Who does the EU AI Act apply to?
AI regulation: the EU AI Act
The EU AI Act applies to more than AI developers. It can apply to providers, deployers, importers, distributors, authorised representatives, and certain product manufacturers, including some actors outside the EU where the Act's nexus rules are met. Your legal role depends on what you do with a specific AI system or GPAI model, not on your job title. That matters because obligations change by role, by risk tier, and sometimes by later role-flips under Article 25.
What this means
The shortest way to read the Act is this: first work out what you are in relation to a specific system or model, then work out what risk bucket that system or model sits in. The same organisation can be a provider for one system, a deployer for another, an importer for a third, and none of those for a fourth.
This page is about those roles and about the common traps. In practice, the biggest mistakes come from assuming only model builders are regulated, assuming a buyer is always "just" a deployer, or missing the moments when a distributor, deployer or product maker becomes a provider because it rebrands, materially changes, or repurposes a system.
As checked on 21 July 2026, the amending "Digital Omnibus on AI" had been adopted and signed, but the European Parliament's OEIL file still showed it as awaiting publication in the Official Journal. That means the current AI Act dates still formally stand unless and until that amending regulation is published and enters into force.
Why it matters
Role-mapping is not paperwork for its own sake. It decides who must do what, who carries pre-market and post-market responsibilities, who must hold technical documentation, who must check CE marking and declarations, who needs an EU authorised representative, who must inform people about AI use, and who can be fined if something is misclassified or wrongly shipped.
It also changes procurement, product design and governance. If you buy a tool, wrap it in your own brand, combine it with your product, or shift it into a high-risk use case, you can move from user to regulated operator with provider-level duties. That affects contracts, assurance, board reporting, incident handling, and launch timing.
For founders, operators and governance leads, this is one of the first practical AI Act questions to answer. If you get the role wrong, the compliance plan will usually be wrong too.
How it works
The roles the Act regulates
The Act uses role words very deliberately. A "provider" is the person or organisation that develops an AI system or general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark. A "deployer" is the person or organisation using an AI system under its authority, except where the system is used in the course of a purely personal non-professional activity. An "importer" is an EU-based actor that places on the market an AI system bearing the name or trademark of a third-country person. A "distributor" is another supply-chain actor, other than provider or importer, that makes an AI system available on the Union market. An "authorised representative" is an EU-based person or organisation formally mandated by a non-EU provider to act on its behalf under the Act.
That means the legal role is functional, not branding-driven. "We are only a platform", "we are only a reseller", or "we only wrapped someone else's model" does not settle the question. You have to ask what your organisation is doing in relation to each system or model.
Product manufacturers are a special case that matters most where AI is part of a regulated product. Article 2 brings in product manufacturers that place on the market or put into service an AI system together with their product and under their own name or trademark. Article 25 then says that, for certain high-risk product situations, the product manufacturer is treated as the provider of the high-risk AI system.
One organisation can occupy several roles at once. A company might import a third-country AI system, deploy that system internally, and separately provide a different AI-enabled product under its own brand. A useful practical discipline is to map roles system by system, not company by company.
Article 2 scope and the main exclusions
Article 2 is broader than many people expect. It covers providers placing AI systems on the EU market or putting them into service in the Union, providers placing GPAI models on the EU market, EU deployers, importers, distributors, product manufacturers, authorised representatives of non-EU providers, and affected persons in the Union. It also reaches certain third-country providers and deployers where the output produced by the AI system is used in the Union. This page only flags that extra-EU reach. The territorial detail belongs on the separate page about the Act outside the EU.
The exclusions matter, but they are narrower than many people assume. The Act does not apply to areas outside the scope of Union law and does not affect Member State competences concerning national security. It also does not apply where AI systems are placed on the market, put into service, or used exclusively for military, defence or national security purposes. "Exclusively" matters. If the same system is also used for civilian or commercial purposes, you cannot assume the whole thing is out of scope.
The Act also excludes AI systems or AI models specifically developed and put into service for the sole purpose of scientific research and development, and it excludes research, testing or development activity before a system or model is placed on the market or put into service. But that pre-market exclusion stops at real-world testing. Once you move into real-world conditions, the easy "research" answer usually disappears.
The personal-use carve-out is often overstated. The Act does not apply to obligations of deployers who are natural persons using AI systems in a purely personal non-professional activity. That does not create a general exemption for the provider of the consumer-facing system itself. A hobby user may fall outside deployer obligations while the provider still remains regulated.
