<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[AI Law. Decoded.]]></title><description><![CDATA[The EU AI Act and global AI regulation — explained in plain English. For in-house lawyers, product managers, founders, and anyone who just got handed "the AI thing."]]></description><link>https://ailawdecoded.com</link><image><url>https://substackcdn.com/image/fetch/$s_!u4nF!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png</url><title>AI Law. Decoded.</title><link>https://ailawdecoded.com</link></image><generator>Substack</generator><lastBuildDate>Tue, 15 Sep 2026 20:52:35 GMT</lastBuildDate><atom:link href="https://ailawdecoded.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[AI Law. Decoded.]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[ailawdecoded@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[ailawdecoded@substack.com]]></itunes:email><itunes:name><![CDATA[Silvia Stepitova]]></itunes:name></itunes:owner><itunes:author><![CDATA[Silvia Stepitova]]></itunes:author><googleplay:owner><![CDATA[ailawdecoded@substack.com]]></googleplay:owner><googleplay:email><![CDATA[ailawdecoded@substack.com]]></googleplay:email><googleplay:author><![CDATA[Silvia Stepitova]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Five EU AI Act Questions to Ask an AI Vendor]]></title><description><![CDATA[You are buying a role not just the tool.]]></description><link>https://ailawdecoded.com/p/questions-to-ask-ai-vendor-eu-ai-act</link><guid isPermaLink="false">https://ailawdecoded.com/p/questions-to-ask-ai-vendor-eu-ai-act</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 09 Sep 2026 19:32:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-6r9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdc7583-098f-41a7-8e39-4ef91fa24a20_6000x4000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-6r9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdc7583-098f-41a7-8e39-4ef91fa24a20_6000x4000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-6r9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdc7583-098f-41a7-8e39-4ef91fa24a20_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-6r9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdc7583-098f-41a7-8e39-4ef91fa24a20_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-6r9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdc7583-098f-41a7-8e39-4ef91fa24a20_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-6r9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdc7583-098f-41a7-8e39-4ef91fa24a20_6000x4000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-6r9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdc7583-098f-41a7-8e39-4ef91fa24a20_6000x4000.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ecdc7583-098f-41a7-8e39-4ef91fa24a20_6000x4000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:957914,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.com/i/214444779?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdc7583-098f-41a7-8e39-4ef91fa24a20_6000x4000.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-6r9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdc7583-098f-41a7-8e39-4ef91fa24a20_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-6r9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdc7583-098f-41a7-8e39-4ef91fa24a20_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-6r9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdc7583-098f-41a7-8e39-4ef91fa24a20_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-6r9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdc7583-098f-41a7-8e39-4ef91fa24a20_6000x4000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>You are buying an AI system.</p><p>You asked the vendor whether it is compliant with the EU AI Act, and they said yes.</p><p>The security questionnaire came back clean. The data processing agreement is signed. </p><p>But somehow you still cannot answer the question whether the EU AI Act treats you as the provider of this system or the deployer of it.</p><p>At some point you start to wonder whether you are asking it wrong.</p><p>You are not. But there are five specific questions you can ask any AI vendor to find out where you stand.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>Why Ask Now</h2><p><a href="https://artificialintelligenceact.eu/article/113/">Article 113</a>, as the Digital Omnibus amended it, defers Chapter III Sections 1, 2 and 3 to December 2, 2027 for the AI systems classified as high-risk under Annex III, and to August 2, 2028 for the ones caught through product legislation in Annex I. Those sections run from Article 6 to Article 27. They contain the classification rules, the requirements for high-risk systems, and the obligations of providers and deployers.</p><p>So the instructions for use, the written agreement, the documentation handover, your own duties as a deployer: none of them apply to anyone today.</p><p>But you should start asking sooner rather than later.</p><p>A vendor who cannot answer these questions in September 2026 is not breaching anything. They also have no obligation to improve, no deadline forcing them to build the documentation, and no reason to volunteer any of it. What they do have is a commercial motive to close, which will not be there again for next couple of years.</p><p>Sign a three-year agreement this month and it runs to September 2029. December 2027 arrives before the halfway point, at which time every answer below stops being a courtesy and starts being an obligation, on an AI system you have already bought, under a contract that has already been signed.</p><p>One part of the role question is already applicable. The transparency rules in <a href="https://artificialintelligenceact.eu/article/50/">Article 50</a> started on August 2, 2026, and they split by role: the duty to build in disclosure and machine-readable marking sits with the provider, the duty to tell people they are looking at a deepfake or an emotion recognition system sits with the deployer. So question one below has a live answer this year, even though most of what the answer decides is still fifteen months out.</p><p>The Commission is required to publish guidelines on the practical implementation of Articles 8 to 15 and Articles 25 and 26, which is where the value chain lives, and separately on what counts as a substantial modification. Neither carries a deadline.</p><div><hr></div><h2>Question No. 1: Who Is the Provider</h2><blockquote><p><em>Under the EU AI Act, are you the provider of this AI system, or are we?</em></p></blockquote><p>You are the provider if you develop an AI system, or have one developed, and place it on the market under your own name or trademark. That second part is the white-label case: somebody else builds it, your logo goes on it, and the AI Act reads that as you. You are the deployer if you use a system under your own authority.</p><p>Two other roles displace the obvious answer. Where a high-risk system is a safety component of a product covered by the legislation in Section A of Annex I, the product manufacturer is the provider. And a supplier established outside the EU has to appoint an authorized representative here before making a high-risk system available on the Union market.</p><p>A good answer names one role and explains why. An evasive answer is &#8220;we&#8217;re fully compliant,&#8221; which answers a question you did not ask.</p><p>Then there is the part of <a href="https://artificialintelligenceact.eu/article/25/">Article 25(1)</a> where three things turn a customer into a provider: </p><ul><li><p>putting your name or trademark on the AI system, </p></li><li><p>making a substantial modification to a high-risk AI system, or </p></li><li><p>changing the intended purpose so that a AI system which was not high-risk becomes high-risk. </p></li></ul><p>The first of those, and only the first, is expressed <em>&#8220;without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated.&#8221;</em></p><p>That the allocation works between the parties is clear from the text. Whether it would bind a market surveillance authority deciding who to pursue is not stated anywhere, and there is no case law. Write the clause. Do not build a position on it.</p><p>Get the answer in writing either way. If they are wrong, you want to know when they said it.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;cdad8888-56ff-4856-a382-4f6514bdbe68&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;What's Your Role Under the EU AI Act? Practical Decision Tree.&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-06-10T12:03:27.696Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!Bh5p!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/your-role-under-the-eu-ai-act-guide&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:199877647,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:5,&quot;comment_count&quot;:5,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>Question No. 2: What the System Is For</h2><blockquote><p><em>What is the intended purpose of this AI system, as you have declared it?</em></p></blockquote><p>For the Annex III categories, high-risk classification runs through the declared intended purpose rather than through raw capability. The same AI system is in or out depending on what it is put in front of. That is not the whole picture, because a AI system caught through Annex I is classified by the product it sits inside, and because changing the purpose yourself has consequences of its own, below. For an Annex III AI system, though, the declared purpose is where classification starts.</p><p><a href="https://artificialintelligenceact.eu/article/3/">Article 3(12)</a> defines intended purpose as the use the provider intends, <em>&#8220;as specified in the information supplied by the provider in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation.&#8221;</em> </p><p>Sales materials are inside the definition. If the deck says the AI system screens applicants and the contract says it performs a narrow procedural task, both are in scope, and the vendor has a problem they may not know about.</p><p>A good answer is a sentence you could paste into your AI governance documentation. An evasive answer describes features.</p><p>From December 2027, the sentence you are asking for is one they will owe you. <a href="https://artificialintelligenceact.eu/article/13/">Article 13(3)(b)</a> puts the intended purpose in the instructions for use. Today they owe you nothing, which is the difference between asking and negotiating.</p><p>And the catch: put the AI system to a use that makes it high-risk, and the AI Act can make you the provider, with every obligation that carries.</p><p>There is also a second half to that, added this summer. Article 25(2) makes the original provider cooperate with the new one, and now itemizes the handover: technical documentation sufficient to assess compliance, information on known limitations and failure modes, and targeted technical access including for testing and validation.</p><p>Then the sentence at the end of the paragraph. None of it applies where <em>&#8220;the initial provider has clearly specified that its AI system is not to be changed into a high-risk AI system.&#8221;</em></p><p>One line in their documentation, and the duty switches off before it ever switches on. It will not stop you becoming the provider, because classification follows the facts and not the paperwork. It stops you getting the three things you would need once you are.</p><div><hr></div><h2>Question No. 3: What Happens If We Change It</h2><blockquote><p><em>If we fine-tune this, or connect it to our own data, does that change your answer about who the provider is?</em></p></blockquote><p>Ask it in the same breath as the role question. Fine-tuning can move the role, but only on specific routes: a substantial modification to an AI system that is already high-risk, or a change of purpose that makes one high-risk.</p><p>For models rather than systems, the Commission&#8217;s guidance from July 2025 points at fine-tuning above roughly a third of the compute used to train the original. That figure is indicative and the guidance does not bind. The legal question is still whether the modification significantly changes the model&#8217;s generality, capabilities or risk profile, and arithmetic does not answer that. </p><p>Feeding it your own data usually does not do it. Retrieval is not training. It can still change what the system is for in practice, and it raises a separate set of questions under data protection law that the AI Act does not touch.</p><p>A good answer to this question engages with what you actually plan to do. An evasive answer is &#8220;that&#8217;s a customer configuration matter,&#8221; which means you own it and they would rather not say so.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;bffdf468-f0ca-4da7-a069-6d6af66d4d7b&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Wrap the Model, or Fine-Tune It?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-06-24T12:03:20.785Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!DIEg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1dc66ad1-bb8b-4845-9b6a-5e4cc5107e70_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/rag-fine-tuning-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:202933950,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>Question No. 4: When They Change the Model</h2><blockquote><p><em>When you change the model behind this, how will we know, and what changes for us?</em></p></blockquote><p>It is whoever makes a substantial modification who picks up the provider obligations, so a vendor-side swap usually stays theirs. What it breaks is yours: the assessment you did on the old model, and whatever you built on top of it. From December 2027, <a href="https://artificialintelligenceact.eu/article/26/">Article 26</a> requires deployers to operate a high-risk AI system in accordance with its instructions for use and to monitor it against them, which assumes the AI system in front of you is the system the instructions describe.</p><p>There will be a document that answers this. Article 13(3)(c) puts into the instructions for use &#8220;<em>the changes to the high-risk AI system and its performance which have been pre-determined by the provider at the moment of the initial conformity assessment, if any.&#8221; </em>Ask for the draft of it now. </p><p>There is an open question underneath that. <a href="https://artificialintelligenceact.eu/article/43/">Article 43(4)</a> says pre-determined changes do not amount to a substantial modification, so no fresh conformity assessment is triggered. Its second subparagraph opens with a condition: <em>&#8220;For high-risk AI systems that continue to learn after being placed on the market or put into service.&#8221;</em></p><p>Read strictly, the relief only reaches systems that keep learning in deployment. Read another way it changes nothing, because <a href="https://artificialintelligenceact.eu/article/3/">Article 3(23)</a> already defines a substantial modification as a change <em>&#8220;not foreseen or planned in the initial conformity assessment,&#8221;</em> and a pre-determined change is foreseen by definition. On the second reading the subparagraph is confirming what the definition already said.</p><p>I do not think that is settled, and it is one of the things the Article 96 guidelines on substantial modification will have to answer. Ask the vendor anyway. Whichever reading wins, they should know which category their AI system is in.</p><p>A good answer includes notice, a changelog and a named person. An evasive answer is <em>&#8220;we continuously improve the product,&#8221;</em> which is basically a yes.</p><div><hr></div><h2>Question No. 5: Will You Put It in the Contract</h2><blockquote><p><em>Will you give us what we need to meet our own obligations, and will you put it in the contract?</em></p></blockquote><p>Where a system is high-risk, Article 25(4) makes the provider and the third parties supplying into it set out in writing what information, capabilities and technical access get handed over. The Digital Omnibus widened it this summer: the list used to read <em>&#8220;an AI system, tools, services, components, or processes,&#8221;</em> and it now reads <em>&#8220;an AI system, AI model, tools, services, components, or processes.</em>&#8221; The model is listed now.</p><p>The same amendment did something else. <a href="https://artificialintelligenceact.eu/article/99/">Article 99</a> sets the penalty tiers, and the Omnibus added a new point to paragraph 4 covering Article 25(2) and Article 25(4). Fifteen million euro or three percent of worldwide annual turnover, whichever is higher.</p><p>Not today. Article 25 applies from December 2027. From then, not having the written agreement is the infringement.</p><p>There are two limits on the duty. It runs between the provider of the high-risk AI system and its suppliers, so if you are the deployer rather than the provider, your hook is different: the instructions for use the provider will owe you under Article 13, which covers accuracy metrics, known limitations, oversight measures, expected lifetime and how to read the logs. And Article 25(4) does not reach third parties making tools, services, processes or components publicly available under a free and open-source license, unless what they are supplying is a general-purpose model. Some of what is in your stack has no counterparty to sign anything.</p><p>Expect Article 25(5) to be quoted back at you, because it preserves intellectual property rights, confidential business information and trade secrets. Read what it is addressed to. It is expressed as without prejudice to paragraphs 2 and 3, which are the handover duties that bite when a role transfers. Paragraph 4 is not in its list, and paragraph 4 is an obligation to agree what will be shared rather than an order to disclose. </p><p>A good answer to this question is a clause. An evasive answer is a reassurance.</p><p>Either way, ask before signing. After signing it is a favor.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>The Five Questions, in One Place</h2><ol><li><p>Under the EU AI Act, are you the provider of this system, or are we?</p></li><li><p>What is the intended purpose of this system, as you have declared it?</p></li><li><p>If we fine-tune this, or connect it to our own data, does that change your answer about who the provider is?</p></li><li><p>When you change the model behind this, how will we know, and what changes for us?</p></li><li><p>Will you give us what we need to meet our own obligations, and will you put it in the contract?</p><div><hr></div></li></ol><h2>What to Do with the Answers</h2><p>Send them to the vendor&#8217;s legal or compliance contact rather than the account executive. An account executive&#8217;s answer is not an answer, and later it will be characterized as sales talk.</p><p>Date what comes back and keep it. Not because a wrong answer to you is an offense in itself. It matters because these answers are what you will be repeating when someone (potentially the regulator) eventually asks how you decided, and a dated file showing what you were told is the difference between a decision and a guess. </p><p>A refusal to answer is also a finding. It is the one you want on file before the argument rather than after.</p><p>If you want somewhere to start on the drafting of the contractual clauses, the Commission&#8217;s Public Buyers Community published model contractual clauses for AI procurement in March 2025, in a high-risk version and a lighter one, with commentary. They are not binding on anyone, and they are free.</p><div><hr></div><h2>The Other Fifteen Questions Worth Asking</h2><p>These five questions settle your role and classification. They are the questions where a wrong answer costs you a reclassification, which is painful and fixable.</p><p>The ones I have not published here settle whether you can prove it, which is a different problem, because the moment to fix that one is before signing.</p><p>Four of them ask for documents the AI Act will entitle you to from December 2027 and which no vendor has to prepare today. Four are not AI Act questions at all, which is exactly why an AI Act review misses them. One is about the prohibitions, which are the only part of this you could be breaching already. And one is the only question in the set about ending the relationship, which is the part the AI Act says nothing about.</p><p>All twenty questions will be available in <a href="https://ailawdecoded.com/p/scope">Scope</a>, which opens this fall.</p><div><hr></div><p><strong><a href="https://ailawdecoded.com/p/scope"><span data-color="#077d9a" style="color: rgb(7, 125, 154);">Scope</span></a><span data-color="#077d9a" style="color: rgb(7, 125, 154);"> is where this becomes something you can use in practice: the regulation map, the role assignment, the vendor questions, the AI inventory spreadsheet, the AI policy template, with sources attached and kept current as the law changes.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[Is Open Source AI Exempt Under the EU AI Act?]]></title><description><![CDATA[It depends on whether you have a system or a model.]]></description><link>https://ailawdecoded.com/p/open-source-exemption-eu-ai-act</link><guid isPermaLink="false">https://ailawdecoded.com/p/open-source-exemption-eu-ai-act</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 02 Sep 2026 12:02:55 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Neq3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1175621-1708-4f6a-a387-f78dba03b8b9_7680x4320.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Neq3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1175621-1708-4f6a-a387-f78dba03b8b9_7680x4320.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Neq3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1175621-1708-4f6a-a387-f78dba03b8b9_7680x4320.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Neq3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1175621-1708-4f6a-a387-f78dba03b8b9_7680x4320.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Neq3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1175621-1708-4f6a-a387-f78dba03b8b9_7680x4320.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Neq3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1175621-1708-4f6a-a387-f78dba03b8b9_7680x4320.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Neq3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1175621-1708-4f6a-a387-f78dba03b8b9_7680x4320.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c1175621-1708-4f6a-a387-f78dba03b8b9_7680x4320.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1060789,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.com/i/213166381?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1175621-1708-4f6a-a387-f78dba03b8b9_7680x4320.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Neq3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1175621-1708-4f6a-a387-f78dba03b8b9_7680x4320.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Neq3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1175621-1708-4f6a-a387-f78dba03b8b9_7680x4320.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Neq3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1175621-1708-4f6a-a387-f78dba03b8b9_7680x4320.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Neq3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1175621-1708-4f6a-a387-f78dba03b8b9_7680x4320.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>You looked up the open source exemption, and it read like good news.</p><p>One sentence. Three exceptions. No conditions attached to any of it. So you wrote it down and went to check it against the thing your company actually runs, which is a set of weights someone downloaded and fine-tuned on your own data.</p><p>The law firm alerts quote that same sentence. So does the vendor documentation. So does the explainer your engineering lead sent you, the one with the green checkmarks.</p><p>At some point you start to wonder whether you have misread something.</p><p>You have not. You are reading an article that does not cover what you are looking at.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>The Sentence in Question</h2><p><a href="https://artificialintelligenceact.eu/article/2/">Article 2(12)</a> of the <a href="https://eur-lex.europa.eu/eli/reg/2024/1689/oj">AI Act</a> says this:</p><blockquote><p><em>&#8220;This Regulation does not apply to AI systems released under free and open-source licences, unless they are placed on the market or put into service as high-risk AI systems or as an AI system that falls under Article 5 or 50.&#8221;</em></p></blockquote><p>That is the whole thing. It is genuinely useful. If you built a low-risk tool, released it openly, and it is not high-risk, not prohibited, and does not trigger transparency duties, you are outside the Regulation. Not lightly regulated. Outside.</p><p>Now read what it does not say.</p><p>It does not define a free and open-source license. It does not require you to publish weights, or architecture information, or anything else. It does not mention money. And it does not mention models.</p><p>That last one is the problem.</p><div><hr></div><h2>A Model Is Not a System</h2><p>The AI Act keeps these apart on purpose. <a href="https://artificialintelligenceact.eu/article/3/">Article 3(1)</a> defines an AI system. Article 3(63) defines a general-purpose AI model. Chapter V regulates general-purpose AI models on a separate track from everything else in the Regulation, with its own obligations and its own enforcement.</p><p>Article 2(12) says <em>AI systems</em>. So it does not reach the model.</p><p>The model exemptions live elsewhere. <a href="https://artificialintelligenceact.eu/article/53/">Article 53(2)</a> provides:</p><blockquote><p><em>&#8220;The obligations set out in paragraph 1, points (a) and (b), shall not apply to providers of AI models that are released under a free and open-source licence that allows for the access, usage, modification, and distribution of the model, and whose parameters, including the weights, the information on the model architecture, and the information on model usage, are made publicly available. This exception shall not apply to general-purpose AI models with systemic risks.&#8221;</em></p></blockquote><p><a href="https://artificialintelligenceact.eu/article/54/">Article 54(6)</a> carries the same conditions across to the authorized representative duty.</p><p>See the difference. Article 2(12) asks one question: was it released under a free and open-source license? Article 53(2) asks three: does the license permit access, usage, modification and distribution, are the parameters public, and is the model free of systemic risk, which under Article 51 means the largest models, presumed once training compute passes 10^25 floating point operations.</p><p>Same phrase, two tests, and which one you are under depends entirely on what you have.</p><p>And there&#8217;s one more complication. Recital 103 opens by saying that free and open-source AI components cover <em>&#8220;the software and data, including models and general-purpose AI models, tools, services or processes of an AI system.&#8221;</em> And Recital 102 supplies, for general-purpose models, the same publicly-available-parameters condition that Article 2(12) leaves out. Neither changes the operative text, and recitals do not create obligations. But they tell you something about where this regime keeps its content.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;5d6b8867-f62f-4997-9b68-2f6d35411ebc&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;What Is an AI System, Actually?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-08T12:03:14.634Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!Lj3S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6c33bfb-66f1-4bc7-aba6-ed6c0d1df60e_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/ai-system-definition-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193355320,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:3,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>The Money Condition Leaves in a Recital</h2><p>The monetization limit is the most consequential condition on the open source exemption, and it appears in neither Article 2(12) nor Article 53(2). It is in Recital 103:</p><blockquote><p><em>&#8220;AI components that are provided against a price or otherwise monetised... should not benefit from the exceptions provided to free and open-source AI components. The fact of making AI components available through open repositories should not, in itself, constitute a monetisation.&#8221;</em></p></blockquote><p>Recitals guide interpretation. They do not impose obligations. So a provider who reads the articles gets a shorter answer than a provider who reads the articles plus the recitals, and nothing in the articles tells you to go looking.</p><p>The Commission filled some of this in. Its <a href="https://digital-strategy.ec.europa.eu/en/library/guidelines-scope-obligations-providers-general-purpose-ai-models-under-ai-act">guidelines on the scope of obligations for providers of general-purpose AI models</a>, the Annex to Commission Decision C(2025) 5045 final of 18 July 2025, are non-binding, and they are the clearest reading available.</p><p>Paragraph 83 lists what disqualifies a license. Limitations to non-commercial or research-only use. Prohibitions on distributing the model. Requirements to obtain separate commercial licenses for specific use cases. And this one:</p><blockquote><p><em>&#8220;usage restrictions triggered by user scale thresholds (e.g. requiring additional licensing if monthly active users exceed a certain number)&#8221;</em></p></blockquote><p>Now open the <a href="https://github.com/meta-llama/llama-models/blob/main/models/llama4/LICENSE">Llama 4 Community License Agreement</a> of April 5, 2025, Section 2:</p><blockquote><p><em>&#8220;If, on the Llama 4 version release date, the monthly active users of the products or services made available by or for Licensee, or Licensee&#8217;s affiliates, is greater than 700 million monthly active users in the preceding calendar month, you must request a license from Meta&#8221;</em></p></blockquote><p>The guidelines describe that clause almost exactly, without naming it.</p><p>We can debate here but my understanding is that some of the most widely deployed open-weight models in Europe may sit outside the AI Act&#8217;s open source exemption while being described as inside it in many articles. The guidelines are not binding, the Commission has published no determination on any named model, and this has not been litigated. Read the clause and the paragraph and judge for yourself. But if your compliance position rests on a model being open source, the license text is the document to read.</p><div><hr></div><h2>What Survives a Perfect Open Release</h2><p>Say the model clears every condition. Truly open license, weights and architecture published, no systemic risk, no charge for anything.</p><p>The copyright policy under Article 53(1)(c) still applies. So does the public summary of training content under 53(1)(d). Recital 104 confirms both were deliberately left outside the exemption. Cooperation with the Commission and national authorities still applies. If the model crosses into systemic risk, Article 55 applies in full and the exemption disappears entirely.</p><p>Then there is everything downstream. Article 50 transparency, if the system talks to people or generates synthetic content. Prohibited practices. High-risk classification.</p><p>The exemption is documentation relief for model providers and a scope exclusion for genuinely low-risk systems. It is not a status your project acquires and keeps.</p><p>However, building on an exempt open model does not make your system exempt. </p><div><hr></div><h2>Another Exception?</h2><p><a href="https://artificialintelligenceact.eu/article/25/">Article 25(4)</a> requires a written agreement between the provider of a high-risk AI system and the third party supplying components into it, specifying the information and technical access the provider needs to comply. Its second subparagraph exempts open source suppliers:</p><blockquote><p><em>&#8220;This paragraph shall not apply to third parties making accessible to the public tools, services, processes, or components, other than general-purpose AI models, under a free and open-source licence.&#8221;</em></p></blockquote><p>Other than general-purpose AI models.</p><p> <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202601744">The Digital Omnibus on AI</a> replaced the first subparagraph of Article 25(4). The list of what a third party can supply now reads <em>&#8220;an AI system, AI model, tools, services, components, or processes.&#8221; </em><strong>AI model is new.</strong></p><p>The second subparagraph was not touched.</p><p>So the written agreement duty grew to reach model suppliers, and the open source relief still excludes exactly the thing model suppliers supply. The single place the AI Act offers open source contributors contractual relief in the high-risk value chain is the place it withholds it from them, and the amendment made the mismatch wider rather than narrower.</p><div><hr></div><h2>Three Exits with Three Different Clocks</h2><p>There is probably one date in your file for this. There are three dates though.</p><p>Article 2(12) names the three ways out of the exemption in a single line of text, which is why they get planned for as one deadline.</p><p>They do not arrive together.</p><ol><li><p><strong>Article 5, prohibited practices.</strong> In force since February 2, 2025, and the Omnibus added two new points that apply from December 2, 2026. <a href="https://artificialintelligenceact.eu/article/99/">Article 99(3)</a> puts breaches here in the top tier: up to &#8364;35 million or 7% of total worldwide annual turnover, whichever is higher.</p></li><li><p><strong>Article 50, transparency.</strong> In force since August 2, 2026. The machine-readable marking duty in Article 50(2) carries a four-month transitional period for systems that were already on the market, and that period is running right now. It closes  December 2, 2026. Up to &#8364;15 million or 3%.</p></li><li><p><strong>High-risk classification.</strong> 2 December 2027 for standalone systems in the Annex III use cases: employment, credit, education and the rest. August 2, 2028 for AI embedded in products already covered by EU product safety law. Up to &#8364;15 million or 3%.</p></li></ol><p>Two of the three are already live. The third is fifteen months out, and it moved to get there. Before the Omnibus, standalone high-risk obligations would have applied from August 2, 2026 and embedded high-risk from August 2, 2027.</p><p>Which leaves the exit most open source coverage is organized around as the one that cannot bite yet, and the two that can as the ones drawing the least attention. </p><p>The Omnibus also inserted new paragraphs 1a, 1b and 1c into Article 6, recutting what counts as a safety component. 1a takes out systems that only assist users or optimize performance. 1b puts back in systems whose failure would endanger health or safety. 1c takes out products that need third-party assessment only for risks other than safety. Article 6(3), the classification off-ramp, was not amended. </p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;0967988f-58ce-4ab6-b5c5-bec7f9b020aa&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;EU AI Act Amended: The Digital Omnibus Timeline&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-13T12:02:43.130Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!DR18!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/eu-ai-act-amended-the-digital-omnibus&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:196926473,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:3,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>The Prohibition That Was Not Costed for Open Weights</h2><p>The Omnibus added two prohibited practices to Article 5, applying December 2, 2026. Point (ba) covers AI systems that generate or manipulate realistic images, video, audio or similar material of an identifiable person&#8217;s intimate parts, or of an identifiable person in sexually explicit activity, without that person&#8217;s explicit consent. Point (bb) covers systems generating or manipulating child sexual abuse material within Directive 2011/93/EU, except where a <em>&#8220;without right&#8221;</em> defense applies under national law.</p><p>Realistic narrows point (ba): it reaches convincing output, not obvious fabrication. Article 5(1b) narrows it again. Editing that neither increases the exposure of intimate parts nor changes the nature of the depicted activity is not manipulation for these purposes. On a provision carrying a 7% ceiling, that is the line between a prohibited system and a lawful one.</p><p>The rest of the limits sit in a new Article 5(1a). For placing on the market, the prohibition bites where that generation is the intended purpose, or where the system&#8217;s design, training, architecture, capabilities or user-facing functionalities make it</p><blockquote><p><em>&#8220;a reasonably foreseeable and reproducible outcome, without requiring significant technical modification, and the system does not have reasonable and adequate technical safety measures and other safeguards to reliably prevent that generation or manipulation, taking into account reasonably foreseeable misuse, and to correct observed or reported misuse&#8221;</em></p></blockquote><p>The standard is reasonableness, not perfection, and open-weight providers can argue prevention: refusal training, classifiers, usage policies, published safeguards.</p><p>Correction is a different question. The provision asks for safeguards to correct observed or reported misuse, and there is no mechanism that reaches a checkpoint after it has been downloaded, mirrored and fine-tuned. You cannot patch it. You cannot recall it. You frequently cannot observe it. The obligation assumes a channel back to the artifact, and open weights is the distribution model defined by not having one.</p><p>The same distinction cuts the other way.</p><p>Article 5 is written throughout in terms of <em>&#8220;an AI system.&#8221;</em> Article 5(1a) turns on &#8220;<em>the system&#8217;s design, training, architecture, capabilities or user-facing functionalities.&#8221; </em>The reasoning that keeps a model outside Article 2(12) keeps a bare weights release outside Article 5. Being outside an exemption costs you obligations, and being outside a prohibition costs the public a protection. The prohibited practices guidelines do not resolve it. As far as I can find, nothing does.</p><p>Your own exposure is clearer than the drafters&#8217; intent. Article 5(1a)(b) prohibits use where <em>&#8220;the deployer uses the system for the purpose of generating or manipulating such material.&#8221; </em>Download open weights, fine-tune away the refusal behavior, generate the output, and you are inside the prohibition with no exemption available at any point, because Article 5 is one of the three named exits from Article 2(12). On that limb, and only that limb, accidental output is outside: the use prohibition turns on purpose. The placing-on-the-market limb is built to catch unintended output where it is foreseeable, reproducible and inadequately guarded.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;1323e90a-553b-4d2b-a316-98b3dc290554&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Prohibited AI Practices Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-15T12:03:15.414Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!81vQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5d9b717-c8ef-4b46-a887-59ff99fbba35_6000x4000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/prohibited-ai-practices-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193589773,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:6,&quot;comment_count&quot;:5,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>The Argument Running the Other Way</h2><p>Everything above says the exemption is narrower than it looks. There is a serious published argument that it is too wide, and it deserves the floor.</p><p>Simona Ramos and Fabio Pianese, writing in <a href="https://link.springer.com/article/10.1007/s43681-026-01177-1">AI and Ethics</a> this year, go after the definition itself. The AI Act never requires training data disclosure. Publish the weights, publish a descriptive summary of what went into them, and you qualify. They call the result open-washing: partial disclosure earning a regulatory exemption that exists to reward transparency, leaving downstream users carrying risks with no identifiable party accountable for them.</p><p>I would say that both readings hold at once. The exemption is too narrow for the person who assumes it covers their fine-tuned model, and too wide for the person who assumes it guarantees them a model they can actually inspect.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>What to Do</h2><ol><li><p><strong>Work out whether you have a system or a general-purpose model.</strong> If you deployed something users interact with, you have a system and Article 2(12) is your provision. If you published weights of a general-purpose model, Articles 53(2) and 54(6) are yours. If you did both, you have both, assessed separately. And if you openly released a narrow, single-purpose model, note that Chapter V does not reach you and neither does Article 2(12), which speaks to systems.</p></li><li><p><strong>Read the license, not the announcement.</strong> Check it against guidelines paragraph 83: non-commercial limits, distribution bans, user-scale thresholds, separate commercial licenses for particular uses. Any one of them and the model is arguably not open source for AI Act purposes, whatever it is called.</p></li><li><p><strong>Check for monetization before you rely on the exemption.</strong> Paid support bundled with access, dual licensing, hosted access behind payment, ad-served access, data collection beyond model security. Recital 103, and guidelines paragraphs 86 to 89.</p></li><li><p><strong>Stop treating upstream openness as your answer.</strong> Write down your own role for each system. The exemption belongs to whoever made the release.</p></li><li><p><strong>If you supply a model into someone&#8217;s high-risk system, expect the written agreement.</strong> The Article 25(4) carve-out does not cover general-purpose models, and after the Omnibus the duty names AI models explicitly.</p></li><li><p><strong>If you deployed a generative system before August 2, 2026, check your Article 50(2) marking.</strong> The transitional period ends December 2, 2026.</p></li><li><p><strong>If you fine-tune image, video or audio generation models, put December 2, 2026 in the calendar.</strong> Not the 2027 date. That one.</p><div><hr></div></li></ol><h2>What Is Left Unresolved</h2><p>An authorized representative exists so that EU authorities have someone inside the Union to serve, question, and hold responsible when the provider is somewhere else.</p><p>Article 54(6) removes that requirement for providers of free and open-source general-purpose AI models without systemic risk. Reasonable enough, in 2024, for a regime built around documentation.</p><p>From December 2, 2026, Article 5(1a) makes lawfulness turn partly on whether misuse gets corrected after release. It does that for the class of providers least able to correct anything, many of them outside the Union, and by virtue of 54(6), with no one inside it to ask.</p><p>The obligation needs a channel back to the artifact. The exemption removed the channel back to the provider.</p><p>Two holes in the same instrument, pointing in opposite directions. One lets a provider look open without being open. The other lets a provider be open without being reachable.</p><div><hr></div><p><strong><a href="https://ailawdecoded.com/p/scope"><span data-color="#077d9a" style="color: rgb(7, 125, 154);">Scope</span></a><span data-color="#077d9a" style="color: rgb(7, 125, 154);"> is where this becomes something you can use in a meeting: the regulation map, the role assignment, the vendor questions, the AI inventory spreadsheet, the AI policy template, with sources attached and kept current as the law changes.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[Harmonized Standards Under the EU AI Act]]></title><description><![CDATA[The Safe Harbor that has not opened.]]></description><link>https://ailawdecoded.com/p/harmonized-standards-eu-ai-act</link><guid isPermaLink="false">https://ailawdecoded.com/p/harmonized-standards-eu-ai-act</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 26 Aug 2026 12:01:37 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0rvA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62514725-22fd-4a53-8c63-c4e846d1d94f_8192x5461.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0rvA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62514725-22fd-4a53-8c63-c4e846d1d94f_8192x5461.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0rvA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62514725-22fd-4a53-8c63-c4e846d1d94f_8192x5461.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0rvA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62514725-22fd-4a53-8c63-c4e846d1d94f_8192x5461.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0rvA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62514725-22fd-4a53-8c63-c4e846d1d94f_8192x5461.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0rvA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62514725-22fd-4a53-8c63-c4e846d1d94f_8192x5461.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0rvA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62514725-22fd-4a53-8c63-c4e846d1d94f_8192x5461.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/62514725-22fd-4a53-8c63-c4e846d1d94f_8192x5461.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1079560,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.com/i/212377135?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62514725-22fd-4a53-8c63-c4e846d1d94f_8192x5461.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0rvA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62514725-22fd-4a53-8c63-c4e846d1d94f_8192x5461.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0rvA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62514725-22fd-4a53-8c63-c4e846d1d94f_8192x5461.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0rvA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62514725-22fd-4a53-8c63-c4e846d1d94f_8192x5461.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0rvA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62514725-22fd-4a53-8c63-c4e846d1d94f_8192x5461.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>You have read Article 15 of the EU AI Act more times than you would like to admit.</p><p>It says your high-risk system needs an appropriate level of accuracy. It does not say what appropriate means. So you go looking, because eventually someone has to write a number into a document and it is going to be you.</p><p>The Commission guidance does not answer it. The law firm alerts do not answer it. The vendor says their product is compliant, which is not an answer to anything.</p><p>At some point you start to wonder whether you are missing something obvious.</p><p>You are not. The thing you are looking for has not been written yet.</p><p>The <a href="https://eur-lex.europa.eu/eli/reg/2024/1689/oj">AI Act</a> was designed to leave that gap. The regulation states the duty, a harmonized standard states how to meet it, and conforming to the standard earns you a presumption that you have satisfied the requirement it covers. That is a good design.</p><p>As of today the European Commission has not cited a single harmonized standard for the AI Act in the Official Journal. Citation is the step that gives a standard its legal effect, and it has not happened once.</p><p>In July the first European standard did arrive. EN 18286, on quality management systems, described by CEN-CENELEC <a href="https://www.cencenelec.eu/news-events/news/2026/en-in-the-spotlight/2026-07-30-ai-quality-management/">on their own site</a> as <em>&#8220;the first harmonized European standard for the AI Act regulatory purposes.&#8221;</em> Every part of that is accurate. It still confers nothing.</p><p>Your date is December 2, 2027. It no longer waits for any of this.