3 minute read | August.31.2026
This update is part of our EU AI Act Series. Learn more about the EU AI Act here.
The EU AI Act imposes obligations on providers, importers, distributors and deployers of AI systems and General-Purpose AI Models (GPAI models).
Note: The European Commission has published guidance on key concepts and provisions under the AI Act in its Guidelines on Prohibited AI Practices.
The AI Act primarily governs two types of AI-related technology:
The obligations imposed on AI systems vary based on whether the system or its use qualifies as Prohibited AI, High-Risk AI or otherwise involves AI interacting directly with individuals or exposing individuals to specified forms of AI-generated content (Individual-User-Facing AI). The law also creates exempted categories or lightens compliance obligations in relation to certain AI systems and GPAI Models.
See below for key definitions for understanding applicability thresholds:
The Act imposes obligations on organizations based on their role in relation to the covered technology. Most obligations apply to providers and deployers, while importers and distributors are primarily subject to regulatory compliance verification and documentation obligations.
Any distributor, importer, deployer or other third-party shall be considered to be a provider of a High-Risk AI System for the purposes of this Regulation and shall be subject to the obligations of the provider under Article 16, in any of the following circumstances:
(a) they put their name or trademark on a High-Risk AI System already placed on the market or put into service, without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated;
(b) they make a substantial modification to a High-Risk AI System that has already been placed on the market or has already been put into service in such a way that it remains a High-Risk AI System pursuant to Article 6;
(c) they modify the intended purpose of an AI system, including a GPAI system, which has not been classified as high-risk and has already been placed on the market or put into service in such a way that the AI system concerned becomes a High-Risk AI System in accordance with Article 6.
‘Substantial modification’ means a change to an AI system after its placing on the market or putting into service which:
Similarly, the European Commission has indicated in its Guidelines of 18 July 2025 on the scope of the obligations for providers of GPAI that a downstream modifier of a GPAI model may be deemed the model’s provider if its modification of the model leads to significant change in the model’s generality, capabilities or systemic risk.
In practice, parties that plan to modify AI systems or AI models purchased or licensed from third parties should assess whether those modifications may bring them within the scope of the AI Act.
The AI Act applies where there is a sufficient territorial link with the EU:
Note: When they are established outside the EU, providers of High-Risk AI Systems (Article 22 of the AI Act) and of GPAI models (Article 54 of the AI Act) must assign an authorized EU representative.
Article 2 of the AI Act provides five exemptions:
Want to know more? Reach out to a member of our team.
Key Definitions for Understanding Applicability
These terms are key concepts in EU product safety law and the European Commission’s Blue Guide on the implementation of the product rules 2022 provides additional valuable context to their interpretation, as does the AI Act-specific guidance published by the European Commission.