EU AI Act for product managers
One sentence in your product definition now has legal effect. Intended purpose determines classification, gets registered publicly, bounds what marketing may claim, and sets the reference point against which every future change is judged substantial or not.
What lands on you, and what does not
Ownership boundaries are the most useful thing to settle early. Expert analysis: the Regulation names organisations, not job titles.
| Obligation | Yours? | Note |
|---|---|---|
| Intended purpose statement | Yes | Drives classification, registration and change control |
| Art. 50 disclosure in the interface | Yes | Live now. Not a ToS clause |
| Art. 13 instructions for use | Yes | Prescribed contents; a product deliverable |
| Design choices that affect Art. 6(3) | Yes | Where you sit relative to the derogation is a design outcome |
| The pre-determined change envelope | Shared with engineering and legal | Bounds your release freedom |
| Conformity assessment | No | Quality function |
| Risk file | No: contribute | Foreseeable misuse is your input |
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
Intended purpose stops being a marketing sentence
Article 3(12) defines intended purpose as the use for which an AI system is intended by the provider, including the specific context and conditions of use, as specified in the information supplied by the provider in the instructions for use, promotional or sales materials and statements, and in the technical documentation.
Promotional and sales materials are named in the definition. Marketing copy is therefore evidence of intended purpose. A product registered as performing a narrow preparatory task and marketed as “automatically picks your best candidates” has a problem that no amount of technical documentation fixes.
Three consequences: classification follows intended purpose, so widening the claim can widen the regime; the purpose is registered in a largely public database under Article 49; and changing the intended purpose so a system becomes high-risk makes the changer a provider under Article 25, which can be your customer, using your product in a way you did not intend.
Article 50 is a UI requirement and it is live
Article 50 has applied since 2 August 2026 and attaches to what the system does, not to its risk tier. A minimal-risk chatbot is caught.
- 50(1): people must be informed they are interacting with an AI system, unless obvious to a reasonably well-informed, observant and circumspect person.
- 50(2): synthetic audio, image, video and text must be marked in a machine-readable format. New systems from 2 Aug 2026; systems already on the market from 2 Dec 2026.
- 50(5): the information must be clear and distinguishable, at the latest at the time of the first interaction or exposure, and meet accessibility requirements.
A footer line or a ToS clause does not meet a requirement drafted in those terms. This is an interface change with a design review, not a legal sign-off. Article 50 →
Your first 30 days
- Write the intended purpose properly for each AI feature, and check marketing against it.
- Audit every AI surface for Article 50 disclosure. First interaction, in the interface.
- Decide your provenance marking approach if you ship generative output. 2 December 2026 for anything already live.
- Draft the change envelope with engineering and legal: it bounds your release cadence.
- Write the foreseeable misuse list. You know how customers actually use the product; Article 9(2)(b) needs it.
Questions worth asking
- Does our marketing copy match our registered intended purpose?
- Where exactly does a user learn they are talking to AI?
- Which changes can we ship without a new conformity assessment?
- Are customers using this in ways that would make them a provider?
Status labels on this page
Verified fact: Article references, dates and penalty tiers cited above, checked against the consolidated Regulation and the Commission's AI Act Service Desk.
Expert analysis: The ownership allocation, the failure modes, and the 30-day sequence — all our practice rather than the text.
Unsettled: Harmonised standards remain in development, and the Commission's Annex III guidelines are in draft. Both affect how these obligations will be evidenced.
Design decides classification
Where a system sits relative to the Article 6(3) derogation is usually settled by product decisions, whether it ranks or parses, scores or summarises, taken long before anyone reads the Regulation.
Start with the inventory
Every role guide on this site converges on the same first step: a list of the AI systems, their intended purpose, their role and their tier.
Frequently asked
What is intended purpose under the EU AI Act?
Article 3(12) defines intended purpose as the use for which an AI system is intended by the provider, including the specific context and conditions of use, as specified in the information supplied by the provider in the instructions for use, promotional or sales materials and statements, and in the technical documentation. Because promotional and sales materials are named, marketing claims are evidence of intended purpose.
Does Article 50 apply to a chatbot that is not high-risk?
Yes. Article 50 attaches to what a system does rather than to its risk classification. A minimal-risk chatbot that interacts with people is within Article 50(1), which requires that people are informed they are interacting with an AI system unless that is obvious to a reasonably well-informed, observant and circumspect person in the circumstances.
Can a customer using our product become a provider?
Yes. Under Article 25, a deployer becomes a provider of a high-risk AI system if it puts its name or trade mark on the system, makes a substantial modification, or modifies the intended purpose so that the system becomes high-risk. Where that happens, the original provider must supply information reasonably needed for compliance unless it has clearly specified that the system is not to be changed into a high-risk one.