Course overview

Module 01

What the AI Act is, and who it lands on

Why the law reaches ordinary companies, and the one distinction everything else depends on.

Free15 min

By the end you should be able to

  • Say whether your organisation is a provider, a deployer, or both — and why it matters
  • Recognise the three ways an ordinary company accidentally becomes a provider
  • Know which obligations apply today and which are still ahead

It regulates systems and uses, not 'AI'

Art. 1; Art. 3(1)

The EU AI Act — Regulation (EU) 2024/1689 — does not regulate artificial intelligence as a subject. It regulates specific AI systems, according to what they are used for. The same model can be unregulated in one use and prohibited in another, which is why 'is our AI legal?' is never a answerable question and 'what is this system used for?' always is.

That has a consequence worth absorbing early: nobody can tell you your obligations from the name of your tool. Two companies using the identical chatbot can owe completely different things.

Provider or deployer — and why people get this wrong

Art. 3(3), 3(4); Art. 25

ProviderDeployer
WhoDevelops an AI system, or has one developed, and places it on the market under its own nameUses an AI system under its own authority
Typical caseA software company shipping an AI featureA company using ChatGPT, Copilot, or a vendor's tool
Core dutiesThe full high-risk regime where it applies; transparency by designUse it as instructed, assign oversight, keep logs, inform people
BasisArt. 3(3), Art. 16Art. 3(4), Art. 26

Most organisations are deployers and assume that makes them the customer of someone else's compliance problem. It does not — deployers have their own obligations. And three things quietly turn a deployer into a provider, with the much heavier duties that carries:

  1. 01You put your own name or trademark on a high-risk AI system that is already on the market. White-labelling a vendor's tool does this.
  2. 02You make a substantial modification to a high-risk system — a change not foreseen or planned in its initial conformity assessment (Art. 3(23)).
  3. 03You change the intended purpose of a system so that it becomes high-risk. Buying a general-purpose tool and pointing it at CV screening does exactly this.

Any distributor, importer, deployer or other third party shall be considered to be a provider of a high-risk AI system for the purposes of this Regulation and shall be subject to the obligations of the provider under Article 16, in any of the following circumstances […]

Art. 25(1)

The one-person Annex III problem

A recruiter starts pasting CVs into a general chatbot to rank candidates before a human reads them. Nobody bought an 'AI system'. No project was approved. But the company is now using AI in an Annex III area — employment — and, because it repurposed a general tool to do it, is arguably the provider of a high-risk system.

One person, no budget, no decision: full high-risk exposure.

What applies today, and what is still ahead

Art. 113, as amended by Reg. (EU) 2026/1744

In July 2026 the AI Act was amended for the first time, by Regulation (EU) 2026/1744 — the Digital Omnibus on AI. A great deal of commentary reported this as 'the AI Act was delayed'. That is wrong in a way that costs money, because the parts most companies actually owe were not delayed at all.

DateWhat appliesStatus
2 February 2025Prohibited practices (Art. 5) and AI literacy (Art. 4)In force
2 August 2025General-purpose AI model obligations (Chapter V)In force
2 August 2026General application. Transparency duties (Art. 50), registration (Art. 49). Enforcement began.In force
2 December 2026Two new prohibitions: non-consensual intimate imagery, AI-generated CSAMComing
2 December 2027High-risk obligations for Annex III use cases — moved from 2 Aug 2026Coming
2 August 2028High-risk obligations for Annex I products — moved from 2 Aug 2027Coming

The deferral is also unconditional. The Commission's original proposal would have tied the new dates to harmonised standards being ready — a 'stop-the-clock' mechanism — and the co-legislators dropped it. Anyone telling you the dates may slip again is describing a rejected proposal, not the law.

The four tiers, in one pass

Art. 5; Art. 6; Art. 50; Chapter V

TierMeaningWhat you owe
ProhibitedArt. 5. Eight practices since Feb 2025, two more from Dec 2026Stop. There is no compliance route
High-riskAnnex I products or Annex III use casesThe full Chapter III regime, from Dec 2027 / Aug 2028
TransparencyArt. 50 — chatbots, synthetic content, deepfakesTell people. Live now
MinimalEverything elseNothing specific; general law still applies

Check yourself

0 of 4 answered

Scenario questions, not definitions — recall proves nothing about judgement. Pick an answer and the reasoning appears whether you were right or wrong, because that is where the learning is.

Q1

Your marketing team subscribes to a tool that writes product descriptions. Nothing is rebranded and its purpose is unchanged. What are you?

Q2

A colleague says 'the AI Act was delayed to 2027, so we can park this.' What is wrong with that?

Q3

Which of these most likely makes your company the provider of a high-risk system?

Q4

What single fact does the whole classification depend on?

Next

The things you may simply not do

Eight prohibitions in force since February 2025, two more from December 2026, and the three an ordinary employer can actually trip.

See what it covers