欧盟AI Act进入执法阶段:采购带AI功能的设备和软件时,买家现在应该向供应商核查什么?

欧盟AI Act进入执法阶段:采购带AI功能的设备和软件时,买家现在应该向供应商核查什么?
采购带AI功能的产品时,买家不应只问“AI能做什么”,还要问“这个AI在法规里属于什么角色、由谁维护、发生变化后谁负责”。

欧盟AI Act采用分阶段实施路径。对于企业采购团队,最重要的变化不是突然多出一张“AI证书”,而是需要更早确认产品中的AI功能、供应商角色、使用场景和风险边界。

RFQ阶段应先确认什么?

1. AI功能是否真正影响产品决策

先区分普通自动化、规则算法与机器学习功能。尤其要确认AI是否参与安全、人员管理、身份识别、评分、预测或重要决策。

2. 谁是法规意义上的责任主体

同一项目中可能同时存在模型提供方、软件开发商、设备制造商、品牌方、进口商和最终部署者。采购合同应明确谁负责技术文件、更新、事件响应与法规变化。

3. 供应商能否提供可验证资料

建议要求:

  • AI功能说明与版本信息;
  • 使用限制和预期用途;
  • 数据来源与数据治理说明;
  • 人工监督方式;
  • 性能与失效边界;
  • 更新和变更管理流程。

买家可以建立的AI采购检查表

检查项采购问题
Intended UseAI具体用于什么场景?
Risk是否涉及受监管或高影响用途?
Documentation是否有产品级技术说明?
Data训练/运行数据如何管理?
Human Oversight人能否复核或覆盖AI结果?
Change Control模型更新后如何通知客户?
Support上线后谁负责持续维护?

为什么合同里要写清“变更”?

AI产品可能通过云端模型、固件或软件持续更新。一次采购合格,并不意味着后续版本自动保持相同能力和风险状态。对长期使用设备,买家应要求供应商记录重要模型、功能和数据处理方式的变化。

适用边界

并非所有带“AI”字样的产品都属于同一监管类别。具体责任需要结合产品角色、实际用途、市场和AI Act适用条款判断。

FAQ

有CE就代表AI部分已经完全合规吗?

不能这样推导。CE与具体产品法规有关,AI Act的适用责任仍需按实际功能和角色单独判断。

买家现在最值得增加的一项供应商问题是什么?

要求供应商明确:AI功能、版本、预期用途、更新责任和人工监督方式

stellar.shop内容承接建议

stellar.shop可在智能硬件、工业设备和软件型产品页面增加AI Function、Model/Software Version、EU AI Act Readiness、Update Policy等字段,帮助海外买家在询盘前完成第一轮信息筛选。

参考来源

  • European Commission — EU Artificial Intelligence Act: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
  • European Commission — AI Act implementation: https://digital-strategy.ec.europa.eu/en/policies/ai-act

Key Takeaway

When procuring AI-enabled products, buyers should not only ask what the AI can do. They should also ask what regulatory role the AI has, who maintains it, and who is responsible when it changes.

The EU AI Act follows a phased implementation schedule. For corporate procurement teams, the main change is not the sudden arrival of a single “AI certificate.” Buyers now need to identify AI functions, supplier roles, intended uses, and risk boundaries earlier in the purchasing process.

What should be confirmed first during the RFQ stage?

1. Does the AI function actually affect product decisions?

Buyers should distinguish ordinary automation and rule-based algorithms from machine-learning functions. They should pay particular attention when AI is involved in safety, personnel management, identity recognition, scoring, prediction, or other important decisions.

2. Who is the responsible party under the regulation?

A single project may involve a model provider, software developer, device manufacturer, brand owner, importer, and final deployer. The procurement contract should state who is responsible for technical documentation, updates, incident response, and regulatory changes.

3. Can the supplier provide verifiable information?

Buyers should request:

  • a description of the AI functions and version information;
  • use restrictions and the intended purpose;
  • an explanation of data sources and data governance;
  • the method of human oversight;
  • performance limits and failure boundaries;
  • update and change-management procedures.

An AI procurement checklist for buyers

CheckProcurement question
Intended UseIn what exact scenario is the AI used?
RiskDoes it involve a regulated or high-impact use?
DocumentationIs product-level technical documentation available?
DataHow are training and operational data managed?
Human OversightCan a person review or override the AI result?
Change ControlHow will customers be notified after a model update?
SupportWho is responsible for ongoing maintenance after deployment?

Why should contracts clearly address changes?

AI products may be updated continuously through cloud models, firmware, or software. Passing procurement review once does not mean that later versions will automatically retain the same capabilities and risk profile. For equipment used over a long period, buyers should require suppliers to record material changes to models, functions, and data-processing methods.

Scope and limits

Not every product marketed as “AI” falls into the same regulatory category. Specific duties depend on the product’s role, actual use, market, and the applicable provisions of the AI Act.

FAQ

Does a CE mark mean that the AI component is fully compliant?

No. CE marking relates to specific product legislation. Responsibilities under the AI Act still need to be assessed separately according to the actual functions and roles.

What is the most useful supplier question buyers can add now?

Ask the supplier to specify the AI function, version, intended use, update responsibility, and method of human oversight.

Recommendation for stellar.shop

stellar.shop can add fields such as AI Function, Model/Software Version, EU AI Act Readiness, and Update Policy to pages for smart hardware, industrial equipment, and software-based products. These fields can help overseas buyers complete an initial information review before sending an inquiry.

References

  • European Commission — EU Artificial Intelligence Act: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
  • European Commission — AI Act implementation: https://digital-strategy.ec.europa.eu/en/policies/ai-act