Vigilis
EU AI Act

Who does the EU AI Act actually apply to?

Sourced from Regulation (EU) 2024/1689 (the EU AI Act), Article 2 and Article 3

In short

The EU AI Act applies to almost any business that uses AI in its operations, not only the companies that build AI. Article 2 covers four roles (provider, deployer, importer, distributor) and reaches organisations outside the EU whenever an AI system’s output is used in the EU. Company size doesn’t change whether the Act applies, only how enforcement is prioritised.

Most companies assume the EU AI Act only affects the handful of firms that build AI models from scratch. That assumption is wrong, and it is the single most common misconception we encounter. The Act’s material scope, set out in Article 2, reaches far beyond AI developers to cover almost anyone who puts an AI system into service or uses one in the course of business, including companies that simply use ChatGPT, an AI-based applicant tracking system, or a third-party fraud-detection tool.

The four roles the Act regulates

Article 3 defines four operator categories, and your obligations depend entirely on which one applies to you:

  • Provider (Art. 3(3)), develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark.
  • Deployer (Art. 3(4)), uses an AI system under its own authority, other than in a purely personal, non-professional capacity. Almost every business that uses AI tools in its operations is a deployer.
  • Importer (Art. 3(6)), places on the EU market an AI system that bears the name of a person established outside the EU.
  • Distributor (Art. 3(7)), makes an AI system available on the EU market without being the provider or importer.

Territorial reach, you don't need to be based in the EU

Article 2(1) applies the Act to providers placing AI systems on the EU market regardless of where they are established, to deployers of AI systems located within the EU, and (critically) to providers and deployers located outside the EU where the output produced by the AI system is used in the EU. A US company running a hiring algorithm that screens applications from EU-based candidates is in scope even without an EU office.

What is exempt

Article 2(6)–(12) carve out specific exemptions: AI systems used exclusively for military, defence, or national security purposes; systems used solely for scientific research and development; AI components released under free and open-source licences (unless they are themselves high-risk, or fall under prohibited or transparency obligations); and personal, non-professional use by natural persons. None of these exemptions apply once an AI system is used in a business context, the “open source” exemption in particular is narrower than most companies assume.

Why deployers carry more risk than they realise

Because deployer obligations (Article 26) apply regardless of company size, a 15-person company using a third-party recruitment AI tool can trigger the same high-risk obligations as the vendor that built it, including human oversight, log retention, and in some cases a fundamental rights impact assessment (Article 27). Company size affects enforcement priorities in practice, but it does not change whether the Act applies.

Phased timeline

The Act entered into force on 1 August 2024. Prohibited-practice rules (Article 5) applied from 2 February 2025. Obligations for general-purpose AI models applied from 2 August 2025. Most of the Act became applicable on 2 August 2026. The high-risk obligations were then deferred by the Digital Omnibus on AI (Regulation (EU) 2026/1744): systems that are high-risk under Annex III now apply from 2 December 2027, and high-risk AI that are safety components of products already regulated under EU product-safety law (Annex I) from 2 August 2028.

If your company uses any AI-powered tool that affects people (customers, employees, or the public) the question is not whether the Act could apply to you, but which role and which risk tier you fall into.

Frequently asked questions

Does the EU AI Act apply to companies that only use AI tools like ChatGPT?
Yes. Using an AI system in your operations makes you a deployer under Article 3(4), and deployer obligations apply regardless of company size, so a business using ChatGPT, an AI-based applicant tracking system, or a third-party fraud-detection tool can be in scope.
Do you have to be based in the EU for the Act to apply?
No. Under Article 2(1) the Act applies to providers placing AI systems on the EU market wherever they are established, to deployers located in the EU, and to providers and deployers outside the EU where the output of the AI system is used in the EU.
Does company size affect whether the EU AI Act applies?
No. Deployer obligations under Article 26 apply regardless of size; a 15-person company can trigger the same high-risk obligations as the vendor that built the tool. Company size affects enforcement priorities in practice, not whether the Act applies.
Is open-source AI exempt from the EU AI Act?
Only narrowly. Free and open-source AI components are exempt unless they are themselves high-risk or fall under prohibited or transparency obligations, and the exemption does not apply once an AI system is used in a business context.

Related guides

Not sure where your company stands?

Our free assessment gives you an indicative result in minutes (free and anonymous) no account needed.

Start the free check