EU AI Act update, 8 May 2026: current law remains the baseline. The Digital Omnibus provisional agreement would move many high-risk AI obligations to 2 Dec 2027 and product-integrated high-risk AI rules to 2 Aug 2028 if formally adopted. Track status EU AI Act update: current law remains the baseline. Digital Omnibus dates apply only if formally adopted. Track status
Vendor governance evidence starter

AI Vendor Intake and Due Diligence Template

Do not approve an AI vendor from a demo deck. Use this worksheet to collect the vendor, data, security, EU AI Act, and evidence questions that should be answered before procurement, renewal, or production use.

Free XLSX workbook · No login · Review-only page

Download the vendor intake worksheet

Professional XLSX worksheet with dashboard, working tabs, lookups, sources, and review notes.

Use it before approval

This is designed to create the first structured evidence file before legal, privacy, risk, security, or management review.

What is inside the workbook

When to use it

  • new AI SaaS procurement
  • vendor renewal reviews
  • shadow AI tools that need vendor assessment
  • sector teams using external AI features

Boundary

This is a practical starter. It is not legal advice, a certification, or a guarantee of EU AI Act compliance. Treat the output as a structured evidence file for qualified review.

Related EU AI Compass tools and guides

FAQ

What is this vendor worksheet meant to decide?

It does not approve or reject a vendor by itself. It helps your team collect the minimum evidence needed before business, security, privacy, procurement, and legal owners make a decision.

Should every vendor complete every field?

No. Use it proportionately. High-impact, sensitive-data, cross-border, or high-risk use cases need deeper evidence than low-risk internal productivity tools.

Source basis

Source basis: Regulation (EU) 2024/1689; European Commission AI Act resources and Service Desk timeline; and official European Commission, European Parliament, and Council Digital Omnibus communications where relevant.

Use note: This page is educational only and is not legal advice, a conformity assessment, or a compliance guarantee.