Welche Rolle spielt KI-Compliance bei der Zusammenarbeit mit externen Dienstleistern?
When external service providers integrate AI systems into their services, the commissioning organisation does not stand apart from the responsibility. You continue to share responsibility for the lawfulness of AI use, particularly under the EU AI Act and the GDPR. In short: AI compliance does not end at your own organisational boundary. The following sections address the most important questions around obligations, governance, contracts, risk assessment, and accountability when working with external AI service providers.
What compliance obligations arise when external service providers use AI?
When an external service provider uses AI systems that operate on behalf of or within the context of your organisation, you as the client incur your own compliance obligations. The EU AI Act explicitly requires operators of AI systems to ensure that the systems used meet regulatory requirements, regardless of whether you or a third party operates the technology.
In concrete terms, this means: as soon as a service provider uses an AI system on your behalf that influences or automates decisions, the following requirements apply to you, among others:
- Risk classification: You must assess whether the AI system in use is to be classified as a high-risk system under the EU AI Act.
- Data protection: The service provider may be processing personal data. The GDPR requirements, particularly those relating to data processing agreements, apply in full.
- Transparency and documentation obligations: For certain AI applications — for example in customer-facing contexts — labelling and information obligations apply, such as for AI-generated content or automated communication systems.
- Copyright and intellectual property rights: When the service provider uses AI to create content, questions arise regarding ownership and licensing.
- Liability law: Damages arising from faulty AI outputs can fall back on the client if no clear contractual provisions are in place.
The range of relevant legal areas is broad: it extends from fundamental rights through contract law, data protection, and information security to employment law and co-determination rights when AI systems affect employees.
What is meant by AI governance in the context of external service providers?
AI governance in the context of external service providers refers to the structured framework that an organisation builds to ensure the lawful, secure, and ethically responsible use of AI even when parts of the value chain are outsourced. It encompasses policies, roles, processes, and control mechanisms that extend beyond the organisation itself to cover service providers.
Effective AI governance within an organisation rests on several pillars. First, a clear AI policy is needed — one that is communicated both internally and to third parties. This policy defines what requirements regarding transparency, fairness, security, and compliance apply to all AI systems, regardless of their origin. In addition, governance structures are required that assign responsibilities unambiguously: Who approves the use of a new AI service provider? Who monitors ongoing compliance?
Within the framework of standards such as ISO 42001, it is recommended to build an AI management system (AIMS) that systematically addresses these questions. An AIMS provides a recognised framework rather than a custom-built solution and makes it possible to realise AI productivity gains through structured data governance without incurring compliance risks. Good AI governance towards service providers means in practice: regular audits, clear escalation paths, and a documented AI inventory that also captures externally operated systems.
What contractual provisions are necessary for AI compliance with service providers?
Contracts with AI service providers must explicitly specify which compliance requirements the provider must meet, what rights the client has to carry out reviews, and who is liable in the event of breaches. Standard service agreements are generally not sufficient for this purpose.
The following areas should be included in every contract with an AI service provider:
- Obligations to comply with the EU AI Act: The service provider must contractually confirm which risk class its systems fall into and how it meets the corresponding requirements.
- Data processing agreement (DPA): Where personal data is processed, a DPA pursuant to Art. 28 GDPR is mandatory.
- Audit and control rights: The client should have the right to request compliance evidence or conduct audits.
- Transparency obligations: The service provider must give notice if the AI system in use changes materially or if incidents occur.
- Liability provisions: Clear agreements on who is liable for damages caused by faulty AI outputs and to what extent.
- Subcontractor clauses: If the service provider itself uses AI services from third parties, this must also be regulated and subject to approval.
The question of copyright is particularly relevant: if the service provider uses AI to create content, code, or other works, the contract must clarify who owns the results and whether third-party rights exist.
How do you assess the AI risks of an external provider?
Assessing the AI risks of an external provider takes place in several steps: first, the AI system in use is classified; then specific risks are identified and evaluated; and finally, risk treatment measures are defined. The EU AI Act and standards such as ISO/IEC 23894 on AI risk management provide the basis for this.