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>What the Presumption Is, Exactly</h2><p><a href="https://artificialintelligenceact.eu/article/40/">Article 40(1)</a> says that a high-risk AI system which conforms to harmonized standards, or parts of them, the references to which have been published in the Official Journal, is presumed to be in conformity with the requirements set out in Section 2 of that Chapter, to the extent those standards cover those requirements.</p><p>There are three conditions though.</p><p><strong>The first</strong> is publication of the reference in the Official Journal. Not drafting. Not approval by CEN-CENELEC. Not publication of the standard itself. The Commission assesses the standard against the request it made and then cites the reference in the OJ, and that is a separate act which happens afterward. EN 18286 has cleared every CEN-CENELEC stage. It has not cleared that one, and there is a Commission assessment and national transposition still to happen in between.</p><p><strong>The second</strong> is coverage. A harmonized standard carries an Annex ZA, the table mapping the standard onto the specific legal provisions it supports. The presumption reaches exactly as far as that table and stops. A cited risk management standard answers Article 9. Your data governance obligations under Article 10 will regard it with polite indifference.</p><p><strong>The third</strong> is the word presumed. It shifts the burden of proof. It does not end the argument. A market surveillance authority can still look at your system, decide it does not meet the requirement, and act on that, even if you followed the standard exactly. The AI Act has a whole procedure for it.</p><p>The standard itself is not permanent either. A Member State or the European Parliament can <a href="https://eur-lex.europa.eu/eli/reg/2012/1025/oj">formally object</a> to a harmonized standard, and the Commission can then narrow what it covers or pull the reference back out of the Official Journal.</p><p>None of that is a flaw. It is how CE marking has always worked. It is just a good deal less than <em>&#8220;safe harbor&#8221;</em> suggests to a board.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;9b316296-60af-4dd8-83d4-66e67f7e7545&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Is My AI System High-Risk Under the EU AI Act?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-06T12:02:25.960Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!-GG3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/is-my-ai-system-high-risk-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:196305760,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>What Is Often Skipped in a Commentary</h2><p>The AI Act splits its high-risk AI system duties into two kinds.</p><p>One set is about the system: it has to manage risk, use decent data, keep records, be transparent, allow human oversight, and be accurate, robust and secure. The other set is about you, the company placing it on the market or putting it into service: run a quality management system, keep the documentation, fix things when they go wrong.</p><p>Article 40 offers the presumption for the first set. Only the first set.</p><p>EN 18286 is a standard for the second set. It covers the quality management system.</p><p>So the first standard to reach publication is a standard for a duty the presumption does not obviously reach. Whether citing it in the Official Journal produces one anyway is a question the text does not answer, and I have not found anything authoritative that does. Common specifications would not solve it either, because <a href="https://artificialintelligenceact.eu/article/41/">Article 41</a> is written to the same scope.</p><p>Most commentary assumes the presumption attaches on citation and moves on. It may. The European Commission did ask for a quality management deliverable when it issued the standardization request, which says something about intent. But intent is not operative text, and this gets settled when the Commission decides whether, and how, to cite.</p><div><hr></div><h2>Where Everything Else Sits</h2><p>As of August 23, 2026 one standard is finished, four drafts out for public comment, the rest is still being written.</p><p>The four out for comment cover risk management, cybersecurity, logging, and human oversight. (prEN 18228, 18282, and 18229 parts 1 and 3, if you want to go and look.) Still being written: transparency, accuracy, robustness, data quality, bias, and the conformity assessment framework itself.</p><p>Do not attach much weight to the count. It moves. The trustworthiness standard that was one document is now a five-part series, and there are ISO-derived standards on the same work program alongside the purpose-written ones. The Commission describes its request as covering ten key areas rather than a number of documents, which is the more useful way to hold it.</p><p>The number that matters is the other one. As of today the Commission has published no reference to a harmonized standard under the AI Act in the Official Journal.</p><p>The Commission issued its standardization request in May 2023, with 30 April 2025 as the deadline for CEN and CENELEC to deliver. That date passed with nothing delivered under the request. An amending request followed in June 2025, extending the timeline and adding quarterly progress reporting.</p><p>Then, in October 2025, CEN and CENELEC <a href="https://www.cencenelec.eu/news-events/news/2025/brief-news/2025-10-23-ai-standardization/">changed their own rules</a>, in what they called exceptional and temporary measures.</p><p>A European standard goes through an enquiry stage, where the national standards bodies vote and comments come in, and then a second formal vote before publication. Under the October measures, a draft that passes enquiry can go straight to publication, and technical changes after that point are no longer allowed.</p><p>The consultation is still real, so this is not consensus abandoned. It is consensus on a shorter rope. But a standards body suspending its own approval vote is not a routine schedule adjustment, and it is the clearest signal available about how the timeline is actually going.</p><p>And note what <em>&#8220;available by the end of 2026&#8221;</em> is a target for. The document existing. Not the Commission citing it, which is a separate step and comes after.</p><div><hr></div><h2>The Condition That Was Proposed, and Removed</h2><p>When the Commission proposed the Digital Omnibus on AI, it did not propose a simple postponement of the high-risk AI systems. According to the Council&#8217;s <a href="https://www.consilium.europa.eu/en/press/press-releases/2026/05/07/artificial-intelligence-council-and-parliament-agree-to-simplify-and-streamline-rules/">own account</a> of the provisional agreement, the Commission had proposed adjusting the timeline by up to sixteen months, so that the rules would start to apply &#8220;once the Commission confirms the needed standards and tools are available.&#8221;</p><p>A conditional trigger. The obligations would begin when the means of complying with them existed.</p><p>Parliament and Council did not keep it. The agreed text replaced the trigger with fixed dates.</p><p>Those dates are now law. <a href="https://eur-lex.europa.eu/eli/reg/2026/1744/oj">Regulation (EU) 2026/1744 of 8 July 2026</a>, published in the Official Journal on 24 July and in force three days later.</p><p>It sets two. 2 December 2027 for high-risk systems that stand on their own, the ones on the Act&#8217;s list in Annex III. 2 August 2028 for high-risk AI built into products that already carry their own EU safety rules, medical devices among them.</p><p>The delay survived. The condition attached to it did not.</p><p>And the Regulation says why, in its own recitals. Recital 40 records that for the high-risk obligations in Chapter III, &#8220;the delayed availability of standards, common specifications, and alternative guidance and the delayed establishment of national competent authorities lead to challenges that jeopardize the effective entry into application of those obligations.&#8221;</p><p>That is the EU stating, inside a binding instrument, that the standards are not ready. In the same instrument that removes the condition which would have waited for them.</p><p>There is a real argument for the choice. An open-ended trigger hands the Commission the power to postpone a regulation indefinitely by declining to confirm readiness, and gives businesses no date to plan against. Fixed dates are certainty, and certainty is what compliance teams have been asking for since 2024.</p><p>But it produces a specific result. The Commission&#8217;s version tied the start to whether the tools existed. The adopted version just picked a day.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;8759f0f5-9c80-4147-b67b-8e0214903fc5&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;EU AI Act Amended: The Digital Omnibus Timeline&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-13T12:02:43.130Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!DR18!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/eu-ai-act-amended-the-digital-omnibus&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:196926473,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:3,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>The Fallback That Has Not Been Used</h2><p>The AI Act does have a backup plan.</p><p>If the standards do not arrive, <a href="https://artificialintelligenceact.eu/article/41/">Article 41</a> lets the European Commission write the specifications itself. They are called common specifications, and they work the same way: follow them and you get the same presumption a harmonized standard would give you. A provider who would rather not use them has to show its own solutions are at least as good, which is real work, and that is the point.</p><p>The conditions for using it are not hypothetical. The Commission has to have asked for standards, the standards have to have missed their deadline, and nothing can be published in the Official Journal or expected there soon.</p><p>A request was issued. The deadline was missed. Nothing is cited.</p><p>As far as I have been able to establish, no common specifications have been adopted for the high-risk requirements. If that is right, the mechanism written into the AI Act for this exact situation is sitting unused while the situation it was written for continues.</p><p>It would not fix the quality management gap either. Common specifications are offered for the same set of duties as the presumption itself, the ones about the system rather than the ones about the company.</p><p>And the AI Act says the Commission may adopt them. Not shall. That one word is why there is no obligation on anyone to fix this, and no date by which it has to be fixed.</p><div><hr></div><h2>The One Box That Is Not Empty in the Same Way</h2><p>Two other routes exist, and neither runs through the standards process. They are the only places where the answer to &#8220;can I get a presumption today&#8221; is not simply no.</p><p><a href="https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-42">Article 42</a> gives them both. If your system was trained and tested on data that reflects the specific setting it will actually be used in, it is presumed to meet that part of the data governance requirement. And if it holds a cybersecurity certificate issued under the EU&#8217;s cybersecurity certification framework, it is presumed to meet the cybersecurity requirement, as far as that certificate reaches.</p><p>The second one comes with a familiar condition. It only works where the references have been published in the Official Journal.</p><p>Same gate. A different queue.</p><div><hr></div><h2>What ISO 42001 and NIST Do Not Do</h2><p>In the absence of something to build against, teams reach for what exists.</p><p><a href="https://www.iso.org/standard/42001">ISO/IEC 42001</a> is an AI management system standard. It is certifiable, genuinely useful, and an organization that holds it is doing real governance work. It carries no presumption of conformity under the AI Act.</p><p>It is not that an ISO standard cannot become a harmonized European standard. ISO standards are adopted as European standards routinely, and the committee writing the AI Act standards is doing exactly that with two of them. The reason is that they chose to write EN 18286 rather than adopt ISO/IEC 42001 for the quality management standard, and 42001 is not on their work program as a candidate for it.</p><p>The substance differs too. EN 18286 is built around obligations that come out of the AI Act rather than out of management system practice, including a strategy for regulatory compliance, the technical specifications and standards to be applied, and procedures for reporting serious incidents under Article 73. Those map onto Article 17(1). An ISO 42001 programme gives you a conceptual head start. It does not give you the evidence.</p><p>The <a href="https://nvlpubs.nist.gov/nistpubs/ai/nist.ai.100-1.pdf">NIST AI Risk Management Framework</a> is a voluntary United States framework with no legal effect in the European Union. If your organization built its AI governance on NIST because that is where the guidance was in 2023, that work is not wasted, but it does not travel to Brussels on its own.</p><p>Both are evidence of a serious organization. Neither is evidence of conformity.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>What to Actually Do</h2><p>Five things, and none of them require you to predict whether CEN-CENELEC makes its target.</p><ol><li><p><strong>Read the drafts, and note which version you read.</strong><span> Four harmonized standards are out for public comment right now: risk management, cybersecurity, logging, and human oversight. A draft gives you no legal protection. It is still the best picture available of what the finished requirement will look like, and having built toward it is worth more than having waited. Write down which draft and which date, so that if the final version changes you can show your decision was current when you made it.</span></p></li><li><p><strong>Start the quality management work now.</strong><span> EN 18286 is the one standard that is finished. Set aside the question of whether it will ever produce a presumption: the AI Act already requires you to record which standards and specifications you apply, so a published European standard is a useful thing to be able to point at. It is also the clearest published description of what a quality management system for high-risk AI is meant to contain.</span></p></li><li><p><strong>Write down your own reasoning, and date it.</strong><span> The requirements apply on their own terms whether or not a standard ever arrives to explain them. So every time you decide what </span><em><span>"appropriate"</span></em><span> means for your AI system, write down what you decided, why, and when. </span></p></li><li><p><strong>Do not buy presumption.</strong><span> If someone tells you their product delivers presumption of conformity, ask which standard, and in which issue of the Official Journal the reference was published. For harmonized standards there is no correct answer today. For the cybersecurity certification route there might be, which makes it the better question.</span></p></li><li><p><strong>Watch the Official Journal, not the announcements.</strong><span> When a standard is published by CEN and CENELEC it generates press coverage. When the European Commission cites it, generally it does not. The second is the one that changes your legal position, so put a recurring check in the calendar rather than waiting to hear about it.</span></p><div><hr></div></li></ol><h2>The Bargain</h2><p>Underneath the procedure, the AI Act&#8217;s design for high-risk AI systems is a trade, and a sensible one.</p><p>The regulation states the requirement in general terms, because a regulation specifying test methodologies would be obsolete before it applied. The harmonized standard then states how to demonstrate it, written by people who understand the technology and updated as the technology moves. Meet the standard and you are presumed to comply. The regulator gets requirements that survive contact with the field. You get a route to certainty that does not depend on your own legal interpretation being correct.</p><p>That is the bargain. It is the only reason a phrase like <em>&#8220;an appropriate level of accuracy&#8221;</em> is a workable legal obligation rather than an invitation to litigate.</p><p>One half of it has been delivered. The requirements have been on the statute book since 2024, and they apply to your systems on 2 December 2027 regardless of what has been cited by then.</p><p>The other half was originally due in April 2025.</p><p>EN 18286 was approved on 12 July 2026. The Digital Omnibus was adopted on 8 July, four days earlier, and it amended Article 17 along the way. So the first AI Act standard to reach publication maps onto a version of the law that had changed the week before. Whatever the Commission is assessing when it decides on citation, it is not assessing a fixed target.</p><p>You are being measured against instructions that have not been issued, for a requirement that has not finished moving. That is not an oversight in the drafting. It is the timetable, as adopted.</p><div><hr></div><p><strong><a href="https://ailawdecoded.com/p/scope"><span data-color="#077d9a" style="color: rgb(7, 125, 154);">Scope</span></a><span data-color="#077d9a" style="color: rgb(7, 125, 154);"> is where this becomes something you can use in a meeting: the regulation map, the role assignment, the vendor questions, the AI inventory spreadsheet, the AI policy template, with sources attached and kept current as the law changes.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[Which One Governs: the EU AI Act or the GDPR?]]></title><description><![CDATA[Both do, at the same time. Same words, different meanings, no rule that picks between them.]]></description><link>https://ailawdecoded.com/p/eu-ai-act-vs-gdpr-which-governs</link><guid isPermaLink="false">https://ailawdecoded.com/p/eu-ai-act-vs-gdpr-which-governs</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 19 Aug 2026 19:05:56 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!pc3c!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe94dcfe-d30d-40f0-8f82-77a64917523c_7680x4320.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pc3c!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe94dcfe-d30d-40f0-8f82-77a64917523c_7680x4320.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pc3c!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe94dcfe-d30d-40f0-8f82-77a64917523c_7680x4320.jpeg 424w, https://substackcdn.com/image/fetch/$s_!pc3c!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe94dcfe-d30d-40f0-8f82-77a64917523c_7680x4320.jpeg 848w, https://substackcdn.com/image/fetch/$s_!pc3c!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe94dcfe-d30d-40f0-8f82-77a64917523c_7680x4320.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!pc3c!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe94dcfe-d30d-40f0-8f82-77a64917523c_7680x4320.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pc3c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe94dcfe-d30d-40f0-8f82-77a64917523c_7680x4320.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fe94dcfe-d30d-40f0-8f82-77a64917523c_7680x4320.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1438298,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.com/i/211666287?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe94dcfe-d30d-40f0-8f82-77a64917523c_7680x4320.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pc3c!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe94dcfe-d30d-40f0-8f82-77a64917523c_7680x4320.jpeg 424w, https://substackcdn.com/image/fetch/$s_!pc3c!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe94dcfe-d30d-40f0-8f82-77a64917523c_7680x4320.jpeg 848w, https://substackcdn.com/image/fetch/$s_!pc3c!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe94dcfe-d30d-40f0-8f82-77a64917523c_7680x4320.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!pc3c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe94dcfe-d30d-40f0-8f82-77a64917523c_7680x4320.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>You have one AI system. A vendor built it, your company runs it, it processes personal data, and if you work in financial services a prudential regulator supervises the whole operation.</p><p>Three rulebooks land on that system at once. The <a href="https://eur-lex.europa.eu/eli/reg/2024/1689/oj">EU AI Act</a> regulates it as an AI system. The <a href="https://eur-lex.europa.eu/eli/reg/2016/679/oj">GDPR</a> regulates the personal data running through it. <a href="https://eur-lex.europa.eu/eli/reg/2022/2554/oj">DORA</a>, the EU&#8217;s financial resilience regulation, regulates the vendor relationship behind it.</p><p>Each of them has something to say about risk. Each of them wants an assessment. Each of them names the parties involved, and none of them uses the same names.</p><p>At some point you go looking for the provision that says which one governs when they answer the same question differently.</p><p>It is not there. For these overlaps the EU never wrote one.</p><p>That absence is deliberate, and understanding why it is deliberate may change what you build. The months that disappear into AI governance projects mostly disappear here, into a search for a tiebreaker that does not exist.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2><strong>There Is No Hierarchy, and Lex Specialis Will Not Help</strong></h2><p>Two EU instruments of equal rank do not resolve against each other by default.</p><p>Where obligations genuinely collide and no express rule applies, the Court of Justice does not pick a winner. It reconciles. </p><p>In <a href="https://curia.europa.eu/juris/liste.jsf?num=C-73/17">C-73/17 </a><em><a href="https://curia.europa.eu/juris/liste.jsf?num=C-73/17">France v Parliament</a></em> the Court held that two provisions of the same legal value must be read <em>&#8220;in a manner that reconciles those obligations and strikes a fair balance between them.&#8221;</em></p><p>Two caveats before you count on that. It concerned primary law, where &#8220;<em>same legal value&#8221;</em> has a specific meaning. And no judgment has applied the method to two equal-rank regulations. Try applying it either way.</p><p>The instinct at this stage is to reach for <em>lex specialis derogat legi generali</em>, the specific displaces the general. It is a real principle and genuinely part of EU legal reasoning. It is also an interpretive tool rather than a hierarchy rule, and it only engages where two provisions govern the same subject matter.</p><p>I believe that the AI Act and the GDPR do not. One regulates the placing on the market and the use of AI systems. The other regulates the processing of personal data. They land on the same system without meeting on the same question.</p><p><a href="https://artificialintelligenceact.eu/article/10/">Article 10 of the EU AI Act</a> on data governance, and the new Article 4a, do regulate the processing of personal data. <a href="https://artificialintelligenceact.eu/article/2/">Article 2(7)</a> carves out its own exceptions to GDPR neutrality, which concedes some overlap. I would say that the overlap sits at the edges, and lex specialis needs more than edges. But many might disagree with me.</p><p>Which leaves the default: absent an express rule, both instruments apply in full. </p><p>Neither is discounted because the other exists. So a single system in a single financial entity might be, at the same time, a high-risk AI system with a provider and a deployer, a processing operation with a controller and a processor, and an ICT service supplied by an ICT third-party service provider to a financial entity.</p><p>Three regimes. Three sets of names for the same two parties. Three definitions of risk.</p><p>You do not choose between them. You carry all of them.</p><div><hr></div><h2><strong>The EU Knows How to Write a Precedence Rule</strong></h2><p><a href="https://eur-lex.europa.eu/eli/dir/2022/2555/oj">Article 4 of NIS2</a>, the EU&#8217;s cybersecurity directive, does exactly what the AI Act declines to do. Where sector-specific Union law imposes cybersecurity risk-management measures or incident notification requirements at least equivalent in effect to NIS2&#8217;s own, the NIS2 provisions do not apply to those entities. </p><p>Do not apply, including the whole supervision and enforcement chapter.</p><p>Article 4(2) then supplies the equivalence test. And Recital 28 names the winner outright:</p><blockquote><p><em>Regulation (EU) 2022/2554 of the European Parliament and of the Council should be considered to be a sector-specific Union legal act in relation to this Directive with regard to financial entities.</em></p></blockquote><p>DORA displaces NIS2 for financial entities. Written down, by name, in the recitals.</p><p>The Commission then published <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:52023XC0918(01)">guidelines</a> on how to apply the equivalence test, setting out what the sectoral measures have to cover to qualify.</p><p>So the mechanism exists. A template, a test, and official guidance on operating the test. (NIS2 is a directive rather than a regulation, which complicates the comparison slightly but it changes nothing about the point.)</p><p>None of it was applied between the AI Act and the GDPR, or between the AI Act and DORA.</p><div><hr></div><h2><strong>What the AI Act Wrote </strong></h2><p>It wrote interaction clauses. </p><p><a href="https://artificialintelligenceact.eu/article/2/">Article 2(7)</a> says Union law on the protection of personal data applies to personal data processed in connection with the rights and obligations in the AI Act, and that the Regulation does not affect the GDPR. That looks like a precedence clause. It is not quite it. It is the AI Act confirming that the GDPR continues to apply alongside it, in full, and declining to say what happens when the two point in different directions.</p><p><a href="https://artificialintelligenceact.eu/article/9/">Article 9(10)</a> says providers already subject to internal risk-management requirements under other Union law <em>may</em> fold the AI Act&#8217;s risk management into those procedures. </p><p><a href="https://artificialintelligenceact.eu/article/8/">Article 8(2)</a> gives providers a choice of integrating testing, reporting and documentation with product-safety law to avoid duplication. However, Article 8(2) opens with a duty, not a choice: providers <em>shall be responsible</em> for ensuring the product is fully compliant with both regimes. Only the integration is optional.</p><p><a href="https://artificialintelligenceact.eu/article/17/">Article 17(4)</a> deems, conditionally. For providers that are financial institutions subject to internal governance requirements under Union financial services law, the quality management obligation is deemed fulfilled <em>by complying with</em> those internal governance rules. Complying, not merely being subject to them. And three points are excepted: the risk management system, post-market monitoring, and serious incident reporting. The AI Act lets existing governance carry the paperwork and keeps the three obligations that detect harm.</p><p>And <a href="https://artificialintelligenceact.eu/article/26/">Article 26(9)</a> says <em>shall</em>. Deployers of high-risk AI systems shall use the information the provider supplies under Article 13 to comply with their data protection impact assessment obligation under Article 35 GDPR.</p><p>That is the only provision in the AI Act that makes an AI Act piece a required input to a GDPR process. The vendor&#8217;s instructions for use are now compulsory reading for company&#8217;s DPIA.</p><div><hr></div><h2><strong>Last Month Wrote Precedence Three Times</strong></h2><p>On 24 July the <a href="https://eur-lex.europa.eu/eli/reg/2026/1744/oj">Digital Omnibus on AI</a> was published in the Official Journal (it was in force three days later). Aside from the deadline deferrals that got all the coverage, it wrote precedence into the AI Act three times, by three different techniques. </p><p><strong>The first is an equivalence route.</strong> New Article 2(13): where product-safety legislation listed in Section A of Annex I already provides an equivalent or higher level of protection, the application of Articles 9 to 15 and 17 to 25 may be limited. The Commission is to adopt delegated acts by 2 August 2027 specifying which systems, which requirements, and how far. Though nothing is limited yet. This is an empowerment with a deadline, not a live carve-out.</p><p><strong>The second is a migration.</strong> The Omnibus moved the <a href="https://eur-lex.europa.eu/eli/reg/2023/1230/oj">Machinery Regulation</a> from Section A of Annex I to Section B. Section B triggers Article 2(2), which disapplies the entire high-risk chapter for those systems. Recital 42 calls it a move to a sectoral approach. However, the Recital also provides that the Commission is to adopt delegated acts amending the Machinery Regulation&#8217;s own annex to reflect the AI Act&#8217;s high-risk requirements, plus Articles 17, 19, 72 and 73, applying by 2 August 2028. Manufacturers can rely on AI Act harmonized standards in the interim. The obligations are not being removed. They are being rehoused.</p><p><strong>The third is a hole aimed at the GDPR.</strong> New Article 4a lets providers and deployers process special categories of personal data where strictly necessary to detect and correct bias. And post-Omnibus, Article 2(7) now opens &#8220;<em>Without prejudice to Articles 4a and 59 of this Regulation.&#8221;</em> The clause that announces GDPR neutrality now names its own exceptions to it, in its first line.</p><p>So the position after last month is this:</p><ul><li><p>Machinery: rehoused, with the requirements to follow it across by 2028. </p></li><li><p>Other Section A product legislation, medical devices and toys and lifts among them: an equivalence route, pending 2027. </p></li><li><p>Personal data: one prohibition, for one purpose. Financial services: nothing, and DORA is not in Annex I at all.</p></li></ul><p>The EU is willing to rank its own instruments. It has at least three techniques for doing it. It used all three last month.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;fc3d2388-2fee-4bbb-baec-792225de3278&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;EU AI Act Amended: The Digital Omnibus Timeline&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-13T12:02:43.130Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!DR18!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/eu-ai-act-amended-the-digital-omnibus&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:196926473,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:3,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2><strong>Same Word, Different Meaning</strong></h2><p>Which brings me back to the beginning and the example of one AI system that falls under three regimes.</p><h4><strong>Risk</strong></h4><p>If you assessing such AI system, start with risk, because three regimes use it to mean three different things.</p><p>The AI Act defines risk in Article 3(2) as the combination of the probability of harm occurring and the severity of that harm. Harm to whom is answered elsewhere in the Act: health, safety and fundamental rights. Of persons.</p><p>The GDPR uses the word risk throughout and never defines it in its definitions article. The operative phrase is risk to the rights and freedoms of natural persons, given content by the recitals, by Articles 24, 32 and 35, and by two decades of supervisory guidance.</p><p>DORA does not define risk at all. It defines <em>ICT risk</em>: a circumstance in relation to the use of network and information systems which, if it materializes, may compromise the security of those systems, of technology-dependent tools and processes, of operations and processes, or of the provision of services.</p><p>Three objects of harm. The AI Act protects the person from the system. The GDPR protects the person&#8217;s rights in their data. DORA protects the firm&#8217;s operations from disruption.</p><p>A system can be low-risk under one and high-risk under another with no contradiction at all, because they are not measuring the same thing. Which is why your DORA risk register is not an AI Act risk management system, and why handing one to a market surveillance authority in place of the other will not go well.</p><h4><strong>Roles</strong></h4><p>The roles diverge the same way, and worse, because the two sets are not even the same kind of category. AI Act roles turn on <em>market position</em>: who placed the system on the market under their own name, who uses it under their authority. GDPR roles turn on <em>decisional control</em>: who determines the purposes and means of processing, who processes on their behalf.</p><p>The working assumption is that provider maps to processor and deployer maps to controller. It holds often enough to be dangerous. An AI vendor that decides what to do with customer data to improve its own model is a controller for that processing while remaining a provider under the AI Act. </p><p>Role determination has to be done twice, on two different tests, and the two answers do not have to agree.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;db9101aa-f9ea-4b26-b0ec-f25670310496&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;What's Your Role Under the EU AI Act? Practical Decision Tree.&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-06-10T12:03:27.696Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!Bh5p!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/your-role-under-the-eu-ai-act-guide&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:199877647,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:5,&quot;comment_count&quot;:5,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2><strong>Where the GDPR Stops, the AI Act Starts?</strong></h2><p>The sharpest divergence is about explanations. </p><p>Article 22 GDPR applies to a decision based <em>solely</em> on automated processing. The received wisdom followed: insert a human who exercises real judgement and Article 22 falls away. It is in most privacy training decks written between 2018 and 2023, and it has not aged well.</p><p>The Court of Justice narrowed it in <a href="https://curia.europa.eu/juris/liste.jsf?num=C-634/21">C-634/21 </a><em><a href="https://curia.europa.eu/juris/liste.jsf?num=C-634/21">SCHUFA Holding</a></em>. Where a credit reference agency produces a probability value and a third party draws strongly on that value in deciding whether to enter into a contract, establishing the value is itself a decision within Article 22(1). The human at the other end signing off does not necessarily rescue you.</p><p>Meanwhile the AI Act arrives from the opposite direction. <a href="https://artificialintelligenceact.eu/article/86/">Article 86</a> gives a right to explanation for</p><blockquote><p><em>a decision which is taken by the deployer on the basis of the output from a high-risk AI system listed in Annex III, with the exception of systems listed under point 2 thereof, and which produces legal effects or similarly significantly affects that person in a way that they consider to have an adverse impact on their health, safety or fundamental rights</em></p></blockquote><p>Taken by the deployer, on the basis of the output. The human is assumed, not excluded. The AI Act&#8217;s right is written for the exact decision the GDPR was thought to release.</p><p>The fix that used to remove the obligation is now what both rules are watching.</p><p>And then the AI Act does something strange with its own right. It applies only where EU law does not already give you one.</p><p>The GDPR does give you one. If a decision about you was made by the machine, you can ask the company for meaningful information about the logic behind it. For years the standard answer was that the logic is a trade secret. <a href="https://infocuria.curia.europa.eu/tabs/affair?sort=AFF_NUM-DESC&amp;searchTerm=%2522C%252D203%252F22%2522&amp;publishedId=C-203%2F22">In 2025 the Court of Justice closed that off</a>: a trade secret is not a refusal. The company hands the material to the supervisory authority or the court, and they decide how much the person sees.</p><p>So the AI Act&#8217;s right exists to cover what the GDPR misses, and what the GDPR misses keeps shrinking.</p><p>The GDPR right attaches to decisions the machine made. The AI Act right attaches to decisions a person made using the machine. Those are different sets. After the credit scoring judgment they overlap more than they used to, and neither the Commission nor a court has said where one ends and the other begins.</p><p>A right defined by the absence of another right, with the boundary still being drawn.</p><div><hr></div><h2><strong>What to Do</strong></h2><p>As always, I want to give you something that you can implement. Five moves:</p><ol><li><p><strong>Stop asking which regulation governs. Ask what each one is measuring.</strong> The first question has no answer. The second always does, and it resolves the practical case. Harm to the person: AI Act. Harm to the person&#8217;s rights in their data: GDPR. Harm to the firm&#8217;s operations: DORA.</p></li><li><p><strong>Classify separately, then map. Never classify once and translate.</strong> Run role determination twice, on each regime&#8217;s own test. Run risk classification separately for each. Build the mapping table as an output, one row per system, one column per regime. </p></li><li><p><strong>When both rules point the same way, meet the tighter one and write down why.</strong> Two regulations rarely ask for opposite things. More often one asks for more than the other, and the stricter version is the one you have to hit. An incident is the clearest case. If you are a financial firm, DORA wants the first report within four hours of classifying it, or 24 hours of noticing it, whichever comes first. The AI Act allows fifteen days. Four hours is your deadline, and the fifteen-day rule is satisfied on the way past. The AI Act lets you reuse the same paperwork for both. It does not let you use the looser standard.</p></li><li><p><strong>When two rules pull against each other, decide, and write down the reasoning.</strong> Sometimes you just have to choose. Bias testing is the live example. The AI Act now lets you use sensitive personal data, health and ethnicity and the rest, to check whether your system discriminates. It also tells you to delete that data once the bias is fixed. Every instinct in a testing team says keep it, so you can prove the fix held. Both positions are defensible, the choice needs to be on paper with a reason attached. </p></li><li><p><strong>Keep a list of the words that do not match.</strong> One line each: the word, the regulation, what it means there, what follows from it. Risk takes three lines. So does provider. So does incident. It is the least impressive document you will produce this year, and it is the one that stops the same argument restarting every quarter, because the answer is written down with a source next to it.</p></li></ol><p>And one note on timing. The AI Act&#8217;s high-risk obligations are deferred to 2 December 2027 for standalone Annex III systems and 2 August 2028 for those embedded in regulated products. Most of the collisions above are not operative today. The divergences are already law. The obligations they create mostly are not.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2><strong>Closing Argument</strong></h2><p>Cumulative application sounds like an inconvenience. It has a sharper edge,and it shows up in the order things happen.</p><p>One system fails. Two regulators can fine you for it: your data protection authority under the GDPR, and whoever supervises the AI Act where you are.</p><p>The Court of Justice has been asked whether that is allowed. Its answer is <a href="https://infocuria.curia.europa.eu/tabs/affair?sort=AFF_NUM-DESC&amp;searchTerm=%2522C%252D117%252F20%2522&amp;publishedId=C-117%2F20">yes</a>, with conditions. The Court said two fines can be lawful, but only where three things are true: </p><ol><li><p>the company could have seen the double exposure coming, </p></li><li><p>the two authorities work in step, and </p></li><li><p>the second fine takes the first into account so the total stays proportionate. </p></li></ol><p>It said the same thing a second time on the same day, <a href="https://infocuria.curia.europa.eu/tabs/affair?sort=AFF_NUM-DESC&amp;searchTerm=%2522C%252D151%252F20%2522&amp;publishedId=C-151%2F20">in a different case</a>. </p><p>A specialist regulator followed by a general one. Which is roughly the shape of a data protection authority and an AI regulator looking at the same system.</p><p>Now look at what the AI Act tells its own regulator to weigh when setting a fine. One item on that list is whether you have already been fined by another authority, under other EU or national law, for the same conduct.</p><p>That is the third condition, written into the statute. Your GDPR fine is something the AI Act instructs the regulator to take into account.</p><p>The GDPR does not return the favour. Its own list of factors has no equivalent item. The closest is a catch-all at the end: any other aggravating or mitigating factor in the circumstances. Open-ended, discretionary, and not the same thing as a rule.</p><p>So the coordination exists, and it runs one way.</p><p>Which means the order matters. Fined under the GDPR first, and the AI Act regulator has to account for it. Fined under the AI Act first, and your data protection authority may account for it, under a catch-all, if it chooses.</p><p>The AI Act was written to account for the GDPR. The GDPR was written eight years before there was anything to account for.</p><div><hr></div><p><strong><a href="https://ailawdecoded.com/p/scope"><span data-color="#077d9a" style="color: rgb(7, 125, 154);">Scope</span></a><span data-color="#077d9a" style="color: rgb(7, 125, 154);"> is where this becomes something you can use in a meeting: the regulation map, the role assignment, the vendor questions, the AI inventory spreadsheet, the AI policy template, with sources attached and kept current as the law changes.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[The EU AI Act's Ownership Gap]]></title><description><![CDATA[Other regulations name a responsible person. This one doesn't.]]></description><link>https://ailawdecoded.com/p/eu-ai-act-ownership-gap-who-is-responsible</link><guid isPermaLink="false">https://ailawdecoded.com/p/eu-ai-act-ownership-gap-who-is-responsible</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 12 Aug 2026 20:13:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0YLp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9c22e45-9f62-4dab-b6b8-e500ee0a51b8_6000x4000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0YLp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9c22e45-9f62-4dab-b6b8-e500ee0a51b8_6000x4000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0YLp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9c22e45-9f62-4dab-b6b8-e500ee0a51b8_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0YLp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9c22e45-9f62-4dab-b6b8-e500ee0a51b8_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0YLp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9c22e45-9f62-4dab-b6b8-e500ee0a51b8_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0YLp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9c22e45-9f62-4dab-b6b8-e500ee0a51b8_6000x4000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0YLp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9c22e45-9f62-4dab-b6b8-e500ee0a51b8_6000x4000.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a9c22e45-9f62-4dab-b6b8-e500ee0a51b8_6000x4000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:445758,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.com/i/210785474?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9c22e45-9f62-4dab-b6b8-e500ee0a51b8_6000x4000.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0YLp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9c22e45-9f62-4dab-b6b8-e500ee0a51b8_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0YLp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9c22e45-9f62-4dab-b6b8-e500ee0a51b8_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0YLp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9c22e45-9f62-4dab-b6b8-e500ee0a51b8_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0YLp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9c22e45-9f62-4dab-b6b8-e500ee0a51b8_6000x4000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>You finish the regulation map. Which laws apply to your company, which of your systems they touch, where every source is. It takes weeks, and almost none of that time goes on reading legislation. It goes on chasing answers around the company: which legal entity does what, whether a tool touches retail customers, who owns which system.</p><p>Then it&#8217;s done, and it does the thing it was built to do. The scope stops being arguable. <em>&#8220;Does this even apply to us&#8221;</em> has an answer now, with citations, and the conversation can finally move.</p><p>It also produces a list of gaps.</p><p>I thought the hard part was over at that point. What actually happened was that people stopped disputing the gaps and started avoiding eye contact instead.</p><p>Nobody argued. That&#8217;s the part worth sitting with. The list worked exactly as intended, and made the problems undeniable. What it could not do was put a name against any of them.</p><p>If you have run this exercise you already know how it ends. The gaps get logged. The document gets circulated. Someone says we should probably look at that. Six months later it is still true.</p><p>There is a reason that happens, and it isn&#8217;t organizational cowardice. It&#8217;s in the regulation.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>The EU AI Act Asks for a Responsibility Map Exactly Once</h2><p><a href="https://artificialintelligenceact.eu/article/17/">Article 17</a> sets out the quality management system a provider of a high-risk AI system has to put in place. Thirteen items: compliance strategy, design control, testing, data management, risk management, post-market monitoring, incident reporting, record-keeping, resource management. Then, at the bottom of the list:</p><blockquote><p><em>(m) an accountability framework setting out the responsibilities of the management and other staff with regard to all the aspects listed in this paragraph.</em></p></blockquote><p>That is the only place in the EU AI Act that asks an organization to write down, in one document, who is responsible for what. One sub-point, thirteenth of thirteen, in the article about quality management.</p><p>But there are three limits.</p><p><strong>It applies to providers.</strong> Article 17 sits in Chapter III and binds providers of high-risk AI systems. If you deploy AI rather than build it, you have no equivalent obligation. If you build AI that isn&#8217;t high-risk, same thing. </p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;efda0c17-975c-4bda-b151-40fb200db0f5&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Provider vs. Deployer Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-22T12:03:43.719Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!NS5L!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35f75bb-44f2-45d4-b53c-84654d8e8617_8192x5461.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/provider-vs-deployer-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:194314202,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:5,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><p><strong>It can be satisfied by something you already have.</strong> Article 17(3) lets any provider already subject to quality management obligations under sectoral EU law fold these aspects into the existing system. That reaches further than it sounds: medical device manufacturers, machinery and automotive suppliers, anyone already running a certified quality management system for a regulated product. Build the accountability framework into the system you were already audited on, and you have complied.</p><p>Article 17(4) goes further still for financial institutions. Comply with your internal governance requirements under EU financial services law and the quality management obligation is deemed fulfilled, with three exceptions: risk management, post-market monitoring, incident reporting. Point (m) is not among the exceptions.