AI Act
Who must comply with the EU AI Act
The AI Act does not ask what industry you are in. It asks what you do with a specific AI system: whether you build it, use it, import it or distribute it — and whether the system, or its output, ends up in the European Union. That is why so many organisations that consider themselves AI consumers rather than AI companies turn out to be in scope.
Scope in 60 seconds
- Four roles
- Provider, deployer, importer and distributor. Your obligations follow the role you occupy for a specific AI system — and one organisation can hold different roles for different systems.
- Territorial reach
- Non-EU providers and deployers are covered when the AI system, or the output it produces, is used in the EU.
- What is excluded
- Military, defence and national security use; pure research and pre-market development; and most free open-source models, unless they are prohibited, high-risk or GPAI with systemic risk.
- How to check
- Inventory your systems, classify the risk level of each, fix your role per system, and work out which duties attach — in that order.
The four operator roles
Everything in the regulation hangs on which role you occupy for a given system. The same company can be a provider of one tool, a deployer of another and an importer of a third. Fix the role first; the duties follow from it. See provider vs deployer for the distinction that causes the most confusion.
| Role | Plain-language definition | What attaches to it |
|---|---|---|
| Provider | Develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark. | The heavy build-side duties: risk management, data governance, technical documentation, logging, human oversight by design, accuracy and cybersecurity, quality management, conformity assessment and CE marking, registration, post-market monitoring and serious-incident reporting. |
| Deployer | Uses an AI system under its own authority in a professional capacity — the organisation that switches it on for real work. | Use-side duties: follow the instructions for use, assign human oversight to competent people, ensure input data is relevant, monitor operation, retain the logs under your control, inform affected workers, and for certain deployers a fundamental rights impact assessment before first use. |
| Importer | Established in the EU and places on the EU market an AI system carrying the name or trademark of a company established outside the Union. | Verify before placing on the market: that conformity assessment was carried out, that the technical documentation exists, that the CE marking and instructions are in place — and do not place the system on the market if you believe it is non-conforming. |
| Distributor | Any other operator in the supply chain that makes an AI system available on the EU market — a reseller or channel partner, for example. | Check that the CE marking, documentation and instructions are present, keep storage and transport conditions from compromising conformity, and act — including withdrawal — when you have reason to believe a system is not conforming. |
The line between roles is not fixed. A deployer that puts its own name on a high-risk system, modifies it substantially, or changes its intended purpose so that it becomes high-risk, becomes a provider for that system and inherits the provider obligations.
Extraterritorial scope
The AI Act follows the placing-on-the-market logic of EU product law rather than the location of the company. You are covered when:
- you are a provider placing an AI system on the EU market or putting it into service in the Union, wherever you are established;
- you are a deployer established or located in the Union;
- you are a provider or deployer established outside the Union, but the output produced by the AI system is used in the EU.
The last one is the trap. A model that runs entirely on servers outside Europe, operated by a company with no European entity, is still within reach if its results are used to make decisions about people or operations inside the Union.
What falls outside
- Military, defence and national security. AI systems used exclusively for those purposes are outside the regulation.
- Pure scientific research and pre-market development. Research activity, and development work before a system is placed on the market or put into service, is excluded. Testing in real-world conditions is not a blanket exemption.
- Most free and open-source models. Released under a free and open-source licence, they fall outside much of the regulation — unless they are prohibited practices, high-risk systems, subject to the transparency duties, or general-purpose AI models with systemic risk.
Self-assessment in five steps
- Inventory every AI system you touch. Built in-house, bought as software, embedded in a product you sell, or quietly enabled inside a SaaS tool your teams already use. If nobody can produce that list, nothing else on this page can be answered.
- Fix your role for each system. Provider, deployer, importer or distributor — separately per system. Note anywhere you rebrand, fine-tune or repurpose someone else's system, because that can turn you into a provider.
- Classify the risk level. Prohibited, high-risk, transparency-risk or minimal risk, and flag anything that is or builds on a general-purpose AI model.
- Check the territorial hook. Where is the system placed on the market, where is it used, and where is its output used? Any of those landing in the EU brings the system into scope.
- Map duties and dates. Write down, per system, which obligations attach to your role and which phase-in date applies, then assign an owner. A classification nobody owns is not a compliance position.
Frequently asked questions
Related reading
AI Act document packages are available now
The AI system inventory, risk classification workbook and documentation templates, in three tiers from 99 EUR. Pay once, download immediately.
