The
EU AI Act has often been mistaken for a law that applies mainly to AI developers. In reality, it reaches far wider —
touching virtually every organisation that deploys AI in a professional context inside the European Union. Understanding who the Act applies to, and the role you play in any given AI deployment, is the first practical step toward compliance.
The Regulation distinguishes between five different roles. Providers develop an AI system, or have one developed, and place it on the EU market under their own name or trademark. They carry the heaviest duty stack: risk management, technical documentation, conformity assessment, CE marking, EU database registration, post-market monitoring. Deployers use an AI system in a professional capacity under their own authority — most banks, insurers, retailers, hospitals, and law firms sit here. Their duties are lighter than providers' but still real, especially for high-risk systems: instructions, human oversight, monitoring, fundamental-rights impact assessments. Importers bring non-EU providers' systems into the EU market; distributors make systems available in the EU supply chain; authorised representatives act on behalf of non-EU providers as a local point of accountability.
The biggest under-appreciated risk in the Act is that roles can shift. If you fine-tune a third-party model, rebrand someone else's AI, or substantially modify an existing system, you can be re-classified as a provider of the modified system — and inherit the full provider duty stack. A bank that fine-tunes a foundation model on its loan book and deploys it under its own brand has, in the Act's eyes, become a provider. So has a law firm that significantly modifies a third-party contract-review tool. Most organisations do not realise this until late in their AI programme, when the compliance cost suddenly multiplies.
The
Act also applies extraterritorially. If your AI's output is used in the EU, or your system is placed on the EU market, you are caught regardless of where you are established. Non-EU providers must usually appoint an EU-based authorised representative — a local entity that can be held accountable by EU regulators. Enforcement runs through national market-surveillance authorities, supported by the
European AI Office for general-purpose AI matters. Penalties tier with the seriousness of the breach: up to €35 million or 7 per cent of worldwide turnover for prohibited practices, €15 million or 3 per cent for most other breaches.
For any organisation deploying AI in the EU, the first compliance move is the same: inventory every AI system, identify your role for each, and map the obligations that follow. Whether the heavy lifting falls to your provider workstream, your deployer workstream, or both is what determines your compliance budget.
If you want to learn more about the EU AI Act and what it means for your company, go to Lexstream's
AI Law and Governance series.