Why the contract carries the weight
A deployer holds real obligations under the AI Act, and almost none of them can be met without information held by the provider.
You must use the system in accordance with the instructions for use, which the provider writes. You must assign human oversight to people with the necessary competence, which requires knowing the system's limitations, which the provider documents. You must keep logs, which the provider generates and may host. You must report serious incidents, which requires recognising them, which requires knowing what normal behaviour looks like.
So the contract is not a formality appended to a technical decision. It is the mechanism by which you obtain the ability to comply.
This reverses the usual dynamic in software contracts, where the terms are largely about money, uptime and liability, and the substantive value is in the product. Here a substantial part of the value is contractual, because a good system supplied without information is a system you cannot lawfully operate in a high-risk context.
The corollary: negotiate these terms while you still have the leverage of not having chosen, which is before the implementation team has committed to a vendor rather than after.

