On Sunday 2 August, in the middle of the Nordic industrial holiday, the EU's AI Act takes full effect. The same week, Brussels moved its hardest deadlines to 2027 and 2028. For an engineering firm buying AI this autumn, the law turns out to be the manageable part; the contract is where the deal is decided. Here are the questions, updated, in one table.
The context
The EU's AI rules, the AI Act, reach their main application date on 2 August 2026, a Sunday in the middle of the Nordic industrial holiday. Three days earlier, an amending regulation quietly enters into force: the Digital Omnibus, published in the EU's Official Journal on 24 July, which moves the heaviest obligations, the ones attached to so-called high-risk systems, to December 2027 and August 2028. So the week the law takes effect is also the week its hardest parts moved further away. For a firm evaluating an AI tool, the picture this autumn has three layers: the AI Act, the cybersecurity law that has applied in Sweden since January, and the contract terms that follow your clients into every subcontract. The weights between the three just shifted.
The sovereignty question has not moved anywhere. Sweco, one of Europe's largest architecture and engineering consultancies, put digital sovereignty on its list of technology trends for 2026, and Staffan Willstrand, head of its Digital Services division in Sweden, summarised the mood:
Summerat är koll på system och data och möjligheten att ha den inom Europas gränser en fråga som fortsätter vara högaktuell under 2026.
The AI Act
Start with what the law expects of you, the buyer, right now, and the honest answer is: not much, if you use an AI tool rather than build one. The bans on a handful of practices, social scoring and the like, have applied since last year, and so has a duty to make sure staff using AI understand what they are using. The transparency rules that begin this month are mostly the vendor's job: telling people when they interact with an AI system, marking AI-generated content. The special obligations attached to the regulation's list of sensitive uses, the high-risk category, were just postponed to December 2027 for standalone systems and August 2028 for AI built into regulated products. And document analysis in engineering work does not normally sit on that list in the first place, a reading your counsel can confirm quickly.
Sweden's supervision is being assembled in the meantime: in June, the government handed the national role to five existing authorities, with the telecom regulator in front, as a bridge until Swedish legislation is in place. None of this makes the AI Act unimportant. Ask every vendor which risk class they consider their system to fall under as you intend to use it, and on what reasoning, in writing, because the classification tells you which rulebook you are buying into. But the waiting position, the idea that a firm should hold its AI purchases until the legal picture settles, got harder to defend this summer. The picture settled. The risk classes got an extension. The data terms did not.
The security law
The EU's new cybersecurity rules, NIS2, became Swedish law in January: cybersäkerhetslagen, in force since 15 January 2026 and covering far more organisations than the law it replaced. Covered organisations have had to register with the authorities since February. The reporting clocks are short: an early warning within 24 hours of learning of a serious incident, a fuller report within 72, a final report within a month. Even the supervision has been on the move, in the Swedish way: the civil-contingencies agency changed its name in January, and on 1 July its cyber operations moved into the national cybersecurity centre at the signals-intelligence agency. The rules stood still while the letterheads changed.
The clause that matters most in a purchase decision concerns supply chains. Organisations covered by the law must manage security risks in their supplier relationships, which means the duty travels through contracts. A tool that reads your project documents is a supplier in your chain; your firm is a supplier in your clients' chains. Even if your own firm falls outside the law's direct scope, a covered client can be obliged to care about the tools you run its documents through. So ask where the vendor sits in that chain, which subcontractors touch the data and in which countries, and how the vendor supports the deadlines above, because the tool's logs may become part of your report.
The data terms
The engineering world just ran this experiment in public. Late last year, Nathan Miller, a principal at the design-technology consultancy Proving Ground, went through Autodesk's terms of use clause by clause on LinkedIn. One clause, in the books since 2018, said customers could not use the software or its output to train any machine-learning system. Read literally, that covered a firm's own drawings and models: your data, produced in tools you pay for, off limits for your own AI. The post travelled through the BIM and computational-design world, and firms paused internal AI projects while their lawyers reread agreements. Autodesk explained that the clause had been meant to stop reverse engineering, and on 8 December 2025 it rewrote the terms: customers may train models on their own data. Miller called the changes "much needed specificity". The episode holds two lessons for a buyer. It is the terms that decide, whatever the marketing says. And vendors move when customers read.