</p><p>Article 17(4) does add a sentence though:</p><blockquote><p><em>To that end, any harmonised standards referred to in Article 40 shall be taken into account.</em></p></blockquote><p>The deeming comes with a duty to take harmonised standards into account. No harmonised standard under <a href="https://artificialintelligenceact.eu/article/40/">Article 40</a> has been cited in the Official Journal yet. A duty to take into account something that doesn&#8217;t exist is a duty in form only, and it stays that way until CEN-CENELEC delivers and the Commission cites the result.</p><p><strong>And it isn&#8217;t in force.</strong> The <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202601744">Digital Omnibus on AI</a> deferred the bulk of Chapter III. Article 17 applies from December 2, 2027 for stand-alone Annex III systems and August 2, 2028 for AI embedded in regulated products.</p><p>Writing in August 2026, that is just under sixteen months. For providers. For high-risk systems only. And satisfiable by pointing at a governance framework you built for something else.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;b5d756c2-c70d-473c-adc8-266ae0175755&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;EU AI Act Amended: The Digital Omnibus Timeline&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-13T12:02:43.130Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!DR18!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/eu-ai-act-amended-the-digital-omnibus&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:196926473,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:3,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>Then the Regulation Steps Back, In Writing</h2><p><a href="https://artificialintelligenceact.eu/article/26/">Article 26</a> covers what deployers of high-risk systems have to do, and it contains the closest thing the EU AI Act has to a named-person requirement:</p><blockquote><p><em>Deployers shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support.</em></p></blockquote><p>Natural persons. Authority. Not a function, not a committee. That&#8217;s real, and it asks for more than a one-line summary of Article 26 suggests.</p><p>But read what it covers: human oversight of a specific high-risk system while it&#8217;s running. It says nothing about who owns the compliance program, who owns a documented gap, or who gets to decide that a gap is acceptable for now.</p><p>The obligations in paragraphs 1 and 2 are without prejudice to other obligations under EU or national law, and then, in paragraph 3, to:</p><blockquote><p><em>..the deployer&#8217;s freedom to organise its own resources and activities for the purpose of implementing the human oversight measures indicated by the provider.</em></p></blockquote><p>The regulation is declining, on the record, to tell you how to organize yourself.</p><p>This is a drafting decision, not an omission. <a href="https://artificialintelligenceact.eu/article/96/">Article 96</a> gives the European Commission open-ended power to issue guidelines, but nothing on its published guidance program addresses who inside your company should own AI compliance. If you have been holding the assignment question open until guidance arrives, it probably won&#8217;t.</p><p>Deployers get their own version of the deeming move. Article 26(5) requires deployers to monitor the operation of a high-risk system, then adds that for deployers who are financial institutions subject to internal governance requirements under EU financial services law, that monitoring obligation is deemed fulfilled by complying with those rules.</p><p>If you built the AI system, Article 17 is yours. If you bought it, Article 26(5) is. Either way the move is identical, and so is the consequence. A structure you built for a different regulation is treated as sufficient, and whether it was designed with AI risk in mind never gets asked.</p><div><hr></div><h2>Other Regulations Name Someone</h2><p><strong>The GDPR</strong> names the data protection officer. <a href="https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng#art_37">Articles 37 and 38</a>: mandatory designation in defined cases, reporting directly to the highest management level.</p><p><strong>DORA</strong> names the management body. <a href="https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng#art_5">Articles 5 and 6</a>: ultimate responsibility for ICT risk, a duty to define, approve and oversee the framework, and an annual review of it.</p><p><strong>NIS2</strong> names management bodies. <a href="https://eur-lex.europa.eu/eli/dir/2022/2555/oj#art_20">Article 20</a>: they approve and oversee the risk-management measures, undergo training, and can be held liable under national implementing law.</p><p><strong>The Medical Devices Regulation</strong> names a person responsible for regulatory compliance. <a href="https://eur-lex.europa.eu/eli/reg/2017/745/oj/eng#art_15">Article 15</a> requires at least one named individual inside the manufacturer, with defined qualifications and minimum years of experience.</p><p><strong>Solvency II</strong> names key function holders. <a href="https://eur-lex.europa.eu/eli/dir/2009/138/oj#art_42">Article 42</a> on fit and proper, then Articles 44, 46, 47 and 48: named holders of risk management, compliance, internal audit and actuarial functions.</p><p><strong>The EU AI Act</strong> names the company.</p><p>Every one of those regimes decided that an obligation without a name attached to it doesn&#8217;t get met. The EU AI Act reached the opposite conclusion, or more precisely, declined to reach one.</p><p>The practical consequence is to pick any regulated system in your company and you will find a named accountable person for its data, its security, or its operational resilience, and no named owner for the fact that it runs on AI. </p><p>Supervisors have started noticing this, and one of them has already acted. EIOPA published an <a href="https://www.eiopa.europa.eu/eiopa-publishes-opinion-ai-governance-and-risk-management-2025-08-06_en">Opinion on AI governance and risk management</a> in August 2025 that creates no new rules and instead reads the EU AI Act alongside the sectoral rules it supervises, including DORA and the GDPR. It says the board remains responsible for the use of AI in the business, calls for clear definition of roles and responsibilities, and notes that firms may appoint AI officers to advise the other functions. The scope is the interesting part: the Opinion covers AI systems that are neither prohibited nor high-risk, expressly to avoid overlapping with the EU AI Act.</p><p>Which means a European supervisor wrote guidance on who owns AI, specifically for the systems the EU AI Act doesn&#8217;t reach.</p><p>That is probably the pattern to watch out for. The bodies that will fill this hole are not going to be the European Commission. They are the supervisors who already regulate you, who already hold a view on who should be accountable for what, and who are used to saying so. </p><div><hr></div><h2>The One Place the EU AI Act Does Allocate Ownership</h2><p>There is a counter-example though.</p><p>The <a href="https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai">General-Purpose AI Code of Practice</a>, drawn up under <a href="https://artificialintelligenceact.eu/article/56/">Article 56</a> and endorsed in August 2025, has a Safety and Security chapter that does what the rest of the EU AI Act doesn&#8217;t. Signatories commit to define responsibilities for managing systemic risk across all levels of the organization, allocate resources to it, and follow specific guidance on distributing those responsibilities, including assigning supervisory duties to the management board and pushing the obligations down defined reporting lines.</p><p>That is an EU instrument naming who owns AI risk, and it is EU AI Act machinery.</p><p>It is also voluntary, provider-side, and very narrow. The Code is not binding law, signatories can adopt some chapters and not others, and the Safety and Security chapter reaches only providers of general-purpose AI models with systemic risk: a handful of frontier labs, not the roughly 190 organizations that have signed the Code overall. </p><p>It buys no presumption of conformity, only the AI Office weighing your commitments when it sets a fine under <a href="https://artificialintelligenceact.eu/article/101/">Article 101</a>.</p><div><hr></div><h2>What a Documented Ownership Gap Does To Your Legal Position</h2><p><a href="https://artificialintelligenceact.eu/article/99/">Article 99</a>(7) lists what a national authority weighs when deciding whether to fine you and how much. Ten factors, (a) through (j). I find two of them important:</p><blockquote><p><em>(g) the degree of responsibility of the operator taking into account the technical and organisational measures implemented by it</em></p><p><em>(i) the intentional or negligent character of the infringement</em></p></blockquote><p>Point (g) puts your organizational measures directly into the fine calculation. Assigning an owner is an organizational measure. So is not assigning one, and the absence shows up on the face of your own governance documents.</p><p>Point (i) is sharper. A gap you never found is negligence. A gap you identified, wrote down, circulated to the people who could have fixed it, and left unassigned for eighteen months is a different animal. You have produced a written record of knowledge and a written record of inaction, and they are in the same document.</p><p>The list that ended the scope argument is also the list that proves you knew.</p><p>None of which is an argument for keeping worse records. Deliberately not looking is its own exposure, and a supervisor who finds no regulation map at all will draw the obvious conclusion about your organizational measures under point (g). The argument is narrower: documenting a gap starts a clock that assignment is supposed to stop.</p><p>Timing matters here. Until December 2027 there is no high-risk obligation to breach, so an unassigned high-risk gap is not yet fineable under the EU AI Act. What is live today: <a href="https://artificialintelligenceact.eu/article/5/">Article 5</a> on prohibited practices, <a href="https://artificialintelligenceact.eu/article/50/">Article 50</a> on transparency, the general-purpose AI obligations in Chapter V, and your GDPR exposure running alongside all of it. A documented gap in any of those is fine-relevant now. A documented high-risk gap is a record being built for a regime that arrives in sixteen months.</p><div><hr></div><h2>What Assignment Actually Takes</h2><p>The reason the ownership gaps stay unassigned is that the assignment step has no deadline attached to it. Everything else on the roadmap has a date. This has nothing, because the one provision that would force it is sixteen months out and doesn&#8217;t reach deployers at all. Organizations focus on the work that has a date on it. </p><p>So it has to be made non-optional by someone with the standing to do that, and there are only three things they need to hand over.</p><p><strong>A name.</strong> Not a function, not a committee, not &#8220;Legal and IT jointly.&#8221; Article 26(2) already tells you the standard for human oversight: natural persons with competence, training and authority. Apply the same test one level up. If your governance document says a department owns something, nobody owns it.</p><p><strong>A budget.</strong> An owner who has to negotiate for resources every time the ownership gap needs work is a person with a title and a problem.</p><p><strong>The authority to stop the system.</strong> This is the one that gets skipped. <a href="https://www.iso.org/standard/42001">ISO/IEC 42001</a> is explicit about it in its treatment of AI roles and responsibilities: the role needs documented authority to act, not a designation. If your named owner cannot pull a system out of production without escalating to three other people, you have assigned blame rather than ownership.</p><p>ISO/IEC 42001 and the <a href="https://airc.nist.gov/airmf-resources/playbook/govern/">NIST AI Risk Management Framework</a> both put role assignment at the foundation, which tells you the practitioners who drafted them hit this same wall. Neither is a harmonised standard under Article 40, so certifying to one discharges no EU AI Act obligation. What it gives you is a defensible answer to Article 99(7)(g) when someone asks what organizational measures you implemented. That&#8217;s not nothing, and it&#8217;s also not compliance.</p><p>None of this works without an honest inventory underneath it, which is the step before this one.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;a8b5335b-4139-4896-94ef-c8ad81690bd5&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Your Role Classification Is Only as Honest as Your AI Inventory&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-07-08T20:12:57.701Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!HkyX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e75c2b-fd26-4440-8986-372d833c62b0_6000x4000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/eu-ai-act-role-classification-ai-inventory&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:205943005,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:3,&quot;comment_count&quot;:4,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>AI Governance Ownership Across Functions</h2><p>The IAPP and Credo AI asked over 670 governance professionals across 45 countries which function holds primary responsibility for AI governance. Privacy came first at 22 percent. Legal and compliance also came first, at 22 percent. Then IT at 17, data governance at 10, ethics and compliance at 6, security at 5. The <a href="https://iapp.org/resources/article/ai-governance-profession-report">fieldwork</a> ran in spring 2024, so read it as how the profession arranged itself as the regulation arrived.</p><p>No function holds a majority. Those six account for 82 percent, which leaves roughly one in five organizations answering something else entirely.</p><p>Distributed is the word the reports use. In practice, distributed is what an ownership gap becomes when it has no name against it.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p>Set the frontier labs aside and every EU AI Act obligation in force today applies to the company as an abstraction. <a href="https://artificialintelligenceact.eu/article/4/">Article 4</a> on AI literacy, which the Omnibus rewrote in July to soften the standard from ensuring a level of literacy to supporting its development. Article 5 on prohibited practices. Article 50 on transparency, live since August 2. All of them binding on &#8220;providers and deployers,&#8221; which is to say on nobody in particular.</p><p>The first provision that requires a written answer to who is responsible arrives in December 2027, for providers, for high-risk systems, and can be satisfied by pointing at a structure you built for a different regulation.</p><p>Which leaves the ownership gap where it started. On the page, undeniable, and still no one&#8217;s.</p><div><hr></div><p><strong><a href="https://ailawdecoded.com/p/scope"><span data-color="#077d9a" style="color: rgb(7, 125, 154);">Scope</span></a><span data-color="#077d9a" style="color: rgb(7, 125, 154);"> is where this becomes something you can use in a meeting: the regulation map, the role assignment, the vendor questions, the AI inventory spreadsheet, the AI policy template, with sources attached and kept current as the law changes.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[Nobody Ever Disclosed the Associate]]></title><description><![CDATA[Substack scans for AI now. The law asks a different question.]]></description><link>https://ailawdecoded.com/p/eu-ai-act-article-50-newsletter-writers</link><guid isPermaLink="false">https://ailawdecoded.com/p/eu-ai-act-article-50-newsletter-writers</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 05 Aug 2026 12:03:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!CbUb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F290f2bf4-5f75-4df5-b495-0d8625a5cc85_5760x3240.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CbUb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F290f2bf4-5f75-4df5-b495-0d8625a5cc85_5760x3240.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CbUb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F290f2bf4-5f75-4df5-b495-0d8625a5cc85_5760x3240.jpeg 424w, https://substackcdn.com/image/fetch/$s_!CbUb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F290f2bf4-5f75-4df5-b495-0d8625a5cc85_5760x3240.jpeg 848w, https://substackcdn.com/image/fetch/$s_!CbUb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F290f2bf4-5f75-4df5-b495-0d8625a5cc85_5760x3240.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!CbUb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F290f2bf4-5f75-4df5-b495-0d8625a5cc85_5760x3240.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CbUb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F290f2bf4-5f75-4df5-b495-0d8625a5cc85_5760x3240.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/290f2bf4-5f75-4df5-b495-0d8625a5cc85_5760x3240.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:415375,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.com/i/209505501?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F290f2bf4-5f75-4df5-b495-0d8625a5cc85_5760x3240.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CbUb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F290f2bf4-5f75-4df5-b495-0d8625a5cc85_5760x3240.jpeg 424w, https://substackcdn.com/image/fetch/$s_!CbUb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F290f2bf4-5f75-4df5-b495-0d8625a5cc85_5760x3240.jpeg 848w, https://substackcdn.com/image/fetch/$s_!CbUb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F290f2bf4-5f75-4df5-b495-0d8625a5cc85_5760x3240.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!CbUb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F290f2bf4-5f75-4df5-b495-0d8625a5cc85_5760x3240.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>An associate spends two weeks on an article. Research, structure, argument, several drafts. A partner reads it, changes a heading, and the firm publishes it under his name.</p><p>This is not a scandal. It is how law firms, the Big Four, consultancies, politics and most of business have worked for as long as any of us have been in it. The named author supplied the judgment about whether the thing was right, and the accountability for it being wrong. The associate supplied the keystrokes.</p><p>And in ordinary commercial publishing, nobody has ever demanded a disclosure. No client alert has carried a line reading <em>&#8220;100% written by our paralegal.&#8221;</em> Formal rules do exist at the edges, where the stakes are personal: several US bars require a lawyer to disclose ghostwriting for a self-represented litigant, and academic authorship standards require contributors to be named. But for the alerts, the briefings and the thought leadership that make up most professional writing, nobody asked, because nobody thought the keystrokes were what they were buying.</p><p>Then the assistant stopped being a person, and suddenly the keystrokes are the only thing anyone wants to measure.</p><p>Two instruments now claim to deliver transparency about written work. One is law and has applied since August 2. The other is a button on this platform, live since July 21. They point at the same anxiety, they measure completely different objects, and if you write a newsletter it is worth knowing which one should actually matter you.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>The Law: In the Version That Concerns Writers</h2><p>I went through <a href="https://artificialintelligenceact.eu/article/50/">Article 50</a> in full last week, including what human review, editorial control and editorial responsibility mean in the European Commission&#8217;s reading. The provision that concerns anyone publishing text is the second subparagraph of Article 50(4). The first subparagraph is about deepfakes. The second one is about you.</p><p><strong>Start with</strong> whether it reaches you at all, because a lot of people reading this are not in Europe. The AI Act binds deployers established or located in the Union, and deployers in third countries where the output of the system is used in the Union. A newsletter written in Ohio with subscribers in Dublin is not obviously outside that. Whether <em>&#8220;output used in the Union&#8221;</em> condition is met by EU readers opening an email is untested, and we don&#8217;t know yet how this will play out.</p><p><strong>Then four questions</strong>, in the order the provision actually asks them.</p><p><strong>The first one</strong> I skipped last week.</p><p>Article 50(4) applies to deployers of an AI system that generates or manipulates text. If nothing generated or manipulated your text, nothing that follows applies. So where does editing assistance stop and generation start? The AIAct does not say so. </p><p>Article 50(2), which governs marking by providers rather than disclosure by deployers, carves out systems performing an assistive function for standard editing, or not substantially altering the input data or its meaning. That carve-out sits textually in 50(2) and does not appear in 50(4). So the argument that polishing is not generating is available, and it is not airtight.</p><p><strong>Second</strong>, are you a deployer? You are, if you use an AI system under your own authority in a professional capacity. The Commission draws the line at economic activity: a natural person who gains economic benefit on a regular basis, or is otherwise engaged in business, trade, occupational or freelance activity, is a deployer. Purely personal, non-professional use sits outside the EU AI Act entirely.</p><p>A newsletter for six friends is out. Paid subscriptions put you in. So does a free newsletter that feeds a consulting practice, or that you treat as professional work. That somebody else pays your salary is irrelevant to your own publication, which is your own professional activity. Inside your day job the analysis differs, because employees acting under a company&#8217;s instructions are not separate deployers.</p><p><strong>Third</strong>, is it a matter of public interest? The European Commission&#8217;s list is illustrative rather than closed, and it runs through politics and democratic processes, public administration and services, the administration of justice and law enforcement, fundamental rights, public security, public health, the environment, consumer safety, and economic, financial, scientific and cultural developments relevant to public debate. Write about any of those seriously and you are inside it. There is no case law. There is guidance, which sets out a three-part test of published, informative to the public, and on a matter of public interest, and which does not tell you where the boundary runs.</p><p><strong>Fourth</strong>, did a person examine the substance, and is a person answerable for it. That is the exemption, and it needs both parts at the same time.</p><p>However, the <a href="https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems">Commission&#8217;s guidelines</a> are interpretive and not binding. Market surveillance authorities can be expected to follow them. The Court of Justice is the only body that decides what the AI Act means, and it has not been asked yet.</p><p>If you get this wrong the ceiling is &#8364;15 million or 3% of worldwide turnover, enforced by national market surveillance authorities. For a solo newsletter the realistic exposure is somewhere near nothing. The line still matters, because it is the only defensible thing you can say.</p><p>And the fourth question is the same question the partner was answering. </p><p>It has never required a disclosure.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;05ef4c81-88fe-472e-bc04-cff9bced25ce&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;AI Has to Say It's AI Now&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-07-29T12:00:10.993Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!We5V!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b677b2-35e9-4947-84e5-2d905c414fba_7680x4320.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/eueu-ai-act-article-50-transparency&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:208463778,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:5,&quot;comment_count&quot;:2,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>The Platform: Live Since July 21</h2><p>On July 21 Substack switched on AI detection built with <a href="https://support.substack.com/hc/en-us/articles/50891130623508-How-can-I-detect-AI-on-Substack">Pangram</a>. Any reader can open a post, tap three dots, choose Scan for AI text, and get an estimate of how much of it was human-written and how much was AI-assisted.</p><p>It works only on posts and Notes published on or after July 21. It runs in the Substack Reader on web and in the iOS app, with Android still to come, and it covers Notes in the feed plus individual comments and replies. Reported minimum lengths differ between outlets, and neither Substack&#8217;s help page nor the announcement gives a firm number, so treat any figure you have seen as unconfirmed.</p><p>Writers get two controls. A statement under Settings called <em>&#8220;How I make this,&#8221;</em> which surfaces to anyone who scans your work. And the option to disable detection on a given post, after which readers see &#8220;<em>AI detection unavailable,</em>&#8221; which is its own kind of answer.</p><p>The European Commission wrote a rule about editorial responsibility. Substack shipped a classifier that reads sentence patterns. </p><p>Both were called transparency.</p><div><hr></div><h2>What Happened When I Scanned My Own Work</h2><p>My article on MS Copilot Agent, published on July 22, came back as fully AI-assisted text. The reading was 100%. That piece was researched by me, argued by me, experienced by me in my day job, checked line by line against the Commission&#8217;s guidelines, and rewritten repeatedly (one part of it I rewrote eight time) because the ambiguity at its centre would not land clearly enough.</p><p>I then scanned the AI Act Tracker. Same desk, same process, different week. 11% AI. 89% human.</p><p>The tempting conclusion is that the detector is broken. </p><p>I do not think that, and I would rather not build an argument on a claim that is convenient. Pangram publishes a false positive rate on the order of one in ten thousand. More usefully, an independent evaluation by Jabarian and Imas, written up by Chicago Booth Review, tested it against three competitors and found it the only detector holding what they call policy-grade accuracy across models, though performance degrades on very short passages.</p><p>So I guess it was doing its job both times, and between those two pieces the amount of AI assistance in the prose genuinely differed. Note the words the tool actually uses. It reports AI-assisted rather than machine-written, and it calls the figure an estimate rather than a verdict. Both of those are more careful than a round 100% makes them sound.</p><p>In my opinion that is the actual problem.</p><p>Both pieces went through the same editorial process. Both were verified against primary sources by a lawyer. Both carry my name, my judgment, and my liability if they are wrong. Under Article 50(4) they are indistinguishable, and I believe that both sit inside the exemption.</p><p>One scored 11%. The other scored 100%.</p><p>The number moved. My accountability did not.</p><p>The detector is not malfunctioning. It is answering a question the law does not ask. Article 50(4) wants to know whether a person examined the substance and whether a person is answerable for it. A classifier cannot see either, because neither is in the text. </p><p>What is in the text is rhythm, cadence and word choice.</p><p><strong>Polish.</strong> </p><p>The least substantive layer of any piece of writing. Not the argument, not the structure, not whether the article number is right or the deadline is real.</p><p>Which is why the verdict and the obligation come apart in both directions. You can be compliant and flagged. You can also be non-compliant and clean, because a writer who pastes raw output, runs it through a rewording tool and publishes without reading it properly may well scan as human. </p><p>That writer is the one Article 50(4) was written for.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;da261741-c848-4105-aca9-025d026b3836&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Your Colleague Built an Agent&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-07-22T20:25:26.707Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!uAh2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e55e258-8578-4dc8-9e69-b560f9cbcf05_6000x4000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/employee-copilot-agents-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:207818109,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:3,&quot;comment_count&quot;:2,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>The Hole In the Tool</h2><p>Substack&#8217;s own documentation says the scan is unavailable for video or audio posts, for posts viewed on standalone Substack sites including custom domains, and for emails.</p><p>Three exclusions, and the last two are the ones that reach you. This newsletter lives at ailawdecoded.com. Most of you are reading this in your inbox, because that is what a newsletter is.</p><p>In both of those places the label does not exist. No scan on the website, no scan in the email. The verdict is visible only to a reader who opens the piece inside the Substack Reader or the iOS app.</p><p>A transparency tool that cannot reach the publisher&#8217;s own website, and cannot reach the email that delivers the writing to the people who subscribed to it, has a fairly substantial gap where its transparency should be.</p><p>There is a third instrument, for completeness. The <a href="https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content">Commission&#8217;s Code of Practice on Transparency of AI-generated Content</a>, finalized in June, covers the labelling duties in Article 50(4) and gives signatories an approved route to demonstrating compliance. It is built for platforms and generative AI companies rather than individual writers, and signing it is not a realistic move for a person with a newsletter. Worth knowing it exists before somebody tells you that you should have signed it.</p><p>So, the law measures editorial responsibility and cannot see how the text was made.</p><p>The detector measures how the text was made and cannot see who is responsible for it. And it only looks in one of the three places people read.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>What Editorial Control Looks Like From the Inside</h2><p>The practical question for a writer is not whether you use AI. It is whether you could describe your process to a reader, or a regulator, and have it clear the exemption. </p><p>Mine, in the detail the standard actually asks for:</p><p>Topics come from practice. From the work itself, and from questions readers leave in the comments. Nothing gets written because it would be easy to generate.</p><p>Every piece starts from a brief I write: the article numbers in play, the argument, the opening, the point the piece has to drive at. Then research, and verification of every claim against the regulation, the official guidance, and other lawyers&#8217; readings of it. Where something cannot be confirmed, the draft says so, and that sentence survives into publication.</p><p>Then editing, which takes most of the time. Like I mentioned, a piece can go through eight rewrites. Not for typos. For the angle, for which points survived, for the closing. Seven versions may not be clear enough about an ambiguity that matters, so they don&#8217;t get to be published.</p><p>That is human review of the substance. Somebody with relevant knowledge decided what was true, what was arguable, and what was not going out, and my name is on the result, which means I hold the legal responsibility for every claim in it.</p><p>A classifier cannot see any of that. It sees the eighth version&#8217;s sentences and reports on their texture.</p><p>If you publish, there are three things worth doing:</p><ol><li><p>Work out whether you are a deployer. That mostly means asking whether the newsletter is professional activity or a hobby, and answering honestly.</p></li><li><p>Decide whether your process would survive the description above. &#8220;AI drafts it, I skim it, it ships&#8221; does not, and that is the case the label exists for.</p></li><li><p>Write the process down. Substack now gives you somewhere to put it, under Settings, called <em>&#8220;How I make this.&#8221;</em> It is the voluntary version of a disclosure the law may or may not require of you.</p></li></ol><p>Detection is on for this piece. Turning off the scanner on an article about AI disclosure would be indefensible, so whatever it returns is what it returns.</p><p>The associate was never the disclosure. The partner&#8217;s name was the disclosure, because the name carried the judgment and the liability. That has not changed. Only the assistant has.</p><p>I won&#8217;t apologize for using AI for my prose. You shouldn&#8217;t either.</p><div><hr></div><p><strong><a href="https://ailawdecoded.com/p/scope"><span data-color="#077d9a" style="color: rgb(7, 125, 154);">Scope</span></a><span data-color="#077d9a" style="color: rgb(7, 125, 154);"> is where this becomes something you can use in a meeting: the regulation map, the role assignment, the vendor questions, the AI inventory spreadsheet, the AI policy template, with sources attached and kept current as the law changes.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[The EU AI Act Tracker]]></title><description><![CDATA[Every change to the EU AI Act, dated. Free, and kept current.]]></description><link>https://ailawdecoded.com/p/eu-ai-act-tracker</link><guid isPermaLink="false">https://ailawdecoded.com/p/eu-ai-act-tracker</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Sun, 02 Aug 2026 13:09:37 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0wZ7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e7c2e98-5ae1-4d40-a1af-c301be69edb2_4500x3000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0wZ7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e7c2e98-5ae1-4d40-a1af-c301be69edb2_4500x3000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0wZ7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e7c2e98-5ae1-4d40-a1af-c301be69edb2_4500x3000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0wZ7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e7c2e98-5ae1-4d40-a1af-c301be69edb2_4500x3000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0wZ7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e7c2e98-5ae1-4d40-a1af-c301be69edb2_4500x3000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0wZ7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e7c2e98-5ae1-4d40-a1af-c301be69edb2_4500x3000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0wZ7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e7c2e98-5ae1-4d40-a1af-c301be69edb2_4500x3000.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1e7c2e98-5ae1-4d40-a1af-c301be69edb2_4500x3000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:454388,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.com/i/208563470?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e7c2e98-5ae1-4d40-a1af-c301be69edb2_4500x3000.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0wZ7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e7c2e98-5ae1-4d40-a1af-c301be69edb2_4500x3000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0wZ7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e7c2e98-5ae1-4d40-a1af-c301be69edb2_4500x3000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0wZ7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e7c2e98-5ae1-4d40-a1af-c301be69edb2_4500x3000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0wZ7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e7c2e98-5ae1-4d40-a1af-c301be69edb2_4500x3000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>I don&#8217;t know if it is just me, but I feel like it&#8217;s becoming increasingly hard to keep track of all the guidelines, Q&amp;As and codes the EU publishes for the AI Act. Especially in combination with the timeline. What is applicable when, which guideline is in force and which one is still in public consultation. And what should a small company actually do, and when?</p><p>OK, I have to be honest. From the conversations I have, I know it&#8217;s not just me. That&#8217;s why I decided it&#8217;s high time I publish this AI Act Tracker.</p><p>I will update the Tracker whenever something moves. The date below tells you when I last checked and updated the Tracker.</p><p>Just one disclaimer (because I&#8217;m a lawyer, you know): This is not a legislative history. The Future of Life Institute maintains <a href="https://artificialintelligenceact.eu/developments/">one of those</a>, plus an <a href="https://artificialintelligenceact.eu/implementation-timeline/">implementation timeline</a> of what is still ahead. This is a different thing: a running record of what has already changed, and what changed for you and me as a result.</p><p><strong>Last checked: August 2, 2026.</strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><div class="callout-block" data-callout="true"><h4><span data-color="#077d9a" style="color: rgb(7, 125, 154);">August 2, 2026:</span> <br>Article 50 transparency obligations apply<br></h4><p><strong>What happened.</strong> The transparency duties in Article 50. Chatbots, synthetic audio, image and video, and text published to inform the public on matters of public interest.</p><p><strong>What changes.</strong> Disclosure stops being something to prepare for. Article 50(2) watermarking runs on its own clock: systems on the market before today have until December 2, 2026, anything placed on the market from today marks its output from day one.</p><p><strong>Penalties, and exceptions.</strong> Article 99(4) sets &#8364;15 million or 3% of worldwide annual turnover, whichever is higher. Article 99(6) reverses that for SMEs and start-ups: whichever is <strong>lower</strong>. If you are small, the second provision is the one that applies to you. The omnibus has extended related simplifications to small mid-cap companies.</p><p><a href="https://artificialintelligenceact.eu/article/50/">Article 50</a> &#183; <a href="https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems">Commission guidelines</a> &#183; <a href="https://digital-strategy.ec.europa.eu/en/policies/eu-icons-labelling-ai-generated-content">EU Official Icons</a> &#183; <a href="https://ailawdecoded.com/p/eueu-ai-act-article-50-transparency">My article</a> </p></div><div><hr></div><div class="callout-block" data-callout="true"><h4><span data-color="#077d9a" style="color: rgb(7, 125, 154);">August 2, 2026:</span> <br>National enforcement powers arrive<br></h4><p><strong>What happened.</strong> Chapter IX, the market surveillance framework. National authorities can now supervise, including Article 4 AI literacy. The AI Office gains its Article 101 power to fine general-purpose model providers.</p><p><strong>What it changes.</strong> Article 4 has applied since February 2025 with no supervisory machinery behind it. That machinery now exists.</p><p>Note the limit, because it is easy to overstate. Article 4 does not appear in the Article 99(4) list of finable provisions. National authorities can supervise AI literacy from today. There is no harmonised fine attached to it. Supervision and exposure to a penalty are not the same thing.</p><p><strong>Except in most of the EU there is no authority to use them yet.</strong> As of June 17, 2026, nine of twenty-seven Member States had designated both a market surveillance authority and a notifying authority. Twelve had done part of it. Six were unclear.</p><p><strong>See where your country stands:</strong></p><ul><li><p><a href="https://artificialintelligenceact.eu/national-implementation-plans/">National implementation plans, by Member State</a></p></li><li><p><a href="https://digital-strategy.ec.europa.eu/en/policies/ai-act-governance-and-enforcement">Commission page on AI Act governance and enforcement</a></p></li></ul></div><div><hr></div><div class="callout-block" data-callout="true"><h4><span data-color="#077d9a" style="color: rgb(7, 125, 154);">July 27, 2026:</span> <br>The Digital Omnibus on AI enters into force<br></h4><p><strong>What happened.</strong> Regulation (EU) 2026/1744 of July 8, 2026, published in the Official Journal on July 24, took effect. It is the first set of formal amendments to the AI Act since adoption in 2024, and it also amends Regulations (EU) 2018/1139 and (EU) 2023/1230. </p><p><strong>What changes:</strong></p><p><em>The high-risk dates.</em> Annex III standalone systems, covering employment, education, credit and access to essential services, move from August 2, 2026 to <strong>December 2, 2027</strong>. Annex I embedded systems move from August 2, 2027 to <strong>August 2, 2028</strong>.</p><p><em>Machinery is not deferred, it is removed.</em><span> Machinery Regulation products were moved out of the high-risk regime, from Annex I Section A to Section B, and handed to delegated acts. The Commission must adopt those by </span><strong>August 2, 2028</strong><span>, adding AI-specific health and safety requirements under the Machinery Regulation. If your AI sits inside machinery you are not waiting for a later deadline, you are waiting for a different instrument, and it has a date.</span></p><p><em>Article 5 gained two prohibitions.</em><span> AI systems that generate or manipulate child sexual abuse material, and systems that generate or manipulate non-consensual intimate imagery. Compliance by </span><strong>December 2, 2026</strong><span>. Read it as covering purpose-built tools and you will conclude it is not about you. It also catches systems where such output is a reasonably foreseeable and reproducible outcome and the provider has not implemented reasonable and adequate safety measures. That part reaches general-purpose image, video and audio generators without safeguards, which is why the recitals discuss training-data filtering, refusal training, and input and output classifiers.</span></p><p><em>Article 4 was softened.</em> The duty moved from ensuring a &#8220;sufficient level&#8221; of AI literacy to taking measures that support it. An obligation of effort rather than result.</p><p><em>Article 50(2) watermarking.</em> Not a blanket move to December. Systems already on the market before August 2, 2026 get a grace period to December 2, 2026. Anything placed on the market from August 2 onwards marks its output from day one.</p><p><a href="https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng">Digital Omnibus on AI</a> &#183; <a href="https://ailawdecoded.com/p/eu-ai-act-amended-the-digital-omnibus">My article on the omnibus</a> </p></div><div><hr></div><div class="callout-block" data-callout="true"><h4><span data-color="#077d9a" style="color: rgb(7, 125, 154);">July 20, 2026: <br></span>Final guidelines on Article 50 transparency<br></h4><p><strong>What happened.</strong> The Commission adopted the final text, replacing the May draft. </p><p><strong>What changed.</strong> The editorial-control exemption in Article 50(4) has a defined shape: human review or editorial control, <strong>and</strong> a person holding editorial responsibility. Both, not either. The artistic and satirical carve-outs are read narrowly, and content that is purely informative or commercial cannot use them.</p><p><a href="https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems">Commission guidelines</a></p></div><div><hr></div><div class="callout-block" data-callout="true"><h4><span data-color="#077d9a" style="color: rgb(7, 125, 154);">June 10, 2026:</span><br>Code of Practice on Transparency of AI-Generated Content</h4><p><strong>What happened.</strong> The AI Office released the final Code, following a first draft in February 2026. It covers providers and deployers subject to Article 50(2) and Article 50(4), including anyone whose system generates synthetic audio, image, video or text.</p><p><strong>What changed.</strong> Signing is a route to demonstrating Article 50 compliance without arguing from first principles. Not signing is permitted, but you then show equivalent measures yourself.</p><p>It acquired legal weight a month later. On July 8, 2026 the Commission concluded that the Code adequately covers Articles 50(2), (4) and (5); on July 9 the AI Board adopted its own adequacy assessment, both published July 9. The Commission attached a limit worth quoting: adherence <em>&#8220;does not constitute conclusive evidence of compliance.&#8221;</em> <a href="https://digital-strategy.ec.europa.eu/en/library/commission-opinion-assessment-code-practice-transparency-ai-generated-content">Commission Opinion</a></p><p><strong>The initial signatory list.</strong> The deadline to be listed was July 27, 2026, 18:00 CEST. Around 190 organizations had signed by the end of July, roughly half of them small and recent companies. Among the providers: Anthropic, Google, Meta, Microsoft, Mistral, OpenAI, Aleph Alpha, Black Forest Labs, Cohere and Synthesia. Among the deployers: Getty Images, Lenovo, Lufthansa, Bulgari, Fastweb and Iberdrola.</p><p>The list is updated on an ongoing basis, so this is a snapshot rather than a closed set.</p><p><a href="https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content">Code of Practice</a> &#183; <a href="https://digital-strategy.ec.europa.eu/en/library/how-sign-code-practice-transparency-ai-generated-content">How to sign</a> &#183; <a href="https://digital-strategy.ec.europa.eu/en/faqs/signing-code-practice-transparency-ai-generated-content">Commission FAQ on signing</a></p></div><div><hr></div><div class="callout-block" data-callout="true"><h4><span data-color="#077d9a" style="color: rgb(7, 125, 154);">May 19, 2026:</span> <br>First draft guidance on high-risk classification<br></h4><p><strong>What happened.</strong> The Commission published a first draft of its guidance on classifying high-risk AI systems, owed under Article 6(5).</p><p><strong>What changed.</strong> Draft status, so nothing binding. It is the first official signal on where the Article 6(3) filter conditions apply, which is the provision most companies rely on to argue they are not high-risk. Consultation closed July 23, 2026 and the final version is expected before the end of the year. It was statutorily due on February 2, 2026.</p><p><a href="https://ailawdecoded.com/p/is-my-ai-system-high-risk-eu-ai-act">My article on high-risk AI systems</a> &#183; <a href="https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems">Draft Commission guidelines</a></p></div><div><hr></div><div class="callout-block" data-callout="true"><h4><span data-color="#077d9a" style="color: rgb(7, 125, 154);">October 6, 2025: <br></span>The AI Liability Directive is withdrawn<br></h4><p><strong>What happened.</strong> The withdrawal notice was published in the Official Journal. No replacement announced. The ePrivacy Regulation went the same way.</p><p><strong>What changed.</strong> The AI Act sets conduct rules. The AI Liability Directive would have set liability rules, shifting the burden of proof and forcing disclosure of documentation so a claimant could build a case. That second layer no longer exists, so liability falls back on national law and the Product Liability Directive.</p><p>This matters because bans, safety duties and who-pays are routinely attributed to &#8220;the EU AI law&#8221; as though it were one instrument.</p><p><a href="https://ailawdecoded.com/p/eu-ai-act-history">My article on history of AI regulation</a></p></div><div><hr></div><div class="callout-block" data-callout="true"><h4><span data-color="#077d9a" style="color: rgb(7, 125, 154);">September 26, 2025:</span> <br>Draft guidance and template on serious incident reporting<br></h4><p><strong>What happened.</strong> The Commission published draft guidance and a reporting template under Article 73.</p><p><strong>What changed.</strong> Providers of high-risk systems have a form and a draft methodology. What they do not have is a final version, and none has been announced. The guidance was originally expected on August 2, 2025.