← Blog

EU Data Act AI Compliance Checklist for Cloud and Model Switching

Parminder Singh
Parminder Singh··6 min read
Summarize with AI

An EU Data Act AI compliance checklist covers the parts of Regulation (EU) 2023/2854 that reach an AI deployment: the switching obligations in Chapter VI, the international governmental access safeguards in Article 32, the contractual transparency duty in Article 28, and the connected-product data rules in Chapter II. Each check has an owner, a pass condition, evidence fields, and a boundary line.

Compliance & Regulationai-complianceai-governanceeu-data-actregulationpolicy-enforcementarchitecture
EU Data Act AI Compliance Checklist for Cloud and Model Switching

Regulation (EU) 2023/2854 has applied since 12 September 2025 under Article 50, and Chapter VI governs switching between data processing services. An enterprise inference platform that holds prompt history, embeddings, fine-tuning artifacts and policy configuration is a data processing service in that sense. An EU Data Act AI compliance checklist that treats the regulation as a connected-device rule will miss the chapter that actually binds an AI deployment.

I would run the switching checks before the contract renewal rather than after, because the exit terms are the part nobody negotiates once the platform is already carrying production traffic.

TL;DR

  • The Data Act has applied since 12 September 2025. Chapter VI on switching between data processing services is the chapter that reaches most AI deployments.
  • Providers of data processing services owe an information duty under Article 26, and everyone involved in a switch owes an obligation of good faith under Article 27.
  • Contractual transparency on international access and transfer comes from Article 28, while Article 32 addresses unlawful international governmental access to non-personal data held in the Union.
  • Switching charges are subject to gradual withdrawal under Article 29, and interoperability for parallel use and between services sits in Articles 34 and 35.

Check 1: classify each AI component under the regulation

Owner: Legal with the AI platform owner.

Pass condition: The register records, for every component in the AI stack, whether it is a data processing service under Chapter VI, a connected product or related service under Chapter II, or outside the regulation entirely. Managed inference platforms, vector databases, fine-tuning services and observability backends usually land in the first category. Chapter II applies to product data and related service data generated by connected products, which is a narrower set.

Evidence: component register with classification and reasoning, contract references, provider establishment details, counsel sign-off. The EU Data Act controls mapping covers the same classification from the control side.

Check 2: test whether you can actually leave

Owner: Procurement with platform engineering.

Pass condition: Chapter VI removes obstacles to effective switching under Article 23, and Article 25 governs contractual terms concerning switching. The check is practical rather than textual: run a scoped export of prompt and response history, policy configuration, evaluation datasets and fine-tuning artifacts, then record what came back in a portable form and what did not.

Evidence: the export request, a manifest listing formats and record counts, the artifacts that came back in an unusable shape or not at all, timings, and provider correspondence. My view is that this is the single most useful hour anyone spends on Data Act readiness, because the gap between the contract language and the export reality is where the risk actually lives.

Check 3: check switching charges and the withdrawal schedule

Owner: Procurement with finance.

Pass condition: Article 29 provides for the gradual withdrawal of switching charges. The contract file records what the provider currently charges for egress, export tooling, parallel running during migration, and early termination, and states how those charges align with the article.

Evidence: current pricing schedule, contract clauses on egress and termination, provider statement on Article 29 compliance, renegotiation record. A charge that makes exit uneconomic is a switching obstacle in commercial clothing.

Check 4: record the provider's information duty

Owner: Procurement with the vendor manager.

Pass condition: Article 26 sets out the information obligation of providers of data processing services, and Article 27 imposes an obligation of good faith on all parties involved in switching. The file holds what the provider actually told you, in writing, about the switching process, available formats, assistance, and timelines.

Evidence: provider documentation, contractual annex, dated correspondence, escalation record where information was incomplete. Ask for it during procurement rather than during migration.

Check 5: address international governmental access

Owner: Legal with the data protection officer.

