<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[AI Law. Decoded.]]></title><description><![CDATA[The EU AI Act and global AI regulation — explained in plain English. For in-house lawyers, product managers, founders, and anyone who just got handed "the AI thing."]]></description><link>https://ailawdecoded.com</link><image><url>https://substackcdn.com/image/fetch/$s_!u4nF!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png</url><title>AI Law. Decoded.</title><link>https://ailawdecoded.com</link></image><generator>Substack</generator><lastBuildDate>Sat, 01 Aug 2026 16:47:11 GMT</lastBuildDate><atom:link href="https://ailawdecoded.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[AI Law. Decoded.]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[ailawdecoded@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[ailawdecoded@substack.com]]></itunes:email><itunes:name><![CDATA[Silvia Stepitova]]></itunes:name></itunes:owner><itunes:author><![CDATA[Silvia Stepitova]]></itunes:author><googleplay:owner><![CDATA[ailawdecoded@substack.com]]></googleplay:owner><googleplay:email><![CDATA[ailawdecoded@substack.com]]></googleplay:email><googleplay:author><![CDATA[Silvia Stepitova]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[AI Has to Say It's AI Now]]></title><description><![CDATA[Chatbots, AI content, and deepfakes you wouldn't call deepfakes. Applies August 2.]]></description><link>https://ailawdecoded.com/p/eueu-ai-act-article-50-transparency</link><guid isPermaLink="false">https://ailawdecoded.com/p/eueu-ai-act-article-50-transparency</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 29 Jul 2026 12:00:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!We5V!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b677b2-35e9-4947-84e5-2d905c414fba_7680x4320.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!We5V!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b677b2-35e9-4947-84e5-2d905c414fba_7680x4320.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!We5V!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b677b2-35e9-4947-84e5-2d905c414fba_7680x4320.jpeg 424w, https://substackcdn.com/image/fetch/$s_!We5V!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b677b2-35e9-4947-84e5-2d905c414fba_7680x4320.jpeg 848w, https://substackcdn.com/image/fetch/$s_!We5V!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b677b2-35e9-4947-84e5-2d905c414fba_7680x4320.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!We5V!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b677b2-35e9-4947-84e5-2d905c414fba_7680x4320.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!We5V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b677b2-35e9-4947-84e5-2d905c414fba_7680x4320.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/01b677b2-35e9-4947-84e5-2d905c414fba_7680x4320.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:342898,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.com/i/208463778?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b677b2-35e9-4947-84e5-2d905c414fba_7680x4320.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!We5V!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b677b2-35e9-4947-84e5-2d905c414fba_7680x4320.jpeg 424w, https://substackcdn.com/image/fetch/$s_!We5V!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b677b2-35e9-4947-84e5-2d905c414fba_7680x4320.jpeg 848w, https://substackcdn.com/image/fetch/$s_!We5V!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b677b2-35e9-4947-84e5-2d905c414fba_7680x4320.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!We5V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b677b2-35e9-4947-84e5-2d905c414fba_7680x4320.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>When the Omnibus on AI deal landed in May, it read as relief. High-risk obligations for <a href="https://artificialintelligenceact.eu/annex/3/">Annex III</a> systems: pushed to December 2027. AI embedded in the regulated products listed in <a href="https://artificialintelligenceact.eu/annex/1/">Annex I</a>: August 2028. If the AI Act sits in your portfolio, next to everything else that does, you probably made the reasonable mental note. <em>Revisit next year.</em></p><p>The note is wrong by one chapter.</p><p><a href="https://artificialintelligenceact.eu/article/50/">Article 50</a>, the transparency rules, did not move. It applies from August 2, 2026. This Sunday. And on July 20, less than two weeks before the deadline, the European Commission published its final <a href="https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems">guidelines on how to comply</a>. Thirteen days of runway. Brussels&#8217; idea of a running start.</p><p>The timing is inconvenient. But I would say that the substance matters more. Article 50 reaches more companies than the high-risk chapter ever will. The high-risk rules catch CV-screening tools and credit scoring. Article 50 catches the chatbot on your website, the AI-generated visuals in your marketing, and the product descriptions your content team stopped writing by hand more than a year ago.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;993cb3ce-51f1-4c2f-80e0-1e6e099417ce&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;EU AI Act Amended: The Digital Omnibus Timeline&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-13T12:02:43.130Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!DR18!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/eu-ai-act-amended-the-digital-omnibus&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:196926473,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:3,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>What Article 50 Is</h2><p>The AI Act sorts systems by risk: prohibited, high-risk, transparency-risk, minimal. Article 50 is the third box. It also stacks on the second, because Article 50(6) says the transparency duties do not affect the <a href="https://artificialintelligenceact.eu/chapter/3/">Chapter III</a> requirements for high-risk systems. So there is no &#8220;we&#8217;re not high-risk, so we&#8217;re fine,&#8221; and no &#8220;we&#8217;re already doing the high-risk work, so this is covered.&#8221; Article 50 applies to any AI system used in four specific situations, whatever else is true about it.</p><p><strong>The four situations:</strong></p><ol><li><p>An AI system interacts directly with people (chatbots, voice assistants, AI agents)</p></li><li><p>An AI system generates synthetic content (text, images, audio, video)</p></li><li><p>An AI system runs emotion recognition or biometric categorisation on people</p></li><li><p>AI-generated content gets published: deepfakes, or text informing the public on matters of public interest</p></li></ol><p>Breach the transparency rules and the ceiling is &#8364;15 million or 3% of worldwide annual turnover, whichever is higher (<a href="https://artificialintelligenceact.eu/article/99/">Article 99(4)(g)</a>). For SMEs and start-ups the calculation flips to whichever is lower, and the European Commission&#8217;s guidance now extends that proportionality to small mid-cap companies as well. Not the &#8364;35 million tier reserved for prohibited practices. Still not a rounding error.</p><p>Two of the four obligations belong to providers, the companies that build the systems. Two belong to deployers, the companies that use them. You may be both. A company that builds a customer-facing bot on top of a foundation model and also publishes AI-generated content holds obligations on both sides.</p><p>One carve-out runs through all four: systems authorised by law to detect, prevent, investigate or prosecute criminal offences are excepted, with conditions. If you are not in law enforcement, it will not help you.</p><div><hr></div><h2>The Provider Duties (Systems That Talk or Generate)</h2><p>If you provide an AI system that interacts with people, Article 50(1) requires it to be designed so that people know they are talking to AI. From the start of the first interaction. Clear, distinguishable, accessible.</p><p>There is an exception where this is obvious. The guidelines then spend considerable effort narrowing what counts as obvious: </p><blockquote><p><em>the test is a reasonably well-informed, observant and circumspect person, judged against your actual audience, </em></p></blockquote><p>And the Commission says to read the exception restrictively. A widget labelled <em>&#8220;Assistant&#8221;</em> is not disclosure. And the obligation protects natural persons, <strong>not just consumers</strong>: the Commission reads it to cover consumers, professionals and other users alike, which is why the internal HR bot your employees use counts too.</p><p>One detail for anyone building agents. The guidelines confirm AI agents fall under Article 50(1), and where a provider cannot reliably predict whether the agent will end up interacting with a human, it should be designed to disclose its AI nature in all situations where such interaction is reasonably foreseeable. The agent has to introduce itself. Few of the agent demos circulating are designed for this.</p><p>If you provide a system that generates synthetic content, Article 50(2) requires the outputs to be marked in a machine-readable format and detectable as AI-generated. This is the watermarking obligation: metadata, watermarks, provenance signals. Article 50(2) asks for solutions that are effective, interoperable, robust and reliable, so far as technically feasible. The <a href="https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content">Code of Practice</a> published in June prescribes no single technique, and the reason is not hard to see: no marking method available today satisfies all four criteria on its own. Expect to layer them.</p><p>The exemptions are worth reading before you panic-procure a watermarking vendor. Standard editing assistance is out: spell-check, grammar, quality improvements, anything that does not substantially alter the data or its meaning. So are short sequences of numbers or letters, source code, and outputs that never reach a human. Content that stays inside closed industrial pipelines is out too, with a condition: the exemption falls away for the final output. The AI-generated asset that actually ships is not covered. The guidelines also include a narrow exemption for certain business-to-business and industrial contexts. Open-source systems, for the record, are not exempt.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;d7d2d2e4-7d47-49e8-8749-8776e28b8f14&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Provider vs. Deployer Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-22T12:03:43.719Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!NS5L!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35f75bb-44f2-45d4-b53c-84654d8e8617_8192x5461.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/provider-vs-deployer-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:194314202,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:5,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>The Deployer Duties: Where You Might Come In</h2><p>Most readers of this newsletter are not building foundation models. You are using AI systems under your own authority, professionally. That probably makes you a deployer, and two obligations are yours.</p><p>If you deploy emotion recognition or biometric categorization, Article 50(3)<strong> requires you to inform the people exposed to it</strong>. Sentiment analysis in the call centre, demographic categorisation in retail analytics. Real-time or after the fact, both count. But screen against <a href="https://artificialintelligenceact.eu/article/5/">Article 5</a> first: inferring emotions in the workplace or in education institutions is prohibited outright, save for narrow medical and safety purposes. Where the ban applies, it is not a disclosure question at all.</p><p>If you use AI to create deepfakes, Article 50(4) <strong>requires you to disclose that the content is artificially generated or manipulated</strong>. Visibly. At first exposure. And this is where the definitions deserve your attention, because the word <em>&#8220;deepfake&#8221;</em> suggests malice, and the definition does not require any.</p><p>A <strong>deepfake</strong> under <a href="https://artificialintelligenceact.eu/article/3/">Article 3(60)</a> is </p><blockquote><p><em>AI-generated or manipulated image, audio or video that resembles existing persons, objects, places, entities or events, and would falsely appear authentic. </em></p></blockquote><p>Three criteria: <strong>resemblance</strong>, <strong>something that exists</strong> or plausibly could, and the <strong>capacity to mislead about authenticity</strong>. Dragons are out. Talking animals are out. Standard film production, color correction, noise reduction: out.</p><p>An authentic photo of an empty apartment, furnished by AI for the listing: in. That example is not mine. It appears in the Commission&#8217;s own <a href="https://digital-strategy.ec.europa.eu/en/policies/eu-icons-labelling-ai-generated-content">labelling guidance</a>, as a case for the &#8220;<em>partially AI-modified&#8221;</em> label. Product visuals, staged scenes, AI photography of real places. Your marketing department has deepfake obligations. It has probably not been told.</p><p><strong>The second half of Article 50(4) covers text. </strong></p><p>Publish AI-generated text with the purpose of informing the public on matters of public interest, and you must disclose it. The public-interest list is long. Politics and democratic processes, public administration and services, justice and law enforcement, fundamental rights, public security, public health, environmental protection, consumer safety, plus economic, financial, scientific and cultural developments that may be relevant to public debate. A fair amount of corporate publishing brushes against that.</p><p>Most corporate text will escape through the exemption: <strong>no label needed where the text underwent human review or editorial control</strong>, and a person holds editorial responsibility for it. Read the definitions before you rely on them. </p><p><strong>Human review</strong><em><strong> </strong></em>means deliberate examination of the substance by someone with relevant knowledge and professional judgement. </p><p><strong>Editorial control</strong> means the authority to approve, alter or reject the content on substantive grounds, fact-checking included. </p><p>And <strong>editorial responsibility</strong>, per the European Commission, means someone holds the ultimate legal responsibility for the publication. A spell-check pass is none of the three. If your workflow is &#8220;AI drafts it, someone skims it, it ships,&#8221; you have a choice: make the review real and documented, with a name attached, or add the label.</p><div><hr></div><h2>The Watermark Is Not the Label</h2><p>Your AI vendor markets its compliance. The model watermarks its outputs, embeds provenance metadata, signs the Code of Practice. You might conclude that content generated with a compliant tool is compliant content.</p><p>The two obligations are two layers, and only one of them is the vendor&#8217;s.</p><p>The <strong>machine-readable mark</strong> under Article 50(2) is the provider&#8217;s job: invisible, embedded, readable by detection tools. Y</p><p>our disclosure duty under Article 50(4) is a separate, visible layer: <strong>a label</strong> a person can see or hear without any tool at all. </p><p>The Commission&#8217;s <a href="https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act">Q&amp;A</a> says it plainly: deployers cannot simply rely on the machine-readable marking embedded by the provider to fulfill their disclosure obligation.</p><p>The provider marks. You label. A compliant tool does not make your published deepfake compliant. It just means the invisible half was done by someone else.</p><div><hr></div><h2>How to Label, Practically</h2><p>The EU published a set of <a href="https://digital-strategy.ec.europa.eu/en/policies/eu-icons-labelling-ai-generated-content">official icons</a> in June. Three of them: </p><ul><li><p>a basic <strong>&#8220;AI&#8221;</strong> icon, </p></li><li><p>one for fully <strong>AI-generated</strong> content, </p></li><li><p>one for partially <strong>AI-modified</strong> content. </p></li></ul><p>They are free to download (SVG and PNG), free to use, no attribution required.</p><p>The placement rules, from the Code of Practice: perceivable at first exposure, not hidden behind overlays, embedded directly into the content (creative works get more flexibility), and still visible when the content is reshared or downloaded. </p><p>The Commission user-tested the icons and found they perform better with a text label attached, <em>&#8220;modified&#8221;</em> or similar. The icon that needs a caption to work.</p><p>Two things to hold apart: the icons are optional, the labelling is not. The Commission says so itself, so downloading the icon set does not close the file. Using these icons does not establish legal compliance by itself. It is the same trap as the watermark, one layer up.</p><p>You can use your own disclosure format if it is clear, distinguishable and accessible. What I think will not survive that test: a small line in the website footer, a faint watermark on an image, a label that flashes for a frame, anything buried in the terms and conditions.</p><p>For artistic, creative, satirical or fictional work, the obligation softens: disclose the manipulation exists, in a way that does not hamper the display or enjoyment of the work. A credits-style disclosure rather than a stamp across the screen.</p><div><hr></div><h2>The Dates</h2><p>August 2, 2026: everything above applies. Chatbot disclosure, emotion-recognition notice, deepfake and text labelling, and the marking obligation for systems placed on the market from that date.</p><p>There is no exception under Article 50. The transitional regime in <a href="https://artificialintelligenceact.eu/article/111/">Article 111</a>, the one that lets certain legacy high-risk systems stay outside the AI Act unless they are significantly changed, has no equivalent here. A chatbot you launched in 2023 is in scope on Sunday. So is the generative tool your team has been using since last spring. One exception, and it is narrow.</p><p>December 2, 2026: Providers of generative systems already on the market before August 2 get four extra months, for the machine-readable marking obligation only. Nothing else is deferred, and no deployer obligation is deferred at all.</p><p><span>The four months come from the </span><a href="https://eur-lex.europa.eu/eli/reg/2026/1744/oj">Omnibus on AI</a><span>, published in the Official Journal on July 24 and in force three days later. Five days before the deadline it modifies. Confirm the publication date yourself before you rely on it, because it landed the same week this article went out.</span></p><p>Content generated before August 2 does not need retroactive labels. The Commission encourages them anyway.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;7711c21b-fae5-463d-9e5c-201cf786c772&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The EU AI Act's Loophole With No Expiry Date&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-07-01T12:03:23.945Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!3JZC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab285665-697f-4608-ad90-6c5cb0e6b5ae_5760x3240.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/eu-ai-act-article-111-loophole-legacy-high-risk-ai&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:202097019,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:2,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>What to Do This Week</h2><p>If you are wondering what to do now, there are five moves needed:</p><ol><li><p><strong>Inventory the four situations.</strong> One page: where do we have systems talking to people, systems generating content, emotion recognition, published AI content? You cannot label what you have not listed.</p></li><li><p><strong>Fix the chatbot disclosure.</strong> The cheapest obligation on the list: a clear line at the start of the first interaction. Include the internal bots.</p></li><li><p><strong>Audit published content against the deepfake definition.</strong> Not &#8220;do we make deepfakes&#8221; but &#8220;do our visuals depict real or plausible people, places or products in a way that looks authentic.&#8221; Start with marketing, where most of the exposure sits.</p></li><li><p><strong>Decide your text position. </strong>For anything AI-written that informs the public: real, documented human review with named responsibility, or a label. Pick one per content stream and write it down.</p></li><li><p><strong>Ask your vendors two questions.</strong> Do your systems mark outputs in machine-readable format, and can we detect it? Their answer covers their layer. Then set up yours.</p></li></ol><div><hr></div><h2>What Sits Underneath</h2><p>Enforcement mostly belongs to national market surveillance authorities, and they are behind. The designation deadline was August 2025. As of June, nine member states had designated both their market surveillance and notifying authorities. National penalty laws are similarly unfinished. The enforcers are not missing so much as untested and unevenly resourced, since most member states are handing AI competence to regulators that already exist and already have full desks.</p><p>Two reasons not to treat that as breathing room.</p><p>The AI Office is not behind. It is competent for AI systems built on general-purpose AI models where the same entity provides both, and for systems integrated into the very large platforms designated under the <a href="https://eur-lex.europa.eu/eli/reg/2022/2065/oj">Digital Services Act</a>. The Omnibus on AI widened its remit further. If your chatbot sits on a foundation model from the company that also built the model, your enforcer is in Brussels, fully staffed.</p><p>And Article 50 breaches are the most visible violations in the entire AI Act. A missing chatbot disclosure, an unlabelled AI visual: public, permanent, screenshot-able by any competitor, journalist or future regulator with a scrolling habit. The <a href="https://eur-lex.europa.eu/eli/dir/2005/29/oj">Unfair Commercial Practices Directive (2005/29/EC)</a> already reaches deceptive content today, enforced by consumer authorities that very much exist.</p><p>The transparency rules arrive Sunday. Some of the enforcers are still being appointed.</p><p>Your audience is already here.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading AI Law. Decoded.! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Your Colleague Built an Agent]]></title><description><![CDATA[An employee builds an MS Copilot agent, then shares it with the whole company. Where the EU AI Act comes in.]]></description><link>https://ailawdecoded.com/p/employee-copilot-agents-eu-ai-act</link><guid isPermaLink="false">https://ailawdecoded.com/p/employee-copilot-agents-eu-ai-act</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 22 Jul 2026 20:25:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!uAh2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e55e258-8578-4dc8-9e69-b560f9cbcf05_6000x4000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uAh2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e55e258-8578-4dc8-9e69-b560f9cbcf05_6000x4000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uAh2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e55e258-8578-4dc8-9e69-b560f9cbcf05_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!uAh2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e55e258-8578-4dc8-9e69-b560f9cbcf05_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!uAh2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e55e258-8578-4dc8-9e69-b560f9cbcf05_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!uAh2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e55e258-8578-4dc8-9e69-b560f9cbcf05_6000x4000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uAh2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e55e258-8578-4dc8-9e69-b560f9cbcf05_6000x4000.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0e55e258-8578-4dc8-9e69-b560f9cbcf05_6000x4000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:547820,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.com/i/207818109?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e55e258-8578-4dc8-9e69-b560f9cbcf05_6000x4000.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uAh2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e55e258-8578-4dc8-9e69-b560f9cbcf05_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!uAh2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e55e258-8578-4dc8-9e69-b560f9cbcf05_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!uAh2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e55e258-8578-4dc8-9e69-b560f9cbcf05_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!uAh2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e55e258-8578-4dc8-9e69-b560f9cbcf05_6000x4000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>An employee builds an MS Copilot agent for their own work. It drafts proposals in the company template, pulls pricing from the right SharePoint folder, and saves them an hour a day. After three weeks, they share it with the team. A month later, it&#8217;s in an all-staff email with a link.</p><p>Somewhere in that sequence, the company acquired obligations under the EU AI Act. The intuitive answer for where: at the sharing. Private use was the employee&#8217;s own business. Distribution made it the company&#8217;s.</p><p>That answer reads the regulation backwards.</p><p>The obligations attached in week one, before anyone else knew the agent existed. Sharing changed something, just not that. The gap between those two answers decides whether a company governs employee-built AI or merely finds out about it.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>The Personal Use Exemption Covers Your Holiday, Not Your Job</h2><p>The AI Act defines a deployer in <a href="https://artificialintelligenceact.eu/article/3/">Article 3(4)</a>:</p><blockquote><p><em>a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity</em></p></blockquote><p><em>&#8220;Personal non-professional activity&#8221;</em> is quite narrow actually. <a href="https://artificialintelligenceact.eu/article/2/">Article 2(10)</a> adds the word <em>&#8220;purely&#8221;</em>: the AI Act does not apply to deployers who are natural persons using AI in the course of a purely personal non-professional activity. Asking Copilot where to go in September: covered. Building an agent that drafts your weekly reports: professional, however few people know about it. The exemption follows the activity, not the account.</p><p>And the deployer of that professional use is the company, not the employee: the agent runs in the company&#8217;s tenant, on a company license, for company work, which is use <em>&#8220;under its authority&#8221;</em> on any serious reading, and Article 3(4) asks nothing about whether the company knew. (No regulator has ruled on an employee-built agent yet. This is interpretation, the mainstream one, and mine.) So the company was a deployer of that agent for three weeks without knowing it existed.</p><p>If a compliance training taught you that the company only becomes a deployer at sharing, the rule has a real source. For tools a company never provided and merely tolerates (an employee&#8217;s private ChatGPT account in a browser), there is a serious argument that the employer lacks authority over the use. Lawyers split on that case.</p><p>An agent built inside the company&#8217;s own Copilot is not that case. The company licensed the platform, enabled the feature, and controls the tenant. Article 4 makes the same assumption: before and after the omnibus softened it, the AI literacy provision is addressed to providers and deployers for the people using AI systems on their behalf. Staff using AI for work is the deployer&#8217;s use. A legal person has no other way to use anything.</p><div><hr></div><h2>What Sharing Changed</h2><p>Legally, almost nothing. Practically, two things moved.</p><p><strong>Scale.</strong> One person relying on an agent is an anecdote. A company relying on it is a dependency, with the error surface to match. If the pricing sheet it reads is stale, that&#8217;s now every proposal it touches.</p><p><strong>Deniability. </strong>Before the email, the company&#8217;s gap was factual: no inventory, no awareness. After the email, the use is announced, organization-wide, in writing. Whatever duties exist are now duties the company visibly isn&#8217;t performing.</p><p>Which leaves the question with actual money on it. The company deploys a Copilot agent, fine. When does it become the deployer of that particular agent, and what extra obligations arrive when it does? Take a harmless one: an agent that walks employees through submitting business-trip reports, shared with the whole company.</p><p>There are two layers here. If the agent counts as nothing more than a configuration of Copilot, there is no separate deployer question: the company was deploying Copilot all along, and the agent is one way of using it. If the agent counts as its own AI system (an open question, below), the deployer analysis repeats: first use for work under company authority, so the company was the agent&#8217;s deployer while its creator was still its only user. Under neither reading is sharing the moment deployer status begins.</p><p>What sharing plausibly triggers is a different concept. The AI Act defines <a href="https://artificialintelligenceact.eu/article/3/">putting into service</a> as supplying an AI system for first use <em>&#8220;directly to the deployer or for own use.&#8221;</em> An agent distributed org-wide starts to look like a system the company put into service for its own use. And whoever develops an AI system and puts it into service is its provider, the role with the heavy obligations. Follow that logic to its end and the company is the provider of this particular agent: it developed the system (through its employee) and rolled it out for its own use.</p><p>Two conditions stand between that sentence and settled law: whether the agent is an AI system in its own right at all, and whether an internal rollout happens <em>&#8220;under its own name or trademark,&#8221;</em> as the provider definition in Article 3(3) requires. Both are unresolved, and for the trip-report agent, comfortably little turns on them. Under the AI Act, obligations scale with risk class, not with the number of systems on your list, and provider of a minimal-risk system is a nearly empty role.</p><p>A benign agent adds almost nothing to what the Copilot rollout already required: literacy, transparency where output leaves an informed audience, prohibited-practice hygiene. What it adds is one unavoidable task: someone has to look at its purpose and classify it. Everything heavier waits on that.</p><p>One thing the email did not do: internal sharing is not <em>&#8220;placing on the market&#8221;. </em>Making available on the market means supply in the course of commercial activity. Colleagues are not a market. The comfort is narrower than it looks, though. Market supply is not the only route to the heavy provider obligations: for a high-risk agent, putting into service for the company&#8217;s own use is enough. What stays internal stays light only while the purpose does.</p><div><hr></div><h2>Microsoft Ships the Gate Open</h2><p>The product mechanics deserve a closer look, because two default settings decide more than most written AI policies do.</p><p>A new Copilot agent is private. <a href="https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/agent-builder-share-manage-agents">Microsoft&#8217;s documentation</a> gives its creator three options: keep it private, share it with specific people or groups, or share it with anyone in the organization via link. Whether employees can use that third option is an admin setting. Its default value: all users may share org-wide.</p><p>Unless your admin changed a setting, every licensed employee can distribute an AI agent to your entire company. No approval step. That all-staff email needed no one&#8217;s permission.</p><p>Microsoft&#8217;s documentation also states that changes to the sharing controls apply only to new sharing actions: existing shared agents remain accessible. Tighten your policy next quarter and every agent shared before the change stays in circulation. </p><p>There is also an approval gate. Agents submitted to the organizational catalog go through admin review before they appear in the company&#8217;s agent store. The gate exists. The sharing link walks around it.</p><p>Two more details for whoever owns offboarding. Only an agent&#8217;s creator can delete it, though admins can <a href="https://learn.microsoft.com/en-us/microsoft-365/admin/manage/agent-registry">reassign ownership</a> if they know the agent exists. And nothing in the sharing flow retires an agent when its creator leaves: it keeps answering questions from a knowledge base nobody is updating.</p><p>None of this is a criticism of Microsoft, and roughly the same story applies to custom GPTs, Gemini Gems, and every other build-your-own-assistant feature: the vendor optimizes for adoption, the defaults follow. But an AI Act compliance program that audits policies and never audits tenant settings is auditing the wrong document. </p><div><hr></div><h2>Purpose Is Where It Turns</h2><p>Everything so far is manageable. The modest obligations that travel with any minimal-risk agent: AI literacy under <a href="https://artificialintelligenceact.eu/article/4/">Article 4</a>, applicable since February 2, 2025, though the omnibus softened it from ensuring literacy to supporting its development. And transparency under <a href="https://artificialintelligenceact.eu/article/50/">Article 50</a> from August 2, 2026, which turns on people knowing they&#8217;re dealing with AI. Inside the company, that&#8217;s obvious. It stops being obvious when the agent&#8217;s output reaches customers. Weeks away, not next year.</p><p>The structural risk is different, and it has a specific address: <a href="https://artificialintelligenceact.eu/article/25/">Article 25(1)(c)</a>.</p><p>A deployer becomes the provider of a high-risk AI system if it modifies the intended purpose of an AI system, including a general-purpose one, such that the system becomes high-risk. And when that happens, Article 25 is explicit about the consequence: the original provider stops being the provider of that system. Microsoft exits. You inherit the full <a href="https://artificialintelligenceact.eu/article/16/">Article 16</a> stack: risk management, technical documentation, conformity assessment, registration, the works.</p><p>One more twist. The departing provider normally owes the new one cooperation and documentation under Article 25(2), except where it clearly specified that its system is not to be turned into a high-risk one. Microsoft&#8217;s use terms restrict high-risk uses. Check your agreement before assuming the handover comes with help.</p><p>Copilot&#8217;s intended purpose is general productivity. An agent is, functionally, a purpose machine: you give it instructions, knowledge, and a job. Which means the distance between <em>&#8220;deployer of Copilot&#8221;</em> and <em>&#8220;provider of a high-risk AI system&#8221;</em> is one agent built with the wrong job description.</p><p>The recruiting team builds an agent that pre-screens CVs against role requirements. That&#8217;s employment, Annex III, point 4: high-risk. Article 25(1)(c) has no seniority threshold, no requirement that anyone approved anything. </p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;b1108049-b45c-4571-809b-d84a5ca89ec1&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Is My AI System High-Risk Under the EU AI Act?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-06T12:02:25.960Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!-GG3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/is-my-ai-system-high-risk-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:196305760,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><p>The high-risk obligations themselves now apply from December 2, 2027, after the <a href="https://ailawdecoded.com/p/eu-ai-act-amended-the-digital-omnibus">omnibus moved the dates</a>. That&#8217;s runway. Use it.</p><p>Two things are not waiting for 2027.</p><p>First, the prohibitions, in force since February 2025 and carrying the <a href="https://ailawdecoded.com/p/prohibited-ai-practices-eu-ai-act">top fine tier</a>: &#8364;35 million or 7% of global turnover. The relevant one for this story is Article 5(1)(f), emotion inference in the workplace. An agent that reads sentiment in the team&#8217;s messages so a manager knows &#8220;how everyone&#8217;s doing&#8221;? An enthusiastic employee can build a prohibited practice in an afternoon, with knowledge sources and a friendly name.</p><p>Second, a detail from <a href="https://artificialintelligenceact.eu/article/26/">Article 26(7)</a> that reframes the whole sharing question: before using a high-risk AI system at the workplace, employers must inform the affected workers and their representatives. For high-risk agents, an announcement to staff isn&#8217;t the moment the trouble starts. It&#8217;s a legal requirement. </p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;1142080d-bd26-4cb3-a719-96991f6e1cb2&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;EU AI Act Amended: The Digital Omnibus Timeline&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-13T12:02:43.130Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!DR18!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/eu-ai-act-amended-the-digital-omnibus&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:196926473,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:3,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>Is an Agent Even a Separate AI System?</h2><p>No one can tell you yet. The Commission&#8217;s <a href="https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application">guidelines on the AI system definition</a> predate the no-code agent wave and don&#8217;t address it. <span>The May 2026 </span><a href="https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems">draft guidelines on high-risk classification</a><span> come closest, but they answer a neighboring question: multi-component and agentic setups are classified as one system when their linked parts jointly serve a high-risk purpose. Direction confirmed, purpose decides, slicing doesn't help. Who answers for a single no-code agent remains open.</span></p><p>There are two defensible readings. </p><p><strong>One: </strong>a declarative agent is a saved configuration of Microsoft&#8217;s system, instructions plus knowledge plus permissions, and the AI system remains Copilot, with Microsoft as its provider. </p><p><strong>Two:</strong> an agent with its own name, its own purpose, its own knowledge, its own tool permissions, its own user base, and an entry in a store is an AI system built on a general-purpose model, and someone other than Microsoft is answering for it. A saved prompt sits at one end. An org-wide Copilot Studio agent with autonomous triggers sits at the other. The vocabulary (&#8221;agent,&#8221; &#8220;skill,&#8221; &#8220;Gem&#8221;) is marketing. The AI Act&#8217;s question is functional.</p><p>Two reasons not to lose sleep over the metaphysics. For a benign internal agent, both readings land in nearly the same place: thin obligations either way. And in the scenario where the readings would diverge, the high-risk one, Article 25(1)(c) settles the question by making you the provider regardless.</p><p>One more fear worth retiring: building agents does not make your company a provider of a general-purpose AI model. Under the Commission&#8217;s <a href="https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers">GPAI guidelines</a>, that role attaches to modifications that significantly change the model, with an indicative threshold of training compute above roughly a third of what trained the original. Instructions and knowledge files are not training compute. Your agents are prompting, not pre-training.</p><div><hr></div><h2>What to Actually Do About It</h2><p>The duties in the AI Act share one hidden precondition: you can&#8217;t train people on agents, disclose agents, purpose-check agents, or classify agents you don&#8217;t know exist. The inventory comes first. </p><p>For the people building agents, six rules that fit on one page:</p><ol><li><p><strong>There is no personal AI at work.</strong> Work account plus work task equals the company&#8217;s deployment, even if no one knows. The exemption you&#8217;re thinking of covers your holiday planning.</p></li><li><p><strong>Building is fine. Repurposing is the event.</strong> The moment an agent starts touching decisions about people (hiring, performance, promotion, credit, claims, access to anything), stop and ask before you share.</p></li><li><p><strong>The short forbidden list is absolute.</strong> No agents that infer colleagues&#8217; emotions, score people, or nudge them manipulatively. Not with approval, not as a pilot, not as a joke.</p></li><li><p><strong>Four questions before you hit Share.</strong> What does it do? Whose data does it read? Who will rely on it? Could its output touch a decision about a person?</p></li><li><p><strong>Label what leaves the team.</strong> People outside your context need to know they&#8217;re reading AI output.</p></li><li><p><strong>Your agents outlive your tenure.</strong> When you change roles or leave, hand them over or kill them.</p></li></ol><p>For whoever owns &#8220;the AI thing&#8221; at your company, six checks:</p><ol><li><p><strong>Open the admin center today</strong> and look at the agent sharing setting. If nobody changed it, it&#8217;s set to everyone.</p></li><li><p><strong>Route org-wide distribution through the catalog.</strong> The approval gate is already built. Make the link route the exception.</p></li><li><p><strong>Build the register.</strong> One row per agent: name, owner, purpose, knowledge sources, audience. This is the unglamorous document that makes every other obligation performable.</p></li><li><p><strong>Add agents to the leaver checklist.</strong> Reassign or retire them when their creator walks out.</p></li><li><p><strong>Put agent-building into your AI literacy training.</strong> Article 4 has applied since February 2025 (now an effort obligation after the omnibus, but applicable), and the person most in need of it is your most enthusiastic builder.</p></li><li><p><strong>Name the escalation trigger in plain words.</strong> &#8220;An agent that helps decide about people goes to [name] before sharing.&#8221; One sentence, on the intranet, beats a policy nobody opens.</p></li></ol><div><hr></div><h2>The Question the AI Act Asks</h2><p>The all-staff email didn&#8217;t create the company&#8217;s obligations. It ended the period in which no one could see them.</p><p>And an email is the polite version. Most agents move through links, team channels, and word of mouth: no announcement, no list, no owner once the creator changes jobs. The population grows every quarter, mostly useful, occasionally one job description away from Annex III.</p><p>The register you haven&#8217;t built yet is a list of things you already answer for.</p><p>The AI Act doesn&#8217;t ask whether you knew.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading AI Law. Decoded.! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Regulate, Retreat, Build]]></title><description><![CDATA[A brief history of AI regulation in the EU, in three acts.]]></description><link>https://ailawdecoded.com/p/eu-ai-act-history</link><guid isPermaLink="false">https://ailawdecoded.com/p/eu-ai-act-history</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 15 Jul 2026 12:03:47 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!RbE7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd5b2b-fb2d-41a8-8f58-9dd990d891f2_6000x4000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RbE7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd5b2b-fb2d-41a8-8f58-9dd990d891f2_6000x4000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RbE7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd5b2b-fb2d-41a8-8f58-9dd990d891f2_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!RbE7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd5b2b-fb2d-41a8-8f58-9dd990d891f2_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!RbE7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd5b2b-fb2d-41a8-8f58-9dd990d891f2_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!RbE7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd5b2b-fb2d-41a8-8f58-9dd990d891f2_6000x4000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RbE7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd5b2b-fb2d-41a8-8f58-9dd990d891f2_6000x4000.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/57bd5b2b-fb2d-41a8-8f58-9dd990d891f2_6000x4000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:737865,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.com/i/206722020?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd5b2b-fb2d-41a8-8f58-9dd990d891f2_6000x4000.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RbE7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd5b2b-fb2d-41a8-8f58-9dd990d891f2_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!RbE7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd5b2b-fb2d-41a8-8f58-9dd990d891f2_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!RbE7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd5b2b-fb2d-41a8-8f58-9dd990d891f2_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!RbE7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd5b2b-fb2d-41a8-8f58-9dd990d891f2_6000x4000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>In February 2017, the European Parliament <a href="https://www.europarl.europa.eu/doceo/document/TA-8-2017-0051_EN.html">voted</a> on considering whether robots should become <em>&#8220;electronic persons&#8221;</em>. ChatGPT was nearly six years away. The most advanced consumer AI in Europe could recommend a playlist. And the Parliament was already asking the question that would follow EU lawmakers for the next nine years: </p><blockquote><p><em>When the machine gets it wrong, who pays?</em></p></blockquote><p>The electronic personhood idea died, mercifully. The question survived.</p><p>Hold onto it. It&#8217;s the thread that makes sense of everything the EU has done on AI since, including the last eighteen months, which otherwise look like the EU changing its mind.</p><p>Because if you&#8217;re trying to track EU AI regulation in 2026, it does look like that. The EU AI Act got amended before most of it applied. A liability directive appeared, sat in Parliament for three years, and vanished. In June, the Commission proposed something called the Cloud and AI Development Act, which regulates data centres and sounds like it wandered in from a different policy file. Each development makes sense on its own. Together, they read as noise.</p><p>They&#8217;re not noise. They&#8217;re one story in three acts: the EU built a complete legal system for AI, dismantled part of it before it applied, and is now spending public money to make sure there&#8217;s a European AI industry left to regulate. If compliance is your job, the arc matters more than any single law. It tells you which rules will be enforced, which got softened, and where the next obligations might come from.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>Act I: Regulate (2017&#8211;2024)</h2><p>That 2017 resolution asked the Commission for liability rules covering robots and AI. The EU&#8217;s opening move on AI law was liability. Market access rules came four years later.</p><p>What followed was Brussels at its usual pace. An AI strategy in 2018. Ethics guidelines from an expert group in 2019: voluntary, high-minded, and largely ignored by the market. Then the February 2020 <a href="https://commission.europa.eu/publications/white-paper-artificial-intelligence-european-approach-excellence-and-trust_en">White Paper</a>, which committed to a risk-based approach and introduced the framing that still runs the show: an &#8220;<em>ecosystem of excellence</em>&#8221; and an &#8220;<em>ecosystem of trust</em>&#8221;. Ursula von der Leyen had promised AI legislation within her first hundred days. What arrived around day one hundred was a white paper announcing the intention to legislate. In Brussels terms, that is punctual.</p><p>The <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A52021PC0206">actual proposal</a> landed on April 21, 2021. The logic behind it: Member States were starting to write their own AI laws, and one regime is cheaper than 27. Trust was treated as an adoption strategy (people won&#8217;t use AI they don&#8217;t trust, so trust rules double as industrial policy). And after the GDPR, there was open ambition to set the global standard again.</p><p>One architecture choice from that proposal explains more than anything else in it. The AI Act was built as product safety law: risk classes, conformity assessments, CE marking. AI regulated like lifts and medical devices, because that was the machine the EU already had. It is a market access instrument, not a fundamental rights instrument. A good share of what frustrates people about the AI Act traces back to that choice.</p><p>And the system was designed with two halves. In September 2022, the Commission proposed the <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A52022PC0496">AI Liability Directive</a> together with a rewritten Product Liability Directive. The AI Act tells you how to put AI on the market. The liability pair answered what happens when it hurts someone anyway. Rules and consequences. On paper, a complete system.</p><p>Then the negotiations met reality. Six days before the Council agreed its negotiating position in December 2022, ChatGPT launched. The text barely contemplated general-purpose AI, so Parliament wrote an entire GPAI chapter mid-flight in 2023. In November 2023, France, Germany and Italy nearly collapsed the final talks by demanding that foundation models be governed by <em>&#8220;mandatory self-regulation&#8221;</em>, a position that happened to match the interests of Mistral and Aleph Alpha. The deal that saved the file took a 36-hour negotiating marathon in December 2023.</p><p>The pattern is worth registering: the fight between protection and competitiveness didn&#8217;t start after the AI Act passed. It was inside the building the whole time.</p><p><a href="https://eur-lex.europa.eu/eli/reg/2024/1689/oj">EU AI Act (Regulation (EU) 2024/1689</a>) entered into force on August 1, 2024. Act one complete. The EU had its rulebook. The liability half was still sitting in committee.</p><div><hr></div><h2>Act II: Retreat (2024&#8211;2026)</h2><p>In September 2024, Mario Draghi&#8217;s competitiveness report handed Brussels a new vocabulary: regulatory burden, simplification. The mood shifted from &#8220;the world will copy our rules&#8221; to &#8220;our rules are why we don&#8217;t have an AI industry.&#8221; Whether that diagnosis is correct is a separate article. Its effects arrived fast.</p><p>Laws usually die loudly. A failed vote, a walkout, a press conference. The AI Liability Directive died in an annex: one line in the Commission&#8217;s <a href="https://eapil.org/2025/10/09/european-commission-withdraws-two-proposals-assignments-of-claims-regulation-and-ai-liability-directive/">2025 work programme</a>, published February 11, 2025, marking it for withdrawal due to &#8220;no foreseeable agreement.&#8221; Parliament&#8217;s legal affairs committee was actively working on the file at the time, with votes scheduled. Twelve industry associations had formally called for the withdrawal weeks earlier. It is rare for Brussels to move so quickly on stakeholder feedback. The formal withdrawal appeared in the Official Journal on October 6, 2025. The ePrivacy Regulation died in the same annex, after eight years of negotiation.</p><p>It&#8217;s worth being precise about what was lost, because the directive had a modest reputation and an even more modest text. It created no new liability regime. It gave people harmed by high-risk AI two procedural tools: court-ordered disclosure of evidence (Article 3) and a rebuttable presumption of causality (Article 4). Without them, a rejected job applicant who suspects the algorithm has to reverse-engineer a neural network to prove their case. Parliament had asked for strict liability in 2020. The Commission offered presumptions. Even presumptions turned out to be too much.</p><p><span>The stated reasoning, per Commissioner </span><a href="https://www.euronews.com/next/2025/07/31/eu-commission-confirms-ditching-of-ai-liability-and-patents-proposals">Virkkunen</a><span>: the directive would have led Member States to </span><em><span>"apply the rules in different ways"</span></em><span>. The result of withdrawing it: AI liability now runs through 27 national tort regimes, each applying its own rules. The fragmentation offered as the risk is the outcome that was chosen.</span></p><p>So where does liability actually live now? In the surviving half of the 2022 pair. The new <a href="https://eur-lex.europa.eu/eli/dir/2024/2853/oj/eng">Product Liability Directive</a> treats software and AI systems as products, SaaS included, and applies to products placed on the market from December 9, 2026. It even inherited the dead directive&#8217;s tools: disclosure duties and presumptions for complex cases. But it compensates product-defect damage: death, personal injury, property, destroyed data. An AI system that wrongfully denies you a loan, filters out your job application, or scores you into a worse insurance bracket produces none of those. The harms that motivated the liability directive in the first place now depend on which of the 27 countries you&#8217;re standing in when the algorithm gets it wrong.</p><p>The retreat also reached the AI Act itself. The Digital Omnibus moved the high-risk obligations to December 2, 2027 (Annex III) and August 2, 2028 (AI embedded in regulated products), fixed dates this time. Parliament adopted it on June 16, the Council <a href="https://www.consilium.europa.eu/en/press/press-releases/2026/06/29/artificial-intelligence-council-gives-final-green-light-to-simplify-and-streamline-rules/">signed off on June 29</a>. I covered the full reshuffled timeline <a href="https://ailawdecoded.com/p/eu-ai-act-amended-the-digital-omnibus">in May</a>. What stayed on schedule is more important than what moved: the prohibitions have applied since February 2025, transparency obligations arrive on August 2, 2026 &#8212; with one carve-out: systems already on the market get until December 2, 2026 for the Article 50(2) watermarking duty &#8212; and the Commission's enforcement powers over general-purpose AI switch on the same day. Weeks away, not next year.</p><p>One more date, because the timing is almost too neat. The following week after the omnibus deal was struck in May, the EU <a href="https://www.coe.int/en/web/artificial-intelligence/-/european-union-ratifies-the-council-of-europe-framework-convention-on-artificial-intelligence">ratified</a> the Council of Europe Framework Convention on AI, the first binding international treaty on AI and human rights. Delaying its own rules at home, signing commitments abroad, in the same week. </p><p>Both are the EU&#8217;s real position. Act two, in a single image.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;6c0f2705-6fdd-4167-8bb0-97e605a234e4&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;EU AI Act Amended: The Digital Omnibus Timeline&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-13T12:02:43.130Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!DR18!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/eu-ai-act-amended-the-digital-omnibus&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:196926473,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:3,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>Act III: Build (2025&#8211;2026)</h2><p>While the rules were being trimmed, the money arrived.</p><p><strong>February 2025, AI Action Summit in Paris</strong>: the Commission announced InvestAI, a plan to mobilize &#8364;200 billion for AI, including &#8364;20 billion for &#8220;gigafactories&#8221; to train frontier-scale models. </p><p><strong>April 2025</strong>: the AI Continent Action Plan, built on five pillars. Compute, data, skills, adoption, and simplification. The thing act two was made of is now an official pillar of AI industrial policy.</p><p><strong>Then June 3, 2026</strong>: the Tech Sovereignty Package, headlined by the <a href="https://digital-strategy.ec.europa.eu/en/library/proposal-cloud-and-ai-development-act-cada">Cloud and AI Development Act</a>. CADA is a proposal, weeks old, and the negotiations will reshape it. But the design is telling. It creates a <em>"cloud sovereignty framework"</em> for providers serving the public sector, built on four "Union assurance levels." The baseline requires infrastructure, assets and customer data to stay in the EU. The strictest tier requires a provider free of any third-country control, no derogations, holding a high-assurance EU cybersecurity certificate, and able to demonstrate control over every software component in the stack, down to who maintains and evolves it.</p><p><span>The Commission's own numbers explain the urgency: European providers' share of their home cloud market fell from roughly 29% in 2017 to 15% by 2022 (from the </span><a href="https://digital-strategy.ec.europa.eu/en/library/proposal-cloud-and-ai-development-act-cada">proposal's explanatory memorandum</a><span>), and the EU spends &#8364;264 billion a year on US proprietary IT products and services (from the </span><a href="https://www.insideglobaltech.com/2026/06/04/eu-tech-sovereignty-package/">Open Source Strategy</a><span> published in the same package).