Guide · Requirements · Articles 4, 6, 26 and 50

Which AI questions do supplier questionnaires ask, and where are they in the EU AI Act?

Written and last checked 9 October 2026 against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744.

Fifteen AI questions recur in supplier security questionnaires. Each one below carries the provision of the EU AI Act it is about. Seven apply only to high-risk systems, one is not an AI Act question at all, and every answer is given per system.

The short answer

  • Answer per system, not per company: Article 6 classifies systems.
  • Rows 8 to 14 apply only to high-risk systems. For any other system they are Not applicable, with the classification as the reason.
  • Row 7, whether a customer's data trains a model, is not an AI Act question.
  • The free Excel template carries all fifteen with their provisions.

Which fifteen questions come up, and where are they in the Act?

Fifteen questions of the kind these questionnaires ask, with the provision each is about. Row 7 is not an AI Act question, and saying so is a correct answer; row 15 is one only in part. Rows marked high-risk only are Not applicable for any other system.

#QuestionWhere in the ActNote
1Do you have an AI policy?Article 4(1); Article 17(1) for high-risk providersNo article names an AI policy. Article 17(1) requires a documented quality management system.
2Are the people who build or use your AI trained for it?Article 4(1)Measures to support AI literacy; no guaranteed level for any individual.
3Do you use AI for any practice the AI Act prohibits?Article 5; Article 113, third paragraph, point (a)Applied since 2 February 2025. The four units Regulation (EU) 2026/1744 inserted apply from 2 December 2026 under Article 113, third paragraph, point (a).
4Is any AI system you provide or use high-risk?Article 6, Annex I and Annex IIIPer system, with the route it rests on or the reason none applies.
5Do you tell people when they are interacting with an AI system?Article 50(1) and (3)A provider duty in paragraph 1, a deployer duty in paragraph 3. Each has its exceptions.
6Do you label content your AI generates?Article 50(2) and (4); Article 111(4)Systems placed on the market before 2 August 2026 have until 2 December 2026 for paragraph 2.
7Is our data used to train your models?Not an AI Act questionAnswer from your contract and your model providers' terms.
8How do you govern training data and check it for bias?Article 10, high-risk onlyBias is Article 10(2), points (f) and (g).
9Do you log what your AI systems do?Article 12(1); Article 26(6), high-risk onlyDeployers keep logs at least six months, unless Union or national law provides otherwise; financial institutions keep them with their financial services documentation.
10Can a person review or override the AI's output?Article 14(1); Article 26(2), high-risk onlyThe provider designs for oversight; the deployer assigns people with the competence, training, authority and support.
11Do you document how the AI works and where its limits are?Article 13(1) and (2), high-risk onlyInstructions for use that deployers can understand.
12How do you test accuracy and robustness?Article 9(6) and (8); Article 15(1), high-risk onlyTested against prior defined metrics and probabilistic thresholds, at the latest before it is placed on the market or put into service.
13How do you protect the AI against attacks?Article 15(5), high-risk onlyNames data poisoning, model poisoning, adversarial examples, confidentiality attacks and model flaws. The Act does not use the term prompt injection.
14Do you monitor AI in use and act on problems?Article 26(5), high-risk onlyA risk means informing the provider or distributor and the authority without undue delay, and suspending use.
15Which AI providers and models do you rely on?Article 53(1), point (b), in partA general-purpose model's provider owes you information on its capabilities and limitations, unless Article 53(2) exempts an open-source model without systemic risk.

How do you answer one of these questions?

In five parts, with one of four statuses: how to answer AI questions in a supplier questionnaire sets them out, with the mistakes that make an answer fail. Classify each system first, in the order how to classify your AI system sets out, so that the high-risk rows have their reason. The four Article 50 disclosures cover rows 5 and 6 provision by provision.

What this means for you

If you build the AI (provider): rows 5 and 6 are yours under Article 50(1) and (2), and for a high-risk system so are rows 8 to 13.

If you use someone else's AI (deployer): row 2 is yours under Article 4 whatever the tier, rows 5 and 6 are yours where Article 50(3) or (4) reaches you, and for a high-risk system so are rows 9, 10 and 14 under Article 26. Which role you hold is set per system: see provider or deployer.

Complipath records each system's classification and the articles it rests on: see what a risk classification records.

FAQ

Is training on a customer's data an AI Act question? No. It is row 7 of the fifteen, and the answer comes from your contract with the customer and from the terms of the model providers you use. Saying that it is not an AI Act question, and then answering it from those documents, is a complete answer.

Does the AI Act require an AI policy? No article names an AI policy. Article 4(1) requires providers and deployers to take measures to support the AI literacy of their staff, without guaranteeing any level for an individual. Article 17(1) requires providers of high-risk systems to put a documented quality management system in place.

Which questions apply only to high-risk systems? Rows 8 to 14: training data, logs, human oversight, instructions for use, accuracy and robustness, security and monitoring in use. For a system that is not high-risk they are Not applicable, and the system's classification, with its date, is the reason you give.

Does the AI Act mention prompt injection? Not by that name. For high-risk systems, Article 15(5) names data poisoning, model poisoning, adversarial examples, confidentiality attacks and model flaws. For a high-risk system, answer it from the measures you take under that paragraph; for any other, from your own security controls.

Where this question meets the product: what counts as evidence for each requirement. Answering it in a customer's questionnaire: how to answer AI questions in a supplier questionnaire.

Read nextWhat does Article 9 of the EU AI Act require for risk management?Article 9What are the data governance requirements under the EU AI Act (Article 10)?Article 10What goes into EU AI Act technical documentation? The Annex IV checklistArticle 11 and Annex IV

See which of your AI systems the Act covers.

No account needed. Every answer cites the article it rests on.

Get your free readiness review

Check your AI systems, free