EU AI Act for general counsel
Three questions decide most of your exposure: are we in scope, what role are we in, and can a contract move it. The answer to the third is largely no, and Article 25 can make you a provider of a high-risk AI system without anyone in the business noticing.
What lands on you, and what does not
Ownership boundaries are the most useful thing to settle early. Expert analysis: the Regulation names organisations, not job titles.
| Obligation | Yours? | Note |
|---|---|---|
| Art. 2 scope determination | Yes | Including the output-used-in-the-EU hook |
| Art. 25 role analysis | Yes | The provider-by-accident risk |
| Contractual allocation with vendors and customers | Yes | Allocates cost, not regulatory duty |
| Art. 6(4) derogation sign-off | Yes | Documented before market placement; tested under Art. 80 |
| Art. 99 exposure analysis | Yes | Correct tier, not the headline figure |
| Art. 73 reportability decision | Yes | Including the fundamental-rights limb |
| Arts. 9–15 technical requirements | No | Advise on standard; do not own delivery |
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
Article 25 makes buyers into builders
Three routes turn a deployer, importer or distributor into a provider of a high-risk AI system: putting your name or trade mark on a system already on the market; making a substantial modification to a high-risk system that remains high-risk; or modifying the intended purpose of a system — including a general-purpose AI system, so that it becomes high-risk.
The third route is the one that catches modern software companies. Building an Annex III use case on top of a foundation model makes you the provider, with the full Chapter III burden: risk management, Annex IV documentation, conformity assessment, CE marking, registration, post-market monitoring.
The model vendor’s documentation is an input to yours. It is not a substitute, and no contractual term makes it one. Where the shift happens, the original provider must supply information reasonably needed for you to comply, unless they clearly specified the system was not to be changed into a high-risk one, which is a clause worth reading in every model contract you hold. Role analysis →
Contracts allocate money, not obligations
A regulatory obligation attaches to the person the Regulation names. An indemnity can shift the financial consequence of failure between commercial parties; it does not move the duty, and it is no answer to a market surveillance authority.
What contracts should do, and mostly do not yet:
- Fix the roles. State who is provider and who is deployer for each system, and what happens if Article 25 is triggered.
- Guarantee information flow. Annex IV inputs, declared accuracy metrics, the pre-determined change envelope, and Article 13 instructions for use.
- Allocate logs. Who controls which logs, retention period, and how the other party obtains them within a two-day incident window.
- Set incident notification timing that actually fits Article 73. Your two-day clock and their fifteen-day clock are not the same clock.
- Constrain modification. If you do not want to become a provider, say so and mean it.
Your first 30 days
- Answer the scope question in writing, including third-country output use. Article 2 does not care where you are established.
- Run the Article 25 analysis across every AI product built on a third-party model.
- Read your foundation model contracts for modification restrictions and information-supply terms.
- Correct the penalty figure wherever it appears internally. €35M/7% is Article 5 only; high-risk and transparency are €15M/3%.
- Decide who signs the EU declaration of conformity and the Article 6(4) derogation assessments.
Questions worth asking
- Which of our systems could trigger Article 25, and who is watching?
- Do our vendor contracts guarantee the Annex IV inputs we will need?
- Who is the named signatory for conformity declarations?
- What is our documented position on the new Article 5 prohibitions before 2 December 2026?
Status labels on this page
Verified fact: Article references, dates and penalty tiers cited above, checked against the consolidated Regulation and the Commission's AI Act Service Desk.
Expert analysis: The ownership allocation, the failure modes, and the 30-day sequence — all our practice rather than the text.
Unsettled: Harmonised standards remain in development, and the Commission's Annex III guidelines are in draft. Both affect how these obligations will be evidenced.
Exposure follows classification
Every legal question here resolves once classification is settled and documented. An undocumented classification is the weakest position to be in when Article 80 is invoked.
Start with the inventory
Every role guide on this site converges on the same first step: a list of the AI systems, their intended purpose, their role and their tier.
Frequently asked
Can we contract out of EU AI Act obligations?
No. Regulatory obligations attach to the person the Regulation names as provider, deployer, importer or distributor. Contracts can allocate the financial consequences of failure between commercial parties and should guarantee the information flow each party needs, but they do not transfer a duty owed to a regulator.
When does a company using AI become a provider?
Article 25 makes a deployer, importer or distributor a provider of a high-risk AI system where it puts its name or trade mark on a high-risk system already placed on the market, makes a substantial modification to a high-risk system such that it remains high-risk, or modifies the intended purpose of a system, including a general-purpose AI system, so that it becomes high-risk.
Does the EU AI Act apply to a US company with no EU entity?
It can. Article 2 applies to providers placing AI systems on the EU market or putting them into service in the EU irrespective of where they are established, and to providers and deployers established in a third country where the output produced by the AI system is used in the Union. Neither hook depends on having an EU entity.