</span></p><p>CADA gets filed under industrial policy, and that&#8217;s how it reads, until you look at the mechanics. Assurance levels. Certification schemes. Software bills of materials. Source code audits. Corporate separation requirements. That is a conformity assessment regime: compliance law in a hard hat. The EU didn&#8217;t stop regulating AI in act three. It changed what it regulates for. Acts one and two regulated to protect individuals. Act three regulates to secure the stack.</p><p>If you sell cloud or AI services to an EU public body, or your product runs on a hyperscaler that does, the sovereignty framework is now a question in your future procurement bids. Which parts of the proposal survive the negotiations is genuinely open. The direction is not.</p><div><hr></div><h2>The Rest of the Map</h2><p>The three acts are the spine. The body of EU AI law is wider, and a map that pretends otherwise would be lying to you. The short version:</p><ul><li><p><strong><a href="https://eur-lex.europa.eu/eli/reg/2016/679/oj">GDPR</a></strong> &#8212; Article 22 on automated decisions is still arguably the most litigated AI provision in Europe. And the omnibus process is now reopening the GDPR itself, including a proposed legal basis for AI training. Contested, not adopted.</p></li><li><p><strong>Copyright</strong> &#8212; the 2019 <a href="https://eur-lex.europa.eu/eli/dir/2019/790/oj">CDSM Directive</a>&#8216;s text-and-data-mining exception (Articles 3 and 4) is the legal foundation of every AI training data fight in the EU. The AI Act cross-references its opt-out directly.</p></li><li><p><strong><a href="https://eur-lex.europa.eu/eli/reg/2022/2065/oj">DSA</a></strong> &#8212; recommender transparency and systemic risk duties for the largest platforms. AI rules that never mention the AI Act.</p></li><li><p><strong><a href="https://eur-lex.europa.eu/eli/reg/2023/2854/oj">Data Act</a></strong> &#8212; applies since September 2025. Who gets access to device data: the supply side of AI.</p></li><li><p><strong><a href="https://eur-lex.europa.eu/eli/reg/2024/2847/oj">Cyber Resilience Act</a></strong> &#8212; security requirements for connected products, AI-enabled ones included. Main obligations land December 2027.</p></li><li><p><strong><a href="https://eur-lex.europa.eu/eli/dir/2024/2831/oj">Platform Work Directive</a></strong> &#8212; the first EU law on algorithmic management. Transposition due December 2026. If you build or use HR tech, this one is aimed at you.</p></li><li><p><strong><a href="https://eur-lex.europa.eu/eli/reg/2025/327/oj">European Health Data Space</a></strong> &#8212; health data for AI training and development, phasing in from 2027.</p></li><li><p><strong><a href="https://www.europarl.europa.eu/legislative-train/theme-protecting-our-democracy-upholding-our-values/file-digital-fairness-act">Digital Fairness Act</a></strong> &#8212; expected as a proposal in late 2026: dark patterns, addictive design, unfair personalization. The next AI-adjacent law is coming from consumer protection, not tech policy.</p></li><li><p><strong><a href="https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/">Harmonised standards</a></strong> &#8212; not law, but where <em>&#8220;compliant&#8221;</em> is currently being defined for high-risk AI. The omnibus delay was officially justified by these not being ready.</p></li><li><p><strong>Sector rules</strong> &#8212; <a href="https://eur-lex.europa.eu/eli/reg/2022/2554/oj">DORA</a> for financial entities, <a href="https://eur-lex.europa.eu/eli/reg/2017/745/oj">MDR</a> for medical devices, vehicle type-approval. Your vertical has its own chapter.</p></li></ul><p>Horizontal EU law only. National AI laws are a separate map, for a separate article.</p><div><hr></div><h2>Where This Leaves You</h2><p>The arc translates into priorities better than any single law does.</p><p>Enforcement energy is real for what&#8217;s already live: prohibitions, GPAI obligations, transparency from August 2. It&#8217;s reduced for high-risk conformity, where you gained time until December 2027. And it&#8217;s rising in two new places: liability and procurement.</p><p>The liability point deserves numbers. </p><p>December 9, 2026: the new product liability regime starts applying to AI products, with disclosure duties and presumptions that make claims easier to bring. </p><p>December 2, 2027: the high-risk safety rules those products would naturally be judged against. The exposure arrives 358 days before the rulebook. </p><p>For roughly a year, a court assessing whether your AI product is <em>&#8220;defective&#8221; </em>has no applicable harmonised standard to measure it against, and you have no AI Act compliance to point to, because there is nothing yet to comply with. Contracts, indemnities, documentation and insurance carry that year. If your liability planning is waiting for 2027 because the AI Act is, it&#8217;s waiting too long.</p><p>Act three is still being written. The gigafactories are funded, CADA is heading into negotiations, and the next obligations are arriving through procurement criteria and consumer law rather than another grand AI statute.</p><p>Which leaves the question from 2017. The Parliament asked who pays when the machine gets it wrong, back when the machines could barely do anything worth suing over. Nine years later, the EU has some 150 pages on how to build AI responsibly, a product liability law that covers half the problem, and 27 national courts assembling the rest.  </p><p><em>When the machine gets it wrong, who pays?</em></p><p>Three acts later, it&#8217;s the one question the EU formally withdrew.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading AI Law. Decoded.! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Your Role Classification Is Only as Honest as Your AI Inventory]]></title><description><![CDATA[The EU AI Act never tells you to build an AI inventory. But every obligation in it assumes you already have one.]]></description><link>https://ailawdecoded.com/p/eu-ai-act-role-classification-ai-inventory</link><guid isPermaLink="false">https://ailawdecoded.com/p/eu-ai-act-role-classification-ai-inventory</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 08 Jul 2026 20:12:57 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!HkyX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e75c2b-fd26-4440-8986-372d833c62b0_6000x4000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HkyX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e75c2b-fd26-4440-8986-372d833c62b0_6000x4000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HkyX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e75c2b-fd26-4440-8986-372d833c62b0_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!HkyX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e75c2b-fd26-4440-8986-372d833c62b0_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!HkyX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e75c2b-fd26-4440-8986-372d833c62b0_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!HkyX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e75c2b-fd26-4440-8986-372d833c62b0_6000x4000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HkyX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e75c2b-fd26-4440-8986-372d833c62b0_6000x4000.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/80e75c2b-fd26-4440-8986-372d833c62b0_6000x4000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:492618,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.com/i/205943005?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e75c2b-fd26-4440-8986-372d833c62b0_6000x4000.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HkyX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e75c2b-fd26-4440-8986-372d833c62b0_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!HkyX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e75c2b-fd26-4440-8986-372d833c62b0_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!HkyX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e75c2b-fd26-4440-8986-372d833c62b0_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!HkyX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e75c2b-fd26-4440-8986-372d833c62b0_6000x4000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>The register is finished.</p><p>Three weeks after the workshop with the blocked calendars and the mandatory attendance, the spreadsheet is complete. Fourteen AI systems, each with a role in column D, each with documented reasoning, each with a reassessment trigger. You presented it to the general counsel. She nodded. In your world, that&#8217;s a standing ovation.</p><p>Then comes the quarterly all-hands. The product team is doing a demo. They&#8217;ve built something called <strong>Atlas</strong>: an internal assistant that answers customer-history questions for the support staff. It runs on a vendor&#8217;s model, fine-tuned on two years of support tickets. It has an internal brand name. It has a logo. Someone made a logo.</p><p>Atlas is not in the register.</p><p>That afternoon, you do something you should have done earlier. You search the expense system for AI subscriptions. Seventeen results. Team cards, individual expense claims, one recurring charge labeled only &#8220;productivity tool&#8221;. Four of them match the register. The other thirteen are new to you.</p><p>The register isn&#8217;t wrong. Everything on it is classified correctly. The problem is what&#8217;s missing from it. And what&#8217;s missing from it follows a pattern.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>The Assumption Underneath the Decision Tree</h2><p>The EU AI Act never tells you to build an AI inventory. No article requires one. What the AI Act does instead is attach every obligation to a specific system and to your role with respect to it.</p><p>Provider and deployer are defined system by system in <a href="https://artificialintelligenceact.eu/article/3/">Article 3</a>. The role-transformation triggers in <a href="https://artificialintelligenceact.eu/article/25/">Article 25</a> fire per system. Deployer obligations under <a href="https://artificialintelligenceact.eu/article/26/">Article 26</a> attach to each high-risk system you operate. The fundamental rights impact assessment in <a href="https://artificialintelligenceact.eu/article/27/">Article 27</a> is per system. Even the AI literacy obligation in <a href="https://artificialintelligenceact.eu/article/4/">Article 4 </a>assumes you know which systems your staff are operating.</p><p>The regulation assumes enumeration without ever mandating it. Every obligation is conditional on knowing a system exists and knowing what you are in relation to it. The inventory is the unstated premise of the whole compliance architecture, which is why <em>build the inventory</em> is step one of the practical process of role assignment.</p><p>Step one is also the step that so often fails.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;14726057-b1e1-4db4-8520-851054d0dcfc&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;What's Your Role Under the EU AI Act? Practical Decision Tree.&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-06-10T12:03:27.696Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!Bh5p!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/your-role-under-the-eu-ai-act-guide&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:199877647,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:5,&quot;comment_count&quot;:5,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>Some Systems Get In, and Some Don&#8217;t</h2><p>A register is built from what can be seen. What can be seen is what passed through procurement: a contract exists, legal reviewed it, the vendor wrote an intended purpose into the documentation. These are also the systems most likely to sit in a clean deployer posture, because a contract and a documented intended purpose are what keep you a deployer. The vendor assessed the use case. You operate inside the lines the vendor drew. Column D says <em>deployer</em>, and column D is right.</p><p>The systems that escape are a different population. The subscription on a team card. The API key a developer set up in an afternoon. The tool a business unit reconfigured after go-live, without anyone from legal knowing. These systems have no documented intended purpose, no contractual guardrails, and no review scheduled for later. Which is the exact environment where the Article 25 triggers live: </p><ul><li><p>repurposing a system beyond what the vendor assessed (25(1)(c)), </p></li><li><p>modifying it in ways no conformity assessment foresaw (25(1)(b)), </p></li><li><p>putting your own name on it because it looked better that way (25(1)(a)).</p></li></ul><p>The properties that keep a system out of your register are the properties that push it toward provider territory.</p><p>So the undercount isn&#8217;t even. The register misses the expensive category first. A procured chatbot used exactly as licensed can go missing too, but the tool that was fine-tuned on proprietary data, branded internally, and pointed at a use case its vendor never heard of? That one skipped procurement almost by definition. </p><p>Atlas was never getting into column D. Systems like Atlas never are.</p><div><hr></div><h2>Two Ways a Register Fails</h2><p>The invisible system is <em>the first failure mode</em>. <strong>Shadow AI</strong>: the system isn&#8217;t in the register, you don&#8217;t know it exists, so you never classify it. A gap, at least, is honest about itself.</p><p><em>The second failure mode</em> sits inside the register. The tool was procured properly. Legal reviewed the contract. The entry says <em>deployed SaaS, vendor X, deployer</em>. Then a business unit fine-tuned it on internal data, or pointed it at a use case the vendor never assessed, or put an internal brand on the interface. The entry was correct on the day it was written. It isn&#8217;t anymore.</p><p>A missing entry is a gap. A stale entry is false confidence, and false confidence costs more, because a signed-off register is the last place anyone looks for a problem. The classification happened. The box is ticked. The general counsel nodded.</p><p>Both modes map onto the <a href="https://ailawdecoded.com/p/your-role-under-the-eu-ai-act-guide">decision tree on role-assignment</a>. The first breaks step one: the classification never runs. The second breaks the &#8220;document and revisit&#8221; step: the classification ran once, and the system kept moving.</p><p>The regulation doesn&#8217;t distinguish between the two. Article 25 fires at the moment of the act. Rebranding is a marketing decision. Substantial modification can be a configuration choice. Repurposing is often plain usage drift. None of it requires a contract, a procurement event, or an approval. The legal event happens when the team does the thing, not when legal finds out. </p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;d5166aef-d980-4843-946e-9558c68ca831&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Provider vs. Deployer Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-22T12:03:43.719Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!NS5L!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35f75bb-44f2-45d4-b53c-84654d8e8617_8192x5461.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/provider-vs-deployer-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:194314202,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:5,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>Shadow AI Data Breach</h2><p>Shadow AI became a security story before it became a compliance story, so the numbers come from the security world.</p><p>IBM&#8217;s <a href="https://www.ibm.com/reports/data-breach">2025 Cost of a Data Breach report</a> found that 20% of studied organizations experienced a breach linked to shadow AI: unsanctioned tools operating outside IT oversight. Those breaches cost an average of $670,000 more than the baseline. And 63% of the breached organizations had no governance policy for managing AI or detecting unauthorized use.</p><p>Reading it as a lawyer, the same numbers say something else. One in five organizations has already had unsanctioned AI surface in the most expensive way possible. The population of unregistered systems is large enough to show up in breach statistics. Every system in it has an AI Act role that has never been assigned.</p><p>The security industry measures shadow AI in exposed records and incident costs. The measurement still missing: how many of those invisible systems have crossed an Article 25 threshold. I haven&#8217;t found a published figure, and I doubt one exists yet. </p><p>I guess that the share is disproportionate. </p><div><hr></div><h2>The Questionnaire Coming Back Clean</h2><p>My next question is how can an organization solve such situation. The instinctive fix is a survey. Email the business units, ask them to list their AI tools, compile the answers.</p><p>But what if the survey comes back clean, and it&#8217;s wrong anyway? </p><p>Self-reporting requires the respondent to know that what they did was legally significant. The team that fine-tuned a vendor model on support tickets did not experience that as a substantial modification within the meaning of Article 25(1)(b). They experienced it as making the tool better. The marketing team that put the company&#8217;s name on the interface wasn&#8217;t rebranding an AI system. They were fixing an ugly login page.</p><p>Article 25 triggers don&#8217;t feel like legal events to the people performing them. Ask people to self-report legal events, and you get a list of everything except the things you need.</p><p>The detection has to run on activity, not on memory:</p><p><strong>Expense data.</strong> Recurring charges to AI vendors, individual subscription claims, the &#8220;productivity tool&#8221; line items. Finance has this already. Legal has never asked for it.</p><p><strong>SSO and network logs.</strong> Which AI services people actually authenticate into. IT can pull the list in a day. It will be longer than your register.</p><p><strong>API traffic.</strong> A live API key to a model provider is the tell for build activity, and build activity is where provider status gets created. If a team holds an OpenAI or Anthropic key, that team is at layer two of the GPAI stack, whether it knows it or not.</p><p><strong>Procurement follow-up, not procurement records.</strong> The register captured what was bought. It didn&#8217;t capture what happened after. For every entry marked <em>deployer</em>, the question is not &#8220;did we license this&#8221; but &#8220;what has been done to it since&#8221;. Fine-tuning, configuration beyond vendor parameters, internal branding, new use cases. Each one is a potential Article 25 event that happened after the paperwork closed.</p><p>Then treat the register as a living document with named reassessment triggers: every modification, every retraining, every new use case, every contract renewal. I have already said this. What I didn&#8217;t say: the trigger list only works for systems already in the register. Everything else needs the detection layer, running continuously, because a system that skipped procurement will skip your triggers too.</p><p>One timing note. The Digital Omnibus pushed high-risk obligations for standalone Annex III systems to 2 December 2027. That reads like breathing room. For the visible register, it is. An Article 25 trigger doesn&#8217;t wait for 2027. The role shift happens when the act happens. The obligations land later. </p><p>The classification error exists now, sitting in systems you haven&#8217;t found yet.</p><div><hr></div><h2>The All-Hands Applause</h2><p>The product team finishes the Atlas demo to applause. It&#8217;s a good tool. That was never the question.</p><p>You&#8217;re running the decision tree in your head. Fine-tuned on proprietary data: possible substantial modification. Internal name and logo: possible 25(1)(a). A purpose the vendor never assessed: possible 25(1)(c). Three potential triggers, one system, zero entries in the register. And thirteen subscriptions in the expense report you haven&#8217;t looked at yet.</p><p>The register you presented was accurate. Every system on it, correctly classified. It just wasn&#8217;t an inventory of your company&#8217;s AI. It was an inventory of your company&#8217;s <em>procured</em> AI. Those are different documents, and what separates them is not a random slice of what&#8217;s out there.</p><p>It&#8217;s the systems that never crossed legal&#8217;s desk, put to uses their vendors never assessed, carrying obligations that have never been assigned.</p><p>The decision tree still works. It will classify anything you feed it.</p><p>Feeding it is the part that has to be solved.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading AI Law. Decoded.! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[The EU AI Act's Loophole With No Expiry Date]]></title><description><![CDATA[Article 111(2) of the EU AI Act decides which high-risk AI systems will never have to comply.]]></description><link>https://ailawdecoded.com/p/eu-ai-act-article-111-loophole-legacy-high-risk-ai</link><guid isPermaLink="false">https://ailawdecoded.com/p/eu-ai-act-article-111-loophole-legacy-high-risk-ai</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 01 Jul 2026 12:03:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!3JZC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab285665-697f-4608-ad90-6c5cb0e6b5ae_5760x3240.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3JZC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab285665-697f-4608-ad90-6c5cb0e6b5ae_5760x3240.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3JZC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab285665-697f-4608-ad90-6c5cb0e6b5ae_5760x3240.jpeg 424w, https://substackcdn.com/image/fetch/$s_!3JZC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab285665-697f-4608-ad90-6c5cb0e6b5ae_5760x3240.jpeg 848w, https://substackcdn.com/image/fetch/$s_!3JZC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab285665-697f-4608-ad90-6c5cb0e6b5ae_5760x3240.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!3JZC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab285665-697f-4608-ad90-6c5cb0e6b5ae_5760x3240.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3JZC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab285665-697f-4608-ad90-6c5cb0e6b5ae_5760x3240.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ab285665-697f-4608-ad90-6c5cb0e6b5ae_5760x3240.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:278476,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.com/i/202097019?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab285665-697f-4608-ad90-6c5cb0e6b5ae_5760x3240.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3JZC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab285665-697f-4608-ad90-6c5cb0e6b5ae_5760x3240.jpeg 424w, https://substackcdn.com/image/fetch/$s_!3JZC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab285665-697f-4608-ad90-6c5cb0e6b5ae_5760x3240.jpeg 848w, https://substackcdn.com/image/fetch/$s_!3JZC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab285665-697f-4608-ad90-6c5cb0e6b5ae_5760x3240.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!3JZC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab285665-697f-4608-ad90-6c5cb0e6b5ae_5760x3240.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>I was at a conference two weeks ago, listening to a presentation on the EU AI Act and its connection to GDPR, when the speaker put Article 111(2) on the screen.</p><p>I had read it before. If you&#8217;ve read the AI Act cover to cover (condolences), so have you. It lives in <a href="https://artificialintelligenceact.eu/chapter/13/">Chapter XIII Final Provisions</a>, the part of a regulation where the highlighter runs dry. Entry into force. Amendments to other regulations. Transitional arrangements. <a href="https://artificialintelligenceact.eu/article/111/">Article 111(2)</a> reads like exactly what it appears to be: a transition rule for AI systems that were already on the market before the new obligations apply.</p><p>Then he walked the room through what it does.</p><p>I sat there realizing I had filed one of the most consequential provisions in the EU AI Act under <em>administrative.</em> Judging by the quality of the silence around me, I wasn&#8217;t the only one.</p><p>Article 111(2) doesn&#8217;t give older AI systems more time to comply.</p><p>It decides which AI systems never have to.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>What the Provision Says</h2><p>The text, from the Official Journal version:</p><blockquote><p><em>&#8220;...this Regulation shall apply to operators of high-risk AI systems... that have been placed on the market or put into service before 2 August 2026, only if, as from that date, those systems are subject to significant changes in their designs. In any case, the providers and deployers of high-risk AI systems intended to be used by public authorities shall take the necessary steps to comply with the requirements and obligations of this Regulation by 2 August 2030.</em>&#8221;</p></blockquote><p>Transitional provisions normally come in two parts. Old systems get relief, and then a date arrives when the relief ends. Article 111(2) has the first part. For private-sector systems, the second part doesn&#8217;t exist.</p><p>A high-risk AI system placed on the EU market before the deadline, and never significantly redesigned afterwards, is exempt. There is no date at which that changes. The risk management system, the data governance requirements, the technical documentation, the human oversight design, the accuracy and robustness standards: none of it applies. Not late. Never.</p><p>Though, I must mention two exceptions. The <a href="https://artificialintelligenceact.eu/article/5/">Article 5</a> prohibitions apply to everything, old or new (a pre-deadline social scoring system is still illegal). And systems intended for use by public authorities must comply by August 2, 2030, modified or not. </p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;09710ba1-fd9d-4c3a-8b85-8cb35255554e&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Is My AI System High-Risk Under the EU AI Act?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-06T12:02:25.960Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!-GG3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/is-my-ai-system-high-risk-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:196305760,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>The Dates Just Moved and the Difference Grew </h2><p>The original cut-off was August 2, 2026. The Digital Omnibus on AI, provisionally agreed on May 7, 2026, moves the high-risk AI obligations to December 2, 2027 for stand-alone <a href="https://artificialintelligenceact.eu/annex/3/">Annex III</a> systems (hiring tools, credit scoring, education, life and health insurance pricing), and to August 2, 2028 for AI embedded in regulated products. The Article 111(2) cut-off moves with them. </p><p>Laura Caroli, who led the Parliament&#8217;s technical negotiations on the AI Act, put it plainly: a high-risk hiring system placed on the market before December 2, 2027 <em>&#8220;may remain outside the AI Act indefinitely, unless it is substantially altered after that date&#8221;</em>.</p><p>At the time of writing this article, the Digital Omnibus on AI isn't in the Official Journal yet. The European Parliament approved the final text on June 16, 2026; the Council's formal adoption and publication follow, before August 2. Everything here reflects the text Parliament approved in June. I'll flag anything that changes in the official version once it's published.</p><p>The Digital Omnibus on AI does one more thing to this provision, and it got a fraction of the attention the delay got. The Commission&#8217;s proposal clarifies that the exemption attaches to the <em>type</em> of system, not to each individual unit. If at least one unit of a high-risk AI system was lawfully placed on the EU market before the deadline, identical units can continue to be placed on the market afterwards, with no conformity assessment, as long as the design stays unchanged. (This clarification originated in the November 2025 proposal, and it survived: the adopted text keeps the grace period attached to the type of system, not each individual unit.)</p><p>The pool of exempt AI systems doesn&#8217;t just persist after December 2027.</p><p>It keeps growing.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;4fcca4a1-ce59-4168-9443-ee69750a21ef&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;EU AI Act Amended: The Digital Omnibus Timeline&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-13T12:02:43.130Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!DR18!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/eu-ai-act-amended-the-digital-omnibus&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:196926473,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:3,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>What This Means if You&#8217;re the One Buying</h2><p>If your company is procuring AI systems in the next 18 months, the system you sign for may never be subject to the AI Act&#8217;s requirements. Not because of a loophole your vendor found. Because of the EU AI Act&#8217;s own architecture.</p><p>Which changes what the compliance conversation in procurement is even about. <em>&#8220;We&#8217;ll be AI Act ready&#8221;</em> on the sales slide is not a compliance status. The question is no longer whether the vendor is compliant. The question is whether their system will ever be legally required to be.</p><p>And you cannot check the answer yourself. There is no public registry of when an AI system was <em>&#8220;placed on the market&#8221;</em>. The EU database for high-risk systems covers systems that register and comply, which exempt legacy systems, by definition, don&#8217;t. A vendor&#8217;s claim about their system&#8217;s legacy status is unverifiable from the outside. That moves it from due-diligence question to contractual warranty (more on that below).</p><div><hr></div><h2>What Your Vendor Is Thinking</h2><p>Every month between now and December 2027 is a strategic shipping window. Place a high-risk AI system on the EU market before the deadline and you&#8217;ve acquired an indefinite exemption. Keep the design frozen and you keep it. Under the type-based clarification, you can keep selling new copies of it too.</p><p>This is not a fringe reading. MEP Sergey Lagodinsky calls the provision <em>&#8220;a loophole&#8221; </em>and <em>&#8220;a weak spot&#8221;</em> in the law. Bram Vranken of Corporate Europe Observatory warns that companies &#8220;might abuse this timeline and quickly push risky AI systems onto the market&#8221; before the deadline, saving the compliance costs entirely. The people who built and watched over this regulation are saying, on the record, that the rational vendor strategy is to race to market and then stand very still.</p><p>None of this requires bad faith. It requires a vendor who reads the regulation and responds to incentives. </p><div><hr></div><h2>On &#8220;Significant Change&#8221;</h2><p>The exemption holds only while the system avoids <em>&#8220;significant changes in its design&#8221;</em>. So the entire question of whether a legacy system ever enters the EU AI Act collapses into one undefined phrase.</p><p>What we know: <a href="https://artificialintelligenceact.eu/recital/177/">Recital 177</a> says significant change should be understood as equivalent to <em>&#8220;substantial modification&#8221;</em> under <a href="https://artificialintelligenceact.eu/article/3/">Article 3(23)</a>. That definition covers a change not foreseen or planned in the provider&#8217;s initial conformity assessment which either affects compliance with the high-risk requirements or changes the system&#8217;s intended purpose.</p><p>Notice the problem. The test&#8217;s reference point is the initial conformity assessment. Legacy systems never had one. That&#8217;s what makes them legacy systems. The yardstick the regulation points to doesn&#8217;t exist for exactly the systems this provision governs. I think that in practice the reference point will have to be the provider&#8217;s own design documentation, which the provider writes, controls, and can draft as broadly as their lawyers dare.</p><p>The open questions are the ones your vendor will answer in their own favor. Is retraining on new data a design change? A new model version behind the same interface? Swapping the underlying foundation model while the product name stays the same? No guidance exists yet. Until it does, expect every vendor changelog to be written by someone who has read Article 111(2) very carefully.</p><div><hr></div><h2>The Trap on Your Side of the Contract</h2><p>The exemption protects the system as the vendor shipped it. It does not protect what you do to it afterwards.</p><p>If you substantially modify a high-risk AI system yourself, or change its intended purpose, <a href="https://artificialintelligenceact.eu/article/25/">Article 25(1)</a> can make <em>you</em> the provider. Not provider-ish. The provider: conformity assessment, technical documentation, CE marking, registration, all of it, for an AI system you didn&#8217;t build, possibly without the documentation you&#8217;d need to do any of it. </p><p>Buying an exempt legacy system and customizing it heavily is how a company wakes up one morning as an AI provider.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;15d3b892-36e5-4ba5-ac0d-7a9268fa92db&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Provider vs. Deployer Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-22T12:03:43.719Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!NS5L!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35f75bb-44f2-45d4-b53c-84654d8e8617_8192x5461.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/provider-vs-deployer-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:194314202,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:5,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>Six Questions Before You Sign</h2><p>The practical part. These belong in your procurement process for any AI system that is or could be high-risk, starting now.</p><ol><li><p><strong>&#8220;When was this system first placed on the EU market?&#8221;</strong></p></li></ol><p>The single most consequential question in the deal, and the sales team likely won&#8217;t know why you&#8217;re asking. Don&#8217;t accept the answer on a call. Make it a contractual warranty, with the date stated. If the vendor won&#8217;t warrant the date, that tells you something too.</p><ol start="2"><li><p><strong>&#8220;Which types of updates do you classify as design changes?</strong>&#8221;</p></li></ol><p>Their update policy decides whether the exemption survives contact with their own roadmap. Get their classification approach in writing, with an obligation to notify you before any update they consider significant, and before any update <em>you</em> might.</p><ol start="3"><li><p><strong>&#8220;If an update brings the system into scope, who carries the compliance?&#8221;</strong></p></li></ol><p>Allocate it in the contract: who performs the conformity assessment, who pays, what happens to the system in production while that takes months. Contract silence defaults to a dispute, and the dispute happens while you&#8217;re running an uncertified high-risk system live.</p><ol start="4"><li><p><strong>&#8220;Will you hand over the technical documentation if the roles shift?&#8221;</strong></p></li></ol><p>If you ever become the provider under Article 25, you need the technical file to have any chance of complying. The EU AI Act foresees cooperation from the original provider, but you don&#8217;t want to be litigating the AI Act when you could be enforcing a clause. Documentation escrow or a hard contractual handover duty.</p><ol start="5"><li><p><strong>Does your AI inventory record legacy status?</strong></p></li></ol><p>Internal question. Every high-risk system in your inventory should carry three fields: its placing-on-market date, its Article 111(2) status, and a modification log. If your inventory doesn&#8217;t have those columns, this article is your reason to add them.</p><ol start="6"><li><p><strong>Are you, or do you sell to, a public authority?</strong></p></li></ol><p>Then the indefinite exemption isn&#8217;t yours. August 2, 2030 applies regardless of modifications. Different planning, different timeline, same provision.</p><div><hr></div><p>The EU AI Act was written to make high-risk AI systems demonstrably safe: documented, overseen, accountable. For systems shipped before December 2027, it will do something else entirely. It will make them permanent.</p><p>From that date, the EU market carries two kinds of high-risk AI, identical on the demo call, separated only by a date. One is governed. One never will be but it will keep selling.</p><p>The date won&#8217;t be on the box. It will be in your contract, if you ask.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading AI Law. Decoded.! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Wrap the Model, or Fine-Tune It?]]></title><description><![CDATA[The build decision that decides what you owe under the EU AI Act.]]></description><link>https://ailawdecoded.com/p/rag-fine-tuning-eu-ai-act</link><guid isPermaLink="false">https://ailawdecoded.com/p/rag-fine-tuning-eu-ai-act</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 24 Jun 2026 12:03:20 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!DIEg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1dc66ad1-bb8b-4845-9b6a-5e4cc5107e70_4500x3000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DIEg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1dc66ad1-bb8b-4845-9b6a-5e4cc5107e70_4500x3000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DIEg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1dc66ad1-bb8b-4845-9b6a-5e4cc5107e70_4500x3000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!DIEg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1dc66ad1-bb8b-4845-9b6a-5e4cc5107e70_4500x3000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!DIEg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1dc66ad1-bb8b-4845-9b6a-5e4cc5107e70_4500x3000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!DIEg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1dc66ad1-bb8b-4845-9b6a-5e4cc5107e70_4500x3000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DIEg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1dc66ad1-bb8b-4845-9b6a-5e4cc5107e70_4500x3000.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1dc66ad1-bb8b-4845-9b6a-5e4cc5107e70_4500x3000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:256852,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.substack.com/i/202933950?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1dc66ad1-bb8b-4845-9b6a-5e4cc5107e70_4500x3000.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DIEg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1dc66ad1-bb8b-4845-9b6a-5e4cc5107e70_4500x3000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!DIEg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1dc66ad1-bb8b-4845-9b6a-5e4cc5107e70_4500x3000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!DIEg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1dc66ad1-bb8b-4845-9b6a-5e4cc5107e70_4500x3000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!DIEg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1dc66ad1-bb8b-4845-9b6a-5e4cc5107e70_4500x3000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>RAG and fine-tuning look like two ways to build the same tool. Under the EU AI Act, one of them hands you a second regulatory role the other never would. </p><p>And the choice almost always gets made before anyone decides to consult Legal.</p><p>You usually find it three weeks after the tool ships, scrolling back through the project board for something else entirely.</p><p>It&#8217;s a card from the planning sprint. The title is some internal codename people outside the team would not recognize. The description is one line, written by an engineer who has long since moved on to the next thing:</p><p><em>Approach: fine-tune the base model on our contract corpus.</em></p><p>You read it once and it means nothing. A technical note about how the contract-review tool got built, the kind of sentence you&#8217;ve trained yourself to skim, because ninety percent of what crosses the engineering channel isn&#8217;t yours to worry about.</p><p>You read it a second time and you stop, because you&#8217;ve spent the last month building the company&#8217;s EU AI Act position for this exact tool. You decided it was a deployer situation, then talked yourself into provider, then wrote three pages explaining why. And you did all of that without knowing this one line existed.</p><p>The word is <em>fine-tune</em>. Not the word you&#8217;d been assuming, which was something closer to <em>plugged the model in</em>.</p><p>And it occurs to you, sitting there with a cold coffee and a project board you opened for an unrelated reason, that you may have been answering the wrong question for a month.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>The Question You Were Being Asked</h2><p>The instinct, when someone hands you a tool built on a model like GPT or Claude, is to ask what kind of system it is. Is it high-risk? Is it a chatbot under <a href="https://artificialintelligenceact.eu/article/50/">Article 50</a>? Where does it sit in <a href="https://artificialintelligenceact.eu/annex/3/">Annex III</a>? Reasonable questions, all of them. And there&#8217;s time for all of them later.</p><p>There&#8217;s a prior question, and it&#8217;s the one the engineer&#8217;s card answered for you without asking. Not <em>what is this tool</em>, but <em>how was it built on the model underneath it</em>. Because under the EU AI Act, that single design choice decides whether your company holds one regulatory role or two.</p><p>The framing usually goes wrong from the start. People ask whether a &#8220;RAG system&#8221; is something different from &#8220;an AI system,&#8221; as though those were two products you could choose between. They aren&#8217;t the same kind of thing. </p><p><strong>&#8220;AI system for contract review&#8221;</strong> describes <em>what the tool does</em>. </p><p><strong>&#8220;RAG system&#8221;</strong> (retrieval-augmented generation) describes <em>how it&#8217;s wired together</em>. </p><p>Your contract tool is almost certainly a RAG system underneath. One word is about function. The other is about plumbing.</p><p>And the plumbing words barely appear in the regulation. </p><p><strong>&#8220;RAG&#8221;</strong> is nowhere in the AI Act. </p><p>Neither is <strong>&#8220;prompting&#8221;</strong> or <strong>&#8220;tool use&#8221;.</strong> </p><p><strong>&#8220;Fine-tuning&#8221;</strong> surfaces once, in a recital, but never as a defined operative term with obligations hung on it. </p><p>These are engineering terms, and the EU AI Act doesn&#8217;t regulate engineering patterns. It regulates two things, and names them precisely: the AI system (<a href="https://artificialintelligenceact.eu/article/3/">Article 3(1)</a>) and the general-purpose AI model (<a href="https://artificialintelligenceact.eu/article/3/">Article 3(63)</a>). The line that decides your obligations runs between those two definitions. It does not run between RAG and not-RAG, which is the comparison that feels natural and leads nowhere.</p><div><hr></div><h2>Start with the Model, Continue with the System</h2><p>Start with the model, because that&#8217;s the foundational part.</p><p>A general-purpose AI model is the engine. <em>GPT, Claude, Llama, Gemini.</em> It displays, in the regulation&#8217;s words, <strong>&#8220;significant generality&#8221;</strong> and can <strong>&#8220;competently perform a wide range of distinct tasks&#8221; </strong>(Article 3(63)). On its own, it is not an AI system, and on its own it puts no AI-system obligations on you at all.</p><p><a href="https://artificialintelligenceact.eu/recital/97/">Recital 97</a> says this in a sentence worth keeping somewhere you can find it: </p><blockquote><p>AI models <em>&#8220;do not constitute AI systems on their own&#8221;</em>, and they <em>&#8220;require the addition of further components, such as for example a user interface, to become AI systems&#8221;</em>.</p></blockquote><p> The model is the engine. It is not the car. You cannot drive it until someone builds the rest of the vehicle around it.</p><p>So the moment your team builds the contract tool, the interface, the inputs, the defined purpose of reading agreements and flagging clauses, they have built an AI system. And your company is its provider under Article 3(3): you developed it, or had it developed, and put it into service under your own name. That last part catches people, so it&#8217;s worth saying plainly. </p><p><strong>&#8220;Putting into service&#8221; </strong>includes building something purely for your own use, inside your own walls, never sold to anyone. Provider does not mean seller. If your firm built this tool to run over its own contracts and never licenses it to a soul, your firm is still the provider.</p><p>Hold onto that, because it is the part the engineer&#8217;s card did not change. Whether the team wrapped the model or fine-tuned it, your company is the provider of the AI system. That was true before you found the card and it&#8217;s true after. </p><p>The card changed something else.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;29d54e6c-aab8-4f10-b89f-472bdd939d82&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;What Is an AI System, Actually?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-08T12:03:14.634Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!Lj3S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6c33bfb-66f1-4bc7-aba6-ed6c0d1df60e_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/ai-system-definition-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193355320,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:3,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>The Real Deal: Did Anyone Touch the Weights?</h2><p>What the card changed is whether your company also reached into the model and altered it.</p><p>This is the fork, and it&#8217;s cleaner than almost any other line the AI Act draws. </p><p>On one side, you wrap the model. On the other, you modify it.</p><p><strong>Wrapping</strong> leaves the model exactly as the provider shipped it. RAG is the clearest example: you connect the model to your clause library and a decade of your old contracts, and at the moment someone asks a question, the system retrieves the relevant material and hands it to the model as context. The model answers from your documents instead of from its training data. But its weights, the actual numbers that make the model what it is, never change. The same is true of prompting, of giving the model tools it can call, of wrapping it in guardrails that check its output. All of that sits around the model. None of it gets inside.</p><p><strong>Fine-tuning</strong> gets inside. You take the model and keep training it, on your own data, until the weights shift and it starts reasoning in your patterns. That is a different act in kind, not in degree. And past a certain point, the regulation stops treating the result as &#8220;the provider&#8217;s model, configured by you&#8221; and starts treating it as a new model, with your company as its provider.</p><p>The dividing question, the one to carry into every build conversation, is not <em>&#8220;are we doing RAG&#8221;. </em></p><p>It&#8217;s whether anyone is touching the model&#8217;s weights.</p><div><hr></div><h2>The Number That Decides It Isn&#8217;t in the EU AI Act</h2><p>The threshold that separates <em>&#8220;you modified the provider&#8217;s model&#8221;</em> from <em>&#8220;you built a new model&#8221;</em> does not appear in the AI Act. It lives in the <a href="https://digital-strategy.ec.europa.eu/en/library/guidelines-scope-obligations-providers-general-purpose-ai-models-under-ai-act">European Commission&#8217;s Guidelines for providers of general-purpose AI models</a>, published 18 July 2025. Guidelines, not regulation. Non-binding guidance interpreting the text. A lawyer who reads the whole EU AI Act cover to cover and stops there will never find this number, which is a strange thing to be able to say about the single line that decides whether you&#8217;ve taken on an entire chapter of obligations.</p><p>The legal trigger is a significant change in the model&#8217;s generality, capabilities, or systemic risk. That phrase is hard to measure, so the guidance offers a number you can actually work with: </p><blockquote><p><em>if the compute used to fine-tune the model exceeds one-third of the compute used to train the original, treat the result as a significant change, the modified version as a new model, and the entity that fine-tuned it as a provider that may become responsible for it. </em></p></blockquote><p>An indicative proxy, not a bright line in the text. Where you don&#8217;t know the original training compute, which is most of the time, the guidance gives a fallback: </p><blockquote><p><em>one-third of 10&#178;&#179; floating-point operations, the same threshold that brings a model into scope as a general-purpose model in the first place.</em></p></blockquote><p>Now the reassuring part, before anyone panics. Almost no downstream fine-tuning comes anywhere near one-third of the compute that trained a frontier model. Training GPT-class models costs sums the majority of companies will never spend on anything, let alone on adjusting one. So the realistic outcome for the vast majority of teams fine-tuning a commercial or open model is that they do not become model providers. The threshold matters less as a trap people are constantly springing, and more as proof of where the real boundary sits: at the model, not at the technique. Fine-tuning is simply the most common way to walk up to that boundary.</p><p>And if you do cross it, <a href="https://artificialintelligenceact.eu/recital/109/">Recital 109 </a>softens the landing in a way that rarely survives into the law-firm summaries. Your obligations as the modifier are limited to the modification. You complement the existing technical documentation with information about what you changed. Your training-data summary and your copyright policy cover only the data and compute you added. You do not inherit the documentation burden for the entire original model, which you couldn&#8217;t produce anyway, because you didn&#8217;t train it. </p><p>That&#8217;s my reading of how 109 operates, and it&#8217;s the reading the guidance supports, though I&#8217;d want to see how the AI Office applies it before treating it as settled.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;48039a0d-45e1-4eb4-95f7-8bbadbc8f31c&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;What Did You Turn the Model Into?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null},{&quot;id&quot;:316763299,&quot;name&quot;:&quot;John Holman&quot;,&quot;bio&quot;:&quot;Awakened-Intelligence.com | AiValuations.org | AI systems architect &amp; MI researcher. We build research infrastructure including automated pipelines, model agnostic coherent continuity containers, fully deployed Ai evaluation frameworks. &quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/643a857c-5bf4-4bfa-8799-c84a4fd20774_960x958.png&quot;,&quot;is_guest&quot;:true,&quot;bestseller_tier&quot;:null,&quot;primaryPublicationSubscribeUrl&quot;:&quot;https://awakenedintelligence.substack.com/subscribe?&quot;,&quot;primaryPublicationUrl&quot;:&quot;https://awakenedintelligence.substack.com&quot;,&quot;primaryPublicationName&quot;:&quot;John Holman&quot;,&quot;primaryPublicationId&quot;:4323125}],&quot;post_date&quot;:&quot;2026-05-20T12:01:50.912Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!YPi-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe843f814-d2c0-4326-aaa9-a86f278556b5_3840x2160.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/what-did-you-turn-the-model-into&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:197544242,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:6,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>Roles Stack. They Don&#8217;t Swap.</h2><p>One thing I&#8217;d want a product team to understand even if they understood nothing else.</p><p>The fine-tune decision did not move your company out of one box and into another. It added a box.</p><p>Wrap the model, and you hold one role: provider of an AI system. Fine-tune past the threshold, and you hold two: provider of that same AI system, and, on top of it, provider of a general-purpose AI model. Not instead of. As well as. You were always the system provider the moment you built the tool, and nothing about modifying the model relieves you of that. It just stacks a second regulatory identity on top of the first.</p><p>And the second identity is its own job, with its own chapter. <a href="https://artificialintelligenceact.eu/chapter/5/">Chapter V</a> brings obligations that have nothing to do with the contract tool sitting on top and everything to do with the model itself: technical documentation drawn up to the standard of <a href="https://artificialintelligenceact.eu/annex/11/">Annex XI</a>, a duty to give downstream builders the information they need to comply with their own obligations (<a href="https://artificialintelligenceact.eu/article/53/">Article 53(1)(b)</a>), a policy for complying with EU copyright law including the text-and-data-mining opt-out, and a publicly available summary of what the model was trained on, using the template the AI Office provides. </p><p>Push the modified model past 10&#178;&#8309; floating-point operations, into systemic-risk territory under <a href="https://artificialintelligenceact.eu/article/51/">Article 51</a>, and the <a href="https://artificialintelligenceact.eu/article/55/">Article 55</a> obligations follow: model evaluations, adversarial testing, serious-incident reporting, cybersecurity measures. Downstream fine-tuners will essentially never hit that ceiling. But the first set of obligations lands the day you become a model provider, and it lands in addition to everything you already carried as the provider of the system.</p><p>One regulatory role, or two. Decided by a line on a sprint card, by people who were choosing, as far as they knew, between two equally good ways to make the tool work better.</p><div><hr></div><h2>Where This Gets Murky</h2><p>The wrap-versus-modify line is clean. </p><p>The threshold sitting on it is not, and honesty about that is the difference between guidance you can trust and guidance that gets you in trouble.</p><p>The one-third figure is indicative. It&#8217;s a compute ratio offered in non-binding guidance, and the fallback (one-third of 10&#178;&#179; FLOP, when you don&#8217;t know the base model&#8217;s training compute) was never meant to be a precise instrument. </p><p>A team fine-tuning close to the line, or building on a model whose training compute the provider has never disclosed, is working with an approximation. The direction is reliable: wrapping is safe, heavy modification is not. The exact boundary is soft, and the guidance may be revised. If you&#8217;re near it, that&#8217;s a <em>&#8220;document your reasoning and watch for updates&#8221;</em> situation, not a <em>&#8220;we did the math, we&#8217;re fine&#8221;</em> situation.</p><p>Two more things that get conflated and shouldn&#8217;t.</p><p>RAG keeps you out of model-provider territory, but it does not keep you out of trouble generally. Point a retrieval system at personal data, privileged material, or confidential client contracts, and you&#8217;ve created a GDPR and confidentiality problem that has nothing to do with the EU AI Act and everything to do with whether you should be shipping the thing at all. </p><p><em>&#8220;We only did RAG, not fine-tuning&#8221; </em>answers the question about your role under the EU AI Act. It does not answer the question about data protection, and the second question is often the one that bites first.</p><p>And fine-tuning below the threshold, while it doesn&#8217;t make you a model provider, still changes the system you provide. If that behavioral shift affects accuracy or bias in a deployment that is high-risk, it&#8217;s squarely relevant to your obligations as the <strong>system</strong> provider, under the data-governance and accuracy requirements in Articles <a href="https://artificialintelligenceact.eu/article/10/">10</a> and <a href="https://artificialintelligenceact.eu/article/15/">15</a>. </p><p>The threshold answers one question. It doesn&#8217;t answer all of them.</p><div><hr></div><h2>One Caveat About the Contract Tool Itself</h2><p>So the example doesn&#8217;t mislead anyone: plain commercial contract review, a tool a company runs over its own agreements, is not high-risk under the EU AI Act. It isn&#8217;t listed in Annex III. The provider obligations that attach to it are light: transparency where Article 50 applies, AI literacy under <a href="https://artificialintelligenceact.eu/article/4/">Article 4</a>, not a great deal beyond that.</p><p>That picture changes the moment the tool starts feeding decisions the AI Act cares about. Use it to screen job candidates and it falls into employment. Use it on behalf of a court to interpret and apply the law and it falls into the administration of justice (The trigger there is use by or for a judicial authority. The same tool run purely inside your own business isn&#8217;t caught). Use it to inform creditworthiness or insurance pricing and it falls into access to essential services. </p><p>All three are Annex III, all three are high-risk, and all three pull the full <a href="https://artificialintelligenceact.eu/chapter/3/">Chapter III</a> provider regime down on top of everything else. And if the tool profiles individuals, the off-ramp in <a href="https://artificialintelligenceact.eu/article/6/">Article 6(3)</a>, the one that lets you argue an Annex III system isn&#8217;t really high-risk, closes on you.