosure enforceable: people must know when they interact with AI, and AI-generated content needs marking. If you will deploy the vendor's product anywhere client-facing, ask whether disclosure surfaces are built in - and whether generated media carries machine-readable marks (marking for systems already on the market moved to 2 December 2026 under the Omnibus). A product that supports the duty by design turns a policy obligation into a checkbox.

Logging is the quieter question with the longer tail. High-risk deployers must retain automatically generated logs for at least six months from December 2027 - and every deployer benefits from an activity record when a client audit or incident asks "who ran what, on which files, when?". Ask what the product logs, whether you can export and retain it, and who else can see it. This is where workspace-grade platforms separate from consumer tools: Judicio's projects and access controls pair Owner, Editor, and Viewer roles with an activity trail as standard.

Red-flag answers

  • "The AI Act doesn't apply to us." With extraterritorial scope and GPAI rules live since 2025, a categorical no is almost never right - and signals the file was never built.
  • No written intended purpose. Your classification and your use-per-instructions duty both anchor on it; without it you are guessing on the vendor's behalf.
  • Silence on the model chain. A vendor that will not name its underlying models cannot pass through the information its own compliance depends on.
  • No exportable logs. If the evidence of use lives only in the vendor's systems on the vendor's terms, your oversight story has a hole.
  • Contract silence on change. Intended purpose, models, and features will change; a contract with no notice or re-approval mechanism reclassifies you by surprise.

Weight the effort by tier. For a minimal-risk research tool, the classification answer, the model chain, and the logging question may be the whole file - an hour of work. For anything approaching Annex III - an HR screening feature, a client-facing decision tool - every theme in the table applies in full, the contract clauses become negotiation points, and the diligence record feeds the impact assessments. Scaling the questionnaire to the tier keeps procurement fast where the risk is low and thorough where it is not.

Contract language deserves one concrete note. The clauses that age best are mechanical: the vendor notifies material changes to intended purpose, underlying models, or documentation with a defined notice period; serious incidents affecting your deployment are reported within a defined window; and documentation versions in force at signature are retained and referenceable. Vague "vendor complies with applicable AI law" warranties are comfort language, not compliance machinery.

Documenting the diligence - and how Judicio answers it

Diligence that is not recorded did not happen, for audit purposes. Give each vendor a file in the inventory your AI governance policy establishes: the questionnaire answers, the documentation versions relied on, the classification conclusion, the contract clauses, and a re-check date - annually, and on any change of models, features, or law. Where a deployment also needs a DPIA or FRIA, the same file feeds it; the triggers are in our FRIA vs DPIA guide.

We hold Judicio to this questionnaire's standard: intended purpose and tier reasoning stated for lawyer-facing research, review, and drafting; the model and grounding approach documented on the methodology page; security, residency, and no-training commitments on the security page; citations on outputs so verification is built into use; and role-based access with an activity trail for the logging questions. Put the question set to us - contact the team or start a free trial and inspect the product against it directly. EU context lives on the Europe hub.