AI vendor directory: what to ask each provider under the EU AI Act
Almost no company builds its own models. You buy them — and the moment you put a supplier’s AI into a business process, the Act expects you to know who the provider is, what documentation they owe you, and which duties stay on your side of the line.
Why this directory exists
Under Article 26, a deployer of a high-risk AI system has to use the system in line with the provider’s instructions for use, assign competent human oversight, keep logs and monitor operation. You cannot do any of that without documentation from the vendor — which is why supplier due diligence is where practical AI Act work usually starts.
Under Article 25, the line can move. If you put your own name on a system, change its intended purpose, or substantially modify it, you stop being a deployer and become the provider, inheriting the far heavier obligations of Article 16. Knowing exactly what you bought — and what you did to it — is what keeps you on the right side of that line.
Separately, Article 53 puts documentation and downstream-information duties on providers of general-purpose AI models. Those duties are theirs, not yours — but the information they produce is what you need for your own file. This directory lists, per vendor, the questions worth sending.
- Vendors profiled
- 14
- Primarily GPAI model providers
- 9
- EU-headquartered
- 3
Foundation models
OpenAI
US-based AI lab behind the GPT model family, ChatGPT and the OpenAI API, one of the most widely deployed LLM providers.
4 questions to send them →Anthropic
US-based AI safety company behind the Claude model family, offered via API and through major cloud platforms.
4 questions to send them →Mistral AI
Paris-based AI company offering general-purpose models via its own API ('La Plateforme') and as open-weight releases; one of Europe's most prominent model labs.
4 questions to send them →xAI
US-based AI company behind the Grok model family, offered via API and integrated into X (formerly Twitter).
4 questions to send them →Foundation models / cloud AI
Cloud AI platform
Microsoft (Azure OpenAI)
Microsoft offers OpenAI's models (and others) as a managed Azure service, wrapped in Azure's enterprise contracts, regions and security tooling.
4 questions to send them →AWS (Bedrock)
Amazon Bedrock is AWS's managed service for accessing foundation models from multiple providers (Anthropic, Meta, Mistral, Amazon's own models and more) under AWS contracts.
4 questions to send them →Open-weight foundation models
Foundation models (enterprise NLP)
Model hub / ML platform
Generative media models
Speech & voice AI
Machine translation
Foundation models (sovereign AI)
The four questions that apply to every AI vendor
- Who is the provider? For resold or hosted models, the model’s provider and your contractual counterparty are often not the same company.
- What documentation do we get? Instructions for use, model documentation, limitations — the inputs to your own Article 26 file.
- Where does our data go? Processing location, retention, sub-processors and whether your inputs train the model — a GDPR question that lands in the same review.
- What did we change? Fine-tuning, rebranding or a new intended purpose can make you the provider under Article 25.
About this directory. Every profile describes only widely known, publicly documented facts about who a vendor is and what they offer. It contains no compliance ratings, certifications or judgements about any company. EU AI Act obligations depend on how you deploy this vendor's technology and on your role (provider, deployer, importer, distributor). Verify every fact and commitment directly with the vendor before relying on it — this profile is a starting point, not legal advice.
The free checker classifies your systems and your role deterministically — no sign-up.