</p><p>The risk question and the role question are separate, and both worth running. But the build point holds at every risk level: wrapping keeps you a system provider, and fine-tuning past the line makes you a model provider too. </p><p>High-risk or not, that&#8217;s still true.</p><div><hr></div><h2>The Question to Ask Before Anyone Writes Code</h2><p>It isn&#8217;t <em>&#8220;is this high-risk&#8221;</em>. </p><p>That one comes later, and someone will eventually ask it, probably loudly, probably close to a deadline. </p><p>The question that gets skipped is the one the sprint card answered while you weren&#8217;t looking:</p><blockquote><p><em>Are we touching the model, or wrapping it?</em></p></blockquote><p>That single answer routes everything downstream of it. Wrap, and your compliance work tracks the system you built, and only that. Modify past the threshold, and you&#8217;ve acquired a second regulatory identity that needs its own documentation, on a clock that starts the day you ship, not the day you notice. </p><p>The question costs nothing to ask in a design review. It costs a great deal to answer in an audit, when the honest answer turns out to be &#8220;we touched it&#8221;, and the follow-up is &#8220;and who wrote that down&#8221;.</p><p>Put it in the AI inventory you should already be keeping. For every system built on someone else&#8217;s model, record one more field next to the role and the risk level: wrapped, or modified. Then set the trigger that matters, because this is the field most likely to change without anyone telling you. </p><p>The day someone decides to retrain, you reassess. Not the day you find the card. The card is still there, one line, an engineer&#8217;s shorthand for a decision that felt purely technical to everyone who touched it.</p><p><em>Approach: fine-tune the base model on our contract corpus.</em></p><p>You&#8217;d written three pages on what your company was under the EU AI Act. You&#8217;re now fairly sure it was a different number of pages than the company actually needed. And the thing that decided that wasn&#8217;t a lawyer, or a regulator, or a clause buried on page four hundred of the AI Act.</p><p>It was a sprint card. And no one thought of sending it to you.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading AI Law. Decoded.! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Fable 5 Was Live for Three Days. Then the US Switched It Off.]]></title><description><![CDATA[What that means for every EU company that built on someone else's model.]]></description><link>https://ailawdecoded.com/p/fable-5-and-the-eu-ai-act</link><guid isPermaLink="false">https://ailawdecoded.com/p/fable-5-and-the-eu-ai-act</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 17 Jun 2026 12:03:53 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!TWhA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fe5c3c-37e1-4157-90d2-5f52489f68d2_6000x4000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TWhA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fe5c3c-37e1-4157-90d2-5f52489f68d2_6000x4000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TWhA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fe5c3c-37e1-4157-90d2-5f52489f68d2_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!TWhA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fe5c3c-37e1-4157-90d2-5f52489f68d2_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!TWhA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fe5c3c-37e1-4157-90d2-5f52489f68d2_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!TWhA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fe5c3c-37e1-4157-90d2-5f52489f68d2_6000x4000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TWhA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fe5c3c-37e1-4157-90d2-5f52489f68d2_6000x4000.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e7fe5c3c-37e1-4157-90d2-5f52489f68d2_6000x4000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:656379,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.substack.com/i/201979952?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fe5c3c-37e1-4157-90d2-5f52489f68d2_6000x4000.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TWhA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fe5c3c-37e1-4157-90d2-5f52489f68d2_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!TWhA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fe5c3c-37e1-4157-90d2-5f52489f68d2_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!TWhA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fe5c3c-37e1-4157-90d2-5f52489f68d2_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!TWhA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fe5c3c-37e1-4157-90d2-5f52489f68d2_6000x4000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>You chose the model carefully.</p><p>You read the documentation. You checked the provider had an EU representative. You logged it in your AI inventory, mapped it to the right obligations, maybe ran a DPIA. </p><p>You did the diligence. Then you built it in: the model now sits inside a product, or a workflow, or a process a few hundred people rely on without thinking about it.</p><p>On Friday evening it stopped existing.</p><p>On June 12, at 5:21pm Eastern time, the <a href="https://www.anthropic.com/news/fable-mythos-access">US government ordered Anthropic to cut off access to its two most capable models</a>, Fable 5 and Mythos 5, for any foreign national. Inside the US or outside it. Including Anthropic&#8217;s own foreign-national staff. Anthropic couldn&#8217;t separate the foreign users from everyone else fast enough to comply selectively, so it did the only thing that guaranteed compliance: it switched both models off for every customer on earth. Fable 5 had been publicly available for three days.</p><p>Somewhere in the EU, a company that built on Fable woke up to a product that no longer worked, and a question its compliance file did not answer.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>What the EU AI Act Promised You</h2><p>The EU AI Act has a great deal to say about a general-purpose AI provider, and almost all of it is reassuring.</p><p><a href="https://artificialintelligenceact.eu/chapter/5/">Chapter V</a> is the part that governs models like Fable and Mythos. Under <a href="https://artificialintelligenceact.eu/article/53/">Article 53</a>, the provider has to write and maintain technical documentation, and hand downstream users a package covering what the model is, what it can do, and how to integrate it.</p><p>Ask for more than that, and the picture gets softer. You will often hear that the provider has fourteen days to answer. The number is real, but it isn&#8217;t in Article 53. It comes from <a href="https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai">the General-Purpose AI Code of Practice</a>, which is voluntary. The Code binds only the providers who signed it, and even then the promise is only to respond <em>&#8220;within a reasonable timeframe, and no later than 14 days&#8221;,</em> save for exceptional circumstances. Article 53 obliges the provider to make the information available. It sets no deadline at all.</p><p>Under <a href="https://artificialintelligenceact.eu/article/54/">Article 54</a>, a provider based outside the EU has to appoint an authorised representative inside it. And because a frontier model of this size crosses the systemic-risk threshold in <a href="https://artificialintelligenceact.eu/article/51/">Article 51</a> (training compute above 10^25 floating-point operations creates a presumption of systemic risk), <a href="https://artificialintelligenceact.eu/article/55/">Article 55</a> piles on more: adversarial testing, systemic-risk assessment, serious-incident reporting to the AI Office, cybersecurity for the model and its infrastructure.</p><p>It is a serious set of obligations. Read them as a group and a pattern shows up.</p><p>Document. Disclose. Evaluate. Mitigate. Report. Secure. Appoint a representative.</p><p>Every one of them is about the provider&#8217;s conduct. Each answers a version of the same question: </p><blockquote><p><em>Is the provider behaving responsibly toward the people downstream and toward the regulator? </em></p></blockquote><p>It is a regime built to make the provider accountable, and on its own terms it does that well.</p><p>None of it answers the question the EU company actually had on Friday.</p><p>Will the model still be there tomorrow.</p><div><hr></div><h2>The Obligation That Isn&#8217;t There</h2><p>There is no continuity duty in Chapter V. </p><p>No obligation to keep the model available. No notice period before withdrawal. No requirement to warn downstream users that access is about to disappear, and certainly nothing about what happens when a government orders the lights off. </p><p>The EU AI Act built an elaborate structure of accountability around the provider and assumed, without ever saying so, that the provider would stay a stable, willing counterparty. Availability was never in question.</p><p>That assumption is the soft spot, and Fable walked straight into it.</p><p>The regulation spent its effort making the provider answerable to you and to the AI Office. </p><p>Last week&#8217;s events answered a question the regulation never asked: </p><blockquote><p><em>Who is the provider answerable to first? </em></p></blockquote><p>Within hours of a government letter, a commercial model serving hundreds of millions of people went dark, worldwide, and not one line of Chapter V slowed it down. The documentation package didn&#8217;t help. The fourteen-day response window didn&#8217;t help. The authorised representative had nothing to represent. The incident-reporting channel to the AI Office runs the wrong way for this: it tells Brussels what happened, after it happened.</p><p>The provider answers to its own government first. Everything the EU AI Act guarantees sits downstream of that fact.</p><div><hr></div><h2>Switching Is the Easy Part</h2><p>The obvious response is to move to another model, and often that&#8217;s genuinely easy. </p><p>Fable 5 and Opus 4.8 are both Anthropic. Same API, same SDK. You change the model name and you&#8217;re running again, possibly the same afternoon. The directive named specific models and left every other Anthropic model untouched, so Opus stayed up the whole time. For a lot of companies, the fallback was a one-line change.</p><p>Notice why it was available, though. Opus stayed up because Washington drew the line at Fable and Mythos, not because you arranged it that way. The scope of the order was the government&#8217;s choice, not yours. A one-line fallback works right up until the next letter names the provider instead of two models, and then the model you&#8217;d switch to is dark as well.</p><p>The easy path also narrows fast once the deployment is real. Move to a different company&#8217;s model and the prompts, the behaviour, and the evaluation results all have to be redone. Fine-tune a model and the tuning doesn&#8217;t travel. You retrain. Run the model somewhere regulated or safety-relevant, and the code change is the smallest part of the job. You tested, documented, and signed off on a specific model. Swapping it can mean re-running evaluations and rewriting documentation before the replacement is allowed to ship.</p><p>The model string changes in a minute. The revalidation doesn&#8217;t.</p><p>So it isn&#8217;t that you&#8217;re stranded. It&#8217;s that switching is often trivial and still doesn&#8217;t cover you, because the part you don&#8217;t control is the part that matters: not how hard the swap is, but how wide the next order reaches. </p><p><em>&#8220;Switch to Opus 4.8&#8221; </em>answers what happened on Friday. It says nothing about the day the order doesn&#8217;t stop at one model.</p><div><hr></div><h2>DORA Saw This Coming</h2><p>There is one corner of EU law that treats the availability of a third-party service as a regulated risk rather than an operational detail. It&#8217;s DORA, <a href="https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng">the Digital Operational Resilience Act</a>, which is in force since January 2025. </p><p>DORA makes financial firms keep documented exit plans (<a href="https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng#art_28">Article 28(8)</a>) and assess concentration risk, including whether a realistic substitute for a critical provider actually exists (<a href="https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng#art_29">Article 29</a>). If you are a bank or an insurer, you already have the muscle to ask the Fable question, because the law made you build it.</p><p>If you are anything else, you don&#8217;t.</p><p>DORA covers roughly twenty categories of financial entities. A hospital running a triage tool on a frontier model is not covered. Nor is a manufacturer, a software company, a university, a public authority. They get the EU AI Act&#8217;s safety and transparency guarantees but no continuity guarantee at all. The one EU rule that would have made them plan for a sudden provider shutdown simply doesn&#8217;t apply to them.</p><p>Even DORA is a smaller shield than it looks. The risks it imagines are outages, cyberattacks, insolvency: the ordinary ways a vendor fails. A foreign government switching the product off on a Friday isn&#8217;t in that taxonomy, and no standard force-majeure clause contemplates it either.</p><p>Worse, DORA&#8217;s designated critical providers are the big clouds: AWS, Google Cloud, Microsoft. Most EU firms reach Anthropic&#8217;s models through exactly those clouds. The cloud is on the register. But last week none of the clouds went down. The model did, pulled clean off the top of infrastructure that kept humming the whole time.</p><p>The dependency that actually failed sits one floor below where even the careful firms were looking.</p><div><hr></div><h2>What to Take From This</h2><p>A few things worth doing before this stops being news.</p><p>1. <strong>Put the model on your register</strong> <strong>as its own dependency</strong>, separate from the cloud it runs on. If your third-party inventory stops at <em>AWS</em>, it does not describe what you&#8217;re actually exposed to.</p><p>2. <strong>Ask the DORA question whether or not DORA applies to you</strong>. If this specific model went dark tomorrow with no notice, what runs in its place, and how long until it does? Name a second model. Cost out the switch honestly. That number is your real exposure.</p><p>3. <strong>Know your own role, because it sets your own obligations.</strong> If you build the model into a system you put on the market, you&#8217;re a downstream provider with duties of your own and a right to the provider&#8217;s <a href="https://artificialintelligenceact.eu/annex/12/">Annex XII </a>documentation. If you only use it, you&#8217;re probably a deployer. The distinction matters a lot.</p><p>4. <strong>And read the EU AI Act for what it is.</strong> It makes your provider document, disclose, test, and report. It is a real set of protections and it is worth understanding. It just never promised the one thing you needed last week, and it is better to know that up front.</p><p>The compliance file you built was honest work. It described a provider doing everything the law requires: documented, transparent, tested, supervised. All of it true, and none of it load-bearing, because the model's availability wasn&#8217;t the provider's promise to give. It belonged to a government you have no standing in front of, under an authority no one disclosed, exercised in one afternoon. </p><p>You can hold a provider to account for how a model behaves. You cannot hold one to account for being switched off by someone else.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading AI Law. Decoded.! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[What's Your Role Under the EU AI Act? Practical Decision Tree.]]></title><description><![CDATA[Provider. Deployer. Importer. Distributor. Authorized Representative.]]></description><link>https://ailawdecoded.com/p/your-role-under-the-eu-ai-act-guide</link><guid isPermaLink="false">https://ailawdecoded.com/p/your-role-under-the-eu-ai-act-guide</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 10 Jun 2026 12:03:27 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Bh5p!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Bh5p!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Bh5p!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Bh5p!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Bh5p!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Bh5p!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Bh5p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:829816,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.substack.com/i/199877647?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Bh5p!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Bh5p!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Bh5p!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Bh5p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>You&#8217;re in a meeting room with six people who&#8217;d rather be somewhere else. The subject line said &#8220;AI Act &#8212; Role Classification Workshop.&#8221; Two hours, blocked calendars, mandatory attendance. The energy is exactly what you&#8217;d expect.</p><p>You&#8217;ve got a shared spreadsheet on the screen. Every AI system the company uses, fourteen of them as of last Thursday&#8217;s count. You&#8217;re working through them one at a time. Column D says &#8220;Our Role Under the EU AI Act&#8221;. You type <em>deployer</em> for the first one. A vendor&#8217;s analytics tool. Easy. <em>Deployer</em> for the second, a customer service chatbot from a SaaS platform. <em>Deployer</em> for the third. You&#8217;re making good progress. Maybe this won&#8217;t take two hours.</p><p>Then the head of data science mentions, casually, like it&#8217;s obvious, that his team has been fine-tuning one of the vendor models on the company&#8217;s proprietary data for the past six months. &#8220;Same tool, just trained on our stuff.&#8221; You stop typing.</p><p>Someone from marketing adds that they rebranded the vendor&#8217;s customer-facing interface. The company&#8217;s logo, the company&#8217;s name, the company&#8217;s colour scheme. &#8220;It just looked better.&#8221; You look at column D.</p><p>Then the colleague from the EU subsidiary, the one who joined the call from Frankfurt, asks a question you weren&#8217;t expecting: &#8220;We&#8217;re the ones who brought the US vendor&#8217;s system into Europe. Does that make us the importer?&#8221;</p><p>Your clean column of <em>deployer, deployer, deployer</em> now has three question marks. And you&#8217;re not even halfway through the list.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>The Question Before All Other Questions</h2><p>The EU AI Act has a lot of moving parts: risk classification, conformity assessment, prohibited practices, transparency obligations, deadlines that keep shifting. But before any of that matters, there&#8217;s a prior question:</p><blockquote><p><em>What are you?</em></p></blockquote><p>Your role determines your obligations. A deployer&#8217;s life fits on one page: operational duties, human oversight, inform people when AI is making decisions about them. A provider&#8217;s life is a different job entirely. Quality management system. Technical documentation. Conformity assessment. CE marking. Post-market monitoring. Incident reporting. The difference between the two isn&#8217;t negligible. </p><p>And unlike GDPR, where both controllers and processors carry real obligations, the EU AI Act creates a sharp asymmetry. Getting your role wrong means either over-investing in obligations you don&#8217;t have, or not meeting obligations you do. Neither is free.</p><p>The regulation defines five roles. Many commentaries cover only two. This piece covers all five and gives you a way to assign them.</p><p><em>If you&#8217;re not sure whether the EU AI Act applies to your company at all, especially if you&#8217;re outside the EU, that question comes before this one.</em></p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;cd5d9c5c-f86f-4f5b-a3c9-0fdfc49927c6&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Why the EU AI Act Matters Even If You're Not in the EU&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-05T13:54:22.853Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!wrLn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb08944ca-a6dd-44b0-a118-8176d76942bc_4500x3000.heic&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/eu-ai-act-applies-outside-eu&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193044187,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>The Five Roles: </h2><h3>1. Provider &#8212; <a href="https://artificialintelligenceact.eu/article/3/">Article 3(3)</a></h3><p>A person or entity that develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark. Whether for payment or free of charge.</p><p>Two elements, both required. First: you developed it, or you had someone develop it for you. Second: your name is on it. Miss either element and the definition doesn&#8217;t apply.</p><p>The part that catches companies: <em>&#8220;puts it into service&#8221; </em><strong>includes internal use</strong>. A company that builds an AI system for its own operations, not selling it, not licensing it, is a provider. It developed the system and put it into service under its own name. The fact that it never left the building doesn&#8217;t matter. </p><p>&#8220;Provider&#8221; doesn&#8217;t mean &#8220;seller&#8221;.</p><h3>2. Deployer &#8212; <a href="https://artificialintelligenceact.eu/article/3/">Article 3(4)</a></h3><p>A person or entity using an AI system under its authority, except for personal non-professional use.</p><p>The simplest definition and the most common role. You bought or licensed an AI system. You use it in your business. You didn&#8217;t build it. You didn&#8217;t put your name on it. Deployer.</p><p><em>&#8220;Under its authority&#8221;</em> means the company controls the deployment, not the individual employee who clicks the button. The company is the deployer. The employee is the user. This matters because deployer obligations (monitoring, human oversight, informing affected people) attach to the entity with operational control.</p><p>However, the risk here is that this role can change without you noticing. Rebrand the system, substantially modify it, or repurpose it into a high-risk use case, and <a href="https://artificialintelligenceact.eu/article/25/">Article 25</a> transforms you into a provider. No grace period. No transition window. The moment it happens, provider obligations apply.</p><p><em>For the deep dive on when a deployer becomes a provider, including the substantial modification analysis and what &#8220;foreseen in the conformity assessment&#8221; actually requires, see the separate piece:</em></p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;fc7d8a79-1ed1-4392-b434-d471d33d0b69&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Provider vs. Deployer Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-22T12:03:43.719Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!NS5L!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35f75bb-44f2-45d4-b53c-84654d8e8617_8192x5461.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/provider-vs-deployer-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:194314202,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:5,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h3>3. Importer &#8212; <a href="https://artificialintelligenceact.eu/article/3/">Article 3(6)</a></h3><p>An EU-based entity that places a non-EU provider&#8217;s AI system on the Union market, where the system bears the non-EU provider&#8217;s name or trademark.</p><p>The importer is the compliance gatekeeper at the EU border. They don&#8217;t need to understand the system&#8217;s internals the way the provider does. They need to verify that the paperwork is in order: conformity assessment done, technical documentation marked down, CE marking affixed, authorized representative appointed (<a href="https://artificialintelligenceact.eu/article/23/">Article 23</a>).</p><p>Two things make this role less straightforward than it sounds: </p><p><strong>First: </strong>it was designed for physical supply chains. Products crossing borders, intermediaries handling goods. For cloud-based AI systems delivered as SaaS, the concept of <em>&#8220;placing on the market&#8221;</em> doesn&#8217;t map cleanly. If a US company offers an AI system directly to EU customers through its website, with no intermediary, there&#8217;s no importer. The US company is the provider, subject to the regulation through its mandatory authorized representative.</p><p><strong>Second: </strong>if the importer puts its own name on the system instead of the non-EU provider&#8217;s, that&#8217;s rebranding. Article 25(1)(a) kicks in. The importer becomes the provider. Congratulations on your new compliance obligations.</p><h3>4. Distributor &#8212; <a href="https://artificialintelligenceact.eu/article/3/">Article 3(7)</a></h3><p>An entity in the supply chain, other than the provider or the importer, that makes an AI system available on the Union market.</p><p>The lightest role. A tech reseller. A value-added reseller bundling an AI system with other services. A retailer stocking AI-enabled devices. The distributor&#8217;s job is verification: check the CE marking, check the conformity documentation, don&#8217;t distribute non-compliant systems, report problems up the chain (<a href="https://artificialintelligenceact.eu/article/24/">Article 24</a>).</p><p>The <em>&#8220;value-added&#8221;</em> part of value-added reseller is where the role gets fragile. If the value you&#8217;re adding involves modifying the system, training it on custom data, or rebranding it, you may have crossed from distributor into provider territory. Article 25 applies to distributors too. </p><p>The lightest role in the regulation turns out to have a trapdoor.</p><h3>5. Authorized representative &#8212; Articles <a href="https://artificialintelligenceact.eu/article/22/">22</a> and <a href="https://artificialintelligenceact.eu/article/54/">54</a></h3><p>An EU-based entity appointed by a non-EU provider, through a written mandate, to perform certain compliance obligations on the provider&#8217;s behalf.</p><p>This isn&#8217;t an optional service. Non-EU providers of high-risk AI systems must appoint one before making their systems available in the EU (<a href="https://artificialintelligenceact.eu/article/22/">Article 22</a>). Non-EU providers of general-purpose AI models must do the same (<a href="https://artificialintelligenceact.eu/article/54/">Article 54</a>).</p><p>Three things about this role that aren&#8217;t obvious:</p><ul><li><p>The authorized representative can be fined. They qualify as an <em>&#8220;operator&#8221;</em> under Article 3(8). The same penalties that apply to providers (up to &#8364;15 million or 3% of global annual turnover) apply to them. This is not a paperwork role. It&#8217;s a liability position.</p></li><li><p>The authorized representative must blow the whistle on its own client. Article 22(4): if the representative considers or has reason to consider the provider is acting contrary to its AI Act obligations, it must terminate the mandate and immediately inform market surveillance authorities. Not <em>may</em>. Must. The regulation built a compliance-cop function into what looks like a commercial relationship.</p></li><li><p>And for GPAI models, the representative&#8217;s exposure extends beyond the model itself. They must cooperate with authorities investigating downstream AI systems that integrated the GPAI model, even though their mandate comes from the model provider, not the system provider.</p></li></ul><p>Who needs to think about this role? </p><ul><li><p>Non-EU companies selling high-risk AI into the EU (they need to appoint one),</p></li><li><p>EU-based companies buying from non-EU providers (importers must verify one exists under Article 23(1)(d)), and </p></li><li><p>EU entities considering serving as authorized representatives (they need to understand the liability before they sign).</p></li></ul><div><hr></div><h2>The Decision Tree</h2><p>To decide on your company&#8217;s role, for each AI system your company touches (not once per company, once per system) walk through these steps:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dex0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f1bbc5-2905-4a15-959e-283a05d59c8e_1440x1960.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dex0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f1bbc5-2905-4a15-959e-283a05d59c8e_1440x1960.png 424w, https://substackcdn.com/image/fetch/$s_!dex0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f1bbc5-2905-4a15-959e-283a05d59c8e_1440x1960.png 848w, https://substackcdn.com/image/fetch/$s_!dex0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f1bbc5-2905-4a15-959e-283a05d59c8e_1440x1960.png 1272w, https://substackcdn.com/image/fetch/$s_!dex0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f1bbc5-2905-4a15-959e-283a05d59c8e_1440x1960.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dex0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f1bbc5-2905-4a15-959e-283a05d59c8e_1440x1960.png" width="1440" height="1960" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/10f1bbc5-2905-4a15-959e-283a05d59c8e_1440x1960.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1960,&quot;width&quot;:1440,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:160857,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.substack.com/i/199877647?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f1bbc5-2905-4a15-959e-283a05d59c8e_1440x1960.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dex0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f1bbc5-2905-4a15-959e-283a05d59c8e_1440x1960.png 424w, https://substackcdn.com/image/fetch/$s_!dex0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f1bbc5-2905-4a15-959e-283a05d59c8e_1440x1960.png 848w, https://substackcdn.com/image/fetch/$s_!dex0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f1bbc5-2905-4a15-959e-283a05d59c8e_1440x1960.png 1272w, https://substackcdn.com/image/fetch/$s_!dex0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f1bbc5-2905-4a15-959e-283a05d59c8e_1440x1960.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Step 1: Did you develop (or have developed) the AI system?</h3><p><strong>YES, </strong><em><strong>and</strong></em><strong> </strong>your name or trademark is on it? <strong>You are a provider.</strong> Full provider obligations apply under Articles 16-21. This includes internal use. If you built it for your own operations, you&#8217;re <em>&#8220;putting it into service&#8221;</em> under your own name, which is one of the two paths to provider status alongside <em>&#8220;placing on the market&#8221;.</em></p><p><strong>YES, </strong><em><strong>but</strong></em><strong> </strong>someone else&#8217;s name is on it? The entity branding it is likely the provider. <strong>You&#8217;re a development contractor.</strong> Your obligations should be governed by a written agreement (Article 25(3)), but you&#8217;re not the provider under the regulation.</p><p><strong>NO:</strong> go to Step 2.</p><h3>Step 2: Are you using an AI system under your authority for business purposes?</h3><p><strong>YES:</strong><em><strong> </strong>provisionally,</em> <strong>you&#8217;re a</strong> <strong>deployer</strong>. But before you stop here, check the <a href="https://artificialintelligenceact.eu/article/25/">Article 25 </a>triggers:</p><ol><li><p><strong>Have you put your name or trademark on a high-risk AI system that was already on the market?</strong> If so, you&#8217;re now a provider under Article 25(1)(a).</p></li><li><p><strong>Have you made a substantial modification to a high-risk AI system?</strong> A modification not foreseen in the original conformity assessment that affects compliance or changes the intended purpose? You&#8217;re a provider under Article 25(1)(b). If you&#8217;re not sure whether your modification qualifies (and this is the hardest question in the entire regulation) the <em><a href="https://ailawdecoded.substack.com/p/provider-vs-deployer-eu-ai-act">Provider vs. Deployer article</a></em> covers the analysis in detail. The short version: if you&#8217;ve changed the model architecture, modified decision logic beyond vendor-specified parameters, or used the system for a purpose the vendor didn&#8217;t assess, treat yourself as a provider until you can confirm otherwise.</p></li><li><p><strong>Have you changed the intended purpose of an AI system so that it now falls into a high-risk category?</strong> If so, you&#8217;re a provider under Article 25(1)(c). No code change required. Just a different use case.</p></li></ol><p>None of the above? <strong>You&#8217;re a deployer.</strong> <a href="https://artificialintelligenceact.eu/article/26/">Article 26</a> obligations apply.</p><p><strong>NO:</strong> go to Step 4.</p><h3>Step 3: Are you in the supply chain?</h3><p><strong>YES </strong><em><strong>and</strong></em><strong> </strong>you are<strong> </strong>first EU-based entity placing a non-EU provider&#8217;s system on the market (under the non-EU provider&#8217;s name)?<strong> You&#8217;re an</strong> <strong>importer</strong>. Obligations under <a href="https://artificialintelligenceact.eu/article/23/">Article 23</a> apply to you.</p><p><strong>YES </strong><em><strong>but</strong></em><strong> </strong>another entity in the supply chain making it available? <strong>You&#8217;re a</strong> <strong>distributor</strong>. Obligations under <a href="https://artificialintelligenceact.eu/article/24/">Article 24</a> apply to you.</p><p><strong>NO:</strong> go to Step 4.</p><h3>Step 4: Are you a non-EU provider?</h3><p><strong>YES:</strong> You must appoint an <strong>authorized representative</strong> in the EU. Obligations under Articles <a href="https://artificialintelligenceact.eu/article/22/">22</a> or <a href="https://artificialintelligenceact.eu/article/54/">54</a> apply to you, depending on whether you are providing a high-risk AI system or GPAI model.</p><p><strong>NO: </strong>None of the above? Check <a href="https://artificialintelligenceact.eu/article/2/">Article 2.</a> You might be outside the scope entirely. Personal non-professional use is excluded. Research, testing, and development before market placement or putting into service are excluded. Systems for exclusively military purposes are excluded.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;9304926e-664f-4777-b3ab-5a258bbf29f8&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;What Is an AI System, Actually?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-08T12:03:14.634Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!Lj3S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6c33bfb-66f1-4bc7-aba6-ed6c0d1df60e_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/ai-system-definition-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193355320,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:3,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>The GPAI Layer &#8212; When Foundation Models Complicate the Picture</h2><p>If you&#8217;re building anything on top of a foundation model, and in 2026 that covers a lot of companies, the role question has an extra dimension.</p><p>Most modern AI deployments involve at least two regulatory actors. Sometimes three.</p><p><strong>Layer 1:</strong> The GPAI model provider. OpenAI for GPT, Anthropic for Claude, Meta for Llama, Google for Gemini. Obligations under <a href="https://artificialintelligenceact.eu/chapter/5/">Chapter V</a>: technical documentation, copyright compliance, training data summaries, and for systemic-risk models, evaluation and adversarial testing.</p><p><strong>Layer 2:</strong> The AI system provider. The company that takes the foundation model and wraps it in a product: a chatbot, a document analyzer, a recruitment screener, a diagnostic tool. If that system is high-risk, full provider obligations under <a href="https://artificialintelligenceact.eu/chapter/3/">Chapter III</a> apply.</p><p><strong>Layer 3:</strong> The deployer. The company using the system in its operations. <a href="https://artificialintelligenceact.eu/article/26/">Article 26</a>.</p><p>Each layer carries its own obligations. The GPAI model provider&#8217;s obligations don&#8217;t cover the system built on top of the model. The system provider&#8217;s obligations don&#8217;t reach down into the model&#8217;s architecture. Separate tracks, separate responsibilities.</p><h3>Four scenarios</h3><p><strong>You use ChatGPT through the web interface for general business tasks.</strong> You&#8217;re a deployer. OpenAI is the provider of both the GPAI model and the AI system. You&#8217;re using it. That&#8217;s it.</p><p><strong>You integrate the OpenAI API into your own product and sell it.</strong> You&#8217;re the provider of an AI system. OpenAI is the GPAI model provider at Layer 1. You built the system at Layer 2. If your system is high-risk (credit scoring built on GPT, for example) full provider obligations apply to you. OpenAI&#8217;s obligations are at the model level, not the system level.</p><p>A practical complication: your ability to comply depends partly on what the GPAI model provider gives you. <a href="https://artificialintelligenceact.eu/article/53/">Article 53(1)(b)</a> and <a href="https://artificialintelligenceact.eu/annex/12/">Annex XII</a> require GPAI model providers to share information about the model&#8217;s capabilities, limitations, and risks, information you need for your technical documentation and risk assessment. If that documentation is thin, you face a compliance gap that isn&#8217;t fully within your control. Your contracts with the GPAI model provider need to address this. </p><p><strong>You fine-tune an open-source model (Llama, for example) and deploy the resulting system.</strong> You&#8217;re the provider of whatever AI system you build with the fine-tuned model. Whether you also become a GPAI model provider depends on how far you went. The <a href="https://digital-strategy.ec.europa.eu/en/library/guidelines-scope-obligations-providers-general-purpose-ai-models-under-ai-act">Commission&#8217;s GPAI Guidelines</a> use an indicative threshold: if the compute used for fine-tuning exceeds <em><strong>one-third</strong></em> of the compute used to train the base model, you may become a GPAI model provider for the modified model. Most fine-tuning falls well below this.</p><p>One thing that doesn&#8217;t cascade: Meta&#8217;s open-source exemption. The lighter GPAI model provider obligations that Meta benefits from don&#8217;t extend to you. Your obligations as the AI system provider are unaffected by what the model provider&#8217;s obligations look like. Their exemption is theirs.</p><p><strong>You build a RAG system on a foundation model via API.</strong> You connect a foundation model to your company&#8217;s knowledge base and deploy it as an internal tool or customer-facing assistant. You are the AI system provider. <em>If you also use it internally, you&#8217;re both provider and deployer of the same system.</em></p><div><hr></div><h2>Multiple Roles: the Norm, Not the Exception</h2><p>The EU AI Act doesn&#8217;t prevent a single entity from holding multiple roles simultaneously. In practice, most companies of any size will.</p><p>A company that builds a proprietary AI tool for its core product (provider) while using off-the-shelf AI tools from vendors for HR, marketing, or operations (deployer for each). Three, four, five different role classifications across different systems. That part is straightforward. The harder versions:</p><h3>Provider AND deployer of the same system</h3><p>A company that builds an AI system for its own internal use. It&#8217;s a provider because it developed the system and put it into service under its own name (Article 3(3)). It&#8217;s also a deployer because it&#8217;s using the system under its authority (Article 3(4)). No mutual exclusivity clause in the regulation.</p><p>The dual classification matters because the deployer role creates specific obligations the provider role alone doesn&#8217;t cover.</p><p><a href="https://artificialintelligenceact.eu/article/26/">Article 26(11)</a>: informing affected natural persons. The provider&#8217;s transparency obligation runs toward deployers (instructions for use). The deployer&#8217;s obligation runs toward the people affected by the system&#8217;s output. When you&#8217;re both, you bear both transparency flows.</p><p><a href="https://artificialintelligenceact.eu/article/26/">Article 26(7)</a>: informing workers&#8217; representatives before deployment. This triggers through the deployer role, not the provider role.</p><p><a href="https://artificialintelligenceact.eu/article/27/">Article 27</a>: the fundamental rights impact assessment. For public bodies and certain private entities, this obligation applies per the deployer role. A public hospital that builds its own diagnostic AI is a provider, but the FRIA triggers through its deployer capacity.</p><p><a href="https://artificialintelligenceact.eu/article/26/">Article 26(2)</a>: human oversight. Providers must design systems to enable oversight (<a href="https://artificialintelligenceact.eu/article/14/">Article 14</a>). Deployers must assign competent, trained people to perform it. When you&#8217;re both, you must do both. Design the capability and staff the function. Different obligations, same entity.</p><h3>Distributor who starts customizing</h3><p>A reseller distributes a vendor&#8217;s AI system. Over time, the reseller starts offering a <em>&#8220;customized&#8221;</em> version: training the system on industry-specific data, adjusting parameters, putting its own logo on the interface. The reseller started as a distributor. It may have crossed into provider territory through substantial modification or rebranding. The obligations don&#8217;t shift gradually. They shift all at once, the moment Article 25 triggers. One day you&#8217;re checking CE markings. The next you need a conformity assessment.</p><h3>The practical implication</h3><p>Don&#8217;t assign one role to the company. Assign roles system-by-system. Build a register that tracks, for each AI system: what it is, what your role is, when you last assessed that role, and what would trigger reassessment (modification, retraining, new use case, contract renewal).</p><p>One note on risk categories for that register: the EU AI Act doesn&#8217;t use the terms &#8220;limited-risk&#8221; or &#8220;minimal-risk.&#8221; Those are common shorthand but not regulatory categories. The actual tiers: prohibited practices (<a href="https://artificialintelligenceact.eu/article/5/">Article 5</a>), high-risk systems (<a href="https://artificialintelligenceact.eu/article/6/">Article 6</a>, Annexes <a href="https://artificialintelligenceact.eu/annex/1/">I</a> and <a href="https://artificialintelligenceact.eu/annex/3/">III</a>), systems with specific transparency obligations (<a href="https://artificialintelligenceact.eu/article/50/">Article 50</a>), and everything else.</p><div><hr></div><h2>The Grey Zones</h2><h3>&#8220;Had developed&#8221; and whose name is on it</h3><p>The provider definition has two cumulative elements: develops or has developed, AND places on market or puts into service under its own name or trademark. Both must be present.</p><p>A company commissions a vendor to build a custom AI system. The vendor brands it. Even if the company &#8220;had it developed&#8221; (detailed specs, iterative reviews, full design control) the vendor&#8217;s name is on the product. The company isn&#8217;t the provider. The vendor is. The company is a deployer of a customized product. That part is clear.</p><p>The real grey zones are elsewhere. A company commissions a system for internal use. No product label, no marketing, no brand on the interface. Whose &#8220;name&#8221; is it under? Internal deployment might constitute putting into service under your own name. The company is the entity operating the system and taking responsibility. But the regulation was written with market-facing branding in mind, not internal tools. The text doesn&#8217;t address this directly.</p><p>Or: two companies co-develop an AI system. Both contribute to the design. Both names appear. Article 3(3) doesn&#8217;t say there can be only one provider. But the regulation&#8217;s obligations (conformity assessment, technical documentation, quality management) are designed for a single accountable entity. How do you split them between two co-providers? The regulation doesn't directly address this. Article 25(3) requires written agreements when a deployer, distributor, or importer assumes provider status &#8212; a succession scenario, not a joint-development one. By analogy, co-providers would need a similar agreement allocating obligations, but the text doesn't prescribe one. The regulatory classification itself remains ambiguous.</p><h3>SaaS and the importer question</h3><p>The importer and distributor roles were designed for physical products. A US company offering an AI SaaS directly to EU customers, with no intermediary, creates no importer. No distributor. The US company is the provider, subject to the regulation through its authorized representative.</p><p>An EU company reselling access to a US-built AI SaaS might be an importer or a distributor. But <em>&#8220;placing on the market&#8221;</em> was defined in Article 3(9) for products, not services. The definition is doing a job it wasn&#8217;t designed for.</p><p>For most companies: if you&#8217;re using an AI SaaS tool, you&#8217;re a deployer. The SaaS vendor is the provider. Importer and distributor questions arise mainly for companies that resell or redistribute AI products, not end users.</p><h3>Embedded AI and the Omnibus</h3><p>AI embedded in a medical device, a car, an industrial machine. The EU AI Act applies alongside the relevant sectoral legislation: Medical Devices Regulation, Vehicle Safety Regulation, Machinery Regulation. Who&#8217;s the AI system provider? The product manufacturer? The AI component supplier?</p><p>The Digital Omnibus on AI, the simplification package provisionally agreed on May 7, 2026, changes this picture.</p><p>Machinery products with embedded AI are now exempted from AI Act high-risk obligations entirely. They comply with the Machinery Regulation only. For other sectors (medical devices, automotive, aviation) the Commission can adopt implementing acts to limit the AI Act&#8217;s application where sectoral legislation already covers equivalent ground. Until those implementing acts land, the overlap persists.</p><p>The omnibus also extended timelines. Standalone Annex III high-risk systems: <strong>2 December 2027</strong> (pushed from August 2026). Annex I product-embedded systems: <strong>2 August 2028</strong> (pushed from August 2027). Obligations already live (prohibited practices, AI literacy) are unaffected.</p><p><em>The omnibus is provisional as of June 2026. Formal adoption is expected before August 2026. Verify the adopted text before acting on the extended timelines.</em></p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;6a2f68a6-07e9-4c1b-af72-c2e59589dd9f&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;EU AI Act Amended: The Digital Omnibus Timeline&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-13T12:02:43.130Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!DR18!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/eu-ai-act-amended-the-digital-omnibus&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:196926473,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:3,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>The Practical Steps </h2><h3>1. Build the AI inventory</h3><p>Before you can assign roles, you need to know what AI systems your organization touches. This is harder than it sounds. AI is embedded in tools people don&#8217;t think of as &#8220;AI&#8221;. </p><p>What to inventory: </p><ul><li><p>systems you built or commissioned (provider candidates), </p></li><li><p>systems you bought or licensed (deployer candidates), </p></li><li><p>systems you resell (distributor or importer candidates), </p></li><li><p>foundation models you build on (system provider candidates), </p></li><li><p>AI-powered features within broader platforms you use (deployer candidates). </p></li></ul><p>And the one that keeps surfacing in every assessment I&#8217;ve seen: AI systems employees are using without formal procurement. <em>Shadow AI.</em> You&#8217;re still potentially a deployer.</p><h3>2. Classify risk, then assign roles</h3><p>For each system, determine the risk level first. Is it high-risk? Most EU AI Act obligations for deployers, importers, and distributors only apply to high-risk systems. Providers carry some obligations regardless (AI literacy under <a href="https://artificialintelligenceact.eu/article/4/">Article 4</a>, transparency under <a href="https://artificialintelligenceact.eu/article/50/">Article 50</a>), but the heavy requirements are for high-risk.</p><p>Then run each system through the decision tree. Document your reasoning. This isn&#8217;t just good practice. It&#8217;s the evidence a regulator will want to see.</p><h3>3. Check for Article 25 triggers</h3><p>For every system where you&#8217;re initially a deployer, distributor, or importer, check whether anything you&#8217;ve done transforms your role. Rebranding. Substantial modification. Repurposing into a high-risk category. If any of these apply, you&#8217;re a provider for that system. </p><h3>4. Map the GPAI layer</h3><p>For every system built on a foundation model: identify the GPAI model provider, confirm they&#8217;re providing the <a href="https://artificialintelligenceact.eu/annex/12/">Annex XII</a> information you need, and ensure your contracts address the information-sharing gap. If you&#8217;ve fine-tuned the model, check the one-third compute threshold from the <a href="https://digital-strategy.ec.europa.eu/en/library/guidelines-scope-obligations-providers-general-purpose-ai-models-under-ai-act">Commission&#8217;s GPAI Guidelines</a>.</p><h3>5. Check cross-border dynamics</h3><p>Non-EU provider? Has it appointed an authorized representative? Are you the first EU entity handling the system? That might make you the importer.</p><h3>6. Document and revisit</h3><p>Role assignment isn&#8217;t a one-time exercise. Set triggers for reassessment: every modification or retraining, every new use case, every contract renewal. When the Commission publishes guidance (particularly the still-pending guidance on substantial modification) reassess in light of it.</p><p>At minimum: annually.</p><div><hr></div><h2>Column D Problem</h2><p>It&#8217;s been ninety minutes. The spreadsheet has changed. Column D has a mix of <em>provider</em>, <em>deployer</em>, one <em>importer</em>, and four entries that say <em>needs further assessment</em>. The head of data science is having a quiet crisis about the fine-tuning. Marketing is Googling &#8220;rebranding AI Act Article 25&#8221;. The colleague from Frankfurt is reading Article 23 on her phone.</p><p>This is the meeting nobody wanted to have. And it&#8217;s the most important meeting the company will have about the EU AI Act, because every other question depends on this one. Risk classification depends on your role. Obligations depend on your role. Deadlines, documentation, conformity assessment: all of it flows from what you are.</p><p>The answers exist. The definitions are in Article 3. The transformation triggers are in Article 25. The obligations are in Articles 16-26. The decision tree works.</p><p>The answers are also per system, not per company. They change when the system changes. And the regulation doesn&#8217;t wait for you to figure it out.</p><p>Column D isn&#8217;t going to fill itself.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading AI Law. Decoded.! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Agentic AI Under the EU AI Act]]></title><description><![CDATA[When the regulation meets systems that act independently.]]></description><link>https://ailawdecoded.com/p/agentic-ai-under-the-eu-ai-act</link><guid isPermaLink="false">https://ailawdecoded.com/p/agentic-ai-under-the-eu-ai-act</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 03 Jun 2026 12:03:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!VHg5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6c9d56f-d86d-465b-b53d-ae335110c026_6000x4000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VHg5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6c9d56f-d86d-465b-b53d-ae335110c026_6000x4000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VHg5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6c9d56f-d86d-465b-b53d-ae335110c026_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!VHg5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6c9d56f-d86d-465b-b53d-ae335110c026_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!VHg5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6c9d56f-d86d-465b-b53d-ae335110c026_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!VHg5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6c9d56f-d86d-465b-b53d-ae335110c026_6000x4000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VHg5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6c9d56f-d86d-465b-b53d-ae335110c026_6000x4000.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c6c9d56f-d86d-465b-b53d-ae335110c026_6000x4000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:20333863,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.substack.com/i/199299205?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6c9d56f-d86d-465b-b53d-ae335110c026_6000x4000.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!VHg5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6c9d56f-d86d-465b-b53d-ae335110c026_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!VHg5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6c9d56f-d86d-465b-b53d-ae335110c026_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!VHg5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6c9d56f-d86d-465b-b53d-ae335110c026_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!VHg5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6c9d56f-d86d-465b-b53d-ae335110c026_6000x4000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>You built the oversight process. Three weeks of work: escalation protocols, a review dashboard, a human approver assigned to every outgoing communication. </p><p>Your company is deploying a customer retention agent. It monitors churn signals, identifies at-risk customers, drafts personalized outreach, and sends it. High-risk? Depends on what it touches. </p><p>But you wanted oversight. Real oversight. Not a checkbox.</p><p>It&#8217;s Tuesday morning. You open the dashboard. The agent processed 47 customer interactions overnight. Emails drafted. Emails sent. Responses received. Follow-ups scheduled. Two discount offers extended, one at a rate that hasn&#8217;t been approved before. One message references a customer&#8217;s medical situation, pulled from a support ticket the agent accessed through the CRM.</p><p>Your human reviewer saw the first three messages. Approved them. Went home at 6pm. The agent didn&#8217;t go home.</p><p>You&#8217;re looking at the log. Not proposed actions. Completed ones. </p><p>And the oversight process you spent three weeks building (the one modeled on <a href="https://artificialintelligenceact.eu/article/14/">Article 14</a> of the EU AI Act, which requires that high-risk systems be designed so humans can effectively oversee them) assumed something that turned out to be false.</p><p>It assumed the human would see the output before it took effect.</p><p>Your agent doesn&#8217;t work that way. It acts first. The human reviews after. If at all.</p><p>You&#8217;re not the only one with this problem. </p><p>The European Commission just noticed it too.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>What Makes an Agent Different</h2><p>If you&#8217;ve used ChatGPT or Claude or any other AI chatbot, you&#8217;ve used a system that follows a simple pattern: you ask a question, the system generates an answer, you decide what to do with it. </p><p>Input, output, human decision. The EU AI Act was drafted around this model.</p><p>An AI agent breaks the pattern.</p><p>An agent doesn&#8217;t just answer your question. It pursues a goal. Give it <em>&#8220;reduce customer churn&#8221;</em> and it will plan a strategy, access your customer database, analyze behavior patterns, draft communications, send them, read the responses, and adjust its approach, chaining actions together, using the output of one step as the input for the next.</p><p>A traditional AI system is like a consultant who writes you a memo. You read it, you decide, you act. An agent is like a consultant you gave your email password, your CRM login, your calendar access, and a set of objectives. Then you went on vacation. When you come back, things have happened.</p><p><em>The critical components:</em> a language model that handles reasoning and planning (the <em>&#8220;brain&#8221;</em>: GPT-4, Claude, Gemini). And an orchestration layer that manages the workflow, breaking goals into steps, choosing tools, handling errors. </p><p><em>Tools that let the agent act in the world, not just generate text:</em> APIs, databases, email systems, calendars, code execution environments. And memory, the ability to retain information across steps and sessions.</p><p>That combination of reasoning, tools, and autonomy is what makes it agentic. And it&#8217;s what breaks three assumptions the EU AI Act was built on.</p><p><strong>Assumption one</strong>: <em>the system has a defined, bounded purpose. </em>Agents can pursue open-ended goals across multiple domains. An agent told to <em>&#8220;improve customer satisfaction&#8221; </em>might end up accessing HR data, modifying product descriptions, and sending emails to suppliers. None of which was the &#8220;<em><strong>intended purpose&#8221;</strong></em> anyone documented.