--- name: ai-vendor-assessment description: Assess an AI vendor, model provider, or supplier relationship. Use for EU AI Act role and evidence checks, GDPR processor terms, security and resilience review, model-change controls, incident routes, audit rights, contractual redlines, or a go/no-go procurement recommendation. --- # Assess an AI vendor Assess the actual service, intended use, contract, DPA, technical material, and operating model. Never substitute a static reputation profile for current evidence. When the file is incomplete, produce a provisional evidence matrix and `hold pending evidence` recommendation rather than inventing terms or withholding all analysis. Follow [LEGAL-SOURCE-PROTOCOL.md](../../references/LEGAL-SOURCE-PROTOCOL.md). Use the Lexbeam EU AI Act MCP to validate classification, actor duties, deadlines, Article 6(3), and decisive articles. ## Establish roles and use case Record the contracting entity, service, version, deployment mode, geography, intended use, decision effect, data, model chain, and customer modifications. Determine provider, deployer, importer, distributor, product-manufacturer, downstream provider, and GPAI model-provider roles. Check Article 25 role changes before assigning duties. ## Build an evidence matrix For every claim record `provided`, `missing`, `conflicting`, or `not applicable`, plus document, page or URL, date, and owner. Review: 1. **AI Act classification and instructions**: intended purpose, prohibited-use controls, Annex I/III analysis, Article 6(3) documentation, Article 50 duties, provider instructions, and high-risk documentation where applicable. 2. **Model-chain accountability**: base model, fine-tuning, downstream modifications, GPAI evidence, value-chain support under Article 25(4), and change notices. 3. **Data protection**: controller/processor roles, instructions, subprocessors, transfers, deletion, return, training use, purpose limits, rights support, and breach route. 4. **Security and resilience**: independent assurance, access control, logging, vulnerability handling, business continuity, recovery, and service levels. 5. **Monitoring and incidents**: performance thresholds, drift and bias monitoring, complaint flow, serious-incident triage, evidence preservation, immediate deployer-to-provider route under Article 26(5), and provider reporting under Article 73. 6. **Audit and evidence access**: current reports, targeted information rights, regulator cooperation, retention, export, termination assistance, and transition. 7. **Commercial allocation**: warranties tied to supplied facts, indemnities, liability, insurance evidence, suspension rights, change control, termination, and precedence between terms. Treat marketing pages and undated trust-centre statements as lower-grade evidence than signed terms, current technical documentation, and independent assurance. ## Redline discipline For each redline provide: - issue and practical risk - current clause or missing term - proposed language or negotiation objective - legal duty, contractual control, or recommended practice label - fallback position and owner Do not state that regulatory fines are automatically indemnifiable or insurable. Flag enforceability and local-law review. ## Report Return an executive recommendation (`approve`, `approve with conditions`, `hold`, or `reject`), scope and assumptions, role map, evidence matrix, redlines ranked critical/high/medium/low, pre-signing conditions, operating controls, open questions, and source note. For workplace deployments, flag fact-specific worker information and national co-determination analysis. Do not treat DACH as a single works-council regime.