EU AI Act Compliance: Who Does It Apply To & Key Roles Explained
When the GDPR landed, many global companies were caught off guard. It appears history might be repeating itself – this time with AI. The EU AI Act is broader than most realize. Even companies with no EU address might be on the hook. If your AI impacts anyone in Europe, this law likely applies – whether you built the tech or just use it.
What you’ll learn in this article:
Who the AI Act applies to and why location doesn’t matter
How to figure out if you're an AI provider, deployer, or something else
Why knowing your role matters more than ever
1. Not just about sci-fi robots – it’s about everyday business tech
The EU AI Act isn’t only for futuristic tech firms building humanoid robots. It applies to nearly any AI system – defined broadly as software that uses machine learning, logic, or statistical approaches to produce outputs.
That includes things like a chatbot recommending insurance products, an algorithm ranking job applicants and model forecasting loan defaults. Whether it’s integrated in customer service, healthcare, or HR – if it performs automated decision-making and impacts people, it probably qualifies.
2. It’s not just for EU companies
Even if you’re not based in the EU, the Act can still apply.
Why? Because it’s based on where the AI system is used, not where it was built. That includes, for instance startups in U.S. selling a general-purpose AI model to European clients, or a Canadian SaaS -tool that uses AI to filter resumes for a German employer. Like the GDPR before it, the EU AI Act applies extraterritorially. It doesn’t matter where you are. It matters who your tech touches.
3. Real example: OpenAI and ChatGPT
In 2023, Italy temporarily banned ChatGPT over data privacy concerns. OpenAI had to act quickly to make adjustments and get reinstated. This case showed that even global leaders must adapt to EU rules. If your AI product – or the data it handles – touches EU residents, compliance is non-negotiable.
4. What’s not covered? A few exceptions
While the EU AI Act casts a wide net, a few things are outside its scope:
Purely scientific research projects are excluded – as long as they’re not used commercially.
Military or national security AI systems fall under separate rules.
And if you’re just tinkering with AI at home for personal use? No worries – private, non-professional AI use is exempt, too.
These carveouts ensure the law stays focused on real-world commercial and societal impacts – not your hobby projects or state secrets.
5. Are you a Provider, Deployer, or something else?
The AI Act distinguishes between several key roles. Why does this matter? Because your role defines your responsibilities under the law. Here’s a quick primer:
5.1 AI Provider
If you develop an AI system or have one developed and then place it on the EU market under your name or trademark, you wear the provider hat – even if you give the model away for free.
As a provider of high-risk AI your key responsibilities are (examples):
Run a risk-management system: identify, evaluate, and mitigate risks across the AI lifecycle;
build or adopt a quality-management system covering design, testing and post-market controls;
draw up technical documentation and enable logging;
maintain strong data governance: establish clear processes for data collection, labeling, and version control;
pass a conformity assessment when necessary (some systems need third-party review, others allow self-assessment, CE marking for AI);
give deployers clear instructions and transparency notices;
build for human oversight;
meet accuracy, robustness & cybersecurity standards: your AI must perform reliably and withstand attacks or misuse;
ensure your own staff’s AI literacy.
From Minor Upgrades to Major Obligations: When a Deployer Becomes a Provider
Here is an example. A German logistics company initially uses an American tech company's route optimization AI, operating as a deployer. The company later fine-tunes the algorithm for European traffic patterns, adds GDPR compliance features, rebrands the system as "EuroLogistics AI," and sells it to other logistics companies.
The minute that customized and rebranded model goes to market, the logistics company becomes a provider with the full compliance stack. This happens even though they didn't build the original technology from scratch.
5.2 AI Deployer
You become a deployer when you integrate or use an AI system under your authority as part of your operations. Private, non-professional tinkering is excluded, but almost any business use counts.
Deployer’s key duties of high-risk AI:
Use the system as instructed and keep records to prove it;
assign trained staff for human oversight and continuous performance monitoring;
input data quality: if the deployer controls the system's input data, deployer must ensure that the input data is relevant and sufficiently representative for the intended purpose of the system;
monitor the high-risk system and report serious incidents to both the provider and the national authority;
logs: retain automatically generated logs for at least 6 months (or according to national legislation);
maintain your team’s AI literacy proportional to their role;
Data protection impact assessment (under GDPR) must be done when necessary;
perform a fundamental-rights impact assessment before deploying certain high-risk systems.
Deployer accountability: Bridging AI potential with responsible implementation
Think of a multinational corporation that uses an AI-powered recruitment tool to screen job applications and rank candidates. As the deployer, the HR department must ensure trained staff review the AI's recommendations before making hiring decisions, maintain records of how the system is used, and monitor for potential bias in candidate selection. They're responsible for ensuring the resumes and application data fed into the system are representative and relevant.
If the system shows signs of discriminatory patterns or other serious issues, they must report these incidents to both the AI provider and relevant authorities. The HR should also ensure all team members using the tool receive appropriate training on its capabilities and limitations.
5.3 Something else?
If you import, re-sell, or act as the EU proxy for an overseas provider, you may also pick up importer, distributor or authorized-representative duties. Those roles carry their own paperwork and recall obligations.
Importer: any EU-established company that brings an AI system in from outside the Union.
Distributor: anyone who resells or bundles an AI product as is in the EU market.
Authorized Representative: the EU proxy for a non-EU provider.
Why does this matter? Because even if your company never develops an AI model from scratch, simply importing AI-powered tools, white-labelling SaaS solutions, or representing non-EU vendors can transform your legal status overnight. What seemed like a simple business decision could suddenly subject you to significant regulatory obligations under the AI Act.
Each of these roles comes with different legal obligations under the EU AI Act. Understanding your exact classification is crucial for determining which specific requirements apply to your organization.
6. Know your role, act smart
Understanding your role isn’t just a legal checklist – it’s how you start building a smart, targeted compliance strategy. If you know you're a deployer, you can prioritize transparency and oversight. If you’re a provider, you know you’ll need technical documentation and risk management. Get this wrong, and you could face surprise audits or fines. Get it right, and you’re a trusted player in the EU AI ecosystem.
A quick warning – roles aren’t fixed forever. If a company customizes an AI model heavily or rebrands it under their name, they may become a “provider” under the law – even if they didn’t build it from scratch. This happens more often than you think.
Therefore, if your team is modifying models or putting your logo on third-party tools, pause and recheck your status. You may have just adopted a new set of obligations.
Wrapping Up – this isn’t optional
The EU AI Act casts a wide net and it’s already (partly) in effect. Whether you’re a startup founder, compliance officer, or product lead, now’s the time to:
Map your AI use cases
Identify your role(s)
Start preparing for the obligations that come with it
Knowing where you stand is the first real move toward trustworthy, future-proof AI.
Next week: We'll unpack the AI Act’s risk categories from banned systems to those with lighter obligations.
Previous week: Read the previous article EU AI Act – Why This New Law Is a Game-Changer for Businesses here: https://www.vestra.fi/blog/eu-ai-act-why-this-new-law-is-a-game-changer-for-businesses-20250624