


Updated July 2026
The EU AI ActThe EU Artificial Intelligence Act was approved by the EU Council on 21 March 2024. A world-first comprehensive AI law, intended to harmonise rules for the development, deployment, and use of artificial intelligence systems across the EU. has extra-territorial reach, which means it can apply to organisations both inside and outside the EU. Obligations depend on the AI system, its risk level, and your organisation’s role.
Some requirements already apply, with most remaining provisions except those relating to high-risk systems taking effect from 2 August 2026. Following the Digital Omnibus on AI, detailed high-risk requirements will apply from 2 December 2027 for stand-alone systems and 2 August 2028 for systems embedded in certain regulated products.
Key takeaway: Your role must be assessed for each AI system. You could be a deployer when using one system and a provider when developing, rebranding or significantly changing another. Provider status brings greater responsibilities.
The AI Act has wide geographical reach and, like the General Data Protection RegulationRegulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation). (GDPR), an organisation does not need physical offices in the EU to fall within its scope.
This makes it a significant law with global implications and means that its provisions apply to any organisation marketing, deploying, or using an AI system in the EU, even if the system is developed or operated outside the EU.
Compliance obligations are determined by two main factors:
Read Compliance with the AI act part 2: What is high risk activity? for details on AI system classification
The same organisation can hold different roles for different AI systems, so a single organisation-wide label is unlikely to be sufficient.
General-purpose AI model providers are subject to a separate set of requirements, which we cover later in this blog.
Roles are determined by what your organisation does with each AI system. You may therefore hold different roles across your AI use.
The AI Act defines six main roles:

Most organisations using third-party AI tools will be Deployers. However, your role can change. Rebranding or substantially modifying a high-risk system or changing an AI system’s purpose so that it becomes high-risk, could mean taking on Provider responsibilities.
Your role should therefore be assessed for each AI system, rather than applying to your organisation as a whole.
All six roles carry responsibilities under the AI Act. However, most organisations developing or using AI systems will likely act as a Provider or Deployer.
Most obligations fall on Providers because they control how systems are developed and supplied, while deployers have certain obligations as they are responsible for how systems are used.
Both roles must take appropriate steps to support AI literacy and meet any transparency requirements that apply to the systems. This includes informing people when they are interacting with AI and labelling certain AI-generated content.
Providers of high-risk AI systems must:
Deployers of high-risk AI systems must:
Providers of general-purpose AI (GPAI) models have separate obligations covering technical documentation, copyright, transparency and information for organisations using their models. Additional requirements apply to models with systemic risk. Organisations using tools built on these models should still understand the provider, intended use and limitations.
This checklist provides a starting point for reviewing each AI system your organisation develops or uses. The specific steps will depend on the system, your role, and the obligations that apply.
Explore the other blogs in our Compliance with the AI Act series:
______________________________________________________________________________________________________________________________
The DPO Centre’s AI governanceThe framework of policies, processes, and roles that ensure Artificial Intelligence (AI) is developed and used responsibly, ethically, and in compliance with applicable laws, societal expectations, and corporate values. services can help you understand your obligations, assess AI risks and put appropriate oversight in place. This includes AI Impact Assessments and support from an Outsourced AI Officer.
______________________________________________________________________________________________________________________________
In case you missed it…
______________________________________________________________________________________________________________________________
For more news and insights about data protection follow The DPO Centre on LinkedIn
Fill in your details below and we’ll get back to you as soon as possible