Compyl
GRC Your Way

Who Does the EU AI Act Apply To?

Last updated: August 13, 2026

The EU AI Act applies to six operator roles across the AI value chain: providers, deployers, importers, distributors, product manufacturers, and authorized representatives. It covers any organization that places an AI system on the EU market or puts one into service in the EU, and it reaches companies outside the EU whenever the output of their AI system is used inside the Union. If your AI touches the EU market or EU users in a professional context, some part of the Act almost certainly applies to you.

This guide breaks down each role, the extraterritorial rules, and the exemptions so you can determine exactly where your organization stands. It is one part of our broader AI governance guide, which maps the full landscape of AI regulations and frameworks.

Key takeaways

  • The Act defines six regulated roles: provider, deployer, importer, distributor, product manufacturer, and authorized representative. Your obligations depend on which role you hold for each AI system.
  • The Act is extraterritorial. Non-EU companies are covered when they place AI on the EU market or when the output of their system is used in the EU.
  • Obligations scale with risk tier (prohibited, high risk, limited risk, minimal risk), not with company size or industry.
  • Exemptions cover military and national security uses, purely personal non-professional use, scientific research, and most free and open-source models.
  • Following the Digital Omnibus, obligations for Annex III high-risk systems now apply from December 2, 2027, but the prohibitions, general-purpose AI rules, and transparency duties are already in force.

What does Article 2 of the EU AI Act cover?

Article 2 sets the scope of the regulation. It applies to: (a) providers placing AI systems on the EU market or putting them into service in the EU, regardless of where the provider is established; (b) deployers of AI systems established or located in the EU; (c) providers and deployers located in third countries where the output produced by the AI system is used in the EU; (d) importers and distributors of AI systems; (e) product manufacturers that place an AI system on the market together with their product under their own name or trademark; and (f) authorized representatives of non-EU providers.

Two things stand out. First, the Act follows the AI system, not the company: a single organization can hold different roles for different systems. Second, clause (c) is the long arm of the regulation. Even with no EU office, no EU customers, and no EU marketing, a company can be in scope if the output of its AI system ends up being used in the Union.

What are the six operator roles under the EU AI Act?

RoleWho it isCore obligations (high-risk systems)
ProviderDevelops an AI system or GPAI model, or has one developed, and places it on the market under its own name or trademarkRisk management, data governance, technical documentation, logging, transparency, human oversight, accuracy and robustness, conformity assessment, CE marking, registration
DeployerUses an AI system under its own authority in a professional contextUse per instructions, human oversight, input data quality, monitoring, log retention, worker notification, and in some cases a fundamental rights impact assessment
ImporterEU-established entity placing a third-country provider’s system on the EU marketVerify conformity assessment, documentation, and CE marking before placing on the market
DistributorMakes a system available on the EU market without being provider or importerVerify CE marking and documentation, hold non-conforming systems back, cooperate with authorities
Product manufacturerPlaces a product on the market with an embedded AI system under its own nameTakes on provider obligations for the embedded AI system
Authorized representativeEU-established party appointed in writing by a non-EU providerVerify and hold documentation, act as contact point for regulators

The provider versus deployer distinction carries the most weight, because providers carry the heaviest compliance load. Be aware that roles can shift: a deployer becomes a provider if it puts its own name or trademark on a high-risk system, substantially modifies one, or changes the intended purpose of a system in a way that makes it high risk. Fine-tuning a foundation model for a high-risk use case can trigger exactly this reclassification.

Does the EU AI Act apply to companies outside the EU?

Yes. The Act applies to non-EU providers that place AI systems or general-purpose AI models on the EU market, and to non-EU providers and deployers whose system output is used in the EU. A US software vendor selling an AI-powered screening tool to a German customer is in scope. So is a UK bank running a resume-ranking model from London to fill roles in its Dublin office, because the output is used in the Union.