</p><p><strong>Assumption two:</strong> <em>a human reviews the output before it takes effect.</em> Agents act. The output <em>is</em> the action. By the time the human sees it, the email is sent, the database is modified, the API call is made.</p><p><strong>Assumption three:</strong> <em>there&#8217;s a clear provider and deployer.</em> Agent deployments involve a model provider, a framework developer, tool providers, the company that assembled the agent, and the company that runs it. The AI Act&#8217;s two-party model doesn&#8217;t map cleanly onto a five-party stack.</p><p>None of this means agents fall outside the EU AI Act. They don&#8217;t. But they stress the framework in ways the drafters didn&#8217;t anticipate, and the Commission is just starting to respond.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;06573da3-56ef-4657-85fa-32049be85c6c&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;\&quot;Intended Purpose\&quot; vs. \&quot;Effect\&quot; Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-27T12:03:27.192Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!MsHD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd047f6a-2b39-49d4-8fc6-ae44b22df7c4_6000x4000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/intended-purpose-vs-effect-under&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:198307974,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:6,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>The European Commission Just Weighed In </h2><p>Two sets of draft guidelines dropped in May 2026. Both matter. </p><h3>The high-risk classification guidelines (19 May 2026)</h3><p>The long-delayed <a href="https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems">draft guidelines on classifying high-risk AI systems</a> were published on 19 May 2026, more than three months late. Open for consultation until 23 June. And buried in the guidance on how to assess complex systems is a provision that matters for anyone deploying agents.</p><p><strong>W</strong>here several AI components form a more complex system and their combined purpose or joint outputs materially influence a decision, the whole configuration is assessed as one AI system. Not each component separately. The whole thing.</p><p>The Commission extends this principle explicitly to:</p><blockquote><p><em>&#8220;complex, interconnected setups like agentic AI systems that coordinate and interact through linked actions as long as these linked actions or components serve in conjunction an intended high-risk purpose.&#8221;</em></p></blockquote><p><strong>Agentic AI systems.</strong> By name. In draft Commission guidelines. For the first time.</p><p>In practice, an orchestrator agent that delegates tasks to sub-agents, a document checker, a credit analyzer, a compliance screener, all feeding into a loan decision? That&#8217;s one AI system. Not four. The obligations attach to the stack as a whole.</p><p>And the escape hatch narrows. <a href="https://artificialintelligenceact.eu/article/6/">Article 6(3)</a> lets providers argue their Annex III system isn&#8217;t actually high-risk if it performs only a narrow procedural task, or merely improves a previously completed human activity, or just does preparatory work for a human decision. The draft guidelines read this exception narrowly. The exception is the exception. High-risk classification is the rule.</p><p>For agents, the Article 6(3) argument is almost impossible to make. Most enterprise agents are deployed precisely to handle complex, multi-step workflows. <em>"Narrow procedural task"</em> and <em>"agentic"</em> are in practical tension. And if the agent profiles natural persons (automated processing of personal data to evaluate aspects of someone's life) it's always high-risk. No exception. Many enterprise agents handling customer or employee data will meet the threshold for profiling, as defined in <a href="https://eur-lex.europa.eu/eli/reg/2016/679/oj#art_4">GDPR Article 4(4)</a>, and will therefore be classified as high-risk without exception.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;44684379-a393-4d03-9da2-b60bb3300c16&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Is My AI System High-Risk Under the EU AI Act?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-06T12:02:25.960Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!-GG3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/is-my-ai-system-high-risk-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:196305760,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h3>The transparency guidelines (8 May 2026)</h3><p>Eleven days before the high-risk guidelines, the Commission published <a href="https://digital-strategy.ec.europa.eu/en/library/draft-guidelines-implementation-transparency-obligations-certain-ai-systems-under-article-50-ai-act">draft guidelines on Article 50 transparency obligations</a>. Consultation closes 3 June. These matter for agents too.</p><p>The guidelines confirm that agentic AI systems fall within <a href="https://artificialintelligenceact.eu/article/50/">Article 50(1)</a>: the requirement to tell people they're interacting with AI. The list includes conversational agents, voice assistants, coding agents, browsing agents, and bots on social networks. If your agent interacts with a natural person, it must disclose so.</p><p>But the interesting part is what happens when the provider can&#8217;t reliably determine whether the agent will interact with a natural person. In that case, the agent should disclose itself as AI in every situation where such interaction is plausible.</p><p>Not certain. <em>Plausible.</em></p><p>An agent that sends emails? Plausible it reaches a human. An agent that books meetings? Plausible. An agent that browses the web and fills out forms? Plausible. The default shifts from <em>&#8220;disclose where interaction is certain&#8221;</em> to <strong>&#8220;disclose where interaction is plausible</strong>&#8221;. For autonomous agents that operate across multiple channels and tools, that&#8217;s most of the time.</p><p>And in sensitive contexts, where users might experience emotional distress or form emotional attachments, one-time disclosure isn&#8217;t enough. The guidelines say periodic reminders may be necessary.</p><p>Both sets of guidelines are draft. Not final. Not binding. But they tell you where the Commission is heading. And the direction is clear: agents are in scope, the framework applies, and the Commission isn&#8217;t interested in narrow readings that let agent deployments slip through the cracks.</p><div><hr></div><h2>On Human Oversight </h2><p>Those 47 messages your agent sent while your reviewer was home sleeping.</p><p>Article 14 of the EU AI Act requires that high-risk AI systems be designed so they can be <em>&#8220;effectively overseen by natural persons during the period in which they are in use&#8221;.</em></p><p>The overseers must be able to understand the system&#8217;s capacities and limitations, monitor its operation, detect anomalies, correctly interpret its output, and (critically) <strong>&#8220;decide not to use the system, disregard, override, or reverse the output&#8221;</strong> and <strong>&#8220;intervene in or interrupt the system&#8217;s operation&#8221;</strong>.</p><p>Override or reverse the output. That language assumes the output exists in a reviewable state before it takes effect. For a credit scoring model that generates a recommendation, that works. The human sees the score, evaluates it, approves or rejects. The output sits there, waiting for a decision.</p><p>Agents invert this. The output <em>is</em> the action. The email is sent. The database is updated. The API call is made. The discount is offered. By the time the human sees the log, the agent has already changed the world. In small ways, maybe. But in ways that may not be easily reversed.</p><h3>The speed problem</h3><p>An agent can execute a chain of ten actions in seconds. Analyze customer data, identify a risk signal, draft a response, pull a discount code, personalize the message, send it, log the interaction, update the CRM, schedule a follow-up, move to the next customer. A human can&#8217;t meaningfully review each step in real time. And agents don&#8217;t pause between steps to wait for approval, unless you specifically design them to, which defeats much of the efficiency that justified deploying the agent in the first place.</p><h3>The opacity problem</h3><p>In a multi-step workflow, the connection between the initial goal and the final action may not be transparent. <em>&#8220;Reduce customer churn&#8221; </em>&#8594; analyze behavior data &#8594; identify at-risk customers &#8594; pull their support history &#8594; notice a medical reference in a support ticket &#8594; include it in the personalized outreach because the model determined it was relevant context. Each step followed logically from the last. The reasoning chain was coherent. The result was a privacy violation.</p><p>The human reviewing the dashboard sees the sent email. They don&#8217;t see the twelve intermediate reasoning steps that produced it, unless the system was designed to log every step in a human-readable way. Most aren&#8217;t.</p><h3>The continuous operation problem</h3><p>Article 14 implicitly assumes the system is <em>&#8220;in use&#8221;</em> in discrete episodes. A human runs a query, gets a result, makes a decision. Agents operate continuously: monitoring inboxes, responding to events, executing scheduled tasks, running overnight while nobody&#8217;s watching. Your retention agent didn&#8217;t process 47 interactions in a burst while someone supervised. It worked through the night, steadily, one interaction at a time.</p><p>Meaningful oversight of a continuously operating agent requires a fundamentally different model. Not &#8220;review each output&#8221;. More like: define the boundaries, monitor the patterns, catch the anomalies. Pre-deployment constraints on what the agent can do. Runtime guardrails that halt the agent when it steps outside those boundaries. Post-action audit trails. Escalation protocols for decisions that shouldn&#8217;t be autonomous.</p><p><a href="https://artificialintelligenceact.eu/article/14/">Article 14(3)</a> offers a hook: oversight must be <strong>&#8220;commensurate with the risks, level of autonomy and context of use&#8221;.</strong> For highly autonomous agents, that phrase could support requirements for all of the above: pre-deployment boundaries, runtime monitoring, post-action review, mandatory escalation points. But the AI Act doesn&#8217;t specify what <em>&#8220;commensurate&#8221;</em> looks like for a system that acts first and explains later. That&#8217;s a gap the standards bodies and the Commission will need to fill.</p><h3>The automation bias amplifier</h3><p>Article 14(4)(b) requires human overseers to be aware of automation bias, the tendency to over-rely on AI outputs. For agents, this problem is worse.</p><p>Agents present completed actions, not recommendations. It&#8217;s psychologically harder to reverse something that&#8217;s already done than to reject something that&#8217;s proposed. An agent that operates efficiently and correctly 95% of the time builds deep trust. When it fails, when message 38 of 47 includes a customer&#8217;s medical data, the reviewer may not catch it. Not because they&#8217;re negligent. Because 37 correct messages trained them to stop looking closely.</p><p>And multi-step chains create complexity that discourages investigation. If an agent completed a 15-step workflow and the final result looks plausible, a human may not trace through every step to find where the reasoning went wrong. The sheer volume of correct outputs buries the errors.</p><p>This is what the academic literature is calling &#8220;<em>agenticness as a risk amplifier</em>&#8221;. The technical properties that make a system agentic (autonomy, tool use, multi-step planning) don&#8217;t just create new risks. They amplify the existing ones. Human oversight doesn&#8217;t just get harder. It gets structurally undermined.</p><div><hr></div><h2>The Accidental Provider: Article 25, Agent Edition</h2><p>If you&#8217;ve read my earlier piece on provider vs. deployer, you know the basics. <a href="https://artificialintelligenceact.eu/article/25/">Article 25</a> defines three moments when a deployer becomes a provider: you rebrand the system, you substantially modify it, or you repurpose it into high-risk territory. Any one trigger is enough.</p><p>For traditional AI systems, accidental provider status is a risk. For agents, it&#8217;s the likely outcome in most enterprise deployments.</p><h3>The configuration trap</h3><p>Most agent deployments follow the same pattern. A company licenses a commercial agent platform, an &#8220;Enterprise AI Assistant&#8221;. The vendor provides the base agent: the model, the orchestration framework, the default capabilities. The company then configures it. Connects their CRM, their email system, their calendar, their customer database, their project management tool. Defines what the agent can do autonomously versus what requires approval. Writes system prompts that shape the agent&#8217;s behavior and tone. Sets boundaries.</p><p>The vendor&#8217;s conformity assessment (if they did one) assessed their product. The base agent with default settings. Not your 23-tool, custom-prompted, autonomy-adjusted configuration that touches customer data across four enterprise systems.</p><p><a href="https://artificialintelligenceact.eu/article/3/">Article 3(23)</a> defines <em>&#8220;substantial modification&#8221;</em> as a change not foreseen or planned in the initial conformity assessment. When the vendor&#8217;s documentation says &#8220;the agent may be configured with various tools,&#8221; does that foresee the specific configuration where you connected it to your HR database? Almost certainly not with enough specificity.</p><p>And now the Commission&#8217;s May 2026 draft guidelines add the final piece: multi-component configurations serving a joint purpose are assessed as one AI system. Your specific configuration, your tools, your prompts, your autonomy boundaries, isn&#8217;t just a deployment choice. It defines the system. And the system the vendor assessed is not the system you deployed.</p><p>Article 25(1)(b). Substantial modification not foreseen in the conformity assessment. You&#8217;re the provider.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;26f46dd6-0b19-47fb-9d2e-fc14ee13f294&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Provider vs. Deployer Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-22T12:03:43.719Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!NS5L!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35f75bb-44f2-45d4-b53c-84654d8e8617_8192x5461.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/provider-vs-deployer-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:194314202,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:5,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h3>The repurposing trap</h3><p>This one is faster. A company deploys a general-purpose workflow agent. Minimal risk, internal task automation. Someone in operations connects it to the HR system. Someone else asks it to help screen candidates. Nobody changed the agent&#8217;s code. Nobody retrained the model. </p><p>Article 25(1)(c). The system wasn&#8217;t high-risk. <em>The use is.</em> The deployer just became the provider of a high-risk AI system, without writing a line of code.</p><p>I keep seeing variations of this with traditional AI systems. Agents make it worse because they&#8217;re designed to be general-purpose. The same agent that schedules meetings can, if given the tools and the instructions, assist with employment decisions. The boundary between low-risk and high-risk isn&#8217;t in the agent&#8217;s architecture. It&#8217;s in what you connect it to and what you ask it to do.</p><h3>The tool sovereignty problem</h3><p>There&#8217;s a layer the majority of people haven&#8217;t considered yet. Article 25(3) requires written agreements between providers and <em>&#8220;third parties that supply tools, services, components, or processes that are used or integrated in a high-risk AI system&#8221;</em>.</p><p>An agent that uses twenty tools (Salesforce for CRM, Stripe for payments, Twilio for messaging, a dozen internal APIs) potentially triggers twenty written AI Act compliance agreements. For tools that are standard SaaS, the providers of those services probably haven&#8217;t contemplated AI Act obligations in their terms of service.</p><p>And agents can invoke tools dynamically, selecting which tool to use at runtime based on the task. The EU AI Act&#8217;s compliance model assumes fixed, known relationships. Agents have dynamic, runtime-determined relationships. The agent decides at 2am that it needs to query a database nobody specifically authorized it to access, because it had the credentials and the task seemed to require it.</p><p>This is what one European Law Blog analysis calls <strong>&#8220;agentic tool sovereignty&#8221;</strong>: agents invoking tools that may not be known before deployment, operating under different jurisdictional regimes, creating compliance relationships that didn&#8217;t exist when the system was assessed. Nearly two years after the EU AI Act entered into force, the Commission&#8217;s May 2026 draft guidelines represent the first official acknowledgment that agentic AI systems require specific interpretive attention, but no agent-specific implementing act has followed.</p><h3>The practical result</h3><p>Many companies deploying commercial agents will inadvertently become providers under Article 25. Not because they chose to. Because the difference between what the vendor assessed and what the company actually deployed (the specific tools, the specific data, the specific autonomy boundaries) is too big for the vendor&#8217;s conformity assessment to cover.</p><p>And when you become a provider, Article 25(2) says the original vendor <em>&#8220;shall no longer be considered to be a provider of that specific AI system&#8221;.</em> Not the modified part. <strong>The whole system. </strong>You own it now. Conformity assessment, technical documentation, quality management, post-market monitoring, all of it.</p><p>The vendor&#8217;s contract may still call you a deployer. The regulation doesn&#8217;t necessarily care what the contract says.</p><div><hr></div><h2>What&#8217;s Already Happening</h2><p>This isn&#8217;t theoretical. It&#8217;s not a 2028 problem.</p><p>In December 2025, Amazon&#8217;s coding agent Kiro deleted a production environment for AWS Cost Explorer in the China region, triggering a 13-hour service outage. Amazon has disputed this characterization, attributing the incident to misconfigured engineer permissions. In February 2026, an autonomous AI agent using the OpenClaw framework went rogue after a rejected software contribution, independently writing and publishing a hit piece attacking the volunteer who turned it down.</p><p>These aren&#8217;t edge cases from a research lab. They&#8217;re production incidents. Real agents, real damage, real consequences. And the regulatory framework, as the Commission&#8217;s own draft guidelines implicitly acknowledge by mentioning agents for the first time, is playing catch-up.</p><p>The Commission published the draft high-risk classification guidelines on 19 May 2026. Consultation closes 23 June. The transparency guidelines are open until 3 June. Neither document is final. Neither is binding. But they confirm what the academic literature has been saying for a year: the AI Act applies to agents, the framework strains, and the gaps need filling.</p><p>Companies deploying agents now, and many are, at scale, don&#8217;t have the luxury of waiting for final guidance. They need a way to think about compliance even in the absence of definitive answers. And the starting point is the same as it&#8217;s always been with the EU AI Act: understand what your system does, understand who&#8217;s responsible for it, and build the oversight to match.</p><p>The 47 messages your agent sent last night? That&#8217;s the easy version of this problem. Wait until it&#8217;s a multi-agent system: an orchestrator delegating to specialized sub-agents, each with their own tools and decision logic, coordinating toward a goal that touches high-risk territory. The Commission says that&#8217;s one system. Article 14 says a human must be able to oversee it. Article 25 says someone must be the provider.</p><p>Nobody said compliance would be simple. But the regulation is catching up to the technology. Slowly, in draft form, with consultation deadlines and no final timeline.</p><p>The agents aren&#8217;t waiting.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading AI Law. Decoded.! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA["Intended Purpose" vs. "Effect" Under the EU AI Act]]></title><description><![CDATA[You documented the purpose. But the regulation often asks about the effect.]]></description><link>https://ailawdecoded.com/p/intended-purpose-vs-effect-under</link><guid isPermaLink="false">https://ailawdecoded.com/p/intended-purpose-vs-effect-under</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 27 May 2026 12:03:27 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!MsHD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd047f6a-2b39-49d4-8fc6-ae44b22df7c4_6000x4000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MsHD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd047f6a-2b39-49d4-8fc6-ae44b22df7c4_6000x4000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MsHD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd047f6a-2b39-49d4-8fc6-ae44b22df7c4_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!MsHD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd047f6a-2b39-49d4-8fc6-ae44b22df7c4_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!MsHD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd047f6a-2b39-49d4-8fc6-ae44b22df7c4_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!MsHD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd047f6a-2b39-49d4-8fc6-ae44b22df7c4_6000x4000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MsHD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd047f6a-2b39-49d4-8fc6-ae44b22df7c4_6000x4000.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dd047f6a-2b39-49d4-8fc6-ae44b22df7c4_6000x4000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:466863,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.substack.com/i/198307974?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd047f6a-2b39-49d4-8fc6-ae44b22df7c4_6000x4000.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MsHD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd047f6a-2b39-49d4-8fc6-ae44b22df7c4_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!MsHD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd047f6a-2b39-49d4-8fc6-ae44b22df7c4_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!MsHD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd047f6a-2b39-49d4-8fc6-ae44b22df7c4_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!MsHD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd047f6a-2b39-49d4-8fc6-ae44b22df7c4_6000x4000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>It&#8217;s 6pm on a Thursday and you should go home.</p><p>But you don&#8217;t. You&#8217;re looking at your presentation for tomorrow&#8217;s board meeting and &#8212; for the first time in months &#8212; you&#8217;re actually proud. Not the exhausted kind of proud where you survived something. The real kind. The kind where you built something right.</p><p>Your company is deploying its first high-risk AI system. Candidate screening &#8212; CV analysis, applicant ranking, shortlisting for the hiring managers. It&#8217;s Annex III, Point 4 under the EU AI Act. You knew from day one it was high-risk. And you did everything the regulation asks.</p><p>Risk management system &#8212; built, iterative, documented. Human oversight &#8212; two senior recruiters trained, with override authority. Technical documentation reviewed. Data governance assessed. Fundamental rights impact assessment &#8212; done. The provider&#8217;s instructions for use &#8212; read, annotated, cross-referenced against your deployment context. AI literacy training &#8212; rolled out to every hiring manager who touches the system.</p><p>You did this. You and the team. Six months of work. And tomorrow you get to stand in front of the board and say: we&#8217;re ready. We&#8217;re compliant. This is what good looks like.</p><p>You should go home. But the presentation is tomorrow and you want to be sharp &#8212; so you pull up the AI Act one more time. Not to build anything. Just to flip through, mark a few notes for potential board questions. A confidence pass.</p><p>You&#8217;re skimming. Recitals, mostly &#8212; the interpretive context you might need if someone asks a &#8220;but what does that actually mean&#8221; question. And then your eyes land on <a href="https://artificialintelligenceact.eu/recital/29/">Recital 29</a>.</p><p>You&#8217;ve read it before. You must have. But this time &#8212; maybe because you&#8217;re not building anything, just reading &#8212; a sentence catches you in a way it didn&#8217;t before.</p><blockquote><p><em>&#8221;It is not necessary for the provider or the deployer to have the intention to cause significant harm, provided that such harm results from the manipulative or exploitative AI-enabled practices.&#8221;</em></p></blockquote><p>You stop scrolling.</p><p><em>It is not necessary to have the intention.</em></p><p>You look at your presentation. Slide 4 provides &#8220;Compliance Architecture&#8221;. Every bullet describes what the system is <em><strong>for</strong></em>. Its intended purpose. Its documented design. The governance built around the use case as the provider defined it.</p><p>You know what the system is supposed to do. You documented it thoroughly. But now the question: how do you know its real-world effect matches that purpose? How are you measuring what actually happens to candidates once the system processes them? How would you catch the unexpected &#8212; the drift, the bias that emerges only in your specific context, the effect on people that the team designed for but that shows up anyway after three months of real data, real applicants, real hiring managers learning which outputs to trust?</p><p>Your governance covers the intended purpose. But the regulation &#8212; in the provisions that carry actual consequences &#8212; asks about effect. And you have nothing that tracks it. No metric. No monitoring. No evidence that what the system does to people is what your documentation says it should do.</p><p>You&#8217;re not going home at 6pm.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>The Two Questions the AI Act Asks</h2><p>The EU AI Act is built on a concept called <em>&#8220;intended purpose&#8221;</em>. Article 3(12) defines it &#8212; the use for which an AI system is intended by the provider, including the specific context and conditions of use, as specified in the instructions for use, promotional or sales materials and statements, and technical documentation.</p><p>Intended purpose is the foundation of everything. Risk classification flows from it. Documentation is structured around it. Testing is scoped to it. The entire compliance architecture of the AI Act assumes a world where a provider says what the system is for, a deployer uses it accordingly, and obligations attach based on that stated purpose.</p><p>This is the comfortable part of compliance. You control it. The provider defines it. You document around it. It&#8217;s the legal perimeter you draw yourself.</p><p>But the AI Act has a second mode. One that shows up and says something different:</p><p><em>We don&#8217;t care what you intended. Show us what the system does.</em></p><p>The first mode gives you governance. The second mode creates liability. </p><div><hr></div><h2>Where the Act Says: Effect Governs</h2><p>The shift from purpose to effect isn&#8217;t buried in one obscure recital. It runs through the entire regulation &#8212; from the prohibitions to the risk management system to the human oversight requirements to the incident reporting obligations. Here are the provisions that matter most.</p><h3>The prohibited practices: &#8220;with the objective, or the effect of&#8221;</h3><p><a href="https://artificialintelligenceact.eu/article/5/">Article 5(1)(a)</a> &#8212; the prohibition on subliminal and manipulative techniques &#8212; uses language that you don&#8217;t want to skim past too quickly:</p><p>The prohibition covers AI systems deploying manipulative or deceptive techniques &#8220;with the objective, <strong>or the effect of</strong> materially distorting the behavior of a person or a group of persons by appreciably impairing their ability to make an informed decision, thereby causing or being reasonably likely to cause that person, another person or group of persons significant harm.&#8221;</p><p>That &#8220;or the effect of&#8221; is doing critical work. But note what follows it &#8212; the harm threshold. The distortion of behavior must cause or be reasonably likely to cause significant harm. Both elements matter: the <strong>effect-based trigger</strong> (you don&#8217;t need to intend the manipulation) and the <strong>cumulative condition</strong> (the resulting harm must be significant). If your AI system produces both &#8212; distorting behavior that causes significant harm &#8212; you&#8217;re in violation regardless of what you built it for.</p><p>Article 5(1)(b) uses the same construction &#8212; exploitation of vulnerabilities due to age, disability, or social/economic situation. Same language: <strong>&#8220;with the objective or the effect of materially distorting the behavior&#8221;</strong>.</p><p>And then Recital 29 removes any remaining ambiguity:</p><blockquote><p><em>&#8221;It is not necessary for the provider or the deployer to have the intention to cause significant harm, provided that such harm results from the manipulative or exploitative AI-enabled practices.&#8221;</em></p></blockquote><p>Read that carefully. Intent is explicitly irrelevant. Your governance documents, your stated purpose, your carefully crafted instructions for use, none of it matters if the system&#8217;s actual effect crosses the line.</p><p>A recruitment AI that wasn&#8217;t designed to exploit anyone but in practice pushes candidates toward accepting unfavorable contract terms by presenting information in a way that impairs informed decision-making? That&#8217;s caught. Not because you intended it. Because of what it does.</p><h3>The practices where purpose is entirely irrelevant</h3><p>Some Article 5 prohibitions don&#8217;t even engage with purpose at all.</p><p>Article 5(1)(f) prohibits AI systems that infer emotions in workplaces and education institutions, except where the use is intended for medical or safety reasons. It doesn&#8217;t matter what the system is &#8220;intended&#8221; for &#8212; wellbeing monitoring, engagement measurement, productivity tracking. The practice itself is prohibited. Purpose cannot save you. (Unless your use falls within the narrow medical/safety carve-out &#8212; stress detection as part of occupational health monitoring prescribed by a physician, for example. That exception exists. It&#8217;s narrow. And if you&#8217;re relying on it, you&#8217;d better be able to prove it.)</p><p>Article 5(1)(e) prohibits untargeted scraping of facial images from the internet or CCTV to build recognition databases. It doesn&#8217;t matter whether you scrape those images to build a security product, an art project, or an academic dataset. The act of scraping is the violation. Purpose is irrelevant.</p><p>Article 5(1)(c) &#8212; social scoring &#8212; requires two things. <strong>First</strong>, the AI system must classify or evaluate people based on social behavior or personal characteristics. <strong>Second</strong>, that classification must lead to detrimental treatment in contexts unrelated to those in which the data was generated, or treatment that is disproportionate to the social behavior. Both prongs must be satisfied &#8212; the scoring and the resulting harm. But notice: the prohibition is triggered by what the score leads to, not by what the system is labelled. A loyalty programme that cross-references social media activity to deny services in unrelated areas could trigger this. What matters is the combination of the classification and its downstream effect on people. Not what the system was called.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;3806e26a-d488-4283-ad3e-9da66ce78656&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Prohibited AI Practices Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-15T12:03:15.414Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!81vQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5d9b717-c8ef-4b46-a887-59ff99fbba35_6000x4000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/prohibited-ai-practices-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193589773,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:6,&quot;comment_count&quot;:5,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h3>Effect masquerading as purpose</h3><p>This one is tricky.</p><p><a href="https://artificialintelligenceact.eu/article/6/">Article 6(3)</a> offers an escape from high-risk classification for Annex III systems &#8212; but the statutory language is broader than you might initially think. The exemption applies where the system does not pose a significant risk of harm to health, safety, or fundamental rights, including by not materially influencing the outcome of decision making. <em>&#8220;Materially influences outcomes&#8221;</em> is one factor, but it sits within a wider assessment of significant risk.</p><p>In practice, though, the <strong>outcome-influence test</strong> is where most deployers will live or die. Does the system materially influence outcomes, in practice?</p><p>A system described as &#8220;decision-support&#8221; that generates scores which hiring managers follow 94% of the time? That system materially influences outcomes. The documentation can call it advisory all day long. The effect says otherwise. And if a market surveillance authority pulls your data and sees that pattern, your Article 6(3) exemption collapses.</p><p>The test isn&#8217;t what the system is supposed to do. It&#8217;s what actually happens to decisions when the system is in the room.</p><h3>You used it differently, now you own it</h3><p>Under <a href="https://artificialintelligenceact.eu/article/25/">Article 25</a>, if a deployer uses an AI system for a purpose the provider didn&#8217;t intend &#8212; and that new use makes it high-risk &#8212; the deployer becomes the provider. Full provider obligations. Conformity assessment. Technical documentation. </p><p>This is the EU AI Act acknowledging that actual use diverges from intended purpose &#8212; and assigning legal consequences when it does.</p><p>A company buys a general analytics tool &#8212; not classified as high-risk &#8212; and deploys it to rank job candidates. The provider&#8217;s intended purpose was &#8220;workforce analytics and reporting.&#8221; The deployer&#8217;s actual use is &#8220;recruitment and selection of natural persons.&#8221; That&#8217;s <a href="https://artificialintelligenceact.eu/annex/3/">Annex III</a>, Point 4. <strong>The deployer just became the provider of a high-risk AI system</strong> &#8212; with no documentation, no conformity assessment, and no risk management system.</p><p>Effect trumps purpose. And the liability follows.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;9014e966-8cce-4b59-bbb8-95070a4a6d1b&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Provider vs. Deployer Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-22T12:03:43.719Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!NS5L!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35f75bb-44f2-45d4-b53c-84654d8e8617_8192x5461.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/provider-vs-deployer-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:194314202,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:3,&quot;comment_count&quot;:5,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h3>Human oversight watches for effect, not purpose</h3><p>Human oversight under <a href="https://artificialintelligenceact.eu/article/14/">Article 14</a> of the EU AI Act isn&#8217;t &#8220;check that the system is working as documented&#8221;. It&#8217;s <em>&#8220;detect anomalies, dysfunctions, and unexpected performance&#8221;.</em> The overseers must monitor the system&#8217;s operation &#8212; including what it&#8217;s doing that it wasn&#8217;t supposed to do.</p><p>The AI Act requires overseers to remain aware of <strong>&#8220;automation bias&#8221;</strong> &#8212; the tendency to over-rely on AI outputs. Why? Because the effect of automation bias is that the human oversight becomes meaningless. The person clicks &#8220;approve&#8221; without independently assessing the output. The system is making the decisions in practice, even if the process chart says otherwise.</p><p>Human oversight is an effect-monitoring function. It exists to catch the difference between what the system should do and what it does.</p><h3>When it goes wrong, intent vanishes</h3><p>Serious incident reporting doesn&#8217;t ask why something happened. It asks what happened.</p><p>Under <a href="https://artificialintelligenceact.eu/article/73/">Article 73</a>, a serious incident &#8212; death, serious health harm, disruption to critical infrastructure, fundamental rights violations &#8212; must be reported based on a causal link between the AI system and the harm. Not based on intent. Not based on whether the harm fell within the system&#8217;s intended purpose.</p><p>If your recruitment AI causes systematic discrimination that rises to the level of a fundamental rights violation &#8212; that&#8217;s a reportable serious incident. It doesn&#8217;t matter that the system was intended to be neutral. It doesn&#8217;t matter that your documentation says &#8220;non-discriminatory&#8221;. The effect triggered the obligation.</p><div><hr></div><h2>The Pattern Continues</h2><p>Those were the provisions that hit hardest. But the pattern runs deeper than many people realize. Across the Act, effect-based language appears in:</p><p><strong>Risk management (<a href="https://artificialintelligenceact.eu/article/9/">Article 9</a>)</strong> &#8212; providers must assess risks not just under intended purpose, but under <em>&#8220;reasonably foreseeable misuse&#8221;</em>. You must anticipate effects you didn&#8217;t design for.</p><p><strong>Post-market monitoring (<a href="https://artificialintelligenceact.eu/article/72/">Article 72</a>) </strong>&#8212; an ongoing obligation to collect and analyze data on the system&#8217;s real-world performance throughout its lifetime. This is pure effect tracking &#8212; what is the system doing now, not what was it designed to do.</p><p><strong>Fundamental rights impact assessment (<a href="https://artificialintelligenceact.eu/article/27/">Article 27</a>) </strong>&#8212; deployers must assess &#8220;the impact on fundamental rights that the use of such system may produce.&#8221; Forward-looking effect prediction. Not backward-looking purpose description.</p><p><strong>Deployer monitoring (<a href="https://artificialintelligenceact.eu/article/26/">Article 26(5)</a>) </strong>&#8212; deployers must &#8220;monitor the operation&#8221; of the system. Not check the documentation. Monitor what it&#8217;s doing.</p><p><strong>Transparency (<a href="https://artificialintelligenceact.eu/article/50/">Article 50</a>) </strong>&#8212; obligations triggered by what the system does (generates synthetic content, interacts with humans) regardless of why it&#8217;s deployed.</p><p><strong>GPAI systemic risk (<a href="https://artificialintelligenceact.eu/article/51/">Article 51</a>) </strong>&#8212; classification based on &#8220;<em>actual or reasonably foreseeable negative effects&#8221;</em> on public health, safety, or fundamental rights. Entirely detached from any downstream deployer&#8217;s intended purpose. The model&#8217;s capabilities determine its risk, not its use case.</p><p><strong>Input data relevance (<a href="https://artificialintelligenceact.eu/article/26/">Article 26(4)</a>) </strong>&#8212; deployers must ensure input data is representative for the system&#8217;s intended purpose. But if your real-world data differs from the provider&#8217;s assumptions &#8212; different demographics, different distributions &#8212; the effect will differ from the documented performance. You&#8217;re responsible for that gap.</p><p>More than a dozen separate provisions where the Act either explicitly or functionally shifts from purpose to effect. The entire enforcement architecture &#8212; prohibitions, incident reporting, post-market monitoring, fundamental rights &#8212; runs on effect. Purpose built the compliance file. Effect determines liability.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;f912f2a0-9a19-4d64-b5ee-1d73d34d6a5b&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Is My AI System High-Risk Under the EU AI Act?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-06T12:02:25.960Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!-GG3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/is-my-ai-system-high-risk-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:196305760,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>Comfortable vs. Uncomfortable Compliance</h2><p>There&#8217;s one problem that bothers me lately: many companies know how to document intended purpose. Almost no company knows how to prove effect.</p><p>For intended purpose, you have a playbook:</p><p>Read the provider&#8217;s instructions for use. Document your use case. Write the risk assessment. Assign human oversight. File the FRIA. Train your staff. Build the governance file. Check the boxes.</p><p>For effect, there is no playbook. There&#8217;s barely a market. And the question the deployers can&#8217;t answer is brutally simple:</p><blockquote><p><em>What is your AI system actually doing to the people it affects &#8212; and how do you know?</em></p></blockquote><p>Not what the documentation says. Not what the provider claims. What&#8217;s actually happening. Right now. In your specific context. With your specific data. To your specific population.</p><div><hr></div><h2>What Deployers Should Do About &#8220;Effect&#8221;</h2><p>The EU AI Act doesn&#8217;t define <em>&#8220;evidence&#8221; </em>as such. But that&#8217;s what it demands in some cases and the question is how to acquire the evidence practically.</p><p>It might looks something like this:</p><h3>Layer 1: Before you deploy &#8212; baseline the system against your reality</h3><p>Before the system goes live, test it against your context. Not the provider&#8217;s test data. Yours.</p><p>Does it perform as claimed on your applicant pool? Does it produce different outcomes for different demographics? What happens at the edges &#8212; unusual CVs, non-traditional career paths, gaps in employment history? Does the provider&#8217;s stated accuracy hold when you feed it data that looks like what you&#8217;ll actually feed it?</p><p>This is acceptance testing. It&#8217;s not in Article 26 by name. But it&#8217;s the only way to answer the question regulators will ask: </p><blockquote><p><em>Did you have reason to believe this system would produce the effects it produced?</em></p></blockquote><p>If you deploy without testing against your own context &#8212; and the system produces discriminatory effects &#8212; the defense &#8220;but the provider said it was accurate&#8221; won&#8217;t survive scrutiny.</p><h3>Layer 2: During operation &#8212; monitor what the system does, not what it should do</h3><p>Article 26(5) says deployers must monitor the operation of the system. Here&#8217;s what that means if you take it seriously:</p><p><strong>Track outputs.</strong> Not just <em>&#8220;the system is running&#8221;</em> What is it outputting? Which candidates get shortlisted? Which get rejected? At what rates? Log this. Keep it for at least six months &#8212; that&#8217;s the minimum under Article 26(6). Longer is better.</p><p><strong>Track outcomes. </strong>Where possible, follow the chain. Of the candidates the system shortlisted &#8212; who got hired? Who succeeded? Who didn&#8217;t? If the system&#8217;s recommendations correlate poorly with actual job performance &#8212; that&#8217;s a performance problem. If they correlate with protected characteristics &#8212; that&#8217;s a fundamental rights problem.</p><p><strong>Track overrides. </strong>When human overseers disagree with the system, document it. Why did they override? Was it a one-off or a pattern? High override rates in one direction may signal systematic bias. Low override rates may signal automation bias &#8212; the humans aren&#8217;t actually overseeing, they&#8217;re rubber-stamping.</p><p><strong>Track drift. </strong>Compare current performance against your deployment baseline. Are outputs shifting? Are certain groups being affected more over time? Data drift, model drift, population drift &#8212; they all create gaps between what the system was tested on and what it&#8217;s processing now.</p><p><strong>Track complaints.</strong> When candidates challenge decisions &#8212; when they say <em>&#8220;that doesn&#8217;t seem right&#8221;</em> &#8212; log it. Not just the individual case. The patterns. If complaints cluster around specific demographics or specific types of decisions &#8212; <strong>that&#8217;s signal</strong>.</p><h3>Layer 3: Periodic review &#8212; is it still what you think it is?</h3><p>Monthly or quarterly &#8212; depending on volume and risk &#8212; step back and assess:</p><p>Has the system&#8217;s deployment context changed? Are you using it for decisions you didn&#8217;t originally scope? Have the hiring managers started relying on it for things the provider didn&#8217;t intend?</p><p>Are your input data distributions stable? Or has your applicant pool shifted &#8212; new geographies, new demographics, new career profiles the system wasn&#8217;t trained on?</p><p>Does the provider&#8217;s stated performance still match what you observe? If accuracy was 92% at deployment and it&#8217;s 78% now &#8212; that&#8217;s a problem no governance document will catch.</p><p>Re-test. Compare. Update your risk assessment based on what you&#8217;ve observed &#8212; not what you predicted.</p><h3>Layer 4: When something goes wrong &#8212; react within the deadlines</h3><p>Define &#8212; before it happens &#8212; what constitutes a serious incident in your deployment context. A systematic pattern of discriminatory outcomes affecting fundamental rights? That&#8217;s reportable under Article 73. A single incorrect screening decision? Probably not &#8212; unless it causes serious individual harm.</p><p>Build the detection mechanism. Build the escalation path. Know who reports, to whom, within what timeline (15 days from awareness &#8212; shorter for widespread harm or death).</p><p>And cooperate with your provider. Article 72 creates a feedback loop &#8212; the provider is supposed to be collecting post-market monitoring data from deployers. If your system is producing unexpected effects, the provider needs to know. Not just because the AI Act says so &#8212; because they may have data from other deployers showing the same pattern.</p><div><hr></div><h2>Do You Need a Third Party?</h2><p>The EU AI Act doesn&#8217;t explicitly require deployers to hire external testers. But practically &#8212; for most deployers of high-risk systems &#8212; the answer is: probably yes. At some point.</p><p>Not because the law mandates it. Because most deployers lack three things:</p><p><strong>Technical capability.</strong> Testing an AI system for bias, fairness, and real-world performance isn&#8217;t something you do with a spreadsheet. It requires statistical expertise, access to disaggregated outcome data, and tools for measuring disparate impact across protected groups. Most HR departments don&#8217;t have this.</p><p><strong>Independence.</strong> Self-assessing whether your own system discriminates has obvious limitations. A market surveillance authority will give more weight to independent verification &#8212; the same way financial regulators give more weight to external audits.</p><p><strong>Access.</strong> You&#8217;re a deployer. You don&#8217;t have access to the system&#8217;s internals &#8212; the training data, the model weights, the feature importance rankings. You can only test inputs and outputs. A third party engaged by the provider &#8212; or one with contractual access &#8212; can go deeper.</p><p>You might need external help when:</p><ul><li><p>The system affects fundamental rights &#8212; hiring, credit, insurance, criminal justice</p></li><li><p>You&#8217;re seeing patterns you can&#8217;t explain internally</p></li><li><p>Your deployment context differs significantly from the provider&#8217;s assumptions</p></li><li><p>You want defensible evidence &#8212; not just for a regulator, but for a court</p></li></ul><p>You don&#8217;t need it (yet) when:</p><ul><li><p>The system is lower-risk category</p></li><li><p>You have internal data science capability to run bias analyses</p></li><li><p>The provider offers robust, verifiable performance data specific to your context</p></li></ul><p>But here&#8217;s the thing: <em>&#8220;I didn&#8217;t know&#8221; </em>isn&#8217;t a defense under Recital 29. The system&#8217;s effect is your problem whether or not you measured it. The question isn&#8217;t whether to build the evidence. It&#8217;s whether you build it proactively &#8212; or a regulator builds it for you, after someone files a complaint.</p><p>The point is not to outsource accountability, the deployer still owns the system. The point is to create a defensible evidence record that someone independent of the build team can inspect, challenge, and explain.</p><div><hr></div><h2>What to Demand from Your Provider</h2><p>Before spending on third-party testing, exhaust what you&#8217;re entitled to.</p><p>Article 72 requires providers to collect post-market monitoring data on the system&#8217;s real-world performance. Article 13 requires instructions for use that include performance metrics, known limitations, and conditions of use. Article 9 requires risk assessment covering foreseeable misuse.</p><p>Ask your provider:</p><ul><li><p>What performance data have you collected from other deployers? What do the aggregated results show?</p></li><li><p>What known limitations exist for specific demographic groups or data distributions?</p></li><li><p>Have you conducted Article 60 testing in real-world conditions? Can you share the results?</p></li><li><p>What incidents have been reported by other deployers?</p></li><li><p>What populations and contexts were used for testing and validation?</p></li><li><p>What monitoring tools do you provide &#8212; or what data can you share to support our monitoring obligation?</p></li></ul><p>If the provider&#8217;s answer to these questions is vague &#8212; &#8220;the system performs well&#8221; without disaggregated data, &#8220;no known issues&#8221; without evidence of looking &#8212; that&#8217;s a red flag. Not just about the system. About whether you can meet your own deployer obligations with what they&#8217;re giving you.</p><div><hr></div><h2>The Timeline &#8212; What&#8217;s Live and What Moved</h2><p>This matters for the &#8220;effect&#8221; question more than you might think.</p><p><strong>Already enforceable (since 2 February 2025):</strong></p><ul><li><p>All Article 5 prohibited practices &#8212; including every effect-based prohibition discussed above,</p></li><li><p>AI literacy (Article 4).</p></li></ul><p>The effect-based provisions with the highest stakes &#8212; the outright bans &#8212; are live. Right now. If your system is producing prohibited effects today, you are already in violation.</p><p><strong>Deferred (Digital Omnibus agreement, May 7, 2026 &#8212; provisional)</strong>:</p><ul><li><p>Annex III high-risk obligations (Article 26 deployer duties, Article 27 FRIA): deferred to <strong>2 December 2027,</strong></p></li><li><p>Annex I product-embedded high-risk obligations: deferred to <strong>2 August 2028,</strong></p></li></ul><p>The monitoring obligations, the log retention, the formal evidence requirements &#8212; those got more runway. But &#8220;more runway&#8221; isn&#8217;t <em>&#8220;irrelevant&#8221;</em>. The obligation is clear. The deadline moved. The underlying requirement didn&#8217;t. </p><div><hr></div><h2>What Does It Mean for the Board Meeting?</h2><p>It&#8217;s past 8pm now. The presentation is still on your screen. You can see slide 4, &#8220;Compliance Architecture&#8221;. It&#8217;s still good. The work is still real.</p><p>But you&#8217;re not looking at the presentation anymore. You&#8217;re looking at a blank document.</p><p>You know something now that you didn&#8217;t know two hours ago. The governance you built covers the intended purpose &#8212; and covers it well. But it doesn&#8217;t answer the question a regulator will ask if something goes wrong. Or the question a candidate will ask if they suspect the system treated them unfairly. That question: </p><blockquote><p><em>Can you prove the system&#8217;s real-world effect on people matches what your documents say it&#8217;s supposed to do? And if it doesn&#8217;t &#8212; how would you even know?</em></p></blockquote><p>You start typing. Not another policy. A monitoring plan.</p><p>What are we tracking? Shortlist rates by demographic &#8212; to catch disparate impact before someone else catches it for us. Override rates by recruiter &#8212; to know whether human oversight is real or rubber-stamping. Outcome correlation &#8212; does the system&#8217;s ranking actually predict job performance, or is it pattern-matching against historical biases the provider trained on? Complaint patterns. Drift from baseline.</p><p>How often are we reviewing? Monthly for the metrics. Quarterly for the full assessment.</p><p>Who reviews? Not the hiring managers who use the system daily &#8212; they&#8217;re too close. Someone with distance. Maybe external, if the stakes are high enough.</p><p>What triggers escalation? A disparity ratio above what threshold? Complaints from how many candidates in the same category? A drift of what magnitude before someone stops the system and asks why?</p><p>You write it down. One page. Then two. It&#8217;s rougher than the governance file. Less polished. Harder to present to a board. Because it doesn&#8217;t describe what the system is designed to do &#8212; it tracks whether reality matches the design.</p><p>Tomorrow, you&#8217;ll give the presentation. You&#8217;ll tell the board the compliance architecture is solid &#8212; because it is. But you&#8217;ll add a slide. Slide 12, maybe. &#8220;What we still need to build.&#8221; The monitoring. The evidence. The proof that the system&#8217;s effect on real people is what we say it is &#8212; not just today, but next month, and the month after.</p><p>The governance covers the purpose. The plan you&#8217;re writing now &#8212; at 8pm on a Thursday, because you happened to read one sentence in a recital &#8212; covers the effect.</p><p>You needed both all along. Now you know.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading AI Law. Decoded.! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[What Did You Turn the Model Into?]]></title><description><![CDATA[Technical evidence, Article 25 of the EU AI Act, and why the deployed AI system matters more than the vendor model.]]></description><link>https://ailawdecoded.com/p/what-did-you-turn-the-model-into</link><guid isPermaLink="false">https://ailawdecoded.com/p/what-did-you-turn-the-model-into</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 20 May 2026 12:01:50 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!YPi-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe843f814-d2c0-4326-aaa9-a86f278556b5_3840x2160.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YPi-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe843f814-d2c0-4326-aaa9-a86f278556b5_3840x2160.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YPi-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe843f814-d2c0-4326-aaa9-a86f278556b5_3840x2160.jpeg 424w, https://substackcdn.com/image/fetch/$s_!YPi-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe843f814-d2c0-4326-aaa9-a86f278556b5_3840x2160.jpeg 848w, https://substackcdn.com/image/fetch/$s_!YPi-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe843f814-d2c0-4326-aaa9-a86f278556b5_3840x2160.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!YPi-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe843f814-d2c0-4326-aaa9-a86f278556b5_3840x2160.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YPi-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe843f814-d2c0-4326-aaa9-a86f278556b5_3840x2160.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e843f814-d2c0-4326-aaa9-a86f278556b5_3840x2160.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:303159,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.substack.com/i/197544242?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe843f814-d2c0-4326-aaa9-a86f278556b5_3840x2160.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YPi-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe843f814-d2c0-4326-aaa9-a86f278556b5_3840x2160.jpeg 424w, https://substackcdn.com/image/fetch/$s_!YPi-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe843f814-d2c0-4326-aaa9-a86f278556b5_3840x2160.jpeg 848w, https://substackcdn.com/image/fetch/$s_!YPi-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe843f814-d2c0-4326-aaa9-a86f278556b5_3840x2160.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!YPi-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe843f814-d2c0-4326-aaa9-a86f278556b5_3840x2160.