Skip to content
EU AI Act · Art. 25 & 26 · supplier due diligence

AI vendor directory: what to ask each provider under the EU AI Act

Almost no company builds its own models. You buy them — and the moment you put a supplier’s AI into a business process, the Act expects you to know who the provider is, what documentation they owe you, and which duties stay on your side of the line.

Why this directory exists

Under Article 26, a deployer of a high-risk AI system has to use the system in line with the provider’s instructions for use, assign competent human oversight, keep logs and monitor operation. You cannot do any of that without documentation from the vendor — which is why supplier due diligence is where practical AI Act work usually starts.

Under Article 25, the line can move. If you put your own name on a system, change its intended purpose, or substantially modify it, you stop being a deployer and become the provider, inheriting the far heavier obligations of Article 16. Knowing exactly what you bought — and what you did to it — is what keeps you on the right side of that line.

Separately, Article 53 puts documentation and downstream-information duties on providers of general-purpose AI models. Those duties are theirs, not yours — but the information they produce is what you need for your own file. This directory lists, per vendor, the questions worth sending.

Vendors profiled
14
Primarily GPAI model providers
9
EU-headquartered
3

Foundation models

Foundation models / cloud AI

Cloud AI platform

Open-weight foundation models

Foundation models (enterprise NLP)

Model hub / ML platform

Generative media models

Speech & voice AI

Machine translation

Foundation models (sovereign AI)

The four questions that apply to every AI vendor

  • Who is the provider? For resold or hosted models, the model’s provider and your contractual counterparty are often not the same company.
  • What documentation do we get? Instructions for use, model documentation, limitations — the inputs to your own Article 26 file.
  • Where does our data go? Processing location, retention, sub-processors and whether your inputs train the model — a GDPR question that lands in the same review.
  • What did we change? Fine-tuning, rebranding or a new intended purpose can make you the provider under Article 25.

About this directory. Every profile describes only widely known, publicly documented facts about who a vendor is and what they offer. It contains no compliance ratings, certifications or judgements about any company. EU AI Act obligations depend on how you deploy this vendor's technology and on your role (provider, deployer, importer, distributor). Verify every fact and commitment directly with the vendor before relying on it — this profile is a starting point, not legal advice.

Find out which duties are actually yours

The free checker classifies your systems and your role deterministically — no sign-up.

Run the free check

When do these duties actually start?

We will email you the staged EU AI Act dates — GPAI obligations, the August 2026 transparency duties and the 2027–2028 high-risk deadlines — so your vendor review is measured against the right clock.

We use your address to send you this and nothing else. Unsubscribe with one click, any time.