Skip to content
Amended. Regulation (EU) 2026/1744 entered into force 27 July 2026. See what moved →
EU AI Act ChecklistIndependent reference
Chapter I · Article 2

Who the EU AI Act actually applies to

Scope is the first question and the one most often answered badly. The Act does not apply to “companies using AI in Europe”. It applies to six named categories of person, through two extra-territorial hooks, with six exclusions that are narrower than they sound.

Art. 2Reg. (EU) 2024/1689

The six categories caught

WhoWhen they are caughtThe trap
ProvidersPlacing an AI system on the EU market or putting it into service in the EU — irrespective of where they are established.“We have no EU entity” is not a defence. Establishment is expressly irrelevant.
DeployersUsing an AI system under their own authority, where the deployer is located in the EU.Internal-only use still counts. Buying rather than building changes your obligations, not whether you have any.
Providers & deployers in third countriesWhere the output produced by the system is used in the EU.The system never has to touch the EU market. This is the hook most non-EU companies miss.
Importers & distributorsPlacing on or making available on the EU market.Resellers and marketplaces inherit verification duties under Arts. 23–24.
Product manufacturersPlacing a system on the market together with their product and under their own name or trade mark.White-labelling someone else’s model makes you the provider.
Authorised representativesAppointed by non-EU providers of high-risk systems.Required, not optional, for non-EU high-risk providers.

Affected persons located in the Union are also within scope for the purposes of the rights the Act creates, notably the Article 85 right to complain to a market surveillance authority and the Article 86 right to an explanation of individual decision-making.

Where this usually goes next

Three situations account for most people reading this page. Each has a different answer.

A deal is blocked on an AI questionnaire

Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.

How this works for AI companies →

You need ISO/IEC 42001 documentation

23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.

Free gap assessment →
See the three tiers →

You are not sure what reaches you

Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.

Book a free 20-minute call →

This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →

The role trap: Article 25

Scope is not fixed at procurement. Article 25 converts a deployer, importer or distributor into a provider of a high-risk system in three situations:

  1. They put their name or trade mark on a high-risk system already placed on the market.
  2. They make a substantial modification to a high-risk system already on the market, such that it remains high-risk.
  3. They modify the intended purpose of a system, including a general-purpose AI system — in a way that makes it high-risk.

Why this matters more than it looks

Point 3 catches the common pattern of taking a general-purpose model and building an Annex III use case on top of it. The model provider is not your shield. If you point a foundation model at CV screening, you are the provider of a high-risk AI system, with the full Chapter III Section 2 burden, whatever your contract with the model vendor says.

Expert analysis. The article text is clear; how aggressively authorities apply it to thin application layers is not yet settled.

Art. 25Reg. (EU) 2024/1689

The six exclusions, and how narrow they are

ExclusionWhat it does not cover
Military, defence, national securityRequires exclusive use for those purposes. A dual-use system with a commercial version is not excluded.
Scientific research & developmentSystems developed and used solely for scientific R&D. Commercialising the output ends the exclusion.
Pre-market R&D activityTesting in real world conditions is expressly carved back in.
Free and open-sourceDoes not apply where the system is prohibited under Art. 5, is high-risk, or falls under Art. 50. In practice this leaves the exemption covering minimal-risk open-source only.
Purely personal non-professional useNatural persons only. A sole trader using AI in their business is not covered by this.
Third-country public authorities under international cooperationConditional on adequate safeguards for fundamental rights.

The open-source exemption is the most over-claimed provision in the Act

“We ship under Apache 2.0, so the AI Act does not apply” is wrong for any system that is high-risk or that interacts with people. Separate and narrower relief exists for general-purpose AI models under free and open-source licences, and that relief does not extend to models with systemic risk.

A four-question scope test

  1. Is it an AI system as defined in Article 3(1)? If it is deterministic rules with no inference, arguably not. The definition, tested →
  2. What role are you in? Provider, deployer, importer, distributor, and could Article 25 move you? Roles compared →
  3. Is there an EU nexus? Market placement, service in the EU, deployer located in the EU, or output used in the EU.
  4. Does an exclusion apply exclusively? Almost all the exclusions carry an exclusivity or purpose condition. Partial fit is no fit.

Document the answer. Article 6(4) already requires providers claiming an Annex III system is not high-risk to document that assessment before market placement; the same discipline applied to scope costs you an afternoon and is the first thing anyone will ask to see.

Next step

Scope decided. Now classify.

Once you know the Act applies and which role you are in, the next question is which tier your system sits in and therefore which obligations and which date. That answer drives everything else.

Not sure where you sit?

The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.

Run the classifier →

Questions

Who does the EU AI Act apply to?

Article 2 applies the Regulation to providers placing AI systems on the EU market or putting them into service in the EU, irrespective of where the provider is established; to deployers of AI systems located in the EU; to providers and deployers established in a third country where the output produced by the AI system is used in the EU; and to importers, distributors, product manufacturers placing a system on the market under their own name, authorised representatives of non-EU providers, and affected persons located in the EU.

Does the EU AI Act apply outside the EU?

Yes. Two extra-territorial hooks exist. First, a non-EU provider is caught if it places an AI system on the EU market or puts it into service in the EU. Second, a non-EU provider or deployer is caught where the output produced by the AI system is used in the EU, even if the system itself never enters the EU market. This is broader than the GDPR's targeting test.

What is excluded from the EU AI Act?

Article 2 excludes AI systems placed on the market or used exclusively for military, defence or national security purposes; AI systems used solely for scientific research and development; research, testing and development activity prior to placing on the market, other than testing in real world conditions; AI systems released under free and open-source licences unless they are prohibited practices, high-risk, or subject to Article 50 transparency obligations; and natural persons using AI systems in the course of a purely personal non-professional activity.

Does the Act apply to AI used internally by a company?

Yes, if the company is a deployer located in the EU. Deployer means a natural or legal person using an AI system under its own authority, except where use is in the course of a personal non-professional activity. Internal-only use of an HR screening tool by an EU employer is deployment, not exemption.

Are open-source AI models exempt?

Only partially. The free and open-source exemption in Article 2 does not apply where the system is a prohibited practice under Article 5, is high-risk, or falls under the Article 50 transparency obligations. Separate rules apply to general-purpose AI models released under free and open-source licences, which get relief from some but not all Chapter V obligations.