Module 01
What the AI Act is, and who it lands on
Why the law reaches ordinary companies, and the one distinction everything else depends on.
By the end you should be able to
- Say whether your organisation is a provider, a deployer, or both — and why it matters
- Recognise the three ways an ordinary company accidentally becomes a provider
- Know which obligations apply today and which are still ahead
It regulates systems and uses, not 'AI'
Art. 1; Art. 3(1)
The EU AI Act — Regulation (EU) 2024/1689 — does not regulate artificial intelligence as a subject. It regulates specific AI systems, according to what they are used for. The same model can be unregulated in one use and prohibited in another, which is why 'is our AI legal?' is never a answerable question and 'what is this system used for?' always is.
That has a consequence worth absorbing early: nobody can tell you your obligations from the name of your tool. Two companies using the identical chatbot can owe completely different things.
Provider or deployer — and why people get this wrong
Art. 3(3), 3(4); Art. 25
| Provider | Deployer | |
|---|---|---|
| Who | Develops an AI system, or has one developed, and places it on the market under its own name | Uses an AI system under its own authority |
| Typical case | A software company shipping an AI feature | A company using ChatGPT, Copilot, or a vendor's tool |
| Core duties | The full high-risk regime where it applies; transparency by design | Use it as instructed, assign oversight, keep logs, inform people |
| Basis | Art. 3(3), Art. 16 | Art. 3(4), Art. 26 |
Most organisations are deployers and assume that makes them the customer of someone else's compliance problem. It does not — deployers have their own obligations. And three things quietly turn a deployer into a provider, with the much heavier duties that carries:
- 01You put your own name or trademark on a high-risk AI system that is already on the market. White-labelling a vendor's tool does this.
- 02You make a substantial modification to a high-risk system — a change not foreseen or planned in its initial conformity assessment (Art. 3(23)).
- 03You change the intended purpose of a system so that it becomes high-risk. Buying a general-purpose tool and pointing it at CV screening does exactly this.
Any distributor, importer, deployer or other third party shall be considered to be a provider of a high-risk AI system for the purposes of this Regulation and shall be subject to the obligations of the provider under Article 16, in any of the following circumstances […]
Art. 25(1)
The one-person Annex III problem
A recruiter starts pasting CVs into a general chatbot to rank candidates before a human reads them. Nobody bought an 'AI system'. No project was approved. But the company is now using AI in an Annex III area — employment — and, because it repurposed a general tool to do it, is arguably the provider of a high-risk system.
One person, no budget, no decision: full high-risk exposure.
What applies today, and what is still ahead
Art. 113, as amended by Reg. (EU) 2026/1744
In July 2026 the AI Act was amended for the first time, by Regulation (EU) 2026/1744 — the Digital Omnibus on AI. A great deal of commentary reported this as 'the AI Act was delayed'. That is wrong in a way that costs money, because the parts most companies actually owe were not delayed at all.
| Date | What applies | Status |
|---|---|---|
| 2 February 2025 | Prohibited practices (Art. 5) and AI literacy (Art. 4) | In force |
| 2 August 2025 | General-purpose AI model obligations (Chapter V) | In force |
| 2 August 2026 | General application. Transparency duties (Art. 50), registration (Art. 49). Enforcement began. | In force |
| 2 December 2026 | Two new prohibitions: non-consensual intimate imagery, AI-generated CSAM | Coming |
| 2 December 2027 | High-risk obligations for Annex III use cases — moved from 2 Aug 2026 | Coming |
| 2 August 2028 | High-risk obligations for Annex I products — moved from 2 Aug 2027 | Coming |
The deferral is also unconditional. The Commission's original proposal would have tied the new dates to harmonised standards being ready — a 'stop-the-clock' mechanism — and the co-legislators dropped it. Anyone telling you the dates may slip again is describing a rejected proposal, not the law.
The four tiers, in one pass
Art. 5; Art. 6; Art. 50; Chapter V
| Tier | Meaning | What you owe |
|---|---|---|
| Prohibited | Art. 5. Eight practices since Feb 2025, two more from Dec 2026 | Stop. There is no compliance route |
| High-risk | Annex I products or Annex III use cases | The full Chapter III regime, from Dec 2027 / Aug 2028 |
| Transparency | Art. 50 — chatbots, synthetic content, deepfakes | Tell people. Live now |
| Minimal | Everything else | Nothing specific; general law still applies |
Check yourself
0 of 4 answered
Scenario questions, not definitions — recall proves nothing about judgement. Pick an answer and the reasoning appears whether you were right or wrong, because that is where the learning is.
Your marketing team subscribes to a tool that writes product descriptions. Nothing is rebranded and its purpose is unchanged. What are you?
A colleague says 'the AI Act was delayed to 2027, so we can park this.' What is wrong with that?
Which of these most likely makes your company the provider of a high-risk system?
What single fact does the whole classification depend on?
Next
The things you may simply not do
Eight prohibitions in force since February 2025, two more from December 2026, and the three an ordinary employer can actually trip.
See what it covers