Full Force Digital AI Engagement Framework

Roles, responsibilities and risk allocation for AI projects

Introduction

This Framework describes how Full Force Digital and its clients allocate roles, responsibilities, compliance obligations and risk when designing, implementing, integrating, deploying or using Artificial Intelligence (AI) solutions.

1. Scope and Purpose

1.1 This Framework applies to all products and services provided by Full Force Digital (“Supplier”) that incorporate, support, configure, integrate, deploy or otherwise relate to artificial intelligence (“AI System”), including but not limited to models, workflows, automation, agentic solutions and AI-enabled software.

1.2 This Framework sets out the allocation of roles, responsibilities and obligations of the Parties in relation to Regulation (EU) 2024/1689 (the “EU AI Act”) and other applicable laws.

1.3 This Framework supplements the Agreement and shall prevail in the event of conflict with other provisions concerning AI-related matters.

1.4 The Parties acknowledge that Supplier may, depending on the specific AI System and the agreed scope of work, act as Provider, Deployer, integrator, technical service provider, consultant or another relevant role under the EU AI Act. The applicable role shall be determined per AI System and, where relevant, documented in the applicable statement of work, order form, project documentation or other written agreement between the Parties.

2. Definitions

For the purposes of this Framework:

  • AI System: any system qualifying as an artificial intelligence system under applicable law.
  • Provider: the party that develops or has an AI System developed and places it on the market or puts it into service under its own name or trademark.
  • Deployer: the party using an AI System under its authority in the course of professional activities.
  • High-Risk AI System: an AI System classified as high-risk under the EU AI Act.
  • GPAI Model: a general-purpose AI model capable of performing a wide range of tasks.
  • Third-Party AI Component: any AI model, AI System, software, API, platform, dataset, tool or service provided by a third party and used in, connected to or forming part of an AI System.

The Parties acknowledge that obligations under the EU AI Act depend on the role of each party in relation to the relevant AI System.

3. Role Allocation

3.1 The Parties acknowledge that, for each AI System, one or more roles under the EU AI Act may apply, including Provider, Deployer, Importer, Distributor or other operator roles.

3.2 Unless explicitly agreed otherwise in writing:

  • Supplier acts as Provider only where Supplier develops, places on the market or puts into service an AI System under Supplier’s own name or trademark;
  • Supplier may act as Deployer where Supplier uses an AI System under its own authority in the performance of its services, including for internal delivery, analysis, configuration, testing, content generation, workflow execution or operational support;
  • Client acts as Deployer where Client uses an AI System under its own authority within its organisation, processes, systems or business operations;
  • Supplier does not assume the role of Provider merely by advising on, configuring, integrating, implementing, supporting or operating a third-party AI System on behalf of Client, unless Supplier places the relevant AI System on the market or puts it into service under Supplier’s own name or trademark.

3.3 The Parties may document role allocation, risk classification, intended use, ownership, operational responsibility and additional obligations in a separate annex, statement of work, order form or project documentation.

3.4 A Party shall be deemed to assume the role of Provider if it:

  • places the AI System on the market under its own name or trademark;
  • substantially modifies the AI System;
  • changes the intended purpose of the AI System;
  • or makes the AI System available to third parties in a manner that qualifies such Party as Provider under applicable law.

3.5 Where the applicable role is unclear, the Parties shall cooperate in good faith to determine the relevant role allocation based on the factual use, control, branding, intended purpose and deployment context of the AI System.

4. Intended Use

4.1 Client shall use the AI System strictly in accordance with:

  • the intended purpose;
  • the agreed scope of use;
  • all instructions, documentation and limitations provided by Supplier or the relevant third-party provider.

4.2 Any use outside the intended purpose or agreed scope shall be at Client’s sole risk and responsibility.

4.3 Supplier shall not be liable for any damage, loss or non-compliance arising from use contrary to the intended purpose, instructions, documentation or agreed scope.

4.4 Where Supplier uses an AI System as Deployer in the performance of its services, Supplier shall use the AI System in accordance with the relevant provider’s instructions and the agreed scope of services.

5. Risk Classification

5.1 The classification of an AI System, including whether it qualifies as High-Risk, shall be determined based on the intended use, functionality, sector, deployment context and applicable law.

5.2 Unless explicitly agreed otherwise in writing, Supplier does not warrant that an AI System is free from classification as High-Risk.

5.3 Where Client uses, modifies, combines, integrates or deploys the AI System in a manner that results in a High-Risk classification, Client shall be responsible for all obligations arising from such use, modification, integration or deployment.