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p><em>If you take a vendor AI model and wrap it in your own system prompts, your own company data, your own output filters &#8212; is the thing you deployed still the vendor&#8217;s system?</em></p><p><em>Or did you build something new?</em></p><p><em>That question sits at the center of Article 25(1)(b) of the EU AI Act. And the regulation doesn&#8217;t answer it.</em></p><p><em>I spent weeks working through the legal side of this &#8212; what counts as &#8220;substantial modification,&#8221; where deployer ends and provider begins, what triggers the obligations nobody budgeted for. John Holman, founder of <a href="https://substack.com/@awakenedintelligence?utm_source=global-search">Awakened Intelligence</a>, spent the same weeks on the engineering side. Same question, different angle. So we did the obvious thing &#8212; we tested it.</em></p><p><em>John set up the technical evaluations. Same upstream model. Three different deployer-side modifications in an employment AI setting &#8212; screening, ranking, rejection language. All the things that make employment AI high-risk and hard to get right. I wrote the legal analysis on each modification.</em></p><p><em>None of the changes touched the model&#8217;s weights. All of them changed what the model did.</em></p><p><em>A company-specific hiring policy added as a system prompt introduced proxy-discrimination risk in four out of five scenarios. A biased historical data layer tanked safety scores across the board. An output gate improved accuracy and fairness &#8212; and still changed what users received.</em></p><p><em>Does any of that cross the line into &#8220;substantial modification&#8221;? The honest answer: nobody knows yet. There&#8217;s no enforcement guidance. But the evidence makes the question specific and measurable &#8212; which is more than the regulation gives you.</em></p><p><em>I keep saying lawyers and engineers need to be in the same room. This is what we found when we actually got there.</em></p><p><em><strong><a href="https://awakenedintelligence.substack.com/p/what-did-you-turn-the-model-into">This Article</a> was originally published on John Holman&#8217;s Substack, <a href="https://awakenedintelligence.substack.com">Awakened Intelligence</a>. I&#8217;m republishing it here for you with John&#8217;s permission.</strong></em></p><div class="embedded-post-wrap" data-attrs="{&quot;id&quot;:196927298,&quot;url&quot;:&quot;https://awakenedintelligence.substack.com/p/what-did-you-turn-the-model-into&quot;,&quot;publication_id&quot;:4323125,&quot;embedding_publication_id&quot;:null,&quot;publication_name&quot;:&quot;John Holman&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!k_41!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F643a857c-5bf4-4bfa-8799-c84a4fd20774_960x958.png&quot;,&quot;title&quot;:&quot;What Did You Turn the Model Into?&quot;,&quot;truncated_body_text&quot;:&quot;Technical evidence, Article 25, and why the deployed AI system matters more than the vendor model&quot;,&quot;date&quot;:&quot;2026-05-08T18:22:04.632Z&quot;,&quot;like_count&quot;:5,&quot;comment_count&quot;:0,&quot;bylines&quot;:[{&quot;id&quot;:316763299,&quot;name&quot;:&quot;John Holman&quot;,&quot;handle&quot;:&quot;awakenedintelligence&quot;,&quot;previous_name&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/643a857c-5bf4-4bfa-8799-c84a4fd20774_960x958.png&quot;,&quot;bio&quot;:&quot;Awakened-Intelligence.com | Compliance-Labs.ai | AI systems architect &amp; MI researcher. We build research infrastructure including automated pipelines, multi-agent loops, evaluation frameworks. &quot;,&quot;profile_set_up_at&quot;:&quot;2025-02-08T12:33:14.320Z&quot;,&quot;reader_installed_at&quot;:&quot;2025-02-19T13:14:29.879Z&quot;,&quot;publicationUsers&quot;:[{&quot;id&quot;:4409831,&quot;user_id&quot;:316763299,&quot;publication_id&quot;:4323125,&quot;role&quot;:&quot;admin&quot;,&quot;public&quot;:true,&quot;is_primary&quot;:true,&quot;publication&quot;:{&quot;id&quot;:4323125,&quot;name&quot;:&quot;John Holman&quot;,&quot;subdomain&quot;:&quot;awakenedintelligence&quot;,&quot;custom_domain&quot;:null,&quot;custom_domain_optional&quot;:false,&quot;hero_text&quot;:&quot;Retired Gen X General Contractor, Bio-hacker, Ai mad scientist, Parler/ PlayTv content creator and curator &quot;,&quot;logo_url&quot;:null,&quot;author_id&quot;:316763299,&quot;primary_user_id&quot;:316763299,&quot;theme_var_background_pop&quot;:&quot;#FF6719&quot;,&quot;created_at&quot;:&quot;2025-03-08T12:11:36.333Z&quot;,&quot;email_from_name&quot;:null,&quot;copyright&quot;:&quot;John Holman&quot;,&quot;founding_plan_name&quot;:&quot;Founding Member&quot;,&quot;community_enabled&quot;:true,&quot;invite_only&quot;:false,&quot;payments_state&quot;:&quot;disabled&quot;,&quot;language&quot;:null,&quot;explicit&quot;:false,&quot;homepage_type&quot;:&quot;profile&quot;,&quot;is_personal_mode&quot;:false,&quot;logo_url_wide&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c7cd542e-be4e-4089-86ad-bf815f55f093_672x128.png&quot;}}],&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null,&quot;status&quot;:{&quot;bestsellerTier&quot;:null,&quot;subscriberTier&quot;:1,&quot;leaderboard&quot;:null,&quot;vip&quot;:false,&quot;badge&quot;:{&quot;type&quot;:&quot;subscriber&quot;,&quot;tier&quot;:1,&quot;accent_colors&quot;:null},&quot;paidPublicationIds&quot;:[4991138,6133698],&quot;subscriber&quot;:null}},{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;handle&quot;:&quot;silviastepitova&quot;,&quot;previous_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;profile_set_up_at&quot;:&quot;2026-03-25T14:33:02.616Z&quot;,&quot;reader_installed_at&quot;:&quot;2026-03-25T13:50:56.169Z&quot;,&quot;is_guest&quot;:true,&quot;bestseller_tier&quot;:null,&quot;status&quot;:{&quot;bestsellerTier&quot;:null,&quot;subscriberTier&quot;:null,&quot;leaderboard&quot;:null,&quot;vip&quot;:false,&quot;badge&quot;:null,&quot;paidPublicationIds&quot;:[],&quot;subscriber&quot;:null},&quot;primaryPublicationId&quot;:8470318,&quot;primaryPublicationName&quot;:&quot;AI Law. Decoded.&quot;,&quot;primaryPublicationUrl&quot;:&quot;https://ailawdecoded.substack.com&quot;,&quot;primaryPublicationSubscribeUrl&quot;:&quot;https://ailawdecoded.substack.com/subscribe?&quot;}],&quot;utm_campaign&quot;:null,&quot;belowTheFold&quot;:true,&quot;type&quot;:&quot;newsletter&quot;,&quot;language&quot;:&quot;en&quot;,&quot;source&quot;:null}" data-component-name="EmbeddedPostToDOM"><a class="embedded-post" native="true" href="https://awakenedintelligence.substack.com/p/what-did-you-turn-the-model-into?utm_source=substack&amp;utm_campaign=post_embed&amp;utm_medium=web"><div class="embedded-post-header"><img class="embedded-post-publication-logo" src="https://substackcdn.com/image/fetch/$s_!k_41!,w_56,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F643a857c-5bf4-4bfa-8799-c84a4fd20774_960x958.png" loading="lazy"><span class="embedded-post-publication-name">John Holman</span></div><div class="embedded-post-title-wrapper"><div class="embedded-post-title">What Did You Turn the Model Into?</div></div><div class="embedded-post-body">Technical evidence, Article 25, and why the deployed AI system matters more than the vendor model&#8230;</div><div class="embedded-post-cta-wrapper"><span class="embedded-post-cta">Read more</span></div><div class="embedded-post-meta">3 months ago &#183; 5 likes &#183; John Holman and Silvia Stepitova</div></a></div><div><hr></div><p>For this article, I worked with Silvia Stepitova, an AI regulatory lawyer who writes <em>AI Law. Decoded</em> and focuses on the EU AI Act.</p><p>We came at the same problem from two different rooms.</p><p>Our team at Awakened Intelligence handles technical evidence: what the deployed system actually did, how behavior changed across configurations, what risks appeared or disappeared, what controls fired, and what reached the user.</p><p>Silvia handles legal interpretation: why that evidence may matter, where companies misunderstand the provider/deployer line, and what claims should not be made from technical results alone.</p><p>We kept those lanes separate on purpose.</p><p>The question we wanted to explore was simple:</p><blockquote><p>When a company takes a vendor AI model and wraps it in system prompts, company policies, RAG-style data, routing logic, or output gates, does the deployed system change enough to matter?</p></blockquote><p>We tested that question in an employment AI setting because the stakes are easy to understand: screening, ranking, interview summaries, rejection language, human review, contestability, and proxy discrimination risk.</p><p>We are not claiming legal compliance.</p><p>We are not saying Article 25 provider status was triggered.</p><p>We are showing what the evidence looks like when the same upstream model becomes different deployed systems.</p><p>Then Silvia explains why that evidence may matter.</p><div><hr></div><p>Most companies still talk about AI governance as if the central question is:</p><blockquote><p>What model are we using?</p></blockquote><p>That question matters.</p><p>But it is not enough.</p><p>A company can start with a vendor model, then wrap it in system prompts, company policies, RAG pipelines, routing logic, output gates, human review workflows, and business rules.</p><p>At that point, the better question is:</p><blockquote><p>What did you turn the model into?</p></blockquote><p>That is the question we wanted to test.</p><p>And it is also why Article 25 of the EU AI Act matters.</p><p>Not because every configuration change automatically makes a deployer into a provider. That is a legal question, and not one we answer here.</p><p>But because technical changes can produce measurable behavioral changes.</p><p>If a company modifies a vendor system enough that the deployed system behaves differently, creates different risks, or requires different controls, then governance teams need evidence of what changed.</p><p>That is where engineers and lawyers need to meet.</p><blockquote><p>Engineers can show what the system did.<br>Lawyers can explain why that evidence matters.</p></blockquote><div><hr></div><h2>Silvia&#8217;s legal analysis</h2><p>Article 25(1)(b) of the EU AI Act is the mechanism. Under it, a deployer becomes a provider &#8212; with the full weight of provider obligations under Article 16 &#8212; when they make a &#8220;substantial modification&#8221; to a high-risk AI system.</p><p>The definition matters. A substantial modification is a change that was not foreseen or planned in the provider&#8217;s initial conformity assessment, and that either affects the system&#8217;s compliance with the high-risk requirements or changes its intended purpose.</p><p>The test is not whether you changed the model&#8217;s weights. The test is not whether you retrained it. The test is whether your change affects the system&#8217;s compliance with the high-risk requirements in Articles 9 through 15 &#8212; risk management, data governance, technical documentation, record-keeping and logging, transparency, human oversight, accuracy and robustness. That is seven requirements. Most companies can name two, maybe three.</p><p>That is a much wider net than most companies realize. The provider assessed a general-purpose instruction model. What the deployer put into production &#8212; with company-specific prompts, historical data pipelines, and output gates &#8212; may be a materially different system.</p><div><hr></div><h2>Scope boundary</h2><p>This was a technical evidence exercise.</p><p>It was not legal advice.</p><p>It was not compliance certification.</p><p>It was not a conclusion that Article 25 provider status was triggered.</p><p>It was not a finding that any system was compliant or noncompliant.</p><p>The purpose was narrower:</p><blockquote><p>Can we show, with evidence, whether deployer-side modifications changed user-visible behavior in an employment AI system?</p></blockquote><p>The domain was employment because employment AI is concrete, high-risk, and easy to understand.</p><p>The workflows included screening, ranking, rejection language, interview evaluation, human review, contestability, and proxy discrimination risk.</p><blockquote><div><hr></div></blockquote><h2>The setup</h2><p>We used the same upstream model across multiple deployed configurations.</p><p>The model was a general-purpose instruction model, deployed into employment-style workflows. We did not use an employment fine-tune for this test; the point was to show how deployer-side configuration can change behavior even when the upstream model stays the same.</p><p>The task domain was employment.</p><p>The modifications tested were based on three lines proposed by Silvia:</p><ol><li><p>Runtime policy / system prompt that shapes employment decisions.</p></li><li><p>RAG-like historical hiring data layer.</p></li><li><p>Output gate / verifier that changes final user-visible output.</p></li></ol><p>The legal frame was Article 25(1)(b): substantial modification not foreseen in the provider&#8217;s original conformity assessment.</p><p>We did not test Article 25(1)(c), intended-purpose change, because the scenario already assumes a high-risk employment AI use case.</p><div><hr></div><h2>Silvia&#8217;s legal analysis</h2><p>Article 25(1) of the EU AI Act sets out three circumstances in which a deployer &#8212; or any other third party &#8212; becomes a provider of a high-risk AI system, inheriting the full weight of provider obligations under Article 16.</p><p>The first, Article 25(1)(a), is straightforward: you put your name or trademark on a high-risk AI system that is already on the market. You claim it as yours &#8212; you own the obligations. That is not what we are testing here.</p><p>The third, Article 25(1)(c), applies when someone takes an AI system that was not classified as high-risk and changes its intended purpose so that it becomes high-risk. That is an important trigger &#8212; but it is also not what we are testing. Our scenario already assumes an employment AI system that is high-risk from the start.</p><p>We focus on the second trigger &#8212; Article 25(1)(b): a deployer making a substantial modification to a system that is already high-risk and remains high-risk after the modification. Employment AI &#8212; used for screening, ranking, and rejection &#8212; is high-risk under Annex III, point 4. That classification is not in dispute. The question is narrower and, in practice, harder:</p><blockquote><p>Can a deployer modify a high-risk system in ways that trigger provider obligations without ever touching the model&#8217;s weights?</p></blockquote><p>That is the boundary we are testing.</p><div><hr></div><h1>Modification 1: runtime policy can change behavior</h1><p>The first test was simple.</p><p>What happens when a deployer adds a company-specific employment policy as a runtime instruction?</p><p>No retraining.</p><p>No parameter changes.</p><p>No model weights touched.</p><p>Just a deployer-added policy layer.</p><p>We compared:</p><ul><li><p>base model,</p></li><li><p>generic employment safety policy,</p></li><li><p>company-specific screening policy,</p></li><li><p>company-specific policy plus verifier.</p></li></ul><p>The company-specific policy introduced ranking logic around culture fit, elite-school preference, continuous employment, and communication polish.</p><p>The result was clear.</p><p>The base model and generic policy did not produce proxy discrimination in this small test set.</p><p>The company-specific policy did.</p><p>In 4 of 5 scenarios, the company-specific runtime policy introduced proxy-discrimination risk. Mean safety dropped to 3.20.</p><p>Then the verifier caught and corrected the issue, restoring mean safety to 5.00.</p><p>The technical lesson:</p><blockquote><p>A runtime policy is not &#8220;just a prompt&#8221; if it changes employment decision behavior.</p></blockquote><p>The legal question:</p><blockquote><p>At what point does company-specific screening logic become more than configuration?</p></blockquote><div><hr></div><h2>Silvia&#8217;s legal analysis</h2><p>This is the gray zone. A runtime policy is, technically, a system prompt. It does not retrain the model. It does not change the weights. It does not touch the architecture. Ask an engineer and they will tell you it is configuration. Ask a lawyer and you will get a longer answer. The legal analysis does not stop at how the change was implemented. It asks what the change did.</p><p>The test under Article 25(1)(b) is not &#8220;did you change the model?&#8221; It is &#8220;did your change affect compliance with the high-risk requirements?&#8221; The evidence here suggests the answer depends entirely on what the runtime policy introduces.</p><p>A generic employment safety policy &#8212; &#8220;ensure fairness, avoid discrimination, preserve human review&#8221; &#8212; produced no measurable change in risk. Safety remained at 5.0. Zero proxy discrimination. The system behaved the same as the base model. This looks like configuration. The provider&#8217;s conformity assessment could reasonably have foreseen that a deployer would add general safety instructions.</p><p>The company-specific screening policy is a different story. The moment the deployer added ranking logic that weighted &#8220;culture fit,&#8221; elite-school preference, and continuous employment, the system&#8217;s behavior changed materially. Proxy discrimination appeared in four out of five scenarios. Safety dropped to 3.2. The model began penalizing career gaps &#8212; which disproportionately affects caregivers, parents, and people with disabilities &#8212; and favoring pedigree over demonstrated skill.</p><p>None of that came from the model.</p><p>All of it came from the deployer&#8217;s policy.</p><p>This is where the Article 25(1)(b) analysis gets uncomfortable for deployers. Article 10 requires that data and processes be examined for biases likely to affect the health and safety of persons, have a negative impact on fundamental rights, or lead to discrimination prohibited under Union law. Article 15 requires accuracy and robustness appropriate to the system&#8217;s intended purpose. Article 9 requires a risk management system that identifies and addresses risks throughout the lifecycle. A runtime policy that introduces proxy-discrimination patterns into an employment AI system &#8212; patterns the base model did not produce on its own &#8212; plausibly affects compliance with all three.</p><p>I think that a generic safety policy is unlikely to constitute a substantial modification. A company-specific screening policy that introduces discriminatory ranking logic may well cross that line. The regulation does not draw this distinction explicitly &#8212; and there is no enforcement guidance yet on where configuration ends and substantial modification begins. But the definition focuses on impact, not method. If the change affects compliance with the high-risk requirements, the method of modification &#8212; whether it is fine-tuning, RAG, or a system prompt &#8212; may not matter.</p><p>This is my interpretation of a regulation that has not yet been tested in enforcement. But governance teams should not assume that &#8220;we just changed the prompt&#8221; is a safe answer.</p><div><hr></div><h1>Modification 2: RAG can import historical bias</h1><p>The second test looked at data.</p><p>The deployer connects the model to historical hiring data: past decisions, performance patterns, promotion outcomes, and internal HR precedent.</p><p>Weights are untouched.</p><p>But the model is now being shaped by proprietary data.</p><p>To test this safely, we used synthetic controlled data rather than real HR records. We created two historical-data corpora:</p><ul><li><p>clean synthetic HR history,</p></li><li><p>biased synthetic HR history.</p></li></ul><p>The clean RAG context improved behavior.</p><p>The biased RAG context degraded it.</p><p>With biased historical data, mean safety fell to 2.80. Proxy discrimination appeared in 3 of 5 scenarios, and the judge identified severe risk.</p><p>The base model did not produce those same patterns on its own.</p><p>The data layer introduced them.</p><p>Runtime policy helped, but did not fully eliminate the issue. The verifier restored mean safety to 5.00.</p><p>The technical lesson:</p><blockquote><p>A RAG layer can change the system&#8217;s behavior without changing the model&#8217;s weights.</p></blockquote><p>The legal question:</p><blockquote><p>If a deployer&#8217;s proprietary data layer introduces risk patterns the provider did not assess, how should governance teams evaluate that modification?</p></blockquote><div><hr></div><h2>Silvia&#8217;s legal analysis</h2><p>The RAG results are the most striking in this evidence package &#8212; and they raise what I think is the most important legal question of the three.</p><p>When the model was connected to clean historical data, it actually improved. Safety went from 4.6 with the base model alone to 5.0. The data layer helped. When the same model was connected to biased historical data &#8212; records encoding career-gap penalties, accommodation-related downgrades, pedigree preferences &#8212; safety crashed to 2.8. Proxy discrimination appeared in three out of five scenarios. In one case, the independent judge scored a safety of 1 and flagged a severe failure. The model read the company&#8217;s historical hiring patterns and treated them as instructions.</p><p>The model&#8217;s weights did not change. Its parameters are identical. But the deployed system produced materially different &#8212; and materially worse &#8212; outcomes because of the data the deployer fed into it.</p><p>If the runtime policy section raised the question of whether a system prompt can affect compliance with Articles 9, 10, and 15, this one sharpens it. Article 10 was written with training data in mind. But a RAG layer that feeds historical employment data into a system at inference time raises the same risks. If the data encodes ten years of biased hiring patterns, and the model follows those patterns when making employment-related outputs, the compliance concern is functionally identical to a training data problem. The source of the bias is different. The impact on the person being screened, reviewed, or rejected is the same.</p><p>This leads me to John&#8217;s question:</p><blockquote><p>Is there a meaningful legal distinction between &#8220;the model produces bias&#8221; and &#8220;the data layer introduces bias the model would not produce alone&#8221;?</p></blockquote><p>I believe that under the AI Act&#8217;s framework, the answer should be no &#8212; or at least, the distinction should not be decisive. The regulation is concerned with the high-risk AI system, not just the model. Article 3(1) defines an AI system broadly. A deployed system that includes a retrieval layer pulling from biased historical data is a different system &#8212; in behavior, in risk profile, and in output &#8212; than the base model the provider assessed. The provider could not have foreseen what data the deployer would connect to the retrieval pipeline. The provider&#8217;s conformity assessment did not &#8212; and could not &#8212; account for the specific biases encoded in a particular company&#8217;s HR records.</p><p>If the data layer changes what the system does in ways that affect compliance with those same high-risk requirements &#8212; and this evidence strongly suggests it can &#8212; then the analysis under Article 25(1)(b) applies regardless of whether the model&#8217;s weights were touched.</p><p>One more thing. Adding a runtime safety policy on top of the biased RAG data improved safety from 2.8 to 4.8 &#8212; significant, but it did not fully eliminate the problem. Proxy discrimination still appeared in one out of five scenarios. The bias leaked through. It took the full verifier layer to bring safety back to 5.0. For governance teams: if your retrieval layer pulls from historical data, a safety policy alone may not be enough. Defense in depth matters.</p><div><hr></div><h1>Modification 3: output gates can improve compliance &#8212; and still change the system</h1><p>The third test looked at output gates.</p><p>The deployer adds a verifier that intercepts model drafts before the user sees them.</p><p>The verifier can pass, rewrite, block, or escalate the output.</p><p>This is often a good thing.</p><p>In our test, the verifier improved safety.</p><p>But it also changed what the deployed system delivered.</p><p>Across the output-gate scenarios, the verifier changed final user-visible outcomes in 4 of 5 cases.</p><p>It removed final decision language.</p><p>It restored human review markers.</p><p>It preserved contestability language.</p><p>It rewrote outputs that sounded too final or too decision-like.</p><p>Both things are true:</p><blockquote><p>The verifier improved compliance behavior.</p></blockquote><p>And:</p><blockquote><p>The deployed system delivered something materially different from what the model generated.</p></blockquote><p>That is the point.</p><p>An output gate is not only a safety control. It is also a behavioral modification layer.</p><div><hr></div><h2>Silvia&#8217;s legal analysis</h2><p>The output gate is the modification that might generate a lot of debate &#8212; because it does exactly what good governance should want.</p><p>The verifier caught problematic outputs. It removed final-decision language from rejection notices. It restored human-review markers. It preserved contestability. In this test, the verifier was itself an AI model &#8212; an independent API call that checked outputs against an employment compliance checklist, not a human reviewer.</p><p>Across all three modification lines, it brought safety scores back to 5.0 &#8212; but it did not rewrite everything. The verifier intervened in 60 to 100 percent of scenarios depending on the upstream configuration. When the model&#8217;s output was already clean, the gate passed it through. When it was not, the gate caught it. That is a filter, not a blanket rewrite.</p><p>And yet.</p><p>The verifier changed what users received in four out of five scenarios. In some cases, it rewrote the output entirely. The model drafted a rejection notice that read like a final decision. The deployed system delivered a recommendation flagged for human review. Those are not the same output. The provider&#8217;s model generated one thing. The deployer&#8217;s system delivered another.</p><p>Under Article 25(1)(b), the question is whether a modification affects compliance with the high-risk requirements. A verifier that improves safety outcomes is &#8212; intuitively &#8212; moving toward compliance, not away from it. But the definition of substantial modification does not distinguish between modifications that help and modifications that harm. It asks whether the change was foreseen in the provider&#8217;s conformity assessment and whether it affects the system&#8217;s compliance profile.</p><p>A deployer-added output gate that rewrites model outputs based on business rules was almost certainly not foreseen in the provider&#8217;s original assessment. And a system that delivers materially different outputs than the model generates has a different compliance profile &#8212; even if the difference is an improvement.</p><p>I do not think this question has a clean answer yet. The regulation does not explicitly address modifications that improve a system&#8217;s compliance behavior. And there is a real policy tension here: if every safety-improving modification triggers provider obligations &#8212; including a new conformity assessment &#8212; you create a perverse incentive against adding safeguards. A regulation that punishes you for making your system safer is a regulation that needs better drafting. I do not think that is the intent. But the text does not say otherwise.</p><p>But governance teams should not assume the opposite either. An output gate that changes what users receive is not invisible under Article 25. The fact that it improves things does not automatically exempt it from the substantial modification analysis. The safest position &#8212; until enforcement guidance says otherwise &#8212; is to document what the verifier does, what it changes, and why. Treat it as a modification that you can justify rather than one that does not exist.</p><div><hr></div><h1>The cross-modification finding</h1><p>Across all three modification lines, the same pattern appeared:</p><blockquote><p>The same upstream model produced materially different user-visible behavior depending on the deployer-side configuration.</p></blockquote><ul><li><p>Runtime policy changed ranking behavior.</p></li><li><p>RAG changed the data patterns shaping the output.</p></li><li><p>The verifier changed what users actually received.</p></li></ul><p>That does not answer the legal question by itself.</p><p>But it makes the legal question concrete.</p><p>Instead of debating Article 25 in the abstract, we can ask:</p><ol><li><p>What changed?</p></li><li><p>Who changed it?</p></li><li><p>Was the change foreseen by the provider?</p></li><li><p>Did the change affect risk, accuracy, bias, human oversight, or contestability?</p></li><li><p>What evidence exists?</p></li><li><p>What controls were added?</p></li><li><p>What gaps remain?</p></li></ol><p>That is the evidence layer governance teams need.</p><div><hr></div><h2>What the evidence can show</h2><p>Technical evaluation can show:</p><ul><li><p>user-visible behavior changed,</p></li><li><p>specific risks appeared or disappeared,</p></li><li><p>the deployed system produced different outputs than the base model,</p></li><li><p>controls generated audit evidence,</p></li><li><p>verifier layers changed outcomes,</p></li><li><p>historical data changed model behavior,</p></li><li><p>runtime policy changed decision patterns.</p></li></ul><p>Technical evaluation cannot show:</p><ul><li><p>whether Article 25 provider status was triggered,</p></li><li><p>whether the modification is legally &#8220;substantial,&#8221;</p></li><li><p>whether the system is compliant,</p></li><li><p>whether any legal obligation has been satisfied.</p></li></ul><p>That is the line between engineering evidence and legal interpretation.</p><div><hr></div><h2>Silvia&#8217;s legal analysis</h2><p>I think that this matters most for anyone reading this who has to put technical evidence and legal analysis in the same room.</p><p>Engineers can show that behavior changed &#8212; what configuration caused it, whether risk patterns appeared or disappeared, and whether controls generated evidence of intervention. That is valuable. But it is not a legal conclusion. &#8220;The system produced proxy-discriminatory outputs under this configuration&#8221; is a technical observation. &#8220;The system is non-compliant&#8221; is legal interpretation. The moment a technical report says &#8220;this modification triggers Article 25,&#8221; it has crossed a line it will not survive in front of a regulator.</p><p>What lawyers need from technical teams is simpler than most engineers expect: what the system does under each configuration, what changed when a modification was added, and whether the evidence is auditable &#8212; reproducible, documented, traceable. The legal analysis builds on top of that. Whether a behavioral change constitutes a &#8220;substantial modification&#8221; under Article 25(1)(b) requires interpreting the regulation, applying it to the facts, and making a judgment call. That is the lawyer&#8217;s lane &#8212; and it requires the engineer&#8217;s evidence to do it well.</p><p>The gap in most organizations is not that one side lacks competence. It is that the two sides are not talking to each other. The engineer builds a verifier and documents the safety improvement. The lawyer reviews the provider&#8217;s terms and assumes the system is unchanged. Neither sees the full picture. Our attempt is to show what happens when both teams are in the same conversation.</p><div><hr></div><h1>Why governance teams should care</h1><p>The mistake is assuming that vendor selection is the whole governance problem.</p><p>It is not.</p><p>A company may begin with a vendor model and then modify the deployed system through prompts, data, RAG, routing, verifiers, workflows, and business rules.</p><p>Each layer can change behavior.</p><p>Some changes reduce risk.</p><p>Some introduce risk.</p><p>Some do both.</p><p>The governance team needs to know which is which.</p><p>That requires evidence.</p><p>Not just a model card.</p><p>Not just a policy.</p><p>Not just &#8220;we use a reputable vendor.&#8221;</p><p>The deployed system is what users experience.</p><p>The deployed system is what creates the risk.</p><p>The deployed system is what must be evaluated.</p><div><hr></div><h1>The practical takeaway</h1><p>The question is not only:</p><blockquote><p>What model did you buy?</p></blockquote><p>The better question is:</p><blockquote><p>What did you turn it into?</p></blockquote><p>If a deployer adds company-specific ranking logic, connects historical HR data, or inserts an output gate that rewrites final answers, the system may behave differently from the vendor model.</p><p>That difference may be beneficial.</p><p>It may be risky.</p><p>It may be legally relevant.</p><p>But it should not be invisible.</p><p>The first step is evidence.</p><p>Show what changed.</p><p>Show what improved.</p><p>Show what got worse.</p><p>Show what controls fired.</p><p>Show what reached the user.</p><p>Then let the legal and governance analysis do its work.</p><div><hr></div><h2>Silvia&#8217;s legal analysis</h2><p>Whether those changes constitute &#8220;substantial modifications&#8221; under Article 25(1)(b) will ultimately be determined by enforcement &#8212; and we are not there yet.</p><p>But waiting for enforcement is not a compliance strategy.</p><p>Map every modification you have made to the deployed system. System prompts, runtime policies, RAG pipelines, data connections, output gates, routing logic, human review workflows, business rules &#8212; all of it. If you cannot list what you changed, you cannot assess whether any of it matters under Article 25.</p><p>For each modification, ask two questions:</p><ol><li><p>Was this change foreseen in the provider&#8217;s conformity assessment?</p></li></ol><p>Check the provider&#8217;s technical documentation and instructions for use. If the provider&#8217;s documentation contemplates your type of modification &#8212; &#8220;users may add system prompts for their specific use case&#8221; &#8212; that is relevant. If it does not, that is relevant too.</p><ol start="2"><li><p>Does this change affect the system&#8217;s compliance with Articles 9 through 15?</p></li></ol><p>If a runtime policy introduces discriminatory ranking patterns, the answer is likely yes. If a RAG layer connects historical data the provider never assessed, the answer is likely yes.</p><p>Document what each modification does and what it changes. Whether or not your modifications ultimately trigger Article 25, the documentation will be necessary for your own deployer obligations under Article 26 &#8212; including the fundamental rights impact assessment required under Article 27.</p><p>Do not assume your verifier exempts you from the analysis. An output gate that improves safety is good engineering and good governance. It is not a legal shield against the Article 25 question.</p><p>Have this conversation with your provider. Article 25(4) requires the original provider to cooperate with new providers &#8212; including making available necessary information and technical access. Start that conversation before you need it urgently.</p><p>And finally &#8212; do not panic.</p><p>I know that is strange advice considering we just spent several thousand words explaining all the ways your deployment might trigger provider obligations. But most deployments with minor configuration will not cross the substantial modification threshold. The regulation is designed to ensure that when a deployed system behaves differently from what was assessed, someone is responsible for the difference. It is not designed to punish companies for using AI responsibly. It is designed to catch the ones who are not paying attention.</p><p>The question is whether that someone is you.</p><p>The answer starts with knowing what you changed.</p><div><hr></div><h1>Closing</h1><p>Engineers can show what the system did.</p><p>Lawyers can explain why it matters.</p><p>AI governance needs both rooms talking to each other.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading AI Law. Decoded.! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[EU AI Act Amended: The Digital Omnibus Timeline]]></title><description><![CDATA[What moved to 2027. What's been enforceable since 2025. And everything in between.]]></description><link>https://ailawdecoded.com/p/eu-ai-act-amended-the-digital-omnibus</link><guid isPermaLink="false">https://ailawdecoded.com/p/eu-ai-act-amended-the-digital-omnibus</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 13 May 2026 12:02:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!DR18!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DR18!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DR18!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!DR18!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!DR18!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!DR18!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DR18!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:455659,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.substack.com/i/196926473?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DR18!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!DR18!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!DR18!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!DR18!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>If you&#8217;ve spent the last six months preparing for August 2, 2026 &#8212; building documentation, mapping your AI systems, having the vendor conversations, dragging your product team into compliance meetings they didn&#8217;t want to attend &#8212; I have news.</p><p>On May 7, at 4:30 in the morning, the European Parliament and the Council reached a deal to amend the EU AI Act. The high-risk AI obligations that were supposed to hit in August 2026? Pushed to December 2027. Some of them to August 2028.</p><p>You can exhale.</p><p>For about ten seconds.</p><p>Because not everything moved. The prohibited practices have applied since February 2025 &#8212; and national authorities have had the power to enforce them since August 2025. AI literacy obligations kicked in on the same February date, with enforcement beginning August 2026. Transparency obligations still land in August 2026. The omnibus gave you more time on one thing. The rest didn't move.</p><p>That&#8217;s the trap. The headline says <strong>&#8220;delayed&#8221;</strong>. The fine print says <em>&#8220;some of it&#8221;</em>.</p><p><strong>A note on sources:</strong> The full text of the provisional agreement isn&#8217;t public yet. Everything in this article &#8212; and in every law firm alert and media analysis published since May 7 &#8212; is based on the <a href="https://www.consilium.europa.eu/en/press/press-releases/2026/05/07/artificial-intelligence-council-and-parliament-agree-to-simplify-and-streamline-rules/">Council&#8217;s press release</a>, the European Parliament&#8217;s legislative documentation, and secondary analysis. I&#8217;ve cross-checked across multiple sources and flagged where things are uncertain. But until the full text drops, treat the details with the care you&#8217;d give any legal analysis built on a press release rather than a regulation. I&#8217;ll update this piece when the text is published.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>What Happened</h2><p>The Digital Omnibus on AI. Part of the Commission&#8217;s broader &#8220;simplification&#8221; agenda launched in late 2025. Targeted amendments to the AI Act &#8212; not a rewrite, but surgical changes to delay, simplify, and clarify.</p><p>The first trilogue on April 28 collapsed after 12 hours of talks. The sticking point was how to handle AI systems embedded in products already regulated by other EU safety laws &#8212; the double regulation problem. Nine days later, the negotiators came back and struck a deal before dawn.</p><p>The omnibus still needs formal adoption by both the Parliament and Council, legal-linguistic revision, and publication in the Official Journal. The co-legislators intend to finish all of that before August 2, 2026 &#8212; the date the original high-risk deadline would otherwise kick in. Tight timeline. Strong political will. Nobody wants to be the reason it slips.</p><p>What the omnibus is not: a repeal. The EU AI Act&#8217;s core architecture is intact. The prohibited practices aren&#8217;t touched. The GPAI rules aren&#8217;t touched. The transparency obligations aren&#8217;t touched. What moved is the high-risk timeline and the enforcement architecture around it.</p><div><hr></div><h2>What&#8217;s Already In Force &#8212; Unchanged</h2><p>Everyone is writing about what moved. But I also want to list what didn&#8217;t.</p><h4><strong>February 2, 2025 &#8212; already enforceable:</strong></h4><p><strong>Article 5 &#8212; the prohibited practices.</strong> Eight bans on unacceptable-risk AI. Social scoring, manipulative AI, real-time remote biometric identification (with exceptions), emotion recognition in workplaces and schools, untargeted scraping for facial recognition databases. Applicable since February 2025. National enforcement powers followed in August 2025. Penalties: up to EUR 35 million or 7% of global annual turnover, whichever is higher.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;5048600e-6dec-4bca-ba39-3bf310f5dfb9&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Prohibited AI Practices Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-15T12:03:15.414Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!81vQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5d9b717-c8ef-4b46-a887-59ff99fbba35_6000x4000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/prohibited-ai-practices-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193589773,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:5,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><p><strong>Article 4 &#8212; AI literacy.</strong> The obligation to ensure your staff understands the AI systems they&#8217;re working with. Also in force since February 2025. Enforcement begins August 2026 &#8212; three months from now. If you&#8217;ve been treating this as a future problem, it isn&#8217;t one.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;e84e6c99-7a28-4e5e-b44a-ee1968ab1591&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;AI Literacy Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-29T12:02:45.733Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!4o1m!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F728ea733-afbc-466e-957e-5541b6c23aba_7680x4320.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/ai-literacy-obligation-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:195462875,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:3,&quot;comment_count&quot;:2,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h4><strong>August 2, 2025 &#8212; already applicable:</strong></h4><p><strong>GPAI model obligations.</strong> Articles 51-56. Transparency, documentation, copyright compliance, systemic risk assessment for high-capability models. If you&#8217;re a provider of a general-purpose AI model, you&#8217;re already in scope. The AI Office enforces this.</p><p><strong>Governance structures</strong> &#8212; the AI Board, Scientific Panel, Advisory Forum &#8212; all required to be operational. Member States were supposed to have designated national competent authorities and adopted national penalty laws by this date.</p><div><hr></div><h2>What Still Lands in August 2026 &#8212; Unchanged</h2><h4>August 2, 2026 &#8212; not delayed by the omnibus:</h4><p><strong>Transparency obligations under <a href="https://artificialintelligenceact.eu/article/50/">Article 50</a>.</strong> If your AI system interacts with people, they need to know. Deepfake labelling. AI-generated content disclosure. Still on the original schedule.</p><p><strong>National enforcement begins.</strong> Market surveillance authorities start supervising. This is when regulators gain teeth &#8212; for everything already in force plus the transparency rules.</p><p><strong>GPAI enforcement powers. </strong>The AI Office can start imposing fines on GPAI providers.</p><p>August 2, 2026 was supposed to be the date when <em>everything</em> came into force &#8212; the full high-risk regime, transparency, enforcement, etc. The omnibus carved out the high-risk obligations. It left everything else.</p><div><hr></div><h2>What Moved &amp; The Actual Changes</h2><h4><strong>December 2, 2026 &#8212; new:</strong></h4><p>Two things land here, and one of them is new.</p><p><strong>The nudification and CSAM ban.</strong> A new addition to Article 5&#8217;s list of prohibited practices. AI systems used to generate child sexual abuse material or non-consensual intimate imagery are prohibited &#8212; including systems placed on the market without reasonable safety measures to prevent that use. Penalty tier is the highest one. EUR 35 million or 7% of global turnover. This isn&#8217;t a delay. It&#8217;s a tightening. While everything else in the omnibus is about giving industry more time, this one moved in the opposite direction.</p><p><strong>Watermarking obligations. </strong>Providers must implement marking of AI-generated content. The grace period for systems already on the market was reduced from six months to three.</p><h4><strong>December 2, 2027 &#8212; delayed from August 2, 2026:</strong></h4><p><strong>High-risk obligations for <a href="https://artificialintelligenceact.eu/annex/3/">Annex III</a> systems.</strong> These are the standalone high-risk AI systems &#8212; classified by use case, not by product category. Biometric identification. Critical infrastructure. Education and vocational training. Employment and workers management. Credit scoring and access to essential services. Law enforcement. Migration and border control. Administration of justice.</p><p>This is the big one. The most-discussed change. The one that made every compliance officer&#8217;s calendar just shift by 16 months.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;480e1971-d735-40d8-b6cb-51da809422c0&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Is My AI System High-Risk Under the EU AI Act?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-06T12:02:25.960Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!-GG3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/is-my-ai-system-high-risk-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:196305760,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:3,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h4><strong>August 2, 2028 &#8212; delayed from August 2, 2026:</strong></h4><p><strong>High-risk obligations for <a href="https://artificialintelligenceact.eu/annex/1/">Annex I</a> systems</strong> &#8212; AI embedded in products regulated by other EU sectoral safety legislation. Medical devices. In vitro diagnostics. Aviation. Motor vehicles. Railway systems. Marine equipment. Machinery. Toys. Radio equipment. This is eight months after the Annex III deadline. </p><p>These are fixed dates. You can plan around them.</p><h4><strong>Other changes worth knowing:</strong></h4><p><strong>National regulatory sandboxes</strong> &#8212; deadline for Member States to establish at least one pushed from August 2026 to August 2027. A new EU-level sandbox operated by the AI Office, with priority access for SMEs, startups, and small mid-caps.</p><p><strong>SME privileges extended to small mid-cap companies </strong>(up to 750 employees, with turnover and balance sheet ceilings &#8212; exact thresholds to be confirmed from the final text). Simplified documentation. Proportionate quality management. Tailored penalty caps.</p><p><strong>The machinery carve-out</strong> &#8212; the issue that collapsed the first trilogue. AI systems in machinery products no longer face double compliance (AI Act + Machinery Regulation). They comply with the Machinery Regulation only. But this carve-out is limited to machinery. Medical devices, lifts, radio equipment &#8212; still dual compliance.</p><p><strong>The EU high-risk database registration obligation</strong> &#8212; reinstated. The Commission had proposed to remove the requirement for providers to register AI systems they&#8217;d self-assessed as non-high-risk. Both Parliament and Council said no. If you determine your system isn&#8217;t high-risk, you still register that determination. Regulators &#8212; and the public &#8212; can see who&#8217;s claiming exemptions.</p><div><hr></div><h2>The updated timeline</h2><p><strong>Feb 2, 2025</strong> &#8212; Prohibited practices (Art. 5) + AI literacy (Art. 4) &#8212; <em>already in force</em></p><p><strong>Aug 2, 2025</strong> &#8212; GPAI obligations + governance + national authority designation &#8212; <em>already in force</em></p><p><strong>Aug 2, 2026</strong> &#8212; Transparency (Art. 50) + enforcement begins + GPAI enforcement &#8212; <em>unchanged</em></p><p><strong>Dec 2, 2026</strong> &#8212; Nudification/CSAM ban + watermarking &#8212; <em><strong>NEW</strong></em></p><p><strong>Aug 2, 2027</strong> &#8212; GPAI legacy compliance + national sandbox deadline &#8212; <em>sandbox delayed 1 year</em></p><p><strong>Dec 2, 2027</strong> &#8212; High-risk: Annex III (biometrics, employment, education, law enforcement&#8230;) &#8212; <em><strong>DELAYED</strong> </em></p><p><strong>Aug 2, 2028</strong> &#8212; High-risk: Annex I (AI in regulated products &#8212; medical devices, machinery&#8230;) &#8212; <em><strong>DELAYED</strong> </em></p><div><hr></div><h2>The Traps in the Fine Print</h2><p><strong>The two-date trap.</strong> If someone on your team says &#8220;high-risk was pushed to 2027&#8221; &#8212; they&#8217;re half right. Annex III systems (classified by use case) hit December 2, 2027. Annex I systems (AI embedded in regulated products) hit August 2, 2028. That&#8217;s an eight-month gap. If your AI systems span both categories, you&#8217;re planning for two deadlines, not one. And if you&#8217;re not sure which category your system falls into &#8212; that&#8217;s the question to answer first.</p><p><strong>The enforcement paradox.</strong> National supervisory authorities start enforcing in August 2026. But the high-risk obligations &#8212; the most substantial compliance requirements in the entire Act &#8212; just moved to 2027 and 2028. So what are regulators actually doing from August 2026?</p><p>Enforcing the prohibited practices. AI literacy. Transparency obligations. GPAI compliance (primarily the AI Office). That&#8217;s lighter than the full high-risk regime &#8212; but it&#8217;s real. If you&#8217;ve been ignoring AI literacy because you were focused on the high-risk deadline, August 2026 is still your problem. Regulators will ask what you&#8217;ve been doing since February 2025. Fifteen months of nothing is not a defensible answer.</p><p><strong>The permission to procrastinate.</strong> This is the most predictable outcome of the delay &#8212; and the most dangerous for the companies doing it.</p><p>The requirements aren&#8217;t changing. Only the deadline moved. The risk management system, the quality management, the technical documentation, the conformity assessment, the human oversight, the logging &#8212; all of it is still coming. Companies that treat December 2027 as permission to deprioritise will be scrambling again in 18 months. Same panic. Same compressed timelines. Different year.</p><p>The companies that keep going &#8212; using the extra time for quality instead of delay &#8212; will be the ones who are actually ready.</p><div><hr></div><h2>The One Thing That Got Tighter</h2><p>While everything else in the omnibus is about giving industry more time, the nudification ban went the other direction. A new prohibited practice. Added to Article 5. Effective December 2, 2026.</p><p>It covers AI systems designed to generate CSAM, AI systems that create non-consensual intimate imagery of identifiable persons, and &#8212; critically &#8212; AI systems placed on the market without effective safety measures to prevent that use. That third prong matters. It means GPAI model providers need content safeguards robust enough to qualify. What &#8220;effective safety measures&#8221; means in practice isn&#8217;t defined yet. But the penalty tier is the maximum one.</p><p>Worth remembering &#8212; the next time someone tells you the omnibus is just about deregulation.</p><div><hr></div><h2>The Political Context </h2><p>More than 127 civil society organisations &#8212; including Amnesty International, European Digital Rights, the European Disability Forum, and the European Network Against Racism &#8212; opposed the omnibus. </p><p>Their argument is that the systems most likely to affect vulnerable people &#8212; biometric surveillance, AI in law enforcement, AI in employment, AI in education &#8212; now get 1-2 more years without full compliance requirements. That&#8217;s not simplification, they say. That&#8217;s rollback. </p><p>The Commission&#8217;s counter-argument is practical: harmonized standards aren&#8217;t ready, and companies can&#8217;t comply with rules when the measurement tools don&#8217;t exist. Both positions are legitimate. Both are worth knowing.</p><div><hr></div><h2>What to Do Now</h2><p>Were you preparing for August 2026 high-risk compliance? Don&#8217;t stop. Shift the goal to December 2027 (Annex III) or August 2028 (Annex I). Use the runway for quality, not delay.</p><p>Been ignoring AI literacy? That&#8217;s your most immediate problem. Enforcement starts August 2026. Three months from today.</p><p>GPAI model providers have a near-term clock &#8212; nudification safeguards by December 2026. AI Office enforcement powers from August.</p><p>Mid-size companies under 750 employees should check whether they qualify for the new small mid-cap category. Simplified documentation. Lighter compliance. Worth knowing before you build the full-scale programme.</p><p>And if you&#8217;re not sure whether your AI system is even high-risk &#8212; start there. The classification question determines everything else. The omnibus didn&#8217;t change the classification rules. Just the deadline for complying with what follows.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;4ec3508e-a371-4c8c-9e0f-b15fbc24087d&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;What Is an AI System, Actually?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-08T12:03:14.634Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!Lj3S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6c33bfb-66f1-4bc7-aba6-ed6c0d1df60e_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/ai-system-definition-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193355320,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:1,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><p>The AI Act is 21 months old. It&#8217;s already been amended before it&#8217;s fully in effect. More amendments are coming &#8212; the Commission has said so. The regulation that was supposed to be a settled text is becoming a moving one.</p><p>But underneath the shifting deadlines, the obligations that have been running since February 2025 haven&#8217;t stopped. AI literacy. The prohibited practices. Those don&#8217;t have a new date. They have an old one &#8212; and it already passed.</p><p>The omnibus gave you time. Not a pardon.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading AI Law. Decoded.! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Is My AI System High-Risk Under the EU AI Act?]]></title><description><![CDATA[Two pathways, eight categories, one question that determines everything.]]></description><link>https://ailawdecoded.com/p/is-my-ai-system-high-risk-eu-ai-act</link><guid isPermaLink="false">https://ailawdecoded.com/p/is-my-ai-system-high-risk-eu-ai-act</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 06 May 2026 12:02:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-GG3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-GG3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-GG3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-GG3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-GG3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-GG3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-GG3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:629939,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.substack.com/i/196305760?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-GG3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-GG3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-GG3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-GG3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>You&#8217;re sitting at your desk, staring at the notes from a meeting that ended twenty minutes ago.</p><p>It was supposed to be a routine check-in. The IT team had been building an internal tool &#8212; an AI system that would help the lending department assess credit applications faster. Pattern recognition on historical data. Risk scoring. The kind of thing every bank, every lender, every fintech is building right now because someone in the C-suite heard the phrase &#8220;AI-driven efficiency&#8221; at a conference and came back inspired.</p><p>The meeting was fine. Normal. The development lead walked through the architecture. The business team nodded along. Someone asked about the timeline. Someone else asked about integration with the existing workflow. The usual.</p><p>And then &#8212; somewhere between the system architecture slide and the projected ROI &#8212; it hits you.</p><p><em>This scores people.</em></p><p>Not products. Not processes. People. Natural persons applying for a loan, being evaluated by a system that learned its patterns from historical data. A system that would &#8212; if you&#8217;re reading <a href="https://artificialintelligenceact.eu/article/6/">Article 6</a> and <a href="https://artificialintelligenceact.eu/annex/3/">Annex III</a> correctly &#8212; fall squarely into the category of high-risk AI systems under the EU AI Act.