Regulation guide

EU AI Act Third-Party AI

Operationalize the EU AI Act Third-Party AI requirements—from regulatory obligations and evidence collection to vendor assessments, continuous monitoring, governance, and remediation workflows.

Overview

The EU AI Act creates a risk-based regulatory framework for AI systems. Third-party AI governance starts by identifying the organization's role: provider, deployer, importer, distributor, product manufacturer, or another actor.

The AI Act regulates AI based on risk. It prohibits certain practices, imposes detailed requirements for high-risk AI systems, adds transparency duties for some systems, and creates obligations for general-purpose AI models.

Rather than prescribing identical controls for every relationship, the regulation emphasizes a risk-based approach, requiring organizations to apply governance, oversight, controls, monitoring, and due diligence according to the criticality and risk of each relationship.

This implementation guide explains what the regulation requires, how those requirements translate into operational controls and evidence, and how Halbarad helps organizations operationalize compliance through assessments, continuous monitoring, governance workflows, and supply chain risk intelligence.

Official Sources

Intent of the Guide

The AI Act regulates AI based on risk. It prohibits certain practices, imposes detailed requirements for high-risk AI systems, adds transparency duties for some systems, and creates obligations for general-purpose AI models.

Operationalization Requirements

  • Inventory AI systems, embedded vendor AI, external models, AI APIs, and AI-enabled products.
  • Determine actor role and risk category for each use case.
  • Identify high-risk systems and required evidence.
  • Review provider documentation, data governance, testing, human oversight, accuracy, robustness,

cyber security, and post-market monitoring where relevant.

  • Track provider changes, model updates, data use, subprocessors, incidents, and contractual terms.

Evidence Requirements

  • AI system inventory and role analysis.
  • Risk classification and high-risk assessment.
  • Provider evidence, technical documentation, testing, and human oversight records.
  • Contract terms for data use, model changes, incidents, auditability, and subcontracting.
  • Monitoring, incidents, remediation, and approval history.

Common Gaps

  • Embedded AI in vendor products is missed.
  • Teams classify AI by tool name rather than use case and legal role.
  • Contracts do not address model changes or data use.
  • Monitoring stops after approval even though AI systems change quickly.

How Halbarad Helps

Halbarad helps teams maintain an AI supplier and use-case inventory, map providers and downstream dependencies, collect evidence, monitor changes, track incidents and issues, and preserve the approval trail.

Halbarad supports AI governance operations. It does not determine AI Act legal classification.

Disclaimer

This guide is for general information only and is not legal advice. Review the official regulation, guidance, and supervisory materials, and consult qualified counsel or compliance advisors for your organization's specific obligations.