5.4 Where Supplier acts as Deployer of a third-party AI System in the performance of its services, Supplier shall be responsible only for those obligations that apply to Supplier in its role as Deployer and only within the agreed scope of services.

5.5 The Parties shall reasonably cooperate to assess the risk classification of an AI System where such assessment is required for the agreed services.

6. Provider Obligations

6.1 Where Supplier acts as Provider, Supplier shall fulfil the obligations applicable to its role under applicable law, including the EU AI Act, to the extent such obligations apply to the relevant AI System and Supplier’s role in relation thereto.

Examples, without being exclusive, of mentioned obligations:

  • provide instructions for use;
  • maintain relevant documentation;
  • implement risk management measures appropriate to the nature of the AI
  • System;
  • enable human oversight where applicable;
  • support monitoring and incident reporting processes;
  • provide information reasonably required for Client to use the AI System in
  • accordance with applicable law and the agreed scope.

6.2 Supplier performs its obligations on a best-efforts basis and does not guarantee:

  • accuracy, completeness or fitness for purpose of AI outputs;
  • uninterrupted availability or error-free operation of the AI System;
  • continuous compliance with evolving regulatory requirements;
  • suitability of the AI System for any use outside the intended purpose or agreed scope.

6.3 Where Supplier is not the Provider of an AI System, Supplier shall not be responsible for Provider obligations relating to that AI System, including obligations concerning design, training, conformity assessment, technical documentation, model development or regulatory registration, except to the extent explicitly agreed in writing.

6.4 Supplier does not warrant that AI-generated outputs are accurate, complete, reliable, unbiased, legally compliant, suitable for any particular purpose or free from errors, hallucinations, omissions or inaccuracies. Client acknowledges that AI outputs require appropriate human review and validation before use, implementation, publication or reliance.

7. Deployer Obligations

7.1 Where Client acts as Deployer, Client shall:

  • use the AI System in accordance with the instructions for use;
  • implement appropriate human oversight;
  • monitor the operation and outputs of the AI System;
  • take appropriate measures to prevent harm to individuals, safety, fundamental rights or third-party rights;
  • suspend use of the AI System where necessary;
  • maintain appropriate internal governance, controls and records relating to its use of the AI System.

7.2 Client shall ensure that personnel using the AI System possess an adequate level of AI literacy.

7.3 Client shall remain responsible for:

  • the context in which the AI System is used;
  • any decisions taken based on AI outputs;
  • the lawful use of input and output data;
  • validation of outputs before relying on them;
  • compliance with sector-specific, employment, consumer, data protection, intellectual property and other applicable laws.

7.4 Where Supplier acts as Deployer in the performance of the services, Supplier shall be responsible for using the AI System in accordance with the applicable instructions and the agreed scope of services. Supplier shall not be responsible for Client’s subsequent use, interpretation or implementation of outputs, unless explicitly agreed otherwise in writing.

8. Modification and Role Transfer

8.1 Where Client:

  • modifies the AI System;
  • changes its intended purpose;
  • integrates the AI System into a new or regulated use case;
  • combines the AI System with other systems, data or workflows in a manner that materially changes its functionality, risk profile or intended purpose;
  • or places the AI System on the market under its own name or trademark,

Client may be deemed to assume the role of Provider.

8.2 In such case:

  • Client shall assume full responsibility for compliance with the EU AI Act and other applicable laws;
  • Supplier shall be released from Provider obligations for the modified AI System;
  • Supplier shall not be liable for non-compliance, damage or loss arising from such modification, change of purpose, integration or market placement.

8.3 Supplier shall provide reasonable cooperation, documentation or assistance as may be required, at Client’s expense and subject to separate agreement.

8.4 Where Supplier substantially modifies a third-party AI System or changes its intended purpose under Supplier’s own name or trademark, Supplier may assume the role of Provider for that modified AI System, but only to the extent required by applicable law and within the scope of Supplier’s modification.

9. Third-Party AI and GPAI Models

9.1 AI Systems may incorporate, connect to or depend on Third-Party AI Components, including GPAI Models, APIs, cloud platforms, software libraries or third-party tools.

9.2 Supplier does not warrant or assume responsibility for:

  • the compliance of such Third-Party AI Components;
  • changes, updates, suspension or discontinuation of such components;
  • the performance, availability, accuracy or outputs generated by such components;
  • the training data, model behaviour, security, documentation or regulatory status of third-party models or systems.

9.3 Client acknowledges that reliance on Third-Party AI Components introduces dependencies and risks beyond Supplier’s control.

