Food Hygiene Rules for Restaurant Staff
Learn essential food hygiene rules restaurant staff must follow, from handwashing and illness reporting to safe food handling, storage, and cleaning.
Learn who must meet EU AI Act Compliance requirements, including providers, deployers, importers, distributors, manufacturers and non-EU companies.
The EU AI Act does not apply only to technology companies that develop artificial intelligence. Its reach extends across the AI supply chain, covering organizations that develop, provide, import, distribute, integrate, or professionally use AI systems in the European Union. It can also apply to companies established outside Europe when their AI systems are placed on the EU market or their outputs are used within the Union.
In practical terms, EU AI Act Compliance begins by identifying the legal role your organization plays for each AI system. A company may be a provider for one system, a deployer for another, and potentially both at the same time.
Organizations operating in or supplying AI to the European market should therefore determine their role, document their AI systems, and assess applicable obligations before the relevant requirements become enforceable.
The EU AI Act applies to a broad range of public and private organizations rather than one specific type of technology business.
Under Article 2 of the EU AI Act, its scope includes providers placing AI systems or general-purpose AI models on the EU market, deployers located or established within the EU, importers, distributors, product manufacturers, and authorized representatives.
Certain organizations outside the European Union can also fall within its scope.
Understanding these categories is fundamental because responsibilities differ depending on the organization's role.

A provider is an organization or individual that develops an AI system or general-purpose AI model, or has one developed, and places that system on the market or puts it into service under its own name or trademark.
This definition covers more than traditional AI developers.
For example, a software company that builds and sells an AI-powered recruitment platform will normally be considered a provider. However, a company that commissions another developer to build an AI system and then markets it under its own brand may also become the provider under the Act.
Provider obligations can be substantial where systems fall into regulated categories such as high-risk AI.
Depending on the system, providers may need to address areas including risk management, technical documentation, record keeping, transparency, human oversight, accuracy, robustness, cybersecurity, and conformity assessment.
Organizations developing or commercializing AI should therefore establish clearly whether they qualify as providers before determining which requirements apply.
Many companies affected by the EU AI Act will never develop an AI model themselves. They may instead qualify as deployers.
A deployer is generally a person or organization using an AI system under its authority in a professional context.
This means employers, financial institutions, healthcare organizations, retailers, universities, government departments, insurers, manufacturers, and many other businesses can fall within the regulatory framework simply through the way they use AI.
A French employer using AI to screen employment applications is one example.
A financial institution using AI to support creditworthiness assessments may also qualify as a deployer and could face additional obligations if the system falls within one of the Act's high-risk categories.
However, being a deployer does not automatically mean every requirement in the AI Act applies. Responsibilities depend heavily on the type of AI system, its intended purpose, and its risk classification.
Organizations therefore need more than a list of the AI tools they use. They need to understand how each tool is actually being deployed. This should be an important part of how businesses prepare for AI Act compliance.
The EU AI Act also covers organizations involved in supplying AI systems rather than creating or directly using them.
An importer can be an organization established in the EU that places an AI system on the market when that system carries the name or trademark of an organization established outside the Union.
A distributor is generally an organization within the AI supply chain that makes an AI system available on the EU market without being the provider or importer. These businesses may need to verify that relevant regulatory requirements have been completed before making certain regulated systems available.
Product manufacturers may also fall within the Act. This is particularly relevant where AI systems are incorporated into products covered by existing EU product safety legislation.
For example, manufacturers placing certain AI-enabled regulated products on the European market may face responsibilities connected to both the AI Act and existing sector-specific product legislation.
AI compliance therefore cannot be treated solely as a software-development issue. It can affect procurement, manufacturing, distribution, product management, legal teams, and supply-chain governance.
One of the most important elements of EU AI Act Compliance is its potential application to organizations established outside the European Union.
The regulation applies to providers placing AI systems or general-purpose AI models on the EU market regardless of whether those providers are established inside or outside the Union.
This means a US, UK, Canadian, Japanese, or other non-EU technology company may fall within the Act when supplying AI products or services to customers in Europe. The scope can extend further.
Under Article 2, certain providers and deployers established in third countries may also be covered where the output produced by an AI system is used within the European Union.
Consider a multinational company operating a centralized AI analytics system from the United States. If that system generates recommendations that are subsequently used by the company's French subsidiary to make employment, financial, or operational decisions, the organization should assess whether the Act's territorial scope applies.
Similarly, a non-EU SaaS provider supplying an AI recruitment tool to companies in France cannot assume that incorporation outside Europe removes it from the regulation.
Organizations should examine where their AI systems are marketed, deployed, and used rather than relying entirely on the location of corporate headquarters.

Organizations should not assume they have a single permanent classification under the AI Act. Their legal role can vary between systems and may even change during an AI system's lifecycle.
