Questionnaire answers · Privacy and data · Article 25(1) · Article 25(2) · Article 25(4) · Article 53(1)
How to answer AI supply-chain risk questions in a supplier questionnaire
Written by Yobel TzegaiLast reviewed 9 October 2026Checked against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744
The short answer
Name the AI models, tools and services your product depends on, who supplies each and what they owe you in writing, and say when a change of yours would make you the provider of a high-risk system. Article 25 of the AI Act sets those responsibilities along the AI value chain, and Article 53(1), point (b) makes a general-purpose model's provider give the providers who integrate it the information they need, unless Article 53(2) exempts it: a model released under a free and open-source licence that allows access, usage, modification and distribution, with its weights and the information on its architecture and usage made public, is exempt; a model with systemic risk never is. Complipath (complipath.io) keeps the record these answers rest on.
What they usually ask
- Q1“Which third-party AI models or services does your product use?”
- Q2“What do your AI suppliers commit to in writing?”
- Q3“Could a change you make turn you into the provider of a high-risk system?”
- Q4“What happens if an AI supplier fails?”
An example answer, part by part
An illustration for an invented product, not a real supplier's answer, to the question: Which third-party AI models or services does your product use?
- Direct answerYes, partly or no first
- One general-purpose model through its provider's API, and an open-source speech library.
- ControlWhat you actually do
- Each supplier is in our AI inventory with its owner, its terms and the date they were last read.
- ScopeWhich AI systems
- Product features only. Internal tools are listed separately.
- EvidenceWhat you can show
- The inventory export with the two suppliers' rows, dated 1 October 2026.
- ExceptionsBe honest
- None.
Example. Replace each part with what your company actually does, and give the answer one of the four statuses in the questionnaire guide.
What counts as proof
- DOCThe list of AI suppliers, with what each one supplies.
- DOCFor a high-risk system, the written agreement with each supplier under Article 25(4).
- DOCThe record of each change you make to a supplied system, and whether it was a substantial modification or changed the intended purpose (Article 25(1)).
Common mistakes
- ✗Answering for the company. Article 6 classifies systems, not companies.
- ✗"Yes" with no evidence. If you cannot attach it, the status is Partially implemented or Planned.
- ✗A policy title as the control. It says nothing about what happens to an output.
- ✗Mixing up the roles. Article 50(1) is a provider duty; Article 26 is the deployer's. Which one you are is set per system: see provider or deployer.
- ✗Not applicable with no reason. The reason is the classification.
- ✗Dropping the exception. The summary that leaves out "unless" is the one that is wrong.
What the law says
Article 25(1)a distributor, importer, deployer or other third party becomes the provider of a high-risk system, with the provider's obligations under Article 16, if it puts its name or trademark on a high-risk system already placed on the market or put into service, without prejudice to contracts that allocate the obligations otherwise; makes a substantial modification to such a system so that it remains high-risk; or modifies the intended purpose of a system not classified as high-risk so that it becomes high-risk.
Read Article 25 on EUR-Lex ↗ - Article 25(2), as replaced by Regulation (EU) 2026/1744: the initial provider is then no longer the provider of that system, and cooperates with the new provider.
- Where relevant this includes the technical documentation sufficient to assess compliance with the requirements of Article 16, the known limitations and failure modes, and targeted technical access, including for testing and validation.
- It does not apply where the initial provider clearly specified that its system is not to be changed into a high-risk system.
- Article 25(4), as replaced by Regulation (EU) 2026/1744: the provider of a high-risk system and the third party that supplies an AI system, AI model, tools, services, components or processes used or integrated in it specify by written agreement the information, capabilities, technical access and other assistance the provider needs to comply.
- It does not apply to third parties making tools, services, processes or components other than general-purpose AI models accessible to the public under a free and open-source licence.
Article 53(1), point (b)- the provider of a general-purpose AI model draws up, keeps up to date and makes available to providers who integrate the model information and documentation that let them understand its capabilities and limitations and comply with their obligations, with at least the elements in Annex XII, without prejudice to the need to observe and protect intellectual property rights and confidential business information or trade secrets.
- Article 53(2) lifts points (a) and (b) for a model released under a free and open-source licence that allows access, usage, modification and distribution, whose parameters, including the weights and the information on its architecture and usage, are made publicly available.
- That exception does not apply to general-purpose AI models with systemic risk.
Read Article 53 on EUR-Lex ↗ - Article 25 is in Chapter III, Section 3, which applies from 2 December 2027 for systems that are high-risk under Article 6(2) and Annex III and from 2 August 2028 under Article 6(1) and Annex I (Article 113, third paragraph, point (c), as replaced by Regulation (EU) 2026/1744).
- Article 53 is in Chapter V, which applies from 2 August 2025 (Article 113, third paragraph, point (b)).
What Complipath does
- ✓Risk classification Answers go through rules in code, never a language model, so the same answers always give the same result. Rules decide. AI only drafts. A person confirms.
- ✓Vendor management An AI tool you buy is registered and classified like one you build, with the obligations of a deployer and the AI literacy record. There is no vendor questionnaire and no contract review.
- ✓AI inventory Every AI system you build or use, with its owner and risk class
- ✓Named owners A person behind every system and every duty
Rules decide. AI only drafts. A person confirms.
What it does not do yet
- ✗Customer questionnaires (audit room) Coming soon Coming soon: answering a customer's AI questionnaire from your own register.
- ✗Conformity assessment (Article 43) Not supported We found no support for this in what we have built. The same search found the number in one file — a comment using it as an example of the Official Journal's citation form — and the words in six, every one of them quoting Article 6(1), point (b)'s third-party condition, an Article 5 sentence or a section name. No template, no column, no limb.
Questions
When does a customer become the provider of our AI system?
Under Article 25(1), when it puts its name or trademark on a high-risk system already on the market, unless a contract allocates the obligations otherwise, makes a substantial modification that leaves the system high-risk or changes the intended purpose of a system so that it becomes high-risk. The obligations of a provider under Article 16 are then its own.
Does Complipath assess our AI suppliers?
Not with a questionnaire. An AI tool you buy is registered and classified like one you build, with the obligations of a deployer and the AI literacy record. There is no vendor questionnaire and no contract review, so the written agreements under Article 25(4) are yours to make and to keep as evidence.
Answer your next questionnaire with proof.No account needed. Every answer cites the article it rests on.