Reglog

← Guides & analysis

Which EU AI Act obligations apply to your company?

· 4 min read

The EU AI Act does not impose one rulebook on everyone. What you actually have to do is decided by two things: what role you play around an AI system, and how risky that system is. Get those two coordinates right and the obligations fall out.

This is a practical orientation, not legal advice — but it will tell you which part of the law to read first. When you want the specific obligations and deadlines for your situation, see which obligations apply to your company.

First coordinate: your role

The Act assigns duties by role, and one company can hold several roles for different systems.

  • Provider — you develop an AI system (or have one developed) and put it on the market or into service under your own name or brand. Providers carry the heaviest obligations, especially for high-risk systems.
  • Deployer — you use an AI system in the course of your work. Most companies are deployers. You have real obligations even when you bought the system from someone else.
  • Importer — you place an AI system from a non-EU provider onto the EU market.
  • Distributor — you make an AI system available on the market without being the provider or importer.

A crucial trap: if you substantially modify a high-risk system, or put your own name on it, you can become a provider in the eyes of the law — and inherit a provider's obligations.

Second coordinate: the risk tier

The Act sorts AI by the risk it poses, and the tier sets the intensity of the rules.

  • Unacceptable risk (prohibited). A short list of practices — such as social scoring by public authorities and certain manipulative or exploitative systems — is banned outright.
  • High risk. AI used as a safety component of regulated products, or used in the sensitive domains listed in Annex III (employment and worker management, access to essential public and private services, creditworthiness, biometric identification, education, law enforcement, critical infrastructure). This tier carries the substantive engineering and governance obligations: risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness, and a conformity assessment before going to market.
  • Limited / transparency risk. Systems that interact with people or generate content — chatbots, and AI that produces synthetic text, image, audio, or video — must meet transparency duties, such as telling people they are dealing with AI and marking AI-generated content.
  • Minimal risk. Everything else — the large majority of AI uses — carries no new mandatory obligations under the Act.

Separately, general-purpose AI (GPAI) models — the foundation models that other products build on — have their own dedicated obligations, with stricter rules for models judged to pose systemic risk.

Putting the two together

Your obligations are the intersection of your role and your tier. A few common cases:

  • You use an AI hiring or credit tool (deployer, high risk). You must use it according to the provider's instructions, ensure meaningful human oversight, monitor it, and be transparent with the people it affects.
  • You build a customer chatbot or a generated-content feature (provider, limited risk). Your main duties are transparency: make clear users are interacting with AI, and mark AI-generated media.
  • You build or fine-tune a foundation model (GPAI provider). You face the GPAI obligations — technical documentation, copyright policy, training-data summary — and more if the model is systemic.
  • You only use low-stakes internal tools (minimal risk). No new mandatory obligations, though good documentation is still wise.

What to do next

  1. List your AI systems and, for each, write down your role and the closest risk tier.
  2. Start with anything high-risk — that is where the real work (and the real penalties) live.
  3. Watch the dates. The obligations phase in between 2025 and 2027, so "which rules apply" changes over time. See the EU AI Act timeline.

The fastest way to get your own list: answer three questions about your AI use and we will show you the verified obligations that match — sorted by deadline. To be told when those obligations change, join the waitlist.

The official text is Regulation (EU) 2024/1689. This article is an information service to help you orient — it is not legal advice.

Frequently asked questions

Does the EU AI Act apply to my company if we're not based in the EU?

It can. The AI Act applies to providers and deployers outside the EU when the output of their AI system is used in the EU. Being established elsewhere does not, by itself, put you out of scope.

We only use AI tools we bought from someone else. Are we still covered?

Yes — you are a 'deployer'. Deployers have their own obligations (for example, using high-risk systems according to instructions, human oversight, and transparency to people affected), even though most of the heavy engineering duties sit with the provider.

What counts as a high-risk AI system?

Broadly, AI used as a safety component of a regulated product, or AI used in the sensitive areas listed in Annex III — such as employment, access to essential services, credit, biometric identification, education, and critical infrastructure. Most obligations attach to this tier.

See which obligations apply to your company → or join the waitlist

This is an information service, not legal advice.