A company might purchase a third-party AI assistant and use it internally. In that situation, it may primarily act as a deployer.
The same company could separately develop an AI-powered compliance tool and make it available to customers under its own brand. For that system, the company could qualify as a provider.
Role changes can also occur when organizations modify third-party AI systems.
Under certain circumstances, an organization may take on provider responsibilities when it puts its own name or trademark on an existing regulated AI system, makes a substantial modification, or changes the system's intended purpose in a manner covered by the regulation. This makes lifecycle governance essential.
An effective AI governance framework should record the organization's role for each AI system and reassess that classification whenever the technology, intended purpose, branding, or deployment model changes.
Companies should therefore maintain an AI inventory that identifies the system owner, supplier, organizational role, intended use, geographic deployment, and applicable risk category.
Although the regulation has broad scope, some AI activities are specifically excluded or receive different treatment.
Natural persons using AI systems for purely personal and non-professional activities generally fall outside the deployer requirements.
For example, an individual using an AI assistant privately is different from an employer using the same technology within a professional process.
The regulation also contains exclusions concerning AI systems developed or used exclusively for military, defense, or national-security purposes.
Certain research and development activities may also fall outside specific requirements before the relevant AI system or model is placed on the market or put into service.
However, organizations should be cautious when relying on these exclusions.
Describing a project as experimental, research-based, internal, or open source does not automatically remove it from the AI Act. The precise conditions of the regulation must still be considered.
Open-source AI is particularly important because the Act provides specific treatment for certain free and open-source AI systems and general-purpose AI models, but there is no universal exemption covering everything released under an open-source licence. The European Commission provides additional guidance concerning general-purpose AI model obligations.
Businesses relying on an exclusion should document the legal reasoning rather than simply assuming that the regulation does not apply.
The organization's role determines which obligations need to be investigated.
|
Organization or role |
Typical example |
Why the EU AI Act may apply |
|
Provider |
Company selling its own AI recruitment software |
Places an AI system on the EU market under its own name |
|
Deployer |
Employer using AI to evaluate job applicants |
Uses an AI system professionally under its authority |
|
Non-EU provider |
US company selling an AI platform to French businesses |
Places an AI system on the EU market |
|
Importer |
EU company bringing a third-country AI system into the market |
Introduces an externally supplied AI system into the EU |
|
Distributor |
Reseller supplying AI software within the EU |
Makes AI systems available within the supply chain |
|
Product manufacturer |
Manufacturer selling a regulated product incorporating AI |
AI forms part of a product placed on the EU market |
|
GPAI provider |
Company supplying a general-purpose AI model |
Specific obligations apply to general-purpose AI model providers |
This table provides an initial screening framework rather than a definitive legal classification.
One company may occupy several categories depending on its AI portfolio.
The EU AI Act entered into force on 1 August 2024, but its requirements have been introduced progressively.
Rules concerning prohibited AI practices and AI literacy obligations began applying on 2 February 2025.
Organizations covered by Article 4 must take measures, to their best extent, to ensure that staff and other persons dealing with AI systems on their behalf possess an appropriate level of AI literacy. The required level depends on factors including their technical knowledge, experience, education, training, and the context in which the systems are used.
Specific obligations relating to general-purpose AI models began applying from 2 August 2025.
Other parts of the regulatory framework have subsequently entered into application according to the Act's phased timetable and subsequent amendments.
For high-risk AI systems, organizations should pay particular attention to the revised timeline introduced through the 2026 Digital Omnibus framework.
Main obligations affecting Annex III high-risk AI systems are scheduled to apply from 2 December 2027, while corresponding requirements for high-risk AI systems connected with certain Annex I regulated products are scheduled for 2 August 2028.
Organizations should not interpret later enforcement dates as a reason to delay preparations.
AI inventories, role classification, vendor assessments, governance structures, documentation processes, employee competence, and risk-management controls can require substantial preparation.
Teams that need structured knowledge of the regulatory framework can also use an AI Act, Law & Governance Training Course to strengthen internal understanding of the Act and its governance requirements.
Master EU AI Act Law & AI Governance.
Build a clear understanding of the EU AI Act, AI governance, GDPR and CNIL requirements, AI risk management, high-risk AI controls, human oversight, documentation, and responsible AI practices. Earn a free Certificate of Completion in English or French. Develop the knowledge to support AI compliance, strengthen organizational oversight, and contribute to responsible AI adoption with confidence.
Enrol Now →Determining who must comply with the EU AI Act requires more than asking whether an organization develops artificial intelligence. Providers, deployers, importers, distributors, manufacturers, general-purpose AI model providers, and certain organizations outside Europe can all fall within its scope.
Businesses should classify their role for every AI system, document where and how the technology is used, and reassess that classification when systems change.