NUDAYOSH

BLOG · 2026-06-25

The AI Act and suppliers: AI sneaks in through the back door

The EU AI Act also binds those who use AI through suppliers. Dates, risks and how to classify your systems before clients demand it.

Quick summary

  • Regulation (EU) 2024/1689 (the AI Act) entered into force on 1 August 2024 and applies in phases.
  • Already in force: the prohibitions and the AI literacy obligation (since 2 February 2025), and the rules on governance, general-purpose models and penalties (since 2 August 2025).
  • General application lands on 2 August 2026. Obligations for high-risk Annex III systems were postponed towards late 2027 under the political agreement of May 2026 (the "AI omnibus"); confirm the consolidated date.
  • The regulation applies to providers, deployers (those who use the AI), importers and distributors. It reaches SMEs and sole traders, and has extraterritorial scope.
  • Penalties reach up to €35M or 7% of global turnover for prohibited practices.
  • In Spain, the supervisory authority is AESIA (based in A Coruña); the AEPD keeps its powers where personal data is involved.

Why is AI a Procurement problem?

Because AI doesn't enter the company through a strategic project with a committee and a budget. It comes in through the back door: every time a new tool is contracted.

The hiring SaaS that scores candidates. The module that decides who gets credit. The system that segments customers or detects fraud. Many of those functions fall into categories the AI Act treats as high-risk (employment and HR, essential services like banking or health, biometrics, education). And when you bring that AI in through a supplier, the obligations don't vanish: they're split between whoever builds it and whoever deploys it. By using it, you are the deployer.

What obligations do you take on by using a supplier's AI?

In practice, you need to be able to answer four questions:

  1. What AI systems do I have running? Most companies don't even have the inventory.
  2. What risk category does each fall into? Unacceptable (prohibited), high, limited or minimal.
  3. What's on me as the deployer? Human oversight, transparency, documentation, staff training.
  4. What must the contract with that supplier include? Technical-information clauses, support and the split of responsibilities.

Why is this the window of opportunity?

Because almost nobody is doing it today, and the big supplier-management platforms barely touch the AI dimension: it's too new and too legal.

The AI Act won't sell on fear of fines yet. It will sell on something more immediate: your large clients will start requiring the classification of your AI systems in their own supplier vetting. Whoever arrives late loses the contract. Whoever builds the AI inventory and triage into the purchasing point today is two years ahead.

Keep reading

Was this article useful? Let's talk.

Do you know how many of your suppliers expose you today?

We make it clear: how many handle data, embed AI, or access your systems, and for how many you have an up-to-date contract and verification. GDPR, AI Act and NIS2 in a single record.

Ask us for details →

We'll reply with a first diagnosis of your supplier exposure · hola@nudayosh.com

Frequently asked questions

About the AI Act and using AI through suppliers.

Does the AI Act affect my company if I only use AI rather than build it?

Yes. Regulation (EU) 2024/1689 also applies to deployers, i.e. those who use an AI system in a professional context within the EU, even if it was bought from a third party.

Does it affect SMEs and sole traders?

Yes. The scope is broad and there's no exemption by size. Obligations depend on the AI system's risk category, not on company size.

When do the high-risk obligations apply?

General application of the regulation is 2 August 2026. Obligations for high-risk Annex III systems were postponed towards late 2027 under the May 2026 agreement; confirm the consolidated date before planning.

Who enforces the AI Act in Spain?

The Spanish Agency for the Supervision of Artificial Intelligence (AESIA). Where the system processes personal data, the AEPD keeps its GDPR powers.

What happens if I don't classify my AI systems?

Beyond the penalty risk, the immediate impact is commercial: more and more clients require AI-system classification to onboard their suppliers.