How obligations differ by role and by risk tier
The Act is not a single checklist. Duties are layered by role and by category of AI.
At the prohibited end, the key rule is simple: these uses are not allowed to be placed on the market, put into service, or used. Scope and role still matter because the ban can catch providers and users of prohibited practices. Under the law currently in force, Chapters I and II already apply, so the scope rules, definitions, AI literacy rule and prohibited practices are already live.
For high-risk AI systems, provider duties are the heaviest. Providers have to ensure compliance with the Chapter III requirements, run the relevant conformity assessment, keep documentation and logs, draw up the EU declaration of conformity, affix CE marking, register where required, take corrective action and cooperate with authorities. Importers and distributors get their own gatekeeping duties for high-risk systems, for example checking conformity assessment, documentation, CE marking, instructions and contact details before placing or making systems available. Deployers of high-risk systems have their own operational duties, including using the system in line with instructions, assigning human oversight, ensuring relevant and sufficiently representative input data where they control it, monitoring operation, keeping logs under their control, and in some cases informing workers or affected persons.
For transparency-only systems, the pattern is different. Article 50 splits duties between providers and deployers. Providers must make sure direct interaction systems disclose that a person is dealing with AI, and providers of systems generating synthetic audio, image, video or text must make outputs detectable as artificially generated or manipulated. Deployers, not providers, carry the disclosure duty for emotion-recognition and biometric-categorisation exposure, for deep fake use, and for certain AI-generated or manipulated text published to inform the public on matters of public interest. Under the current AI Act text, these transparency duties still formally apply from 2 August 2026.
For GPAI, the regulated actor is the provider of the model, not every business that uses a model downstream. GPAI providers must prepare technical documentation, give downstream AI system providers the information they need, maintain a copyright policy, publish a training-data summary, and cooperate with the Commission and national authorities. Providers of GPAI models with systemic risk have extra duties. Those GPAI obligations have applied since 2 August 2025, and the Commission's enforcement powers, including fines, start on 2 August 2026.
At the lower-risk end, many systems do not have AI-Act-specific design or conformity duties at all. But that does not mean "nothing applies". Scope, definitions, AI literacy, existing sectoral law, data protection, consumer law, employment law and internal governance can still matter.
The Article 25 role-flip traps
Article 25 is where many organisations stop being what they thought they were. A distributor, importer, deployer or other third party becomes the provider of a high-risk AI system if it puts its own name or trademark on a high-risk system already on the market or in service, makes a substantial modification to a high-risk system that remains high-risk, or changes the intended purpose of a system, including a GPAI system, so that it becomes a high-risk AI system.
Those are the three classic role-flip traps.
The branding trap is the easiest to miss. White-labelling a high-risk system under your own trademark can move you into provider status even if you did not build the technology.
The modification trap depends on "substantial modification". The Act defines that as a change after placing on the market or putting into service that was not foreseen or planned in the original conformity assessment and that either affects compliance with the high-risk requirements or alters the intended purpose for which the system was assessed. Not every tweak qualifies. But architecture changes, major capability changes, or reworking a system so that the compliance basis no longer holds can.
The repurposing trap is especially important for downstream integrators. If you take a system that was not high-risk and put it into a use that makes it high-risk under Article 6, you can become the provider of that high-risk system. This is one reason role analysis has to be tied to actual intended purpose, not to generic labels like "assistant", "co-pilot" or "workflow tool".
Article 25 also changes the original provider's position. Once the role-flip happens, the original provider is no longer treated as the provider of that specific system for the purposes of the Regulation, but it must closely cooperate with the new provider and make available the information, technical access and assistance reasonably needed for compliance and conformity assessment. There is a narrow exception where the original provider clearly specified that its system was not to be changed into a high-risk AI system.
For regulated products, the product-manufacturer rule is parallel. Where a high-risk AI system is a safety component of a product covered by the relevant Union harmonisation legislation, the product manufacturer is treated as the provider if the AI system is placed on the market with the product under the manufacturer's name or trademark, or is put into service under that name or trademark after the product is placed on the market.
GPAI providers are not the same as downstream integrators
This distinction is one of the most useful in practice. The Act regulates providers of GPAI models at the model layer. It also regulates downstream providers of AI systems that integrate those models. Those are not the same job.
