AIG-034 Customer and Deployer Obligations Communication
Description
Where the organisation provides an AI system that a customer deploys or operates, the customer receives instructions for use, known limitations and performance characteristics, guidance on appropriate human oversight, notification of model updates and material changes and the information needed to meet its own regulatory obligations. Instructions for use are written, versioned and kept current. The provider's name or trade mark and a contact address are shown on the system itself or in the documentation that accompanies it. Where an integrator builds on the organisation's AI system, a written agreement allocates each party's regulatory responsibilities, sets information exchange and incident notification obligations with timeframes and states what applies when the integrator's use brings the system into a high-risk class.
Rationale
Providers bear upstream responsibility for enabling their customers to govern the AI systems they deploy, and incomplete instructions create downstream governance failures and regulatory exposure for both parties. The identification marking is the smallest item here and the one most often absent from a hosted product: a customer or an authority that needs to reach the entity that placed the system on the market should not have to work it out from a domain registration. An about page or a documentation header carries it for a hosted service. The information a downstream provider receives when it integrates a general-purpose model is AIG-047; this control is what a customer deploying a system receives.
Applicability (9 profiles)
Instructions for use, the provider identification and the customer agreement are provider duties (Art.13, Art.16.2, ISO 42001 A.8).
The deployer is the customer this control addresses. Its evidence is the instructions for use, limitations, oversight guidance and update notices the provider issues, held against the inventory entry. The agreement allocating regulatory responsibility is the AIG-032 agreement. This is the route the other satisfied-by-provider rows name.
Instructions for use, the provider identification and the customer agreement are provider duties (Art.13, Art.16.2, ISO 42001 A.8).
Art.13(2) and (3) turn the instructions for use into a regulated document with a fixed minimum content: an appropriate digital or other format, concise, complete, correct, clear, relevant, accessible and comprehensible to deployers, carrying the provider identity and contact details, the capabilities, limitations and performance metrics including the accuracy, robustness and cybersecurity levels, the known foreseeable risks, the explainability capabilities, performance on specific persons or groups where relevant, the input data specifications, the guidance for interpreting outputs, the human oversight measures, the compute and hardware requirements, the expected lifetime and maintenance and the log collection guidance. Art.16(b) fixes the identification marking, the provider's name, registered trade name or trade mark and a contact address, shown on the system, its packaging or the accompanying documentation. The Art.25(1) clause that decides when an integrator becomes the provider is on AIG-032.
The deployer's evidence for most of this profile, on both seats. The instructions for use under Art.13(2) and (3) are what Art.26(1) measures use against, what the Art.27 seat draws the risk information at point (d) and the oversight description at point (e) from and what Art.26(9) means by the information the provider supplies for the data protection impact assessment. Obtained under the AIG-032 agreement and held against the inventory entry.
Instructions for use, the provider identification and the customer agreement are provider duties (Art.13, Art.16.2, ISO 42001 A.8).
Instructions for use, the provider identification and the customer agreement are provider duties (Art.13, Art.16.2, ISO 42001 A.8).
Instructions for use, the provider identification and the customer agreement are provider duties (Art.13, Art.16.2, ISO 42001 A.8).
Instructions for use, the provider identification and the customer agreement are provider duties (Art.13, Art.16.2, ISO 42001 A.8).
Framework Mappings (18)
| EU-AI-Art.13.1 | Transparency — System Transparency for Deployers | partial |
| EU-AI-Art.13.2 | Transparency — Instructions for Use | full |
| EU-AI-Art.13.3 | Transparency — Mandatory Content of Instructions for Use | full |
| EU-AI-Art.15.5 | Accuracy, Robustness and Cybersecurity — Declaration of Accuracy Levels and Metrics | full |
| EU-AI-Art.16.2 | Provider Obligations — System Identification Marking | full |
| EU-AI-Art.25.2 | Value Chain Responsibilities — Supply Chain Agreements | informative |
| EU-AI-Art.26.1 | Deployer Obligations — Use in Accordance with Instructions | informative |
| EU-AI-Art.26.8 | Deployer Obligations — GDPR Data Protection Impact Assessment Support | partial |
| EU-AI-Art.53.2 | GPAI Model Obligations — Downstream Provider Information | informative |
| COP-T-1.2 | Providing relevant information | informative |
| A.10.2 | Allocating responsibilities | informative |
| A.10.4 | Customers | full |
| A.8.2 | System documentation and information for users | full |
| A.8.5 | Information for interested parties | full |
| GV-2.1-001 | AI Risk Roles and Responsibilities | GV-2.1-001 | informative |
| GV-4.2-001 | Organisational AI Risk Communication | GV-4.2-001 | partial |
| MG-4.1-005 | Post-Deployment AI System Monitoring | MG-4.1-005 | partial |
| MS-2.8-004 | AI Transparency and Accountability Risks | MS-2.8-004 | partial |
Evidence (5)
Written agreements with third-party AI providers and downstream AI integrators defining each party's compliance responsibilities, information exchange obligations, and incident and model-change notification duties.
