Clef · Try the live demo →
Regulation (EU) 2024/1689, amended by 2026/1744

The first question is not what you must do — it is whether this reaches you

Two independent grounds put a company outside the Union in scope: placing a system on the Union market, or having its output used inside the Union. Neither has a revenue threshold. The small-company relief in the Act concerns how a penalty is calculated, not whether the rules apply — a distinction that vendor material collapses regularly and that costs money when it does.

Which role does it put you in?

Obligations attach to roles, not to organisations. The same company can hold two at once for two different systems — and change role without noticing.

Provider

Develops an AI system or a general-purpose AI model and places it on the Union market, or puts it into service under its own name or trademark. Carries the bulk of the obligations. Establishment outside the EU is irrelevant to this.

Deployer

Uses an AI system under its own authority in a professional capacity. Fewer obligations, but they are the ones that bite in daily operation: human oversight, transparency, keeping to the intended purpose.

Both at once

Under Article 25 a deployer becomes a provider by putting its own name on a system, substantially modifying it, or using it for a purpose the original provider did not intend. Assembling a chatbot from an API is the common case.

Importer and distributor

Intermediate roles with verification duties — that the conformity assessment was carried out, that the documentation exists, that the CE marking is present.

What actually binds a deployer today

Three things, and the high-risk regime is not among them for most organisations.Article 5 prohibitions have applied since February 2025 — mostly theoretical, with one exception that turns up in ordinary software: emotion inference in the workplace, sold under names like sentiment analysis, engagement score or call quality.

Article 4 on AI literacy, same date. The Omnibus softened the standard from ensuring a sufficient level to supporting its development, and clarified that no particular level need be guaranteed for any individual. Doing nothing still fails it.

Article 50 transparency, since August 2026 and not postponed. This is the one that arrived in 2026 while everyone was watching the part that left it.

Frequently asked

Does the EU AI Act apply to a company established outside the EU?+

Yes, on two independent grounds. Placing an AI system or a general-purpose AI model on the Union market brings a provider in scope regardless of where it is established. Separately, a provider or deployer outside the Union is in scope where the output produced by the system is used in the Union. Neither ground has a revenue threshold.

What changed in 2026?+

Regulation (EU) 2026/1744 — the Digital Omnibus on AI — was published on 24 July 2026 and entered into force on 27 July. It postponed Annex III high-risk obligations from 2 August 2026 to 2 December 2027 and Annex I from 2 August 2027 to 2 August 2028, rewrote Article 4 on AI literacy, and added one prohibition to Article 5. Everything already in application stayed in application.

Are we a provider or a deployer?+

Usually a deployer, until you are not. Article 25 turns a deployer into a provider in three situations: putting your own name or trademark on a system, substantially modifying a high-risk system, or changing its intended purpose so that it becomes high-risk. Building an assistant on top of a model API and offering it to customers is the case that catches most organisations by surprise.

Is there a small-company exemption?+

Not from the obligations. SMEs and start-ups get procedural relief — simplified technical documentation in some cases, priority access to regulatory sandboxes — and a different penalty calculation, where the lower rather than the higher of the two ceilings applies. Scope itself does not depend on size or turnover.

How does this interact with the GDPR?+

They apply in parallel and protect different things. The GDPR governs personal data; the AI Act governs AI systems as products, including systems that touch no personal data at all. Compliance with one is not a defence under the other, and the roles do not map onto each other: controller and deployer are determined by different criteria and do not always coincide.

What should a non-EU company do first?+

Determine scope, then check Article 50. Scope is usually answered in an afternoon — do we place anything on the Union market, is any output used there. Article 50 is the obligation that already applies and that almost nobody has checked: disclosure where a system speaks to people, marking of synthetic content, disclosure for deepfakes and for published text on matters of public interest.