9.4 Where Supplier uses Third-Party AI Components as part of the services, Supplier shall use reasonable efforts to select and use such components in a professional manner and in accordance with the agreed scope.

9.5 Where Client requires the use of a specific Third-Party AI Component, Client shall be responsible for assessing whether such component is suitable and lawful for Client’s intended use.

9.6 Where AI Systems incorporate, access or rely upon Third-Party AI Components, the applicable terms, policies, technical limitations, acceptable use requirements and licensing conditions of the relevant third-party provider shall apply in addition to this Framework. Client agrees to comply with such terms where applicable.

9.7 Supplier shall not be liable for any interruption, degradation, modification, withdrawal, pricing changes, licensing changes or regulatory restrictions affecting Third-Party AI Components.

10. Intellectual Property and AI Outputs

10.1 Unless otherwise agreed in writing, ownership of Client-provided data, prompts, instructions and materials shall remain with Client.

10.2 Supplier does not warrant that AI-generated outputs are unique, original, capable of intellectual property protection, non-infringing or exclusive to Client.

10.3 To the maximum extent permitted by law, Supplier shall not be liable for claims alleging that AI-generated outputs infringe intellectual property rights of third parties.

10.4 Client shall review and approve all AI-generated outputs prior to publication, distribution, commercial use or reliance.

10.5 Client assumes responsibility for determining whether AI-generated outputs are suitable for protection, registration, publication, commercialization or any other intended use.

11. Incident Management

11.1 Client shall promptly notify Supplier of any:

  • serious incidents;
  • unexpected outcomes;
  • malfunctioning;
  • suspected non-compliance;
  • or potential risks to individuals, safety, fundamental rights or third-party rights.

11.2 Where Supplier acts as Provider, Supplier shall determine and perform any required reporting obligations applicable to Supplier under the EU AI Act.

11.3 Where Supplier acts as Deployer, Supplier shall cooperate with the relevant provider and Client as reasonably required within the agreed scope of services.

11.4 Client shall cooperate in investigations, mitigation measures and reporting.

11.5 Supplier shall not be responsible for incidents caused by Client’s misuse, modification, unlawful data, failure to monitor outputs, failure to implement human oversight or use outside the intended purpose.

11.6 Client shall promptly notify Supplier of any regulatory inquiry, enforcement action, complaint, claim or investigation relating to the AI System and shall provide reasonable cooperation to Supplier in responding thereto.

12. Transparency and Use of Outputs

12.1 Client shall ensure, where applicable, that:

  • users are informed when interacting with AI systems;
  • AI-generated content is appropriately identified;
  • outputs are reviewed where required;
  • affected individuals receive any notices, explanations or information required by applicable law.

12.2 Supplier does not guarantee that outputs are suitable for automated or unsupervised decision-making.

12.3 Client shall not rely on AI outputs as the sole basis for decisions that may materially affect individuals, legal rights, employment, access to services, financial position, health, safety or similar significant matters, unless explicitly agreed and legally permitted.

12.4 Where Supplier generates or supports AI-generated outputs as part of the services, such outputs shall be subject to Client review and approval unless explicitly agreed otherwise in writing.

13. Data Responsibility

13.1 Client remains solely responsible for:

  • the legality, quality, accuracy and suitability of input data;
  • compliance with applicable data protection, confidentiality, intellectual property and sectoral laws;
  • ensuring that data does not infringe third-party rights;
  • ensuring that Client has the necessary rights, permissions and legal basis to provide, upload, process or use such data.

13.2 Supplier is not obliged to verify the accuracy, legality, completeness or suitability of Client-provided data.

13.3 Where Supplier processes personal data on behalf of Client, such processing shall be governed by the applicable data processing agreement between the Parties.

13.4 Client acknowledges that the quality, reliability and lawfulness of AI outputs may depend on the quality, completeness and lawfulness of the input data, prompts, instructions and operational context provided by Client.

13.5 Client shall not submit to any AI System any confidential, classified, regulated, export-controlled, trade secret or sensitive information unless such use has been expressly approved by the Parties and appropriate technical and organisational safeguards have been implemented.

13.6 Supplier shall not be responsible for risks arising from Client’s decision to disclose, upload or process data using Third-Party AI Components selected or approved by Client.

14. Audit and Cooperation

14.1 The Parties shall reasonably cooperate in responding to:

  • regulatory inquiries;
  • audits;
  • compliance assessments;
  • documentation requests;
  • risk assessments relating to the AI System.

14.2 Supplier may provide documentation, certifications, reports or third-party materials where available and relevant to the agreed services.