Risk classification as the first step
The EU AI Act distinguishes between prohibited AI practices, high-risk systems, limited-risk systems, and AI with minimal risk. For each external service provider, the first step should be to determine which category their systems fall into. High-risk systems — for example those that support personnel decisions or are used in customer scoring — are subject to particularly strict requirements.
Reviewing specific risk dimensions
Beyond regulatory classification, the following risk dimensions should be systematically reviewed:
- Discrimination and bias: Does the system produce discriminatory outputs? AI systems must be free from unlawful bias.
- Data security: How does the provider protect the data it processes from unauthorised access?
- Explainability: Can the system’s decisions be traced and explained?
- Dependency risk: What happens if the service provider discontinues or materially changes its service?
- Disinformation risks: Particularly with generative AI, it must be assessed whether the system can produce inaccurate or misleading content.
A structured AI inventory that also captures externally operated systems is an indispensable tool in this process. It enables consistent evaluation and provides the foundation for ongoing monitoring.
Who bears responsibility when a service provider commits an AI compliance breach?
When an external service provider commits an AI compliance breach, the organisation that commissioned the provider generally bears shared responsibility, provided it cannot demonstrate that it exercised due diligence in selection, contract design, and oversight. The EU AI Act distinguishes between providers and operators of AI systems, whereby operators also have obligations even if they did not develop the system themselves.
In practice, this means: anyone who commissions a service provider operating an AI system is treated legally as an operator and must fulfil the corresponding duty of care. Responsibility cannot simply be transferred entirely to the service provider through a contract. What matters is whether the client:
- was aware of and documented the risk class of the system,
- agreed on adequate contractual protective clauses,
- regularly reviewed the service provider for compliance,
- acted upon identifiable breaches.
Data protection law follows a similar logic: the controller within the meaning of the GDPR remains liable if a data processor breaches data protection requirements and no proper DPA was in place. In the case of serious breaches — for example against human dignity or the prohibition of discrimination — criminal consequences cannot be ruled out either.
How can AI compliance be permanently embedded in service provider management?
Permanently embedding AI compliance in service provider management requires a systematic approach that goes beyond one-off contract negotiations. Continuous review processes, clear internal responsibilities, and a living AI governance structure that also encompasses external partners are all essential.
Proven measures for permanent embedding include:
- Regular compliance reviews: At least once a year, it should be assessed whether the service provider continues to meet all agreed requirements and whether the regulatory framework has changed.
- Incident management processes: Clear procedures are needed for cases where an AI incident occurs at the service provider, including reporting obligations and escalation paths.
- Keeping the AI inventory up to date: The internal AI inventory must include all externally operated systems and be updated regularly.
- Training internal stakeholders: Employees who manage service providers need solid knowledge of AI compliance and governance in order to identify and assess risks.
- Compliance mapping: A structured mapping of regulatory requirements to specific service providers and systems considerably simplifies ongoing monitoring.
Long-term success comes from continuous improvement, not one-off measures. Organisations that have implemented an AI management system based on ISO 42001 benefit from a recognised framework that structurally ensures exactly this kind of lasting effectiveness.
How mITSM supports you with AI compliance and external service provider management
At mITSM, we provide the knowledge your teams need to not only understand AI compliance but to actively implement it — including when working with external service providers. Our training portfolio covers all relevant areas of competence:
- AI compliance training: In-depth knowledge of the EU AI Act, GDPR, liability law, and other relevant legal areas, presented in a practical way by certified experts.
- AI manager and AI officer programmes: Structured training pathways for specialists and managers who take on responsibility for AI governance and compliance.
- Personal certifications via ICO-Cert: We prepare participants for recognised personal certifications via ICO-Cert, which concretely increase market value and demonstrate competence in AI management.
- In-house training: Our courses can also be delivered directly on your premises, enabling entire teams to build a shared understanding of AI compliance together.
Whether as in-person training, online live sessions, or in-house format: our trainers are certified experts with hands-on practical experience. If you would like to find out more about how a structured ISO 42001 audit can advance your organisation, or which training courses are the best fit for your team, take a look at our training offering or get in touch with us directly.
Dieser Inhalt wurde mithilfe von KI erstellt und kann Fehler enthalten.