Example: AI Supply Chain Responsibility Addendum to Partner API Agreement (executed 2025-07-12): defines provider's obligation to notify of model changes affecting high-risk classification within 14 days, integrator's obligation to maintain deployer compliance obligations equivalent to EU AI Act Art. 25, and mutual incident notification SLA of 48 hours
Test: Request supply chain responsibility agreements for upstream AI providers and downstream integrators. Verify: (1) each party's compliance responsibilities are explicitly allocated, (2) model change and incident notification obligations are defined with timeframes, (3) downstream integrators building on the organisation's AI are bound to equivalent deployer obligations, (4) agreements are executed and current, (5) responsibility allocation covers the scenario where a downstream party's use case triggers a high-risk classification.
Versioned instructions for use provided to customer deployers, covering system limitations, human oversight guidance, model update notifications, and information necessary for deployers to fulfil their regulatory obligations.
Example: Instructions for Use · AI Contract Analysis API v3.1 (developer documentation portal, published 2026-01-15): known limitations section, recommended human oversight implementation patterns, EU AI Act deployer obligations checklist, DPIA information pack, and model update changelog v3.0 to v3.1
Test: Request the instructions for use provided to customers for each AI system. Verify: (1) instructions cover known limitations and performance characteristics, (2) human oversight guidance is included with concrete implementation recommendations, (3) information required for GDPR DPIA is provided, (4) model update notifications are issued to deployers when material changes occur (check changelog and notification records), (5) instructions are version-controlled and the current version is accessible to customers.
Model update notification records demonstrating that deployers were notified of material model changes within the committed timeframe, prior to or concurrent with the change taking effect.
Example: Email/Webhook notification log for AI Contract Analysis API model update v3.1 (2026-01-14): 843 customer accounts notified via API changelog webhook, notification sent 7 days before deployment; 12 accounts without webhook received email notification, all within committed 7-day advance notice period
Test: Request notification records for the two most recent material model updates. Verify: (1) notification was sent to all deployers before or concurrent with the model change, (2) notification lead time meets the committed period in the supply chain agreement, (3) notification content includes the nature of the change, impact on performance characteristics, and any action required by the deployer, (4) delivery is confirmed for all customer accounts.
Inspection of the running system and the documentation shipped with it for the provider's name or trade mark and a contact address.
Example: Walkthrough note, product about page and documentation header, 2026-08-14
Test: Inspect the running system and its accompanying documentation. Verify: (1) the name or trade mark and a contact address are reachable from the product within one step, or appear in the documentation shipped with it, (2) the contact address reaches a monitored destination rather than an unattended alias, (3) the details name the entity that placed the system on the market rather than a reseller or a hosting provider, (4) a test message sent to the address was answered within the period the organisation states.
Export from the customer communication system of the instructions-for-use releases and model change notifications sent to deployers.
Example: Customer notification export, 2026-01-01 to 2026-08-31: 4 instruction-for-use releases and 7 model change notifications, each with recipient tenant list, send timestamp and document version
Test: Export the notifications sent to customer deployers for the period. Verify: (1) each model change or material change recorded in the change log has a matching notification, (2) each notification records the version of the instructions for use it carried, (3) the recipient list covers every tenant on the affected version rather than a subset, (4) each notification was sent within the timeframe the agreement states, measured from the change record, (5) changes with no notification are reported with the reason rather than absent from the export.
Questions (3)
Where your organisation provides an AI system that a customer deploys, do customers receive written instructions for use?
A provider bears upstream responsibility for enabling customers to govern the AI systems they deploy. Incomplete instructions create downstream governance failures and regulatory exposure for both parties under the EU AI Act.
Which of the following are included in the instructions for use you provide to customer deployers?
Options run from the most commonly provided to the least. Impact assessment information packs and deployer obligation checklists are the usual gaps: they shift the compliance burden onto customers who lack the technical context to carry it. For the identification marking, answer against what a customer can see in the product or its documentation, not against what appears on your website footer.
Which of the following are addressed in your agreements with integrators that build on your AI systems?
All six provisions are expected for agreements covering high-risk AI systems. The obligation covering high-risk reclassification by downstream use is the provision most often absent from AI supply chain contracts.