GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

AIG-034 Customer and Deployer Obligations Communication

Tier 2+AIProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Where the organisation provides an AI system that a customer deploys or operates, the customer receives instructions for use, known limitations and performance characteristics, guidance on appropriate human oversight, notification of model updates and material changes and the information needed to meet its own regulatory obligations. Instructions for use are written, versioned and kept current. The provider's name or trade mark and a contact address are shown on the system itself or in the documentation that accompanies it. Where an integrator builds on the organisation's AI system, a written agreement allocates each party's regulatory responsibilities, sets information exchange and incident notification obligations with timeframes and states what applies when the integrator's use brings the system into a high-risk class.

Rationale

Providers bear upstream responsibility for enabling their customers to govern the AI systems they deploy, and incomplete instructions create downstream governance failures and regulatory exposure for both parties. The identification marking is the smallest item here and the one most often absent from a hosted product: a customer or an authority that needs to reach the entity that placed the system on the market should not have to work it out from a domain registration. An about page or a documentation header carries it for a hosted service. The information a downstream provider receives when it integrates a general-purpose model is AIG-047; this control is what a customer deploying a system receives.

Applicability (9 profiles)

SaaS AI Providerstablerequiredrole duty

Instructions for use, the provider identification and the customer agreement are provider duties (Art.13, Art.16.2, ISO 42001 A.8).

Enterprise AI Deployerstablerequiredsatisfied by provider

The deployer is the customer this control addresses. Its evidence is the instructions for use, limitations, oversight guidance and update notices the provider issues, held against the inventory entry. The agreement allocating regulatory responsibility is the AIG-032 agreement. This is the route the other satisfied-by-provider rows name.

GPAI Model Providerstablerequiredrole duty

Instructions for use, the provider identification and the customer agreement are provider duties (Art.13, Art.16.2, ISO 42001 A.8).

High-Risk Provider (EU)stablerequiredrisk class duty

Art.13(2) and (3) turn the instructions for use into a regulated document with a fixed minimum content: an appropriate digital or other format, concise, complete, correct, clear, relevant, accessible and comprehensible to deployers, carrying the provider identity and contact details, the capabilities, limitations and performance metrics including the accuracy, robustness and cybersecurity levels, the known foreseeable risks, the explainability capabilities, performance on specific persons or groups where relevant, the input data specifications, the guidance for interpreting outputs, the human oversight measures, the compute and hardware requirements, the expected lifetime and maintenance and the log collection guidance. Art.16(b) fixes the identification marking, the provider's name, registered trade name or trade mark and a contact address, shown on the system, its packaging or the accompanying documentation. The Art.25(1) clause that decides when an integrator becomes the provider is on AIG-032.

Public Body Deployer (EU)stablerequiredsatisfied by provider

The deployer's evidence for most of this profile, on both seats. The instructions for use under Art.13(2) and (3) are what Art.26(1) measures use against, what the Art.27 seat draws the risk information at point (d) and the oversight description at point (e) from and what Art.26(9) means by the information the provider supplies for the data protection impact assessment. Obtained under the AIG-032 agreement and held against the inventory entry.

Data Act Cloud Provider (EU)stablerequiredrole duty

Instructions for use, the provider identification and the customer agreement are provider duties (Art.13, Art.16.2, ISO 42001 A.8).

DORA ICT Provider (EU)stablerequiredrole duty

Instructions for use, the provider identification and the customer agreement are provider duties (Art.13, Art.16.2, ISO 42001 A.8).

HIPAA Business Associate (US)stablerequiredrole duty

Instructions for use, the provider identification and the customer agreement are provider duties (Art.13, Art.16.2, ISO 42001 A.8).

NIS2 Cloud Provider (EU)stablerequiredrole duty

Instructions for use, the provider identification and the customer agreement are provider duties (Art.13, Art.16.2, ISO 42001 A.8).

Framework Mappings (18)

EU-AI-Art.13.1Transparency — System Transparency for Deployerspartial
EU-AI-Art.13.2Transparency — Instructions for Usefull
EU-AI-Art.13.3Transparency — Mandatory Content of Instructions for Usefull
EU-AI-Art.15.5Accuracy, Robustness and Cybersecurity — Declaration of Accuracy Levels and Metricsfull
EU-AI-Art.16.2Provider Obligations — System Identification Markingfull
EU-AI-Art.25.2Value Chain Responsibilities — Supply Chain Agreementsinformative
EU-AI-Art.26.1Deployer Obligations — Use in Accordance with Instructionsinformative
EU-AI-Art.26.8Deployer Obligations — GDPR Data Protection Impact Assessment Supportpartial
EU-AI-Art.53.2GPAI Model Obligations — Downstream Provider Informationinformative
COP-T-1.2Providing relevant informationinformative
A.10.2Allocating responsibilitiesinformative
A.10.4Customersfull
A.8.2System documentation and information for usersfull
A.8.5Information for interested partiesfull
GV-2.1-001AI Risk Roles and Responsibilities | GV-2.1-001informative
GV-4.2-001Organisational AI Risk Communication | GV-4.2-001partial
MG-4.1-005Post-Deployment AI System Monitoring | MG-4.1-005partial
MS-2.8-004AI Transparency and Accountability Risks | MS-2.8-004partial

Evidence (5)

contractdocumentmanual

Written agreements with third-party AI providers and downstream AI integrators defining each party's compliance responsibilities, information exchange obligations, and incident and model-change notification duties.

