Prohibited
Practices banned outright, including social scoring, untargeted facial image scraping, and emotion inference in workplaces and education. Highest penalty tier, already applicable.
Six questions. No email required. You will get an indicative read on your territorial scope, your role, and which obligation set you are looking at. It is a starting point, not an opinion, but it is the starting point most companies have not done.
Indicative only. This is a triage tool, not legal advice, and it does not create a client relationship. Classification turns on facts this form cannot capture.
The Regulation follows the market, not the incorporation certificate. It reaches providers placing AI systems on the EU market wherever they are established, and it reaches providers and deployers outside the EU where the output produced by the system is used in the EU.
That last hook catches more companies than people expect. A US analytics product whose scoring output is relied on by a customer in Germany is inside the conversation, even with no EU entity, no EU staff and no EU servers.
The practical consequence: the question is not "are we an EU company." It is "where does the output land," and that is an evidence question you should be able to answer in writing.
A provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark. A deployer uses an AI system under its own authority in a professional capacity.
Providers carry the heavy end: risk management, data governance, technical documentation, conformity assessment, registration, post-market monitoring. Deployers carry a lighter but real set: oversight, monitoring, logging, and in some cases a fundamental rights impact assessment.
The trap is that the roles are not fixed. Put your own brand on a bought-in system, modify it substantially, or change its intended purpose, and you can become the provider of it. Companies that assumed they were deployers because they did not train anything are the ones most often wrong.
Practices banned outright, including social scoring, untargeted facial image scraping, and emotion inference in workplaces and education. Highest penalty tier, already applicable.
Systems in listed areas such as employment, education, credit, essential services, biometrics and critical infrastructure. The full compliance programme applies.
Systems interacting with people or generating synthetic content. People must know they are dealing with AI, and generated content must be marked machine-readably.
Everything else. No specific obligations, but you still need the inventory and classification to be able to demonstrate that this is where you sit.
General-purpose AI models sit on a parallel track: documentation for downstream providers, a copyright policy covering text and data mining, and a public summary of training content, with an additional layer of evaluation, adversarial testing and incident reporting where a model presents systemic risk.
In this order. Skipping to policy drafting is the most common and most wasteful mistake.
Every AI system in the business, including the ones bought by marketing without telling anyone. You cannot classify what you have not listed.
Where do your users sit and where does your output land. Write the answer down with evidence behind it.
Provider or deployer, system by system. One company can be both, and usually is.
Fast, binary, and the highest consequence if you get it wrong. Do this before anything else on the list takes budget.
High-risk, transparency, or minimal. This determines your actual workload and your actual deadline.
Governance framework, oversight design, vendor terms, documentation. Built against real classification rather than a generic template.
Probably as a deployer, and probably in the lowest tiers, but that is a conclusion you should be able to evidence rather than assume. The exposure for most internal-use companies is not the Regulation directly. It is that an enterprise customer or investor asks for your AI inventory and governance position and you do not have one.
It can. The output hook reaches systems whose results are used in the EU regardless of where the company sits. If you have EU customers, or customers with EU operations, the question is live.
They are separate instruments with overlapping subject matter. An AI system processing personal data has to satisfy both. In practice the work overlaps heavily: the inventory, the lawful basis analysis, the impact assessment and the vendor terms all serve both regimes if they are built once and built properly.
The Regulation sets tiered administrative fines. The highest tier applies to breaches of the prohibited practices provisions, with lower tiers for other obligations and for supplying incorrect information to authorities. Each is expressed as a fixed ceiling or a percentage of worldwide annual turnover, whichever is higher.
Sequencing and guidance have continued to develop since adoption, including proposals affecting the phasing of certain obligations. Treat any published date as needing confirmation at the time you rely on it. That is one of the things the subscription is for.
A written applicability opinion covering territorial scope, role, risk tier and your obligation map. Fixed fee, agreed upfront, five business days.