EU AI Act Article 10: the data governance questions buyers ask suppliers
Article 10 of the EU AI Act requires providers of high-risk AI systems to apply documented data governance, with relevant, representative datasets and bias examination. The duty is the buyer's, but US data suppliers are asked for provenance, preparation logs, coverage and known gaps to support it. Counsel should read the current consolidated text.
What does Article 10 of the EU AI Act ask of training data, and why would a US supplier hear about it?
Article 10 of the EU Artificial Intelligence Act sets data governance requirements for the training, validation and testing data of high-risk AI systems. The duty sits with the provider of the AI system, not with the company that licenses it data. A US supplier hears about it because a buyer building a high-risk system for the EU market may ask the supplier for documents that help the buyer show compliance.
In practice the questions arrive as a supplier questionnaire: where did the data come from, how was it collected, what was removed, what is missing, and can you show it. Companies that can answer in an orderly way close faster than those that cannot.
This is general information, not legal, tax or financial advice. Confirm with your own counsel, tax adviser or professional body before acting. Application dates and details can change, so read the current consolidated text on EUR-Lex.
What does Article 10 require, in plain terms?
Paraphrasing the text, and subject to counsel reading it, Article 10 expects documented data governance and management practices that cover the following ground. It also expects datasets to be relevant, sufficiently representative and, to the best extent possible, free of errors and complete for the intended purpose.
| Article 10 theme | What it means for the dataset | What a buyer may ask a supplier |
|---|---|---|
| Design choices | Why this data was chosen for the task | What business process the records come from |
| Data collection and origin | Where data came from and for what original purpose | Systems of record, date range, who created the records |
| Preparation operations | Annotation, labelling, cleaning, enrichment | What was filtered, redacted or de-identified, and by whom |
| Assumptions | What the data is supposed to measure | Field definitions and known limits |
| Availability and suitability | Whether the quantity and quality are enough | Volume, coverage, gaps |
| Bias examination | Whether the data could cause discriminatory outcomes | Known skews, such as one region or customer type |
| Gaps and shortcomings | What cannot be fixed and how it is handled | A list of missing periods or populations |
| Personal data handling | Protection of rights and special categories where relevant | Whether personal data is present and how it was treated |
Which documents can a supplier prepare?
A company does not need to be a compliance expert to be ready. Most of what a buyer asks for already exists in some form if someone collects it. A short supplier data sheet usually covers the ground.
- Provenance note. Which systems the records came from, the date range, and which team created them.
- Rights statement. Who owns the records, what the company may license, and which categories are excluded.
- Processing log. What was filtered, de-identified or redacted, with the rules used and the date.
- Coverage summary. Volume by year and source, plus known gaps, such as a migration that lost 2019.
- Known skews. Customer mix, regions, languages and job roles that dominate or are missing.
- Personal data note. Whether personal data remains and what protections apply. EU residents' data is covered in the guide on carving EU and UK records out of a US license.
- Change record. Who approved the final delivery and when.
SourceX's data inventory and review stages are where these facts are gathered, and de-identification and redaction requirements are agreed with the company before any work begins.
How does this link to GDPR and other buyer concerns?
Article 10 is about AI data quality and governance. It sits next to, not in place of, privacy law. Where records include personal data of people in the EU, the General Data Protection Regulation can apply even to a US supplier, which is why buyers also ask about purpose limitation, see the GDPR further processing guide. Buyers worried about legal taint in their models also care about the FTC's algorithmic disgorgement remedy, another reason they want documented provenance.
Common supplier mistakes
| Mistake | Why it hurts | Fix |
|---|---|---|
| Cannot say where records came from | Provenance is the first question | Write the provenance note before the first call |
| Mixing client-owned and company-owned records | Rights are unclear | Tag source and owner per system |
| No log of redactions | Buyer cannot verify preparation | Keep a dated processing log |
| Claiming the data is unbiased | Nobody can prove it | Describe known skews and gaps |
| Promising compliance for the buyer | The duty belongs to the provider of the AI system | Provide facts, not guarantees |
Illustrative scenario
A fictional 250-person insurance claims administrator is asked by a buyer for its "Article 10 pack". The company prepares a four-page sheet: claims notes and emails from 2016 to 2024 across five systems; a rights statement excluding records belonging to carrier clients; a log showing names, policy numbers and addresses were redacted; a coverage table showing one state is overrepresented; and a note that records of EU residents were excluded. The buyer's counsel uses it in its own compliance file.
What to say when a buyer sends the questionnaire
Questions to ask the buyer's side
- Which parts of the questionnaire come from regulation and which from the buyer's own policy?
- Is the buyer asking for documents we hold, or for assurances we cannot give?
- Does the buyer want records of EU residents included, or excluded?
- Who at the buyer will own follow-up questions after delivery?
- Will the license state that the supplier gives facts about the data and not a compliance opinion?
What does this mean for a referral partner?
You will not draft governance documents. You can tell an owner that buyers now ask structured questions about origin and preparation, that the answers come from facts the company already holds, and that SourceX's inventory stage helps organize them. For a company that cannot say where its records came from, say so early, because that gap affects how a buyer sees the dataset. The overview of AI data buyers explains who asks these questions, and the residuals clause explainer clarifies a common misunderstanding about rights.
The partner earns 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, up to $100,000 per referred company, paid only after the buyer pays and SourceX receives its fee.
Next step
Start with the company fit checker, review how it works, and register as a partner to introduce a US company with 50+ full-time employees at peak (contractors excluded) and well-documented operations.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Does Article 10 apply directly to a company that licenses its data?
The obligations fall on providers of high-risk AI systems, not on a data supplier. A supplier is still asked for documentation because the provider needs evidence of origin, preparation and gaps. Suppliers that can answer clearly and consistently tend to move through review more smoothly.
What documents should a supplier have ready?
A provenance note, a rights statement, a processing log of filtering and redaction, a coverage summary with known gaps, a note on known skews, and a personal data note. Most of this already exists informally, and a short data sheet is enough to start the conversation.
Does the EU AI Act apply to US companies?
It can reach providers placing AI systems on the EU market even when they are based elsewhere, so buyers with EU customers may pass its requirements down to suppliers by contract. Whether it applies to a specific buyer is a legal question for that buyer and its counsel.
How does bias examination relate to a supplier's records?
Article 10 expects the provider to examine datasets for biases that could cause harm. A supplier helps by describing known skews, such as regions, customer segments, languages or periods that dominate or are missing, rather than claiming the data is neutral.
Will the dates and details stay the same?
Not necessarily. Application dates and some provisions can change, so always check the current consolidated text on EUR-Lex or ask counsel, and treat any summary, including this one, as a starting point.
Related pages
- How to carve EU and UK records out of a US data license
- GDPR further processing: can operational data be reused for AI training?
- FTC algorithmic disgorgement and why AI buyers want licensed, documented data
- What is an AI data buyer?
- What is a residuals clause, and why does it matter in a data license?
- Check Company Fit for Data Licensing
Free resources
- Operational data inventory builder — List systems, record types, years held and owners.
- AI readiness assessment — Ten questions, five dimensions, a score out of 100.
- EBITDA calculator — Reported and adjusted EBITDA from net income.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment