Who Must Comply with the EU AI Act?

Learn who must meet EU AI Act Compliance requirements, including providers, deployers, importers, distributors, manufacturers and non-EU companies.

 EU AI Act compliance scope showing providers, deployers, importers, distributors, manufacturers, and non-EU companies.

The EU AI Act does not apply only to technology companies that develop artificial intelligence. Its reach extends across the AI supply chain, covering organizations that develop, provide, import, distribute, integrate, or professionally use AI systems in the European Union. It can also apply to companies established outside Europe when their AI systems are placed on the EU market or their outputs are used within the Union.

In practical terms, EU AI Act Compliance begins by identifying the legal role your organization plays for each AI system. A company may be a provider for one system, a deployer for another, and potentially both at the same time.

Organizations operating in or supplying AI to the European market should therefore determine their role, document their AI systems, and assess applicable obligations before the relevant requirements become enforceable.

Which Organizations Must Comply with the EU AI Act?

The EU AI Act applies to a broad range of public and private organizations rather than one specific type of technology business.

Under Article 2 of the EU AI Act, its scope includes providers placing AI systems or general-purpose AI models on the EU market, deployers located or established within the EU, importers, distributors, product manufacturers, and authorized representatives.

Certain organizations outside the European Union can also fall within its scope.

Understanding these categories is fundamental because responsibilities differ depending on the organization's role.

EU AI Act compliance roles showing providers, deployers, importers, distributors, manufacturers, and non-EU companies.

AI System Providers

A provider is an organization or individual that develops an AI system or general-purpose AI model, or has one developed, and places that system on the market or puts it into service under its own name or trademark.

This definition covers more than traditional AI developers.

For example, a software company that builds and sells an AI-powered recruitment platform will normally be considered a provider. However, a company that commissions another developer to build an AI system and then markets it under its own brand may also become the provider under the Act.

Provider obligations can be substantial where systems fall into regulated categories such as high-risk AI.

Depending on the system, providers may need to address areas including risk management, technical documentation, record keeping, transparency, human oversight, accuracy, robustness, cybersecurity, and conformity assessment.

Organizations developing or commercializing AI should therefore establish clearly whether they qualify as providers before determining which requirements apply.

Businesses That Use AI Can Be Deployers

Many companies affected by the EU AI Act will never develop an AI model themselves. They may instead qualify as deployers.

A deployer is generally a person or organization using an AI system under its authority in a professional context.

This means employers, financial institutions, healthcare organizations, retailers, universities, government departments, insurers, manufacturers, and many other businesses can fall within the regulatory framework simply through the way they use AI.

A French employer using AI to screen employment applications is one example.

A financial institution using AI to support creditworthiness assessments may also qualify as a deployer and could face additional obligations if the system falls within one of the Act's high-risk categories.

However, being a deployer does not automatically mean every requirement in the AI Act applies. Responsibilities depend heavily on the type of AI system, its intended purpose, and its risk classification.

Organizations therefore need more than a list of the AI tools they use. They need to understand how each tool is actually being deployed. This should be an important part of how businesses prepare for AI Act compliance.

Importers, Distributors and Product Manufacturers

The EU AI Act also covers organizations involved in supplying AI systems rather than creating or directly using them.

An importer can be an organization established in the EU that places an AI system on the market when that system carries the name or trademark of an organization established outside the Union.

A distributor is generally an organization within the AI supply chain that makes an AI system available on the EU market without being the provider or importer. These businesses may need to verify that relevant regulatory requirements have been completed before making certain regulated systems available.

Product manufacturers may also fall within the Act. This is particularly relevant where AI systems are incorporated into products covered by existing EU product safety legislation.

For example, manufacturers placing certain AI-enabled regulated products on the European market may face responsibilities connected to both the AI Act and existing sector-specific product legislation.

AI compliance therefore cannot be treated solely as a software-development issue. It can affect procurement, manufacturing, distribution, product management, legal teams, and supply-chain governance.

Does the EU AI Act Apply to Companies Outside the EU?

One of the most important elements of EU AI Act Compliance is its potential application to organizations established outside the European Union.

The regulation applies to providers placing AI systems or general-purpose AI models on the EU market regardless of whether those providers are established inside or outside the Union.

This means a US, UK, Canadian, Japanese, or other non-EU technology company may fall within the Act when supplying AI products or services to customers in Europe. The scope can extend further.

Under Article 2, certain providers and deployers established in third countries may also be covered where the output produced by an AI system is used within the European Union.

Consider a multinational company operating a centralized AI analytics system from the United States. If that system generates recommendations that are subsequently used by the company's French subsidiary to make employment, financial, or operational decisions, the organization should assess whether the Act's territorial scope applies.

Similarly, a non-EU SaaS provider supplying an AI recruitment tool to companies in France cannot assume that incorporation outside Europe removes it from the regulation.

Organizations should examine where their AI systems are marketed, deployed, and used rather than relying entirely on the location of corporate headquarters.

Can One Company Have Multiple Roles?

Infographic showing how one company can hold multiple EU AI Act roles, including deployer and provider responsibilities.

Organizations should not assume they have a single permanent classification under the AI Act. Their legal role can vary between systems and may even change during an AI system's lifecycle.

A company might purchase a third-party AI assistant and use it internally. In that situation, it may primarily act as a deployer.