Example: AI Supply Chain Responsibility Addendum to Partner API Agreement (executed 2025-07-12): defines provider's obligation to notify of model changes affecting high-risk classification within 14 days, integrator's obligation to maintain deployer compliance obligations equivalent to EU AI Act Art. 25, and mutual incident notification SLA of 48 hours

Test: Request supply chain responsibility agreements for upstream AI providers and downstream integrators. Verify: (1) each party's compliance responsibilities are explicitly allocated, (2) model change and incident notification obligations are defined with timeframes, (3) downstream integrators building on the organisation's AI are bound to equivalent deployer obligations, (4) agreements are executed and current, (5) responsibility allocation covers the scenario where a downstream party's use case triggers a high-risk classification.

recorddocumentmanual

Versioned instructions for use provided to customer deployers, covering system limitations, human oversight guidance, model update notifications, and information necessary for deployers to fulfil their regulatory obligations.

Example: Instructions for Use · AI Contract Analysis API v3.1 (developer documentation portal, published 2026-01-15): known limitations section, recommended human oversight implementation patterns, EU AI Act deployer obligations checklist, DPIA information pack, and model update changelog v3.0 to v3.1

Test: Request the instructions for use provided to customers for each AI system. Verify: (1) instructions cover known limitations and performance characteristics, (2) human oversight guidance is included with concrete implementation recommendations, (3) information required for GDPR DPIA is provided, (4) model update notifications are issued to deployers when material changes occur (check changelog and notification records), (5) instructions are version-controlled and the current version is accessible to customers.

recorddocumentmanual

Model update notification records demonstrating that deployers were notified of material model changes within the committed timeframe, prior to or concurrent with the change taking effect.

Example: Email/Webhook notification log for AI Contract Analysis API model update v3.1 (2026-01-14): 843 customer accounts notified via API changelog webhook, notification sent 7 days before deployment; 12 accounts without webhook received email notification, all within committed 7-day advance notice period

Test: Request notification records for the two most recent material model updates. Verify: (1) notification was sent to all deployers before or concurrent with the model change, (2) notification lead time meets the committed period in the supply chain agreement, (3) notification content includes the nature of the change, impact on performance characteristics, and any action required by the deployer, (4) delivery is confirmed for all customer accounts.

observationobservationmanual

Inspection of the running system and the documentation shipped with it for the provider's name or trade mark and a contact address.

Example: Walkthrough note, product about page and documentation header, 2026-08-14

Test: Inspect the running system and its accompanying documentation. Verify: (1) the name or trade mark and a contact address are reachable from the product within one step, or appear in the documentation shipped with it, (2) the contact address reaches a monitored destination rather than an unattended alias, (3) the details name the entity that placed the system on the market rather than a reseller or a hosting provider, (4) a test message sent to the address was answered within the period the organisation states.

system_exporttechnicalautomated

Export from the customer communication system of the instructions-for-use releases and model change notifications sent to deployers.

Example: Customer notification export, 2026-01-01 to 2026-08-31: 4 instruction-for-use releases and 7 model change notifications, each with recipient tenant list, send timestamp and document version

Test: Export the notifications sent to customer deployers for the period. Verify: (1) each model change or material change recorded in the change log has a matching notification, (2) each notification records the version of the instructions for use it carried, (3) the recipient list covers every tenant on the affected version rather than a subset, (4) each notification was sent within the timeframe the agreement states, measured from the change record, (5) changes with no notification are reported with the reason rather than absent from the export.

Questions (3)

boolean

Where your organisation provides an AI system that a customer deploys, do customers receive written instructions for use?

A provider bears upstream responsibility for enabling customers to govern the AI systems they deploy. Incomplete instructions create downstream governance failures and regulatory exposure for both parties under the EU AI Act.

multi

Which of the following are included in the instructions for use you provide to customer deployers?

Known limitations and performance characteristicsGuidance on implementing appropriate human oversightInformation required for deployers to conduct a data protection impact assessmentNotification of model updates or material changesA deployer obligations checklistThe provider's name or trade mark and a contact address, on the system or in its documentationVersioned documentation kept current and accessible to customersNone of the above

Options run from the most commonly provided to the least. Impact assessment information packs and deployer obligation checklists are the usual gaps: they shift the compliance burden onto customers who lack the technical context to carry it. For the identification marking, answer against what a customer can see in the product or its documentation, not against what appears on your website footer.

multi

Which of the following are addressed in your agreements with integrators that build on your AI systems?

Each party's responsibilities for compliance with applicable AI regulationsTechnical documentation exchange obligationsIncident notification obligations with defined timeframesModel change notification obligations with defined timeframesObligations that apply when the integrator's use triggers a high-risk classificationIntegrators bound to deployer obligations equivalent to EU AI Act Art. 25None of the above

All six provisions are expected for agreements covering high-risk AI systems. The obligation covering high-risk reclassification by downstream use is the provision most often absent from AI supply chain contracts.