What documents does your AI provider really owe?

Your AI provider owes you just one document by law: the Art. 13 instructions for use. Technical documentation and the declaration go to the authorities.

You are buying in an AI system and want to know which evidence you can demand from the provider. The usual checklists give a confident answer: ask for the technical documentation and the EU declaration of conformity. On its most important axis, that answer is backwards — and anyone relying on it is negotiating in the wrong place.

The short answer: exactly one document

As a deployer, the AI Act gives you a claim to a single document: the instructions for use under Art. 13. The article is headed “Transparency and provision of information to deployers” — it is the only one in the obligations catalogue that addresses you at all.

Art. 13(2) is explicit: high-risk AI systems “shall be accompanied by instructions for use in an appropriate digital format or otherwise” containing concise, complete, correct and clear information. The instructions are therefore not something to be requested; they belong to the system. If they are missing, part of the product is missing.

What the provider does not owe you

This is where the usual lists go wrong. The technical documentation under Art. 11 and Annex IV exists so that — in the words of Art. 11(1) — the information is available “to national competent authorities and notified bodies in a clear and comprehensive form” for assessing whether the system meets the requirements. The deployer does not appear in that sentence.

The EU declaration of conformity under Art. 47 works the same way. The provider keeps it for ten years “at the disposal of the national competent authorities”, and a copy is submitted “to the national competent authorities upon request”. Again: no mention of the deployer.

Both are real, hard obligations — they simply run towards market surveillance, not towards you. You can ask, and many providers will hand the documents over. What you do not have is a legal right to them.

A related misunderstanding concerns Art. 25(4): the written agreement it requires — covering information, capabilities and technical access — runs between the provider and its own suppliers, that is, upstream in the value chain, not down to you.

What the instructions must contain

Because Art. 13 is your only lever, Art. 13(3) repays close reading. The instructions contain at least: the provider’s name and contact details; the characteristics, capabilities and limitations of performance, including its intended purpose; the level of accuracy — including its metrics — robustness and cybersecurity under Art. 15 against which the system was tested and validated; and any known or foreseeable circumstance of reasonably foreseeable misuse.

That is more than most providers volunteer. “Instructions for use” that state no accuracy metric and describe no performance limits do not satisfy Art. 13(3) — and that is a point you can press on concretely, instead of asking in general terms for “compliance evidence”.

Everything else is a matter of contract

Which leads to the sentence no checklist contains: what you do not put in the contract, you do not get — and you have no lever to demand it later. The declaration of conformity, access to parts of the technical documentation, bias test reports, commitments about model changes, cooperation with regulator requests: these are subjects for procurement, not statutory entitlements.

The practical difference is large. Saying “we need your technical documentation” in a negotiation invokes an obligation that does not exist towards you. Saying “the Art. 13(3) instructions must include accuracy metrics, and we are making the declaration of conformity a contractual obligation” stands on firm ground.

When this starts to apply

For standalone high-risk systems under Annex III, the obligations in Art. 8–27 only apply from 2 December 2027 following the Digital Omnibus; for high-risk AI inside regulated products, from 2 August 2028. What becomes applicable on 2 August 2026 are the transparency obligations under Art. 50.

One caveat you rarely read: as of 15 July 2026 the Omnibus had been adopted by Parliament and Council but not yet published in the Official Journal — it enters into force on the third day after publication. The dates are politically settled; formally, until then, the old deadline stands in the applicable text.

What this means for procurement today

Procurement runs for months and contracts for years. A contract you sign today runs into December 2027 — and by then you will need documents you have to secure now. First check whether your system falls under Annex III at all: if it does not, Art. 13 does not apply, and the question looks quite different.

Whether your system is high-risk is something the free risk check settles in a few minutes. This article sets out the statutory documentation position and does not replace legal advice in an individual case.

Factual orientation, not legal advice. Citations refer to the named legal acts and were checked against the official EUR-Lex texts.