Non-EU providers of high-risk systems must also appoint an EU-based authorized representative before making their systems available in the Union. If you sell software internationally, treat the AI Act the way most companies learned to treat GDPR: as a de facto global baseline rather than a regional rule. Our overview of EU AI Act compliance for GRC teams covers what this means operationally.

Who is exempt from the EU AI Act?

The Act carves out several areas. AI systems placed on the market or used exclusively for military, defense, or national security purposes are out of scope, as are systems used by non-EU public authorities under international law enforcement or judicial cooperation agreements that offer adequate safeguards. AI systems and models developed and used solely for scientific research and development are exempt, and so is research, testing, and development activity before a system is placed on the market, although real-world testing is still regulated.

Individuals using AI in a purely personal, non-professional capacity have no deployer obligations. Free and open-source AI is largely exempt too, with an important caveat: the exemption falls away if the system is a prohibited practice, qualifies as high risk, or falls under the Article 50 transparency rules. Open-source general-purpose models with systemic risk also remain covered.

When do the obligations actually apply?

The Act entered into force on August 1, 2024, and its obligations arrive in waves. The Article 5 prohibitions (social scoring, manipulative techniques, and other banned practices) have applied since February 2, 2025. Obligations for general-purpose AI model providers have applied since August 2, 2025. The Article 50 transparency duties, including AI content labeling and chatbot disclosure, took effect on August 2, 2026.

The dates for high-risk systems changed in mid 2026. The Digital Omnibus, which entered into force on July 27, 2026, deferred the compliance deadline for standalone high-risk systems under Annex III from August 2, 2026 to December 2, 2027, and for high-risk AI embedded in regulated products under Annex I to August 2, 2028. Penalties are substantial: up to 35 million euros or 7 percent of global annual turnover for prohibited practices. See our EU AI Act compliance timeline for the full schedule of dates.

How should you determine your role and obligations?

Work system by system. First, inventory every AI system and model your organization builds, buys, embeds, or uses. Second, assign a role for each one: are you the provider, the deployer, or both? Third, classify each system by risk tier, since that determines which obligations attach. Fourth, check extraterritorial exposure by asking where each system’s output is actually used. Finally, assign an owner for each compliance obligation with a deadline tied to the dates above.

Many organizations anchor this work in ISO 42001, the certifiable AI management system standard, because it provides the governance structure (roles, risk assessment, impact assessment, monitoring) that the AI Act expects you to demonstrate. Our breakdown of ISO 42001 requirements shows how the pieces map together.

Frequently asked questions

Does the EU AI Act apply to small businesses and startups?

Yes. There is no size threshold. A two-person startup providing a high-risk system faces the same core obligations as an enterprise. The Act does include SME support measures, such as priority access to regulatory sandboxes, reduced conformity assessment fees, and simplified technical documentation formats.

Are internal-only AI tools covered?

Yes. Deployer obligations apply to professional use of AI regardless of whether the system is customer facing. An HR team in the EU using an AI resume screener is a deployer of a high-risk system even though the tool never touches a customer.

Can one company hold more than one role?

Yes, and most do. A company can be a provider of the product it sells, a deployer of the AI tools it uses internally, and an importer of a third-country system it brings to the EU market. Roles are assessed per system, not per company.

Does using ChatGPT or another general-purpose model make us a provider?

Ordinarily no, you are a deployer. You can become a provider if you place a system built on the model on the market under your own name, substantially modify a high-risk system, or repurpose a system into a high-risk use.

What happens if we ignore the Act because we are not based in the EU?

Enforcement applies to non-EU operators in scope, with fines up to 35 million euros or 7 percent of worldwide turnover for the most serious violations. Market access is also at stake: importers and distributors must refuse non-conforming systems, so non-compliant vendors lose EU customers.

Compyl helps compliance teams operationalize exactly this work: building the AI system inventory, mapping each system to a role and risk tier, and running the controls that regulators and auditors expect. If you are working toward a certifiable AI governance program, see how Compyl supports ISO 42001 compliance from gap assessment through audit.

By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies