TL;DR: Most guides to the EU AI Act are already out of date: a June 2026 Digital Omnibus amendment pushed the high-risk system deadline back to December 2027, while the content-labeling rules stayed on schedule for August 2026. Below is the actual 2026 checklist for auditing an outsourcing or staffing vendor's AI governance, not the deadline everyone already got wrong once.
Outsourcing a workload does not outsource the legal responsibility for it. If a vendor builds or runs an AI system on your behalf, you stay accountable for it under the EU AI Act, whether that vendor is a five-person agency or a global staffing platform.
This is for anyone hiring an outsourcing partner, staffing agency, or contractor to build or operate AI systems in 2026, and who needs to know what to actually check before signing.

What’s Actually Active in the EU AI Act Right Now
As of Q3 2026, three phases of the EU AI Act are already active, and one major deadline has moved. Prohibited AI practices and AI literacy obligations became active in February 2025. General-purpose AI transparency rules followed in August 2025. Since August 2, 2026, chatbot disclosure, machine-readable marking of AI-generated content, and deepfake labeling are all active and were not part of the delay.

What did not stay on schedule is the part most vendor contracts were written around. On June 29, 2026, the Council of the EU gave final approval to a Digital Omnibus amendment that pushes high-risk system obligations for standalone Annex III systems back sixteen months, to December 2, 2027. AI embedded in already-regulated products moves to August 2, 2028, according to legal analysis of the Council’s approval.
That delay is real relief on paperwork, not a reason to stop checking vendors. Every one of the checklist items below still applies to any AI system a vendor already ships to you, delayed deadline or not.
Separate legal analysis of the same Council vote confirms the shape of the delay: standalone high-risk systems move to December 2027, and the European Commission’s own regulatory framework page for AI is the primary source to check whenever a vendor or a blog post quotes a specific date, including this one, since the timeline has already moved once this year.
Why This Is a Vendor Problem
The company that places an AI system on the EU market stays accountable for it even when a third-party vendor built or ran it, including staffing and outsourcing partners. Hiring a vendor to build your AI feature does not hire away that legal exposure.
Fines under the Act reach €35 million or 7% of global annual turnover, whichever is higher, well above the equivalent GDPR ceiling. That number is why procurement teams increasingly audit a vendor’s AI governance before signing a contract, not after a regulator asks for one.
Most vendors are not ready for that audit. 77% of organizations are actively building AI governance programs, but only 1.5% report being satisfied with their current governance headcount, according to the IAPP’s AI Governance Profession Report. If your own organization is short-staffed on this, assume most of your vendors are too.

A separate legal review of the Digital Omnibus vote reaches the same conclusion from the compliance side: Gibson Dunn’s analysis of the postponed deadlines notes that the extra runway is meant for building real governance capacity, not for deferring the question entirely. A vendor that treats a pushed-back deadline as permission to do nothing has misread why the delay happened.
The Vendor Compliance Checklist
Run through these before signing, or before renewing an existing contract. Each item is something you should be able to get a direct, specific answer to, not a general reassurance.
1. Can they classify the system’s risk tier?
Ask the vendor to state, in writing, which EU AI Act risk tier the system you’re commissioning falls under: prohibited, high-risk, limited-risk, or minimal-risk. A vendor who cannot answer this specifically, or who answers with “we’ll figure that out if it comes up,” has not done the classification work the Act requires before development starts.
This matters even for a system that looks minimal-risk today. Adding one feature, like a scoring step or an automated decision, can move a system into a higher tier without anyone updating the paperwork. Ask how the vendor re-checks classification when scope changes, not just at project kickoff.
2. Do they maintain a technical file?
For anything high-risk, the Act requires a technical file documenting how the system was built, tested, and monitored. Ask to see a redacted example from a past project. A vendor assembling this kind of documentation for the first time, under audit pressure, produces a much weaker file than one built alongside development.
3. Who owns AI risk on their side?
There should be a named person or team, not “the engineering lead handles it when needed.” Growing numbers of vendors now have a dedicated AI Governance Specialist role precisely because this needs continuous ownership, not an ad hoc assignment.
4. Can they name your system’s obligations under the current timeline?
A vendor who still cites the original August 2026 high-risk deadline without mentioning the Digital Omnibus delay is working from outdated information; that same vendor may also be behind on other regulatory changes that affect your system. Regulatory currency is itself a signal of governance maturity.
5. How do they document model evaluation?
Ask what their evaluation process looks like and who signs off on it. If the answer is entirely automated with no human review step, that is a gap for anything high-risk. Some vendors now route this through a dedicated AI Evaluator & Trainer function rather than leaving it to whoever built the model.
6. What is their data lineage and permissioning story?
Ask where training and fine-tuning data came from, and how they know it was permissioned for that use. This overlaps with GDPR wherever personal data is involved, and a vendor with a clean answer here usually has the rest of their governance program in reasonable shape too.
7. Do they carry their own AI liability coverage or contractual indemnity?
This will not remove your own legal exposure as the deploying company, but it tells you whether the vendor has priced their own risk realistically. A vendor who has never considered this has probably not considered much else on this list either.
How This Differs From a GDPR Vendor Audit
If your procurement team already runs GDPR vendor audits, do not assume that process covers AI governance too. The two overlap wherever an AI system processes personal data, but the EU AI Act asks a broader question than GDPR ever did.
A GDPR audit asks how personal data is collected, stored, and processed. An AI Act audit asks that plus a second question GDPR never covers: how the system itself behaves, what it was tested against, and whether a human can explain and defend its outputs. A vendor can pass a GDPR audit cleanly while still failing every item on the checklist above, because their data handling is fine and their model governance simply does not exist yet.
In practice this means running two audits, not stretching one to cover both. Procurement teams that fold AI governance questions into an existing GDPR questionnaire tend to get GDPR-shaped answers back: strong on data handling, silent on model behavior and risk classification.