The same company could separately develop an AI-powered compliance tool and make it available to customers under its own brand. For that system, the company could qualify as a provider.

Role changes can also occur when organizations modify third-party AI systems.

Under certain circumstances, an organization may take on provider responsibilities when it puts its own name or trademark on an existing regulated AI system, makes a substantial modification, or changes the system's intended purpose in a manner covered by the regulation. This makes lifecycle governance essential.

An effective AI governance framework should record the organization's role for each AI system and reassess that classification whenever the technology, intended purpose, branding, or deployment model changes.

Companies should therefore maintain an AI inventory that identifies the system owner, supplier, organizational role, intended use, geographic deployment, and applicable risk category.

Who May Fall Outside the EU AI Act?

Although the regulation has broad scope, some AI activities are specifically excluded or receive different treatment.

Natural persons using AI systems for purely personal and non-professional activities generally fall outside the deployer requirements.

For example, an individual using an AI assistant privately is different from an employer using the same technology within a professional process.

The regulation also contains exclusions concerning AI systems developed or used exclusively for military, defense, or national-security purposes.

Certain research and development activities may also fall outside specific requirements before the relevant AI system or model is placed on the market or put into service.

However, organizations should be cautious when relying on these exclusions.

Describing a project as experimental, research-based, internal, or open source does not automatically remove it from the AI Act. The precise conditions of the regulation must still be considered.

Open-source AI is particularly important because the Act provides specific treatment for certain free and open-source AI systems and general-purpose AI models, but there is no universal exemption covering everything released under an open-source licence. The European Commission provides additional guidance concerning general-purpose AI model obligations.

Businesses relying on an exclusion should document the legal reasoning rather than simply assuming that the regulation does not apply.

EU AI Act Responsibilities by Organizational Role

The organization's role determines which obligations need to be investigated.

Organization or role

Typical example

Why the EU AI Act may apply

Provider

Company selling its own AI recruitment software

Places an AI system on the EU market under its own name

Deployer

Employer using AI to evaluate job applicants

Uses an AI system professionally under its authority

Non-EU provider

US company selling an AI platform to French businesses

Places an AI system on the EU market

Importer

EU company bringing a third-country AI system into the market

Introduces an externally supplied AI system into the EU

Distributor

Reseller supplying AI software within the EU

Makes AI systems available within the supply chain

Product manufacturer

Manufacturer selling a regulated product incorporating AI

AI forms part of a product placed on the EU market

GPAI provider

Company supplying a general-purpose AI model

Specific obligations apply to general-purpose AI model providers

This table provides an initial screening framework rather than a definitive legal classification.

One company may occupy several categories depending on its AI portfolio.

When Do These Obligations Apply?

The EU AI Act entered into force on 1 August 2024, but its requirements have been introduced progressively.

Rules concerning prohibited AI practices and AI literacy obligations began applying on 2 February 2025.

Organizations covered by Article 4 must take measures, to their best extent, to ensure that staff and other persons dealing with AI systems on their behalf possess an appropriate level of AI literacy. The required level depends on factors including their technical knowledge, experience, education, training, and the context in which the systems are used.

Specific obligations relating to general-purpose AI models began applying from 2 August 2025.

Other parts of the regulatory framework have subsequently entered into application according to the Act's phased timetable and subsequent amendments.

For high-risk AI systems, organizations should pay particular attention to the revised timeline introduced through the 2026 Digital Omnibus framework.

Main obligations affecting Annex III high-risk AI systems are scheduled to apply from 2 December 2027, while corresponding requirements for high-risk AI systems connected with certain Annex I regulated products are scheduled for 2 August 2028.

Organizations should not interpret later enforcement dates as a reason to delay preparations.

AI inventories, role classification, vendor assessments, governance structures, documentation processes, employee competence, and risk-management controls can require substantial preparation.

Teams that need structured knowledge of the regulatory framework can also use an AI Act, Law & Governance Training Course to strengthen internal understanding of the Act and its governance requirements.

★ Free PDF Certificate Included

Master EU AI Act Law & AI Governance.

Build a clear understanding of the EU AI Act, AI governance, GDPR and CNIL requirements, AI risk management, high-risk AI controls, human oversight, documentation, and responsible AI practices. Earn a free Certificate of Completion in English or French. Develop the knowledge to support AI compliance, strengthen organizational oversight, and contribute to responsible AI adoption with confidence.

Enrol Now →

Conclusion

Determining who must comply with the EU AI Act requires more than asking whether an organization develops artificial intelligence. Providers, deployers, importers, distributors, manufacturers, general-purpose AI model providers, and certain organizations outside Europe can all fall within its scope.

Businesses should classify their role for every AI system, document where and how the technology is used, and reassess that classification when systems change.

Frequently Asked Questions

Not every business will face the same obligations. A company professionally using an AI system may qualify as a deployer, but its specific responsibilities depend on the system's intended purpose, risk classification, and relevant provisions of the Act.

Yes. Small and medium-sized businesses are not automatically exempt from the regulation. The requirements that apply depend primarily on their role and the type of AI system involved, although the Act includes measures intended to support SMEs and start-ups.

It can. A US company may fall within the Act when it places an AI system or general-purpose AI model on the EU market. Certain non-EU providers and deployers may also be covered when AI system outputs are used within the European Union.