EU AI Act Article 10: the data governance questions buyers ask suppliers

Article 10 of the EU AI Act requires providers of high-risk AI systems to apply documented data governance, with relevant, representative datasets and bias examination. The duty is the buyer's, but US data suppliers are asked for provenance, preparation logs, coverage and known gaps to support it. Counsel should read the current consolidated text.

What does Article 10 of the EU AI Act ask of training data, and why would a US supplier hear about it?

Article 10 of the EU Artificial Intelligence Act sets data governance requirements for the training, validation and testing data of high-risk AI systems. The duty sits with the provider of the AI system, not with the company that licenses it data. A US supplier hears about it because a buyer building a high-risk system for the EU market may ask the supplier for documents that help the buyer show compliance.

In practice the questions arrive as a supplier questionnaire: where did the data come from, how was it collected, what was removed, what is missing, and can you show it. Companies that can answer in an orderly way close faster than those that cannot.

This is general information, not legal, tax or financial advice. Confirm with your own counsel, tax adviser or professional body before acting. Application dates and details can change, so read the current consolidated text on EUR-Lex.

What does Article 10 require, in plain terms?

Paraphrasing the text, and subject to counsel reading it, Article 10 expects documented data governance and management practices that cover the following ground. It also expects datasets to be relevant, sufficiently representative and, to the best extent possible, free of errors and complete for the intended purpose.

Article 10 themeWhat it means for the datasetWhat a buyer may ask a supplier
Design choicesWhy this data was chosen for the taskWhat business process the records come from
Data collection and originWhere data came from and for what original purposeSystems of record, date range, who created the records
Preparation operationsAnnotation, labelling, cleaning, enrichmentWhat was filtered, redacted or de-identified, and by whom
AssumptionsWhat the data is supposed to measureField definitions and known limits
Availability and suitabilityWhether the quantity and quality are enoughVolume, coverage, gaps
Bias examinationWhether the data could cause discriminatory outcomesKnown skews, such as one region or customer type
Gaps and shortcomingsWhat cannot be fixed and how it is handledA list of missing periods or populations
Personal data handlingProtection of rights and special categories where relevantWhether personal data is present and how it was treated

Which documents can a supplier prepare?

A company does not need to be a compliance expert to be ready. Most of what a buyer asks for already exists in some form if someone collects it. A short supplier data sheet usually covers the ground.

  1. Provenance note. Which systems the records came from, the date range, and which team created them.
  2. Rights statement. Who owns the records, what the company may license, and which categories are excluded.
  3. Processing log. What was filtered, de-identified or redacted, with the rules used and the date.
  4. Coverage summary. Volume by year and source, plus known gaps, such as a migration that lost 2019.
  5. Known skews. Customer mix, regions, languages and job roles that dominate or are missing.
  6. Personal data note. Whether personal data remains and what protections apply. EU residents' data is covered in the guide on carving EU and UK records out of a US license.
  7. Change record. Who approved the final delivery and when.

SourceX's data inventory and review stages are where these facts are gathered, and de-identification and redaction requirements are agreed with the company before any work begins.

How does this link to GDPR and other buyer concerns?

Article 10 is about AI data quality and governance. It sits next to, not in place of, privacy law. Where records include personal data of people in the EU, the General Data Protection Regulation can apply even to a US supplier, which is why buyers also ask about purpose limitation, see the GDPR further processing guide. Buyers worried about legal taint in their models also care about the FTC's algorithmic disgorgement remedy, another reason they want documented provenance.

Common supplier mistakes

MistakeWhy it hurtsFix
Cannot say where records came fromProvenance is the first questionWrite the provenance note before the first call
Mixing client-owned and company-owned recordsRights are unclearTag source and owner per system
No log of redactionsBuyer cannot verify preparationKeep a dated processing log
Claiming the data is unbiasedNobody can prove itDescribe known skews and gaps
Promising compliance for the buyerThe duty belongs to the provider of the AI systemProvide facts, not guarantees

Illustrative scenario

A fictional 250-person insurance claims administrator is asked by a buyer for its "Article 10 pack". The company prepares a four-page sheet: claims notes and emails from 2016 to 2024 across five systems; a rights statement excluding records belonging to carrier clients; a log showing names, policy numbers and addresses were redacted; a coverage table showing one state is overrepresented; and a note that records of EU residents were excluded. The buyer's counsel uses it in its own compliance file.

What to say when a buyer sends the questionnaire

Questions to ask the buyer's side

  • Which parts of the questionnaire come from regulation and which from the buyer's own policy?
  • Is the buyer asking for documents we hold, or for assurances we cannot give?
  • Does the buyer want records of EU residents included, or excluded?
  • Who at the buyer will own follow-up questions after delivery?
  • Will the license state that the supplier gives facts about the data and not a compliance opinion?

What does this mean for a referral partner?

You will not draft governance documents. You can tell an owner that buyers now ask structured questions about origin and preparation, that the answers come from facts the company already holds, and that SourceX's inventory stage helps organize them. For a company that cannot say where its records came from, say so early, because that gap affects how a buyer sees the dataset. The overview of AI data buyers explains who asks these questions, and the residuals clause explainer clarifies a common misunderstanding about rights.

The partner earns 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, up to $100,000 per referred company, paid only after the buyer pays and SourceX receives its fee.

Next step

Start with the company fit checker, review how it works, and register as a partner to introduce a US company with 50+ full-time employees at peak (contractors excluded) and well-documented operations.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Does Article 10 apply directly to a company that licenses its data?

The obligations fall on providers of high-risk AI systems, not on a data supplier. A supplier is still asked for documentation because the provider needs evidence of origin, preparation and gaps. Suppliers that can answer clearly and consistently tend to move through review more smoothly.

What documents should a supplier have ready?

A provenance note, a rights statement, a processing log of filtering and redaction, a coverage summary with known gaps, a note on known skews, and a personal data note. Most of this already exists informally, and a short data sheet is enough to start the conversation.

Does the EU AI Act apply to US companies?

It can reach providers placing AI systems on the EU market even when they are based elsewhere, so buyers with EU customers may pass its requirements down to suppliers by contract. Whether it applies to a specific buyer is a legal question for that buyer and its counsel.

How does bias examination relate to a supplier's records?

Article 10 expects the provider to examine datasets for biases that could cause harm. A supplier helps by describing known skews, such as regions, customer segments, languages or periods that dominate or are missing, rather than claiming the data is neutral.

Will the dates and details stay the same?

Not necessarily. Application dates and some provisions can change, so always check the current consolidated text on EUR-Lex or ask counsel, and treat any summary, including this one, as a starting point.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment