Skip to content

011 · PUBLIC SECTOR

AI and public procurement: what a buyer can require

Most tenders now say « with AI ». Few say what that means for the buyer's obligations. Four things you can require in writing, and what a serious supplier answers.

Where the model runs

The first question a data-protection officer asks about a tool with a model in it is where the prompt goes. If your agents' questions and your citizens' requests travel to a server outside the European Union, the transfer analysis and the contractual safeguards that follow are yours to produce, and they are not small. You can require that inference runs in the EU, and name the country.

A supplier who cannot answer this in one sentence has not thought about it. The answer we give is Paris, on Scaleway's model service, and it is in the contract.

What it learns from

The second question is whether your data trains anything. A consumer API's default terms often allow it; an enterprise agreement usually forbids it; the contract with your supplier must say which, in writing, and cover the supplier's own suppliers. You can require « no client data is used to train or improve a model » as a clause, not a promise on a slide.

Ask also what is kept: prompts, outputs, for how long, and whether you can delete them. A tool that logs every question a social worker asked has created a personal-data store nobody planned for.

Who decides

The third is the line between assisting and deciding. A model may sort, draft, summarise and flag; a person decides on anything that affects a citizen's rights, and the record shows who. You can require the human in the loop as a design constraint and ask to see it on a screen before signing. The instruction desk in Agora's ideas module is what it looks like: the model's suggestion, the person's decision, both kept.

This is also the line the regulation draws. A system that decides on eligibility or ranks people is high-risk; one that helps a clerk find a document is not. Knowing which side your tool sits on is the buyer's job, and the supplier should make it easy.

What the register says

The fourth is paperwork, and it is the one that saves you later. Every AI use in the tool should be a line in the processing register you receive with the instance: purpose, data read, data produced, retention, the human step. You can require that register as a deliverable, dated, and updated at each release that changes a use.

A supplier who delivers it without being asked has been through an audit before. That is worth more than any demo.