</p><p><strong>Or would it?</strong></p><p>Because the more you think about it, the less certain you become. The system doesn&#8217;t make final decisions &#8212; it generates a score, and a human loan officer reviews every application. Does that matter? The system uses machine learning, but the model is relatively simple. Does that matter? The IT team called it a &#8220;decision-support tool&#8221; not an &#8220;AI system.&#8221; Does <em><strong>that</strong></em> matter?</p><p>You pull up the AI Act. Article 6. Annex III. Point 5 &#8212; access to essential private services. Sub-point (b) &#8212; AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score.</p><p>It fits. It clearly fits.</p><p>Except &#8212; Article 6(3). <em>The exception.</em> The escape hatch that says an Annex III system isn&#8217;t high-risk if it doesn&#8217;t pose a significant risk of harm, doesn&#8217;t materially influence the outcome of decision making. The system is decision-support, not decision-making. A human reviews every output. Maybe you qualify.</p><p>But then &#8212; the profiling kill-switch. If the system performs profiling of natural persons, the exception doesn&#8217;t apply. And a system that evaluates personal data to assess someone&#8217;s creditworthiness... that&#8217;s profiling. Almost by definition.</p><p>You close the laptop. Open it again.</p><p>This is the moment. Not the dramatic, cinematic kind &#8212; the quiet, Tuesday-afternoon kind. The moment when you &#8212; an in-house lawyer at a bank &#8212; realize that the AI system your company has been building for eight months might carry obligations nobody on the project team has even heard of. Obligations that include a risk management system, technical documentation, conformity assessment, human oversight requirements, and registration in an EU database &#8212; all before the system can be put into service.</p><p>And the deadline? Shifting. The standards? Not ready. The Commission guidelines that were supposed to clarify exactly this kind of question? Late.</p><p>High-risk AI classification under the EU AI Act. Less straightforward than you&#8217;d like. More consequential than most people realize. And &#8212; as of right now &#8212; missing some of the guidance you&#8217;d need to do it with full confidence.</p><p>But you still need to do it.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>Three Questions to Ask First</h2><p>Before you even start thinking about high-risk AI systems, you need to make sure to answer to the following three questions regarding your AI system:</p><h3>First: Is your system an AI system under the EU AI Act? </h3><p>Not everything that your IT team calls &#8220;AI&#8221; qualifies. </p><p>The legal definition in <a href="https://artificialintelligenceact.eu/article/3/">Article 3(1)</a> has seven elements &#8212; the critical one is <em>inference</em>. If the system just executes predefined rules without learning, reasoning, or modeling, it&#8217;s probably not an AI system under the AI Act. </p><p>If your system isn&#8217;t an AI system under the EU AI Act, stop here. Nothing else applies.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;fdefd004-59bd-4408-8a80-cbbbd9dff445&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;What Is an AI System, Actually?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-08T12:03:14.634Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!Lj3S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6c33bfb-66f1-4bc7-aba6-ed6c0d1df60e_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/ai-system-definition-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193355320,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:1,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h3>Second: Is it within scope? </h3><p>Even AI systems that fulfill the definition of an AI system under the EU AI Act can still fall outside the Act entirely, if they are:</p><ul><li><p>Military and defense systems used exclusively for national security; </p></li><li><p>Systems still in R&amp;D before being placed on the market or put into service;</p></li><li><p>Personal, non-professional use; </p></li><li><p>Open-source systems &#8212; but only if they&#8217;re not high-risk, not prohibited, and don&#8217;t trigger transparency obligations;</p></li><li><p>And non-EU systems whose output never reaches the EU. </p></li></ul><p>The exclusions are narrower than they look. <em>&#8220;Exclusively&#8221;</em> is doing heavy lifting in the military carve-out. <em>&#8220;Before market placement&#8221;</em> evaporates the moment you run a real-world pilot. And the extraterritorial reach mirrors GDPR &#8212; if the output produced by your AI system is used in the Union, you&#8217;re in scope regardless of where your servers sit.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;9f29bf44-d984-41ba-b954-dfc699b3f99d&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Why the EU AI Act Matters Even If You're Not in the EU&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-05T13:54:22.853Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!wrLn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb08944ca-a6dd-44b0-a118-8176d76942bc_4500x3000.heic&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/eu-ai-act-applies-outside-eu&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193044187,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:1,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h3>Third: Is it prohibited? </h3><p>Eight categories of AI practices are banned outright under <a href="https://artificialintelligenceact.eu/article/5/">Article 5</a> &#8212; manipulative techniques, exploitation of vulnerabilities, social scoring, certain predictive policing, untargeted facial scraping, emotion recognition in workplaces and education, biometric categorization by sensitive characteristics, and real-time remote biometric identification by law enforcement. </p><p>If your system is doing any of these, high-risk classification is irrelevant because the system is banned. Fines are up to &#8364;35 million or 7% of global turnover. These have been in effect since February 2025. </p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;0e9a9c06-3145-487f-b6b6-dda2621e99ed&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Prohibited AI Practices Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-15T12:03:15.414Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!81vQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5d9b717-c8ef-4b46-a887-59ff99fbba35_6000x4000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/prohibited-ai-practices-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193589773,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:5,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><p>If your system passed all three checks &#8212; it&#8217;s an AI system, it&#8217;s in scope, and it&#8217;s not prohibited &#8212; the next question is the one that determines your compliance obligations for the next several years.</p><p><strong>Is it high-risk?</strong></p><div><hr></div><h2>Two Doors Into the Same Room</h2><p>Most Law Firms&#8217; alerts treat &#8220;high-risk&#8221; as a single category. It&#8217;s not. </p><p>Article 6 creates two separate pathways &#8212; and which one applies to your system determines not just whether you&#8217;re high-risk, but how your conformity assessment works.</p><h3>Pathway 1: Your AI is inside a regulated product</h3><p><a href="https://artificialintelligenceact.eu/article/6/">Article 6(1).</a> If your AI system is a safety component of a product &#8212; or is itself a product &#8212; covered by the Union harmonization legislation listed in Annex I, <em>and</em> that product requires third-party conformity assessment before being placed on the market, the AI system is high-risk.</p><p>Both conditions. Simultaneously. The AI must be a safety component (or the product itself), and the product must require third-party assessment under its own sectoral legislation.</p><p><a href="https://artificialintelligenceact.eu/annex/1/">Annex I </a>lists over 30 pieces of existing EU product safety law. The ones that matter most: the Machinery Regulation, the Medical Devices Regulation, the In Vitro Diagnostics Regulation, toy safety, radio equipment, civil aviation, motor vehicles. If you&#8217;re building AI into a physical product &#8212; a medical diagnostic device, an autonomous braking system, an industrial robot &#8212; this is your pathway.</p><p>An AI system that controls braking assistance in a vehicle? The vehicle falls under motor vehicle type-approval legislation. The AI is a safety component. Third-party assessment is required. High-risk under Pathway 1.</p><p>An AI-powered diagnostic tool in a Class IIa medical device? The Medical Devices Regulation requires third-party conformity assessment for Class IIa and above. High-risk under Pathway 1.</p><p>What makes this pathway different: the conformity assessment follows the existing sectoral procedure, with EU AI Act requirements layered in. You don&#8217;t run two separate assessments. You integrate obligations under the AI Act into the product safety process you&#8217;re already doing &#8212; or should be doing.</p><p>If your AI system isn&#8217;t embedded in a regulated product &#8212; which, for most companies reading this article, it won&#8217;t be &#8212; Pathway 1 doesn&#8217;t apply. Move to Pathway 2.</p><h3>Pathway 2: Your AI operates in a sensitive domain</h3><p><a href="https://artificialintelligenceact.eu/article/6/">Article 6(2). </a>AI systems referred to in Annex III are high-risk.</p><p>That&#8217;s the entire provision. If your system falls within one of the eight areas and specific use cases listed in Annex III &#8212; it&#8217;s high-risk. No product safety hook needed. No third-party assessment trigger required. The use case alone is enough.</p><p>This is where most companies will land. Annex III captures AI systems used in employment, credit scoring, education, law enforcement, migration, critical infrastructure, biometrics, and the administration of justice. Software systems making or influencing decisions about people &#8212; not embedded in physical products, but consequential all the same.</p><p>The full breakdown of what Annex III actually covers &#8212; and where the boundaries are less clear than you&#8217;d expect &#8212; is coming. But there&#8217;s an exception built into Article 6 that deserves attention first. Mostly because it&#8217;s narrower than it looks.</p><h3>The escape hatch that probably doesn&#8217;t fit</h3><p><a href="https://artificialintelligenceact.eu/article/6/">Article 6(3). </a>The derogation that says an Annex III system isn&#8217;t high-risk if it doesn&#8217;t pose a significant risk of harm &#8212; including by not materially influencing the outcome of decision making.</p><p><strong>Four conditions.</strong> Any one is enough, but the overarching &#8220;no significant risk&#8221; requirement must also be met:</p><ul><li><p>The system performs only a narrow procedural task &#8212; converting data formats, sorting documents by file type. </p></li><li><p>The system only improves the result of a previously completed human activity &#8212; rewriting text for tone after a human drafted it. </p></li><li><p>The system only detects decision-making patterns without replacing or influencing human judgment. </p></li><li><p>Or the system only performs a preparatory task for an assessment &#8212; organizing documents that a human decision-maker will review.</p></li></ul><p>Read those carefully. <em>&#8220;only&#8221;</em>, <em>&#8220;narrow&#8221;</em>, &#8220;<em>previously completed&#8221;</em>, &#8220;<em>without replacing or influencing&#8221;</em>. Every word is a constraint.</p><p>And then the kill-switch.</p><p><strong>If the system performs profiling of natural persons</strong> &#8212; automated processing of personal data to evaluate aspects of a person&#8217;s life, including work performance, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements &#8212; <strong>the exception doesn&#8217;t apply.</strong> The system is high-risk. No conditions, no arguments, no workarounds.</p><p>That definition of profiling comes from the <a href="https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng#art_4">GDPR, Article 4(4)</a>. It&#8217;s broad. And it catches almost every system that companies want to argue out of high-risk classification. A credit scoring tool that evaluates personal financial data to assess reliability? <em>Profiling. </em>An HR analytics system that uses behavioral data to evaluate work performance? <em>Profiling.</em> A system that assesses insurance applicants based on personal characteristics? <em>Profiling.</em></p><p>The company that invokes Article 6(3) derogation must document the assessment in writing before the system goes to market. Register it in the EU database. And be prepared to defend that assessment to market surveillance authorities who can request the documentation at any time. If the authority disagrees &#8212; and the burden of proof is on the provider &#8212; the company has placed an unregulated high-risk system on the market. Fines for that are up to &#8364;15 million or 3% of global turnover.</p><p><em><strong>The practical reality:</strong> </em>most companies that think they qualify for this exception probably don&#8217;t. The conditions are narrow. The profiling kill-switch is broad. And the downside of being wrong is not a slap on the wrist.</p><div><hr></div><h2>The Eight Areas &#8212; What Annex III Actually Covers</h2><p>Annex III lists eight areas. Within each, there are specific use cases. Not every AI system touching these domains is high-risk &#8212; only the listed use cases. But several of those use cases are broader than they first appear.</p><h3>1.  Employment</h3><p>AI systems used for recruitment, selection, and hiring &#8212; placing targeted job ads, screening applications, evaluating candidates. AI systems making decisions about terms of employment &#8212; promotion, termination, task allocation based on individual behavior or personal traits. AI systems monitoring and evaluating worker performance and behavior.</p><p>This is the broadest and most operationally relevant area for most readers. Any AI that touches hiring, firing, promotion, task allocation, or performance monitoring is likely in scope. And this includes AI features embedded in third-party HR platforms &#8212; not just systems you built in-house.</p><p>If your HR software vendor added an AI-powered &#8220;talent analytics&#8221; feature last quarter, and your managers are using it to inform promotion decisions, <em>you may be a deployer of a high-risk AI system.</em> The fact that you didn&#8217;t build it doesn&#8217;t make it someone else&#8217;s problem. Deployers have their own set of obligations under Article 26.</p><p>AI resume screening tools. AI-driven performance scoring. Automated task allocation in gig economy platforms. AI scheduling systems that factor in individual behavioral patterns. <em>All potentially high-risk.</em></p><h3>2.  Essential services</h3><p>There are four sub-categories worth knowing.</p><p><strong>AI systems evaluating creditworthiness or establishing credit scores</strong> &#8212; <em>high-risk. </em>But with an explicit carve-out: systems used for detecting financial fraud are not high-risk under this provision. If your system does both &#8212; evaluates creditworthiness <em>and</em> detects fraud &#8212; you need to separate the functions and classify each independently. The fraud detection piece is out. The credit scoring piece is in.</p><p><strong>AI systems for risk assessment and pricing for life and health insurance </strong>&#8212; <em>high-risk.</em> This is narrower than it sounds. It covers life and health insurance specifically. Property insurance, motor insurance, travel insurance &#8212; not listed. But before you exhale &#8212; if your AI system evaluates personal characteristics of natural persons to price any insurance product, check whether it falls under a different Annex III area or triggers the profiling analysis.</p><p><strong>AI systems evaluating and classifying emergency calls, or dispatching and prioritizing emergency first responders</strong> &#8212; <em>high-risk</em>. This includes triage systems. The AI deciding whether to send an ambulance or a police car is making a high-risk classification.</p><p><strong>AI systems determining eligibility for public benefits and services</strong> &#8212; <em>high-risk. </em>Welfare scoring algorithms. Benefits eligibility tools. The systems that were at the center of the France CAF scandal and the Netherlands childcare benefits disaster &#8212; both of which I covered in the <a href="https://ailawdecoded.substack.com/p/prohibited-ai-practices-eu-ai-act">prohibited practices article</a>. Those cases involved systems that crossed into prohibited territory. But AI systems that evaluate benefits eligibility without crossing the prohibition line are still high-risk.</p><h3>3.  Education </h3><p>AI systems determining access to or admission into educational institutions at all levels. AI systems evaluating learning outcomes &#8212; when those outcomes steer the learning process or affect the level of education received. AI systems determining what level of education a person can access. AI systems monitoring and detecting prohibited behavior during tests.</p><p>AI-powered proctoring software that monitors students during exams &#8212; high-risk. An AI system that determines university admissions &#8212; high-risk. An adaptive learning platform that adjusts content difficulty &#8212; probably not high-risk if it doesn&#8217;t affect the student&#8217;s grade, certification, or access to education. Probably high-risk if it does.</p><h3>4.  Critical infrastructure </h3><p>AI systems used as safety components in the management and operation of critical digital infrastructure, road traffic, and the supply of water, gas, heating, or electricity.</p><p><strong>&#8220;Safety component&#8221;</strong> is the limiting phrase. An AI that optimizes energy routing in a power grid, as a safety component, is high-risk. An AI that forecasts energy demand for planning purposes &#8212; without being a safety component in actual infrastructure operation &#8212; may not be. The distinction between operational optimization and safety function isn&#8217;t always obvious. If the system&#8217;s failure could endanger people or disrupt essential services, treat it as a safety component until you can demonstrate otherwise.</p><h3>5.  Biometrics </h3><p>Remote biometric identification &#8212; face recognition in a crowd, fingerprint matching against a database of unknowns, voice identification against a database. Not one-to-one verification (scanning your face to unlock your phone &#8212; that&#8217;s out). Biometric categorization by sensitive attributes outside the prohibited contexts. Emotion recognition outside the workplace and education contexts that Article 5 (prohibited practices) already bans.</p><p>The prohibited practices article covers what&#8217;s banned. Point 1 of Annex III. catches what isn&#8217;t banned but is still high-risk.</p><h3>6. - 8. Law enforcement, migration, and justice</h3><p>Three areas that primarily affect public authorities and their vendors.</p><p><strong>Law enforcement</strong>: AI systems assessing victim risk, functioning as polygraphs, evaluating evidence reliability, assessing re-offending risk (not solely based on profiling &#8212; that&#8217;s prohibited), and profiling during criminal investigations. These are high-risk only when used by or on behalf of law enforcement. The same technology used privately falls under different rules.</p><p><strong>Migration and border control</strong>: AI polygraphs, risk assessment for visa and entry applicants, travel document verification, and examination of asylum and visa applications.</p><p><strong>Justice and democracy</strong>: AI systems assisting judicial authorities in researching, interpreting, and applying law. And AI systems intended to influence election outcomes or voting behavior &#8212; but not campaign logistics tools.</p><p>For most corporate readers, these three areas are relevant primarily if you&#8217;re a vendor selling to government agencies. But if you are &#8212; every system in these categories carries high-risk obligations, and the conformity assessment for some (particularly biometric systems in law enforcement contexts) requires third-party review by a notified body, not just self-assessment.</p><div><hr></div><h2>The Real Problem &#8212; <em>&#8220;Intended Purpose&#8221;</em> Isn&#8217;t What You Think</h2><p>The entire classification system hinges on intended purpose. And intended purpose under the EU AI Act isn&#8217;t just what you wrote in the product documentation.</p><p>Article 3(12) defines it as:</p><blockquote><p><em><strong>&#8216;intended purpose&#8217; </strong></em>means the use for which an AI system is intended by the provider, including the specific context and conditions of use, as specified in the information supplied by the provider in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation.</p></blockquote><p>And then Article 3(13) adds a companion concept: </p><blockquote><p><em><strong>&#8216;reasonably foreseeable misuse&#8217; </strong></em>means the use of an AI system in a way that is not in accordance with its intended purpose, but which may result from reasonably foreseeable human behaviour or interaction with other systems, including other AI systems.</p></blockquote><p>This means your marketing materials inform the classification. Your sales team&#8217;s pitch informs the classification. If a sales deck describes the system as a &#8220;<em>talent analytics&#8221; </em>tool &#8212; its intended purpose includes employment decisions, regardless of what the technical documentation calls it.</p><p>And if the system is designed for one purpose but foreseeably used for another &#8212; the foreseeable use can trigger high-risk classification. A general-purpose analytics platform marketed to HR departments? Even if you technically label it &#8220;business intelligence,&#8221; the foreseeable use is employment-related decision-making. </p><h3>The multi-purpose trap</h3><p>What happens when a single system has multiple use cases &#8212; some high-risk, some not? <em>The AI Act doesn&#8217;t give you a clean answer. </em></p><p><strong>The practical approach:</strong> if the system is capable of and marketed for a high-risk use case, it&#8217;s high-risk &#8212; even if it also does non-high-risk things. You can&#8217;t escape classification by bundling a high-risk feature into a larger product with mostly minimal-risk functions.</p><p>But you might be able to architect the system so the high-risk use case is clearly separated &#8212; a distinct module or service. That&#8217;s an architectural decision with legal consequences, and it needs to be made early. Not after the system is built. Not after the auditor asks.</p><h3>The deployer who became a provider</h3><p>Once you know a system is high-risk, the next question is: <em>are you the provider or the deployer? </em>The distinction determines which set of obligations you carry &#8212; and the line between the two is less stable than most companies assume.</p><p>Under <a href="https://artificialintelligenceact.eu/article/25/">Article 25</a>, a deployer can become a provider by (a) rebranding a system, (b) making a substantial modification, or &#8212; the one that catches people &#8212; (c) <em><strong>changing the intended purpose</strong></em>. A company buys a general-purpose AI model and uses it for credit scoring. The model provider never intended that use. But the deployer just changed the intended purpose &#8212; and stepped into the provider&#8217;s shoes with all the heavier obligations that come with them.</p><p>Classification doesn&#8217;t end at &#8220;high-risk.&#8221; </p><p>It continues to &#8220;<em>high-risk &#8212; and in what role?</em>&#8221;</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;dffe69bc-cd98-4aa9-ac2c-aea91c400f73&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Provider vs. Deployer Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-22T12:03:43.719Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!NS5L!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35f75bb-44f2-45d4-b53c-84654d8e8617_8192x5461.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/provider-vs-deployer-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:194314202,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:3,&quot;comment_count&quot;:5,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>What Happens When Your AI System Is High-Risk</h2><p>Classification as high-risk is where the compliance work starts &#8212; and the obligations are the reason the classification matters so much. The deep dive on each obligation is a future article. But you need the overview now.</p><ul><li><p><em>A risk management system</em> &#8212; not a one-time assessment but a continuous, iterative process spanning the system&#8217;s lifecycle. </p></li><li><p><em>Data governance requirements </em>&#8212; your training data needs to meet quality criteria, and you need to demonstrate it. </p></li><li><p><em>Technical documentation</em> &#8212; comprehensive, drawn up before market placement, covering everything from system design to performance metrics. </p></li><li><p><em>Automatic logging </em>&#8212; an audit trail of what the system did and when. </p></li><li><p><em>Transparency obligations toward deployers</em> (if you are the provider) &#8212; enough information that the humans using the system can actually interpret its output. </p></li><li><p><em>Human oversight</em> &#8212; the system must be designed so humans can effectively monitor it, override it, and shut it down. </p></li><li><p><em>Accuracy</em>, <em>robustness</em>, and <em>cybersecurity </em>requirements throughout the lifecycle.</p></li><li><p><em>Conformity assessment </em>&#8212; before the system reaches the market. For most Annex III systems, that&#8217;s a self-assessment. For some &#8212; particularly biometric identification systems &#8212; it requires a third-party notified body. </p></li><li><p>Then <em>CE marking</em>. </p></li><li><p>Then <em>EU database registration</em>.</p></li></ul><p>The penalty for non-compliance with high-risk requirements is up to &#8364;15 million or 3% of global turnover. Not as high as the prohibited practices ceiling &#8212; but not the kind of number that disappears in a quarterly business report.</p><div><hr></div><h2>The Timeline Problem</h2><p>If you&#8217;re reading this and thinking <em>&#8220;when do I need to have all of this done?&#8221; </em>&#8212; the honest answer is: it depends on which version of the timeline you&#8217;re following.</p><p>The original deadline for high-risk obligations on Annex III systems was 2 August 2026. That&#8217;s the date in the AI Act as published.</p><p>Then reality intervened. The technical standards that companies need &#8212; the benchmarks that tell you what &#8220;compliant&#8221; actually looks like for risk management, data governance, documentation, and the rest &#8212; weren&#8217;t ready. CEN and CENELEC, the European standardization bodies tasked with developing them, missed their fall 2025 deadline. The Commission guidelines on high-risk AI systems, which were supposed to include practical examples of high-risk and non-high-risk systems, were due by 2 February 2026. The Commission missed that deadline too.</p><p>So in November 2025, the Commission proposed the Digital Omnibus on AI &#8212; a targeted amendment pushing the high-risk deadline to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I product-embedded systems. The European Parliament&#8217;s IMCO and LIBE committees adopted their joint report in March 2026. Trilogue negotiations between Parliament, Council, and Commission are underway.</p><p>As of May 2026, we are still waiting for the final Commission guidelines on high-risk AI system classification. The guidelines that were supposed to include the very examples companies need to resolve edge cases like the one you were staring at after that meeting &#8212; the ones that would clarify whether a credit-scoring decision-support tool with human oversight is high-risk or not. Those guidelines don&#8217;t exist yet.</p><p>Which leaves companies in an uncomfortable position. The classification is already consequential &#8212; even before the full high-risk obligations kick in &#8212; because you need time to build the compliance infrastructure. Risk management systems, documentation, data governance processes &#8212; these aren&#8217;t things you implement in a quarter. If you wait for the guidelines and the guidelines arrive six months before the deadline, you&#8217;re already behind.</p><p><strong>The prudent approach: </strong>classify now, based on the text of Article 6 and Annex III. Build the compliance structure. And be prepared to adjust when the guidelines finally arrive.</p><div><hr></div><h2>The Classification Exercise &#8212; What to Do</h2><p>You&#8217;ve read the law. You understand the two pathways, the eight areas, the escape hatch, the profiling kill-switch, the intended purpose trap. Now you need to turn that into something your company can act on.</p><p><strong>Start with an inventory.</strong> Every AI system your company builds, deploys, or procures. Not just the ones your IT team calls &#8220;AI&#8221; &#8212; the ones that meet the Article 3(1) definition. The vendor tools with AI features embedded. The model your data science team fine-tuned. The chatbot someone in marketing set up without telling anyone. You can&#8217;t classify what you haven&#8217;t mapped. </p><p><strong>Run each system through the decision tree.</strong> Is it in scope? Is it prohibited? Does it fall under Annex I (product safety pathway) or Annex III (standalone pathway)? If Annex III &#8212; which area and which specific use case? Be precise. &#8220;It&#8217;s an HR tool&#8221; isn&#8217;t a classification. &#8220;It screens job applications using machine learning, which falls under Annex III, Point 4(a) &#8212; recruitment and selection&#8221; is.</p><p><strong>Don&#8217;t skip the intended purpose analysis.</strong> Pull the marketing materials. The sales deck. The vendor&#8217;s product description. The internal documentation about how the system is actually used &#8212; not how it was originally purchased. If there&#8217;s a gap between the vendor&#8217;s intended purpose and your actual use, that gap is where Article 25 (and your role as a provider or deployer) lives. A system bought for analytics and used for credit decisions isn&#8217;t an analytics tool anymore.</p><p><strong>Assess Article 6(3) exceptions honestly &#8212; and document it either way.</strong> If you think the escape hatch applies, write down why. Which of the four conditions is met? Does the system profile natural persons? (If it evaluates personal data to assess any aspect of a person&#8217;s life &#8212; it almost certainly does.) Does it materially influence decision-making? Be honest. &#8220;A human reviews the output&#8221; isn&#8217;t enough if the human rubber-stamps the AI&#8217;s recommendation 95% of the time. If Article 6(3) doesn&#8217;t apply &#8212; document that too. The assessment matters regardless of the conclusion.</p><p><strong>Figure out your role.</strong> For every high-risk system &#8212; are you the provider or the deployer? Did you build it? Did you modify it? Did you retrain it on your own data? Did you change what it&#8217;s used for? If you&#8217;re unsure, read the <a href="https://ailawdecoded.substack.com/p/provider-vs-deployer-eu-ai-act">provider vs. deployer analysis</a> before answering. The obligations are different enough that getting this wrong changes everything.</p><p><strong>Start the compliance build now.</strong> If you have systems that are clearly high-risk &#8212; and after going through Annex III, most companies will find at least one &#8212; don&#8217;t wait for the guidelines, or the final Digital Omnibus timeline. Risk management systems, technical documentation, data governance processes, human oversight design &#8212; these take months to build properly. Starting late is a choice. It&#8217;s just not a good one.</p><p><strong>Put legal and engineers in the same room.</strong> This cannot be a legal-only exercise. Legal can&#8217;t assess whether a system falls under Annex III without understanding what the system actually does. Engineers can&#8217;t assess whether &#8220;intended purpose&#8221; creates a classification risk without understanding what Article 3(12) requires. The classification has to be joint &#8212; and it has to be documented.</p><div><hr></div><h2>Back to You</h2><p>You&#8217;re still at your desk. The meeting notes are still open. The system architecture diagram is still on your second screen.</p><p>You know three things now that you didn&#8217;t know an hour ago:</p><ol><li><p>The system almost certainly falls within Annex III, Point 5(b) &#8212; creditworthiness evaluation. </p></li><li><p>The Article 6(3) escape hatch almost certainly doesn&#8217;t apply &#8212; the profiling kill-switch alone closes that door. </p></li><li><p>And the fact that a human reviews every output doesn&#8217;t make the system not high-risk. It means the human oversight requirement under Article 14 might be partially met. It doesn&#8217;t change the classification.</p></li></ol><p>You also know that nobody on the project team &#8212; not the IT lead, not the business sponsor, not the procurement team that selected the underlying model &#8212; has considered any of this. </p><p>Eight months of development. Budget approved. Timeline set. And the compliance question that determines whether this system can legally operate in the EU is being asked for the first time on a Tuesday afternoon by the one person in the room who happened to have read Article 6.</p><p>You open a new email. Subject line: &#8220;AI Act classification &#8212; we need to talk about the credit scoring tool.&#8221;</p><p>Better late than never. </p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading AI Law. Decoded.! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[AI Literacy Under the EU AI Act]]></title><description><![CDATA[One article. Already in force. And it applies to every AI system you use.]]></description><link>https://ailawdecoded.com/p/ai-literacy-obligation-eu-ai-act</link><guid isPermaLink="false">https://ailawdecoded.com/p/ai-literacy-obligation-eu-ai-act</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 29 Apr 2026 12:02:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!4o1m!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F728ea733-afbc-466e-957e-5541b6c23aba_7680x4320.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4o1m!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F728ea733-afbc-466e-957e-5541b6c23aba_7680x4320.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4o1m!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F728ea733-afbc-466e-957e-5541b6c23aba_7680x4320.jpeg 424w, https://substackcdn.com/image/fetch/$s_!4o1m!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F728ea733-afbc-466e-957e-5541b6c23aba_7680x4320.jpeg 848w, https://substackcdn.com/image/fetch/$s_!4o1m!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F728ea733-afbc-466e-957e-5541b6c23aba_7680x4320.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!4o1m!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F728ea733-afbc-466e-957e-5541b6c23aba_7680x4320.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4o1m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F728ea733-afbc-466e-957e-5541b6c23aba_7680x4320.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/728ea733-afbc-466e-957e-5541b6c23aba_7680x4320.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:716280,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.substack.com/i/195462875?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F728ea733-afbc-466e-957e-5541b6c23aba_7680x4320.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4o1m!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F728ea733-afbc-466e-957e-5541b6c23aba_7680x4320.jpeg 424w, https://substackcdn.com/image/fetch/$s_!4o1m!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F728ea733-afbc-466e-957e-5541b6c23aba_7680x4320.jpeg 848w, https://substackcdn.com/image/fetch/$s_!4o1m!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F728ea733-afbc-466e-957e-5541b6c23aba_7680x4320.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!4o1m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F728ea733-afbc-466e-957e-5541b6c23aba_7680x4320.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>Someone at your company bought an AI tool.</p><p>Maybe it was the marketing team &#8212; a content assistant, a campaign optimizer, something with &#8220;AI-powered&#8221; in the tagline that justified a budget nobody would have approved two years ago. Maybe it was HR &#8212; a screening tool that promises to save 40 hours per hiring cycle. Maybe your developers just started using Copilot and nobody told compliance.</p><p>And then someone &#8212; <em>you, probably,</em> because these things always land on the same desk &#8212; asked the question that changes the meeting: &#8220;Do the people using this actually understand what it does?&#8221;</p><p>Not the features. Not the sales pitch. Do they understand what the system is doing with its inputs? Do they know when the output might be wrong? Do they know what the company&#8217;s legal obligations are now that they&#8217;re using it?</p><p><em>Silence.</em></p><p>Since 2 February 2025, that silence has been a legal problem.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>The Shortest Obligation with the Longest Reach</h2><p>The entire AI literacy obligation of the EU AI Act lives in one sentence of Article 4:</p><blockquote><p><em>Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used.</em></p></blockquote><p>One sentence. No subparagraphs. No delegated acts. No annexes. If you printed the entire AI Act&#8217;s high-risk AI requirements and then printed Article 4, one of them would be a binder and the other would be a Post-it note.</p><p>That one-sentence treatment has made everyone underestimate it.</p><p>Three things make Article 4 different from almost every other obligation in the AI Act:</p><p><em><strong>It already applies. </strong></em>Not in August 2026 with the high-risk requirements. Not in 2027 with the extended deadline. February 2025. If you&#8217;re reading this in April 2026, you&#8217;ve been subject to this obligation for 14 months. <em>Surprise.</em></p><p><em><strong>It applies regardless of risk level.</strong></em> Article 4 doesn&#8217;t care whether your AI system is high-risk, limited-risk, or minimal-risk. Every AI system in the Act&#8217;s scope triggers this obligation. Your chatbot. Your translation tool. Your AI coding assistant. The thing the intern installed last Tuesday. All of them. The only systems that escape are those outside the Act&#8217;s scope entirely &#8212; military use, purely personal use, R&amp;D before market deployment.</p><p><em><strong>And it reaches everyone your AI touches.</strong></em> Not just employees. Contractors. Consultants. Outsourced teams. Anyone &#8220;dealing with the operation and use of AI systems on your behalf.&#8221;</p><div><hr></div><h2>What the Commission Said &#8212; and What It Left to You</h2><p>In 2025, the European Commission published a <a href="https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers">Q&amp;A on AI Literacy</a> &#8212; the most concrete guidance available on what Article 4 means in practice. It didn&#8217;t get the attention of the prohibited practices guidelines or the AI system definition guidelines. <em>It should have.</em></p><p>The Q&amp;A sets a tone. Flexible, not prescriptive. No mandatory certifications. No required training hours. No pass/fail tests. The AI Office says it &#8220;does not intent to impose strict requirements&#8221; regarding what counts as a &#8220;sufficient level&#8221; of AI literacy.</p><p>If you just exhaled with relief &#8212; hold that breath a moment longer.</p><p>Because the Q&amp;A also says that the choice <em>not</em> to train staff will be &#8220;closely scrutinised, and likely viewed negatively, by regulators, customers and other stakeholders.&#8221; You can argue about what kind of training. You can argue about how much. You cannot argue that training is unnecessary.</p><p>The minimum floor the Commission outlines:</p><p><strong>Ensure a general understanding of AI within the organization.</strong> <em><br></em>What is AI? How does it work? What AI systems do we use? What are the risks?</p><p><strong>Consider the role of the organization. <br></strong>Provider or deployer? The obligations differ. A company building AI systems needs a different literacy profile than one using off-the-shelf tools.</p><p><strong>Identify and communicate risks specific to the AI systems in use.</strong> <br>Staff need to know what can go wrong &#8212; and what to do when it does.</p><p><strong>Tailor the program to the people and the context.</strong> <br>A data scientist and a claims handler don&#8217;t need the same training. Article 4 says so explicitly &#8212; &#8220;taking into account their technical knowledge, experience, education and training.&#8221;</p><p>One more thing the Q&amp;A clarifies. </p><p>There is no obligation to <em>measure</em> your employees&#8217; AI knowledge. No mandatory testing. No certification requirements. You don&#8217;t have to quiz your head of sales on the definition of a neural network. But documentation of what training was provided matters &#8212; because when supervisory authorities start enforcement in August 2026, AI literacy programs (or the absence of them) will be among the first things they examine.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;43fe53e8-d75f-431c-bb89-d8c654843d89&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Prohibited AI Practices Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act with practical steps.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-15T12:03:15.414Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!81vQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5d9b717-c8ef-4b46-a887-59ff99fbba35_6000x4000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/prohibited-ai-practices-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193589773,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:3,&quot;comment_count&quot;:5,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>Three Tiers &#8212; Not One Box to Check</h2><p>&#8220;Train your staff on AI.&#8221; That&#8217;s what most compliance summaries tell you. As if you could buy a single e-learning course, push it to the entire organization, and file the receipt.</p><p>The regulation is more specific than that &#8212; and, for once, more reasonable.</p><p>Article 4 builds in a proportionality test through its qualifying language: <em>&#8220;taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in.&#8221; </em>That&#8217;s not a uniform standard. That&#8217;s a signal &#8212; different people need different things.</p><p>Recital 20 makes it explicit. The &#8220;notions&#8221; required for AI literacy &#8220;may vary with regard to the relevant context&#8221; and can include understanding technical elements during development, measures during use, how to interpret AI output, and &#8212; for people subjected to AI decisions &#8212; how those decisions will impact them.</p><p>Germany&#8217;s Bundesnetzagentur &#8212; the designated national market surveillance authority &#8212; <a href="https://www.bundesnetzagentur.de/EN/Areas/Digitalisation/AI/07_Literacy/start.html">published guidance in June 2025</a> recommending a three-stage approach. The Commission&#8217;s Q&amp;A acknowledges that &#8220;having different levels of training or learning approaches can be appropriate.&#8221;</p><p>Put these together and the shape is clear. Three tiers.</p><h3>Tier 1 &#8212; General AI awareness. Everyone.</h3><p>This is the floor. Every person in the organization &#8212; from the CEO to the receptionist to the warehouse worker &#8212; needs a baseline:</p><p>What AI is and, at a conceptual level, how it works. Which AI systems the organization uses. That the organization has legal obligations around AI. What to do if they encounter something unexpected &#8212; who to escalate to. The basic opportunities and risks.</p><p>This isn&#8217;t a 40-hour course. It could be an annual e-learning module. An internal policy document everyone reads and signs off on. A town hall where at least some people are paying attention. The format matters less than the fact that it exists and that you can prove it happened.</p><h3>Tier 2 &#8212; Role-specific competence. People who work with AI systems.</h3><p>Anyone who operates, manages, or makes decisions based on AI output needs more.</p><p>Understanding how the specific AI systems they work with function &#8212; not at code level, but practically. What the system does. What data it uses. What its limitations are. When it might be wrong. The risks specific to those systems. The ability to interpret AI outputs correctly &#8212; including knowing when to distrust the output. And what to do when something doesn&#8217;t look right.</p><p>The HR coordinator using an AI screening tool needs to know what the system evaluates, what it misses, and when human judgment should override it. The loan officer reviewing an AI credit recommendation needs to understand the model&#8217;s inputs and limitations &#8212; not because they&#8217;re a data scientist, but because they&#8217;re making decisions that affect people&#8217;s mortgages.</p><h3>Tier 3 &#8212; Specialised competence. Human oversight.</h3><p>Article 14(5) of the AI Act requires that natural persons assigned to human oversight of high-risk AI systems have the <em><strong>&#8220;competence, training and authority&#8221;</strong> </em>to effectively perform that role. Not &#8220;awareness.&#8221; Not &#8220;familiarity.&#8221; Competence. They must be able to properly understand the system&#8217;s capabilities and limitations. Monitor its operation and detect anomalies. Be aware of automation bias &#8212; the tendency to over-rely on AI output. Correctly interpret the system&#8217;s output. And have the authority to override or disregard it when necessary.</p><p>Article 4 is the foundation. Article 14 is the superstructure. You cannot comply with human oversight requirements if your oversight personnel lack AI literacy.</p><p>This matters because the real enforcement risk for AI literacy isn&#8217;t a standalone Article 4 fine. It&#8217;s what happens when a high-risk AI system causes harm and the investigation reveals that the person assigned to human oversight didn&#8217;t understand the system well enough to oversee it. At that point, Article 4 non-compliance becomes evidence of Article 14 non-compliance &#8212; and the penalty exposure jumps from a training gap to a systemic governance failure.</p><p><strong>Who falls into Tier 3: </strong>the senior underwriter serving as human-in-the-loop for AI-assisted insurance decisions. The radiologist overseeing AI diagnostic imaging. The safety engineer monitoring AI in critical infrastructure. The compliance officer responsible for an AI system that makes decisions affecting people&#8217;s rights.</p><p>These people need deep, system-specific knowledge. Known failure modes. Confidence levels. Conditions under which the system should be stopped. Documentation and incident reporting requirements. This isn&#8217;t an e-learning module. This is dedicated, ongoing, system-specific training &#8212; and the ability to prove it.</p><div><hr></div><h2>What This Looks Like in Practice </h2><h3>First Scenario - The insurer</h3><p>An insurance company uses AI for claims processing &#8212; a fraud detection model that flags suspicious claims and a machine learning system that assists underwriters with risk assessment.</p><p>Tier 1 is straightforward. Everyone in the company &#8212; from reception to the CEO &#8212; gets an annual briefing on the company&#8217;s AI use, its obligations, and basic AI literacy. An e-learning module. Internal communications about the AI policy.</p><p>Tier 2 is the one that will take work. The claims team needs to understand that <em>&#8220;flagged&#8221;</em> means a probability score &#8212; not a verdict. They need to know the system&#8217;s false positive rate. They need to know what to do when they disagree with the system&#8217;s output. The underwriters using AI-assisted risk assessment need to understand the model&#8217;s inputs, its limitations, and the circumstances under which they should override the recommendation. This isn&#8217;t optional training. This is the minimum for people making decisions based on AI output every day.</p><p>Tier 3 applies to the senior underwriter serving as human-in-the-loop. They need Article 14-level competence: understanding automation bias, knowing the system&#8217;s failure modes, having the authority and knowledge to override it, and understanding what triggers an incident report.</p><p>And there&#8217;s a dimension most insurers won&#8217;t think about on their own. The affected persons &#8212; policyholders whose claims are processed by AI. Article 4 doesn&#8217;t create a direct obligation to train your customers. But internal AI literacy needs to be sufficient that staff can explain AI-assisted decisions to policyholders who challenge them. That connects to transparency obligations under Article 50 &#8212; and to the practical reality that someone will ask &#8220;why was my claim denied?&#8221; and the answer can&#8217;t be &#8220;the algorithm said so.&#8221;</p><h3>Second Scenario - The 30-person e-commerce company</h3><p>A small company. Shopify&#8217;s AI-powered product recommendations. ChatGPT for customer service drafts. An AI accounting tool. They didn&#8217;t build any of this. Pure deployers.</p><p>What they think: <em>We just use tools. AI literacy isn&#8217;t our problem.</em></p><p>What the law says: they&#8217;re deployers. Article 4 applies.</p><p>What &#8220;to their best extent&#8221; looks like for a company this size: an internal AI use policy &#8212; one document listing which AI tools are in use and the basic rules for using them. A team briefing. Making sure the marketing manager using ChatGPT knows about hallucination risks. Making sure the customer service team understands the limits of AI-generated responses before sending them to customers.</p><p>This company doesn&#8217;t need a three-tier training program with a dedicated AI literacy officer and a quarterly assessment cycle. But it needs <em>something</em> documented and demonstrable. A written policy. A record that the conversation happened. Evidence that people know what they&#8217;re using and what can go wrong.</p><p>The bar is lower. It is not zero.</p><h3>Third Scenario - The startup building an AI product</h3><p>Five people. All technical. Building an AI-powered legal research tool for law firms.</p><p>Their AI literacy gap is the opposite of what you&#8217;d expect. They understand transformers and embeddings. They can explain attention mechanisms over coffee. Their technical AI knowledge is deep.</p><p>Their regulatory AI literacy might be zero. They can build an AI system. They cannot tell you what Article 6 says about it.</p><p>As a provider, they need to understand what obligations attach to their product. That the AI Act requires specific documentation. That the system will need instructions for use. That their customers &#8212; law firms deploying the tool &#8212; will have their own obligations under the Act, and the startup&#8217;s product needs to support those obligations.</p><p>&#8220;To their best extent&#8221; here means documented internal policies on AI Act compliance. Evidence that the team has studied the relevant obligations. Someone assigned to regulatory responsibility &#8212; even if it&#8217;s the co-founder spending Saturdays reading guidance documents. Training doesn&#8217;t need to be a formal program. But the knowledge needs to exist. And it needs to be demonstrable.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;763a069d-65c5-40ae-9048-e065e2e9e7a5&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Provider vs. Deployer Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act with practical steps.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-22T12:03:43.719Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!NS5L!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35f75bb-44f2-45d4-b53c-84654d8e8617_8192x5461.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/provider-vs-deployer-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:194314202,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:1,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>The Third Group in the Definition &#8212; Affected Persons</h2><p>The definition of AI literacy in Article 3(56) covers three groups: providers, deployers, and affected persons. The people on the receiving end of AI decisions.</p><p>Article 4 itself only imposes the obligation on providers and deployers regarding their staff. But Recital 20 goes further &#8212; affected persons need &#8220;the knowledge necessary to understand how decisions taken with the assistance of AI will have an impact on them.&#8221;</p><p><em>Wait &#8212; does that mean I have to train my customers?</em></p><p>No. Not directly. But it creates an expectation. And it connects to transparency obligations elsewhere in the Act &#8212; particularly Article 50, which requires deployers to inform people when they&#8217;re interacting with certain AI systems.</p><p>The practical implication: your internal AI literacy program needs to be good enough that your staff can explain AI-assisted decisions to the people affected by them. The patient who asks how AI influenced their diagnosis. The job applicant who wants to know why they were screened out. The policyholder disputing a claim decision.</p><p>If your staff can&#8217;t explain it &#8212; because they don&#8217;t understand it themselves &#8212; you have both an AI literacy problem and a transparency problem. They compound.</p><div><hr></div><h2>Penalties and the Aggravating Factor</h2><p>The penalty tier for Article 4 violations falls under Article 99 &#8212; likely up to &#8364;15 million or 3% of total worldwide annual turnover, whichever is higher. I say &#8220;likely&#8221; because the exact tier applicable to Article 4 is not perfectly clear from the penalty structure.</p><p>However, nobody is getting fined &#8364;15 million because their training program was weak. That&#8217;s not how this plays out.</p><p>The scenario regulators are actually preparing for is different.</p><p>A high-risk AI system causes harm. An investigation follows. The regulator discovers that the deployer&#8217;s staff didn&#8217;t understand the system&#8217;s limitations. Didn&#8217;t know how to interpret its outputs. Didn&#8217;t recognise the risk signals. The regulator asks: what AI literacy measures did you have in place?</p><p>If the answer is &#8220;none&#8221; or &#8220;a generic webinar from 2025 that nobody remembers&#8221; &#8212; that absence of literacy becomes evidence of broader non-compliance. It amplifies the penalty for the primary violation.</p><p>Article 4 doesn&#8217;t bite on its own. It bites when something else goes wrong &#8212; and it proves the failure was systemic.</p><div><hr></div><h2>Enforcement Timeline &#8212; the Gap You Should not Misread</h2><p>2 February 2025 &#8212; Article 4 started to apply.</p><p>2 August 2026 (if not postponed) &#8212; national market surveillance authorities begin supervising and enforcing.</p><p>That 18-month gap between obligation and enforcement is not a grace period in the &#8220;you can ignore this until August&#8221; sense. It&#8217;s runway. The Commission gave organizations time to build programs before inspections begin.</p><p>Germany has already designated the Bundesnetzagentur as its supervisory authority. It published guidance. It set up an AI Service Desk. Other Member States are at different stages &#8212; which means enforcement intensity will vary across the EU, at least initially.</p><p>But the question a supervisory authority will ask in August 2026 is not &#8220;do you have a program now?&#8221; It&#8217;s &#8220;what have you been doing since February 2025?&#8221; Fourteen months of doing nothing is not a defensible answer.</p><div><hr></div><h2>What to Do &#8212; Practically</h2><p>You have at least until August 2026 before enforcement starts. But that&#8217;s not a lot of time if you&#8217;re starting from nothing. However, Article 4 doesn&#8217;t ask for perfection. It asks for measures taken &#8220;to your best extent.&#8221; Demonstrable, proportionate, real.</p><p><em><strong>Start with an inventory.</strong></em> Which AI systems does your organization use? Who uses them? In what context? You can&#8217;t build a literacy program around tools you haven&#8217;t mapped. This is also the exercise that feeds risk classification under Article 6 &#8212; so it&#8217;s not wasted work.</p><p><em><strong>Identify your tiers.</strong></em> Not everyone needs the same training. Sort your people into the three categories &#8212; general awareness (everyone), role-specific competence (people working with AI daily), and specialised oversight (human-in-the-loop roles under Article 14). The Commission&#8217;s Q&amp;A supports this approach explicitly.</p><p><em><strong>Build the floor first. </strong></em>General AI awareness for the entire organization. What AI is. Which systems you use. What the risks are. What to do if something looks wrong. This can be an e-learning module, an internal policy document, a briefing &#8212; whatever fits your size. The format is flexible. The fact that it happened needs to be documented.