Enterprise AI Procurement in Europe: AI Act, GDPR and Supplier Risk
A European framework for buying AI systems under the EU AI Act, GDPR and cybersecurity obligations while managing supplier, cost and exit risk.
By Leila Haddad, Women in AI Editorial Fellow ยท 1 September 2026
Enterprise AI procurement in Europe now sits at the intersection of the EU AI Act, GDPR, cybersecurity, sector regulation and contract law. Buyers cannot reduce that landscape to a supplier checkbox.
The first task is to identify the system, intended purpose, legal roles, affected people and jurisdictions. The same model can create different obligations when used for internal drafting, recruitment or a consequential public service.
Classify before comparing
Document the use case, users, decisions, data, current process and accountable owner. Determine whether the buyer is acting as a provider, deployer, importer, distributor or another party under the AI Act. Assess prohibited practices, high-risk categories, transparency duties and general-purpose AI dependencies.
The Act follows a phased application timetable. Procurement plans should map the provisions relevant to the actual deployment rather than quote one compliance date.
GDPR remains part of the decision
Ask what personal data enters the system, the lawful basis, purpose, retention, location, access and international transfers. Determine whether data or prompts train a model and how rights requests can be fulfilled.
AI Act documentation does not replace a data protection impact assessment where GDPR requires one. The two regimes address overlapping but distinct questions.
Examine the supply chain
Identify foundation-model providers, hosting, retrieval services, subprocessors, open-source components and human review. Ask how model changes are evaluated and communicated.
For agents, list every tool and permission. Define human approvals, transaction limits, logging, rollback and emergency revocation. A model should not receive broad access because fine-grained controls are inconvenient.
Test evidence, not demonstrations
Evaluate representative cases against the current process and a credible alternative. Measure quality, severe failures, group performance, security, accessibility, latency, cost and review workload.
Agree thresholds and stop conditions before the pilot. Otherwise, both buyer and supplier can reinterpret mixed evidence as success.
Put change into the contract
The European Commission's updated AI model contractual clauses for public buyers illustrate how AI-specific responsibilities can be expressed. Contracts may need to cover:
intended and prohibited uses; data and model training; documentation and audit rights; supplier and model changes; security incidents; regulatory cooperation; human oversight; accessibility and non-discrimination; export, termination and deletion.
The clauses are not a substitute for tailored legal advice. Private and public buyers should adapt terms to the system and risk.
Design exit before entry
Confirm that data, prompts, evaluation sets, configurations and logs can be exported. Understand switching costs and how a critical process continues if the supplier fails.
Keep a decision record covering classification, evidence, limitations, controls, exceptions, total cost, monitoring and the review date. Good procurement does not promise certainty. It makes responsibility and uncertainty visible.
Compare our UK enterprise procurement guide and US edition. Continue with the EU AI Act guide, enterprise AI hub and AI impact assessment guide.