</p><p><a href="https://digital-strategy.ec.europa.eu/en/consultations/ai-act-commission-issues-draft-guidance-and-reporting-template-serious-ai-incidents-and-seeks">Draft Commission guidelines</a></p></div><div><hr></div><div class="callout-block" data-callout="true"><h4><span data-color="#077d9a" style="color: rgb(7, 125, 154);">August 2, 2025: <br></span>GPAI obligations apply, and the penalties regime<br></h4><p><strong>What happened.</strong> Chapter V became applicable for general-purpose AI model providers, alongside the governance framework provisions. Chapter XII on penalties also applied from this date, so Article 5 infringements became finable, subject to each Member State having laid down and notified its penalty rules. Many had not. It was also the deadline for Member States to designate their national competent authorities.</p><p>Note the distinction, because it is easy to blur: penalties became available in August 2025, the market surveillance machinery in Chapter IX arrives in August 2026.</p><p><strong>What changed.</strong> If you fine-tune a model past the threshold and become a model provider, those obligations attached a year ago, not in 2027. Models placed on the market before this date have until August 2, 2027 under Article 111(3).</p><p><a href="https://ailawdecoded.com/p/rag-fine-tuning-eu-ai-act">My article on wrapping vs. fine-tuning</a></p></div><div><hr></div><div class="callout-block" data-callout="true"><h4><span data-color="#077d9a" style="color: rgb(7, 125, 154);">July 24, 2025: <br></span>Template for GPAI training content summaries<br></h4><p><strong>What happened.</strong> The Commission published the template GPAI providers use to summarize what their model was trained on.</p><p><strong>What changed.</strong> The Article 53(1)(d) obligation stopped being abstract. If you become a model provider through fine-tuning, this is the form you fill in, and Recital 109 limits it to what you added rather than the whole base model.</p><p><a href="https://digital-strategy.ec.europa.eu/en/library/explanatory-notice-and-template-public-summary-training-content-general-purpose-ai-models">Commission Template</a></p></div><div><hr></div><div class="callout-block" data-callout="true"><h4><span data-color="#077d9a" style="color: rgb(7, 125, 154);">July 18, 2025:</span> <br>Guidelines for providers of general-purpose AI models<br></h4><p><strong>What happened.</strong> Guidelines published on the scope of Chapter V obligations.</p><p><strong>What changed.</strong> These contain the compute figure people use to work out when fine-tuning turns you into a model provider. The guidelines present it as an indicative criterion rather than a test: one third of the compute used to train the original model. Where that is unknown, the fallback is one third of 10&#178;&#179; FLOP for models without systemic risk, and one third of 10&#178;&#8309; FLOP for models with it.</p><p>The underlying legal question stays the same, and it is not arithmetic: whether your modification significantly changes the model&#8217;s generality, capabilities or systemic risk.</p><p>That number appears nowhere in the AI Act. Reading the regulation cover to cover will never surface it.</p><p><a href="https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers">Commission guidelines</a> &#183; <a href="https://ailawdecoded.com/p/rag-fine-tuning-eu-ai-act">My article on wrapping vs. fine-tuning</a></p></div><div><hr></div><div class="callout-block" data-callout="true"><h4><span data-color="#077d9a" style="color: rgb(7, 125, 154);">July 10, 2025:</span><br>The General-Purpose AI Code of Practice is published<br></h4><p><strong>What happened.</strong> The Commission published the voluntary code for providers of general-purpose AI models. On August 1, 2025 the Commission, the AI Board and the Member States confirmed it as an adequate tool, and the list of signatories went public the same day, one day before the GPAI obligations applied.</p><p><strong>What changed.</strong> Signing became the practical route to demonstrating compliance with Chapter V. It remains voluntary, and a non-signatory has to show equivalent measures by another means. If fine-tuning ever tips you into being a model provider, this is the instrument you are measured against.</p><p><a href="https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai">The GPAI Code of Practice</a></p></div><div><hr></div><div class="callout-block" data-callout="true"><h4><span data-color="#077d9a" style="color: rgb(7, 125, 154);">February 6, 2025:</span> <br>Guidelines on the definition of an AI system<br></h4><p><strong>What happened.</strong> The Commission published guidelines interpreting Article 3(1).</p><p><strong>What changed.</strong> The threshold question. Whether the thing your team built is an AI system at all decides whether any of the rest applies, and a great deal of ordinary software sits close to the line. An update was expected in May 2026 and has not been published.</p><p><a href="https://ailawdecoded.com/p/ai-system-definition-eu-ai-act">My article on what counts as an AI system</a> &#183; <a href="https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application">Commission guidelines</a></p></div><div><hr></div><div class="callout-block" data-callout="true"><h4><span data-color="#077d9a" style="color: rgb(7, 125, 154);">February 4, 2025:</span> <br>Guidelines on prohibited practices<br></h4><p><strong>What happened.</strong> Guidelines published two days after the prohibitions took effect. </p><p><strong>What changed.</strong> They interpret Article 5 rather than extend it. Useful because the prohibitions are drafted in language that sounds absolute and turns out to carry conditions.</p><p><a href="https://ailawdecoded.com/p/prohibited-ai-practices-eu-ai-act">My article on prohibited practices</a> &#183; <a href="https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act">Commission guidelines</a></p></div><div><hr></div><div class="callout-block" data-callout="true"><h4><span data-color="#077d9a" style="color: rgb(7, 125, 154);">February 2, 2025:</span> <br>The prohibitions and the AI literacy duty apply<br></h4><p><strong>What happened.</strong> Article 5 and Article 4 became applicable, the first provisions of the AI Act to apply.</p><p><strong>What changed.</strong> Both have been live for eighteen months. Article 4 covers every provider and deployer regardless of risk level. No certificate is required, documented measures are.</p><p><em>Superseded in part.</em> The omnibus softened Article 4 in July 2026 and added two prohibitions to Article 5. See the July 27, 2026 entry.</p><p><a href="https://ailawdecoded.com/p/ai-literacy-obligation-eu-ai-act">My article on AI literacy</a> &#183; <a href="https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers">Commission Q&amp;A on AI Literacy</a></p></div><div><hr></div><h4>Still in draft</h4><p>Two documents on this page are not final. Do not build a position on either without saying so.</p><p><strong>Serious incident reporting, Article 73.</strong> Draft and template published September 26, 2025. No final version, no announced date. Originally expected August 2, 2025.</p><p><strong>High-risk classification, Article 6(5).</strong> Draft published May 19, 2026, consultation closed July 23, 2026, final expected before the end of the year. </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h4>Dates ahead</h4><p>After August 2, 2026, these are the following obligations that we can expect:</p><p><strong>December 2, 2026</strong>. New Article 5 prohibitions take effect: AI systems that generate or manipulate child sexual abuse material, and systems that generate or manipulate non-consensual intimate imagery. Added by the omnibus.</p><p><strong>December 2, 2026</strong>. Article 50(2) watermarking, for systems placed on the market before August 2, 2026. Anything launched from August 2 marks from day one, so this date only helps systems that already existed.</p><p><strong>End of 2026</strong>. Final guidance on high-risk classification under Article 6(5) expected. It was statutorily due on February 2, 2026.</p><p><strong>August 2, 2027</strong>. GPAI models placed on the market before August 2, 2025 must comply. Article 111(3).</p><p><strong>December 2, 2027</strong>. Annex III standalone high-risk obligations apply. Moved from August 2, 2026.</p><p><strong>August 2, 2028</strong>. Annex I embedded high-risk obligations apply. Moved from August 2, 2027. Machinery Regulation products were excluded from the high-risk regime altogether and handed to delegated acts, so they are not on this clock at all.</p><p><strong>August 2, 2030</strong>. Legacy high-risk systems operated by public authorities. </p><p>For the fuller forward view, including procedural milestones, the Future of Life Institute&#8217;s <a href="https://artificialintelligenceact.eu/implementation-timeline/">implementation timeline</a> is more detailed than anything worth duplicating here.</p><div><hr></div><p><em>Something changed and it is not here? Email me: <a href="mailto:silvia@ailawdecoded.com">silvia@ailawdecoded.com</a></em></p><div><hr></div><p><strong><a href="https://ailawdecoded.com/p/scope"><span data-color="#077d9a" style="color: rgb(7, 125, 154);">Scope</span></a><span data-color="#077d9a" style="color: rgb(7, 125, 154);"> is where this becomes something you can use in a meeting: the regulation map, the role assignment, the vendor questions, the AI inventory spreadsheet, the AI policy template, with sources attached and kept current as the law changes.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[AI Has to Say It's AI Now]]></title><description><![CDATA[Chatbots, AI content, and deepfakes you wouldn't call deepfakes. Applies August 2.]]></description><link>https://ailawdecoded.com/p/eu-ai-act-article-50-transparency</link><guid isPermaLink="false">https://ailawdecoded.com/p/eu-ai-act-article-50-transparency</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 29 Jul 2026 12:00:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!We5V!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b677b2-35e9-4947-84e5-2d905c414fba_7680x4320.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!We5V!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b677b2-35e9-4947-84e5-2d905c414fba_7680x4320.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!We5V!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b677b2-35e9-4947-84e5-2d905c414fba_7680x4320.jpeg 424w, https://substackcdn.com/image/fetch/$s_!We5V!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b677b2-35e9-4947-84e5-2d905c414fba_7680x4320.jpeg 848w, https://substackcdn.com/image/fetch/$s_!We5V!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b677b2-35e9-4947-84e5-2d905c414fba_7680x4320.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!We5V!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b677b2-35e9-4947-84e5-2d905c414fba_7680x4320.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!We5V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b677b2-35e9-4947-84e5-2d905c414fba_7680x4320.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/01b677b2-35e9-4947-84e5-2d905c414fba_7680x4320.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:342898,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.com/i/208463778?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b677b2-35e9-4947-84e5-2d905c414fba_7680x4320.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!We5V!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b677b2-35e9-4947-84e5-2d905c414fba_7680x4320.jpeg 424w, https://substackcdn.com/image/fetch/$s_!We5V!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b677b2-35e9-4947-84e5-2d905c414fba_7680x4320.jpeg 848w, https://substackcdn.com/image/fetch/$s_!We5V!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b677b2-35e9-4947-84e5-2d905c414fba_7680x4320.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!We5V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b677b2-35e9-4947-84e5-2d905c414fba_7680x4320.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>When the Omnibus on AI deal landed in May, it read as relief. High-risk obligations for <a href="https://artificialintelligenceact.eu/annex/3/">Annex III</a> systems: pushed to December 2027. AI embedded in the regulated products listed in <a href="https://artificialintelligenceact.eu/annex/1/">Annex I</a>: August 2028. If the AI Act sits in your portfolio, next to everything else that does, you probably made the reasonable mental note. <em>Revisit next year.</em></p><p>The note is wrong by one chapter.</p><p><a href="https://artificialintelligenceact.eu/article/50/">Article 50</a>, the transparency rules, did not move. It applies from August 2, 2026. This Sunday. And on July 20, less than two weeks before the deadline, the European Commission published its final <a href="https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems">guidelines on how to comply</a>. Thirteen days of runway. Brussels&#8217; idea of a running start.</p><p>The timing is inconvenient. But I would say that the substance matters more. Article 50 reaches more companies than the high-risk chapter ever will. The high-risk rules catch CV-screening tools and credit scoring. Article 50 catches the chatbot on your website, the AI-generated visuals in your marketing, and the product descriptions your content team stopped writing by hand more than a year ago.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;993cb3ce-51f1-4c2f-80e0-1e6e099417ce&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;EU AI Act Amended: The Digital Omnibus Timeline&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-13T12:02:43.130Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!DR18!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/eu-ai-act-amended-the-digital-omnibus&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:196926473,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:3,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>What Article 50 Is</h2><p>The AI Act sorts systems by risk: prohibited, high-risk, transparency-risk, minimal. Article 50 is the third box. It also stacks on the second, because Article 50(6) says the transparency duties do not affect the <a href="https://artificialintelligenceact.eu/chapter/3/">Chapter III</a> requirements for high-risk systems. So there is no &#8220;we&#8217;re not high-risk, so we&#8217;re fine,&#8221; and no &#8220;we&#8217;re already doing the high-risk work, so this is covered.&#8221; Article 50 applies to any AI system used in four specific situations, whatever else is true about it.</p><p><strong>The four situations:</strong></p><ol><li><p>An AI system interacts directly with people (chatbots, voice assistants, AI agents)</p></li><li><p>An AI system generates synthetic content (text, images, audio, video)</p></li><li><p>An AI system runs emotion recognition or biometric categorisation on people</p></li><li><p>AI-generated content gets published: deepfakes, or text informing the public on matters of public interest</p></li></ol><p>Breach the transparency rules and the ceiling is &#8364;15 million or 3% of worldwide annual turnover, whichever is higher (<a href="https://artificialintelligenceact.eu/article/99/">Article 99(4)(g)</a>). For SMEs and start-ups the calculation flips to whichever is lower, and the European Commission&#8217;s guidance now extends that proportionality to small mid-cap companies as well. Not the &#8364;35 million tier reserved for prohibited practices. Still not a rounding error.</p><p>Two of the four obligations belong to providers, the companies that build the systems. Two belong to deployers, the companies that use them. You may be both. A company that builds a customer-facing bot on top of a foundation model and also publishes AI-generated content holds obligations on both sides.</p><p>One carve-out runs through all four: systems authorised by law to detect, prevent, investigate or prosecute criminal offences are excepted, with conditions. If you are not in law enforcement, it will not help you.</p><div><hr></div><h2>The Provider Duties (Systems That Talk or Generate)</h2><p>If you provide an AI system that interacts with people, Article 50(1) requires it to be designed so that people know they are talking to AI. From the start of the first interaction. Clear, distinguishable, accessible.</p><p>There is an exception where this is obvious. The guidelines then spend considerable effort narrowing what counts as obvious: </p><blockquote><p><em>the test is a reasonably well-informed, observant and circumspect person, judged against your actual audience, </em></p></blockquote><p>And the Commission says to read the exception restrictively. A widget labelled <em>&#8220;Assistant&#8221;</em> is not disclosure. And the obligation protects natural persons, <strong>not just consumers</strong>: the Commission reads it to cover consumers, professionals and other users alike, which is why the internal HR bot your employees use counts too.</p><p>One detail for anyone building agents. The guidelines confirm AI agents fall under Article 50(1), and where a provider cannot reliably predict whether the agent will end up interacting with a human, it should be designed to disclose its AI nature in all situations where such interaction is reasonably foreseeable. The agent has to introduce itself. Few of the agent demos circulating are designed for this.</p><p>If you provide a system that generates synthetic content, Article 50(2) requires the outputs to be marked in a machine-readable format and detectable as AI-generated. This is the watermarking obligation: metadata, watermarks, provenance signals. Article 50(2) asks for solutions that are effective, interoperable, robust and reliable, so far as technically feasible. The <a href="https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content">Code of Practice</a> published in June prescribes no single technique, and the reason is not hard to see: no marking method available today satisfies all four criteria on its own. Expect to layer them.</p><p>The exemptions are worth reading before you panic-procure a watermarking vendor. Standard editing assistance is out: spell-check, grammar, quality improvements, anything that does not substantially alter the data or its meaning. So are short sequences of numbers or letters, source code, and outputs that never reach a human. Content that stays inside closed industrial pipelines is out too, with a condition: the exemption falls away for the final output. The AI-generated asset that actually ships is not covered. The guidelines also include a narrow exemption for certain business-to-business and industrial contexts. Open-source systems, for the record, are not exempt.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;d7d2d2e4-7d47-49e8-8749-8776e28b8f14&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Provider vs. Deployer Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-22T12:03:43.719Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!NS5L!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35f75bb-44f2-45d4-b53c-84654d8e8617_8192x5461.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/provider-vs-deployer-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:194314202,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:5,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>The Deployer Duties: Where You Might Come In</h2><p>Most readers of this newsletter are not building foundation models. You are using AI systems under your own authority, professionally. That probably makes you a deployer, and two obligations are yours.</p><p>If you deploy emotion recognition or biometric categorization, Article 50(3)<strong> requires you to inform the people exposed to it</strong>. Sentiment analysis in the call centre, demographic categorisation in retail analytics. Real-time or after the fact, both count. But screen against <a href="https://artificialintelligenceact.eu/article/5/">Article 5</a> first: inferring emotions in the workplace or in education institutions is prohibited outright, save for narrow medical and safety purposes. Where the ban applies, it is not a disclosure question at all.</p><p>If you use AI to create deepfakes, Article 50(4) <strong>requires you to disclose that the content is artificially generated or manipulated</strong>. Visibly. At first exposure. And this is where the definitions deserve your attention, because the word <em>&#8220;deepfake&#8221;</em> suggests malice, and the definition does not require any.</p><p>A <strong>deepfake</strong> under <a href="https://artificialintelligenceact.eu/article/3/">Article 3(60)</a> is </p><blockquote><p><em>AI-generated or manipulated image, audio or video that resembles existing persons, objects, places, entities or events, and would falsely appear authentic. </em></p></blockquote><p>Three criteria: <strong>resemblance</strong>, <strong>something that exists</strong> or plausibly could, and the <strong>capacity to mislead about authenticity</strong>. Dragons are out. Talking animals are out. Standard film production, color correction, noise reduction: out.</p><p>An authentic photo of an empty apartment, furnished by AI for the listing: in. That example is not mine. It appears in the Commission&#8217;s own <a href="https://digital-strategy.ec.europa.eu/en/policies/eu-icons-labelling-ai-generated-content">labelling guidance</a>, as a case for the &#8220;<em>partially AI-modified&#8221;</em> label. Product visuals, staged scenes, AI photography of real places. Your marketing department has deepfake obligations. It has probably not been told.</p><p><strong>The second half of Article 50(4) covers text. </strong></p><p>Publish AI-generated text with the purpose of informing the public on matters of public interest, and you must disclose it. The public-interest list is long. Politics and democratic processes, public administration and services, justice and law enforcement, fundamental rights, public security, public health, environmental protection, consumer safety, plus economic, financial, scientific and cultural developments that may be relevant to public debate. A fair amount of corporate publishing brushes against that.</p><p>Most corporate text will escape through the exemption: <strong>no label needed where the text underwent human review or editorial control</strong>, and a person holds editorial responsibility for it. Read the definitions before you rely on them. </p><p><strong>Human review</strong><em><strong> </strong></em>means deliberate examination of the substance by someone with relevant knowledge and professional judgement. </p><p><strong>Editorial control</strong> means the authority to approve, alter or reject the content on substantive grounds, fact-checking included. </p><p>And <strong>editorial responsibility</strong>, per the European Commission, means someone holds the ultimate legal responsibility for the publication. A spell-check pass is none of the three. If your workflow is &#8220;AI drafts it, someone skims it, it ships,&#8221; you have a choice: make the review real and documented, with a name attached, or add the label.</p><div><hr></div><h2>The Watermark Is Not the Label</h2><p>Your AI vendor markets its compliance. The model watermarks its outputs, embeds provenance metadata, signs the Code of Practice. You might conclude that content generated with a compliant tool is compliant content.</p><p>The two obligations are two layers, and only one of them is the vendor&#8217;s.</p><p>The <strong>machine-readable mark</strong> under Article 50(2) is the provider&#8217;s job: invisible, embedded, readable by detection tools. Y</p><p>our disclosure duty under Article 50(4) is a separate, visible layer: <strong>a label</strong> a person can see or hear without any tool at all. </p><p>The Commission&#8217;s <a href="https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act">Q&amp;A</a> says it plainly: deployers cannot simply rely on the machine-readable marking embedded by the provider to fulfill their disclosure obligation.</p><p>The provider marks. You label. A compliant tool does not make your published deepfake compliant. It just means the invisible half was done by someone else.</p><div><hr></div><h2>How to Label, Practically</h2><p>The EU published a set of <a href="https://digital-strategy.ec.europa.eu/en/policies/eu-icons-labelling-ai-generated-content">official icons</a> in June. Three of them: </p><ul><li><p>a basic <strong>&#8220;AI&#8221;</strong> icon, </p></li><li><p>one for fully <strong>AI-generated</strong> content, </p></li><li><p>one for partially <strong>AI-modified</strong> content. </p></li></ul><p>They are free to download (SVG and PNG), free to use, no attribution required.</p><p>The placement rules, from the Code of Practice: perceivable at first exposure, not hidden behind overlays, embedded directly into the content (creative works get more flexibility), and still visible when the content is reshared or downloaded. </p><p>The Commission user-tested the icons and found they perform better with a text label attached, <em>&#8220;modified&#8221;</em> or similar. The icon that needs a caption to work.</p><p>Two things to hold apart: the icons are optional, the labelling is not. The Commission says so itself, so downloading the icon set does not close the file. Using these icons does not establish legal compliance by itself. It is the same trap as the watermark, one layer up.</p><p>You can use your own disclosure format if it is clear, distinguishable and accessible. What I think will not survive that test: a small line in the website footer, a faint watermark on an image, a label that flashes for a frame, anything buried in the terms and conditions.</p><p>For artistic, creative, satirical or fictional work, the obligation softens: disclose the manipulation exists, in a way that does not hamper the display or enjoyment of the work. A credits-style disclosure rather than a stamp across the screen.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>The Dates</h2><p>August 2, 2026: everything above applies. Chatbot disclosure, emotion-recognition notice, deepfake and text labelling, and the marking obligation for systems placed on the market from that date.</p><p>There is no exception under Article 50. The transitional regime in <a href="https://artificialintelligenceact.eu/article/111/">Article 111</a>, the one that lets certain legacy high-risk systems stay outside the AI Act unless they are significantly changed, has no equivalent here. A chatbot you launched in 2023 is in scope on Sunday. So is the generative tool your team has been using since last spring. One exception, and it is narrow.</p><p>December 2, 2026: Providers of generative systems already on the market before August 2 get four extra months, for the machine-readable marking obligation only. Nothing else is deferred, and no deployer obligation is deferred at all.</p><p><span>The four months come from the </span><a href="https://eur-lex.europa.eu/eli/reg/2026/1744/oj">Omnibus on AI</a><span>, published in the Official Journal on July 24 and in force three days later. Five days before the deadline it modifies. Confirm the publication date yourself before you rely on it, because it landed the same week this article went out.</span></p><p>Content generated before August 2 does not need retroactive labels. The Commission encourages them anyway.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;7711c21b-fae5-463d-9e5c-201cf786c772&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The EU AI Act's Loophole With No Expiry Date&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-07-01T12:03:23.945Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!3JZC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab285665-697f-4608-ad90-6c5cb0e6b5ae_5760x3240.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/eu-ai-act-article-111-loophole-legacy-high-risk-ai&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:202097019,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:2,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>What to Do This Week</h2><p>If you are wondering what to do now, there are five moves needed:</p><ol><li><p><strong>Inventory the four situations.</strong> One page: where do we have systems talking to people, systems generating content, emotion recognition, published AI content? You cannot label what you have not listed.</p></li><li><p><strong>Fix the chatbot disclosure.</strong> The cheapest obligation on the list: a clear line at the start of the first interaction. Include the internal bots.</p></li><li><p><strong>Audit published content against the deepfake definition.</strong> Not &#8220;do we make deepfakes&#8221; but &#8220;do our visuals depict real or plausible people, places or products in a way that looks authentic.&#8221; Start with marketing, where most of the exposure sits.</p></li><li><p><strong>Decide your text position. </strong>For anything AI-written that informs the public: real, documented human review with named responsibility, or a label. Pick one per content stream and write it down.</p></li><li><p><strong>Ask your vendors two questions.</strong> Do your systems mark outputs in machine-readable format, and can we detect it? Their answer covers their layer. Then set up yours.</p></li></ol><div><hr></div><h2>What Sits Underneath</h2><p>Enforcement mostly belongs to national market surveillance authorities, and they are behind. The designation deadline was August 2025. As of June, nine member states had designated both their market surveillance and notifying authorities. National penalty laws are similarly unfinished. The enforcers are not missing so much as untested and unevenly resourced, since most member states are handing AI competence to regulators that already exist and already have full desks.</p><p>Two reasons not to treat that as breathing room.</p><p>The AI Office is not behind. It is competent for AI systems built on general-purpose AI models where the same entity provides both, and for systems integrated into the very large platforms designated under the <a href="https://eur-lex.europa.eu/eli/reg/2022/2065/oj">Digital Services Act</a>. The Omnibus on AI widened its remit further. If your chatbot sits on a foundation model from the company that also built the model, your enforcer is in Brussels, fully staffed.</p><p>And Article 50 breaches are the most visible violations in the entire AI Act. A missing chatbot disclosure, an unlabelled AI visual: public, permanent, screenshot-able by any competitor, journalist or future regulator with a scrolling habit. The <a href="https://eur-lex.europa.eu/eli/dir/2005/29/oj">Unfair Commercial Practices Directive (2005/29/EC)</a> already reaches deceptive content today, enforced by consumer authorities that very much exist.</p><p>The transparency rules arrive Sunday. Some of the enforcers are still being appointed.</p><p>Your audience is already here.</p><div><hr></div><p><strong><a href="https://ailawdecoded.com/p/scope"><span data-color="#077d9a" style="color: rgb(7, 125, 154);">Scope</span></a><span data-color="#077d9a" style="color: rgb(7, 125, 154);"> is where this becomes something you can use in a meeting: the regulation map, the role assignment, the vendor questions, the AI inventory spreadsheet, the AI policy template, with sources attached and kept current as the law changes.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[Your Colleague Built an Agent]]></title><description><![CDATA[An employee builds an MS Copilot agent, then shares it with the whole company. Where the EU AI Act comes in.]]></description><link>https://ailawdecoded.com/p/employee-copilot-agents-eu-ai-act</link><guid isPermaLink="false">https://ailawdecoded.com/p/employee-copilot-agents-eu-ai-act</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 22 Jul 2026 20:25:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!uAh2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e55e258-8578-4dc8-9e69-b560f9cbcf05_6000x4000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uAh2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e55e258-8578-4dc8-9e69-b560f9cbcf05_6000x4000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uAh2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e55e258-8578-4dc8-9e69-b560f9cbcf05_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!uAh2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e55e258-8578-4dc8-9e69-b560f9cbcf05_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!uAh2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e55e258-8578-4dc8-9e69-b560f9cbcf05_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!uAh2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e55e258-8578-4dc8-9e69-b560f9cbcf05_6000x4000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uAh2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e55e258-8578-4dc8-9e69-b560f9cbcf05_6000x4000.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0e55e258-8578-4dc8-9e69-b560f9cbcf05_6000x4000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:547820,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.com/i/207818109?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e55e258-8578-4dc8-9e69-b560f9cbcf05_6000x4000.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uAh2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e55e258-8578-4dc8-9e69-b560f9cbcf05_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!uAh2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e55e258-8578-4dc8-9e69-b560f9cbcf05_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!uAh2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e55e258-8578-4dc8-9e69-b560f9cbcf05_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!uAh2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e55e258-8578-4dc8-9e69-b560f9cbcf05_6000x4000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>An employee builds an MS Copilot agent for their own work. It drafts proposals in the company template, pulls pricing from the right SharePoint folder, and saves them an hour a day. After three weeks, they share it with the team. A month later, it&#8217;s in an all-staff email with a link.</p><p>Somewhere in that sequence, the company acquired obligations under the EU AI Act. The intuitive answer for where: at the sharing. Private use was the employee&#8217;s own business. Distribution made it the company&#8217;s.</p><p>That answer reads the regulation backwards.</p><p>The obligations attached in week one, before anyone else knew the agent existed. Sharing changed something, just not that. The gap between those two answers decides whether a company governs employee-built AI or merely finds out about it.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>The Personal Use Exemption Covers Your Holiday, Not Your Job</h2><p>The AI Act defines a deployer in <a href="https://artificialintelligenceact.eu/article/3/">Article 3(4)</a>:</p><blockquote><p><em>a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity</em></p></blockquote><p><em>&#8220;Personal non-professional activity&#8221;</em> is quite narrow actually. <a href="https://artificialintelligenceact.eu/article/2/">Article 2(10)</a> adds the word <em>&#8220;purely&#8221;</em>: the AI Act does not apply to deployers who are natural persons using AI in the course of a purely personal non-professional activity. Asking Copilot where to go in September: covered. Building an agent that drafts your weekly reports: professional, however few people know about it. The exemption follows the activity, not the account.</p><p>And the deployer of that professional use is the company, not the employee: the agent runs in the company&#8217;s tenant, on a company license, for company work, which is use <em>&#8220;under its authority&#8221;</em> on any serious reading, and Article 3(4) asks nothing about whether the company knew. (No regulator has ruled on an employee-built agent yet. This is interpretation, the mainstream one, and mine.) So the company was a deployer of that agent for three weeks without knowing it existed.</p><p>If a compliance training taught you that the company only becomes a deployer at sharing, the rule has a real source. For tools a company never provided and merely tolerates (an employee&#8217;s private ChatGPT account in a browser), there is a serious argument that the employer lacks authority over the use. Lawyers split on that case.</p><p>An agent built inside the company&#8217;s own Copilot is not that case. The company licensed the platform, enabled the feature, and controls the tenant. Article 4 makes the same assumption: before and after the omnibus softened it, the AI literacy provision is addressed to providers and deployers for the people using AI systems on their behalf. Staff using AI for work is the deployer&#8217;s use. A legal person has no other way to use anything.</p><div><hr></div><h2>What Sharing Changed</h2><p>Legally, almost nothing. Practically, two things moved.</p><p><strong>Scale.</strong> One person relying on an agent is an anecdote. A company relying on it is a dependency, with the error surface to match. If the pricing sheet it reads is stale, that&#8217;s now every proposal it touches.</p><p><strong>Deniability. </strong>Before the email, the company&#8217;s gap was factual: no inventory, no awareness. After the email, the use is announced, organization-wide, in writing. Whatever duties exist are now duties the company visibly isn&#8217;t performing.</p><p>Which leaves the question with actual money on it. The company deploys a Copilot agent, fine. When does it become the deployer of that particular agent, and what extra obligations arrive when it does? Take a harmless one: an agent that walks employees through submitting business-trip reports, shared with the whole company.</p><p>There are two layers here. If the agent counts as nothing more than a configuration of Copilot, there is no separate deployer question: the company was deploying Copilot all along, and the agent is one way of using it. If the agent counts as its own AI system (an open question, below), the deployer analysis repeats: first use for work under company authority, so the company was the agent&#8217;s deployer while its creator was still its only user. Under neither reading is sharing the moment deployer status begins.</p><p>What sharing plausibly triggers is a different concept. The AI Act defines <a href="https://artificialintelligenceact.eu/article/3/">putting into service</a> as supplying an AI system for first use <em>&#8220;directly to the deployer or for own use.&#8221;</em> An agent distributed org-wide starts to look like a system the company put into service for its own use. And whoever develops an AI system and puts it into service is its provider, the role with the heavy obligations. Follow that logic to its end and the company is the provider of this particular agent: it developed the system (through its employee) and rolled it out for its own use.</p><p>Two conditions stand between that sentence and settled law: whether the agent is an AI system in its own right at all, and whether an internal rollout happens <em>&#8220;under its own name or trademark,&#8221;</em> as the provider definition in Article 3(3) requires. Both are unresolved, and for the trip-report agent, comfortably little turns on them. Under the AI Act, obligations scale with risk class, not with the number of systems on your list, and provider of a minimal-risk system is a nearly empty role.</p><p>A benign agent adds almost nothing to what the Copilot rollout already required: literacy, transparency where output leaves an informed audience, prohibited-practice hygiene. What it adds is one unavoidable task: someone has to look at its purpose and classify it. Everything heavier waits on that.</p><p>One thing the email did not do: internal sharing is not <em>&#8220;placing on the market&#8221;. </em>Making available on the market means supply in the course of commercial activity. Colleagues are not a market. The comfort is narrower than it looks, though. Market supply is not the only route to the heavy provider obligations: for a high-risk agent, putting into service for the company&#8217;s own use is enough. What stays internal stays light only while the purpose does.</p><div><hr></div><h2>Microsoft Ships the Gate Open</h2><p>The product mechanics deserve a closer look, because two default settings decide more than most written AI policies do.</p><p>A new Copilot agent is private. <a href="https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/agent-builder-share-manage-agents">Microsoft&#8217;s documentation</a> gives its creator three options: keep it private, share it with specific people or groups, or share it with anyone in the organization via link. Whether employees can use that third option is an admin setting. Its default value: all users may share org-wide.</p><p>Unless your admin changed a setting, every licensed employee can distribute an AI agent to your entire company. No approval step. That all-staff email needed no one&#8217;s permission.</p><p>Microsoft&#8217;s documentation also states that changes to the sharing controls apply only to new sharing actions: existing shared agents remain accessible. Tighten your policy next quarter and every agent shared before the change stays in circulation. </p><p>There is also an approval gate. Agents submitted to the organizational catalog go through admin review before they appear in the company&#8217;s agent store. The gate exists. The sharing link walks around it.</p><p>Two more details for whoever owns offboarding. Only an agent&#8217;s creator can delete it, though admins can <a href="https://learn.microsoft.com/en-us/microsoft-365/admin/manage/agent-registry">reassign ownership</a> if they know the agent exists. And nothing in the sharing flow retires an agent when its creator leaves: it keeps answering questions from a knowledge base nobody is updating.</p><p>None of this is a criticism of Microsoft, and roughly the same story applies to custom GPTs, Gemini Gems, and every other build-your-own-assistant feature: the vendor optimizes for adoption, the defaults follow. But an AI Act compliance program that audits policies and never audits tenant settings is auditing the wrong document. </p><div><hr></div><h2>Purpose Is Where It Turns</h2><p>Everything so far is manageable. The modest obligations that travel with any minimal-risk agent: AI literacy under <a href="https://artificialintelligenceact.eu/article/4/">Article 4</a>, applicable since February 2, 2025, though the omnibus softened it from ensuring literacy to supporting its development. And transparency under <a href="https://artificialintelligenceact.eu/article/50/">Article 50</a> from August 2, 2026, which turns on people knowing they&#8217;re dealing with AI. Inside the company, that&#8217;s obvious. It stops being obvious when the agent&#8217;s output reaches customers. Weeks away, not next year.</p><p>The structural risk is different, and it has a specific address: <a href="https://artificialintelligenceact.eu/article/25/">Article 25(1)(c)</a>.</p><p>A deployer becomes the provider of a high-risk AI system if it modifies the intended purpose of an AI system, including a general-purpose one, such that the system becomes high-risk. And when that happens, Article 25 is explicit about the consequence: the original provider stops being the provider of that system. Microsoft exits. You inherit the full <a href="https://artificialintelligenceact.eu/article/16/">Article 16</a> stack: risk management, technical documentation, conformity assessment, registration, the works.</p><p>One more twist. The departing provider normally owes the new one cooperation and documentation under Article 25(2), except where it clearly specified that its system is not to be turned into a high-risk one. Microsoft&#8217;s use terms restrict high-risk uses. Check your agreement before assuming the handover comes with help.</p><p>Copilot&#8217;s intended purpose is general productivity. An agent is, functionally, a purpose machine: you give it instructions, knowledge, and a job. Which means the distance between <em>&#8220;deployer of Copilot&#8221;</em> and <em>&#8220;provider of a high-risk AI system&#8221;</em> is one agent built with the wrong job description.</p><p>The recruiting team builds an agent that pre-screens CVs against role requirements. That&#8217;s employment, Annex III, point 4: high-risk. Article 25(1)(c) has no seniority threshold, no requirement that anyone approved anything. </p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;b1108049-b45c-4571-809b-d84a5ca89ec1&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Is My AI System High-Risk Under the EU AI Act?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-06T12:02:25.960Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!-GG3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/is-my-ai-system-high-risk-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:196305760,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><p>The high-risk obligations themselves now apply from December 2, 2027, after the <a href="https://ailawdecoded.com/p/eu-ai-act-amended-the-digital-omnibus">omnibus moved the dates</a>. That&#8217;s runway. Use it.</p><p>Two things are not waiting for 2027.</p><p>First, the prohibitions, in force since February 2025 and carrying the <a href="https://ailawdecoded.com/p/prohibited-ai-practices-eu-ai-act">top fine tier</a>: &#8364;35 million or 7% of global turnover. The relevant one for this story is Article 5(1)(f), emotion inference in the workplace. An agent that reads sentiment in the team&#8217;s messages so a manager knows &#8220;how everyone&#8217;s doing&#8221;? An enthusiastic employee can build a prohibited practice in an afternoon, with knowledge sources and a friendly name.</p><p>Second, a detail from <a href="https://artificialintelligenceact.eu/article/26/">Article 26(7)</a> that reframes the whole sharing question: before using a high-risk AI system at the workplace, employers must inform the affected workers and their representatives. For high-risk agents, an announcement to staff isn&#8217;t the moment the trouble starts. It&#8217;s a legal requirement. </p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;1142080d-bd26-4cb3-a719-96991f6e1cb2&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;EU AI Act Amended: The Digital Omnibus Timeline&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-13T12:02:43.130Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!DR18!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/eu-ai-act-amended-the-digital-omnibus&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:196926473,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:3,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>Is an Agent Even a Separate AI System?</h2><p>No one can tell you yet. The Commission&#8217;s <a href="https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application">guidelines on the AI system definition</a> predate the no-code agent wave and don&#8217;t address it. <span>The May 2026 </span><a href="https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems">draft guidelines on high-risk classification</a><span> come closest, but they answer a neighboring question: multi-component and agentic setups are classified as one system when their linked parts jointly serve a high-risk purpose. Direction confirmed, purpose decides, slicing doesn't help. Who answers for a single no-code agent remains open.</span></p><p>There are two defensible readings. </p><p><strong>One: </strong>a declarative agent is a saved configuration of Microsoft&#8217;s system, instructions plus knowledge plus permissions, and the AI system remains Copilot, with Microsoft as its provider. </p><p><strong>Two:</strong> an agent with its own name, its own purpose, its own knowledge, its own tool permissions, its own user base, and an entry in a store is an AI system built on a general-purpose model, and someone other than Microsoft is answering for it. A saved prompt sits at one end. An org-wide Copilot Studio agent with autonomous triggers sits at the other. The vocabulary (&#8221;agent,&#8221; &#8220;skill,&#8221; &#8220;Gem&#8221;) is marketing. The AI Act&#8217;s question is functional.</p><p>Two reasons not to lose sleep over the metaphysics. For a benign internal agent, both readings land in nearly the same place: thin obligations either way. And in the scenario where the readings would diverge, the high-risk one, Article 25(1)(c) settles the question by making you the provider regardless.