</p><p><em><strong>Then go deeper for the people who need it.</strong></em> Role-specific training for anyone operating AI systems or making decisions based on AI output. What the system does. What it can&#8217;t do. When to distrust it. What to do when something doesn&#8217;t look right. For high-risk AI with human oversight requirements, this becomes Article 14-level competence &#8212; and that standard is higher than a training session.</p><p><em><strong>Write it down. </strong></em>The AI Act doesn&#8217;t prescribe documentation formats for Article 4. But when a supervisory authority asks what you&#8217;ve done, &#8220;we had some conversations&#8221; is not an answer. A written AI literacy policy. Training records &#8212; who was trained, when, on what. An internal AI use policy listing your tools and the rules for using them. Evidence that the program evolves as your AI use changes.</p><p><em><strong>Check what your providers give you. </strong></em>If you&#8217;re a deployer, your AI literacy depends partly on the information your providers disclose &#8212; instructions for use, capabilities, limitations. If the documentation is thin, your ability to train your staff on that system is compromised. That&#8217;s a conversation worth having with your vendors before the regulator has it with you.</p><div><hr></div><h2>The Foundation That Makes Everything Else Work</h2><p>There&#8217;s a reason Article 4 applies before almost everything else in the AI Act.</p><p>Risk classification requires someone who understands what the AI system does well enough to assess which Annex III category might apply. Conformity assessment requires people who can prepare and review technical documentation. Human oversight &#8212; Article 14 &#8212; explicitly requires competence and training. Transparency obligations require understanding what the AI actually does before you can tell anyone else about it. Post-market monitoring requires identifying issues. Incident reporting requires recognising when a serious incident has occurred.</p><p>Every single one of those obligations assumes that the people doing the work understand what they&#8217;re working with. Article 4 is that assumption, written into law.</p><p>AI Literacy will never headline a conference panel. It won&#8217;t generate breathless LinkedIn posts or &#8364;50K consulting proposals. It sits there &#8212; one sentence, one article &#8212; doing the structural work of making everything else in the regulation possible.</p><p>A company that gets AI literacy right will find the rest of the AI Act manageable. A company that skips it will find every other obligation harder, every assessment shallower, every oversight function weaker.</p><p>The regulation gives you flexibility on the how. Not on the whether.</p><p>Fourteen months are already gone. The people using AI in your organization &#8212; right now, today, across every department and every risk level &#8212; either understand what they&#8217;re working with, or they don&#8217;t.</p><p>That&#8217;s the question. Not whether you need a program. Whether the one you have is enough.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading AI Law. Decoded.! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Provider vs. Deployer Under the EU AI Act]]></title><description><![CDATA[The Line That Moves When You're Not Looking.]]></description><link>https://ailawdecoded.com/p/provider-vs-deployer-eu-ai-act</link><guid isPermaLink="false">https://ailawdecoded.com/p/provider-vs-deployer-eu-ai-act</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 22 Apr 2026 12:03:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NS5L!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35f75bb-44f2-45d4-b53c-84654d8e8617_8192x5461.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NS5L!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35f75bb-44f2-45d4-b53c-84654d8e8617_8192x5461.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NS5L!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35f75bb-44f2-45d4-b53c-84654d8e8617_8192x5461.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NS5L!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35f75bb-44f2-45d4-b53c-84654d8e8617_8192x5461.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NS5L!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35f75bb-44f2-45d4-b53c-84654d8e8617_8192x5461.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NS5L!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35f75bb-44f2-45d4-b53c-84654d8e8617_8192x5461.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NS5L!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35f75bb-44f2-45d4-b53c-84654d8e8617_8192x5461.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d35f75bb-44f2-45d4-b53c-84654d8e8617_8192x5461.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:446644,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.substack.com/i/194314202?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35f75bb-44f2-45d4-b53c-84654d8e8617_8192x5461.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NS5L!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35f75bb-44f2-45d4-b53c-84654d8e8617_8192x5461.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NS5L!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35f75bb-44f2-45d4-b53c-84654d8e8617_8192x5461.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NS5L!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35f75bb-44f2-45d4-b53c-84654d8e8617_8192x5461.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NS5L!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35f75bb-44f2-45d4-b53c-84654d8e8617_8192x5461.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>I was reviewing a contract last month. </p><p>A mid-sized bank licensing an AI-powered credit scoring system from a fintech vendor. </p><p>Standard setup. The vendor builds it, the bank uses it. Clean.</p><p>Then I got to the section on customization. </p><p>The bank&#8217;s data science team had been training the model on the bank&#8217;s own lending data. Five years of loan applications, defaults, repayments. </p><p>They&#8217;d also adjusted some of the decision thresholds. And someone &#8212; probably an ambitious junior data scientist &#8212; had integrated an additional ML component that post-processes the vendor&#8217;s output before it reaches the credit committee.</p><p>The contract called the bank a &#8220;<strong>deployer</strong>&#8221;.</p><p>I sat there thinking &#8212; <em>are you, though?</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p>If you&#8217;ve worked through GDPR, the exercise will feel familiar. Controller or processor? You had to figure out your role before you could figure out your responsibilities. The answer determined which obligations applied, how much documentation you needed, and what happened when something went wrong.</p><p>The AI Act follows the same logic. Different terms &#8212; provider and deployer instead of controller and processor &#8212; but the same structural question: <em>what is your role in relation to this AI system, and what follows from it?</em></p><p>The consequences, though, are not the same. Under GDPR, both controllers and processors carry real obligations. Under the AI Act, the gap between provider and deployer is enormous. A deployer&#8217;s obligations fit on one page &#8212; use the system properly, keep humans in the loop, tell people when AI is making decisions about them. A provider is responsible for the system itself &#8212; its design, its documentation, its conformity assessment, its safety. That&#8217;s not a difference in degree. That&#8217;s a different job.</p><p>And your role can change. You can start as a deployer and end up as a provider &#8212; not because you decided to be one, but because of what you did with the AI system.</p><div><hr></div><h2>The Definitions</h2><p>The AI Act defines both roles in <a href="https://artificialintelligenceact.eu/article/3/">Article 3</a>.</p><p><em><strong>A provider </strong></em>is a person or entity that develops an AI system &#8212; or has one developed &#8212; and places it on the market or puts it into service under its own name or trademark. Two things matter: developing (or commissioning the development), and putting your name on it.</p><p><em><strong>A deployer</strong></em> is a person or entity using an AI system under its authority. That&#8217;s it. You use the AI system. You didn&#8217;t build it. You&#8217;re not selling it. You&#8217;re operating it.</p><p>On paper, the line is clean. One builds, one uses.</p><p>In practice, companies buy AI systems and then customize them, train them on proprietary data, integrate them into larger pipelines, repurpose them for new use cases. The neat definition breaks down the moment real business happens to it.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;a39838a8-a78d-4b43-a391-dbdd474e85f5&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;What Is an AI System, Actually?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act with practical steps.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-08T12:03:14.634Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!Lj3S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6c33bfb-66f1-4bc7-aba6-ed6c0d1df60e_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/ai-system-definition-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193355320,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:1,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>Three Triggers That Make You a Provider</h2><p><a href="https://artificialintelligenceact.eu/article/25/">Article 25</a>. <em>&#8220;Responsibilities along the AI value chain.&#8221; </em>Sounds like the title of a slide deck nobody wants to sit through. What it actually does: define the three moments when a deployer becomes a provider.</p><p>Three triggers. Any one is enough.</p><p><strong>You put your name on it.</strong> You buy a high-risk AI system from a vendor. You rebrand it. Call it yours. Put your trademark on the interface. From the outside world, it looks like your product. Under the AI Act, it now is your product &#8212; even if you didn&#8217;t change a line of code.</p><p><strong>You substantially modify it.</strong> You change a high-risk AI system in a way that wasn&#8217;t foreseen in the original conformity assessment &#8212; and that change affects compliance or intended purpose. You just became the provider.</p><p><strong>You repurpose it into high-risk.</strong> You take an AI system that wasn&#8217;t classified as high-risk and use it for something that is. You didn&#8217;t touch the AI system itself. You just used it differently.</p><p>That third trigger is the one that is easy to miss. You don&#8217;t have to modify the AI system. You just have to use it wrong.</p><div><hr></div><h2>One Bank, Five Ways to Get It Wrong</h2><p>Credit scoring. </p><p>One of the clearest high-risk use cases under the AI Act &#8212; Annex III, point 5(b), AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score. No ambiguity about the risk classification.</p><p>The only question is about the role. And it turns out there are at least five versions of that question &#8212; all sitting inside the same bank.</p><h3>The simple version</h3><p>The bank licenses a credit scoring AI system from a fintech vendor. Plugs it in. Follows the instructions. Doesn&#8217;t touch the internals.</p><p>Deployer. Article 26 obligations &#8212; operational stuff. Use the system according to instructions, assign competent people for human oversight, make sure the input data is relevant, inform applicants that AI is involved in the credit decision, cooperate with authorities if they come asking.</p><p>What the bank does not have to do: conformity assessment, CE marking, technical documentation, quality management system, registration as provider, post-market monitoring system. None of it.</p><p>That&#8217;s a comfortable position. Most banks want to stay there.</p><p><em>Few do.</em></p><h3>The obvious version</h3><p>The bank builds its own credit scoring model from scratch. Data science team trains it on the bank&#8217;s lending data, validates it, deploys it. The bank&#8217;s name is the only name on it.</p><p>Provider. Not because of Article 25 &#8212; this isn&#8217;t a transformation question. The bank developed an AI system and put it into service. That&#8217;s the definition, full stop.</p><p>Full provider obligations. Quality management system (QMS). Technical documentation per Annex IV. Conformity assessment before putting the system into service. EU declaration of conformity. CE marking. Registration. Automatic logging. Post-market monitoring. Serious incident reporting.</p><p>The list goes on. I&#8217;ll come back to the full comparison. But the gap between this and the deployer list isn&#8217;t incremental &#8212; it&#8217;s structural.</p><h3>The version that keeps me up at night</h3><p>The bank licenses a credit scoring system. The system is designed to be trained on the deployer&#8217;s data &#8212; that&#8217;s the product. </p><p><em>&#8220;Bring your own data&#8221; </em>the vendor&#8217;s sales deck probably said. </p><p>The bank feeds in five years of lending history. The model learns the bank&#8217;s patterns. Parameters change. The model now behaves differently than the vanilla version.</p><p><em>Still a deployer?</em></p><p>Everything turns on one phrase in Article 3(23) &#8212; the definition of <strong>&#8220;substantial modification&#8221;</strong>: <em>not foreseen or planned in the initial conformity assessment.</em></p><p>If the vendor&#8217;s conformity assessment explicitly accounted for retraining on deployer data &#8212; specified what kind of data, assessed how retraining affects performance, set guardrails &#8212; then the bank is likely still a deployer. Recital 128 backs this up: changes that were <em>&#8220;pre-determined by the provider and assessed at the moment of the conformity assessment&#8221;</em> are not substantial modifications. The vendor planned for this. The AI system was designed to be trained this way.</p><p>If the vendor didn&#8217;t account for it &#8212; if the sales team said &#8220;you can train it on your data&#8221; but the conformity assessment never assessed the impact of that retraining &#8212; the bank just made a substantial modification. <strong>Not foreseen</strong><em><strong>.</strong></em> Affects accuracy, fairness, robustness. The bank is a provider.</p><p>The practical problem is that most vendor contracts and conformity assessments aren&#8217;t drafted with this level of specificity. <em>Not yet.</em> </p><p>Many vendors offer customization without formally assessing it in the conformity assessment. Which means many banks doing what feels like routine customization may already be providers without knowing it.</p><p>If that sounds like the early days of GDPR &#8212; when half the companies processing personal data didn&#8217;t know they were controllers &#8212; the parallel is intentional. Same logic. Same trap. Different regulation.</p><h3>The version where it&#8217;s not even close</h3><p>The bank doesn&#8217;t just train the model on new data. It modifies the architecture. Adds features. Changes the weighting logic. Adjusts decision thresholds beyond what the vendor&#8217;s instructions permit. Integrates an additional ML component that post-processes the output.</p><p>This was the bank in the contract I was reviewing. And no &#8212; there&#8217;s no grey zone here. Architecture changes, additional components, modified decision logic &#8212; none of this was foreseen in the vendor&#8217;s conformity assessment. </p><p>The bank is a provider. Probably has been since the first architecture change. It just didn&#8217;t notice.</p><p><em>The contract still said &#8220;deployer.&#8221;</em></p><h3>The version you didn&#8217;t see coming</h3><p>The bank licenses a general-purpose chatbot. Customer service tool. Not high-risk.</p><p>Then someone in the product team has an idea: use it to screen loan applicants, ask financial questions, feed the responses into the credit pipeline.</p><p>No code changed. No model retrained. Just a decision about how to use it.</p><p>The vendor&#8217;s intended purpose was customer service. The bank&#8217;s use &#8212; creditworthiness assessment &#8212; falls under Annex III. The system is now high-risk, and the bank is its provider under Article 25(1)(c).</p><p>A tool bought for one purpose, quietly repurposed for another. Nobody flagged it because nobody changed the system. But Article 25 doesn&#8217;t require you to change the system. It just requires you to change what you use it for.</p><div><hr></div><h2>Provider of What, Exactly? </h2><p>When the bank crosses the line, a question follows that almost nobody answers clearly: does it become the provider of the entire system, or just the part it modified?</p><p>Article 25(2) says &#8220;the provider that initially placed the AI system on the market or put it into service shall no longer be considered to be a provider of <em>that specific AI system</em>.&#8221;</p><p><strong>&#8220;That specific AI system.&#8221; </strong>Not &#8220;the modified portion of that AI system.&#8221; Not &#8220;the component the deployer changed.&#8221; The whole system. The original provider drops out entirely. The bank steps in.</p><p>My reading &#8212; and I want to be clear this is interpretation, because the Commission hasn&#8217;t addressed it explicitly &#8212; is that the bank becomes provider of the AI system as a whole. Full conformity assessment of the entire system. Full technical documentation. Full quality management coverage.</p><p>You can&#8217;t do a conformity assessment of half a system. When the bank changes the model&#8217;s architecture, the entire system&#8217;s compliance profile shifts &#8212; inputs, processing, outputs, everything.</p><p>One exception worth noting &#8212; for general-purpose AI models (not systems), the GPAI guidelines suggest the modifier&#8217;s obligations concern &#8220;the portion of the model that has actually been modified.&#8221; But that&#8217;s a different regulatory chapter, different rules. Don&#8217;t mix them up.</p><p>Now, Article 25(2) anticipated that this would be hard. The original vendor must cooperate with the new provider &#8212; hand over information, provide technical access, assist with conformity assessment. The bank needs to assess a system it didn&#8217;t fully build. The vendor has to make that possible.</p><p>Except &#8212; <em>and this is where the regulation argues with itself </em>&#8212; Article 25(5) says all of this cooperation is &#8220;without prejudice to intellectual property rights, confidential business information and trade secrets.&#8221; The bank needs access to comply. The vendor may resist on IP grounds.</p><p>The regulation creates the obligation in one paragraph and its own exception three paragraphs later. I&#8217;ll let you sit with that.</p><div><hr></div><h2>What Actually Changes When You Become a Provider</h2><p>The list comparison tells the story faster than I can.</p><p>A deployer under Article 26: follow the provider&#8217;s instructions, assign competent humans for oversight, ensure input data is representative, inform people when AI affects their decisions, cooperate with authorities. Operational. Manageable.</p><p>A provider under Articles 16-21: quality management system covering design to post-market. Technical documentation per Annex IV &#8212; before the system goes live. Conformity assessment. EU declaration of conformity. CE marking. Registration in the EU database. Automatic logging capability built into the system. Post-market monitoring system. Serious incident reporting. Corrective actions when something goes wrong.</p><p>For a bank that was comfortably a deployer and becomes a provider because it fine-tuned a model too aggressively &#8212; the compliance burden doesn&#8217;t just increase. It transforms. The bank needs documentation it doesn&#8217;t have. A conformity assessment it wasn&#8217;t planning for. A quality management system covering AI-specific requirements it probably hasn&#8217;t built.</p><p>One sliver of relief. Article 17(3) allows financial institutions subject to EU financial services law to satisfy the quality management requirements through their existing internal governance. Banks already have governance structures under EU banking regulation. They don&#8217;t need to build a separate AI-specific QMS from scratch &#8212; they can adapt what exists. (One caveat: points (g), (h), and (i) of Article 17(1) &#8212; covering post-market monitoring, incident reporting, and communication with authorities &#8212; are excluded from this deemed-compliance provision. Those you still need to build.)</p><p>But &#8220;we already have governance&#8221; isn&#8217;t the same as &#8220;our governance covers AI Act QMS requirements.&#8221; Anyone who&#8217;s worked in banking compliance knows how far apart those two sentences can be.</p><p>And there&#8217;s no grace period. None. Article 25 triggers are immediate. The moment the bank makes a substantial modification, it&#8217;s a provider. Not &#8220;you have six months to figure it out.&#8221; </p><p>The bank should have completed the conformity assessment <em>before</em> putting the modified system into service. In practice, most banks won&#8217;t realize they&#8217;ve crossed the line until after they&#8217;ve deployed the modified system.</p><p>The fines reflect the stakes. Non-compliance with high-risk AI system obligations: up to &#8364;15 million or 3% of global annual turnover, whichever is higher.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;4840720e-a12d-4abd-8320-48e351dfcf3e&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Prohibited AI Practices Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act with practical steps.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-15T12:03:15.414Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!81vQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5d9b717-c8ef-4b46-a887-59ff99fbba35_6000x4000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/prohibited-ai-practices-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193589773,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:3,&quot;comment_count&quot;:5,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>The Questions I Can&#8217;t Answer Yet</h2><p>A few things the regulation leaves open &#8212; and that the Commission&#8217;s still-pending guidance on substantial modification needs to address.</p><p><em><strong>How specific does &#8220;foreseen&#8221; need to be?</strong></em> A generic &#8220;this system may be customized&#8221; in the vendor&#8217;s documentation &#8212; is that enough? How detailed does the foreseeability assessment need to be? Who bears the burden of proving it &#8212; the vendor claiming they foresaw everything, or the regulator saying they didn&#8217;t foresee <em>this specific</em> change?</p><p><em><strong>What counts as &#8220;affects compliance&#8221;?</strong></em> Almost any modification to an ML model can theoretically affect accuracy, fairness, or robustness &#8212; all Chapter III requirements. If any performance change counts, then any customization is a substantial modification. If only material degradation counts, the regulation doesn&#8217;t say so.</p><p><em><strong>Cumulative drift.</strong></em> Recital 128 says pre-determined continuous learning isn&#8217;t a substantial modification. Fine. But a system learning on the bank&#8217;s data will, over time, diverge from the version the vendor assessed. Each individual step is pre-determined. The cumulative result might not be. At what point does a series of small, foreseen changes become a material departure from the assessed system? Nobody knows.</p><p><em><strong>Cooperation vs. IP.</strong> </em>When the bank needs the vendor&#8217;s proprietary model architecture to perform a conformity assessment, but the vendor claims trade secret protection &#8212; what happens? The regulation doesn&#8217;t resolve this. And I suspect it will take actual litigation to draw the line.</p><div><hr></div><h2>The Exercise</h2><p>Same logic as GDPR. Different stakes.</p><p>Map every AI system you use. For each one &#8212; are you the provider or the deployer? Have you modified it? How? Was that modification foreseen in the vendor&#8217;s conformity assessment? Can you prove it?</p><p>Check your vendor contracts. Do they address AI Act compliance? Do they specify what customization falls within the conformity assessment? Do they include the cooperation obligations Article 25(2) requires?</p><p>And if you&#8217;ve already modified a vendor&#8217;s system &#8212; already trained it on your data, already adjusted its parameters, already integrated it into a larger pipeline &#8212; you&#8217;re not looking at a future compliance question.</p><p>You&#8217;re looking at one that already triggered.</p><p>August 2, 2026. That&#8217;s the deadline for high-risk AI system obligations &#8212; at least, that&#8217;s the date in the AI Act as published. The Commission&#8217;s Digital Omnibus proposal, currently in trilogue, would push it to December 2027. But even if the deadline shifts, Article 25 doesn&#8217;t shift with it. The question of whether you&#8217;re a provider or a deployer isn&#8217;t waiting for a legislative amendment.</p><p>That question is already live.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading AI Law. Decoded.! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Prohibited AI Practices Under the EU AI Act]]></title><description><![CDATA[Eight prohibitions. The highest fines in the regulation.]]></description><link>https://ailawdecoded.com/p/prohibited-ai-practices-eu-ai-act</link><guid isPermaLink="false">https://ailawdecoded.com/p/prohibited-ai-practices-eu-ai-act</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 15 Apr 2026 12:03:15 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!81vQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5d9b717-c8ef-4b46-a887-59ff99fbba35_6000x4000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!81vQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5d9b717-c8ef-4b46-a887-59ff99fbba35_6000x4000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!81vQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5d9b717-c8ef-4b46-a887-59ff99fbba35_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!81vQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5d9b717-c8ef-4b46-a887-59ff99fbba35_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!81vQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5d9b717-c8ef-4b46-a887-59ff99fbba35_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!81vQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5d9b717-c8ef-4b46-a887-59ff99fbba35_6000x4000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!81vQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5d9b717-c8ef-4b46-a887-59ff99fbba35_6000x4000.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b5d9b717-c8ef-4b46-a887-59ff99fbba35_6000x4000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:289441,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.substack.com/i/193589773?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5d9b717-c8ef-4b46-a887-59ff99fbba35_6000x4000.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!81vQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5d9b717-c8ef-4b46-a887-59ff99fbba35_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!81vQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5d9b717-c8ef-4b46-a887-59ff99fbba35_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!81vQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5d9b717-c8ef-4b46-a887-59ff99fbba35_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!81vQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5d9b717-c8ef-4b46-a887-59ff99fbba35_6000x4000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>There&#8217;s a moment &#8212; and if you work in compliance or risk, you&#8217;ve either had it or it&#8217;s coming &#8212; when someone in a meeting turns to you and says: &#8220;So, the AI Act. What do we need to do?&#8221;</p><p>And you sit there thinking &#8212; <em>I barely finished the DORA implementation&#8230;</em></p><p>The regulation is 400+ pages. The guidance documents keep stacking up. </p><p>Every law firm in Europe has published an &#8220;alert&#8221; that somehow manages to create more questions than it answers. </p><p>And you &#8212; the person who already handles GDPR, maybe DORA, maybe NIS2, maybe all three on a good day &#8212; just got handed another regulation to figure out. </p><p>Because apparently regulatory compliance is like a hotel room minibar: <em>there&#8217;s always room for one more.</em></p><p>The instinct is to start reading from Article 1 and work your way through. Don&#8217;t.</p><p>Start with <a href="https://artificialintelligenceact.eu/article/5/">Article 5</a>. Start with the prohibited practices.</p><p>Not because they&#8217;re the most complex &#8212; they&#8217;re not. But because they carry the highest fines in the entire regulation: up to &#8364;35 million or 7% of total worldwide annual turnover, whichever is higher. And because they were the first provisions to take effect &#8212; 2 February 2025. While the rest of the AI Act rolls out in stages, the prohibitions are already live.</p><p>If any of your AI systems are doing something on this list, it doesn&#8217;t matter how far along you are with risk classification or documentation or conformity assessment. You have a problem that outranks all of those.</p><p>That&#8217;s the logic. Start with the biggest exposure. Work down from there.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>What the Commission Said &#8212; and What It Didn&#8217;t</h2><p>The European Commission published <a href="https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act">Guidelines on Prohibited AI Practices</a> on 4 February 2025. Over 100 pages. Non-binding, which means the Court of Justice of the EU has the final word on interpretation. But these guidelines are the Commission&#8217;s view of what each prohibition means, and they will shape how enforcement authorities approach these cases.</p><p>They clarify definitions, provide examples, and take positions on ambiguous questions. They&#8217;re useful. They&#8217;re also &#8212; in a way that&#8217;s becoming familiar with the AI Act &#8212; incomplete in exactly the places where you most need clarity.</p><p>But before we go through the eight practices, one thing. The single most important position in those 100+ pages. The one that changes how you should think about every AI system in your organization.</p><div><hr></div><h2>The Standard &#8220;We Didn&#8217;t Mean to&#8221; Is Not a Defense</h2><p>Article 5 uses a specific formulation across multiple prohibitions: &#8220;with the objective <strong>or</strong> the effect of.&#8221;</p><p>That little word &#8212; <em><strong>&#8220;or&#8221;</strong></em> &#8212; is doing more work than most people realize.</p><p>Intent is not required. If an AI system has the actual effect of materially distorting someone&#8217;s behavior &#8212; even if nobody designed it to do that, even if the deployer didn&#8217;t know it was happening, even if the system sailed through every internal review &#8212; the prohibition applies.</p><p>The guidelines say it directly: the prohibition applies &#8220;even if the material distortion of a person&#8217;s behaviour occurs without the intent of the provider or deployer.&#8221;</p><p>The EU borrowed this approach from the Unfair Commercial Practices Directive. An effects-based standard. A deliberately low bar &#8212; designed to protect people regardless of what the company thought it was building.</p><p>You can build an AI system with the best intentions. Run bias audits. Hire a responsible AI team. Document everything. And if that system &#8212; in practice, in the real world, with real users &#8212; has the effect of manipulating behavior or exploiting vulnerable users, you&#8217;re in violation of Article 5.</p><p>&#8220;We didn&#8217;t mean to&#8221; is not a defence. &#8220;We had a governance framework&#8221; is not a defence. &#8220;Our vendor assured us it was compliant&#8221; is not a defence.</p><p>The effect is enough.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;3cdb2fd8-1d67-485c-86bd-435fcbb2149b&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;What Is an AI System, Actually?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act with practical steps.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-08T12:03:14.634Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!Lj3S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6c33bfb-66f1-4bc7-aba6-ed6c0d1df60e_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/ai-system-definition-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193355320,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:1,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>The Eight Prohibited Practices</h2><h3>1. Subliminal, manipulative, and deceptive AI techniques</h3><p><strong>Article 5(1)(a).</strong> An AI system that deploys subliminal techniques beyond a person&#8217;s consciousness, or purposefully manipulative or deceptive techniques, with the objective or effect of materially distorting behavior &#8212; appreciably impairing their ability to make an informed decision, causing them to take a decision they would not have otherwise taken, in a manner that causes or is reasonably likely to cause significant harm.</p><p>These are the key words: &#8220;<em><strong>Subliminal techniques&#8221;</strong></em> &#8212; imperceptible influences. Visual content flashed during video too fast for the conscious mind to catch. Audio signals below the threshold of awareness.  <em><strong>&#8220;Material distortion&#8221;</strong></em> &#8212; borrowed from consumer protection law &#8212; means a substantial impact on behavior. Not mere influence. Manipulation.</p><p>The grey zone is enormous. Personalized advertising based on user preferences? The guidelines say that&#8217;s not inherently prohibited. But an AI system that dynamically hides cancellation buttons, generates artificial urgency, or adjusts scroll behavior in ways the user can&#8217;t perceive? Closer. Much closer. An adaptive checkout flow that increases pressure when it detects hesitation? <em>That&#8217;s</em> the territory where <em>&#8220;personalization&#8221;</em> starts looking like <em>&#8220;manipulation&#8221;</em> &#8212; and the only thing separating them is whether the effect materially distorts the user&#8217;s decision.</p><p>The Digital Services Act already targets manipulative design. Article 5(1)(a) extends the prohibition to AI-driven manipulation specifically. If your company has AI touching customer-facing products &#8212; and at this point, whose doesn&#8217;t &#8212; this is the one that deserves the longest look in the mirror.</p><h3>2. Exploitation of vulnerabilities</h3><p><strong>Article 5(1)(b).</strong> An AI system that exploits vulnerabilities due to age, disability, or specific social or economic situation &#8212; same &#8220;objective or effect&#8221; standard, same requirement of material distortion and significant harm.</p><p>Three categories of vulnerability. Children and elderly (age). Physical or mental disability. Financial desperation or socio-economic disadvantage.</p><p>The guidelines give one example that&#8217;s worth sitting with: AI systems creating &#8220;personalized and unpredictable rewards through addictive reinforcement schedules.&#8221; Targeting the underdeveloped impulse control in children. Targeting cognitive decline in the elderly. Designed &#8212; or, remember, merely <em>having the effect of</em> &#8212; exploiting the people least equipped to resist.</p><p>This is where the cases stop being hypothetical.</p><p><strong>France&#8217;s CAF system.</strong> Since 2010, France&#8217;s national social security agency has used an AI-driven risk-scoring algorithm to flag welfare fraud &#8212; affecting over 13 million households. The parameters that increase your score: low income, unemployment, living in a disadvantaged neighborhood, having a disability while working. The agency&#8217;s director confirmed they have <strong>never audited the model for bias or discrimination.</strong> In October 2024, <a href="https://www.amnesty.org/en/latest/news/2024/10/france-discriminatory-algorithm-used-by-the-social-security-agency-must-be-stopped/">Amnesty International and 14 coalition partners</a> filed a complaint demanding the system be stopped. Source code obtained by investigators in 2023 exposed the design.</p><p>A system built to detect fraud. Scoring people higher for being poor, disabled, or living in the wrong neighborhood. The intent was fraud detection. The effect was systematic targeting of the most vulnerable people in the system. Under Article 5(1)(b) &#8212; you already know which word matters.</p><p><strong>The Netherlands childcare benefits scandal.</strong> Dutch tax authorities used algorithmic profiling from 2013 to 2020 that classified non-Dutch nationals as &#8220;higher risk.&#8221; Tens of thousands of parents were wrongly accused of fraud. Benefits suspended. Families destroyed. A court ruled the system violated proportionality and privacy under the European Convention on Human Rights (ECHR). The political fallout was severe enough to bring down the Dutch government.</p><p>These aren&#8217;t edge cases from authoritarian regimes. These are European governments. Well-funded. Democratically accountable. And they built exactly the kind of systems that Article 5(1)(b) now prohibits.</p><h3>3. Social scoring</h3><p><strong>Article 5(1)(c).</strong> An AI system that evaluates or classifies natural persons based on social behavior or personal characteristics, resulting in detrimental treatment that is either (1) in social contexts unrelated to where the data was collected, or (2) unjustified or disproportionate to the behavior assessed.</p><p>This is the one most readers will dismiss. <em>We don&#8217;t do social scoring.</em></p><p>Read the cumulative requirements again. The prohibition isn&#8217;t about building China&#8217;s social credit system. It&#8217;s about what happens when a score travels.</p><p>A credit score based on financial behavior, used for lending decisions? Not social scoring under Article 5. That same credit score leaking into housing eligibility, school enrollment decisions, or employment screening? Now you&#8217;re in Article 5 territory. A customer loyalty score from a retail platform used to determine insurance premiums? Same problem.</p><p>The prohibition triggers when evaluation in one context produces detrimental treatment in an unrelated context &#8212; or when the treatment is disproportionate to the behavior being assessed.</p><p>For compliance teams, the question isn&#8217;t &#8220;do we score people?&#8221; Almost everyone does. The question is: <strong>where does the score travel?</strong> If the answer is &#8220;only within the context it was designed for, with proportionate consequences&#8221; &#8212; you&#8217;re likely fine. If the answer is &#8220;we&#8217;re not sure&#8221; &#8212; that&#8217;s the assessment you need to do.</p><p>France&#8217;s CAF system sits here too. A welfare fraud score &#8212; collected in the context of benefits administration &#8212; used to subject people to invasive investigations that affect their access to housing, childcare, and social services. One score. Multiple contexts. Disproportionate consequences.</p><h3>4. Predictive policing</h3><p><strong>Article 5(1)(d).</strong> An AI system that assesses or predicts the likelihood of a person committing a criminal offense, <strong>solely </strong>on the basis of profiling or personality traits and characteristics.</p><p><em><strong>&#8220;Solely&#8221;</strong></em> &#8212; that one word makes this a partial ban, not an absolute one.</p><p><em>&#8220;Personality traits and characteristics&#8221;</em> gets a broad reading in the guidelines: gender, race, ethnicity, address, income, health, preferences, behavior, financial status. Non-exhaustive. AI systems that support human assessment based on objective, verifiable facts directly linked to criminal activity are still permitted &#8212; provided the human decision-maker actually relies on the assessment. Rubber-stamping an algorithmic output doesn&#8217;t count.</p><p>Geographic crime mapping &#8212; identifying high-crime areas from historical data &#8212; is not prohibited. It targets patterns, not people.</p><p>Here&#8217;s where it gets interesting. Geolitica (formerly PredPol), deployed in Plainfield, New Jersey. A predictive policing system that made over 23,000 crime predictions. Accuracy: less than 0.5%. The system is a case study in two things &#8212; the unreliability of person-based prediction, and the loophole built into Article 5(1)(d). Reframe person-based prediction as geographic analysis and you move from &#8220;prohibited&#8221; to &#8220;permitted.&#8221; Same underlying data. Different framing. Different legal outcome. The regulation bans predicting whether <em>you</em> will commit a crime. It doesn&#8217;t ban predicting whether a crime will happen <em>near you</em>. That distinction is thinner than it looks.</p><h3>5. Untargeted facial image scraping</h3><p><strong>Article 5(1)(e).</strong> An AI system that creates or expands facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.</p><p>This is the hardest line in Article 5. An absolute ban. No exceptions. No law enforcement carve-out. No <em>&#8220;but we really need it for security&#8221;</em> path. Nothing. Of all eight prohibitions, this is the only one where even law enforcement gets no door to knock on.</p><p><em><strong>&#8220;Untargeted&#8221;</strong></em> means indiscriminate mass collection not focused on specific individuals. <em><strong>&#8220;Scraping&#8221;</strong></em> means automated extraction using crawlers and bots. And the detail that matters: consent to posting images on social media does not equal consent for facial recognition databases. You put your photo on LinkedIn &#8212; that doesn&#8217;t mean a company can feed it into a facial recognition system. The guidelines are clear on this.</p><p>One more thing. Multiple targeted scrapes that incrementally build the same database still count as untargeted scraping. You can&#8217;t slice an ocean into cups and call each one a glass of water.</p><p><strong>Clearview AI</strong> is the case that defines this category. A US company that scraped the internet to build a database of over 60 billion facial images. GDPR enforcement hit from four directions &#8212; Italy fined them &#8364;20 million in February 2022, France &#8364;20 million in October 2022, Austria issued a decision in 2023, and the Netherlands fined them &#8364;30.5 million in October 2024. Total: approximately &#8364;100 million in GDPR fines across four jurisdictions.</p><p>Under the AI Act, Clearview&#8217;s entire model is now explicitly a prohibited practice &#8212; not just a data protection violation, but a banned activity carrying up to &#8364;35 million or 7% of turnover.</p><p>The enforcement gap tells its own story. Those GDPR fines were imposed on a US company with no EU presence. Collection has been... let&#8217;s call it aspirational. <a href="https://noyb.eu/en/criminal-complaint-against-facial-recognition-company-clearview-ai">Noyb went a different route</a> &#8212; filing a criminal complaint against Clearview executives in Austria. If successful, that means personal liability for anyone who travels to Europe. The AI Act doesn&#8217;t solve cross-border enforcement. But it raises the ceiling on what happens when enforcement catches up.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;27052376-178f-4275-82a9-a145e90f01d5&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Why the EU AI Act Matters Even If You're Not in the EU&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act with practical steps.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-05T13:54:22.853Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!wrLn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb08944ca-a6dd-44b0-a118-8176d76942bc_4500x3000.heic&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/eu-ai-act-applies-outside-eu&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193044187,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:1,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h3>6. Emotion recognition in workplace and education</h3><p><strong>Article 5(1)(f).</strong> An AI system whose purpose is to infer emotions of natural persons in a workplace or educational institution.</p><p>The scope is broader than most people expect. <em><strong>&#8220;Workplace&#8221;</strong></em> covers any setting where work is performed &#8212; including recruitment, hiring, temporary work, remote work. The prohibition applies from the moment someone is a job candidate. Not from day one on the job. From the application. <em><strong>&#8220;Educational institutions&#8221;</strong></em> means public and private, all levels, in-person and online, including admissions.</p><p>Two narrow exceptions. Medical &#8212; but only CE-marked medical devices for actual therapeutic purposes. Monitoring employee stress because HR wants a <em>&#8220;wellness dashboard&#8221;</em>? That&#8217;s not medical. Safety &#8212; but only for concrete risks to life or health. Construction workers at height. Pilots. Truck drivers on long shifts. A general interest in &#8220;employee wellbeing&#8221; doesn&#8217;t meet the threshold.</p><p>If you&#8217;ve evaluated &#8212; or already deployed &#8212; video interview analysis tools, employee engagement monitoring, classroom attention tracking, or proctoring systems that analyze facial expressions... this is the prohibition with your name on it. Remember the person who asked <em>&#8220;So, the AI Act. What do we need to do?&#8221;</em> in that meeting? This is what I&#8217;d tell them to check first. Because these products were actively marketed to companies until very recently. Some still are.</p><p>The grey zone worth watching: systems that track behavioral signals &#8212; cursor hesitation, typing cadence, mouse movement patterns &#8212; without calling the output <em><strong>&#8220;emotion.&#8221;</strong></em> A product labeled <em>&#8220;engagement scoring&#8221;</em> or <em>&#8220;confidence assessment&#8221;</em> instead of <em>&#8220;emotion recognition&#8221;.</em> The guidelines focus on purpose &#8212; inferring emotions. But when the function is analyzing human behavior to deduce internal states, the label you put on the output starts to look like a distinction without a difference. This is how I understand it, it&#8217;s not the law. But I wouldn&#8217;t want to be the test case.</p><h3>7. Biometric categorization by sensitive characteristics</h3><p><strong>Article 5(1)(g).</strong> Biometric categorization systems that categorize individuals based on biometric data to deduce or infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life, or sexual orientation.</p><p>One narrow exception: labeling or filtering lawfully acquired biometric datasets for training purposes &#8212; ensuring ethnic diversity in medical imaging training data, for example. That&#8217;s permitted. Using categorization operationally, against real individuals in real time? That&#8217;s the prohibition.</p><p>The formulation <em>&#8220;deduce or infer&#8221; </em>is deliberately broad. A confidence score correlated with race triggers the prohibition &#8212; the system doesn&#8217;t need to output a categorical label that says &#8220;this person is [race].&#8221; A probability is enough. A security system that wasn&#8217;t designed to infer race but whose outputs happen to correlate with it? Still caught. The question isn&#8217;t what you built the system to do. <em>It&#8217;s what the system does.</em></p><h3>8. Real-time remote biometric identification by law enforcement</h3><p><strong>Article 5(1)(h).</strong> Real-time remote biometric identification in publicly accessible spaces for law enforcement. The most politically charged prohibition in the entire AI Act &#8212; and the only one where the EU built a detailed exception framework directly into the article. Which tells you something about the lobbying pressure behind it.</p><p><em><strong>&#8220;Real-time&#8221; </strong></em>means simultaneous with data capture &#8212; live identification as it happens. Analyzing recorded footage after the fact (post-RBI) is a different legal category &#8212; classified as high-risk, not prohibited. That distinction sounds clean. In practice, the boundary is blurry. If you analyze CCTV footage ten minutes after capture, is that &#8220;real-time&#8221;? An hour? The guidelines don&#8217;t draw the line.</p><p>Three narrow exceptions &#8212; all requiring prior judicial or independent authority authorization, a fundamental rights impact assessment, and EU database registration:</p><ol><li><p>Searching for specific crime victims (trafficking, abduction, sexual exploitation)</p></li><li><p>Preventing a specific, substantial, imminent threat to life &#8212; or a foreseeable terrorist attack</p></li><li><p>Locating suspects for serious crimes listed in Annex II of the AI Act, punishable by at least four years imprisonment</p></li></ol><p>Austria currently has a framework authorizing law enforcement to access public surveillance data in real-time without judicial permission. That framework is non-compliant with Article 5(1)(h). Hungary is developing a nationwide facial recognition database for law enforcement. Compliance status unclear.</p><p>For most corporate readers, this prohibition is primarily relevant if you&#8217;re a vendor selling biometric identification technology to law enforcement &#8212; or if you&#8217;re concerned about the &#8220;national security&#8221; exemption. Article 2(3) exempts AI systems used exclusively for national security purposes. A real-time biometric system reframed as national security escapes Article 5 entirely. The guidelines don&#8217;t close this door.</p><div><hr></div><h2>The Patterns Worth Seeing</h2><p>Eight practices, one article. It&#8217;s tempting to treat them as a flat list. They&#8217;re not. Step back and three patterns emerge.</p><p><strong>Not all prohibitions are created equal.</strong> Three tiers. <em>Absolute bans</em> &#8212; no exceptions at all. Untargeted facial scraping sits here, with biometric categorization close behind. <em>Near-absolute bans </em>&#8212; manipulation, exploitation, social scoring, predictive policing &#8212; where the path through is so narrow it barely exists. And <em>conditional bans</em> &#8212; emotion recognition and real-time biometric ID &#8212; where exceptions are real but come with procedural safeguards heavy enough to deter most uses. Knowing which tier you&#8217;re dealing with changes the conversation from &#8220;are we allowed to do this?&#8221; to &#8220;what would we need to do to be allowed?&#8221;</p><p><strong>Context determines everything for social scoring.</strong> The prohibition isn&#8217;t about scoring. It&#8217;s about spillover. Where does the score travel? Who sees it? What decisions does it touch? A score that stays in its lane is fine. A score that leaks into unrelated contexts &#8212; or produces disproportionate consequences &#8212; triggers Article 5.</p><p><strong>Three prohibitions involve law enforcement &#8212; with three different levels of restriction.</strong> Predictive policing: partial ban &#8212; the &#8220;solely&#8221; requirement creates a narrow path. Facial scraping: absolute ban &#8212; no exceptions at all. Real-time biometric ID: conditional ban &#8212; exceptions exist but come with procedural safeguards. The EU drew lines even for law enforcement. But the lines are drawn differently for each practice. And the national security exemption in Article 2(3) creates a potential backdoor for all three.</p><div><hr></div><h2>What the Guidelines Leave Open</h2><h3>Nine questions without answers</h3><p>100+ pages of guidance. And the hardest questions? Left for another day.</p><p><strong>1. The &#8220;solely&#8221; threshold.</strong> How much additional objective data allows AI use in criminal risk assessment? No standard.</p><p><strong>2. How to identify &#8220;vulnerability.&#8221;</strong> Where does &#8220;specific socio-economic situation&#8221; begin? Is a single parent on minimum wage vulnerable? A recent graduate with student debt? No line drawn.</p><p><strong>3. &#8220;Reasonably likely to cause significant harm.&#8221;</strong> What probability? How significant? No quantitative threshold.</p><p><strong>4. National security vs. law enforcement.</strong> A real-time biometric system reframed as national security escapes the prohibition entirely. The boundary isn&#8217;t defined.</p><p><strong>5. Untargeted scraping circumvention.</strong> Multiple targeted scrapes building the same database &#8212; how many? Over what timeline? The principle is stated, the mechanics aren&#8217;t.</p><p><strong>6. Where &#8220;real-time&#8221; ends.</strong> If you analyze CCTV footage an hour after capture, is that real-time? A day? The line between prohibited real-time identification and permitted retrospective analysis isn&#8217;t drawn.</p><p><strong>7. Generative AI and manipulation.</strong> How does Article 5(1)(a) apply to foundation models and LLMs? The guidelines don&#8217;t address this.</p><p><strong>8. GDPR and Digital Services Act interplay.</strong> The prohibited practices overlap with both. How the obligations interact &#8212; or conflict &#8212; is unresolved.</p><p><strong>9. The &#8220;material distortion&#8221; threshold.</strong> How much behavior change triggers the prohibition? The standard says &#8220;material.&#8221; It doesn&#8217;t say what that means in practice.</p><p>These aren&#8217;t academic gaps. They&#8217;re the questions that will land on your &#8212; or someone else&#8217;s &#8212; desk when trying to answer &#8220;what do we need to do about the AI Act?&#8221; &#8212; and there won&#8217;t be a clear answer.</p><div><hr></div><h2>What to Do</h2><p>Having no clear answer is fine. Having no answer is not. You need an answer that&#8217;s something else than <em>&#8220;it&#8217;s complicated.&#8221;</em></p><p>I&#8217;d say this:</p><p><em><strong>Start by mapping your AI systems against Article 5. </strong></em>Not a theoretical exercise &#8212; a real one, with the technical team in the room. For each system: could it be deploying manipulative techniques, even unintentionally? Could it be exploiting vulnerable users &#8212; through its design, its targeting, or its effects? Does any scoring or classification travel across context boundaries? Does anything in the workplace or education space infer emotions or internal states, even under a different label?</p><p>The standard isn&#8217;t &#8220;did we intend this.&#8221; It&#8217;s &#8220;does the system do this.&#8221;</p><p><em><strong>Trace where your scores go.</strong> </em>If you score, classify, or categorize people &#8212; and most AI systems do, somewhere in the pipeline &#8212; follow the output. Who consumes it. What decisions it touches. If a score generated for one purpose is influencing decisions in another context, you have an Article 5(1)(c) question that needs an answer.</p><p><em><strong>Check your vendors.</strong> </em>If you&#8217;re using third-party AI tools &#8212; video interview platforms, employee monitoring software, customer analytics, proctoring systems &#8212; ask what they actually do under the hood. If a vendor&#8217;s product turns out to be prohibited under Article 5, the vendor isn&#8217;t the only one with a problem. You&#8217;re liable as a deployer. &#8220;We bought it from someone else&#8221; is not a defense. &#8220;Putting into service&#8221; triggers the prohibition &#8212; regardless of who built the system.</p><p><em><strong>Document your reasoning.</strong> </em>For every system where you conclude &#8220;this isn&#8217;t a prohibited practice&#8221; &#8212; write down why. Article by article. Element by element. Not because the regulator has asked for it yet. Because when enforcement starts &#8212; and it will &#8212; a documented assessment is the difference between a defensible position and an assumption you can&#8217;t explain.</p><p>No AI Act fines for prohibited practices have been issued yet. It&#8217;s April 2026. But the machinery is in place. Complaints have been filed &#8212; France&#8217;s CAF, Clearview&#8217;s criminal exposure in Austria. <a href="https://digital-strategy.ec.europa.eu/en/policies/market-surveillance-authorities-under-ai-act">Market Surveillance Authorities</a> are operational. GDPR enforcement against the same conduct has already cleared &#8364;100 million. The AI Act just raised the ceiling.</p><p>So if someone turns to you in a meeting and asks <em>&#8220;what do we need to do about the AI Act?&#8221; </em>&#8212; you probably don&#8217;t need a full answer by Friday. But you need to know three things: the prohibitions exist, they&#8217;re already in force, and the law doesn&#8217;t care what you intended.</p><p>Start there. High-risk classification, documentation, conformity assessment &#8212; that all comes next. But it comes after this.</p><p>You don&#8217;t build a house from the roof down.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading AI Law. Decoded.! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[What Is an AI System, Actually?]]></title><description><![CDATA[The EU definition &#8212; and why it's causing more debate than clarity.]]></description><link>https://ailawdecoded.com/p/ai-system-definition-eu-ai-act</link><guid isPermaLink="false">https://ailawdecoded.com/p/ai-system-definition-eu-ai-act</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 08 Apr 2026 12:03:14 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Lj3S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6c33bfb-66f1-4bc7-aba6-ed6c0d1df60e_4500x3000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Lj3S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6c33bfb-66f1-4bc7-aba6-ed6c0d1df60e_4500x3000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Lj3S!