[TECHLAWG]
Regulation (EU) 2024/1689

Does the EU AI Act apply to you?

Six questions. No email required. You will get an indicative read on your territorial scope, your role, and which obligation set you are looking at. It is a starting point, not an opinion, but it is the starting point most companies have not done.

3.1 Applicability check

Six questions.

EU AI Act applicability checker

0 of 6 answered
Do you place an AI system on the EU market, have users in the EU, or is the output of your system used in the EU?
Which best describes you in relation to the AI system?
Do you develop or fine-tune a general-purpose AI model, as opposed to only building on someone else's API?
Is the system used in any of these areas: employment or recruitment, education, credit or insurance scoring, essential public or private services, biometrics, critical infrastructure, law enforcement, migration, or justice?
Does the system involve social scoring, untargeted scraping of facial images, emotion inference in workplaces or education, or manipulation of vulnerable groups?
Does the system interact directly with people, or generate text, image, audio or video content?

Indicative only. This is a triage tool, not legal advice, and it does not create a client relationship. Classification turns on facts this form cannot capture.

3.2 Scope

Being outside the EU is not a defence.

The Regulation follows the market, not the incorporation certificate. It reaches providers placing AI systems on the EU market wherever they are established, and it reaches providers and deployers outside the EU where the output produced by the system is used in the EU.

That last hook catches more companies than people expect. A US analytics product whose scoring output is relied on by a customer in Germany is inside the conversation, even with no EU entity, no EU staff and no EU servers.

The practical consequence: the question is not "are we an EU company." It is "where does the output land," and that is an evidence question you should be able to answer in writing.

3.3 Role

Provider or deployer is the fork everything else hangs on.

A provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark. A deployer uses an AI system under its own authority in a professional capacity.

Providers carry the heavy end: risk management, data governance, technical documentation, conformity assessment, registration, post-market monitoring. Deployers carry a lighter but real set: oversight, monitoring, logging, and in some cases a fundamental rights impact assessment.

The trap is that the roles are not fixed. Put your own brand on a bought-in system, modify it substantially, or change its intended purpose, and you can become the provider of it. Companies that assumed they were deployers because they did not train anything are the ones most often wrong.

3.4 Tiers

The four tiers, plus a separate track for models.

Tier 1

Prohibited

Practices banned outright, including social scoring, untargeted facial image scraping, and emotion inference in workplaces and education. Highest penalty tier, already applicable.

Tier 2

High-risk

Systems in listed areas such as employment, education, credit, essential services, biometrics and critical infrastructure. The full compliance programme applies.

Tier 3

Transparency

Systems interacting with people or generating synthetic content. People must know they are dealing with AI, and generated content must be marked machine-readably.

Tier 4

Minimal

Everything else. No specific obligations, but you still need the inventory and classification to be able to demonstrate that this is where you sit.

General-purpose AI models sit on a parallel track: documentation for downstream providers, a copyright policy covering text and data mining, and a public summary of training content, with an additional layer of evaluation, adversarial testing and incident reporting where a model presents systemic risk.

3.5 Practical

What to do in the next thirty days.

In this order. Skipping to policy drafting is the most common and most wasteful mistake.

Build the inventory

Every AI system in the business, including the ones bought by marketing without telling anyone. You cannot classify what you have not listed.

Fix the territorial question

Where do your users sit and where does your output land. Write the answer down with evidence behind it.

Classify role per system

Provider or deployer, system by system. One company can be both, and usually is.

Screen for prohibitions

Fast, binary, and the highest consequence if you get it wrong. Do this before anything else on the list takes budget.

Tier the remainder

High-risk, transparency, or minimal. This determines your actual workload and your actual deadline.

Then, and only then, build the programme

Governance framework, oversight design, vendor terms, documentation. Built against real classification rather than a generic template.

3.6 Questions

Common questions.

We only use ChatGPT internally. Are we in scope?

Probably as a deployer, and probably in the lowest tiers, but that is a conclusion you should be able to evidence rather than assume. The exposure for most internal-use companies is not the Regulation directly. It is that an enterprise customer or investor asks for your AI inventory and governance position and you do not have one.

We are a US company with no EU entity. Does this matter?

It can. The output hook reaches systems whose results are used in the EU regardless of where the company sits. If you have EU customers, or customers with EU operations, the question is live.

How does this interact with GDPR?

They are separate instruments with overlapping subject matter. An AI system processing personal data has to satisfy both. In practice the work overlaps heavily: the inventory, the lawful basis analysis, the impact assessment and the vendor terms all serve both regimes if they are built once and built properly.

What are the penalties?

The Regulation sets tiered administrative fines. The highest tier applies to breaches of the prohibited practices provisions, with lower tiers for other obligations and for supplying incorrect information to authorities. Each is expressed as a fixed ceiling or a percentage of worldwide annual turnover, whichever is higher.

Is the timeline going to change?

Sequencing and guidance have continued to develop since adoption, including proposals affecting the phasing of certain obligations. Treat any published date as needing confirmation at the time you rely on it. That is one of the things the subscription is for.

Get the classification in writing.

A written applicability opinion covering territorial scope, role, risk tier and your obligation map. Fixed fee, agreed upfront, five business days.