</p><p>One more fear worth retiring: building agents does not make your company a provider of a general-purpose AI model. Under the Commission&#8217;s <a href="https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers">GPAI guidelines</a>, that role attaches to modifications that significantly change the model, with an indicative threshold of training compute above roughly a third of what trained the original. Instructions and knowledge files are not training compute. Your agents are prompting, not pre-training.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>What to Actually Do About It</h2><p>The duties in the AI Act share one hidden precondition: you can&#8217;t train people on agents, disclose agents, purpose-check agents, or classify agents you don&#8217;t know exist. The inventory comes first. </p><p>For the people building agents, six rules that fit on one page:</p><ol><li><p><strong>There is no personal AI at work.</strong> Work account plus work task equals the company&#8217;s deployment, even if no one knows. The exemption you&#8217;re thinking of covers your holiday planning.</p></li><li><p><strong>Building is fine. Repurposing is the event.</strong> The moment an agent starts touching decisions about people (hiring, performance, promotion, credit, claims, access to anything), stop and ask before you share.</p></li><li><p><strong>The short forbidden list is absolute.</strong> No agents that infer colleagues&#8217; emotions, score people, or nudge them manipulatively. Not with approval, not as a pilot, not as a joke.</p></li><li><p><strong>Four questions before you hit Share.</strong> What does it do? Whose data does it read? Who will rely on it? Could its output touch a decision about a person?</p></li><li><p><strong>Label what leaves the team.</strong> People outside your context need to know they&#8217;re reading AI output.</p></li><li><p><strong>Your agents outlive your tenure.</strong> When you change roles or leave, hand them over or kill them.</p></li></ol><p>For whoever owns &#8220;the AI thing&#8221; at your company, six checks:</p><ol><li><p><strong>Open the admin center today</strong> and look at the agent sharing setting. If nobody changed it, it&#8217;s set to everyone.</p></li><li><p><strong>Route org-wide distribution through the catalog.</strong> The approval gate is already built. Make the link route the exception.</p></li><li><p><strong>Build the register.</strong> One row per agent: name, owner, purpose, knowledge sources, audience. This is the unglamorous document that makes every other obligation performable.</p></li><li><p><strong>Add agents to the leaver checklist.</strong> Reassign or retire them when their creator walks out.</p></li><li><p><strong>Put agent-building into your AI literacy training.</strong> Article 4 has applied since February 2025 (now an effort obligation after the omnibus, but applicable), and the person most in need of it is your most enthusiastic builder.</p></li><li><p><strong>Name the escalation trigger in plain words.</strong> &#8220;An agent that helps decide about people goes to [name] before sharing.&#8221; One sentence, on the intranet, beats a policy nobody opens.</p></li></ol><div><hr></div><h2>The Question the AI Act Asks</h2><p>The all-staff email didn&#8217;t create the company&#8217;s obligations. It ended the period in which no one could see them.</p><p>And an email is the polite version. Most agents move through links, team channels, and word of mouth: no announcement, no list, no owner once the creator changes jobs. The population grows every quarter, mostly useful, occasionally one job description away from Annex III.</p><p>The register you haven&#8217;t built yet is a list of things you already answer for.</p><p>The AI Act doesn&#8217;t ask whether you knew.</p><div><hr></div><p><strong><a href="https://ailawdecoded.com/p/scope"><span data-color="#077d9a" style="color: rgb(7, 125, 154);">Scope</span></a><span data-color="#077d9a" style="color: rgb(7, 125, 154);"> is where this becomes something you can use in a meeting: the regulation map, the role assignment, the vendor questions, the AI inventory spreadsheet, the AI policy template, with sources attached and kept current as the law changes.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[Regulate, Retreat, Build]]></title><description><![CDATA[A brief history of AI regulation in the EU, in three acts.]]></description><link>https://ailawdecoded.com/p/eu-ai-act-history</link><guid isPermaLink="false">https://ailawdecoded.com/p/eu-ai-act-history</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 15 Jul 2026 12:03:47 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!RbE7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd5b2b-fb2d-41a8-8f58-9dd990d891f2_6000x4000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RbE7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd5b2b-fb2d-41a8-8f58-9dd990d891f2_6000x4000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RbE7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd5b2b-fb2d-41a8-8f58-9dd990d891f2_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!RbE7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd5b2b-fb2d-41a8-8f58-9dd990d891f2_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!RbE7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd5b2b-fb2d-41a8-8f58-9dd990d891f2_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!RbE7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd5b2b-fb2d-41a8-8f58-9dd990d891f2_6000x4000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RbE7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd5b2b-fb2d-41a8-8f58-9dd990d891f2_6000x4000.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/57bd5b2b-fb2d-41a8-8f58-9dd990d891f2_6000x4000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:737865,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.com/i/206722020?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd5b2b-fb2d-41a8-8f58-9dd990d891f2_6000x4000.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RbE7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd5b2b-fb2d-41a8-8f58-9dd990d891f2_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!RbE7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd5b2b-fb2d-41a8-8f58-9dd990d891f2_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!RbE7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd5b2b-fb2d-41a8-8f58-9dd990d891f2_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!RbE7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd5b2b-fb2d-41a8-8f58-9dd990d891f2_6000x4000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>In February 2017, the European Parliament <a href="https://www.europarl.europa.eu/doceo/document/TA-8-2017-0051_EN.html">voted</a> on considering whether robots should become <em>&#8220;electronic persons&#8221;</em>. ChatGPT was nearly six years away. The most advanced consumer AI in Europe could recommend a playlist. And the Parliament was already asking the question that would follow EU lawmakers for the next nine years: </p><blockquote><p><em>When the machine gets it wrong, who pays?</em></p></blockquote><p>The electronic personhood idea died, mercifully. The question survived.</p><p>Hold onto it. It&#8217;s the thread that makes sense of everything the EU has done on AI since, including the last eighteen months, which otherwise look like the EU changing its mind.</p><p>Because if you&#8217;re trying to track EU AI regulation in 2026, it does look like that. The EU AI Act got amended before most of it applied. A liability directive appeared, sat in Parliament for three years, and vanished. In June, the Commission proposed something called the Cloud and AI Development Act, which regulates data centres and sounds like it wandered in from a different policy file. Each development makes sense on its own. Together, they read as noise.</p><p>They&#8217;re not noise. They&#8217;re one story in three acts: the EU built a complete legal system for AI, dismantled part of it before it applied, and is now spending public money to make sure there&#8217;s a European AI industry left to regulate. If compliance is your job, the arc matters more than any single law. It tells you which rules will be enforced, which got softened, and where the next obligations might come from.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>Act I: Regulate (2017&#8211;2024)</h2><p>That 2017 resolution asked the Commission for liability rules covering robots and AI. The EU&#8217;s opening move on AI law was liability. Market access rules came four years later.</p><p>What followed was Brussels at its usual pace. An AI strategy in 2018. Ethics guidelines from an expert group in 2019: voluntary, high-minded, and largely ignored by the market. Then the February 2020 <a href="https://commission.europa.eu/publications/white-paper-artificial-intelligence-european-approach-excellence-and-trust_en">White Paper</a>, which committed to a risk-based approach and introduced the framing that still runs the show: an &#8220;<em>ecosystem of excellence</em>&#8221; and an &#8220;<em>ecosystem of trust</em>&#8221;. Ursula von der Leyen had promised AI legislation within her first hundred days. What arrived around day one hundred was a white paper announcing the intention to legislate. In Brussels terms, that is punctual.</p><p>The <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A52021PC0206">actual proposal</a> landed on April 21, 2021. The logic behind it: Member States were starting to write their own AI laws, and one regime is cheaper than 27. Trust was treated as an adoption strategy (people won&#8217;t use AI they don&#8217;t trust, so trust rules double as industrial policy). And after the GDPR, there was open ambition to set the global standard again.</p><p>One architecture choice from that proposal explains more than anything else in it. The AI Act was built as product safety law: risk classes, conformity assessments, CE marking. AI regulated like lifts and medical devices, because that was the machine the EU already had. It is a market access instrument, not a fundamental rights instrument. A good share of what frustrates people about the AI Act traces back to that choice.</p><p>And the system was designed with two halves. In September 2022, the Commission proposed the <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A52022PC0496">AI Liability Directive</a> together with a rewritten Product Liability Directive. The AI Act tells you how to put AI on the market. The liability pair answered what happens when it hurts someone anyway. Rules and consequences. On paper, a complete system.</p><p>Then the negotiations met reality. Six days before the Council agreed its negotiating position in December 2022, ChatGPT launched. The text barely contemplated general-purpose AI, so Parliament wrote an entire GPAI chapter mid-flight in 2023. In November 2023, France, Germany and Italy nearly collapsed the final talks by demanding that foundation models be governed by <em>&#8220;mandatory self-regulation&#8221;</em>, a position that happened to match the interests of Mistral and Aleph Alpha. The deal that saved the file took a 36-hour negotiating marathon in December 2023.</p><p>The pattern is worth registering: the fight between protection and competitiveness didn&#8217;t start after the AI Act passed. It was inside the building the whole time.</p><p><a href="https://eur-lex.europa.eu/eli/reg/2024/1689/oj">EU AI Act (Regulation (EU) 2024/1689</a>) entered into force on August 1, 2024. Act one complete. The EU had its rulebook. The liability half was still sitting in committee.</p><div><hr></div><h2>Act II: Retreat (2024&#8211;2026)</h2><p>In September 2024, Mario Draghi&#8217;s competitiveness report handed Brussels a new vocabulary: regulatory burden, simplification. The mood shifted from &#8220;the world will copy our rules&#8221; to &#8220;our rules are why we don&#8217;t have an AI industry.&#8221; Whether that diagnosis is correct is a separate article. Its effects arrived fast.</p><p>Laws usually die loudly. A failed vote, a walkout, a press conference. The AI Liability Directive died in an annex: one line in the Commission&#8217;s <a href="https://eapil.org/2025/10/09/european-commission-withdraws-two-proposals-assignments-of-claims-regulation-and-ai-liability-directive/">2025 work programme</a>, published February 11, 2025, marking it for withdrawal due to &#8220;no foreseeable agreement.&#8221; Parliament&#8217;s legal affairs committee was actively working on the file at the time, with votes scheduled. Twelve industry associations had formally called for the withdrawal weeks earlier. It is rare for Brussels to move so quickly on stakeholder feedback. The formal withdrawal appeared in the Official Journal on October 6, 2025. The ePrivacy Regulation died in the same annex, after eight years of negotiation.</p><p>It&#8217;s worth being precise about what was lost, because the directive had a modest reputation and an even more modest text. It created no new liability regime. It gave people harmed by high-risk AI two procedural tools: court-ordered disclosure of evidence (Article 3) and a rebuttable presumption of causality (Article 4). Without them, a rejected job applicant who suspects the algorithm has to reverse-engineer a neural network to prove their case. Parliament had asked for strict liability in 2020. The Commission offered presumptions. Even presumptions turned out to be too much.</p><p><span>The stated reasoning, per Commissioner </span><a href="https://www.euronews.com/next/2025/07/31/eu-commission-confirms-ditching-of-ai-liability-and-patents-proposals">Virkkunen</a><span>: the directive would have led Member States to </span><em><span>"apply the rules in different ways"</span></em><span>. The result of withdrawing it: AI liability now runs through 27 national tort regimes, each applying its own rules. The fragmentation offered as the risk is the outcome that was chosen.</span></p><p>So where does liability actually live now? In the surviving half of the 2022 pair. The new <a href="https://eur-lex.europa.eu/eli/dir/2024/2853/oj/eng">Product Liability Directive</a> treats software and AI systems as products, SaaS included, and applies to products placed on the market from December 9, 2026. It even inherited the dead directive&#8217;s tools: disclosure duties and presumptions for complex cases. But it compensates product-defect damage: death, personal injury, property, destroyed data. An AI system that wrongfully denies you a loan, filters out your job application, or scores you into a worse insurance bracket produces none of those. The harms that motivated the liability directive in the first place now depend on which of the 27 countries you&#8217;re standing in when the algorithm gets it wrong.</p><p>The retreat also reached the AI Act itself. The Digital Omnibus moved the high-risk obligations to December 2, 2027 (Annex III) and August 2, 2028 (AI embedded in regulated products), fixed dates this time. Parliament adopted it on June 16, the Council <a href="https://www.consilium.europa.eu/en/press/press-releases/2026/06/29/artificial-intelligence-council-gives-final-green-light-to-simplify-and-streamline-rules/">signed off on June 29</a>. I covered the full reshuffled timeline <a href="https://ailawdecoded.com/p/eu-ai-act-amended-the-digital-omnibus">in May</a>. What stayed on schedule is more important than what moved: the prohibitions have applied since February 2025, transparency obligations arrive on August 2, 2026 &#8212; with one carve-out: systems already on the market get until December 2, 2026 for the Article 50(2) watermarking duty &#8212; and the Commission's enforcement powers over general-purpose AI switch on the same day. Weeks away, not next year.</p><p>One more date, because the timing is almost too neat. The following week after the omnibus deal was struck in May, the EU <a href="https://www.coe.int/en/web/artificial-intelligence/-/european-union-ratifies-the-council-of-europe-framework-convention-on-artificial-intelligence">ratified</a> the Council of Europe Framework Convention on AI, the first binding international treaty on AI and human rights. Delaying its own rules at home, signing commitments abroad, in the same week. </p><p>Both are the EU&#8217;s real position. Act two, in a single image.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;6c0f2705-6fdd-4167-8bb0-97e605a234e4&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;EU AI Act Amended: The Digital Omnibus Timeline&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-13T12:02:43.130Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!DR18!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/eu-ai-act-amended-the-digital-omnibus&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:196926473,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:3,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>Act III: Build (2025&#8211;2026)</h2><p>While the rules were being trimmed, the money arrived.</p><p><strong>February 2025, AI Action Summit in Paris</strong>: the Commission announced InvestAI, a plan to mobilize &#8364;200 billion for AI, including &#8364;20 billion for &#8220;gigafactories&#8221; to train frontier-scale models. </p><p><strong>April 2025</strong>: the AI Continent Action Plan, built on five pillars. Compute, data, skills, adoption, and simplification. The thing act two was made of is now an official pillar of AI industrial policy.</p><p><strong>Then June 3, 2026</strong>: the Tech Sovereignty Package, headlined by the <a href="https://digital-strategy.ec.europa.eu/en/library/proposal-cloud-and-ai-development-act-cada">Cloud and AI Development Act</a>. CADA is a proposal, weeks old, and the negotiations will reshape it. But the design is telling. It creates a <em>"cloud sovereignty framework"</em> for providers serving the public sector, built on four "Union assurance levels." The baseline requires infrastructure, assets and customer data to stay in the EU. The strictest tier requires a provider free of any third-country control, no derogations, holding a high-assurance EU cybersecurity certificate, and able to demonstrate control over every software component in the stack, down to who maintains and evolves it.</p><p><span>The Commission's own numbers explain the urgency: European providers' share of their home cloud market fell from roughly 29% in 2017 to 15% by 2022 (from the </span><a href="https://digital-strategy.ec.europa.eu/en/library/proposal-cloud-and-ai-development-act-cada">proposal's explanatory memorandum</a><span>), and the EU spends &#8364;264 billion a year on US proprietary IT products and services (from the </span><a href="https://www.insideglobaltech.com/2026/06/04/eu-tech-sovereignty-package/">Open Source Strategy</a><span> published in the same package).</span></p><p>CADA gets filed under industrial policy, and that&#8217;s how it reads, until you look at the mechanics. Assurance levels. Certification schemes. Software bills of materials. Source code audits. Corporate separation requirements. That is a conformity assessment regime: compliance law in a hard hat. The EU didn&#8217;t stop regulating AI in act three. It changed what it regulates for. Acts one and two regulated to protect individuals. Act three regulates to secure the stack.</p><p>If you sell cloud or AI services to an EU public body, or your product runs on a hyperscaler that does, the sovereignty framework is now a question in your future procurement bids. Which parts of the proposal survive the negotiations is genuinely open. The direction is not.</p><div><hr></div><h2>The Rest of the Map</h2><p>The three acts are the spine. The body of EU AI law is wider, and a map that pretends otherwise would be lying to you. The short version:</p><ul><li><p><strong><a href="https://eur-lex.europa.eu/eli/reg/2016/679/oj">GDPR</a></strong> &#8212; Article 22 on automated decisions is still arguably the most litigated AI provision in Europe. And the omnibus process is now reopening the GDPR itself, including a proposed legal basis for AI training. Contested, not adopted.</p></li><li><p><strong>Copyright</strong> &#8212; the 2019 <a href="https://eur-lex.europa.eu/eli/dir/2019/790/oj">CDSM Directive</a>&#8216;s text-and-data-mining exception (Articles 3 and 4) is the legal foundation of every AI training data fight in the EU. The AI Act cross-references its opt-out directly.</p></li><li><p><strong><a href="https://eur-lex.europa.eu/eli/reg/2022/2065/oj">DSA</a></strong> &#8212; recommender transparency and systemic risk duties for the largest platforms. AI rules that never mention the AI Act.</p></li><li><p><strong><a href="https://eur-lex.europa.eu/eli/reg/2023/2854/oj">Data Act</a></strong> &#8212; applies since September 2025. Who gets access to device data: the supply side of AI.</p></li><li><p><strong><a href="https://eur-lex.europa.eu/eli/reg/2024/2847/oj">Cyber Resilience Act</a></strong> &#8212; security requirements for connected products, AI-enabled ones included. Main obligations land December 2027.</p></li><li><p><strong><a href="https://eur-lex.europa.eu/eli/dir/2024/2831/oj">Platform Work Directive</a></strong> &#8212; the first EU law on algorithmic management. Transposition due December 2026. If you build or use HR tech, this one is aimed at you.</p></li><li><p><strong><a href="https://eur-lex.europa.eu/eli/reg/2025/327/oj">European Health Data Space</a></strong> &#8212; health data for AI training and development, phasing in from 2027.</p></li><li><p><strong><a href="https://www.europarl.europa.eu/legislative-train/theme-protecting-our-democracy-upholding-our-values/file-digital-fairness-act">Digital Fairness Act</a></strong> &#8212; expected as a proposal in late 2026: dark patterns, addictive design, unfair personalization. The next AI-adjacent law is coming from consumer protection, not tech policy.</p></li><li><p><strong><a href="https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/">Harmonised standards</a></strong> &#8212; not law, but where <em>&#8220;compliant&#8221;</em> is currently being defined for high-risk AI. The omnibus delay was officially justified by these not being ready.</p></li><li><p><strong>Sector rules</strong> &#8212; <a href="https://eur-lex.europa.eu/eli/reg/2022/2554/oj">DORA</a> for financial entities, <a href="https://eur-lex.europa.eu/eli/reg/2017/745/oj">MDR</a> for medical devices, vehicle type-approval. Your vertical has its own chapter.</p></li></ul><p>Horizontal EU law only. National AI laws are a separate map, for a separate article.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>Where This Leaves You</h2><p>The arc translates into priorities better than any single law does.</p><p>Enforcement energy is real for what&#8217;s already live: prohibitions, GPAI obligations, transparency from August 2. It&#8217;s reduced for high-risk conformity, where you gained time until December 2027. And it&#8217;s rising in two new places: liability and procurement.</p><p>The liability point deserves numbers. </p><p>December 9, 2026: the new product liability regime starts applying to AI products, with disclosure duties and presumptions that make claims easier to bring. </p><p>December 2, 2027: the high-risk safety rules those products would naturally be judged against. The exposure arrives 358 days before the rulebook. </p><p>For roughly a year, a court assessing whether your AI product is <em>&#8220;defective&#8221; </em>has no applicable harmonised standard to measure it against, and you have no AI Act compliance to point to, because there is nothing yet to comply with. Contracts, indemnities, documentation and insurance carry that year. If your liability planning is waiting for 2027 because the AI Act is, it&#8217;s waiting too long.</p><p>Act three is still being written. The gigafactories are funded, CADA is heading into negotiations, and the next obligations are arriving through procurement criteria and consumer law rather than another grand AI statute.</p><p>Which leaves the question from 2017. The Parliament asked who pays when the machine gets it wrong, back when the machines could barely do anything worth suing over. Nine years later, the EU has some 150 pages on how to build AI responsibly, a product liability law that covers half the problem, and 27 national courts assembling the rest.  </p><p><em>When the machine gets it wrong, who pays?</em></p><p>Three acts later, it&#8217;s the one question the EU formally withdrew.</p><div><hr></div><p><strong><a href="https://ailawdecoded.com/p/scope"><span data-color="#077d9a" style="color: rgb(7, 125, 154);">Scope</span></a><span data-color="#077d9a" style="color: rgb(7, 125, 154);"> is where this becomes something you can use in a meeting: the regulation map, the role assignment, the vendor questions, the AI inventory spreadsheet, the AI policy template, with sources attached and kept current as the law changes.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[Your Role Classification Is Only as Honest as Your AI Inventory]]></title><description><![CDATA[The EU AI Act never tells you to build an AI inventory. But every obligation in it assumes you already have one.]]></description><link>https://ailawdecoded.com/p/eu-ai-act-role-classification-ai-inventory</link><guid isPermaLink="false">https://ailawdecoded.com/p/eu-ai-act-role-classification-ai-inventory</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 08 Jul 2026 20:12:57 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!HkyX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e75c2b-fd26-4440-8986-372d833c62b0_6000x4000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HkyX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e75c2b-fd26-4440-8986-372d833c62b0_6000x4000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HkyX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e75c2b-fd26-4440-8986-372d833c62b0_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!HkyX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e75c2b-fd26-4440-8986-372d833c62b0_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!HkyX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e75c2b-fd26-4440-8986-372d833c62b0_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!HkyX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e75c2b-fd26-4440-8986-372d833c62b0_6000x4000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HkyX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e75c2b-fd26-4440-8986-372d833c62b0_6000x4000.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/80e75c2b-fd26-4440-8986-372d833c62b0_6000x4000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:492618,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.com/i/205943005?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e75c2b-fd26-4440-8986-372d833c62b0_6000x4000.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HkyX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e75c2b-fd26-4440-8986-372d833c62b0_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!HkyX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e75c2b-fd26-4440-8986-372d833c62b0_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!HkyX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e75c2b-fd26-4440-8986-372d833c62b0_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!HkyX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e75c2b-fd26-4440-8986-372d833c62b0_6000x4000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>The register is finished.</p><p>Three weeks after the workshop with the blocked calendars and the mandatory attendance, the spreadsheet is complete. Fourteen AI systems, each with a role in column D, each with documented reasoning, each with a reassessment trigger. You presented it to the general counsel. She nodded. In your world, that&#8217;s a standing ovation.</p><p>Then comes the quarterly all-hands. The product team is doing a demo. They&#8217;ve built something called <strong>Atlas</strong>: an internal assistant that answers customer-history questions for the support staff. It runs on a vendor&#8217;s model, fine-tuned on two years of support tickets. It has an internal brand name. It has a logo. Someone made a logo.</p><p>Atlas is not in the register.</p><p>That afternoon, you do something you should have done earlier. You search the expense system for AI subscriptions. Seventeen results. Team cards, individual expense claims, one recurring charge labeled only &#8220;productivity tool&#8221;. Four of them match the register. The other thirteen are new to you.</p><p>The register isn&#8217;t wrong. Everything on it is classified correctly. The problem is what&#8217;s missing from it. And what&#8217;s missing from it follows a pattern.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>The Assumption Underneath the Decision Tree</h2><p>The EU AI Act never tells you to build an AI inventory. No article requires one. What the AI Act does instead is attach every obligation to a specific system and to your role with respect to it.</p><p>Provider and deployer are defined system by system in <a href="https://artificialintelligenceact.eu/article/3/">Article 3</a>. The role-transformation triggers in <a href="https://artificialintelligenceact.eu/article/25/">Article 25</a> fire per system. Deployer obligations under <a href="https://artificialintelligenceact.eu/article/26/">Article 26</a> attach to each high-risk system you operate. The fundamental rights impact assessment in <a href="https://artificialintelligenceact.eu/article/27/">Article 27</a> is per system. Even the AI literacy obligation in <a href="https://artificialintelligenceact.eu/article/4/">Article 4 </a>assumes you know which systems your staff are operating.</p><p>The regulation assumes enumeration without ever mandating it. Every obligation is conditional on knowing a system exists and knowing what you are in relation to it. The inventory is the unstated premise of the whole compliance architecture, which is why <em>build the inventory</em> is step one of the practical process of role assignment.</p><p>Step one is also the step that so often fails.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;14726057-b1e1-4db4-8520-851054d0dcfc&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;What's Your Role Under the EU AI Act? Practical Decision Tree.&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-06-10T12:03:27.696Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!Bh5p!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/your-role-under-the-eu-ai-act-guide&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:199877647,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:5,&quot;comment_count&quot;:5,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>Some Systems Get In, and Some Don&#8217;t</h2><p>A register is built from what can be seen. What can be seen is what passed through procurement: a contract exists, legal reviewed it, the vendor wrote an intended purpose into the documentation. These are also the systems most likely to sit in a clean deployer posture, because a contract and a documented intended purpose are what keep you a deployer. The vendor assessed the use case. You operate inside the lines the vendor drew. Column D says <em>deployer</em>, and column D is right.</p><p>The systems that escape are a different population. The subscription on a team card. The API key a developer set up in an afternoon. The tool a business unit reconfigured after go-live, without anyone from legal knowing. These systems have no documented intended purpose, no contractual guardrails, and no review scheduled for later. Which is the exact environment where the Article 25 triggers live: </p><ul><li><p>repurposing a system beyond what the vendor assessed (25(1)(c)), </p></li><li><p>modifying it in ways no conformity assessment foresaw (25(1)(b)), </p></li><li><p>putting your own name on it because it looked better that way (25(1)(a)).</p></li></ul><p>The properties that keep a system out of your register are the properties that push it toward provider territory.</p><p>So the undercount isn&#8217;t even. The register misses the expensive category first. A procured chatbot used exactly as licensed can go missing too, but the tool that was fine-tuned on proprietary data, branded internally, and pointed at a use case its vendor never heard of? That one skipped procurement almost by definition. </p><p>Atlas was never getting into column D. Systems like Atlas never are.</p><div><hr></div><h2>Two Ways a Register Fails</h2><p>The invisible system is <em>the first failure mode</em>. <strong>Shadow AI</strong>: the system isn&#8217;t in the register, you don&#8217;t know it exists, so you never classify it. A gap, at least, is honest about itself.</p><p><em>The second failure mode</em> sits inside the register. The tool was procured properly. Legal reviewed the contract. The entry says <em>deployed SaaS, vendor X, deployer</em>. Then a business unit fine-tuned it on internal data, or pointed it at a use case the vendor never assessed, or put an internal brand on the interface. The entry was correct on the day it was written. It isn&#8217;t anymore.</p><p>A missing entry is a gap. A stale entry is false confidence, and false confidence costs more, because a signed-off register is the last place anyone looks for a problem. The classification happened. The box is ticked. The general counsel nodded.</p><p>Both modes map onto the <a href="https://ailawdecoded.com/p/your-role-under-the-eu-ai-act-guide">decision tree on role-assignment</a>. The first breaks step one: the classification never runs. The second breaks the &#8220;document and revisit&#8221; step: the classification ran once, and the system kept moving.</p><p>The regulation doesn&#8217;t distinguish between the two. Article 25 fires at the moment of the act. Rebranding is a marketing decision. Substantial modification can be a configuration choice. Repurposing is often plain usage drift. None of it requires a contract, a procurement event, or an approval. The legal event happens when the team does the thing, not when legal finds out. </p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;d5166aef-d980-4843-946e-9558c68ca831&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Provider vs. Deployer Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-22T12:03:43.719Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!NS5L!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35f75bb-44f2-45d4-b53c-84654d8e8617_8192x5461.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/provider-vs-deployer-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:194314202,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:5,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>Shadow AI Data Breach</h2><p>Shadow AI became a security story before it became a compliance story, so the numbers come from the security world.</p><p>IBM&#8217;s <a href="https://www.ibm.com/reports/data-breach">2025 Cost of a Data Breach report</a> found that 20% of studied organizations experienced a breach linked to shadow AI: unsanctioned tools operating outside IT oversight. Those breaches cost an average of $670,000 more than the baseline. And 63% of the breached organizations had no governance policy for managing AI or detecting unauthorized use.</p><p>Reading it as a lawyer, the same numbers say something else. One in five organizations has already had unsanctioned AI surface in the most expensive way possible. The population of unregistered systems is large enough to show up in breach statistics. Every system in it has an AI Act role that has never been assigned.</p><p>The security industry measures shadow AI in exposed records and incident costs. The measurement still missing: how many of those invisible systems have crossed an Article 25 threshold. I haven&#8217;t found a published figure, and I doubt one exists yet. </p><p>I guess that the share is disproportionate. </p><div><hr></div><h2>The Questionnaire Coming Back Clean</h2><p>My next question is how can an organization solve such situation. The instinctive fix is a survey. Email the business units, ask them to list their AI tools, compile the answers.</p><p>But what if the survey comes back clean, and it&#8217;s wrong anyway? </p><p>Self-reporting requires the respondent to know that what they did was legally significant. The team that fine-tuned a vendor model on support tickets did not experience that as a substantial modification within the meaning of Article 25(1)(b). They experienced it as making the tool better. The marketing team that put the company&#8217;s name on the interface wasn&#8217;t rebranding an AI system. They were fixing an ugly login page.</p><p>Article 25 triggers don&#8217;t feel like legal events to the people performing them. Ask people to self-report legal events, and you get a list of everything except the things you need.</p><p>The detection has to run on activity, not on memory:</p><p><strong>Expense data.</strong> Recurring charges to AI vendors, individual subscription claims, the &#8220;productivity tool&#8221; line items. Finance has this already. Legal has never asked for it.</p><p><strong>SSO and network logs.</strong> Which AI services people actually authenticate into. IT can pull the list in a day. It will be longer than your register.</p><p><strong>API traffic.</strong> A live API key to a model provider is the tell for build activity, and build activity is where provider status gets created. If a team holds an OpenAI or Anthropic key, that team is at layer two of the GPAI stack, whether it knows it or not.</p><p><strong>Procurement follow-up, not procurement records.</strong> The register captured what was bought. It didn&#8217;t capture what happened after. For every entry marked <em>deployer</em>, the question is not &#8220;did we license this&#8221; but &#8220;what has been done to it since&#8221;. Fine-tuning, configuration beyond vendor parameters, internal branding, new use cases. Each one is a potential Article 25 event that happened after the paperwork closed.</p><p>Then treat the register as a living document with named reassessment triggers: every modification, every retraining, every new use case, every contract renewal. I have already said this. What I didn&#8217;t say: the trigger list only works for systems already in the register. Everything else needs the detection layer, running continuously, because a system that skipped procurement will skip your triggers too.</p><p>One timing note. The Digital Omnibus pushed high-risk obligations for standalone Annex III systems to 2 December 2027. That reads like breathing room. For the visible register, it is. An Article 25 trigger doesn&#8217;t wait for 2027. The role shift happens when the act happens. The obligations land later. </p><p>The classification error exists now, sitting in systems you haven&#8217;t found yet.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>The All-Hands Applause</h2><p>The product team finishes the Atlas demo to applause. It&#8217;s a good tool. That was never the question.</p><p>You&#8217;re running the decision tree in your head. Fine-tuned on proprietary data: possible substantial modification. Internal name and logo: possible 25(1)(a). A purpose the vendor never assessed: possible 25(1)(c). Three potential triggers, one system, zero entries in the register. And thirteen subscriptions in the expense report you haven&#8217;t looked at yet.</p><p>The register you presented was accurate. Every system on it, correctly classified. It just wasn&#8217;t an inventory of your company&#8217;s AI. It was an inventory of your company&#8217;s <em>procured</em> AI. Those are different documents, and what separates them is not a random slice of what&#8217;s out there.</p><p>It&#8217;s the systems that never crossed legal&#8217;s desk, put to uses their vendors never assessed, carrying obligations that have never been assigned.</p><p>The decision tree still works. It will classify anything you feed it.</p><p>Feeding it is the part that has to be solved.</p><div><hr></div><p><strong><a href="https://ailawdecoded.com/p/scope"><span data-color="#077d9a" style="color: rgb(7, 125, 154);">Scope</span></a><span data-color="#077d9a" style="color: rgb(7, 125, 154);"> is where this becomes something you can use in a meeting: the regulation map, the role assignment, the vendor questions, the AI inventory spreadsheet, the AI policy template, with sources attached and kept current as the law changes.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[The EU AI Act's Loophole With No Expiry Date]]></title><description><![CDATA[Article 111(2) of the EU AI Act decides which high-risk AI systems will never have to comply.]]></description><link>https://ailawdecoded.com/p/eu-ai-act-article-111-loophole-legacy-high-risk-ai</link><guid isPermaLink="false">https://ailawdecoded.com/p/eu-ai-act-article-111-loophole-legacy-high-risk-ai</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 01 Jul 2026 12:03:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!3JZC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab285665-697f-4608-ad90-6c5cb0e6b5ae_5760x3240.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3JZC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab285665-697f-4608-ad90-6c5cb0e6b5ae_5760x3240.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3JZC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab285665-697f-4608-ad90-6c5cb0e6b5ae_5760x3240.jpeg 424w, https://substackcdn.com/image/fetch/$s_!3JZC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab285665-697f-4608-ad90-6c5cb0e6b5ae_5760x3240.jpeg 848w, https://substackcdn.com/image/fetch/$s_!3JZC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab285665-697f-4608-ad90-6c5cb0e6b5ae_5760x3240.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!3JZC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab285665-697f-4608-ad90-6c5cb0e6b5ae_5760x3240.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3JZC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab285665-697f-4608-ad90-6c5cb0e6b5ae_5760x3240.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ab285665-697f-4608-ad90-6c5cb0e6b5ae_5760x3240.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:278476,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.com/i/202097019?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab285665-697f-4608-ad90-6c5cb0e6b5ae_5760x3240.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3JZC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab285665-697f-4608-ad90-6c5cb0e6b5ae_5760x3240.jpeg 424w, https://substackcdn.com/image/fetch/$s_!3JZC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab285665-697f-4608-ad90-6c5cb0e6b5ae_5760x3240.jpeg 848w, https://substackcdn.com/image/fetch/$s_!3JZC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab285665-697f-4608-ad90-6c5cb0e6b5ae_5760x3240.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!3JZC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab285665-697f-4608-ad90-6c5cb0e6b5ae_5760x3240.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>I was at a conference two weeks ago, listening to a presentation on the EU AI Act and its connection to GDPR, when the speaker put Article 111(2) on the screen.</p><p>I had read it before. If you&#8217;ve read the AI Act cover to cover (condolences), so have you. It lives in <a href="https://artificialintelligenceact.eu/chapter/13/">Chapter XIII Final Provisions</a>, the part of a regulation where the highlighter runs dry. Entry into force. Amendments to other regulations. Transitional arrangements. <a href="https://artificialintelligenceact.eu/article/111/">Article 111(2)</a> reads like exactly what it appears to be: a transition rule for AI systems that were already on the market before the new obligations apply.</p><p>Then he walked the room through what it does.</p><p>I sat there realizing I had filed one of the most consequential provisions in the EU AI Act under <em>administrative.</em> Judging by the quality of the silence around me, I wasn&#8217;t the only one.</p><p>Article 111(2) doesn&#8217;t give older AI systems more time to comply.</p><p>It decides which AI systems never have to.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>What the Provision Says</h2><p>The text, from the Official Journal version:</p><blockquote><p><em>&#8220;...this Regulation shall apply to operators of high-risk AI systems... that have been placed on the market or put into service before 2 August 2026, only if, as from that date, those systems are subject to significant changes in their designs. In any case, the providers and deployers of high-risk AI systems intended to be used by public authorities shall take the necessary steps to comply with the requirements and obligations of this Regulation by 2 August 2030.</em>&#8221;</p></blockquote><p>Transitional provisions normally come in two parts. Old systems get relief, and then a date arrives when the relief ends. Article 111(2) has the first part. For private-sector systems, the second part doesn&#8217;t exist.</p><p>A high-risk AI system placed on the EU market before the deadline, and never significantly redesigned afterwards, is exempt. There is no date at which that changes. The risk management system, the data governance requirements, the technical documentation, the human oversight design, the accuracy and robustness standards: none of it applies. Not late. Never.</p><p>Though, I must mention two exceptions. The <a href="https://artificialintelligenceact.eu/article/5/">Article 5</a> prohibitions apply to everything, old or new (a pre-deadline social scoring system is still illegal). And systems intended for use by public authorities must comply by August 2, 2030, modified or not. </p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;09710ba1-fd9d-4c3a-8b85-8cb35255554e&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Is My AI System High-Risk Under the EU AI Act?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-06T12:02:25.960Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!-GG3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/is-my-ai-system-high-risk-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:196305760,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>The Dates Just Moved and the Difference Grew </h2><p>The original cut-off was August 2, 2026. The Digital Omnibus on AI, provisionally agreed on May 7, 2026, moves the high-risk AI obligations to December 2, 2027 for stand-alone <a href="https://artificialintelligenceact.eu/annex/3/">Annex III</a> systems (hiring tools, credit scoring, education, life and health insurance pricing), and to August 2, 2028 for AI embedded in regulated products. The Article 111(2) cut-off moves with them. </p><p>Laura Caroli, who led the Parliament&#8217;s technical negotiations on the AI Act, put it plainly: a high-risk hiring system placed on the market before December 2, 2027 <em>&#8220;may remain outside the AI Act indefinitely, unless it is substantially altered after that date&#8221;</em>.</p><p>At the time of writing this article, the Digital Omnibus on AI isn't in the Official Journal yet. The European Parliament approved the final text on June 16, 2026; the Council's formal adoption and publication follow, before August 2. Everything here reflects the text Parliament approved in June. I'll flag anything that changes in the official version once it's published.</p><p>The Digital Omnibus on AI does one more thing to this provision, and it got a fraction of the attention the delay got. The Commission&#8217;s proposal clarifies that the exemption attaches to the <em>type</em> of system, not to each individual unit. If at least one unit of a high-risk AI system was lawfully placed on the EU market before the deadline, identical units can continue to be placed on the market afterwards, with no conformity assessment, as long as the design stays unchanged. (This clarification originated in the November 2025 proposal, and it survived: the adopted text keeps the grace period attached to the type of system, not each individual unit.)</p><p>The pool of exempt AI systems doesn&#8217;t just persist after December 2027.</p><p>It keeps growing.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;4fcca4a1-ce59-4168-9443-ee69750a21ef&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;EU AI Act Amended: The Digital Omnibus Timeline&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-13T12:02:43.130Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!DR18!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/eu-ai-act-amended-the-digital-omnibus&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:196926473,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:3,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>What This Means if You&#8217;re the One Buying</h2><p>If your company is procuring AI systems in the next 18 months, the system you sign for may never be subject to the AI Act&#8217;s requirements. Not because of a loophole your vendor found. Because of the EU AI Act&#8217;s own architecture.