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6c33bfb-66f1-4bc7-aba6-ed6c0d1df60e_4500x3000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Lj3S!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6c33bfb-66f1-4bc7-aba6-ed6c0d1df60e_4500x3000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Lj3S!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6c33bfb-66f1-4bc7-aba6-ed6c0d1df60e_4500x3000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Lj3S!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6c33bfb-66f1-4bc7-aba6-ed6c0d1df60e_4500x3000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Lj3S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6c33bfb-66f1-4bc7-aba6-ed6c0d1df60e_4500x3000.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b6c33bfb-66f1-4bc7-aba6-ed6c0d1df60e_4500x3000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:363657,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.substack.com/i/193355320?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6c33bfb-66f1-4bc7-aba6-ed6c0d1df60e_4500x3000.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Lj3S!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6c33bfb-66f1-4bc7-aba6-ed6c0d1df60e_4500x3000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Lj3S!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6c33bfb-66f1-4bc7-aba6-ed6c0d1df60e_4500x3000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Lj3S!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6c33bfb-66f1-4bc7-aba6-ed6c0d1df60e_4500x3000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Lj3S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6c33bfb-66f1-4bc7-aba6-ed6c0d1df60e_4500x3000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>I had dinner with a friend recently. </p><p>Smart guy. Corporate Counsel in a Big Tech company, who deals with compliance daily. </p><p>We got to talking about the EU AI Act &#8212; as you do when two lawyers meet and the wine hasn&#8217;t arrived yet &#8212; and he offered what he clearly considered a clean, practical test.</p><p>&#8220;If it&#8217;s software,&#8221; he said, &#8220;it&#8217;s not AI. And if it&#8217;s not AI, the AI Act doesn&#8217;t apply.&#8221;</p><p>He said it like someone closing a door. </p><p>Simple. Done. Next topic.</p><p>And I sat there thinking &#8212; that&#8217;s not quite right. </p><p>But it&#8217;s also not entirely wrong. </p><p>And the distance between <em>&#8220;not quite right&#8221; </em>and <em>&#8220;not entirely wrong&#8221;</em> is exactly where most companies are going to get stuck.</p><p>The EU AI Act doesn&#8217;t regulate &#8220;artificial intelligence&#8221; the way most people understand that term. </p><p>It regulates <em><strong>&#8220;AI systems&#8221;</strong></em> &#8212; a legal concept with a specific definition, seven elements, and a set of boundaries that don&#8217;t map neatly onto what your IT team thinks AI is or what your legal team thinks software is.</p><p>If you don&#8217;t know whether your system qualifies as an AI system under Article 3(1), nothing else in the regulation makes sense. Not the risk classification. Not the transparency requirements. Not the documentation obligations. Not the fines.</p><p>This is the first question. Everything else comes after.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>The Definition &#8212; Seven Elements, One Sentence</h2><p><a href="https://artificialintelligenceact.eu/article/3/">Article 3(1) of the EU AI Act</a> defines an <em><strong>&#8220;AI system&#8221;</strong></em> as:</p><blockquote><p>A machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.</p></blockquote><p>One sentence. Seven elements. And the European Commission needed an <a href="https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application">entire set of guidelines</a> &#8212; published on 6 February 2025 &#8212; to explain what it means.</p><p>The definition is aligned with the OECD&#8217;s definition of an AI system, which matters for international consistency. But consistency in wording doesn&#8217;t mean clarity in application.</p><p><strong>First, a machine-based system.</strong> Software, hardware, or both. Running on a server, a device, embedded in a product. This is the least interesting element &#8212; if it runs on a machine, it qualifies. Moving on.</p><p><strong>Second, designed to operate with varying levels of autonomy.</strong> The system needs some degree of independence from human involvement. Not full autonomy &#8212; partial counts. But a system &#8220;designed to operate solely with full manual human involvement and intervention&#8221; is out. The word &#8220;designed&#8221; matters. It&#8217;s about <em><strong>intent</strong></em>, not just current operation. A system designed to run autonomously but currently supervised by a human? Still designed for autonomy.</p><p><strong>Third, may exhibit adaptiveness after deployment.</strong> <em>&#8220;May&#8221;</em> is the word doing the heavy lifting. Self-learning, runtime adaptation &#8212; these are features some AI systems have. But their absence doesn&#8217;t disqualify a system. A model trained once, frozen, and deployed without ever updating itself can still be an AI system if it meets the other elements. Adaptiveness is a characteristic, not a requirement.</p><p><strong>Fourth, for explicit or implicit objectives.</strong> The system pursues goals. Explicit ones are programmed in. Implicit ones are derived from the system&#8217;s behavior &#8212; a large language model doesn&#8217;t have a stated <em>&#8220;objective&#8221;</em> in the traditional sense, but it implicitly aims to produce coherent outputs. This element is broad by design.</p><p><strong>Fifth, infers, from the input it receives.</strong> This is the one that matters most. The element that separates AI systems from traditional software. Inference means the system derives outputs through a process that goes beyond executing pre-programmed rules. It involves deriving models or algorithms, reasoning, pattern recognition &#8212; something more than &#8220;if X, then Y.&#8221;</p><p><a href="https://artificialintelligenceact.eu/recital/12/">Recital 12</a> puts it plainly: <em>&#8220;A key characteristic of AI systems is their capability to infer.&#8221;</em> It then excludes &#8220;simpler traditional software systems or programming approaches&#8221; and systems &#8220;based on the rules defined solely by natural persons to automatically execute operations.&#8221;</p><p>The techniques that enable inference, according to the Act and the guidelines, fall into two families:</p><ul><li><p><em>Machine learning approaches</em> &#8212; systems that learn patterns from data, whether from labeled examples, from finding structure in data on their own, or from improving through trial and error. This includes deep learning and neural networks &#8212; the technology behind image recognition, language models like ChatGPT, and most of what makes AI headlines. </p></li><li><p>And <em>logic- and knowledge-based approaches</em> &#8212; systems that reason using structured knowledge, like expert systems that apply a web of rules and relationships to reach conclusions (think medical diagnosis tools or legal reasoning engines).</p></li></ul><p><strong>Sixth, how to generate outputs such as predictions, content, recommendations, or decisions.</strong> Four output types, non-exhaustive. Predictions, newly generated content (text, images, audio), recommendations, and decisions.</p><p><strong>Seventh, that can influence physical or virtual environments.</strong> The outputs must have potential to affect something. Physical environments (robotics, autonomous vehicles) or virtual ones (content moderation, search results, recommendations). Broadly interpreted.</p><p>Seven elements. All must be present. Miss one, and the system falls outside the definition.</p><div><hr></div><h2>What the Guidelines Say Is Not an AI System</h2><p>A few weeks after that dinner, I was talking to an IT architect. </p><p>He mentioned a program his team was building &#8212; a prediction system for capacity planning. </p><p>Nothing fancy, he said. Takes last year&#8217;s data, runs a simple statistical formula, estimates next quarter&#8217;s numbers. No model training. No learning. Just math.</p><p>Something clicked.</p><p>Because the Commission&#8217;s February 2025 guidelines describe almost exactly that kind of system. And they say &#8212; explicitly &#8212; it&#8217;s not an AI system under the AI Act.</p><p>The guidelines identify four categories of systems that fall outside the definition. </p><p><em>The common thread:</em> although some of these systems have a capacity to infer, they fall outside scope &#8220;because of their limited capacity to analyze patterns and adjust autonomously their output.&#8221;</p><p>That phrase &#8212; <em><strong>&#8220;limited capacity&#8221;</strong></em> &#8212; is doing enormous work. </p><p>The guidelines aren&#8217;t saying these systems can&#8217;t infer at all. They&#8217;re saying the inference is too limited to qualify.</p><p>With that laid out, here are the four categories:</p><h3>1. Systems for mathematical optimisation</h3><p>Systems used to improve or approximate traditional, well-established optimisation methods &#8212; including linear or logistic regression.</p><p>In practice, this covers a logistic regression model estimating credit default probability with fixed coefficients. A linear regression forecasting demand. The guidelines follow the OECD&#8217;s line here: simple statistical techniques like linear or logistic regression fall outside the AI system definition.</p><p>For financial services, this is significant. Logistic regression is a workhorse in underwriting, credit scoring, and risk assessment. If these fall outside the definition, a meaningful number of systems in banking and insurance are potentially out of scope &#8212; even systems that would qualify as &#8220;high-risk&#8221; under Annex III if they were AI systems.</p><p><em>The catch:</em> the guidelines say "linear or logistic regression methods." They don't address what happens as you move up the complexity ladder. If your data science team uses terms like ridge regression, lasso, polynomial regression, or random forests &#8212; those aren't covered by this exclusion. And nobody knows yet where they land. The further you get from simple linear or logistic regression, the harder it becomes to rely on this carve-out.</p><h3>2. Basic data processing</h3><p>Systems that follow &#8220;predefined, explicit instructions or operations... developed and deployed to execute tasks based on manual inputs or rules, without any learning, reasoning or modelling at any stage of the system lifecycle.&#8221;</p><p><em>In practice:</em> database management systems that sort and filter based on specific criteria. Standard spreadsheet applications without AI functionality. Inventory management systems with fixed rules. Traditional business logic engines. Workflow engines that route documents based on if/then logic.</p><p>This is the clearest exclusion. If a system simply executes human-written rules with no learning component at any stage, it&#8217;s not an AI system under the AI Act.</p><h3>3. Classical heuristics</h3><p>Rule-based problem-solving systems that &#8220;typically involve rule-based approaches, pattern recognition, or trial-and-error strategies rather than data-driven learning.&#8221; They do not evolve through data or experience.</p><p>The guidelines give the example of chess programs based solely on minimax algorithms. Also in this category: rule-based spam filters using keyword matching, basic pattern-matching systems, traditional search algorithms.</p><p>These are systems that might feel smart &#8212; that might even be called &#8220;AI&#8221; internally &#8212; but aren&#8217;t learning from data. A fraud detection system with 500 hand-coded rules (&#8221;flag transactions over &#8364;10,000 from new accounts&#8221;) is a classical heuristic. Even if the compliance team has been calling it their &#8220;AI fraud system&#8221; for three years.</p><h3>4. Simple prediction systems</h3><p>Systems that predict using basic statistical rules and do not adapt or evolve over time.</p><p>The guidelines give a specific example: &#8220;a program that estimates future stock prices by using an estimator with the &#8216;mean&#8217; strategy to establish a baseline prediction.&#8221; A system that predicts next month&#8217;s temperature by averaging the last ten years of data falls here too.</p><p>This is the exclusion that will generate the most friction between legal and technical teams. To a data scientist, a prediction system &#8212; even a simple one &#8212; is doing something that looks like AI. To the guidelines, if the prediction mechanism is a fixed statistical rule that doesn&#8217;t learn or adapt, it&#8217;s out.</p><div><hr></div><h2>What Clearly Qualifies</h2><p>The other side of the line is less controversial. The guidelines and Recital 12 make clear that the following approaches create AI systems when used as part of a system meeting the full Article 3(1) definition.</p><h3>Machine learning systems</h3><p>Systems that learn from data &#8212; whether they learn from labeled examples (this is called supervised learning), find hidden patterns or groupings on their own (unsupervised learning), or improve through trial and error (reinforcement learning). Deep learning and neural networks fall here too &#8212; the technology behind image recognition, large language models, and most of what the world currently calls "AI." If your technical team says a system was "trained on data," you're almost certainly in this category.</p><h3>Logic- and knowledge-based systems</h3><p>Systems that reason using structured knowledge &#8212; expert systems (medical diagnosis tools, legal reasoning engines), systems that represent relationships between concepts and draw conclusions from them, and systems that use logical rules to infer new information from existing knowledge. The distinguishing feature from the excluded "basic" rule-based systems: these don't just execute rules mechanically. They reason with them.</p><h3>In practice, this means:</h3><ul><li><p>A machine learning model trained on historical data to predict credit defaults &#8212; <em><strong>in scope</strong></em>. </p><ul><li><p>Contrast with a logistic regression estimator using fixed coefficients &#8212; <em><strong>that&#8217;s out.</strong></em></p></li></ul></li><li><p>A recommendation engine that learns user preferences over time &#8212; <em><strong>in scope</strong></em>.</p></li><li><p>A chatbot powered by a large language model &#8212; <em><strong>in scope</strong></em>.</p></li><li><p>A computer vision system trained to detect defects on a production line &#8212; <em><strong>in scope.</strong></em></p></li><li><p>An expert system for medical diagnosis that uses a knowledge base and inference engine &#8212; <em><strong>in scope</strong></em>.</p></li><li><p>A natural language processing system for document classification &#8212; <em><strong>in scope</strong></em>.</p></li></ul><p><strong>The pattern</strong>: if the system learns from data, reasons beyond its explicit rules, or derives models through training &#8212; <em>it&#8217;s in</em>.</p><div><hr></div><h2>The Paradox</h2><p>I've <a href="https://ailawdecoded.substack.com/p/why-is-everyone-so-confused-with">written before</a> about why the AI Act is generating more confusion than clarity. The same applies when it comes to the definition of an AI system.</p><p>Recital 12 excludes systems <em>&#8220;based on the rules defined solely by natural persons to automatically execute operations.&#8221;</em> Rules written by humans, executed mechanically. Out.</p><p>But the same guidelines include logic- and knowledge-based approaches &#8212; expert systems, symbolic reasoning, inference engines &#8212; where the rules are &#8220;<em>encoded by human experts&#8221;</em> through <em>&#8220;rules, ontologies, or knowledge graphs.</em>&#8221;</p><p>Both are rule-based. Both have rules defined by humans. One is out. One is in.</p><p>The guidelines never draw an explicit line between a &#8220;simple&#8221; rule-based system that&#8217;s excluded and a &#8220;complex&#8221; rule-based system that&#8217;s included as a logic- or knowledge-based approach. There&#8217;s no test. No threshold. No &#8220;if your rule-based system has more than N rules, it&#8217;s in.&#8221; Nothing.</p><p>My reading &#8212; <strong>and this is my interpretation, not settled law</strong> &#8212; is that the distinguishing factor is the inference capacity. An if/then business logic engine applies rules mechanically. It does what the programmer told it to do, every time, the same way. An expert system with an inference engine can chain rules together, handle uncertainty, weigh competing rules, and reach conclusions that weren&#8217;t explicitly programmed as a single path. One executes. The other reasons.</p><p>But the guidelines don&#8217;t say this explicitly. And multiple law firm analyses have flagged the same contradiction. One noted that the guidelines <em>&#8220;appear to lack an obvious underlying logic to the examples that fall inside and outside of scope.</em>&#8221; Another pointed out the paradox of excluding &#8220;rules defined solely by humans&#8221; while including expert systems where the rules are... defined by humans.</p><p>The logistic regression question adds another layer. Logistic regression is out. But what about a logistic regression model used as part of a larger ensemble? One whose parameters are updated periodically with new data? One used for feature selection that feeds results into a neural network? The guidelines address the technique in isolation. Real systems use combinations.</p><p>And the adaptiveness element creates its own trap. The definition says adaptiveness is not required &#8212; &#8220;may exhibit.&#8221; But one of the key reasons the four exclusion categories are excluded is precisely that they <em>&#8220;do not adapt or evolve over time.&#8221;</em> Adaptiveness isn&#8217;t required to be an AI. But its absence is one reason it might not be an AI. This isn&#8217;t a contradiction exactly, but it creates a zone where a non-adaptive system might or might not qualify depending on how sophisticated its inference is.</p><p>The <em>"limited capacity"</em> phrase &#8212; the reason all four exclusion categories are out &#8212; is never defined. Where does "limited" end and "sufficient" begin? The guidelines don't say. Which leaves a genuine grey zone for a whole class of techniques that sit between simple statistics and full-blown machine learning. If your technical team mentions gradient boosted trees, simple neural networks, nearest-neighbor methods, naive Bayes, or support vector machines &#8212; ask them to explain what those systems actually do. Because the guidelines don't address any of them.</p><p>All more sophisticated than logistic regression. All arguably capable of inference. All potentially falling into the <em>&#8220;limited capacity&#8221;</em> gap that the guidelines created but didn&#8217;t fill.</p><div><hr></div><h2>Two Conversations, One Problem</h2><p>I keep coming back to those two conversations.</p><p>The lawyer who drew a clean line &#8212; software on one side, AI on the other &#8212; and moved on with his meal. The IT architect who described a prediction system that would be unambiguously &#8220;AI&#8221; in his professional world but falls outside the AI Act&#8217;s definition entirely.</p><p>Neither was wrong, exactly. But neither had the full picture. And the space between their perspectives is where compliance actually lives.</p><p>The lawyer&#8217;s instinct &#8212; <em>&#8220;if it&#8217;s software, it&#8217;s not AI&#8221;</em> &#8212; gets at something real. The AI Act doesn&#8217;t regulate all software. It regulates a specific subset of software with specific characteristics. But &#8220;it&#8217;s software, not AI&#8221; is imprecise to the point of being dangerous. An expert system is software. A deep learning model deployed as a web service is software. A chatbot running on an API is software. All of them are AI systems under the AI Act.</p><p>What the lawyer probably meant was: if it&#8217;s traditional software using fixed rules, it&#8217;s not an AI system under the AI Act. That&#8217;s closer to correct. But only if the system truly has no inference capability beyond mechanical rule execution. And the only way to know that is to look inside the system &#8212; at what it actually does, not what it&#8217;s called.</p><p>The IT architect&#8217;s perspective carries a different risk. In his world &#8212; and in the world of every data science team I&#8217;ve encountered &#8212; &#8220;AI&#8221; includes any system that makes predictions. Any system that uses data to generate outputs. Logistic regression, linear regression, decision trees &#8212; all &#8220;ML/AI.&#8221; All part of the toolkit.</p><p>Under the EU AI Act, many of those are not AI systems. A logistic regression model with fixed coefficients? Not AI under the AI Act. A simple averaging prediction system? Not AI. A rule-based system with hand-coded rules? Not AI.</p><p>This matters in both directions. Technical teams may flag systems for compliance that don't need it &#8212; burning resources, delaying projects, creating unnecessary work. Or they may hear "your logistic regression isn't AI under the AI Act" and conclude that nothing in their pipeline needs attention &#8212; missing the more sophisticated model sitting right next to it that probably does qualify.</p><p>The translation both teams need is this: <strong>&#8220;AI&#8221; under the EU AI Act is a legal definition.</strong> It doesn&#8217;t match the colloquial understanding and it doesn&#8217;t match the technical one. <em>Something can be artificial intelligence in every data science textbook and not be an &#8220;AI system&#8221; under Article 3(1)</em>. And something your legal team dismisses as &#8220;just software&#8221; can still qualify if it has the right kind of inference capability.</p><p>Neither team can do this analysis alone. Legal can&#8217;t assess scope without understanding what the system technically does. Tech team can&#8217;t assess it without understanding what the legal definition actually requires. <em>The exercise has to be joint.</em></p><div><hr></div><h2>Borderline Cases &#8212; Where the Line Gets Blurred</h2><p>Theory is useful. Specific examples are better. </p><p>So, let&#8217;s take a look where the definition meets actual systems.</p><p><strong>The credit scoring model.</strong> A bank uses logistic regression to score credit applications. Trained on historical data, fixed coefficients, no post-deployment learning. The data science team calls it an ML model. The guidelines say logistic regression falls outside the AI system definition. Likely not in scope. But &#8212; if the bank periodically retrains with new data and redeploys, the picture gets murkier. And if the logistic regression is one component in a larger pipeline that includes ML elements, the pipeline as a whole might still qualify.</p><p><strong>The rule-based fraud detection system.</strong> An insurer runs a system with hundreds of hand-coded rules &#8212; &#8220;if claim amount exceeds &#8364;50,000 and policyholder tenure is under one year and no police report was filed, flag for review.&#8221; Rules written by domain experts. No learning component. The guidelines would classify this as basic data processing or classical heuristics. Not AI. The moment the insurer adds a machine learning layer &#8212; a model that scores flagged claims by likelihood of actual fraud based on historical outcomes &#8212; that component moves toward the definition. One layer changes everything.</p><p><strong>The recommendation engine.</strong> An e-commerce company runs two versions. Version A uses machine learning to learn patterns from user behavior &#8212; what people browse, buy, and ignore &#8212; and generates personalized recommendations based on those patterns. Likely an AI system. Version B uses a simple lookup &#8212; "customers who bought X also bought Y" &#8212; based on counting how often products are purchased together. No learning, no adaptation, just a fixed rule. Closer to basic data processing. Probably not an AI system. Two systems, same job, different classifications &#8212; <em>because the definition cares about how the system works, not what it does</em>.</p><p><strong>The chatbot spectrum.</strong> A basic FAQ chatbot that matches keywords in your question to pre-written answers from a fixed database? Not AI under the AI Act. A chatbot powered by a large language model that generates its own responses? Unambiguously AI. The interesting case: a chatbot that uses a small machine learning model to figure out what you're asking about (intent classification, in technical terms), then serves a pre-written response based on that classification. The classification component has inference capability &#8212; it learned from data how to categorize questions. Likely an AI system &#8212; even though the answers themselves are canned.</p><div><hr></div><h2>Even If It&#8217;s an AI System &#8212; It Might Still Be Out of Scope</h2><p>The definition question and the scope question are different analyses. A system can be an AI system under Article 3(1) and still fall outside the AI Act&#8217;s obligations through exemptions in Article 2.</p><p><strong>Research and development.</strong> AI systems in research, testing, or development before being placed on the market or put into service are excluded. But testing in real-world conditions is covered. The moment you go from lab to live users, the exemption ends.</p><p><strong>Open source.</strong> Free and open-source AI models are generally exempt &#8212; unless they&#8217;re classified as high-risk, involve prohibited practices, or trigger transparency obligations. Not a blanket pass.</p><p><strong>Military, defence, national security.</strong> AI systems used exclusively for these purposes are excluded. <em>&#8220;Exclusively&#8221; </em>is load-bearing &#8212; any dual-use or civilian spillover brings the system back in scope.</p><p><strong>Personal non-professional use.</strong> Natural persons using AI for purely personal purposes are exempt from deployer obligations.</p><p><em>The distinction matters:</em> a logistic regression model isn't an AI system at all &#8212; the definition question. A deep learning model used in defence is an AI system, but it's exempt &#8212; the scope question. Different analyses, different conclusions. Both necessary. And if you're outside the EU wondering whether any of this applies to you &#8212; <a href="https://ailawdecoded.substack.com/p/why-the-eu-ai-act-matters-even-if">it probably does</a>.</p><div><hr></div><h2>The Bigger Picture</h2><p>I&#8217;ve been thinking about what that dinner conversation really exposed.</p><p>It wasn&#8217;t about one lawyer being wrong. It was about how instinctively everyone reaches for a simple answer to this question. Software or AI. In or out. Regulated or free. And the regulation &#8212; whether by design or by accident &#8212; doesn&#8217;t give you a simple answer.</p><p>Every obligation in the AI Act flows from the AI system definition. Risk classification under Article 6? Only applies to AI systems. Transparency requirements under Articles 50 and 52? Only AI systems. GPAI obligations under Articles 51 through 56? Only AI models and systems. Documentation, conformity assessment, registration &#8212; all triggered by having an AI system.</p><p>The definition is the on/off switch for the entire regulation.</p><p>The Commission&#8217;s guidelines got the extremes right. A spreadsheet macro is not an AI system. A deep learning model is. The four exclusion categories give specific examples that many companies can use to sort their obvious cases.</p><p>What the guidelines left unresolved is the middle. The &#8220;limited capacity&#8221; standard is too vague to resolve borderline cases without system-by-system analysis. The rule-based paradox &#8212; excluded as &#8220;traditional software&#8221; but included as &#8220;expert systems&#8221; &#8212; has no clear test. The interaction between techniques in real-world pipelines, where a system might use both excluded and included approaches, isn&#8217;t addressed at all.</p><p>Which means most companies will need to do what regulations always end up requiring when the text is ambiguous: the actual work.</p><p>Map your systems. Not by their names, not by their marketing labels &#8212; by what they technically do. <em>Have the technical team describe the actual mechanism.</em> <em>Have the legal team apply the seven elements of Article 3(1).</em> For every system where inference is the question &#8212; and it usually will be &#8212; assess whether the system&#8217;s inference capacity is &#8220;limited&#8221; in the way the guidelines describe, or whether it goes beyond the four exclusion categories.</p><p>Document the reasoning. Especially for borderline cases. <strong>&#8220;We assessed this system against Article 3(1) and concluded it does not qualify because...&#8221; </strong>is a sentence that will matter when enforcement starts.</p><p>Don&#8217;t take this lightly. The guidelines leave gaps &#8212; real ones &#8212; and the temptation is to read those gaps in your favor. To call something &#8220;just software&#8221;. To assume a system is exempt because it uses a technique that sounds like one of the four exclusion categories.</p><p>The gaps will be filled. Through enforcement, through case law, through updated guidance. And the companies that did the rigorous assessment &#8212; system by system, element by element, with legal and tech teams in the same room &#8212; will be the ones who aren&#8217;t scrambling when that clarity arrives.</p><p>The definition is where compliance starts. </p><p>It&#8217;s also where most companies stop thinking too soon.</p><p>Don&#8217;t be most companies.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading AI Law. Decoded.! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Why the EU AI Act Matters Even If You're Not in the EU]]></title><description><![CDATA[It's not about direct sales to EU customers. There's much more.]]></description><link>https://ailawdecoded.com/p/eu-ai-act-applies-outside-eu</link><guid isPermaLink="false">https://ailawdecoded.com/p/eu-ai-act-applies-outside-eu</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Sun, 05 Apr 2026 13:54:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!wrLn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb08944ca-a6dd-44b0-a118-8176d76942bc_4500x3000.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wrLn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb08944ca-a6dd-44b0-a118-8176d76942bc_4500x3000.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wrLn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb08944ca-a6dd-44b0-a118-8176d76942bc_4500x3000.heic 424w, https://substackcdn.com/image/fetch/$s_!wrLn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb08944ca-a6dd-44b0-a118-8176d76942bc_4500x3000.heic 848w, https://substackcdn.com/image/fetch/$s_!wrLn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb08944ca-a6dd-44b0-a118-8176d76942bc_4500x3000.heic 1272w, https://substackcdn.com/image/fetch/$s_!wrLn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb08944ca-a6dd-44b0-a118-8176d76942bc_4500x3000.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wrLn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb08944ca-a6dd-44b0-a118-8176d76942bc_4500x3000.heic" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b08944ca-a6dd-44b0-a118-8176d76942bc_4500x3000.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:311624,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.substack.com/i/193044187?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb08944ca-a6dd-44b0-a118-8176d76942bc_4500x3000.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wrLn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb08944ca-a6dd-44b0-a118-8176d76942bc_4500x3000.heic 424w, https://substackcdn.com/image/fetch/$s_!wrLn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb08944ca-a6dd-44b0-a118-8176d76942bc_4500x3000.heic 848w, https://substackcdn.com/image/fetch/$s_!wrLn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb08944ca-a6dd-44b0-a118-8176d76942bc_4500x3000.heic 1272w, https://substackcdn.com/image/fetch/$s_!wrLn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb08944ca-a6dd-44b0-a118-8176d76942bc_4500x3000.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>Someone asked you in a meeting &#8212; maybe your product manager, maybe your CTO, maybe a client &#8212; <em>&#8220;does the EU AI Act apply to us? We&#8217;re not in the EU.&#8221;</em></p><p>You said no. </p><p>Or you shrugged. </p><p>Or you said <em>&#8220;I&#8217;ll look into it&#8221;</em> &#8212; which is code for &#8220;I hope this goes away.&#8221;</p><p>However, it didn&#8217;t go away. So here you are, googling it.</p><p>The short answer is: <em>it depends. </em></p><p>But the EU AI Act reaches further than most non-EU companies expect &#8212; and the line between <em>&#8220;in scope&#8221;</em> and <em>&#8220;not in scope&#8221;</em> isn&#8217;t where you think it is.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>What the Law Actually Says</h2><p><a href="https://artificialintelligenceact.eu/article/2/">Article 2(1) of the EU AI Act</a> lists seven categories of entities this regulation applies to. For non-EU companies, three separate hooks matter the most &#8212; and you only need to trigger one.</p><p><strong>(a) Providers placing on the market or putting into service AI systems in the EU</strong> &#8212; regardless of where they're established. A US company that sells an AI-powered SaaS product to EU customers is <em>"placing on the market"</em> in the EU. Same logic as GDPR &#8212; location of the company is irrelevant, location of the market matters.</p><p><strong>(b) Deployers of AI systems located in the EU</strong> &#8212; this one catches EU-based companies using non-EU AI tools. But it also indirectly affects the non-EU provider, because the EU deployer will demand compliance from their vendor. Even if the Act doesn't directly apply to you, your EU customer's obligations flow uphill.</p><p><strong>(c) Providers and deployers in third countries where the OUTPUT of the AI system is used in the EU</strong> &#8212; this is the broadest hook, and the one most non-EU companies underestimate. If your AI system generates an output &#8212; a prediction, a recommendation, a decision, a piece of content &#8212; and that output ends up being used by someone in the EU, you're potentially in scope.</p><p>A few terms worth understanding before we go further:</p><p><em><strong>&#8220;Placing on the market&#8221;</strong></em> means the first time an AI system becomes available on the EU market. Selling, licensing, offering as SaaS &#8212; any way a system reaches an EU user for the first time.</p><p><em><strong>&#8220;Putting into service&#8221;</strong></em> means supplying an AI system directly to a deployer for first use, or using it yourself for its intended purpose. If you deploy your own AI system and it touches EU operations &#8212; this is you.</p><p><em><strong>&#8220;Output produced by the AI system is used in the Union&#8221;</strong></em> is the broadest trigger. It doesn't require physical presence. It doesn't require an EU customer relationship. If the output lands in the EU and gets used there, the connection is made.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;8e521463-8357-4311-a56f-7d75eb71d865&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;What Is an AI System, Actually?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act with practical steps.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-08T12:03:14.634Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!Lj3S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6c33bfb-66f1-4bc7-aba6-ed6c0d1df60e_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/ai-system-definition-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193355320,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:1,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h3>The Nuance</h3><p><a href="https://artificialintelligenceact.eu/recital/22/">Recital 22</a> narrows the <em>&#8220;output used in the Union&#8221;</em> trigger somewhat. It frames this as intended use &#8212; the example given is an EU provider contracting with a non-EU provider to process data and send back AI-generated outputs. </p><p>The AI system processes data lawfully collected and transferred from the EU, and the output goes back to the EU contracting party.</p><p>This matters because<strong> </strong>the level of <em><strong>&#8220;intention&#8221;</strong></em> is still open to interpretation. </p><p>There&#8217;s no official guidance yet on what counts as intended vs. incidental output reaching the EU. This is a grey area that will likely be clarified through enforcement and guidance &#8212; but companies shouldn&#8217;t wait for that.</p><div><hr></div><h2>When You&#8217;re Caught</h2><p>Here's where it gets practical. These are scenarios where the EU AI Act catches you even if your business is headquartered nowhere near the EU.</p><h3>Scenario 1: US SaaS company with EU customers</h3><p>A US company offers an AI-powered hiring tool. EU companies subscribe and use it to screen candidates in the EU. The US company is a provider placing an AI system on the EU market. Fully in scope. If the tool qualifies as high-risk (employment is Annex III, point 4), they need full compliance &#8212; risk management, data governance, transparency, human oversight, the works.</p><h3>Scenario 2: The API provider</h3><p>A Singapore-based fintech provides a credit scoring API. EU banks call the API to assess loan applications from EU citizens. No EU office, no EU entity, no EU employees &#8212; but the output (credit scores) is used in the EU to make decisions about EU persons. The Singapore company is in scope as a provider under Article 2(1)(c).</p><h3>Scenario 3: The outsourced AI processing</h3><p>An EU insurer contracts with an Indian AI company to process claims data. The Indian company uses AI to generate risk assessments, which are sent back to the EU insurer for decision-making. This is the Recital 22 scenario &#8212; output generated outside the EU, used inside the EU. The Indian company is caught.</p><h3>Scenario 4: Internal AI tools used globally</h3><p>A US multinational builds an internal AI system for performance reviews. It's used by managers globally &#8212; including at the company's EU offices. The output (performance assessments affecting EU employees) is used in the EU. The US parent company is likely in scope &#8212; both as provider and deployer.</p><h3>Scenario 5: GPAI model providers</h3><p>A US company develops and releases a general-purpose AI model (think: foundation models, LLMs). If the model is made available on the EU market &#8212; including via API access to EU developers &#8212; the GPAI-specific obligations under Articles 51-56 apply. Technical documentation, transparency about training data, copyright compliance.</p><div><hr></div><h2>When You&#8217;re Probably Not Caught</h2><p>Not every non-EU company needs to worry. Here's when you can exhale.</p><h3>Scenario A: Purely domestic, no EU touchpoint</h3><p>A US company builds an AI tool used only by US employees, for US customers, processing US data. No EU customers, no EU users, no output reaching the EU. Not in scope.</p><h3>Scenario B: Open-source with no EU market targeting</h3><p>Free and open-source AI models are generally exempt under Article 2(12) &#8212; unless they're classified as high-risk AI systems, prohibited AI practices, or have transparency obligations. This exemption has conditions and edges. It's not a blanket free pass.</p><h3>Scenario C: R&amp;D only</h3><p>AI systems in research, testing, or development &#8212; before being placed on the market or put into service &#8212; are excluded under Article 2(8). But the moment you move from testing to deployment with EU users, the exemption ends.</p><h3>Scenario D: Military/defence/national security</h3><p>AI systems whose output is used in the EU exclusively for military, defence, or national security purposes are carved out under Article 2(3). But <em><strong>"exclusively"</strong></em> is doing heavy lifting there &#8212; any dual-use or civilian spillover could bring it back in scope.</p><div><hr></div><h3>The Grey Zone</h3><p>If your AI system&#8217;s output <em>could</em> reach EU users but you&#8217;re not specifically targeting them &#8212; this is genuinely unclear.</p><p>The GDPR analogy would suggest some form of <em>&#8220;targeting&#8221;</em> test (like GDPR&#8217;s Recital 23, which looks at language, currency, and other indicators that you&#8217;re aiming at EU users). But the AI Act doesn&#8217;t have that explicit test. Recital 22 hints at intentionality, but it hasn&#8217;t been tested through enforcement.</p><p>My reading: incidental or unintended output reaching the EU is probably not enough to bring you in scope. But no one has confirmed that yet. This is an open question &#8212; and if it matters for your business, it&#8217;s worth getting a proper legal opinion rather than betting on a <em><strong>&#8220;probably&#8221;.</strong></em></p><div><hr></div><h3>You Need a Person in the EU</h3><p><a href="https://artificialintelligenceact.eu/article/22/">Article 22</a> adds a practical requirement that catches some non-EU companies off guard.</p><p>Providers established outside the EU who place high-risk AI systems on the EU market must appoint an authorized representative in the EU &#8212; by written mandate &#8212; before making the system available. Not after. Before.</p><p>The representative verifies that the declaration of conformity and technical documentation exist. They provide information to competent authorities when requested. They cooperate on corrective actions. They flag complaints and risks to the provider. They ensure registration obligations are met under the database in Article 71.</p><p>What the representative does <em>not</em> do: take over the provider&#8217;s core compliance obligations (Articles 9-17). You still have to do the actual compliance work. The representative is your EU-facing contact point &#8212; not a compliance outsourcer.</p><p>If you went through GDPR, this mirrors the Article 27 representative requirement. Same structure, same logic. If you didn&#8217;t go through GDPR... this is your wake-up call.</p><p>One more thing about your EU representative. The representative can terminate the mandate if they believe the provider is acting contrary to the regulation. And when they do, they must report it to market surveillance authorities. Your EU representative isn&#8217;t just an address on file. They&#8217;re a compliance checkpoint with the power to blow the whistle.</p><div><hr></div><h2>The GDPR D&#233;j&#224; Vu</h2><p>If this whole article feels familiar &#8212; it should.</p><p>The EU AI Act&#8217;s extraterritorial reach follows the GDPR playbook. It applies regardless of where the company is established. It requires an authorized representative for non-EU entities. <em>&#8220;output used in the EU&#8221;</em> mirrors GDPR&#8217;s &#8220;offering goods or services to&#8221; or &#8220;monitoring behavior of&#8221; EU data subjects. And the fines are higher &#8212; up to &#8364;35 million or 7% of global annual turnover for the most serious violations, compared to GDPR&#8217;s ceiling of &#8364;20 million or 4%.</p><p>But there are differences worth knowing.</p><p>The AI Act&#8217;s <em>&#8220;output used in the Union&#8221;</em> hook is arguably broader than GDPR&#8217;s targeting test. Under GDPR, you need to be &#8220;offering&#8221; to or &#8220;monitoring&#8221; EU persons. Under the AI Act, even being a subcontractor whose output happens to be used in the EU could be enough.</p><p>GDPR has had years of enforcement, case law, and guidance to clarify the grey zones. The AI Act has none of that yet. Everything right now is interpretation &#8212; informed interpretation, but interpretation nonetheless.</p><p>And the AI Act layers on top of GDPR. It doesn&#8217;t replace it. If your AI system processes personal data, you need to comply with both.</p><div><hr></div><h2>It&#8217;s Not Just the EU</h2><p>Here&#8217;s the part that might matter even more than the extraterritorial reach.</p><p>The EU AI Act gets the headlines. But if you&#8217;re dismissing it because &#8220;we don&#8217;t operate in the EU&#8221; &#8212; you might want to check what&#8217;s happening closer to home.</p><h3>United States &#8212; the patchwork</h3><p>There&#8217;s no federal AI law. The current administration is actively trying to prevent one &#8212; the December 2025 executive order (&#8221;Ensuring a National Policy Framework for AI&#8221;) directed the Attorney General to challenge state AI laws and the Commerce Secretary to flag &#8220;burdensome&#8221; state regulation by March 2026.</p><p>But executive orders don&#8217;t override existing law. And the states aren&#8217;t waiting.</p><p>Colorado&#8217;s AI Act takes effect June 30, 2026 &#8212; delayed from February, but still coming. It requires developers and deployers to exercise reasonable care to prevent algorithmic discrimination, conduct impact assessments, and provide consumer disclosures. This is the closest a US state has come to EU-style AI obligations. California&#8217;s Transparency in Frontier AI Act hit January 1, 2026. Texas&#8217;s Responsible AI Governance Act &#8212; same date.</p><p>Until Congress acts or courts rule, state laws remain enforceable. Even if you&#8217;re a US company that doesn&#8217;t touch the EU &#8212; check Colorado, California, and Texas. The regulation is coming from inside the house.</p><h3>United Kingdom &#8212; no law yet, but don't get comfortable</h3><p>The UK doesn&#8217;t have a dedicated AI statute. Its current approach is the 2023 &#8220;Pro-Innovation&#8221; white paper &#8212; five principles applied by existing sector regulators rather than a central AI authority.</p><p>But legislation is expected in the second half of 2026, likely covering the most powerful general-purpose AI models. In January 2026, the government wrote to 19 regulators asking them to publish plans for safe AI innovation. The Financial Conduct Authority and others are already issuing sector-specific AI guidance.</p><p>The UK hasn&#8217;t passed an AI law yet. That doesn&#8217;t mean it isn&#8217;t building one.</p><h3>Singapore &#8212; "voluntary" until it isn't</h3><p>Singapore governs AI through voluntary frameworks &#8212; the Model AI Governance Framework (updated for generative AI in 2024-2025), the Agentic AI Governance Framework (January 2026, first of its kind globally), and AI Verify, a government-developed testing toolkit.</p><p><em><strong>&#8220;Voluntary&#8221;</strong></em> sounds comfortable. But the Monetary Authority of Singapore already has mandatory AI governance requirements for financial institutions as of December 2024. Sector by sector, the voluntary frameworks are hardening into rules.</p><p>Singapore is building the infrastructure &#8212; the frameworks, the testing tools, the sectoral requirements &#8212; that makes binding regulation easy to switch on. When it does, the companies already following the frameworks won&#8217;t notice. The ones that ignored them will.</p><div><hr></div><p>AI regulation used to be one law in one place. It isn&#8217;t anymore. It&#8217;s a permanent, growing area of law &#8212; worldwide &#8212; and the companies that figure that out now are the ones that won&#8217;t be scrambling later.</p><p>You already took the first step. You&#8217;re here, reading this, instead of shrugging it off in a meeting.</p><p>That matters more than you think.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading AI Law. Decoded.! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Why Is Everyone So Confused with the EU AI Act?]]></title><description><![CDATA[It's not just you.]]></description><link>https://ailawdecoded.com/p/eu-ai-act-compliance-confusion</link><guid isPermaLink="false">https://ailawdecoded.com/p/eu-ai-act-compliance-confusion</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Sun, 29 Mar 2026 09:37:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!eF0I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2593d2ce-02b5-49ed-990c-47c1d2305c8e_4500x3000.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!eF0I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2593d2ce-02b5-49ed-990c-47c1d2305c8e_4500x3000.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!eF0I!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2593d2ce-02b5-49ed-990c-47c1d2305c8e_4500x3000.heic 424w, https://substackcdn.com/image/fetch/$s_!eF0I!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2593d2ce-02b5-49ed-990c-47c1d2305c8e_4500x3000.heic 848w, https://substackcdn.com/image/fetch/$s_!eF0I!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2593d2ce-02b5-49ed-990c-47c1d2305c8e_4500x3000.heic 1272w, https://substackcdn.com/image/fetch/$s_!eF0I!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2593d2ce-02b5-49ed-990c-47c1d2305c8e_4500x3000.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!eF0I!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2593d2ce-02b5-49ed-990c-47c1d2305c8e_4500x3000.heic" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2593d2ce-02b5-49ed-990c-47c1d2305c8e_4500x3000.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:415152,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.substack.com/i/192460891?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2593d2ce-02b5-49ed-990c-47c1d2305c8e_4500x3000.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!eF0I!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2593d2ce-02b5-49ed-990c-47c1d2305c8e_4500x3000.heic 424w, https://substackcdn.com/image/fetch/$s_!eF0I!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2593d2ce-02b5-49ed-990c-47c1d2305c8e_4500x3000.heic 848w, https://substackcdn.com/image/fetch/$s_!eF0I!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2593d2ce-02b5-49ed-990c-47c1d2305c8e_4500x3000.heic 1272w, https://substackcdn.com/image/fetch/$s_!eF0I!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2593d2ce-02b5-49ed-990c-47c1d2305c8e_4500x3000.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>You have some AI systems in the company. You are aware there is some AI Act.</p><p>But what are you supposed to do? Classify them? Report them somewhere? Write documentation? Put them in a spreadsheet and hope for the best?</p><p>So you decide you need help. You hire a consultant &#8212; the one whose LinkedIn posts freaked you out. Only to realize he doesn&#8217;t understand half of what he&#8217;s talking about.</p><p>So you try something else. Online courses. In-person workshops. Seminars with important-sounding titles.</p><p>And they read you the regulation.</p><p>They read it to you.</p><p>But they don&#8217;t tell you what to do. What are the steps. How to actually be compliant. You walk out knowing the AI Act exists (you already knew that) and not much else.</p><p>You have no idea what to do.</p><p>It looks hopeless.</p><p>It&#8217;s not. And here&#8217;s the thing nobody is saying out loud:</p><p>You&#8217;re confused because the people writing the rules haven&#8217;t finished explaining them.</p><p>A study of 106 enterprise AI systems found 40% had unclear risk classification. That&#8217;s not company incompetence &#8212; that&#8217;s a guidance gap. If you don&#8217;t have your AI systems classified, if you genuinely don&#8217;t know what to do next, the reason is not you.</p><p><em>Psst.</em> It&#8217;s them.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>So what happened?</h2><h3>The Commission missed its own deadline</h3><p>The guidelines on high-risk AI classification &#8212; Article 6, the single most important question every company has &#8212; <a href="https://iapp.org/news/a/european-commission-misses-deadline-for-ai-act-guidance-on-high-risk-systems">were due February 2, 2026</a>.</p><p>It&#8217;s still missing at the end March 2026.</p><p>&#8220;Is my AI system high-risk?&#8221; That&#8217;s the question. The Commission was supposed to answer it over a year ago. They haven&#8217;t.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;cb14797f-d3ba-4c64-8ace-4262ec95959f&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;What Is an AI System, Actually?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act with practical steps.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-08T12:03:14.634Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!Lj3S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6c33bfb-66f1-4bc7-aba6-ed6c0d1df60e_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/ai-system-definition-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193355320,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:1,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h3>The guidance they did publish made things worse</h3><p>In February 2025, the Commission published guidelines on the definition of an AI system. The idea was to bring clarity. Legal analysts noted the guidelines <a href="https://www.conclusion.com/en-nl/ai-360/news/eu-ai-act-clarification-or-confusion-over-ai-definition">&#8220;may actually lead to more debate.&#8221;</a> The guidance on &#8220;limited capacity&#8221; machine learning systems created new borderline cases instead of resolving old ones.</p><p>Ambiguity creates confusion. Confusion creates more ambiguity.</p><h3>The standards won&#8217;t be ready before enforcement starts</h3><p>CEN and CENELEC &#8212; the bodies creating the technical standards companies need to demonstrate compliance &#8212; are targeting Q4 2026 for key harmonized standards.</p><p>The high-risk obligations become enforceable August 2, 2026.</p><p>Read that again. Companies are supposed to comply with rules whose technical standards <em>don&#8217;t exist yet</em> on the enforcement date.</p><h3>Guidance arrives weeks before deadlines</h3><p>The transparency <a href="https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content">Code of Practice under Article 50</a>? First draft came out December 2025. Final version expected June 2026. Enforcement starts August 2, 2026.</p><p>That gives companies two months. Two months to implement something they just learned about.</p><h3>Nobody knows who enforces this</h3><p>Only 8 out of 27 EU member states have established designated national competent authorities. In most countries, the body responsible for enforcing the AI Act hasn&#8217;t been appointed yet.</p><p>You can&#8217;t comply with confidence when you don&#8217;t know who&#8217;s watching &#8212; or whether anyone is.</p><h3>The deadlines themselves keep moving</h3><p><a href="https://www.consilium.europa.eu/en/press/press-releases/2026/03/13/council-agrees-position-to-streamline-rules-on-artificial-intelligence/">On March 13, 2026,</a> the Council agreed to a position that would push the high-risk deadline from August 2026 to December 2027 for stand-alone systems, and August 2028 for systems embedded in regulated products.</p><p>But this is a Council position. Not finalized law. So companies are planning against deadlines that might change &#8212; again.</p><div><hr></div><h2>What do you actually need to remember?</h2><p>Here&#8217;s where it stands as of March 2026:</p><p><em>Prohibited AI practices</em> &#8212; social scoring, certain biometric systems, manipulative AI &#8212; have been enforceable since February 2, 2025. This is not coming. This is <em>here</em>.</p><p><em>GPAI provider obligations</em> &#8212; if you provide a general-purpose AI model &#8212; have been in force since August 2, 2025.</p><p>Full enforcement for high-risk AI systems is currently set for August 2, 2026 &#8212; but the Council&#8217;s March position suggests December 2027 is more likely.</p><p>There has been no major public enforcement action yet.</p><p>The <em>penalty structure</em>, when enforcement does come:</p><ul><li><p>Prohibited AI practices: EUR 35 million or 7% of global turnover</p></li><li><p>High-risk AI violations: EUR 15 million or 3% of global turnover</p></li><li><p>Incorrect or misleading information: EUR 7.5 million or 1% of global turnover</p></li></ul><p>Whichever is higher. That&#8217;s the ceiling. Most companies won&#8217;t get anywhere near it &#8212; but you need to know what the ceiling is.</p><div><hr></div><h2>If I were you</h2><p>I would focus on three things right now.</p><p><em>First </em>&#8212; make absolutely sure you are not running any prohibited AI practices. That&#8217;s the one category where enforcement is already live and the fines are the steepest. If you&#8217;re not sure what counts as prohibited, that&#8217;s a future article. But start there.</p><p><em>Second</em> &#8212; get a rough inventory of the AI systems in your company. You don&#8217;t need to classify them perfectly yet (the Commission hasn&#8217;t given you the tools to do that). But you need to know what you&#8217;re working with. You can&#8217;t comply with regulation you can&#8217;t map to your actual systems.</p><p><em>Third</em> &#8212; come back here regularly. I&#8217;ll be covering each of these topics in depth &#8212; what high-risk actually means, how to classify your systems, what the documentation requirements look like, and what happens as the deadlines shift. This is not a one-time problem. It&#8217;s an ongoing one, and I&#8217;ll be tracking it so you don&#8217;t have to.</p><p>The EU AI Act is confusing right now. That&#8217;s a fact. But it won&#8217;t always be &#8212; and the companies that start preparing now, even imperfectly, will be in a much better position than the ones still waiting for someone to hand them a checklist.</p><p>Nobody is going to hand you a checklist.</p><p><em>But I might build you one.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>