Pass condition: Article 28 imposes contractual transparency obligations on international access and transfer, and Article 32 covers international governmental access and transfer of non-personal data held in the Union. For an AI deployment the practical question is which third-country authority could compel a provider to disclose prompt content, embeddings or logs, and what the provider commits to do when it receives such a request.

Evidence: provider transparency statement, contract clause on third-country requests, notification commitment, transparency report history, the entity's own assessment of where the records physically sit. The AI data residency controls guide covers the technical side of keeping records where you intend them to be.

Check 6: assess interoperability before it becomes urgent

Owner: Platform engineering with the architecture owner.

Pass condition: Article 34 covers interoperability for the purposes of in-parallel use of data processing services, and Article 35 covers interoperability of data processing services generally. Article 33 sets essential requirements regarding interoperability of data, data sharing mechanisms and services. The check confirms whether the AI stack could run two providers in parallel during a migration window, and what breaks if it tries.

Evidence: architecture assessment, dependency list on provider-specific features, a parallel-run test result or a documented reason one was not attempted, migration runbook. Provider-specific prompt caching, tool-calling formats and safety filters are common places where parallel running stops being feasible.

Check 7: keep an independent record of AI traffic

Owner: Security engineering with the AI platform owner.

Pass condition: Whatever the contract says about export, an entity that keeps its own per-decision record of authenticated AI requests, including caller identity, model destination, policy version, decision and timestamp, is not dependent on a departing provider for its own history. That record survives the switch.

Evidence: independent record store, retention configuration, export test to a neutral format, integrity verification, sample retrieval from the oldest available period. The AI audit trail requirements guide covers the field design, and the EU Data Act audit evidence article covers assembling it into a package.

Check 8: close gaps with contract actions, not just tickets

Owner: The named contract owner with legal oversight.

Pass condition: Every failed check produces either a technical remediation with an owner and date, or a contract action scheduled for the next renewal. Chapter IV addresses unfair contractual terms related to data access and use between enterprises, with Article 13 covering terms unilaterally imposed on another enterprise, so some gaps have a legal route rather than only a commercial one.

Evidence: gap register with severity and owner, renewal calendar with the specific clauses to renegotiate, legal position on any term assessed under Chapter IV, retest date. Article 40 leaves penalties to Member States, so the local enforcement position belongs in the register too.

DeepInspect

DeepInspect operates at the HTTP boundary between authenticated users or agents and LLM endpoints. It evaluates the identity and policy context an application supplies, permits, redacts or denies the request, inspects the response, and writes a per-decision record the entity holds independently of any model provider. For a Data Act file that matters in two places: the record survives a switch under Chapter VI, and it gives the entity its own account of what data reached which provider when an Article 28 or Article 32 question arrives.

Contract negotiation, export tooling, provider assurance, interoperability engineering, and the legal assessment under Chapter IV stay with the teams that own them. A gateway record is evidence about traffic, not a substitute for a portability guarantee. Book a demo today.

Frequently asked questions

When did the Data Act start applying?

Article 50 sets application from 12 September 2025, following entry into force on the twentieth day after publication. Chapter IV applies from 12 September 2027 to contracts concluded on or before 12 September 2025 where the stated conditions are met, so older agreements have a separate timeline. The European Commission's Data Act page tracks implementation material.

Does the Data Act regulate AI models directly?

The regulation sets rules on access to and use of data rather than on model development or deployment. Its reach into an AI programme comes through the data processing services the programme runs on, the connected-product data it may consume, and the contractual terms governing both.

Which chapter matters most for a typical enterprise AI deployment?

Chapter VI on switching between data processing services, covering Articles 23 through 31. Chapter VII on unlawful international governmental access and transfer of non-personal data, and Chapter VIII on interoperability, follow closely behind it.

Does an AI gateway help with Data Act obligations?

It contributes an independent, portable record of who called which model under what policy, which reduces provider lock-in on the evidence layer and supports transparency questions about where data went. Portability of model artifacts, contract terms and provider assistance sit outside that boundary.