What Happens If You Skip This
The most common failure mode is not a dramatic regulatory action. It is discovering, mid-audit or mid-incident, that nobody, on your side or the vendor’s, can produce the documentation a regulator asks for.
At that point the €35 million or 7% of global turnover ceiling stops being an abstract number, and the cost of retrofitting governance onto a system that is already in production is far higher than building it in from the start. Picture the common version of this: a vendor built a customer-facing scoring or ranking feature eighteen months ago, nobody classified its risk tier at the time, and now a client’s legal team is asking for a technical file that was never started. Rebuilding that documentation after the fact, under a deadline, costs far more in engineering time than writing it alongside the original build would have.
This is the same logic driving the broader shift toward routing AI-related hiring through an Employer of Record: one accountable entity handling compliance, payroll, and worker classification instead of five different contractors across five countries, each with their own gaps.
How to Actually Run the Audit
Treat this as a recurring process, not a one-time gate at contract signing. Regulatory timelines move, as the 2026 Digital Omnibus delay just proved, and a vendor’s own governance maturity changes as they take on new work.

Step 1: Request written answers to all seven checklist items above before signing. Verbal reassurance during a sales call is not documentation.
Step 2: Verify with an example, not just a policy statement. A redacted technical file or evaluation report from a past project shows whether the process is real or aspirational.
Step 3: Confirm the named owner on the vendor’s side, and get a direct line to them, not just to your account manager.
Step 4: Re-check the timeline every two quarters. The Digital Omnibus amendment moved a headline deadline by sixteen months in a single vote; assume future amendments are possible and build the check into your calendar, not just your memory.
Step 5: Re-audit at every contract renewal. A vendor’s governance maturity when you signed is not a permanent guarantee, especially if their business has grown or changed scope since.
None of these five steps require legal training to run. They require asking specific questions and insisting on specific, documented answers instead of general reassurance. Most of the risk in this area comes from never asking in the first place, not from asking and getting a bad answer.
Where This Fits Into a Broader AI Hiring Strategy
Vendor compliance is one piece of a larger shift already underway in how companies outsource AI work. It sits alongside the move toward fractional AI engagements, the fragmentation of the generic “AI Engineer” title into specialized roles, and the pull toward AI-native talent hubs, all covered in more depth in our full breakdown of the five shifts in AI workforce outsourcing for 2026.
That is the same model Second Talent is built around: pre-vetted AI-native engineers, matched fast, with compliance handled instead of left to chance. The checklist above works whether you run it against an outsourcing vendor, a staffing agency, or your own internal team building an AI feature for the first time; the questions do not change based on who is answering them.