</p><p>Which changes what the compliance conversation in procurement is even about. <em>&#8220;We&#8217;ll be AI Act ready&#8221;</em> on the sales slide is not a compliance status. The question is no longer whether the vendor is compliant. The question is whether their system will ever be legally required to be.</p><p>And you cannot check the answer yourself. There is no public registry of when an AI system was <em>&#8220;placed on the market&#8221;</em>. The EU database for high-risk systems covers systems that register and comply, which exempt legacy systems, by definition, don&#8217;t. A vendor&#8217;s claim about their system&#8217;s legacy status is unverifiable from the outside. That moves it from due-diligence question to contractual warranty (more on that below).</p><div><hr></div><h2>What Your Vendor Is Thinking</h2><p>Every month between now and December 2027 is a strategic shipping window. Place a high-risk AI system on the EU market before the deadline and you&#8217;ve acquired an indefinite exemption. Keep the design frozen and you keep it. Under the type-based clarification, you can keep selling new copies of it too.</p><p>This is not a fringe reading. MEP Sergey Lagodinsky calls the provision <em>&#8220;a loophole&#8221; </em>and <em>&#8220;a weak spot&#8221;</em> in the law. Bram Vranken of Corporate Europe Observatory warns that companies &#8220;might abuse this timeline and quickly push risky AI systems onto the market&#8221; before the deadline, saving the compliance costs entirely. The people who built and watched over this regulation are saying, on the record, that the rational vendor strategy is to race to market and then stand very still.</p><p>None of this requires bad faith. It requires a vendor who reads the regulation and responds to incentives. </p><div><hr></div><h2>On &#8220;Significant Change&#8221;</h2><p>The exemption holds only while the system avoids <em>&#8220;significant changes in its design&#8221;</em>. So the entire question of whether a legacy system ever enters the EU AI Act collapses into one undefined phrase.</p><p>What we know: <a href="https://artificialintelligenceact.eu/recital/177/">Recital 177</a> says significant change should be understood as equivalent to <em>&#8220;substantial modification&#8221;</em> under <a href="https://artificialintelligenceact.eu/article/3/">Article 3(23)</a>. That definition covers a change not foreseen or planned in the provider&#8217;s initial conformity assessment which either affects compliance with the high-risk requirements or changes the system&#8217;s intended purpose.</p><p>Notice the problem. The test&#8217;s reference point is the initial conformity assessment. Legacy systems never had one. That&#8217;s what makes them legacy systems. The yardstick the regulation points to doesn&#8217;t exist for exactly the systems this provision governs. I think that in practice the reference point will have to be the provider&#8217;s own design documentation, which the provider writes, controls, and can draft as broadly as their lawyers dare.</p><p>The open questions are the ones your vendor will answer in their own favor. Is retraining on new data a design change? A new model version behind the same interface? Swapping the underlying foundation model while the product name stays the same? No guidance exists yet. Until it does, expect every vendor changelog to be written by someone who has read Article 111(2) very carefully.</p><div><hr></div><h2>The Trap on Your Side of the Contract</h2><p>The exemption protects the system as the vendor shipped it. It does not protect what you do to it afterwards.</p><p>If you substantially modify a high-risk AI system yourself, or change its intended purpose, <a href="https://artificialintelligenceact.eu/article/25/">Article 25(1)</a> can make <em>you</em> the provider. Not provider-ish. The provider: conformity assessment, technical documentation, CE marking, registration, all of it, for an AI system you didn&#8217;t build, possibly without the documentation you&#8217;d need to do any of it. </p><p>Buying an exempt legacy system and customizing it heavily is how a company wakes up one morning as an AI provider.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;15d3b892-36e5-4ba5-ac0d-7a9268fa92db&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Provider vs. Deployer Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-22T12:03:43.719Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!NS5L!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35f75bb-44f2-45d4-b53c-84654d8e8617_8192x5461.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/provider-vs-deployer-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:194314202,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:5,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>Six Questions Before You Sign</h2><p>The practical part. These belong in your procurement process for any AI system that is or could be high-risk, starting now.</p><ol><li><p><strong>&#8220;When was this system first placed on the EU market?&#8221;</strong></p></li></ol><p>The single most consequential question in the deal, and the sales team likely won&#8217;t know why you&#8217;re asking. Don&#8217;t accept the answer on a call. Make it a contractual warranty, with the date stated. If the vendor won&#8217;t warrant the date, that tells you something too.</p><ol start="2"><li><p><strong>&#8220;Which types of updates do you classify as design changes?</strong>&#8221;</p></li></ol><p>Their update policy decides whether the exemption survives contact with their own roadmap. Get their classification approach in writing, with an obligation to notify you before any update they consider significant, and before any update <em>you</em> might.</p><ol start="3"><li><p><strong>&#8220;If an update brings the system into scope, who carries the compliance?&#8221;</strong></p></li></ol><p>Allocate it in the contract: who performs the conformity assessment, who pays, what happens to the system in production while that takes months. Contract silence defaults to a dispute, and the dispute happens while you&#8217;re running an uncertified high-risk system live.</p><ol start="4"><li><p><strong>&#8220;Will you hand over the technical documentation if the roles shift?&#8221;</strong></p></li></ol><p>If you ever become the provider under Article 25, you need the technical file to have any chance of complying. The EU AI Act foresees cooperation from the original provider, but you don&#8217;t want to be litigating the AI Act when you could be enforcing a clause. Documentation escrow or a hard contractual handover duty.</p><ol start="5"><li><p><strong>Does your AI inventory record legacy status?</strong></p></li></ol><p>Internal question. Every high-risk system in your inventory should carry three fields: its placing-on-market date, its Article 111(2) status, and a modification log. If your inventory doesn&#8217;t have those columns, this article is your reason to add them.</p><ol start="6"><li><p><strong>Are you, or do you sell to, a public authority?</strong></p></li></ol><p>Then the indefinite exemption isn&#8217;t yours. August 2, 2030 applies regardless of modifications. Different planning, different timeline, same provision.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p>The EU AI Act was written to make high-risk AI systems demonstrably safe: documented, overseen, accountable. For systems shipped before December 2027, it will do something else entirely. It will make them permanent.</p><p>From that date, the EU market carries two kinds of high-risk AI, identical on the demo call, separated only by a date. One is governed. One never will be but it will keep selling.</p><p>The date won&#8217;t be on the box. It will be in your contract, if you ask.</p><div><hr></div><p><strong><a href="https://ailawdecoded.com/p/scope"><span data-color="#077d9a" style="color: rgb(7, 125, 154);">Scope</span></a><span data-color="#077d9a" style="color: rgb(7, 125, 154);"> is where this becomes something you can use in a meeting: the regulation map, the role assignment, the vendor questions, the AI inventory spreadsheet, the AI policy template, with sources attached and kept current as the law changes.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[Wrap the Model, or Fine-Tune It?]]></title><description><![CDATA[The build decision that decides what you owe under the EU AI Act.]]></description><link>https://ailawdecoded.com/p/rag-fine-tuning-eu-ai-act</link><guid isPermaLink="false">https://ailawdecoded.com/p/rag-fine-tuning-eu-ai-act</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 24 Jun 2026 12:03:20 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!DIEg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1dc66ad1-bb8b-4845-9b6a-5e4cc5107e70_4500x3000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DIEg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1dc66ad1-bb8b-4845-9b6a-5e4cc5107e70_4500x3000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DIEg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1dc66ad1-bb8b-4845-9b6a-5e4cc5107e70_4500x3000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!DIEg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1dc66ad1-bb8b-4845-9b6a-5e4cc5107e70_4500x3000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!DIEg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1dc66ad1-bb8b-4845-9b6a-5e4cc5107e70_4500x3000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!DIEg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1dc66ad1-bb8b-4845-9b6a-5e4cc5107e70_4500x3000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DIEg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1dc66ad1-bb8b-4845-9b6a-5e4cc5107e70_4500x3000.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1dc66ad1-bb8b-4845-9b6a-5e4cc5107e70_4500x3000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:256852,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.substack.com/i/202933950?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1dc66ad1-bb8b-4845-9b6a-5e4cc5107e70_4500x3000.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DIEg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1dc66ad1-bb8b-4845-9b6a-5e4cc5107e70_4500x3000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!DIEg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1dc66ad1-bb8b-4845-9b6a-5e4cc5107e70_4500x3000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!DIEg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1dc66ad1-bb8b-4845-9b6a-5e4cc5107e70_4500x3000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!DIEg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1dc66ad1-bb8b-4845-9b6a-5e4cc5107e70_4500x3000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>RAG and fine-tuning look like two ways to build the same tool. Under the EU AI Act, one of them hands you a second regulatory role the other never would. </p><p>And the choice almost always gets made before anyone decides to consult Legal.</p><p>You usually find it three weeks after the tool ships, scrolling back through the project board for something else entirely.</p><p>It&#8217;s a card from the planning sprint. The title is some internal codename people outside the team would not recognize. The description is one line, written by an engineer who has long since moved on to the next thing:</p><p><em>Approach: fine-tune the base model on our contract corpus.</em></p><p>You read it once and it means nothing. A technical note about how the contract-review tool got built, the kind of sentence you&#8217;ve trained yourself to skim, because ninety percent of what crosses the engineering channel isn&#8217;t yours to worry about.</p><p>You read it a second time and you stop, because you&#8217;ve spent the last month building the company&#8217;s EU AI Act position for this exact tool. You decided it was a deployer situation, then talked yourself into provider, then wrote three pages explaining why. And you did all of that without knowing this one line existed.</p><p>The word is <em>fine-tune</em>. Not the word you&#8217;d been assuming, which was something closer to <em>plugged the model in</em>.</p><p>And it occurs to you, sitting there with a cold coffee and a project board you opened for an unrelated reason, that you may have been answering the wrong question for a month.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>The Question You Were Being Asked</h2><p>The instinct, when someone hands you a tool built on a model like GPT or Claude, is to ask what kind of system it is. Is it high-risk? Is it a chatbot under <a href="https://artificialintelligenceact.eu/article/50/">Article 50</a>? Where does it sit in <a href="https://artificialintelligenceact.eu/annex/3/">Annex III</a>? Reasonable questions, all of them. And there&#8217;s time for all of them later.</p><p>There&#8217;s a prior question, and it&#8217;s the one the engineer&#8217;s card answered for you without asking. Not <em>what is this tool</em>, but <em>how was it built on the model underneath it</em>. Because under the EU AI Act, that single design choice decides whether your company holds one regulatory role or two.</p><p>The framing usually goes wrong from the start. People ask whether a &#8220;RAG system&#8221; is something different from &#8220;an AI system,&#8221; as though those were two products you could choose between. They aren&#8217;t the same kind of thing. </p><p><strong>&#8220;AI system for contract review&#8221;</strong> describes <em>what the tool does</em>. </p><p><strong>&#8220;RAG system&#8221;</strong> (retrieval-augmented generation) describes <em>how it&#8217;s wired together</em>. </p><p>Your contract tool is almost certainly a RAG system underneath. One word is about function. The other is about plumbing.</p><p>And the plumbing words barely appear in the regulation. </p><p><strong>&#8220;RAG&#8221;</strong> is nowhere in the AI Act. </p><p>Neither is <strong>&#8220;prompting&#8221;</strong> or <strong>&#8220;tool use&#8221;.</strong> </p><p><strong>&#8220;Fine-tuning&#8221;</strong> surfaces once, in a recital, but never as a defined operative term with obligations hung on it. </p><p>These are engineering terms, and the EU AI Act doesn&#8217;t regulate engineering patterns. It regulates two things, and names them precisely: the AI system (<a href="https://artificialintelligenceact.eu/article/3/">Article 3(1)</a>) and the general-purpose AI model (<a href="https://artificialintelligenceact.eu/article/3/">Article 3(63)</a>). The line that decides your obligations runs between those two definitions. It does not run between RAG and not-RAG, which is the comparison that feels natural and leads nowhere.</p><div><hr></div><h2>Start with the Model, Continue with the System</h2><p>Start with the model, because that&#8217;s the foundational part.</p><p>A general-purpose AI model is the engine. <em>GPT, Claude, Llama, Gemini.</em> It displays, in the regulation&#8217;s words, <strong>&#8220;significant generality&#8221;</strong> and can <strong>&#8220;competently perform a wide range of distinct tasks&#8221; </strong>(Article 3(63)). On its own, it is not an AI system, and on its own it puts no AI-system obligations on you at all.</p><p><a href="https://artificialintelligenceact.eu/recital/97/">Recital 97</a> says this in a sentence worth keeping somewhere you can find it: </p><blockquote><p>AI models <em>&#8220;do not constitute AI systems on their own&#8221;</em>, and they <em>&#8220;require the addition of further components, such as for example a user interface, to become AI systems&#8221;</em>.</p></blockquote><p> The model is the engine. It is not the car. You cannot drive it until someone builds the rest of the vehicle around it.</p><p>So the moment your team builds the contract tool, the interface, the inputs, the defined purpose of reading agreements and flagging clauses, they have built an AI system. And your company is its provider under Article 3(3): you developed it, or had it developed, and put it into service under your own name. That last part catches people, so it&#8217;s worth saying plainly. </p><p><strong>&#8220;Putting into service&#8221; </strong>includes building something purely for your own use, inside your own walls, never sold to anyone. Provider does not mean seller. If your firm built this tool to run over its own contracts and never licenses it to a soul, your firm is still the provider.</p><p>Hold onto that, because it is the part the engineer&#8217;s card did not change. Whether the team wrapped the model or fine-tuned it, your company is the provider of the AI system. That was true before you found the card and it&#8217;s true after. </p><p>The card changed something else.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;29d54e6c-aab8-4f10-b89f-472bdd939d82&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;What Is an AI System, Actually?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-08T12:03:14.634Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!Lj3S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6c33bfb-66f1-4bc7-aba6-ed6c0d1df60e_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/ai-system-definition-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193355320,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:3,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>The Real Deal: Did Anyone Touch the Weights?</h2><p>What the card changed is whether your company also reached into the model and altered it.</p><p>This is the fork, and it&#8217;s cleaner than almost any other line the AI Act draws. </p><p>On one side, you wrap the model. On the other, you modify it.</p><p><strong>Wrapping</strong> leaves the model exactly as the provider shipped it. RAG is the clearest example: you connect the model to your clause library and a decade of your old contracts, and at the moment someone asks a question, the system retrieves the relevant material and hands it to the model as context. The model answers from your documents instead of from its training data. But its weights, the actual numbers that make the model what it is, never change. The same is true of prompting, of giving the model tools it can call, of wrapping it in guardrails that check its output. All of that sits around the model. None of it gets inside.</p><p><strong>Fine-tuning</strong> gets inside. You take the model and keep training it, on your own data, until the weights shift and it starts reasoning in your patterns. That is a different act in kind, not in degree. And past a certain point, the regulation stops treating the result as &#8220;the provider&#8217;s model, configured by you&#8221; and starts treating it as a new model, with your company as its provider.</p><p>The dividing question, the one to carry into every build conversation, is not <em>&#8220;are we doing RAG&#8221;. </em></p><p>It&#8217;s whether anyone is touching the model&#8217;s weights.</p><div><hr></div><h2>The Number That Decides It Isn&#8217;t in the EU AI Act</h2><p>The threshold that separates <em>&#8220;you modified the provider&#8217;s model&#8221;</em> from <em>&#8220;you built a new model&#8221;</em> does not appear in the AI Act. It lives in the <a href="https://digital-strategy.ec.europa.eu/en/library/guidelines-scope-obligations-providers-general-purpose-ai-models-under-ai-act">European Commission&#8217;s Guidelines for providers of general-purpose AI models</a>, published 18 July 2025. Guidelines, not regulation. Non-binding guidance interpreting the text. A lawyer who reads the whole EU AI Act cover to cover and stops there will never find this number, which is a strange thing to be able to say about the single line that decides whether you&#8217;ve taken on an entire chapter of obligations.</p><p>The legal trigger is a significant change in the model&#8217;s generality, capabilities, or systemic risk. That phrase is hard to measure, so the guidance offers a number you can actually work with: </p><blockquote><p><em>if the compute used to fine-tune the model exceeds one-third of the compute used to train the original, treat the result as a significant change, the modified version as a new model, and the entity that fine-tuned it as a provider that may become responsible for it. </em></p></blockquote><p>An indicative proxy, not a bright line in the text. Where you don&#8217;t know the original training compute, which is most of the time, the guidance gives a fallback: </p><blockquote><p><em>one-third of 10&#178;&#179; floating-point operations, the same threshold that brings a model into scope as a general-purpose model in the first place.</em></p></blockquote><p>Now the reassuring part, before anyone panics. Almost no downstream fine-tuning comes anywhere near one-third of the compute that trained a frontier model. Training GPT-class models costs sums the majority of companies will never spend on anything, let alone on adjusting one. So the realistic outcome for the vast majority of teams fine-tuning a commercial or open model is that they do not become model providers. The threshold matters less as a trap people are constantly springing, and more as proof of where the real boundary sits: at the model, not at the technique. Fine-tuning is simply the most common way to walk up to that boundary.</p><p>And if you do cross it, <a href="https://artificialintelligenceact.eu/recital/109/">Recital 109 </a>softens the landing in a way that rarely survives into the law-firm summaries. Your obligations as the modifier are limited to the modification. You complement the existing technical documentation with information about what you changed. Your training-data summary and your copyright policy cover only the data and compute you added. You do not inherit the documentation burden for the entire original model, which you couldn&#8217;t produce anyway, because you didn&#8217;t train it. </p><p>That&#8217;s my reading of how 109 operates, and it&#8217;s the reading the guidance supports, though I&#8217;d want to see how the AI Office applies it before treating it as settled.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;48039a0d-45e1-4eb4-95f7-8bbadbc8f31c&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;What Did You Turn the Model Into?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null},{&quot;id&quot;:316763299,&quot;name&quot;:&quot;John Holman&quot;,&quot;bio&quot;:&quot;Awakened-Intelligence.com | AiValuations.org | AI systems architect &amp; MI researcher. We build research infrastructure including automated pipelines, model agnostic coherent continuity containers, fully deployed Ai evaluation frameworks. &quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/643a857c-5bf4-4bfa-8799-c84a4fd20774_960x958.png&quot;,&quot;is_guest&quot;:true,&quot;bestseller_tier&quot;:null,&quot;primaryPublicationSubscribeUrl&quot;:&quot;https://awakenedintelligence.substack.com/subscribe?&quot;,&quot;primaryPublicationUrl&quot;:&quot;https://awakenedintelligence.substack.com&quot;,&quot;primaryPublicationName&quot;:&quot;John Holman&quot;,&quot;primaryPublicationId&quot;:4323125}],&quot;post_date&quot;:&quot;2026-05-20T12:01:50.912Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!YPi-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe843f814-d2c0-4326-aaa9-a86f278556b5_3840x2160.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/what-did-you-turn-the-model-into&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:197544242,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:6,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>Roles Stack. They Don&#8217;t Swap.</h2><p>One thing I&#8217;d want a product team to understand even if they understood nothing else.</p><p>The fine-tune decision did not move your company out of one box and into another. It added a box.</p><p>Wrap the model, and you hold one role: provider of an AI system. Fine-tune past the threshold, and you hold two: provider of that same AI system, and, on top of it, provider of a general-purpose AI model. Not instead of. As well as. You were always the system provider the moment you built the tool, and nothing about modifying the model relieves you of that. It just stacks a second regulatory identity on top of the first.</p><p>And the second identity is its own job, with its own chapter. <a href="https://artificialintelligenceact.eu/chapter/5/">Chapter V</a> brings obligations that have nothing to do with the contract tool sitting on top and everything to do with the model itself: technical documentation drawn up to the standard of <a href="https://artificialintelligenceact.eu/annex/11/">Annex XI</a>, a duty to give downstream builders the information they need to comply with their own obligations (<a href="https://artificialintelligenceact.eu/article/53/">Article 53(1)(b)</a>), a policy for complying with EU copyright law including the text-and-data-mining opt-out, and a publicly available summary of what the model was trained on, using the template the AI Office provides. </p><p>Push the modified model past 10&#178;&#8309; floating-point operations, into systemic-risk territory under <a href="https://artificialintelligenceact.eu/article/51/">Article 51</a>, and the <a href="https://artificialintelligenceact.eu/article/55/">Article 55</a> obligations follow: model evaluations, adversarial testing, serious-incident reporting, cybersecurity measures. Downstream fine-tuners will essentially never hit that ceiling. But the first set of obligations lands the day you become a model provider, and it lands in addition to everything you already carried as the provider of the system.</p><p>One regulatory role, or two. Decided by a line on a sprint card, by people who were choosing, as far as they knew, between two equally good ways to make the tool work better.</p><div><hr></div><h2>Where This Gets Murky</h2><p>The wrap-versus-modify line is clean. </p><p>The threshold sitting on it is not, and honesty about that is the difference between guidance you can trust and guidance that gets you in trouble.</p><p>The one-third figure is indicative. It&#8217;s a compute ratio offered in non-binding guidance, and the fallback (one-third of 10&#178;&#179; FLOP, when you don&#8217;t know the base model&#8217;s training compute) was never meant to be a precise instrument. </p><p>A team fine-tuning close to the line, or building on a model whose training compute the provider has never disclosed, is working with an approximation. The direction is reliable: wrapping is safe, heavy modification is not. The exact boundary is soft, and the guidance may be revised. If you&#8217;re near it, that&#8217;s a <em>&#8220;document your reasoning and watch for updates&#8221;</em> situation, not a <em>&#8220;we did the math, we&#8217;re fine&#8221;</em> situation.</p><p>Two more things that get conflated and shouldn&#8217;t.</p><p>RAG keeps you out of model-provider territory, but it does not keep you out of trouble generally. Point a retrieval system at personal data, privileged material, or confidential client contracts, and you&#8217;ve created a GDPR and confidentiality problem that has nothing to do with the EU AI Act and everything to do with whether you should be shipping the thing at all. </p><p><em>&#8220;We only did RAG, not fine-tuning&#8221; </em>answers the question about your role under the EU AI Act. It does not answer the question about data protection, and the second question is often the one that bites first.</p><p>And fine-tuning below the threshold, while it doesn&#8217;t make you a model provider, still changes the system you provide. If that behavioral shift affects accuracy or bias in a deployment that is high-risk, it&#8217;s squarely relevant to your obligations as the <strong>system</strong> provider, under the data-governance and accuracy requirements in Articles <a href="https://artificialintelligenceact.eu/article/10/">10</a> and <a href="https://artificialintelligenceact.eu/article/15/">15</a>. </p><p>The threshold answers one question. It doesn&#8217;t answer all of them.</p><div><hr></div><h2>One Caveat About the Contract Tool Itself</h2><p>So the example doesn&#8217;t mislead anyone: plain commercial contract review, a tool a company runs over its own agreements, is not high-risk under the EU AI Act. It isn&#8217;t listed in Annex III. The provider obligations that attach to it are light: transparency where Article 50 applies, AI literacy under <a href="https://artificialintelligenceact.eu/article/4/">Article 4</a>, not a great deal beyond that.</p><p>That picture changes the moment the tool starts feeding decisions the AI Act cares about. Use it to screen job candidates and it falls into employment. Use it on behalf of a court to interpret and apply the law and it falls into the administration of justice (The trigger there is use by or for a judicial authority. The same tool run purely inside your own business isn&#8217;t caught). Use it to inform creditworthiness or insurance pricing and it falls into access to essential services. </p><p>All three are Annex III, all three are high-risk, and all three pull the full <a href="https://artificialintelligenceact.eu/chapter/3/">Chapter III</a> provider regime down on top of everything else. And if the tool profiles individuals, the off-ramp in <a href="https://artificialintelligenceact.eu/article/6/">Article 6(3)</a>, the one that lets you argue an Annex III system isn&#8217;t really high-risk, closes on you.</p><p>The risk question and the role question are separate, and both worth running. But the build point holds at every risk level: wrapping keeps you a system provider, and fine-tuning past the line makes you a model provider too. </p><p>High-risk or not, that&#8217;s still true.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>The Question to Ask Before Anyone Writes Code</h2><p>It isn&#8217;t <em>&#8220;is this high-risk&#8221;</em>. </p><p>That one comes later, and someone will eventually ask it, probably loudly, probably close to a deadline. </p><p>The question that gets skipped is the one the sprint card answered while you weren&#8217;t looking:</p><blockquote><p><em>Are we touching the model, or wrapping it?</em></p></blockquote><p>That single answer routes everything downstream of it. Wrap, and your compliance work tracks the system you built, and only that. Modify past the threshold, and you&#8217;ve acquired a second regulatory identity that needs its own documentation, on a clock that starts the day you ship, not the day you notice. </p><p>The question costs nothing to ask in a design review. It costs a great deal to answer in an audit, when the honest answer turns out to be &#8220;we touched it&#8221;, and the follow-up is &#8220;and who wrote that down&#8221;.</p><p>Put it in the AI inventory you should already be keeping. For every system built on someone else&#8217;s model, record one more field next to the role and the risk level: wrapped, or modified. Then set the trigger that matters, because this is the field most likely to change without anyone telling you. </p><p>The day someone decides to retrain, you reassess. Not the day you find the card. The card is still there, one line, an engineer&#8217;s shorthand for a decision that felt purely technical to everyone who touched it.</p><p><em>Approach: fine-tune the base model on our contract corpus.</em></p><p>You&#8217;d written three pages on what your company was under the EU AI Act. You&#8217;re now fairly sure it was a different number of pages than the company actually needed. And the thing that decided that wasn&#8217;t a lawyer, or a regulator, or a clause buried on page four hundred of the AI Act.</p><p>It was a sprint card. And no one thought of sending it to you.</p><div><hr></div><p><strong><a href="https://ailawdecoded.com/p/scope"><span data-color="#077d9a" style="color: rgb(7, 125, 154);">Scope</span></a><span data-color="#077d9a" style="color: rgb(7, 125, 154);"> is where this becomes something you can use in a meeting: the regulation map, the role assignment, the vendor questions, the AI inventory spreadsheet, the AI policy template, with sources attached and kept current as the law changes.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[Fable 5 Was Live for Three Days. Then the US Switched It Off.]]></title><description><![CDATA[What that means for every EU company that built on someone else's model.]]></description><link>https://ailawdecoded.com/p/fable-5-and-the-eu-ai-act</link><guid isPermaLink="false">https://ailawdecoded.com/p/fable-5-and-the-eu-ai-act</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 17 Jun 2026 12:03:53 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!TWhA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fe5c3c-37e1-4157-90d2-5f52489f68d2_6000x4000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TWhA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fe5c3c-37e1-4157-90d2-5f52489f68d2_6000x4000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TWhA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fe5c3c-37e1-4157-90d2-5f52489f68d2_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!TWhA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fe5c3c-37e1-4157-90d2-5f52489f68d2_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!TWhA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fe5c3c-37e1-4157-90d2-5f52489f68d2_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!TWhA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fe5c3c-37e1-4157-90d2-5f52489f68d2_6000x4000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TWhA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fe5c3c-37e1-4157-90d2-5f52489f68d2_6000x4000.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e7fe5c3c-37e1-4157-90d2-5f52489f68d2_6000x4000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:656379,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.substack.com/i/201979952?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fe5c3c-37e1-4157-90d2-5f52489f68d2_6000x4000.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TWhA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fe5c3c-37e1-4157-90d2-5f52489f68d2_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!TWhA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fe5c3c-37e1-4157-90d2-5f52489f68d2_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!TWhA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fe5c3c-37e1-4157-90d2-5f52489f68d2_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!TWhA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fe5c3c-37e1-4157-90d2-5f52489f68d2_6000x4000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>You chose the model carefully.</p><p>You read the documentation. You checked the provider had an EU representative. You logged it in your AI inventory, mapped it to the right obligations, maybe ran a DPIA. </p><p>You did the diligence. Then you built it in: the model now sits inside a product, or a workflow, or a process a few hundred people rely on without thinking about it.</p><p>On Friday evening it stopped existing.</p><p>On June 12, at 5:21pm Eastern time, the <a href="https://www.anthropic.com/news/fable-mythos-access">US government ordered Anthropic to cut off access to its two most capable models</a>, Fable 5 and Mythos 5, for any foreign national. Inside the US or outside it. Including Anthropic&#8217;s own foreign-national staff. Anthropic couldn&#8217;t separate the foreign users from everyone else fast enough to comply selectively, so it did the only thing that guaranteed compliance: it switched both models off for every customer on earth. Fable 5 had been publicly available for three days.</p><p>Somewhere in the EU, a company that built on Fable woke up to a product that no longer worked, and a question its compliance file did not answer.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>What the EU AI Act Promised You</h2><p>The EU AI Act has a great deal to say about a general-purpose AI provider, and almost all of it is reassuring.</p><p><a href="https://artificialintelligenceact.eu/chapter/5/">Chapter V</a> is the part that governs models like Fable and Mythos. Under <a href="https://artificialintelligenceact.eu/article/53/">Article 53</a>, the provider has to write and maintain technical documentation, and hand downstream users a package covering what the model is, what it can do, and how to integrate it.</p><p>Ask for more than that, and the picture gets softer. You will often hear that the provider has fourteen days to answer. The number is real, but it isn&#8217;t in Article 53. It comes from <a href="https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai">the General-Purpose AI Code of Practice</a>, which is voluntary. The Code binds only the providers who signed it, and even then the promise is only to respond <em>&#8220;within a reasonable timeframe, and no later than 14 days&#8221;,</em> save for exceptional circumstances. Article 53 obliges the provider to make the information available. It sets no deadline at all.</p><p>Under <a href="https://artificialintelligenceact.eu/article/54/">Article 54</a>, a provider based outside the EU has to appoint an authorised representative inside it. And because a frontier model of this size crosses the systemic-risk threshold in <a href="https://artificialintelligenceact.eu/article/51/">Article 51</a> (training compute above 10^25 floating-point operations creates a presumption of systemic risk), <a href="https://artificialintelligenceact.eu/article/55/">Article 55</a> piles on more: adversarial testing, systemic-risk assessment, serious-incident reporting to the AI Office, cybersecurity for the model and its infrastructure.</p><p>It is a serious set of obligations. Read them as a group and a pattern shows up.</p><p>Document. Disclose. Evaluate. Mitigate. Report. Secure. Appoint a representative.</p><p>Every one of them is about the provider&#8217;s conduct. Each answers a version of the same question: </p><blockquote><p><em>Is the provider behaving responsibly toward the people downstream and toward the regulator? </em></p></blockquote><p>It is a regime built to make the provider accountable, and on its own terms it does that well.</p><p>None of it answers the question the EU company actually had on Friday.</p><p>Will the model still be there tomorrow.</p><div><hr></div><h2>The Obligation That Isn&#8217;t There</h2><p>There is no continuity duty in Chapter V. </p><p>No obligation to keep the model available. No notice period before withdrawal. No requirement to warn downstream users that access is about to disappear, and certainly nothing about what happens when a government orders the lights off. </p><p>The EU AI Act built an elaborate structure of accountability around the provider and assumed, without ever saying so, that the provider would stay a stable, willing counterparty. Availability was never in question.</p><p>That assumption is the soft spot, and Fable walked straight into it.</p><p>The regulation spent its effort making the provider answerable to you and to the AI Office. </p><p>Last week&#8217;s events answered a question the regulation never asked: </p><blockquote><p><em>Who is the provider answerable to first? </em></p></blockquote><p>Within hours of a government letter, a commercial model serving hundreds of millions of people went dark, worldwide, and not one line of Chapter V slowed it down. The documentation package didn&#8217;t help. The fourteen-day response window didn&#8217;t help. The authorised representative had nothing to represent. The incident-reporting channel to the AI Office runs the wrong way for this: it tells Brussels what happened, after it happened.</p><p>The provider answers to its own government first. Everything the EU AI Act guarantees sits downstream of that fact.</p><div><hr></div><h2>Switching Is the Easy Part</h2><p>The obvious response is to move to another model, and often that&#8217;s genuinely easy. </p><p>Fable 5 and Opus 4.8 are both Anthropic. Same API, same SDK. You change the model name and you&#8217;re running again, possibly the same afternoon. The directive named specific models and left every other Anthropic model untouched, so Opus stayed up the whole time. For a lot of companies, the fallback was a one-line change.</p><p>Notice why it was available, though. Opus stayed up because Washington drew the line at Fable and Mythos, not because you arranged it that way. The scope of the order was the government&#8217;s choice, not yours. A one-line fallback works right up until the next letter names the provider instead of two models, and then the model you&#8217;d switch to is dark as well.</p><p>The easy path also narrows fast once the deployment is real. Move to a different company&#8217;s model and the prompts, the behaviour, and the evaluation results all have to be redone. Fine-tune a model and the tuning doesn&#8217;t travel. You retrain. Run the model somewhere regulated or safety-relevant, and the code change is the smallest part of the job. You tested, documented, and signed off on a specific model. Swapping it can mean re-running evaluations and rewriting documentation before the replacement is allowed to ship.</p><p>The model string changes in a minute. The revalidation doesn&#8217;t.</p><p>So it isn&#8217;t that you&#8217;re stranded. It&#8217;s that switching is often trivial and still doesn&#8217;t cover you, because the part you don&#8217;t control is the part that matters: not how hard the swap is, but how wide the next order reaches. </p><p><em>&#8220;Switch to Opus 4.8&#8221; </em>answers what happened on Friday. It says nothing about the day the order doesn&#8217;t stop at one model.</p><div><hr></div><h2>DORA Saw This Coming</h2><p>There is one corner of EU law that treats the availability of a third-party service as a regulated risk rather than an operational detail. It&#8217;s DORA, <a href="https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng">the Digital Operational Resilience Act</a>, which is in force since January 2025. </p><p>DORA makes financial firms keep documented exit plans (<a href="https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng#art_28">Article 28(8)</a>) and assess concentration risk, including whether a realistic substitute for a critical provider actually exists (<a href="https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng#art_29">Article 29</a>). If you are a bank or an insurer, you already have the muscle to ask the Fable question, because the law made you build it.</p><p>If you are anything else, you don&#8217;t.</p><p>DORA covers roughly twenty categories of financial entities. A hospital running a triage tool on a frontier model is not covered. Nor is a manufacturer, a software company, a university, a public authority. They get the EU AI Act&#8217;s safety and transparency guarantees but no continuity guarantee at all. The one EU rule that would have made them plan for a sudden provider shutdown simply doesn&#8217;t apply to them.</p><p>Even DORA is a smaller shield than it looks. The risks it imagines are outages, cyberattacks, insolvency: the ordinary ways a vendor fails. A foreign government switching the product off on a Friday isn&#8217;t in that taxonomy, and no standard force-majeure clause contemplates it either.</p><p>Worse, DORA&#8217;s designated critical providers are the big clouds: AWS, Google Cloud, Microsoft. Most EU firms reach Anthropic&#8217;s models through exactly those clouds. The cloud is on the register. But last week none of the clouds went down. The model did, pulled clean off the top of infrastructure that kept humming the whole time.</p><p>The dependency that actually failed sits one floor below where even the careful firms were looking.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>What to Take From This</h2><p>A few things worth doing before this stops being news.</p><p>1. <strong>Put the model on your register</strong> <strong>as its own dependency</strong>, separate from the cloud it runs on. If your third-party inventory stops at <em>AWS</em>, it does not describe what you&#8217;re actually exposed to.</p><p>2. <strong>Ask the DORA question whether or not DORA applies to you</strong>. If this specific model went dark tomorrow with no notice, what runs in its place, and how long until it does? Name a second model. Cost out the switch honestly. That number is your real exposure.</p><p>3. <strong>Know your own role, because it sets your own obligations.</strong> If you build the model into a system you put on the market, you&#8217;re a downstream provider with duties of your own and a right to the provider&#8217;s <a href="https://artificialintelligenceact.eu/annex/12/">Annex XII </a>documentation. If you only use it, you&#8217;re probably a deployer. The distinction matters a lot.</p><p>4. <strong>And read the EU AI Act for what it is.</strong> It makes your provider document, disclose, test, and report. It is a real set of protections and it is worth understanding. It just never promised the one thing you needed last week, and it is better to know that up front.</p><p>The compliance file you built was honest work. It described a provider doing everything the law requires: documented, transparent, tested, supervised. All of it true, and none of it load-bearing, because the model's availability wasn&#8217;t the provider's promise to give. It belonged to a government you have no standing in front of, under an authority no one disclosed, exercised in one afternoon. </p><p>You can hold a provider to account for how a model behaves. You cannot hold one to account for being switched off by someone else.</p><div><hr></div><p><strong><a href="https://ailawdecoded.com/p/scope"><span data-color="#077d9a" style="color: rgb(7, 125, 154);">Scope</span></a><span data-color="#077d9a" style="color: rgb(7, 125, 154);"> is where this becomes something you can use in a meeting: the regulation map, the role assignment, the vendor questions, the AI inventory spreadsheet, the AI policy template, with sources attached and kept current as the law changes.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[What's Your Role Under the EU AI Act? Practical Decision Tree.]]></title><description><![CDATA[Provider. Deployer. Importer. Distributor. Authorized Representative.]]></description><link>https://ailawdecoded.com/p/your-role-under-the-eu-ai-act-guide</link><guid isPermaLink="false">https://ailawdecoded.com/p/your-role-under-the-eu-ai-act-guide</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 10 Jun 2026 12:03:27 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Bh5p!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Bh5p!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Bh5p!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Bh5p!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Bh5p!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Bh5p!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Bh5p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:829816,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.substack.com/i/199877647?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Bh5p!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Bh5p!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Bh5p!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Bh5p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e75ba06-a16d-4314-8d1c-c0f8dd40c6cd_7680x4320.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>You&#8217;re in a meeting room with six people who&#8217;d rather be somewhere else. The subject line said &#8220;AI Act &#8212; Role Classification Workshop.&#8221; Two hours, blocked calendars, mandatory attendance. The energy is exactly what you&#8217;d expect.</p><p>You&#8217;ve got a shared spreadsheet on the screen. Every AI system the company uses, fourteen of them as of last Thursday&#8217;s count. You&#8217;re working through them one at a time. Column D says &#8220;Our Role Under the EU AI Act&#8221;. You type <em>deployer</em> for the first one. A vendor&#8217;s analytics tool. Easy. <em>Deployer</em> for the second, a customer service chatbot from a SaaS platform. <em>Deployer</em> for the third. You&#8217;re making good progress. Maybe this won&#8217;t take two hours.</p><p>Then the head of data science mentions, casually, like it&#8217;s obvious, that his team has been fine-tuning one of the vendor models on the company&#8217;s proprietary data for the past six months. &#8220;Same tool, just trained on our stuff.&#8221; You stop typing.</p><p>Someone from marketing adds that they rebranded the vendor&#8217;s customer-facing interface. The company&#8217;s logo, the company&#8217;s name, the company&#8217;s colour scheme. &#8220;It just looked better.&#8221; You look at column D.