Skip to content
Amended. Regulation (EU) 2026/1744 entered into force 27 July 2026. See what moved →
EU AI Act ChecklistIndependent reference
Role guide · General counsel

EU AI Act for general counsel

Three questions decide most of your exposure: are we in scope, what role are we in, and can a contract move it. The answer to the third is largely no, and Article 25 can make you a provider of a high-risk AI system without anyone in the business noticing.

Arts. 2, 6(4), 25, 99Reg. (EU) 2024/1689

What lands on you, and what does not

Ownership boundaries are the most useful thing to settle early. Expert analysis: the Regulation names organisations, not job titles.

ObligationYours?Note
Art. 2 scope determinationYesIncluding the output-used-in-the-EU hook
Art. 25 role analysisYesThe provider-by-accident risk
Contractual allocation with vendors and customersYesAllocates cost, not regulatory duty
Art. 6(4) derogation sign-offYesDocumented before market placement; tested under Art. 80
Art. 99 exposure analysisYesCorrect tier, not the headline figure
Art. 73 reportability decisionYesIncluding the fundamental-rights limb
Arts. 9–15 technical requirementsNoAdvise on standard; do not own delivery

Where this usually goes next

Three situations account for most people reading this page. Each has a different answer.

A deal is blocked on an AI questionnaire

Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.

How this works for AI companies →

You need ISO/IEC 42001 documentation

23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.

Free gap assessment →
See the three tiers →

You are not sure what reaches you

Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.

Book a free 20-minute call →

This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →

Article 25 makes buyers into builders

Three routes turn a deployer, importer or distributor into a provider of a high-risk AI system: putting your name or trade mark on a system already on the market; making a substantial modification to a high-risk system that remains high-risk; or modifying the intended purpose of a system — including a general-purpose AI system, so that it becomes high-risk.

The third route is the one that catches modern software companies. Building an Annex III use case on top of a foundation model makes you the provider, with the full Chapter III burden: risk management, Annex IV documentation, conformity assessment, CE marking, registration, post-market monitoring.

The model vendor’s documentation is an input to yours. It is not a substitute, and no contractual term makes it one. Where the shift happens, the original provider must supply information reasonably needed for you to comply, unless they clearly specified the system was not to be changed into a high-risk one, which is a clause worth reading in every model contract you hold. Role analysis →

Contracts allocate money, not obligations

A regulatory obligation attaches to the person the Regulation names. An indemnity can shift the financial consequence of failure between commercial parties; it does not move the duty, and it is no answer to a market surveillance authority.

What contracts should do, and mostly do not yet:

  • Fix the roles. State who is provider and who is deployer for each system, and what happens if Article 25 is triggered.
  • Guarantee information flow. Annex IV inputs, declared accuracy metrics, the pre-determined change envelope, and Article 13 instructions for use.
  • Allocate logs. Who controls which logs, retention period, and how the other party obtains them within a two-day incident window.
  • Set incident notification timing that actually fits Article 73. Your two-day clock and their fifteen-day clock are not the same clock.
  • Constrain modification. If you do not want to become a provider, say so and mean it.

Your first 30 days

  1. Answer the scope question in writing, including third-country output use. Article 2 does not care where you are established.
  2. Run the Article 25 analysis across every AI product built on a third-party model.
  3. Read your foundation model contracts for modification restrictions and information-supply terms.
  4. Correct the penalty figure wherever it appears internally. €35M/7% is Article 5 only; high-risk and transparency are €15M/3%.
  5. Decide who signs the EU declaration of conformity and the Article 6(4) derogation assessments.

Questions worth asking

  • Which of our systems could trigger Article 25, and who is watching?
  • Do our vendor contracts guarantee the Annex IV inputs we will need?
  • Who is the named signatory for conformity declarations?
  • What is our documented position on the new Article 5 prohibitions before 2 December 2026?

Status labels on this page

Verified fact: Article references, dates and penalty tiers cited above, checked against the consolidated Regulation and the Commission's AI Act Service Desk.

Expert analysis: The ownership allocation, the failure modes, and the 30-day sequence — all our practice rather than the text.

Unsettled: Harmonised standards remain in development, and the Commission's Annex III guidelines are in draft. Both affect how these obligations will be evidenced.

Next step

Exposure follows classification

Every legal question here resolves once classification is settled and documented. An undocumented classification is the weakest position to be in when Article 80 is invoked.

Start with the inventory

Every role guide on this site converges on the same first step: a list of the AI systems, their intended purpose, their role and their tier.

Run the classifier →

Frequently asked

Can we contract out of EU AI Act obligations?

No. Regulatory obligations attach to the person the Regulation names as provider, deployer, importer or distributor. Contracts can allocate the financial consequences of failure between commercial parties and should guarantee the information flow each party needs, but they do not transfer a duty owed to a regulator.

When does a company using AI become a provider?

Article 25 makes a deployer, importer or distributor a provider of a high-risk AI system where it puts its name or trade mark on a high-risk system already placed on the market, makes a substantial modification to a high-risk system such that it remains high-risk, or modifies the intended purpose of a system, including a general-purpose AI system, so that it becomes high-risk.

Does the EU AI Act apply to a US company with no EU entity?

It can. Article 2 applies to providers placing AI systems on the EU market or putting them into service in the EU irrespective of where they are established, and to providers and deployers established in a third country where the output produced by the AI system is used in the Union. Neither hook depends on having an EU entity.