Your Prospect’s Procurement Team Just Added an AI Clause
The short version
Since 2 August 2026 the EU AI Act’s transparency obligations have been in force, and procurement teams have started adding AI clauses to contracts that have nothing to do with AI products. If you sell technology into the EU, someone is going to send you one. Most of what it asks is answerable — but only if you know which side of the provider/deployer line you are standing on.
The clause usually arrives late, from legal rather than from your evaluator, and it is written by someone who has been told to cover AI risk without being told what your product does. Handled badly it adds three weeks. Handled well it is a differentiator, because most of your competitors will handle it badly.
Why you are getting the clause even though you don’t sell “AI”
Two things happened at once. The Act’s transparency obligations became applicable, and every enterprise legal team acquired a template. Templates do not distinguish carefully between a product built on models and a product that has a summarisation feature. So the clause goes to everyone, and the burden of sorting it out lands on the seller.
The seller who can sort it out in one call, rather than escalating to their own counsel for two weeks, wins time that the competition spends waiting.
Provider or deployer — the question underneath every clause
Almost every obligation in the Act attaches differently depending on role. A provider develops an AI system and places it on the market. A deployer uses one under its own authority. The same company can be both, for different systems, and frequently is.
This matters commercially because the clause your buyer sent probably assumes you are the provider of everything in the stack, including the foundation model you call through an API. You are usually not. Getting the role assignment written down correctly is the single highest-leverage edit you can propose, and it is the one buyers accept most readily, because it is a statement of fact rather than a limitation of liability.
The practical move
Do not argue the clause. Send back a short role map: which component you provide, which you deploy, and which is provided by a named upstream model provider. Buyers rarely object to a map. They object to a redline with no explanation attached.
What the transparency obligation actually asks for
For systems that generate content, Article 50 is about disclosure and marking. Two distinct things, often conflated:
Human-readable disclosure
A person interacting with the system, or receiving its output, should be able to tell that the content was AI-generated. This is a product surface question: does the output say so, where the recipient will see it?
Machine-readable marking
Generated output carries provenance metadata a machine can read — not just a visible label. This is the half most teams discover late, because it lives in file properties and export pipelines rather than in the UI.
The dates matter
Transparency obligations applied from 2 August 2026, with a transitional deadline for machine-readable marking on generative systems already on the market before that date. “On our roadmap” stopped being an answer.
Documentation, not just behaviour
Expect to be asked for the assessment behind your answers — how you classified the system’s risk level and why. An answer without a document behind it does not survive the second round.
The five answers to have ready
- Your risk classification, and the reasoning. Most B2B productivity tooling lands outside the high-risk categories, but “we are not high risk” is a conclusion. Buyers increasingly ask for the assessment.
- Your model providers, named. Not “leading foundation models” — the actual list, with regions, because the buyer’s DPO needs it for their own record of processing.
- Whether output is marked, and how. Both halves: what the human sees, and what the file carries.
- The human-oversight story. Who reviews output before it reaches a decision, and whether the product makes that review possible or merely permits it.
- What you do not claim. The clause often asks for assurances no vendor can honestly give — accuracy guarantees, bias-free output. Saying so plainly, and pointing at the controls you do have, closes the conversation faster than a hedge.
Where we stand, since you will ask
We publish our own assessment rather than a badge: the risk classification and reasoning, the model providers and regions, the timeline, and what is implemented against each obligation. Machine-readable output marking under Article 50(2) is implemented across our export surfaces, alongside the human-readable disclosure — the EU AI Act page carries the detail and the dates.
The role map is on the same page, and it is the part worth copying if you are drafting your own: we are the provider of the WinIQ system and the deployer of the upstream models, which are named. If you want the data-handling half of the same story, where your prompt actually goes covers it.
The clause is a qualification signal
One last thing worth noticing. A buyer who sends a serious, specific AI clause has a compliance function that has actually engaged with the purchase. That is usually a sign of a real deal with a real budget, not a tyre-kicker.
Treat it as the first technical requirement rather than as paperwork, answer it in the same week, and it stops being three weeks of delay and becomes the moment the evaluator decides you are the low-risk option.
Related reading
Answer the clause in the first week
WinIQ drafts security and compliance questionnaire responses from your own documented answers, with the source attached — so legal review starts from a draft instead of a blank page.
Request a Demo