Your Company Might Already Be Subject to the EU AI Act,Here's Why
The EU AI Act's reach extends across the entire AI supply chain, not just to companies that build artificial intelligence systems. Organizations that develop, provide, import, distribute, integrate, or professionally use AI systems in the European Union must comply with the regulation. Even companies established outside Europe can fall under its scope when their AI systems are placed on the EU market or their outputs are used within the Union.
Who Actually Has to Comply with the EU AI Act?
The regulation applies to a surprisingly broad range of public and private organizations. Under Article 2 of the EU AI Act, compliance obligations extend across multiple roles in the AI ecosystem. Understanding which category your organization falls into is critical because responsibilities differ significantly depending on your specific role.
The organizations that must comply include:
- AI System Providers: Organizations that develop AI systems or general-purpose AI models and place them on the market under their own name or trademark, including software companies building AI-powered tools and businesses that commission developers to build systems they then market under their own brand.
- Deployers: Employers, financial institutions, healthcare organizations, retailers, universities, government departments, insurers, and manufacturers that use AI systems in a professional context under their authority.
- Importers: Organizations established in the EU that place an AI system on the market when that system carries the name or trademark of an organization established outside the Union.
- Distributors: Organizations within the AI supply chain that make AI systems available on the EU market without being the provider or importer, and may need to verify that regulatory requirements have been completed before making certain regulated systems available.
- Product Manufacturers: Businesses placing AI-enabled regulated products on the European market, particularly where AI systems are incorporated into products covered by existing EU product safety legislation.
A French employer using AI to screen employment applications qualifies as a deployer and could face additional obligations if the system falls within the Act's high-risk categories. Similarly, a financial institution using AI to support creditworthiness assessments may also qualify as a deployer with specific regulatory responsibilities.
Does the EU AI Act Apply to Companies Outside Europe?
One of the most significant aspects of EU AI Act compliance is its potential application to organizations established outside the European Union. The regulation applies to providers placing AI systems or general-purpose AI models on the EU market regardless of whether those providers are established inside or outside the Union. This means a US, UK, Canadian, Japanese, or other non-EU technology company may fall within the Act when supplying AI products or services to customers in Europe.
The scope extends even further in certain circumstances. Under Article 2, providers and deployers established in third countries may also be covered where the output produced by an AI system is used within the European Union. Consider a multinational company operating a centralized AI analytics system from the United States. If that system generates recommendations that are subsequently used by the company's French subsidiary to make employment, financial, or operational decisions, the organization should assess whether the Act's territorial scope applies. A non-EU SaaS provider supplying an AI recruitment tool to companies in France cannot assume that incorporation outside Europe removes it from the regulation.
How to Determine Your Organization's Role Under the EU AI Act
- Identify Your Legal Role: Begin by determining the legal role your organization plays for each AI system, recognizing that a company may be a provider for one system, a deployer for another, and potentially both simultaneously.
- Document Your AI Systems: Create a comprehensive inventory of all AI systems your organization develops, uses, imports, or distributes, including details about their intended purpose and how they are deployed in practice.
- Assess Applicable Obligations: Evaluate which regulatory requirements apply based on your role and the risk classification of each system before the relevant requirements become enforceable.
- Monitor Role Changes: Recognize that your organization's legal role can vary between systems and may change during an AI system's lifecycle, particularly when modifying third-party systems or changing their intended purpose.
Organizations should not assume they have a single permanent classification under the AI Act. A company might purchase a third-party AI assistant and use it internally, primarily acting as a deployer. The same company could separately develop an AI-powered compliance tool and make it available to customers under its own brand, qualifying as a provider for that system. Role changes can also occur when organizations modify third-party AI systems. Under certain circumstances, an organization may take on provider responsibilities when it puts its own name or trademark on an existing regulated AI system, makes a substantial modification, or changes the system's intended purpose in a manner covered by the regulation.
Provider obligations can be substantial where systems fall into regulated categories such as high-risk AI. Depending on the system, providers may need to address areas including risk management, technical documentation, record keeping, transparency, human oversight, accuracy, robustness, cybersecurity, and conformity assessment. This makes lifecycle governance essential for any organization operating in the AI space.
The key takeaway is straightforward: if your organization touches AI in any way within Europe's market, you likely have compliance responsibilities under the EU AI Act. Organizations operating in or supplying AI to the European market should determine their role, document their AI systems, and assess applicable obligations before the relevant requirements become enforceable.