“We’re not an AI company — surely this doesn’t concern us.” That is the single most common (and most expensive) misconception about the EU AI Act. Here is a plain-language way to work out whether you are in scope.
The short answer
If your organisation develops, sells, imports, distributes, or simply uses AI systems — and the system or its output touches the EU — the AI Act almost certainly applies to you in some form. The real question is not whether it applies, but which obligations apply and how heavy they are.
Who is covered? The four roles
The Act assigns obligations by role, not by industry:
- Providers — you develop an AI system (or have one developed) and place it on the market under your name. Heaviest obligations.
- Deployers — you use an AI system in your professional activities. Lighter, but real, obligations — especially for high-risk use cases.
- Importers — you place an AI system from a non-EU provider on the EU market.
- Distributors — you make an AI system available on the EU market without modifying it.
Two traps worth flagging:
- Extraterritorial reach: a US or UK company whose AI output is used in the EU is in scope, even with no EU office.
- Becoming a provider by accident: if you substantially modify a high-risk system, put your brand on it, or repurpose it for a high-risk use, you can inherit full provider obligations.
Which risk tier is your AI in?
The Act is a pyramid — obligations scale with risk:
| Tier | Examples | What it means |
|---|---|---|
| Prohibited | Social scoring, manipulative techniques, untargeted facial-image scraping, emotion recognition at work/school (with narrow exceptions) | Banned since 2 Feb 2025 |
| High-risk | AI in hiring, credit scoring, education, critical infrastructure, essential services, law enforcement, medical devices | Full Chapter III compliance regime |
| Limited risk (transparency) | Chatbots, deepfakes, AI-generated content | Users must be informed they are dealing with AI |
| Minimal risk | Spam filters, AI in games, most internal productivity tooling | No new obligations (voluntary codes encouraged) |
“We just use off-the-shelf AI tools” — you are still in scope
Even a company that builds nothing has, at minimum:
- an AI-literacy duty — staff using AI must be adequately trained (Article 4, in force since February 2025);
- transparency duties where customers interact with AI or receive AI-generated content;
- full deployer obligations where the use case is high-risk — screening CVs with an AI tool is the canonical example.
A five-minute self-assessment
Answer these four questions per AI system:
- Do we develop it, or just use it? → provider vs deployer track.
- Does it (or its output) reach the EU? → territorial scope.
- Does the use case appear in Annex III (employment, credit, education, essential services…) or is it a safety component of a regulated product? → high-risk track and its deadline (Aug 2026 or Aug 2027).
- Do people interact with it or see its output? → transparency duties.
If you answered “yes” to question 3 for any system, your compliance work has a hard deadline — see our complete EU AI Act timeline for the dates.
Where to go from here
A structured inventory-and-classification exercise typically takes a focused team a day — and it converts vague regulatory anxiety into a concrete, prioritised to-do list. That is precisely the outcome our EU AI Act Delivery Workshop is designed to produce.
Frequently Asked Questions
Does the EU AI Act apply to companies outside the EU?
Yes. The Act is extraterritorial: it applies to providers placing AI systems on the EU market regardless of where they are established, and even to providers and deployers outside the EU when the output of their AI system is used within the EU.
Are small companies (SMEs) exempt from the EU AI Act?
No. There is no SME exemption. The Act does include SME-friendly measures — priority access to regulatory sandboxes, simplified documentation options, and proportionally lower fines — but the substantive obligations apply to organisations of every size.
We only use AI tools like ChatGPT or Copilot — are we affected?
Most likely yes, as a deployer. Using AI systems in your operations triggers the AI-literacy duty (in force since February 2025), transparency duties where users interact with AI or see AI-generated content, and full deployer obligations if the use case is high-risk (for example, CV screening in hiring).
What should we do first to check whether we are in scope?
Build an inventory of every AI system you develop, procure, or embed; then classify each one against the risk tiers and identify your role (provider, deployer, importer, distributor). That inventory is the foundation every other compliance step builds on.
This guide is provided for general information and does not constitute legal advice. Regulatory details evolve — verify current requirements against official EU sources or seek qualified counsel for decisions affecting your organisation.