If you place a GPAI model on the EU market, you sit in the Chapter V frame. If you build a customer-facing AI system on top of someone else's model, you are usually dealing with the provider or deployer rules for your downstream system, plus any transparency or high-risk duties that system triggers. Article 53 is designed to support that split by requiring GPAI model providers to give downstream providers information and documentation so that downstream systems can comply.
That means most businesses that use a third-party general-purpose model are not automatically transformed into GPAI providers. But they do not escape regulation. They may become providers of the downstream system, and they still need to assess transparency, prohibited-use, high-risk and deployer issues.
The hard edge is modification. The Commission's GPAI guidance takes a pragmatic line and says not every change to a model triggers GPAI-provider obligations. Minor or limited changes are not enough on their own. But significant modifications can move the modifying actor into GPAI-provider territory. In other words, integrating is one thing; materially remaking the model is another.
For non-EU GPAI providers, there is also an authorised-representative requirement before placing the model on the EU market. That makes the representative role relevant at the model layer, not only for high-risk AI systems.
Dates and legal status as checked on 21 July 2026
As of 21 July 2026, the baseline law in force is still Regulation (EU) 2024/1689. The OEIL procedure file for 2025/0359(COD) showed the Digital Omnibus on AI as "procedure completed, awaiting publication in Official Journal". The adopted text had been signed on 8 July 2026, but I did not find a published final regulation number or Official Journal citation at the time of checking. So the current AI Act dates still formally govern.
On that current-law basis, Chapters I and II already apply from 2 February 2025. Chapter III Section 4, Chapter V, Chapter VII, Chapter XII and Article 78 apply from 2 August 2025, except Article 101. Everything else applies from 2 August 2026, except Article 6(1) and the corresponding obligations, which apply from 2 August 2027. For this page, that means the role definitions and scope rules are already live; GPAI duties are already live; Article 50 transparency duties and most remaining high-risk machinery under the current law still formally point to 2 August 2026; and Article 6(1) product-related high-risk timing still formally points to 2 August 2027.
If the adopted Omnibus is published and enters into force in its current form, that timing changes in important but not universal ways. It would add two new prohibited-practice points in Article 5 with effect from 2 December 2026. It would also create a transitional rule giving providers of synthetic-content systems already on the market before 2 August 2026 until 2 December 2026 to comply with Article 50(2). It would move the application date for Annex III stand-alone high-risk systems to 2 December 2027 at the latest and for Annex I product-related high-risk systems to 2 August 2028. But it would not move the already-running GPAI regime, and until publication those new dates are not yet the law in force.
The Commission guidance picture is also moving. The Commission's GPAI guidelines are already in place. Draft high-risk classification guidelines are still under consultation until 23 July 2026. The Commission also adopted Article 50 transparency guidelines on 20 July 2026, which are relevant to the provider and deployer split for disclosure duties.
Examples
A developer places a CV-screening tool on the EU market under its own brand. That actor is the provider. A bank that uses the tool in its own hiring process is the deployer. The provider and deployer do not share the same checklist: the provider carries the design, conformity and documentation burden for a high-risk system, while the bank's duties are about lawful use, human oversight, monitoring, logs under its control, and the related deployer obligations.
A distributor takes an existing high-risk AI system and sells it under the distributor's own trademark. Article 25 treats that distributor as the provider of that high-risk AI system. The practical consequence is not just commercial. Provider-level obligations move with the rebranding move, even if the underlying technology came from someone else.
A manufacturer places a product with an AI safety component on the market under the manufacturer's own name. In that product-law setting, the manufacturer is treated as the provider of the high-risk AI system. The original AI supplier does not necessarily disappear from the picture, but the manufacturer cannot assume the AI supplier remains the only regulated provider.
A non-EU company places a GPAI model on the EU market. That company needs an EU authorised representative. If an EU software company then integrates that model into its own customer-facing assistant, the EU software company is not automatically the GPAI model provider. It may instead be the provider of the downstream AI system, with its own system-level and transparency obligations.
Common misunderstandings
"Only the company that trained the model is regulated." No. The Act also regulates deployers, importers, distributors, authorised representatives, and certain product manufacturers. It can also make a downstream actor into a provider.
"If we bought the tool, we are only a deployer." Often yes, but not always. White-labelling, substantial modification, or repurposing a system into a high-risk use can flip you into provider status under Article 25.
"The personal-use exclusion means the system is outside the Act." Not quite. The carve-out is mainly for natural-person deployers using AI in a purely personal non-professional activity. It does not automatically exempt the provider of the system.