</p><p>Then the colleague from the EU subsidiary, the one who joined the call from Frankfurt, asks a question you weren&#8217;t expecting: &#8220;We&#8217;re the ones who brought the US vendor&#8217;s system into Europe. Does that make us the importer?&#8221;</p><p>Your clean column of <em>deployer, deployer, deployer</em> now has three question marks. And you&#8217;re not even halfway through the list.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>The Question Before All Other Questions</h2><p>The EU AI Act has a lot of moving parts: risk classification, conformity assessment, prohibited practices, transparency obligations, deadlines that keep shifting. But before any of that matters, there&#8217;s a prior question:</p><blockquote><p><em>What are you?</em></p></blockquote><p>Your role determines your obligations. A deployer&#8217;s life fits on one page: operational duties, human oversight, inform people when AI is making decisions about them. A provider&#8217;s life is a different job entirely. Quality management system. Technical documentation. Conformity assessment. CE marking. Post-market monitoring. Incident reporting. The difference between the two isn&#8217;t negligible. </p><p>And unlike GDPR, where both controllers and processors carry real obligations, the EU AI Act creates a sharp asymmetry. Getting your role wrong means either over-investing in obligations you don&#8217;t have, or not meeting obligations you do. Neither is free.</p><p>The regulation defines five roles. Many commentaries cover only two. This piece covers all five and gives you a way to assign them.</p><p><em>If you&#8217;re not sure whether the EU AI Act applies to your company at all, especially if you&#8217;re outside the EU, that question comes before this one.</em></p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;cd5d9c5c-f86f-4f5b-a3c9-0fdfc49927c6&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Why the EU AI Act Matters Even If You're Not in the EU&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-05T13:54:22.853Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!wrLn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb08944ca-a6dd-44b0-a118-8176d76942bc_4500x3000.heic&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/eu-ai-act-applies-outside-eu&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193044187,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>The Five Roles: </h2><h3>1. Provider &#8212; <a href="https://artificialintelligenceact.eu/article/3/">Article 3(3)</a></h3><p>A person or entity that develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark. Whether for payment or free of charge.</p><p>Two elements, both required. First: you developed it, or you had someone develop it for you. Second: your name is on it. Miss either element and the definition doesn&#8217;t apply.</p><p>The part that catches companies: <em>&#8220;puts it into service&#8221; </em><strong>includes internal use</strong>. A company that builds an AI system for its own operations, not selling it, not licensing it, is a provider. It developed the system and put it into service under its own name. The fact that it never left the building doesn&#8217;t matter. </p><p>&#8220;Provider&#8221; doesn&#8217;t mean &#8220;seller&#8221;.</p><h3>2. Deployer &#8212; <a href="https://artificialintelligenceact.eu/article/3/">Article 3(4)</a></h3><p>A person or entity using an AI system under its authority, except for personal non-professional use.</p><p>The simplest definition and the most common role. You bought or licensed an AI system. You use it in your business. You didn&#8217;t build it. You didn&#8217;t put your name on it. Deployer.</p><p><em>&#8220;Under its authority&#8221;</em> means the company controls the deployment, not the individual employee who clicks the button. The company is the deployer. The employee is the user. This matters because deployer obligations (monitoring, human oversight, informing affected people) attach to the entity with operational control.</p><p>However, the risk here is that this role can change without you noticing. Rebrand the system, substantially modify it, or repurpose it into a high-risk use case, and <a href="https://artificialintelligenceact.eu/article/25/">Article 25</a> transforms you into a provider. No grace period. No transition window. The moment it happens, provider obligations apply.</p><p><em>For the deep dive on when a deployer becomes a provider, including the substantial modification analysis and what &#8220;foreseen in the conformity assessment&#8221; actually requires, see the separate piece:</em></p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;fc7d8a79-1ed1-4392-b434-d471d33d0b69&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Provider vs. Deployer Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-22T12:03:43.719Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!NS5L!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35f75bb-44f2-45d4-b53c-84654d8e8617_8192x5461.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/provider-vs-deployer-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:194314202,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:5,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h3>3. Importer &#8212; <a href="https://artificialintelligenceact.eu/article/3/">Article 3(6)</a></h3><p>An EU-based entity that places a non-EU provider&#8217;s AI system on the Union market, where the system bears the non-EU provider&#8217;s name or trademark.</p><p>The importer is the compliance gatekeeper at the EU border. They don&#8217;t need to understand the system&#8217;s internals the way the provider does. They need to verify that the paperwork is in order: conformity assessment done, technical documentation marked down, CE marking affixed, authorized representative appointed (<a href="https://artificialintelligenceact.eu/article/23/">Article 23</a>).</p><p>Two things make this role less straightforward than it sounds: </p><p><strong>First: </strong>it was designed for physical supply chains. Products crossing borders, intermediaries handling goods. For cloud-based AI systems delivered as SaaS, the concept of <em>&#8220;placing on the market&#8221;</em> doesn&#8217;t map cleanly. If a US company offers an AI system directly to EU customers through its website, with no intermediary, there&#8217;s no importer. The US company is the provider, subject to the regulation through its mandatory authorized representative.</p><p><strong>Second: </strong>if the importer puts its own name on the system instead of the non-EU provider&#8217;s, that&#8217;s rebranding. Article 25(1)(a) kicks in. The importer becomes the provider. Congratulations on your new compliance obligations.</p><h3>4. Distributor &#8212; <a href="https://artificialintelligenceact.eu/article/3/">Article 3(7)</a></h3><p>An entity in the supply chain, other than the provider or the importer, that makes an AI system available on the Union market.</p><p>The lightest role. A tech reseller. A value-added reseller bundling an AI system with other services. A retailer stocking AI-enabled devices. The distributor&#8217;s job is verification: check the CE marking, check the conformity documentation, don&#8217;t distribute non-compliant systems, report problems up the chain (<a href="https://artificialintelligenceact.eu/article/24/">Article 24</a>).</p><p>The <em>&#8220;value-added&#8221;</em> part of value-added reseller is where the role gets fragile. If the value you&#8217;re adding involves modifying the system, training it on custom data, or rebranding it, you may have crossed from distributor into provider territory. Article 25 applies to distributors too. </p><p>The lightest role in the regulation turns out to have a trapdoor.</p><h3>5. Authorized representative &#8212; Articles <a href="https://artificialintelligenceact.eu/article/22/">22</a> and <a href="https://artificialintelligenceact.eu/article/54/">54</a></h3><p>An EU-based entity appointed by a non-EU provider, through a written mandate, to perform certain compliance obligations on the provider&#8217;s behalf.</p><p>This isn&#8217;t an optional service. Non-EU providers of high-risk AI systems must appoint one before making their systems available in the EU (<a href="https://artificialintelligenceact.eu/article/22/">Article 22</a>). Non-EU providers of general-purpose AI models must do the same (<a href="https://artificialintelligenceact.eu/article/54/">Article 54</a>).</p><p>Three things about this role that aren&#8217;t obvious:</p><ul><li><p>The authorized representative can be fined. They qualify as an <em>&#8220;operator&#8221;</em> under Article 3(8). The same penalties that apply to providers (up to &#8364;15 million or 3% of global annual turnover) apply to them. This is not a paperwork role. It&#8217;s a liability position.</p></li><li><p>The authorized representative must blow the whistle on its own client. Article 22(4): if the representative considers or has reason to consider the provider is acting contrary to its AI Act obligations, it must terminate the mandate and immediately inform market surveillance authorities. Not <em>may</em>. Must. The regulation built a compliance-cop function into what looks like a commercial relationship.</p></li><li><p>And for GPAI models, the representative&#8217;s exposure extends beyond the model itself. They must cooperate with authorities investigating downstream AI systems that integrated the GPAI model, even though their mandate comes from the model provider, not the system provider.</p></li></ul><p>Who needs to think about this role? </p><ul><li><p>Non-EU companies selling high-risk AI into the EU (they need to appoint one),</p></li><li><p>EU-based companies buying from non-EU providers (importers must verify one exists under Article 23(1)(d)), and </p></li><li><p>EU entities considering serving as authorized representatives (they need to understand the liability before they sign).</p></li></ul><div><hr></div><h2>The Decision Tree</h2><p>To decide on your company&#8217;s role, for each AI system your company touches (not once per company, once per system) walk through these steps:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dex0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f1bbc5-2905-4a15-959e-283a05d59c8e_1440x1960.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dex0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f1bbc5-2905-4a15-959e-283a05d59c8e_1440x1960.png 424w, https://substackcdn.com/image/fetch/$s_!dex0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f1bbc5-2905-4a15-959e-283a05d59c8e_1440x1960.png 848w, https://substackcdn.com/image/fetch/$s_!dex0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f1bbc5-2905-4a15-959e-283a05d59c8e_1440x1960.png 1272w, https://substackcdn.com/image/fetch/$s_!dex0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f1bbc5-2905-4a15-959e-283a05d59c8e_1440x1960.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dex0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f1bbc5-2905-4a15-959e-283a05d59c8e_1440x1960.png" width="1440" height="1960" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/10f1bbc5-2905-4a15-959e-283a05d59c8e_1440x1960.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1960,&quot;width&quot;:1440,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:160857,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.substack.com/i/199877647?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f1bbc5-2905-4a15-959e-283a05d59c8e_1440x1960.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dex0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f1bbc5-2905-4a15-959e-283a05d59c8e_1440x1960.png 424w, https://substackcdn.com/image/fetch/$s_!dex0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f1bbc5-2905-4a15-959e-283a05d59c8e_1440x1960.png 848w, https://substackcdn.com/image/fetch/$s_!dex0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f1bbc5-2905-4a15-959e-283a05d59c8e_1440x1960.png 1272w, https://substackcdn.com/image/fetch/$s_!dex0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f1bbc5-2905-4a15-959e-283a05d59c8e_1440x1960.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Step 1: Did you develop (or have developed) the AI system?</h3><p><strong>YES, </strong><em><strong>and</strong></em><strong> </strong>your name or trademark is on it? <strong>You are a provider.</strong> Full provider obligations apply under Articles 16-21. This includes internal use. If you built it for your own operations, you&#8217;re <em>&#8220;putting it into service&#8221;</em> under your own name, which is one of the two paths to provider status alongside <em>&#8220;placing on the market&#8221;.</em></p><p><strong>YES, </strong><em><strong>but</strong></em><strong> </strong>someone else&#8217;s name is on it? The entity branding it is likely the provider. <strong>You&#8217;re a development contractor.</strong> Your obligations should be governed by a written agreement (Article 25(3)), but you&#8217;re not the provider under the regulation.</p><p><strong>NO:</strong> go to Step 2.</p><h3>Step 2: Are you using an AI system under your authority for business purposes?</h3><p><strong>YES:</strong><em><strong> </strong>provisionally,</em> <strong>you&#8217;re a</strong> <strong>deployer</strong>. But before you stop here, check the <a href="https://artificialintelligenceact.eu/article/25/">Article 25 </a>triggers:</p><ol><li><p><strong>Have you put your name or trademark on a high-risk AI system that was already on the market?</strong> If so, you&#8217;re now a provider under Article 25(1)(a).</p></li><li><p><strong>Have you made a substantial modification to a high-risk AI system?</strong> A modification not foreseen in the original conformity assessment that affects compliance or changes the intended purpose? You&#8217;re a provider under Article 25(1)(b). If you&#8217;re not sure whether your modification qualifies (and this is the hardest question in the entire regulation) the <em><a href="https://ailawdecoded.substack.com/p/provider-vs-deployer-eu-ai-act">Provider vs. Deployer article</a></em> covers the analysis in detail. The short version: if you&#8217;ve changed the model architecture, modified decision logic beyond vendor-specified parameters, or used the system for a purpose the vendor didn&#8217;t assess, treat yourself as a provider until you can confirm otherwise.</p></li><li><p><strong>Have you changed the intended purpose of an AI system so that it now falls into a high-risk category?</strong> If so, you&#8217;re a provider under Article 25(1)(c). No code change required. Just a different use case.</p></li></ol><p>None of the above? <strong>You&#8217;re a deployer.</strong> <a href="https://artificialintelligenceact.eu/article/26/">Article 26</a> obligations apply.</p><p><strong>NO:</strong> go to Step 4.</p><h3>Step 3: Are you in the supply chain?</h3><p><strong>YES </strong><em><strong>and</strong></em><strong> </strong>you are<strong> </strong>first EU-based entity placing a non-EU provider&#8217;s system on the market (under the non-EU provider&#8217;s name)?<strong> You&#8217;re an</strong> <strong>importer</strong>. Obligations under <a href="https://artificialintelligenceact.eu/article/23/">Article 23</a> apply to you.</p><p><strong>YES </strong><em><strong>but</strong></em><strong> </strong>another entity in the supply chain making it available? <strong>You&#8217;re a</strong> <strong>distributor</strong>. Obligations under <a href="https://artificialintelligenceact.eu/article/24/">Article 24</a> apply to you.</p><p><strong>NO:</strong> go to Step 4.</p><h3>Step 4: Are you a non-EU provider?</h3><p><strong>YES:</strong> You must appoint an <strong>authorized representative</strong> in the EU. Obligations under Articles <a href="https://artificialintelligenceact.eu/article/22/">22</a> or <a href="https://artificialintelligenceact.eu/article/54/">54</a> apply to you, depending on whether you are providing a high-risk AI system or GPAI model.</p><p><strong>NO: </strong>None of the above? Check <a href="https://artificialintelligenceact.eu/article/2/">Article 2.</a> You might be outside the scope entirely. Personal non-professional use is excluded. Research, testing, and development before market placement or putting into service are excluded. Systems for exclusively military purposes are excluded.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;9304926e-664f-4777-b3ab-5a258bbf29f8&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;What Is an AI System, Actually?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-08T12:03:14.634Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!Lj3S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6c33bfb-66f1-4bc7-aba6-ed6c0d1df60e_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/ai-system-definition-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193355320,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:3,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>The GPAI Layer &#8212; When Foundation Models Complicate the Picture</h2><p>If you&#8217;re building anything on top of a foundation model, and in 2026 that covers a lot of companies, the role question has an extra dimension.</p><p>Most modern AI deployments involve at least two regulatory actors. Sometimes three.</p><p><strong>Layer 1:</strong> The GPAI model provider. OpenAI for GPT, Anthropic for Claude, Meta for Llama, Google for Gemini. Obligations under <a href="https://artificialintelligenceact.eu/chapter/5/">Chapter V</a>: technical documentation, copyright compliance, training data summaries, and for systemic-risk models, evaluation and adversarial testing.</p><p><strong>Layer 2:</strong> The AI system provider. The company that takes the foundation model and wraps it in a product: a chatbot, a document analyzer, a recruitment screener, a diagnostic tool. If that system is high-risk, full provider obligations under <a href="https://artificialintelligenceact.eu/chapter/3/">Chapter III</a> apply.</p><p><strong>Layer 3:</strong> The deployer. The company using the system in its operations. <a href="https://artificialintelligenceact.eu/article/26/">Article 26</a>.</p><p>Each layer carries its own obligations. The GPAI model provider&#8217;s obligations don&#8217;t cover the system built on top of the model. The system provider&#8217;s obligations don&#8217;t reach down into the model&#8217;s architecture. Separate tracks, separate responsibilities.</p><h3>Four scenarios</h3><p><strong>You use ChatGPT through the web interface for general business tasks.</strong> You&#8217;re a deployer. OpenAI is the provider of both the GPAI model and the AI system. You&#8217;re using it. That&#8217;s it.</p><p><strong>You integrate the OpenAI API into your own product and sell it.</strong> You&#8217;re the provider of an AI system. OpenAI is the GPAI model provider at Layer 1. You built the system at Layer 2. If your system is high-risk (credit scoring built on GPT, for example) full provider obligations apply to you. OpenAI&#8217;s obligations are at the model level, not the system level.</p><p>A practical complication: your ability to comply depends partly on what the GPAI model provider gives you. <a href="https://artificialintelligenceact.eu/article/53/">Article 53(1)(b)</a> and <a href="https://artificialintelligenceact.eu/annex/12/">Annex XII</a> require GPAI model providers to share information about the model&#8217;s capabilities, limitations, and risks, information you need for your technical documentation and risk assessment. If that documentation is thin, you face a compliance gap that isn&#8217;t fully within your control. Your contracts with the GPAI model provider need to address this. </p><p><strong>You fine-tune an open-source model (Llama, for example) and deploy the resulting system.</strong> You&#8217;re the provider of whatever AI system you build with the fine-tuned model. Whether you also become a GPAI model provider depends on how far you went. The <a href="https://digital-strategy.ec.europa.eu/en/library/guidelines-scope-obligations-providers-general-purpose-ai-models-under-ai-act">Commission&#8217;s GPAI Guidelines</a> use an indicative threshold: if the compute used for fine-tuning exceeds <em><strong>one-third</strong></em> of the compute used to train the base model, you may become a GPAI model provider for the modified model. Most fine-tuning falls well below this.</p><p>One thing that doesn&#8217;t cascade: Meta&#8217;s open-source exemption. The lighter GPAI model provider obligations that Meta benefits from don&#8217;t extend to you. Your obligations as the AI system provider are unaffected by what the model provider&#8217;s obligations look like. Their exemption is theirs.</p><p><strong>You build a RAG system on a foundation model via API.</strong> You connect a foundation model to your company&#8217;s knowledge base and deploy it as an internal tool or customer-facing assistant. You are the AI system provider. <em>If you also use it internally, you&#8217;re both provider and deployer of the same system.</em></p><div><hr></div><h2>Multiple Roles: the Norm, Not the Exception</h2><p>The EU AI Act doesn&#8217;t prevent a single entity from holding multiple roles simultaneously. In practice, most companies of any size will.</p><p>A company that builds a proprietary AI tool for its core product (provider) while using off-the-shelf AI tools from vendors for HR, marketing, or operations (deployer for each). Three, four, five different role classifications across different systems. That part is straightforward. The harder versions:</p><h3>Provider AND deployer of the same system</h3><p>A company that builds an AI system for its own internal use. It&#8217;s a provider because it developed the system and put it into service under its own name (Article 3(3)). It&#8217;s also a deployer because it&#8217;s using the system under its authority (Article 3(4)). No mutual exclusivity clause in the regulation.</p><p>The dual classification matters because the deployer role creates specific obligations the provider role alone doesn&#8217;t cover.</p><p><a href="https://artificialintelligenceact.eu/article/26/">Article 26(11)</a>: informing affected natural persons. The provider&#8217;s transparency obligation runs toward deployers (instructions for use). The deployer&#8217;s obligation runs toward the people affected by the system&#8217;s output. When you&#8217;re both, you bear both transparency flows.</p><p><a href="https://artificialintelligenceact.eu/article/26/">Article 26(7)</a>: informing workers&#8217; representatives before deployment. This triggers through the deployer role, not the provider role.</p><p><a href="https://artificialintelligenceact.eu/article/27/">Article 27</a>: the fundamental rights impact assessment. For public bodies and certain private entities, this obligation applies per the deployer role. A public hospital that builds its own diagnostic AI is a provider, but the FRIA triggers through its deployer capacity.</p><p><a href="https://artificialintelligenceact.eu/article/26/">Article 26(2)</a>: human oversight. Providers must design systems to enable oversight (<a href="https://artificialintelligenceact.eu/article/14/">Article 14</a>). Deployers must assign competent, trained people to perform it. When you&#8217;re both, you must do both. Design the capability and staff the function. Different obligations, same entity.</p><h3>Distributor who starts customizing</h3><p>A reseller distributes a vendor&#8217;s AI system. Over time, the reseller starts offering a <em>&#8220;customized&#8221;</em> version: training the system on industry-specific data, adjusting parameters, putting its own logo on the interface. The reseller started as a distributor. It may have crossed into provider territory through substantial modification or rebranding. The obligations don&#8217;t shift gradually. They shift all at once, the moment Article 25 triggers. One day you&#8217;re checking CE markings. The next you need a conformity assessment.</p><h3>The practical implication</h3><p>Don&#8217;t assign one role to the company. Assign roles system-by-system. Build a register that tracks, for each AI system: what it is, what your role is, when you last assessed that role, and what would trigger reassessment (modification, retraining, new use case, contract renewal).</p><p>One note on risk categories for that register: the EU AI Act doesn&#8217;t use the terms &#8220;limited-risk&#8221; or &#8220;minimal-risk.&#8221; Those are common shorthand but not regulatory categories. The actual tiers: prohibited practices (<a href="https://artificialintelligenceact.eu/article/5/">Article 5</a>), high-risk systems (<a href="https://artificialintelligenceact.eu/article/6/">Article 6</a>, Annexes <a href="https://artificialintelligenceact.eu/annex/1/">I</a> and <a href="https://artificialintelligenceact.eu/annex/3/">III</a>), systems with specific transparency obligations (<a href="https://artificialintelligenceact.eu/article/50/">Article 50</a>), and everything else.</p><div><hr></div><h2>The Grey Zones</h2><h3>&#8220;Had developed&#8221; and whose name is on it</h3><p>The provider definition has two cumulative elements: develops or has developed, AND places on market or puts into service under its own name or trademark. Both must be present.</p><p>A company commissions a vendor to build a custom AI system. The vendor brands it. Even if the company &#8220;had it developed&#8221; (detailed specs, iterative reviews, full design control) the vendor&#8217;s name is on the product. The company isn&#8217;t the provider. The vendor is. The company is a deployer of a customized product. That part is clear.</p><p>The real grey zones are elsewhere. A company commissions a system for internal use. No product label, no marketing, no brand on the interface. Whose &#8220;name&#8221; is it under? Internal deployment might constitute putting into service under your own name. The company is the entity operating the system and taking responsibility. But the regulation was written with market-facing branding in mind, not internal tools. The text doesn&#8217;t address this directly.</p><p>Or: two companies co-develop an AI system. Both contribute to the design. Both names appear. Article 3(3) doesn&#8217;t say there can be only one provider. But the regulation&#8217;s obligations (conformity assessment, technical documentation, quality management) are designed for a single accountable entity. How do you split them between two co-providers? The regulation doesn't directly address this. Article 25(3) requires written agreements when a deployer, distributor, or importer assumes provider status &#8212; a succession scenario, not a joint-development one. By analogy, co-providers would need a similar agreement allocating obligations, but the text doesn't prescribe one. The regulatory classification itself remains ambiguous.</p><h3>SaaS and the importer question</h3><p>The importer and distributor roles were designed for physical products. A US company offering an AI SaaS directly to EU customers, with no intermediary, creates no importer. No distributor. The US company is the provider, subject to the regulation through its authorized representative.</p><p>An EU company reselling access to a US-built AI SaaS might be an importer or a distributor. But <em>&#8220;placing on the market&#8221;</em> was defined in Article 3(9) for products, not services. The definition is doing a job it wasn&#8217;t designed for.</p><p>For most companies: if you&#8217;re using an AI SaaS tool, you&#8217;re a deployer. The SaaS vendor is the provider. Importer and distributor questions arise mainly for companies that resell or redistribute AI products, not end users.</p><h3>Embedded AI and the Omnibus</h3><p>AI embedded in a medical device, a car, an industrial machine. The EU AI Act applies alongside the relevant sectoral legislation: Medical Devices Regulation, Vehicle Safety Regulation, Machinery Regulation. Who&#8217;s the AI system provider? The product manufacturer? The AI component supplier?</p><p>The Digital Omnibus on AI, the simplification package provisionally agreed on May 7, 2026, changes this picture.</p><p>Machinery products with embedded AI are now exempted from AI Act high-risk obligations entirely. They comply with the Machinery Regulation only. For other sectors (medical devices, automotive, aviation) the Commission can adopt implementing acts to limit the AI Act&#8217;s application where sectoral legislation already covers equivalent ground. Until those implementing acts land, the overlap persists.</p><p>The omnibus also extended timelines. Standalone Annex III high-risk systems: <strong>2 December 2027</strong> (pushed from August 2026). Annex I product-embedded systems: <strong>2 August 2028</strong> (pushed from August 2027). Obligations already live (prohibited practices, AI literacy) are unaffected.</p><p><em>The omnibus is provisional as of June 2026. Formal adoption is expected before August 2026. Verify the adopted text before acting on the extended timelines.</em></p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;6a2f68a6-07e9-4c1b-af72-c2e59589dd9f&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;EU AI Act Amended: The Digital Omnibus Timeline&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-13T12:02:43.130Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!DR18!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/eu-ai-act-amended-the-digital-omnibus&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:196926473,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:3,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>The Practical Steps </h2><h3>1. Build the AI inventory</h3><p>Before you can assign roles, you need to know what AI systems your organization touches. This is harder than it sounds. AI is embedded in tools people don&#8217;t think of as &#8220;AI&#8221;. </p><p>What to inventory: </p><ul><li><p>systems you built or commissioned (provider candidates), </p></li><li><p>systems you bought or licensed (deployer candidates), </p></li><li><p>systems you resell (distributor or importer candidates), </p></li><li><p>foundation models you build on (system provider candidates), </p></li><li><p>AI-powered features within broader platforms you use (deployer candidates). </p></li></ul><p>And the one that keeps surfacing in every assessment I&#8217;ve seen: AI systems employees are using without formal procurement. <em>Shadow AI.</em> You&#8217;re still potentially a deployer.</p><h3>2. Classify risk, then assign roles</h3><p>For each system, determine the risk level first. Is it high-risk? Most EU AI Act obligations for deployers, importers, and distributors only apply to high-risk systems. Providers carry some obligations regardless (AI literacy under <a href="https://artificialintelligenceact.eu/article/4/">Article 4</a>, transparency under <a href="https://artificialintelligenceact.eu/article/50/">Article 50</a>), but the heavy requirements are for high-risk.</p><p>Then run each system through the decision tree. Document your reasoning. This isn&#8217;t just good practice. It&#8217;s the evidence a regulator will want to see.</p><h3>3. Check for Article 25 triggers</h3><p>For every system where you&#8217;re initially a deployer, distributor, or importer, check whether anything you&#8217;ve done transforms your role. Rebranding. Substantial modification. Repurposing into a high-risk category. If any of these apply, you&#8217;re a provider for that system. </p><h3>4. Map the GPAI layer</h3><p>For every system built on a foundation model: identify the GPAI model provider, confirm they&#8217;re providing the <a href="https://artificialintelligenceact.eu/annex/12/">Annex XII</a> information you need, and ensure your contracts address the information-sharing gap. If you&#8217;ve fine-tuned the model, check the one-third compute threshold from the <a href="https://digital-strategy.ec.europa.eu/en/library/guidelines-scope-obligations-providers-general-purpose-ai-models-under-ai-act">Commission&#8217;s GPAI Guidelines</a>.</p><h3>5. Check cross-border dynamics</h3><p>Non-EU provider? Has it appointed an authorized representative? Are you the first EU entity handling the system? That might make you the importer.</p><h3>6. Document and revisit</h3><p>Role assignment isn&#8217;t a one-time exercise. Set triggers for reassessment: every modification or retraining, every new use case, every contract renewal. When the Commission publishes guidance (particularly the still-pending guidance on substantial modification) reassess in light of it.</p><p>At minimum: annually.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>Column D Problem</h2><p>It&#8217;s been ninety minutes. The spreadsheet has changed. Column D has a mix of <em>provider</em>, <em>deployer</em>, one <em>importer</em>, and four entries that say <em>needs further assessment</em>. The head of data science is having a quiet crisis about the fine-tuning. Marketing is Googling &#8220;rebranding AI Act Article 25&#8221;. The colleague from Frankfurt is reading Article 23 on her phone.</p><p>This is the meeting nobody wanted to have. And it&#8217;s the most important meeting the company will have about the EU AI Act, because every other question depends on this one. Risk classification depends on your role. Obligations depend on your role. Deadlines, documentation, conformity assessment: all of it flows from what you are.</p><p>The answers exist. The definitions are in Article 3. The transformation triggers are in Article 25. The obligations are in Articles 16-26. The decision tree works.</p><p>The answers are also per system, not per company. They change when the system changes. And the regulation doesn&#8217;t wait for you to figure it out.</p><p>Column D isn&#8217;t going to fill itself.</p><div><hr></div><p><strong><a href="https://ailawdecoded.com/p/scope"><span data-color="#077d9a" style="color: rgb(7, 125, 154);">Scope</span></a><span data-color="#077d9a" style="color: rgb(7, 125, 154);"> is where this becomes something you can use in a meeting: the regulation map, the role assignment, the vendor questions, the AI inventory spreadsheet, the AI policy template, with sources attached and kept current as the law changes.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[Agentic AI Under the EU AI Act]]></title><description><![CDATA[When the regulation meets systems that act independently.]]></description><link>https://ailawdecoded.com/p/agentic-ai-under-the-eu-ai-act</link><guid isPermaLink="false">https://ailawdecoded.com/p/agentic-ai-under-the-eu-ai-act</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 03 Jun 2026 12:03:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!VHg5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6c9d56f-d86d-465b-b53d-ae335110c026_6000x4000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VHg5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6c9d56f-d86d-465b-b53d-ae335110c026_6000x4000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VHg5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6c9d56f-d86d-465b-b53d-ae335110c026_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!VHg5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6c9d56f-d86d-465b-b53d-ae335110c026_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!VHg5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6c9d56f-d86d-465b-b53d-ae335110c026_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!VHg5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6c9d56f-d86d-465b-b53d-ae335110c026_6000x4000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VHg5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6c9d56f-d86d-465b-b53d-ae335110c026_6000x4000.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c6c9d56f-d86d-465b-b53d-ae335110c026_6000x4000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:20333863,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.substack.com/i/199299205?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6c9d56f-d86d-465b-b53d-ae335110c026_6000x4000.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!VHg5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6c9d56f-d86d-465b-b53d-ae335110c026_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!VHg5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6c9d56f-d86d-465b-b53d-ae335110c026_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!VHg5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6c9d56f-d86d-465b-b53d-ae335110c026_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!VHg5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6c9d56f-d86d-465b-b53d-ae335110c026_6000x4000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>You built the oversight process. Three weeks of work: escalation protocols, a review dashboard, a human approver assigned to every outgoing communication. </p><p>Your company is deploying a customer retention agent. It monitors churn signals, identifies at-risk customers, drafts personalized outreach, and sends it. High-risk? Depends on what it touches. </p><p>But you wanted oversight. Real oversight. Not a checkbox.</p><p>It&#8217;s Tuesday morning. You open the dashboard. The agent processed 47 customer interactions overnight. Emails drafted. Emails sent. Responses received. Follow-ups scheduled. Two discount offers extended, one at a rate that hasn&#8217;t been approved before. One message references a customer&#8217;s medical situation, pulled from a support ticket the agent accessed through the CRM.</p><p>Your human reviewer saw the first three messages. Approved them. Went home at 6pm. The agent didn&#8217;t go home.</p><p>You&#8217;re looking at the log. Not proposed actions. Completed ones. </p><p>And the oversight process you spent three weeks building (the one modeled on <a href="https://artificialintelligenceact.eu/article/14/">Article 14</a> of the EU AI Act, which requires that high-risk systems be designed so humans can effectively oversee them) assumed something that turned out to be false.</p><p>It assumed the human would see the output before it took effect.</p><p>Your agent doesn&#8217;t work that way. It acts first. The human reviews after. If at all.</p><p>You&#8217;re not the only one with this problem. </p><p>The European Commission just noticed it too.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>What Makes an Agent Different</h2><p>If you&#8217;ve used ChatGPT or Claude or any other AI chatbot, you&#8217;ve used a system that follows a simple pattern: you ask a question, the system generates an answer, you decide what to do with it. </p><p>Input, output, human decision. The EU AI Act was drafted around this model.</p><p>An AI agent breaks the pattern.</p><p>An agent doesn&#8217;t just answer your question. It pursues a goal. Give it <em>&#8220;reduce customer churn&#8221;</em> and it will plan a strategy, access your customer database, analyze behavior patterns, draft communications, send them, read the responses, and adjust its approach, chaining actions together, using the output of one step as the input for the next.</p><p>A traditional AI system is like a consultant who writes you a memo. You read it, you decide, you act. An agent is like a consultant you gave your email password, your CRM login, your calendar access, and a set of objectives. Then you went on vacation. When you come back, things have happened.</p><p><em>The critical components:</em> a language model that handles reasoning and planning (the <em>&#8220;brain&#8221;</em>: GPT-4, Claude, Gemini). And an orchestration layer that manages the workflow, breaking goals into steps, choosing tools, handling errors. </p><p><em>Tools that let the agent act in the world, not just generate text:</em> APIs, databases, email systems, calendars, code execution environments. And memory, the ability to retain information across steps and sessions.</p><p>That combination of reasoning, tools, and autonomy is what makes it agentic. And it&#8217;s what breaks three assumptions the EU AI Act was built on.</p><p><strong>Assumption one</strong>: <em>the system has a defined, bounded purpose. </em>Agents can pursue open-ended goals across multiple domains. An agent told to <em>&#8220;improve customer satisfaction&#8221; </em>might end up accessing HR data, modifying product descriptions, and sending emails to suppliers. None of which was the &#8220;<em><strong>intended purpose&#8221;</strong></em> anyone documented.</p><p><strong>Assumption two:</strong> <em>a human reviews the output before it takes effect.</em> Agents act. The output <em>is</em> the action. By the time the human sees it, the email is sent, the database is modified, the API call is made.</p><p><strong>Assumption three:</strong> <em>there&#8217;s a clear provider and deployer.</em> Agent deployments involve a model provider, a framework developer, tool providers, the company that assembled the agent, and the company that runs it. The AI Act&#8217;s two-party model doesn&#8217;t map cleanly onto a five-party stack.</p><p>None of this means agents fall outside the EU AI Act. They don&#8217;t. But they stress the framework in ways the drafters didn&#8217;t anticipate, and the Commission is just starting to respond.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;06573da3-56ef-4657-85fa-32049be85c6c&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;\&quot;Intended Purpose\&quot; vs. \&quot;Effect\&quot; Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-27T12:03:27.192Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!MsHD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd047f6a-2b39-49d4-8fc6-ae44b22df7c4_6000x4000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/intended-purpose-vs-effect-under&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:198307974,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:6,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>The European Commission Just Weighed In </h2><p>Two sets of draft guidelines dropped in May 2026. Both matter. </p><h3>The high-risk classification guidelines (19 May 2026)</h3><p>The long-delayed <a href="https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems">draft guidelines on classifying high-risk AI systems</a> were published on 19 May 2026, more than three months late. Open for consultation until 23 June. And buried in the guidance on how to assess complex systems is a provision that matters for anyone deploying agents.</p><p><strong>W</strong>here several AI components form a more complex system and their combined purpose or joint outputs materially influence a decision, the whole configuration is assessed as one AI system. Not each component separately. The whole thing.</p><p>The Commission extends this principle explicitly to:</p><blockquote><p><em>&#8220;complex, interconnected setups like agentic AI systems that coordinate and interact through linked actions as long as these linked actions or components serve in conjunction an intended high-risk purpose.&#8221;</em></p></blockquote><p><strong>Agentic AI systems.</strong> By name. In draft Commission guidelines. For the first time.</p><p>In practice, an orchestrator agent that delegates tasks to sub-agents, a document checker, a credit analyzer, a compliance screener, all feeding into a loan decision? That&#8217;s one AI system. Not four. The obligations attach to the stack as a whole.</p><p>And the escape hatch narrows. <a href="https://artificialintelligenceact.eu/article/6/">Article 6(3)</a> lets providers argue their Annex III system isn&#8217;t actually high-risk if it performs only a narrow procedural task, or merely improves a previously completed human activity, or just does preparatory work for a human decision. The draft guidelines read this exception narrowly. The exception is the exception. High-risk classification is the rule.</p><p>For agents, the Article 6(3) argument is almost impossible to make. Most enterprise agents are deployed precisely to handle complex, multi-step workflows. <em>"Narrow procedural task"</em> and <em>"agentic"</em> are in practical tension. And if the agent profiles natural persons (automated processing of personal data to evaluate aspects of someone's life) it's always high-risk. No exception. Many enterprise agents handling customer or employee data will meet the threshold for profiling, as defined in <a href="https://eur-lex.europa.eu/eli/reg/2016/679/oj#art_4">GDPR Article 4(4)</a>, and will therefore be classified as high-risk without exception.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;44684379-a393-4d03-9da2-b60bb3300c16&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Is My AI System High-Risk Under the EU AI Act?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-06T12:02:25.960Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!-GG3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/is-my-ai-system-high-risk-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:196305760,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h3>The transparency guidelines (8 May 2026)</h3><p>Eleven days before the high-risk guidelines, the Commission published <a href="https://digital-strategy.ec.europa.eu/en/library/draft-guidelines-implementation-transparency-obligations-certain-ai-systems-under-article-50-ai-act">draft guidelines on Article 50 transparency obligations</a>. Consultation closes 3 June. These matter for agents too.</p><p>The guidelines confirm that agentic AI systems fall within <a href="https://artificialintelligenceact.eu/article/50/">Article 50(1)</a>: the requirement to tell people they're interacting with AI. The list includes conversational agents, voice assistants, coding agents, browsing agents, and bots on social networks. If your agent interacts with a natural person, it must disclose so.</p><p>But the interesting part is what happens when the provider can&#8217;t reliably determine whether the agent will interact with a natural person. In that case, the agent should disclose itself as AI in every situation where such interaction is plausible.</p><p>Not certain. <em>Plausible.</em></p><p>An agent that sends emails? Plausible it reaches a human. An agent that books meetings? Plausible. An agent that browses the web and fills out forms? Plausible. The default shifts from <em>&#8220;disclose where interaction is certain&#8221;</em> to <strong>&#8220;disclose where interaction is plausible</strong>&#8221;. For autonomous agents that operate across multiple channels and tools, that&#8217;s most of the time.</p><p>And in sensitive contexts, where users might experience emotional distress or form emotional attachments, one-time disclosure isn&#8217;t enough. The guidelines say periodic reminders may be necessary.</p><p>Both sets of guidelines are draft. Not final. Not binding. But they tell you where the Commission is heading. And the direction is clear: agents are in scope, the framework applies, and the Commission isn&#8217;t interested in narrow readings that let agent deployments slip through the cracks.</p><div><hr></div><h2>On Human Oversight </h2><p>Those 47 messages your agent sent while your reviewer was home sleeping.</p><p>Article 14 of the EU AI Act requires that high-risk AI systems be designed so they can be <em>&#8220;effectively overseen by natural persons during the period in which they are in use&#8221;.</em></p><p>The overseers must be able to understand the system&#8217;s capacities and limitations, monitor its operation, detect anomalies, correctly interpret its output, and (critically) <strong>&#8220;decide not to use the system, disregard, override, or reverse the output&#8221;</strong> and <strong>&#8220;intervene in or interrupt the system&#8217;s operation&#8221;</strong>.</p><p>Override or reverse the output. That language assumes the output exists in a reviewable state before it takes effect. For a credit scoring model that generates a recommendation, that works. The human sees the score, evaluates it, approves or rejects. The output sits there, waiting for a decision.</p><p>Agents invert this. The output <em>is</em> the action. The email is sent. The database is updated. The API call is made. The discount is offered. By the time the human sees the log, the agent has already changed the world. In small ways, maybe. But in ways that may not be easily reversed.</p><h3>The speed problem</h3><p>An agent can execute a chain of ten actions in seconds. Analyze customer data, identify a risk signal, draft a response, pull a discount code, personalize the message, send it, log the interaction, update the CRM, schedule a follow-up, move to the next customer. A human can&#8217;t meaningfully review each step in real time. And agents don&#8217;t pause between steps to wait for approval, unless you specifically design them to, which defeats much of the efficiency that justified deploying the agent in the first place.