The classic data questions remain, and they are two, not one. Residency is about where data is stored and processed: can it be confined to the EU, and which subcontractors are involved, in which countries. Jurisdiction is about legal reach: under which country's law can an authority compel access, wherever the servers stand. The EU-US data agreement that keeps transatlantic transfers lawful survived a court challenge in September 2025 and is now before the EU's highest court on appeal; American law, for its part, can reach data held by American providers regardless of where the servers stand, which is why the question exists. Residency is easy to get in writing. Jurisdiction is worth understanding rather than winning.
The newer questions go one layer deeper than storage. Vendors increasingly want rights to learn from customer data and to reuse what they learn in new products, and that is exactly the kind of clause the Autodesk episode taught buyers to look for. Swedish consultancies have a head start here, because their own standard contract already thinks in these terms: a client gets to use a delivered result for the purpose of the assignment, while the consultant keeps carrying knowledge between projects. Apply the same care to what accumulates inside an AI service: the templates, the processes, the memory built up from your work. Ownership on paper is the start; ask in which formats it exports, and what it is worth outside the service. The stakes are not theoretical. In February, a Swedish municipal procurement was redone, over contradictory terms, after an architecture firm challenged a demand for full ownership of its work. The fight over who owns working material is live, on every side of the table.
For firms working for public-sector clients there is one more layer: the client's own contract. Framework agreements and tender documents often carry confidentiality clauses, and some project material is covered by secrecy rules. Whether those documents may be processed in a given cloud service is a contract question, project by project, before it is a technology question. The dullest failure mode in this field is still a tool that passes every technical review and cannot be used on the one project it was bought for.
The checklist
Two free tools make the vendor conversation easier. The EU publishes model contractual clauses for buying AI, updated in March 2025, in a high-risk and a light version with a commentary, in every EU language; they are written for public buyers, and law firms point private companies to them as a starting point. Sweden's digital-government agency and privacy authority published eighteen national guidelines for generative AI in January 2025, procurement included. Neither replaces your counsel; both mean you no longer start from the vendor's template. Then print this, bring it to the first vendor meeting, and write the answers down. Every question has a dry, checkable answer, and that is the point.
| Area | Question to ask | Why it matters |
|---|---|---|
| AI Act | Which risk class do you consider your system to fall under, as we use it, and on what reasoning? In writing. | The heavy duties are deferred to 2027–2028, but the classification tells you which rulebook you are buying into. |
| AI Act | Which general-purpose AI models run underneath, and on what terms? | Upstream model terms and obligations follow into your use. |
| Security law | Are you in scope of NIS2 or the Swedish cybersecurity law, and how do you support our 24- and 72-hour incident deadlines? | The clocks have been law since January; the tool's logs may become part of the record. |
| Supply chain | Which subcontractors touch our data, and in which countries? | Supply-chain security is a legal duty for covered organisations, not a preference. |
| Residency | Where is data stored and processed? Can it be confined to the EU/EEA? | Residency is a client requirement and a sovereignty question before it is a legal one. |
| Jurisdiction | Under which country's law can authorities compel access to our data? | Where the servers stand and who can reach the data are different questions. |
| Training | Is our material used to train models offered to other customers? Can we decline, in the contract? | Project documents usually carry client confidentiality. |
| Learning rights | Beyond training: which rights to learn from, aggregate or reuse our data do your terms claim, and for what? | The Autodesk episode showed these clauses sit unread until they matter. |
| Working assets | Who owns what accumulates in the service, the templates, processes and memory built from our work, and in which formats does it export? | A file export is the minimum; the built-up working material is the value. |
| Procurement | Do our client contracts allow project documents in your service? What do we need from the client? | Public-sector contracts and secrecy rules can veto a technically flawless tool. |
| IT security | SSO, role-based access, encryption at rest and in transit, audit logging, retention, a recent third-party penetration test? | The standard security review; a mature vendor has the pack ready. |
| Exit | How do we export everything, and what is deleted, when, on termination? | An exit that exists only in the sales deck is not an exit. |
| Data flow | Where do the models run, and is our data sent to public AI APIs outside the EU? | A tool can store data in the EU and still send every query to a public API elsewhere. Two separate flows. |
| Commercial | What drives the price: users, usage or results? And how do we forecast the cost of a typical project? | You are budgeting a new kind of line item. Know what moves it before the volumes do. |
None of this is exotic. A vendor accustomed to European engineering work will have written answers to all fourteen, and hesitation is also information. Take the table to your counsel and your IT department, and let them add rows.
Get news and articles in your inbox.
The guide is written to be held against any vendor, us included. Book a demo and we'll walk through the questions with Yesper as the example.
Book demo