"Research pilots are always exempt." No. Pre-market research, testing and development can be outside scope, but real-world testing is not covered by that exclusion.
"The Omnibus already delayed everything." No. As checked on 21 July 2026, it had been adopted and signed but was still awaiting Official Journal publication, so the current AI Act dates still formally stand. Even once published, the adopted text does not wipe away the whole timetable. GPAI duties stay where they are, and the main shifts concern certain high-risk and synthetic-content milestones.
Risks and boundaries
This page is about roles, scope and role-flips. It is not the full territorial-scope analysis, not the full high-risk classification guide, and not a complete implementation manual for every obligation article by article.
Role analysis is system-specific. A single organisation can be a provider for one system and a deployer for another. It can also move roles over time as it rebrands, modifies, or repurposes systems. That is why static labels in procurement systems are often not enough.
The trickiest boundary issues are usually mixed-use systems and borderline high-risk cases. Military, defence and national-security exclusions are framed around exclusive use for those purposes, not around the identity of the organisation alone. Annex III cases can also be contested where a provider argues that Article 6(3) takes a system out of the high-risk bucket. The Commission's classification guidance is still not final as of 21 July 2026.
There is also a temporary legal-status boundary to state plainly. The Digital Omnibus on AI had completed the legislative procedure and been signed, but was still shown as awaiting Official Journal publication when checked. That means the current AI Act dates are still the formal legal baseline until publication and entry into force. Organisations should therefore monitor publication closely rather than assuming the amended dates already apply.
Nothing here is legal advice. It is a practical reading of the role structure and current official materials.
What to do next
Start with an AI use-case inventory. For each system or model, record who develops it, whose name it goes out under, who uses it, who imports it, who distributes it, whether it sits inside a regulated product, and whether its outputs are used in the Union.
Then assign a role per system. Do not assign one role to the whole company. Create a simple role matrix covering provider, deployer, importer, distributor, authorised representative and product manufacturer, plus a separate field for whether the asset is a GPAI model, a downstream AI system, or both at different layers.
Add an Article 25 checkpoint to product, procurement and change-control workflows. Any white-label arrangement, substantial model or system modification, or move into a high-risk use case should trigger reclassification before launch.
Separate model-layer and system-layer governance. If you build on a third-party GPAI model, make sure your teams know the difference between being a GPAI provider and being the provider or deployer of a downstream system. Make your suppliers commit to the documentation, technical access and assistance you may need if roles shift or if your downstream system becomes high-risk.
Finally, plan to the law that is in force today, while watching the Official Journal for the Omnibus publication event. For many teams, that means preparing now for 2 August 2026 obligations unless and until the published amending regulation changes the timetable.
FAQs
Does the EU AI Act apply only to companies established in the EU?
No. The Act also reaches certain third-country providers and deployers, including cases where the output of an AI system is used in the Union. Non-EU providers may also need an EU authorised representative in some cases.
Can one organisation be both a provider and a deployer?
Yes. You can be the provider of one AI system that you place on the market under your name, and the deployer of a different system that you use internally. You can also be both in relation to the same stack at different layers, for example as a downstream system provider that deploys its own system.
If I integrate a third-party GPAI model into my product, do I become a GPAI provider?
Not automatically. You are often the provider of the downstream AI system, not the provider of the upstream GPAI model. But significant modifications to the model can change that analysis.
When does a deployer become a provider?
The main Article 25 triggers are rebranding a high-risk system under your own name or trademark, making a substantial modification to a high-risk system, or changing the intended purpose of a non-high-risk system so that it becomes high-risk.
Is a natural person using AI for private life covered as a deployer?
No, not for deployer obligations in a purely personal non-professional activity. But that does not automatically remove the provider of the system from the Act.
Are prototypes and internal testing outside scope?
Pre-market research, testing and development can be outside scope, and systems specifically developed and put into service for the sole purpose of scientific research and development are excluded. But real-world testing is not covered by the pre-market research exclusion.
What is the practical difference between an importer and a distributor?
An importer is the EU-based actor that places on the market an AI system bearing the name or trademark of a third-country person. A distributor is another supply-chain actor, other than the provider or importer, that makes the AI system available on the Union market.
Has the Digital Omnibus on AI already changed the dates?
Not yet as a matter of formal law, as checked on 21 July 2026. It had been adopted and signed, but the OEIL file still showed it as awaiting Official Journal publication. Until publication and entry into force, the current AI Act dates remain the legal baseline.
