Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The EU AI Act can require businesses to change how they design, document, supply and use certain AI systems. What applies depends on the business’s location and role, the system’s intended purpose and risk category, and the date and transition rule that govern it. The Act is EU legislation—not a worldwide AI law—but some obligations can reach businesses outside the EU.

When can the EU AI Act apply to a business?

The Act’s territorial scope is broader than businesses established in the EU. Under Article 2 of Regulation (EU) 2024/1689, it can cover providers placing AI systems or general-purpose AI (GPAI) models on the EU market or putting AI systems into service in the EU, regardless of where the provider is located. It can also cover deployers established or located in the EU and certain providers or deployers established outside the EU when their system’s output is used in the EU.

Importers, distributors, certain product manufacturers and authorised representatives can also fall within the Act’s scope. The regulation includes exclusions and qualifications, so an international business should assess its specific activities rather than assume that either an EU presence or an AI-industry label is decisive. The operative text is Regulation (EU) 2024/1689, published in the Official Journal on 12 July 2024; the consolidated EUR-Lex text consulted is amended through 27 July 2026.

Which role does the business have?

The Act assigns duties according to an organisation’s actual role in the AI supply chain and use—not simply the description it gives itself. The same organisation may have different roles for different systems or activities.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Role How the Act frames it Where the main responsibility falls
Provider Develops or commissions an AI system or GPAI model and places it on the market or puts an AI system into service under its own name or trademark. For high-risk AI systems, design, risk management, documentation, conformity and post-market responsibilities.
Deployer Uses an AI system under its authority, except for personal, non-professional activity. For high-risk systems, instructed use, human oversight, monitoring and response to risks.
Importer, distributor or other covered operator Participates in placing or making a system available in the EU, or otherwise meets a role covered by the regulation. Responsibilities depend on the operator’s role and the applicable provisions.

These are not always fixed labels. Branding, involvement in development, the intended purpose, supply-chain position, actual use and later modifications can affect classification. In specified circumstances, an importer, distributor or deployer can assume provider obligations—for example, following certain modifications or a change to the system’s intended purpose. Article 3(4) contains the Act’s definition of a deployer.

How does the Act classify AI uses?

The regulation does not treat every AI system as prohibited or high-risk. It distinguishes specified prohibited practices, certain high-risk uses, uses subject to transparency requirements, and uses that do not fall into those categories. Classification turns on the Act’s definitions, the system’s intended purpose and the use cases set out in the regulation.

  • Prohibited practices: The Act bans specified practices. A business must determine whether its particular system and use fall within a prohibition.
  • High-risk systems: Certain uses are subject to more extensive requirements for providers and deployers. The category includes systems covered by Article 6 and the relevant annexes, with different rules for different routes into the category.
  • Transparency duties: Specific obligations apply to certain interactions or synthetic content. They are not a blanket transparency requirement for every AI tool.

Start the classification with what the system is intended to do, where and by whom it will be used, and the relevant legal category. A system’s technical label alone does not settle its status.

What must providers of high-risk AI systems do?

For a high-risk system, provider responsibilities extend beyond delivering a product. The Act requires a set of design, evidence and lifecycle controls, with details depending on the system and applicable provisions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Establish a risk-management system and data-governance practices.
  • Prepare technical documentation and keep required records.
  • Give deployers the information and instructions needed to use the system.
  • Design the system to enable human oversight.
  • Meet applicable accuracy, robustness and cybersecurity requirements.
  • Maintain quality management and complete the applicable conformity-assessment and registration steps.
  • Monitor the system after it enters the market or service and take corrective action when required.

These duties concern the system’s development and ongoing compliance. The exact assessment route and other procedural details depend on the system and the applicable provisions of Regulation (EU) 2024/1689.

What must deployers of high-risk AI systems do?

A business using a high-risk system has operational duties of its own; acquiring a system from a provider does not by itself discharge them.

  • Take appropriate technical and organisational measures to use the system in accordance with its instructions.
  • Assign human oversight to people with the necessary competence, training, authority and support.
  • Monitor the system’s operation.
  • Where the deployer controls input data, ensure that data is relevant and sufficiently representative for the system’s intended purpose.
  • Take the required escalation, suspension and incident-reporting actions when risks or serious incidents arise.

Some deployers and use cases have additional obligations. In particular, specified deployers must conduct a fundamental-rights impact assessment before first use. Whether that requirement applies must be checked against the relevant provisions, rather than assumed to apply to every deployer.

How are GPAI model obligations different?

The Act has a separate regime for providers of general-purpose AI models. It includes technical-documentation and information obligations; providers of some models also face additional duties related to systemic risk. These model-level obligations are not interchangeable with the high-risk AI-system requirements. A GPAI model and a high-risk system are distinct regulatory categories, even where a model is used within a system that is regulated separately.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When do the requirements apply?

The general application date in Article 113 is 2 August 2026. That is not a single start date for every provision: some rules applied earlier, and the consolidated regulation sets later dates for specified high-risk categories. The table gives the dates stated in the consolidated EUR-Lex text consulted, amended through 27 July 2026.

Provision or system category Relevant date stated in the consolidated text
Chapters I and II, subject to specified exceptions 2 February 2025
Provisions concerning governance, penalties and GPAI models 2 August 2025
General application date under Article 113 2 August 2026
High-risk systems under Article 6(2) in Annex III 2 December 2027
High-risk systems under Article 6(1) tied to product-safety legislation 2 August 2028

Transition provisions also apply to certain legacy systems and public-authority uses. A business with an existing system should check the specific transition rule that covers it rather than infer the deadline from the general application date. The European Commission’s official summary, “Rules for trustworthy artificial intelligence in the EU” (accessed 7 October 2026), also describes the staged approach and earlier application dates.

How should a business work out what applies?

  1. Map the activity and geography. Identify where the business is established, where the system is placed on the market or put into service, who uses it, and where its output is used.
  2. Assign the operator roles. Record who develops or commissions the system, whose name or trademark it is supplied under, who imports or distributes it, and who uses it under their authority. Reassess roles after a material modification or intended-purpose change.
  3. Classify the system and purpose. Check whether the specific use is prohibited, high-risk, subject to a transparency duty, or outside those categories under the Act.
  4. Identify the applicable obligations by role. Separate provider-side design and conformity work from deployer-side use, oversight and monitoring. Check for distinct GPAI-model obligations where relevant.
  5. Determine the operative date and transition rule. Match the system and use to the provision that applies, including any legacy-system or public-authority transition rule.
  6. Check other applicable laws. The AI Act does not displace other EU rules, including those concerning data protection, consumer protection, employment, product safety and regulated sectors.

This is a framework for identifying the issues, not a fact-specific legal determination. For operational decisions, consult the regulation’s current consolidated text, relevant guidance and applicable national enforcement arrangements; obtain legal advice where the classification or transition position is uncertain.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.