14.3 Additional support, documentation, audit assistance, legal assessment support, technical investigation or compliance work shall be provided at Supplier’s applicable rates, unless explicitly included in the agreed scope.

14.4 Supplier shall not be required to disclose confidential information, trade secrets, proprietary methods, third-party confidential materials or security-sensitive information, except where legally required and subject to appropriate safeguards.

14.5 Client shall not conduct audits, inspections or access reviews relating to Supplier’s source code, prompts, models, methodologies, development environments, security architecture, infrastructure or proprietary information except where required under mandatory applicable law.

14.6 Any audit rights shall be exercised in a manner that minimizes disruption to Supplier’s business operations and protects Supplier’s confidential information and trade secrets.

15. No Warranty of Legal Compliance

15.1 Supplier does not warrant that the AI System, Client’s use of the AI System or any AI output complies with all applicable laws and regulations, including the EU AI Act.

15.2 Client acknowledges that compliance depends on:

  • the specific use case;
  • the intended purpose;
  • implementation choices;
  • risk classification;
  • data used;
  • human oversight;
  • operational context;

and Client’s own governance and decision-making processes.

15.3 Client remains responsible for ensuring that its use of the AI System complies with applicable laws.

15.4 Supplier may provide support, advice or documentation in relation to AI compliance, but such support does not constitute legal advice unless explicitly agreed in writing.

15.5 Any information, guidance, templates, recommendations or assistance provided by Supplier regarding AI governance, AI compliance or regulatory obligations are provided for informational purposes only and shall not be considered legal, regulatory or professional advice.

16. Liability and Risk Allocation

16.1 Each Party is responsible for compliance with the obligations corresponding to its role under the EU AI Act and this Framework.

16.2 All risks associated with:

  • use outside intended purpose;
  • modification of the AI System;
  • use in a High-Risk or regulated context not explicitly agreed with Supplier;
  • unlawful, inaccurate or unsuitable input data;
  • inadequate human oversight;
  • or unlawful or inappropriate use,

shall be borne by Client.

16.3 Supplier shall not be liable for:

  • decisions taken based on AI outputs;
  • Client’s failure to review, validate or supervise AI outputs;
  • indirect or consequential damages arising from AI use;
  • non-compliance caused by Client actions, omissions, data, systems, instructions or operational context;
  • third-party AI components, models, platforms or services outside Supplier’s control.

16.4 Nothing in this Framework shall limit or exclude liability to the extent such limitation or exclusion is not permitted under applicable law.

16.5 Any liability arising under or in connection with this Framework shall be subject to the exclusions, limitations of liability and liability caps contained in the Agreement.

16.6 Client shall indemnify, defend and hold harmless Supplier against claims, losses, penalties, regulatory sanctions, damages and costs arising from:

  • Client’s use of the AI System in violation of applicable law;
  • Client’s use of the AI System in a prohibited AI practice;
  • Client’s modification of the AI System;
  • Client’s provision of unlawful or infringing data;
  • Client’s failure to implement required human oversight or governance measures.

17. AI Literacy and Governance

17.1 Client shall ensure that:

  • personnel using AI Systems are adequately informed and trained;
  • appropriate internal governance and controls for AI use are in place;
  • roles and responsibilities for AI use, review, approval and escalation are clearly assigned;
  • AI outputs are used responsibly and proportionately.

17.2 Supplier may, where agreed, support Client with AI literacy, governance, policies, workshops, training or operational guidance. Such support shall not transfer Client’s legal or operational responsibilities to Supplier unless explicitly agreed in writing.

18. Final Provisions

18.1 This Framework shall be interpreted in line with a risk-based and role-based approach, consistent with the EU AI Act.

18.2 Obligations may evolve as laws, regulations, guidance and enforcement practice develop; Parties shall cooperate in good faith to adapt where required.

18.3 If any provision of this Framework is found to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.

18.4 In the event of uncertainty regarding the applicable AI Act role, risk classification or compliance obligations, the Parties shall cooperate in good faith to document their respective responsibilities in writing.

18.5 The Parties acknowledge that the regulatory framework governing artificial intelligence is evolving. Supplier may update its policies, technical measures, operational procedures and compliance approach where reasonably necessary to reflect changes in applicable law, regulatory guidance, industry standards or technological developments.

Version: 1.0

Effective date: 14 August, 2026

Last reviewed: 14 August, 2026

The version of this AI Framework in effect on the effective date of the applicable Statement of Work shall apply unless otherwise agreed in writing.

Contact

Connect with us

Talk to one of us

Header image
Roles, responsibilities and risk allocation for AI projects