Government procurement of high- risk AI
In March 2025, the EU published model contractual clauses for public procurement of27 high-risk AI systems (MCC-AI-High-Risk), which public contractors can include in contracts with suppliers of AI systems. The Regulation of28 EU AI Act defines high-risk AI as systems related to critical infrastructure, biometrics, human rights, education, employment and justice.
Из выпуска мониторинга No. 3 (15), March 2025 · выпуск целиком, PDF · на сайте Института Гайдара

The EU experience
In March 2025, the EU published model contractual clauses for public procurement of1 high-risk AI systems (MCC-AI-High-Risk), which public contractors can include in contracts with suppliers of AI systems. The Regulation of2 EU AI Act defines high-risk AI as systems related to critical infrastructure, biometrics, human rights, education, employment and justice.
MCC-AI-High-Risk establishes typical vendor contractual obligations, including establishing a risk management system, ensuring data quality, transparency of AI system operations, human oversight of AI-generated solutions, etc., as required by the AI Act, (discussed in Monitoring No. 3 for 2024).
From a procurement perspective, the primary concern is securing the rights to the data being used. MCC-AI-High-Risk distinguishes between customer and supplier data. The customer's data (whether transferred by a public body or specifically collected for it) remains the property of the customer, while the supplier may not use it outside the scope of the contract and must return or destroy it on demand. Supplier data (such as models and training datasets) remain under the supplier's control, but the customer is granted a non-exclusive license to use them as part of system operation. To ensure compliance with all contract requirements, the customer may request supporting documentation and audits from the supplier at all stages (design, implementation and operation).
MCC-AI-High-Risk obliges to include in the original contract price all costs associated with meeting AI Act requirements, including audit costs, preparation of supporting documentation, implementation of transparency mechanisms, etc.
The US experience
In the United States, in September 2024, Office of Management and Budget of the President (OMB) issued Memorandum M-24-3 18 to standardize the procurement of AI systems by federal agencies. The document emphasizes procurement of particularly highrisk AI:
Rights-affecting systems that impact on human rights (e.g. automatic selection in employment). Contractual terms should include mandatory transparency measures, remedial mechanisms and mandatory human review of disputed decisions.
Systems that affect safety impacting the health and lives of citizens, infrastructure, etc. (e.g., transportation management systems, energy management systems, etc.). (e.g., transportation and energy management systems). The procurement should be accompanied by full access to information on the development of the system, allowing to assess its reliability and prevent negative consequences.
It is recommended that the following conditions includedin contracts to regulate AI:
Use of test data sets generated by the government customer for independent verification of the supplied AI. Such sets should not be available to the contractor in advance and should mimic as closely as possible the real data with which the AI system will work.
The contractor's obligation to provide access for the state customer to conduct tests under conditions close to the actual conditions of system use (similar requirement in the EU).
The right of the state customer to publish the methods and results of system testing (without violating the supplier's intellectual property rights).
The Memorandum establishes requirements for:
Generative AI - by mandating content labeling (e.g. watermarking), providing detailed documentation on training and testing methods, etc.
Biometric AI that performs personal identification - requires independent tests for recognition accuracy, compliance with input data quality standards, setting search accuracy thresholds and mandatory maintenance of secure logs of queries and identifications.
The Memorandum reinforces contractors' obligation to notify agencies of serious AI incidents to promptly respond and prevent negative consequences.
Russia’s experience
Currently Russia lacks specialized regulation for state procurement of AI systems. However, GOST R 71752-2024 “Artificial Intelligence. Terms of Reference” which establishes requirements for technical specifications for the procurement and implementation of AI systems, including public and commercial procurement. The Russian Ministry of Finance developed Methodological Recommendations on Digital Transformation, which recommend integrating AI into the business processes of government organizations, forming strategies for the use of AI and assessing the effectiveness of implemented solutions.
- https://www.resmigazete.gov.tr/eskiler/2025/03/20250319-1.htm ↑
- https://xaydungchinhsach.chinhphu.vn/toan-van-du-thao-nghi-dinh-quy-dinh-chi-tiet-mot-so-dieu-va-bien-phap-thi-hanh-luat-du-lieu-du-thao-2-119250123120619898.htm ↑
- https://public-buyers-community.ec.europa.eu/communities/procurement-ai/resources/updated-eu-ai-model-contractual-clauses ↑
- https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689 ↑
- https://www.whitehouse.gov/wp-content/uploads/2024/10/M-24-18-AI-Acquisition-Memorandum.pdf ↑
From the monitoring issue No. 3 (15), March 2025. Download the full issue (PDF) · issue page at the Gaidar Institute