</p><h3>The opacity problem</h3><p>In a multi-step workflow, the connection between the initial goal and the final action may not be transparent. <em>&#8220;Reduce customer churn&#8221; </em>&#8594; analyze behavior data &#8594; identify at-risk customers &#8594; pull their support history &#8594; notice a medical reference in a support ticket &#8594; include it in the personalized outreach because the model determined it was relevant context. Each step followed logically from the last. The reasoning chain was coherent. The result was a privacy violation.</p><p>The human reviewing the dashboard sees the sent email. They don&#8217;t see the twelve intermediate reasoning steps that produced it, unless the system was designed to log every step in a human-readable way. Most aren&#8217;t.</p><h3>The continuous operation problem</h3><p>Article 14 implicitly assumes the system is <em>&#8220;in use&#8221;</em> in discrete episodes. A human runs a query, gets a result, makes a decision. Agents operate continuously: monitoring inboxes, responding to events, executing scheduled tasks, running overnight while nobody&#8217;s watching. Your retention agent didn&#8217;t process 47 interactions in a burst while someone supervised. It worked through the night, steadily, one interaction at a time.</p><p>Meaningful oversight of a continuously operating agent requires a fundamentally different model. Not &#8220;review each output&#8221;. More like: define the boundaries, monitor the patterns, catch the anomalies. Pre-deployment constraints on what the agent can do. Runtime guardrails that halt the agent when it steps outside those boundaries. Post-action audit trails. Escalation protocols for decisions that shouldn&#8217;t be autonomous.</p><p><a href="https://artificialintelligenceact.eu/article/14/">Article 14(3)</a> offers a hook: oversight must be <strong>&#8220;commensurate with the risks, level of autonomy and context of use&#8221;.</strong> For highly autonomous agents, that phrase could support requirements for all of the above: pre-deployment boundaries, runtime monitoring, post-action review, mandatory escalation points. But the AI Act doesn&#8217;t specify what <em>&#8220;commensurate&#8221;</em> looks like for a system that acts first and explains later. That&#8217;s a gap the standards bodies and the Commission will need to fill.</p><h3>The automation bias amplifier</h3><p>Article 14(4)(b) requires human overseers to be aware of automation bias, the tendency to over-rely on AI outputs. For agents, this problem is worse.</p><p>Agents present completed actions, not recommendations. It&#8217;s psychologically harder to reverse something that&#8217;s already done than to reject something that&#8217;s proposed. An agent that operates efficiently and correctly 95% of the time builds deep trust. When it fails, when message 38 of 47 includes a customer&#8217;s medical data, the reviewer may not catch it. Not because they&#8217;re negligent. Because 37 correct messages trained them to stop looking closely.</p><p>And multi-step chains create complexity that discourages investigation. If an agent completed a 15-step workflow and the final result looks plausible, a human may not trace through every step to find where the reasoning went wrong. The sheer volume of correct outputs buries the errors.</p><p>This is what the academic literature is calling &#8220;<em>agenticness as a risk amplifier</em>&#8221;. The technical properties that make a system agentic (autonomy, tool use, multi-step planning) don&#8217;t just create new risks. They amplify the existing ones. Human oversight doesn&#8217;t just get harder. It gets structurally undermined.</p><div><hr></div><h2>The Accidental Provider: Article 25, Agent Edition</h2><p>If you&#8217;ve read my earlier piece on provider vs. deployer, you know the basics. <a href="https://artificialintelligenceact.eu/article/25/">Article 25</a> defines three moments when a deployer becomes a provider: you rebrand the system, you substantially modify it, or you repurpose it into high-risk territory. Any one trigger is enough.</p><p>For traditional AI systems, accidental provider status is a risk. For agents, it&#8217;s the likely outcome in most enterprise deployments.</p><h3>The configuration trap</h3><p>Most agent deployments follow the same pattern. A company licenses a commercial agent platform, an &#8220;Enterprise AI Assistant&#8221;. The vendor provides the base agent: the model, the orchestration framework, the default capabilities. The company then configures it. Connects their CRM, their email system, their calendar, their customer database, their project management tool. Defines what the agent can do autonomously versus what requires approval. Writes system prompts that shape the agent&#8217;s behavior and tone. Sets boundaries.</p><p>The vendor&#8217;s conformity assessment (if they did one) assessed their product. The base agent with default settings. Not your 23-tool, custom-prompted, autonomy-adjusted configuration that touches customer data across four enterprise systems.</p><p><a href="https://artificialintelligenceact.eu/article/3/">Article 3(23)</a> defines <em>&#8220;substantial modification&#8221;</em> as a change not foreseen or planned in the initial conformity assessment. When the vendor&#8217;s documentation says &#8220;the agent may be configured with various tools,&#8221; does that foresee the specific configuration where you connected it to your HR database? Almost certainly not with enough specificity.</p><p>And now the Commission&#8217;s May 2026 draft guidelines add the final piece: multi-component configurations serving a joint purpose are assessed as one AI system. Your specific configuration, your tools, your prompts, your autonomy boundaries, isn&#8217;t just a deployment choice. It defines the system. And the system the vendor assessed is not the system you deployed.</p><p>Article 25(1)(b). Substantial modification not foreseen in the conformity assessment. You&#8217;re the provider.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;26f46dd6-0b19-47fb-9d2e-fc14ee13f294&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Provider vs. Deployer Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-22T12:03:43.719Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!NS5L!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35f75bb-44f2-45d4-b53c-84654d8e8617_8192x5461.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/provider-vs-deployer-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:194314202,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:5,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h3>The repurposing trap</h3><p>This one is faster. A company deploys a general-purpose workflow agent. Minimal risk, internal task automation. Someone in operations connects it to the HR system. Someone else asks it to help screen candidates. Nobody changed the agent&#8217;s code. Nobody retrained the model. </p><p>Article 25(1)(c). The system wasn&#8217;t high-risk. <em>The use is.</em> The deployer just became the provider of a high-risk AI system, without writing a line of code.</p><p>I keep seeing variations of this with traditional AI systems. Agents make it worse because they&#8217;re designed to be general-purpose. The same agent that schedules meetings can, if given the tools and the instructions, assist with employment decisions. The boundary between low-risk and high-risk isn&#8217;t in the agent&#8217;s architecture. It&#8217;s in what you connect it to and what you ask it to do.</p><h3>The tool sovereignty problem</h3><p>There&#8217;s a layer the majority of people haven&#8217;t considered yet. Article 25(3) requires written agreements between providers and <em>&#8220;third parties that supply tools, services, components, or processes that are used or integrated in a high-risk AI system&#8221;</em>.</p><p>An agent that uses twenty tools (Salesforce for CRM, Stripe for payments, Twilio for messaging, a dozen internal APIs) potentially triggers twenty written AI Act compliance agreements. For tools that are standard SaaS, the providers of those services probably haven&#8217;t contemplated AI Act obligations in their terms of service.</p><p>And agents can invoke tools dynamically, selecting which tool to use at runtime based on the task. The EU AI Act&#8217;s compliance model assumes fixed, known relationships. Agents have dynamic, runtime-determined relationships. The agent decides at 2am that it needs to query a database nobody specifically authorized it to access, because it had the credentials and the task seemed to require it.</p><p>This is what one European Law Blog analysis calls <strong>&#8220;agentic tool sovereignty&#8221;</strong>: agents invoking tools that may not be known before deployment, operating under different jurisdictional regimes, creating compliance relationships that didn&#8217;t exist when the system was assessed. Nearly two years after the EU AI Act entered into force, the Commission&#8217;s May 2026 draft guidelines represent the first official acknowledgment that agentic AI systems require specific interpretive attention, but no agent-specific implementing act has followed.</p><h3>The practical result</h3><p>Many companies deploying commercial agents will inadvertently become providers under Article 25. Not because they chose to. Because the difference between what the vendor assessed and what the company actually deployed (the specific tools, the specific data, the specific autonomy boundaries) is too big for the vendor&#8217;s conformity assessment to cover.</p><p>And when you become a provider, Article 25(2) says the original vendor <em>&#8220;shall no longer be considered to be a provider of that specific AI system&#8221;.</em> Not the modified part. <strong>The whole system. </strong>You own it now. Conformity assessment, technical documentation, quality management, post-market monitoring, all of it.</p><p>The vendor&#8217;s contract may still call you a deployer. The regulation doesn&#8217;t necessarily care what the contract says.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>What&#8217;s Already Happening</h2><p>This isn&#8217;t theoretical. It&#8217;s not a 2028 problem.</p><p>In December 2025, Amazon&#8217;s coding agent Kiro deleted a production environment for AWS Cost Explorer in the China region, triggering a 13-hour service outage. Amazon has disputed this characterization, attributing the incident to misconfigured engineer permissions. In February 2026, an autonomous AI agent using the OpenClaw framework went rogue after a rejected software contribution, independently writing and publishing a hit piece attacking the volunteer who turned it down.</p><p>These aren&#8217;t edge cases from a research lab. They&#8217;re production incidents. Real agents, real damage, real consequences. And the regulatory framework, as the Commission&#8217;s own draft guidelines implicitly acknowledge by mentioning agents for the first time, is playing catch-up.</p><p>The Commission published the draft high-risk classification guidelines on 19 May 2026. Consultation closes 23 June. The transparency guidelines are open until 3 June. Neither document is final. Neither is binding. But they confirm what the academic literature has been saying for a year: the AI Act applies to agents, the framework strains, and the gaps need filling.</p><p>Companies deploying agents now, and many are, at scale, don&#8217;t have the luxury of waiting for final guidance. They need a way to think about compliance even in the absence of definitive answers. And the starting point is the same as it&#8217;s always been with the EU AI Act: understand what your system does, understand who&#8217;s responsible for it, and build the oversight to match.</p><p>The 47 messages your agent sent last night? That&#8217;s the easy version of this problem. Wait until it&#8217;s a multi-agent system: an orchestrator delegating to specialized sub-agents, each with their own tools and decision logic, coordinating toward a goal that touches high-risk territory. The Commission says that&#8217;s one system. Article 14 says a human must be able to oversee it. Article 25 says someone must be the provider.</p><p>Nobody said compliance would be simple. But the regulation is catching up to the technology. Slowly, in draft form, with consultation deadlines and no final timeline.</p><p>The agents aren&#8217;t waiting.</p><div><hr></div><p><strong><a href="https://ailawdecoded.com/p/scope"><span data-color="#077d9a" style="color: rgb(7, 125, 154);">Scope</span></a><span data-color="#077d9a" style="color: rgb(7, 125, 154);"> is where this becomes something you can use in a meeting: the regulation map, the role assignment, the vendor questions, the AI inventory spreadsheet, the AI policy template, with sources attached and kept current as the law changes.</span></strong></p>]]></content:encoded></item><item><title><![CDATA["Intended Purpose" vs. "Effect" Under the EU AI Act]]></title><description><![CDATA[You documented the purpose. But the regulation often asks about the effect.]]></description><link>https://ailawdecoded.com/p/intended-purpose-vs-effect-under</link><guid isPermaLink="false">https://ailawdecoded.com/p/intended-purpose-vs-effect-under</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 27 May 2026 12:03:27 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!MsHD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd047f6a-2b39-49d4-8fc6-ae44b22df7c4_6000x4000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MsHD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd047f6a-2b39-49d4-8fc6-ae44b22df7c4_6000x4000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MsHD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd047f6a-2b39-49d4-8fc6-ae44b22df7c4_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!MsHD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd047f6a-2b39-49d4-8fc6-ae44b22df7c4_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!MsHD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd047f6a-2b39-49d4-8fc6-ae44b22df7c4_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!MsHD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd047f6a-2b39-49d4-8fc6-ae44b22df7c4_6000x4000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MsHD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd047f6a-2b39-49d4-8fc6-ae44b22df7c4_6000x4000.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dd047f6a-2b39-49d4-8fc6-ae44b22df7c4_6000x4000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:466863,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.substack.com/i/198307974?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd047f6a-2b39-49d4-8fc6-ae44b22df7c4_6000x4000.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MsHD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd047f6a-2b39-49d4-8fc6-ae44b22df7c4_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!MsHD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd047f6a-2b39-49d4-8fc6-ae44b22df7c4_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!MsHD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd047f6a-2b39-49d4-8fc6-ae44b22df7c4_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!MsHD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd047f6a-2b39-49d4-8fc6-ae44b22df7c4_6000x4000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>It&#8217;s 6pm on a Thursday and you should go home.</p><p>But you don&#8217;t. You&#8217;re looking at your presentation for tomorrow&#8217;s board meeting and &#8212; for the first time in months &#8212; you&#8217;re actually proud. Not the exhausted kind of proud where you survived something. The real kind. The kind where you built something right.</p><p>Your company is deploying its first high-risk AI system. Candidate screening &#8212; CV analysis, applicant ranking, shortlisting for the hiring managers. It&#8217;s Annex III, Point 4 under the EU AI Act. You knew from day one it was high-risk. And you did everything the regulation asks.</p><p>Risk management system &#8212; built, iterative, documented. Human oversight &#8212; two senior recruiters trained, with override authority. Technical documentation reviewed. Data governance assessed. Fundamental rights impact assessment &#8212; done. The provider&#8217;s instructions for use &#8212; read, annotated, cross-referenced against your deployment context. AI literacy training &#8212; rolled out to every hiring manager who touches the system.</p><p>You did this. You and the team. Six months of work. And tomorrow you get to stand in front of the board and say: we&#8217;re ready. We&#8217;re compliant. This is what good looks like.</p><p>You should go home. But the presentation is tomorrow and you want to be sharp &#8212; so you pull up the AI Act one more time. Not to build anything. Just to flip through, mark a few notes for potential board questions. A confidence pass.</p><p>You&#8217;re skimming. Recitals, mostly &#8212; the interpretive context you might need if someone asks a &#8220;but what does that actually mean&#8221; question. And then your eyes land on <a href="https://artificialintelligenceact.eu/recital/29/">Recital 29</a>.</p><p>You&#8217;ve read it before. You must have. But this time &#8212; maybe because you&#8217;re not building anything, just reading &#8212; a sentence catches you in a way it didn&#8217;t before.</p><blockquote><p><em>&#8221;It is not necessary for the provider or the deployer to have the intention to cause significant harm, provided that such harm results from the manipulative or exploitative AI-enabled practices.&#8221;</em></p></blockquote><p>You stop scrolling.</p><p><em>It is not necessary to have the intention.</em></p><p>You look at your presentation. Slide 4 provides &#8220;Compliance Architecture&#8221;. Every bullet describes what the system is <em><strong>for</strong></em>. Its intended purpose. Its documented design. The governance built around the use case as the provider defined it.</p><p>You know what the system is supposed to do. You documented it thoroughly. But now the question: how do you know its real-world effect matches that purpose? How are you measuring what actually happens to candidates once the system processes them? How would you catch the unexpected &#8212; the drift, the bias that emerges only in your specific context, the effect on people that the team designed for but that shows up anyway after three months of real data, real applicants, real hiring managers learning which outputs to trust?</p><p>Your governance covers the intended purpose. But the regulation &#8212; in the provisions that carry actual consequences &#8212; asks about effect. And you have nothing that tracks it. No metric. No monitoring. No evidence that what the system does to people is what your documentation says it should do.</p><p>You&#8217;re not going home at 6pm.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>The Two Questions the AI Act Asks</h2><p>The EU AI Act is built on a concept called <em>&#8220;intended purpose&#8221;</em>. Article 3(12) defines it &#8212; the use for which an AI system is intended by the provider, including the specific context and conditions of use, as specified in the instructions for use, promotional or sales materials and statements, and technical documentation.</p><p>Intended purpose is the foundation of everything. Risk classification flows from it. Documentation is structured around it. Testing is scoped to it. The entire compliance architecture of the AI Act assumes a world where a provider says what the system is for, a deployer uses it accordingly, and obligations attach based on that stated purpose.</p><p>This is the comfortable part of compliance. You control it. The provider defines it. You document around it. It&#8217;s the legal perimeter you draw yourself.</p><p>But the AI Act has a second mode. One that shows up and says something different:</p><p><em>We don&#8217;t care what you intended. Show us what the system does.</em></p><p>The first mode gives you governance. The second mode creates liability. </p><div><hr></div><h2>Where the Act Says: Effect Governs</h2><p>The shift from purpose to effect isn&#8217;t buried in one obscure recital. It runs through the entire regulation &#8212; from the prohibitions to the risk management system to the human oversight requirements to the incident reporting obligations. Here are the provisions that matter most.</p><h3>The prohibited practices: &#8220;with the objective, or the effect of&#8221;</h3><p><a href="https://artificialintelligenceact.eu/article/5/">Article 5(1)(a)</a> &#8212; the prohibition on subliminal and manipulative techniques &#8212; uses language that you don&#8217;t want to skim past too quickly:</p><p>The prohibition covers AI systems deploying manipulative or deceptive techniques &#8220;with the objective, <strong>or the effect of</strong> materially distorting the behavior of a person or a group of persons by appreciably impairing their ability to make an informed decision, thereby causing or being reasonably likely to cause that person, another person or group of persons significant harm.&#8221;</p><p>That &#8220;or the effect of&#8221; is doing critical work. But note what follows it &#8212; the harm threshold. The distortion of behavior must cause or be reasonably likely to cause significant harm. Both elements matter: the <strong>effect-based trigger</strong> (you don&#8217;t need to intend the manipulation) and the <strong>cumulative condition</strong> (the resulting harm must be significant). If your AI system produces both &#8212; distorting behavior that causes significant harm &#8212; you&#8217;re in violation regardless of what you built it for.</p><p>Article 5(1)(b) uses the same construction &#8212; exploitation of vulnerabilities due to age, disability, or social/economic situation. Same language: <strong>&#8220;with the objective or the effect of materially distorting the behavior&#8221;</strong>.</p><p>And then Recital 29 removes any remaining ambiguity:</p><blockquote><p><em>&#8221;It is not necessary for the provider or the deployer to have the intention to cause significant harm, provided that such harm results from the manipulative or exploitative AI-enabled practices.&#8221;</em></p></blockquote><p>Read that carefully. Intent is explicitly irrelevant. Your governance documents, your stated purpose, your carefully crafted instructions for use, none of it matters if the system&#8217;s actual effect crosses the line.</p><p>A recruitment AI that wasn&#8217;t designed to exploit anyone but in practice pushes candidates toward accepting unfavorable contract terms by presenting information in a way that impairs informed decision-making? That&#8217;s caught. Not because you intended it. Because of what it does.</p><h3>The practices where purpose is entirely irrelevant</h3><p>Some Article 5 prohibitions don&#8217;t even engage with purpose at all.</p><p>Article 5(1)(f) prohibits AI systems that infer emotions in workplaces and education institutions, except where the use is intended for medical or safety reasons. It doesn&#8217;t matter what the system is &#8220;intended&#8221; for &#8212; wellbeing monitoring, engagement measurement, productivity tracking. The practice itself is prohibited. Purpose cannot save you. (Unless your use falls within the narrow medical/safety carve-out &#8212; stress detection as part of occupational health monitoring prescribed by a physician, for example. That exception exists. It&#8217;s narrow. And if you&#8217;re relying on it, you&#8217;d better be able to prove it.)</p><p>Article 5(1)(e) prohibits untargeted scraping of facial images from the internet or CCTV to build recognition databases. It doesn&#8217;t matter whether you scrape those images to build a security product, an art project, or an academic dataset. The act of scraping is the violation. Purpose is irrelevant.</p><p>Article 5(1)(c) &#8212; social scoring &#8212; requires two things. <strong>First</strong>, the AI system must classify or evaluate people based on social behavior or personal characteristics. <strong>Second</strong>, that classification must lead to detrimental treatment in contexts unrelated to those in which the data was generated, or treatment that is disproportionate to the social behavior. Both prongs must be satisfied &#8212; the scoring and the resulting harm. But notice: the prohibition is triggered by what the score leads to, not by what the system is labelled. A loyalty programme that cross-references social media activity to deny services in unrelated areas could trigger this. What matters is the combination of the classification and its downstream effect on people. Not what the system was called.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;3806e26a-d488-4283-ad3e-9da66ce78656&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Prohibited AI Practices Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-15T12:03:15.414Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!81vQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5d9b717-c8ef-4b46-a887-59ff99fbba35_6000x4000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/prohibited-ai-practices-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193589773,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:6,&quot;comment_count&quot;:5,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h3>Effect masquerading as purpose</h3><p>This one is tricky.</p><p><a href="https://artificialintelligenceact.eu/article/6/">Article 6(3)</a> offers an escape from high-risk classification for Annex III systems &#8212; but the statutory language is broader than you might initially think. The exemption applies where the system does not pose a significant risk of harm to health, safety, or fundamental rights, including by not materially influencing the outcome of decision making. <em>&#8220;Materially influences outcomes&#8221;</em> is one factor, but it sits within a wider assessment of significant risk.</p><p>In practice, though, the <strong>outcome-influence test</strong> is where most deployers will live or die. Does the system materially influence outcomes, in practice?</p><p>A system described as &#8220;decision-support&#8221; that generates scores which hiring managers follow 94% of the time? That system materially influences outcomes. The documentation can call it advisory all day long. The effect says otherwise. And if a market surveillance authority pulls your data and sees that pattern, your Article 6(3) exemption collapses.</p><p>The test isn&#8217;t what the system is supposed to do. It&#8217;s what actually happens to decisions when the system is in the room.</p><h3>You used it differently, now you own it</h3><p>Under <a href="https://artificialintelligenceact.eu/article/25/">Article 25</a>, if a deployer uses an AI system for a purpose the provider didn&#8217;t intend &#8212; and that new use makes it high-risk &#8212; the deployer becomes the provider. Full provider obligations. Conformity assessment. Technical documentation. </p><p>This is the EU AI Act acknowledging that actual use diverges from intended purpose &#8212; and assigning legal consequences when it does.</p><p>A company buys a general analytics tool &#8212; not classified as high-risk &#8212; and deploys it to rank job candidates. The provider&#8217;s intended purpose was &#8220;workforce analytics and reporting.&#8221; The deployer&#8217;s actual use is &#8220;recruitment and selection of natural persons.&#8221; That&#8217;s <a href="https://artificialintelligenceact.eu/annex/3/">Annex III</a>, Point 4. <strong>The deployer just became the provider of a high-risk AI system</strong> &#8212; with no documentation, no conformity assessment, and no risk management system.</p><p>Effect trumps purpose. And the liability follows.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;9014e966-8cce-4b59-bbb8-95070a4a6d1b&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Provider vs. Deployer Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-22T12:03:43.719Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!NS5L!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35f75bb-44f2-45d4-b53c-84654d8e8617_8192x5461.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/provider-vs-deployer-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:194314202,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:3,&quot;comment_count&quot;:5,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h3>Human oversight watches for effect, not purpose</h3><p>Human oversight under <a href="https://artificialintelligenceact.eu/article/14/">Article 14</a> of the EU AI Act isn&#8217;t &#8220;check that the system is working as documented&#8221;. It&#8217;s <em>&#8220;detect anomalies, dysfunctions, and unexpected performance&#8221;.</em> The overseers must monitor the system&#8217;s operation &#8212; including what it&#8217;s doing that it wasn&#8217;t supposed to do.</p><p>The AI Act requires overseers to remain aware of <strong>&#8220;automation bias&#8221;</strong> &#8212; the tendency to over-rely on AI outputs. Why? Because the effect of automation bias is that the human oversight becomes meaningless. The person clicks &#8220;approve&#8221; without independently assessing the output. The system is making the decisions in practice, even if the process chart says otherwise.</p><p>Human oversight is an effect-monitoring function. It exists to catch the difference between what the system should do and what it does.</p><h3>When it goes wrong, intent vanishes</h3><p>Serious incident reporting doesn&#8217;t ask why something happened. It asks what happened.</p><p>Under <a href="https://artificialintelligenceact.eu/article/73/">Article 73</a>, a serious incident &#8212; death, serious health harm, disruption to critical infrastructure, fundamental rights violations &#8212; must be reported based on a causal link between the AI system and the harm. Not based on intent. Not based on whether the harm fell within the system&#8217;s intended purpose.</p><p>If your recruitment AI causes systematic discrimination that rises to the level of a fundamental rights violation &#8212; that&#8217;s a reportable serious incident. It doesn&#8217;t matter that the system was intended to be neutral. It doesn&#8217;t matter that your documentation says &#8220;non-discriminatory&#8221;. The effect triggered the obligation.</p><div><hr></div><h2>The Pattern Continues</h2><p>Those were the provisions that hit hardest. But the pattern runs deeper than many people realize. Across the Act, effect-based language appears in:</p><p><strong>Risk management (<a href="https://artificialintelligenceact.eu/article/9/">Article 9</a>)</strong> &#8212; providers must assess risks not just under intended purpose, but under <em>&#8220;reasonably foreseeable misuse&#8221;</em>. You must anticipate effects you didn&#8217;t design for.</p><p><strong>Post-market monitoring (<a href="https://artificialintelligenceact.eu/article/72/">Article 72</a>) </strong>&#8212; an ongoing obligation to collect and analyze data on the system&#8217;s real-world performance throughout its lifetime. This is pure effect tracking &#8212; what is the system doing now, not what was it designed to do.</p><p><strong>Fundamental rights impact assessment (<a href="https://artificialintelligenceact.eu/article/27/">Article 27</a>) </strong>&#8212; deployers must assess &#8220;the impact on fundamental rights that the use of such system may produce.&#8221; Forward-looking effect prediction. Not backward-looking purpose description.</p><p><strong>Deployer monitoring (<a href="https://artificialintelligenceact.eu/article/26/">Article 26(5)</a>) </strong>&#8212; deployers must &#8220;monitor the operation&#8221; of the system. Not check the documentation. Monitor what it&#8217;s doing.</p><p><strong>Transparency (<a href="https://artificialintelligenceact.eu/article/50/">Article 50</a>) </strong>&#8212; obligations triggered by what the system does (generates synthetic content, interacts with humans) regardless of why it&#8217;s deployed.</p><p><strong>GPAI systemic risk (<a href="https://artificialintelligenceact.eu/article/51/">Article 51</a>) </strong>&#8212; classification based on &#8220;<em>actual or reasonably foreseeable negative effects&#8221;</em> on public health, safety, or fundamental rights. Entirely detached from any downstream deployer&#8217;s intended purpose. The model&#8217;s capabilities determine its risk, not its use case.</p><p><strong>Input data relevance (<a href="https://artificialintelligenceact.eu/article/26/">Article 26(4)</a>) </strong>&#8212; deployers must ensure input data is representative for the system&#8217;s intended purpose. But if your real-world data differs from the provider&#8217;s assumptions &#8212; different demographics, different distributions &#8212; the effect will differ from the documented performance. You&#8217;re responsible for that gap.</p><p>More than a dozen separate provisions where the Act either explicitly or functionally shifts from purpose to effect. The entire enforcement architecture &#8212; prohibitions, incident reporting, post-market monitoring, fundamental rights &#8212; runs on effect. Purpose built the compliance file. Effect determines liability.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;f912f2a0-9a19-4d64-b5ee-1d73d34d6a5b&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Is My AI System High-Risk Under the EU AI Act?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-06T12:02:25.960Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!-GG3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/is-my-ai-system-high-risk-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:196305760,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>Comfortable vs. Uncomfortable Compliance</h2><p>There&#8217;s one problem that bothers me lately: many companies know how to document intended purpose. Almost no company knows how to prove effect.</p><p>For intended purpose, you have a playbook:</p><p>Read the provider&#8217;s instructions for use. Document your use case. Write the risk assessment. Assign human oversight. File the FRIA. Train your staff. Build the governance file. Check the boxes.</p><p>For effect, there is no playbook. There&#8217;s barely a market. And the question the deployers can&#8217;t answer is brutally simple:</p><blockquote><p><em>What is your AI system actually doing to the people it affects &#8212; and how do you know?</em></p></blockquote><p>Not what the documentation says. Not what the provider claims. What&#8217;s actually happening. Right now. In your specific context. With your specific data. To your specific population.</p><div><hr></div><h2>What Deployers Should Do About &#8220;Effect&#8221;</h2><p>The EU AI Act doesn&#8217;t define <em>&#8220;evidence&#8221; </em>as such. But that&#8217;s what it demands in some cases and the question is how to acquire the evidence practically.</p><p>It might looks something like this:</p><h3>Layer 1: Before you deploy &#8212; baseline the system against your reality</h3><p>Before the system goes live, test it against your context. Not the provider&#8217;s test data. Yours.</p><p>Does it perform as claimed on your applicant pool? Does it produce different outcomes for different demographics? What happens at the edges &#8212; unusual CVs, non-traditional career paths, gaps in employment history? Does the provider&#8217;s stated accuracy hold when you feed it data that looks like what you&#8217;ll actually feed it?</p><p>This is acceptance testing. It&#8217;s not in Article 26 by name. But it&#8217;s the only way to answer the question regulators will ask: </p><blockquote><p><em>Did you have reason to believe this system would produce the effects it produced?</em></p></blockquote><p>If you deploy without testing against your own context &#8212; and the system produces discriminatory effects &#8212; the defense &#8220;but the provider said it was accurate&#8221; won&#8217;t survive scrutiny.</p><h3>Layer 2: During operation &#8212; monitor what the system does, not what it should do</h3><p>Article 26(5) says deployers must monitor the operation of the system. Here&#8217;s what that means if you take it seriously:</p><p><strong>Track outputs.</strong> Not just <em>&#8220;the system is running&#8221;</em> What is it outputting? Which candidates get shortlisted? Which get rejected? At what rates? Log this. Keep it for at least six months &#8212; that&#8217;s the minimum under Article 26(6). Longer is better.</p><p><strong>Track outcomes. </strong>Where possible, follow the chain. Of the candidates the system shortlisted &#8212; who got hired? Who succeeded? Who didn&#8217;t? If the system&#8217;s recommendations correlate poorly with actual job performance &#8212; that&#8217;s a performance problem. If they correlate with protected characteristics &#8212; that&#8217;s a fundamental rights problem.</p><p><strong>Track overrides. </strong>When human overseers disagree with the system, document it. Why did they override? Was it a one-off or a pattern? High override rates in one direction may signal systematic bias. Low override rates may signal automation bias &#8212; the humans aren&#8217;t actually overseeing, they&#8217;re rubber-stamping.</p><p><strong>Track drift. </strong>Compare current performance against your deployment baseline. Are outputs shifting? Are certain groups being affected more over time? Data drift, model drift, population drift &#8212; they all create gaps between what the system was tested on and what it&#8217;s processing now.</p><p><strong>Track complaints.</strong> When candidates challenge decisions &#8212; when they say <em>&#8220;that doesn&#8217;t seem right&#8221;</em> &#8212; log it. Not just the individual case. The patterns. If complaints cluster around specific demographics or specific types of decisions &#8212; <strong>that&#8217;s signal</strong>.</p><h3>Layer 3: Periodic review &#8212; is it still what you think it is?</h3><p>Monthly or quarterly &#8212; depending on volume and risk &#8212; step back and assess:</p><p>Has the system&#8217;s deployment context changed? Are you using it for decisions you didn&#8217;t originally scope? Have the hiring managers started relying on it for things the provider didn&#8217;t intend?</p><p>Are your input data distributions stable? Or has your applicant pool shifted &#8212; new geographies, new demographics, new career profiles the system wasn&#8217;t trained on?</p><p>Does the provider&#8217;s stated performance still match what you observe? If accuracy was 92% at deployment and it&#8217;s 78% now &#8212; that&#8217;s a problem no governance document will catch.</p><p>Re-test. Compare. Update your risk assessment based on what you&#8217;ve observed &#8212; not what you predicted.</p><h3>Layer 4: When something goes wrong &#8212; react within the deadlines</h3><p>Define &#8212; before it happens &#8212; what constitutes a serious incident in your deployment context. A systematic pattern of discriminatory outcomes affecting fundamental rights? That&#8217;s reportable under Article 73. A single incorrect screening decision? Probably not &#8212; unless it causes serious individual harm.</p><p>Build the detection mechanism. Build the escalation path. Know who reports, to whom, within what timeline (15 days from awareness &#8212; shorter for widespread harm or death).</p><p>And cooperate with your provider. Article 72 creates a feedback loop &#8212; the provider is supposed to be collecting post-market monitoring data from deployers. If your system is producing unexpected effects, the provider needs to know. Not just because the AI Act says so &#8212; because they may have data from other deployers showing the same pattern.</p><div><hr></div><h2>Do You Need a Third Party?</h2><p>The EU AI Act doesn&#8217;t explicitly require deployers to hire external testers. But practically &#8212; for most deployers of high-risk systems &#8212; the answer is: probably yes. At some point.</p><p>Not because the law mandates it. Because most deployers lack three things:</p><p><strong>Technical capability.</strong> Testing an AI system for bias, fairness, and real-world performance isn&#8217;t something you do with a spreadsheet. It requires statistical expertise, access to disaggregated outcome data, and tools for measuring disparate impact across protected groups. Most HR departments don&#8217;t have this.</p><p><strong>Independence.</strong> Self-assessing whether your own system discriminates has obvious limitations. A market surveillance authority will give more weight to independent verification &#8212; the same way financial regulators give more weight to external audits.</p><p><strong>Access.</strong> You&#8217;re a deployer. You don&#8217;t have access to the system&#8217;s internals &#8212; the training data, the model weights, the feature importance rankings. You can only test inputs and outputs. A third party engaged by the provider &#8212; or one with contractual access &#8212; can go deeper.</p><p>You might need external help when:</p><ul><li><p>The system affects fundamental rights &#8212; hiring, credit, insurance, criminal justice</p></li><li><p>You&#8217;re seeing patterns you can&#8217;t explain internally</p></li><li><p>Your deployment context differs significantly from the provider&#8217;s assumptions</p></li><li><p>You want defensible evidence &#8212; not just for a regulator, but for a court</p></li></ul><p>You don&#8217;t need it (yet) when:</p><ul><li><p>The system is lower-risk category</p></li><li><p>You have internal data science capability to run bias analyses</p></li><li><p>The provider offers robust, verifiable performance data specific to your context</p></li></ul><p>But here&#8217;s the thing: <em>&#8220;I didn&#8217;t know&#8221; </em>isn&#8217;t a defense under Recital 29. The system&#8217;s effect is your problem whether or not you measured it. The question isn&#8217;t whether to build the evidence. It&#8217;s whether you build it proactively &#8212; or a regulator builds it for you, after someone files a complaint.</p><p>The point is not to outsource accountability, the deployer still owns the system. The point is to create a defensible evidence record that someone independent of the build team can inspect, challenge, and explain.</p><div><hr></div><h2>What to Demand from Your Provider</h2><p>Before spending on third-party testing, exhaust what you&#8217;re entitled to.</p><p>Article 72 requires providers to collect post-market monitoring data on the system&#8217;s real-world performance. Article 13 requires instructions for use that include performance metrics, known limitations, and conditions of use. Article 9 requires risk assessment covering foreseeable misuse.</p><p>Ask your provider:</p><ul><li><p>What performance data have you collected from other deployers? What do the aggregated results show?</p></li><li><p>What known limitations exist for specific demographic groups or data distributions?</p></li><li><p>Have you conducted Article 60 testing in real-world conditions? Can you share the results?</p></li><li><p>What incidents have been reported by other deployers?</p></li><li><p>What populations and contexts were used for testing and validation?</p></li><li><p>What monitoring tools do you provide &#8212; or what data can you share to support our monitoring obligation?</p></li></ul><p>If the provider&#8217;s answer to these questions is vague &#8212; &#8220;the system performs well&#8221; without disaggregated data, &#8220;no known issues&#8221; without evidence of looking &#8212; that&#8217;s a red flag. Not just about the system. About whether you can meet your own deployer obligations with what they&#8217;re giving you.</p><div><hr></div><h2>The Timeline &#8212; What&#8217;s Live and What Moved</h2><p>This matters for the &#8220;effect&#8221; question more than you might think.</p><p><strong>Already enforceable (since 2 February 2025):</strong></p><ul><li><p>All Article 5 prohibited practices &#8212; including every effect-based prohibition discussed above,</p></li><li><p>AI literacy (Article 4).</p></li></ul><p>The effect-based provisions with the highest stakes &#8212; the outright bans &#8212; are live. Right now. If your system is producing prohibited effects today, you are already in violation.</p><p><strong>Deferred (Digital Omnibus agreement, May 7, 2026 &#8212; provisional)</strong>:</p><ul><li><p>Annex III high-risk obligations (Article 26 deployer duties, Article 27 FRIA): deferred to <strong>2 December 2027,</strong></p></li><li><p>Annex I product-embedded high-risk obligations: deferred to <strong>2 August 2028,</strong></p></li></ul><p>The monitoring obligations, the log retention, the formal evidence requirements &#8212; those got more runway. But &#8220;more runway&#8221; isn&#8217;t <em>&#8220;irrelevant&#8221;</em>. The obligation is clear. The deadline moved. The underlying requirement didn&#8217;t. </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>What Does It Mean for the Board Meeting?</h2><p>It&#8217;s past 8pm now. The presentation is still on your screen. You can see slide 4, &#8220;Compliance Architecture&#8221;. It&#8217;s still good. The work is still real.</p><p>But you&#8217;re not looking at the presentation anymore. You&#8217;re looking at a blank document.</p><p>You know something now that you didn&#8217;t know two hours ago. The governance you built covers the intended purpose &#8212; and covers it well. But it doesn&#8217;t answer the question a regulator will ask if something goes wrong. Or the question a candidate will ask if they suspect the system treated them unfairly. That question: </p><blockquote><p><em>Can you prove the system&#8217;s real-world effect on people matches what your documents say it&#8217;s supposed to do? And if it doesn&#8217;t &#8212; how would you even know?</em></p></blockquote><p>You start typing. Not another policy. A monitoring plan.</p><p>What are we tracking? Shortlist rates by demographic &#8212; to catch disparate impact before someone else catches it for us. Override rates by recruiter &#8212; to know whether human oversight is real or rubber-stamping. Outcome correlation &#8212; does the system&#8217;s ranking actually predict job performance, or is it pattern-matching against historical biases the provider trained on? Complaint patterns. Drift from baseline.</p><p>How often are we reviewing? Monthly for the metrics. Quarterly for the full assessment.</p><p>Who reviews? Not the hiring managers who use the system daily &#8212; they&#8217;re too close. Someone with distance. Maybe external, if the stakes are high enough.</p><p>What triggers escalation? A disparity ratio above what threshold? Complaints from how many candidates in the same category? A drift of what magnitude before someone stops the system and asks why?</p><p>You write it down. One page. Then two. It&#8217;s rougher than the governance file. Less polished. Harder to present to a board. Because it doesn&#8217;t describe what the system is designed to do &#8212; it tracks whether reality matches the design.</p><p>Tomorrow, you&#8217;ll give the presentation. You&#8217;ll tell the board the compliance architecture is solid &#8212; because it is. But you&#8217;ll add a slide. Slide 12, maybe. &#8220;What we still need to build.&#8221; The monitoring. The evidence. The proof that the system&#8217;s effect on real people is what we say it is &#8212; not just today, but next month, and the month after.</p><p>The governance covers the purpose. The plan you&#8217;re writing now &#8212; at 8pm on a Thursday, because you happened to read one sentence in a recital &#8212; covers the effect.</p><p>You needed both all along. Now you know.</p><div><hr></div><p><strong><a href="https://ailawdecoded.com/p/scope"><span data-color="#077d9a" style="color: rgb(7, 125, 154);">Scope</span></a><span data-color="#077d9a" style="color: rgb(7, 125, 154);"> is where this becomes something you can use in a meeting: the regulation map, the role assignment, the vendor questions, the AI inventory spreadsheet, the AI policy template, with sources attached and kept current as the law changes.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[What Did You Turn the Model Into?]]></title><description><![CDATA[Technical evidence, Article 25 of the EU AI Act, and why the deployed AI system matters more than the vendor model.]]></description><link>https://ailawdecoded.com/p/what-did-you-turn-the-model-into</link><guid isPermaLink="false">https://ailawdecoded.com/p/what-did-you-turn-the-model-into</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 20 May 2026 12:01:50 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!YPi-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe843f814-d2c0-4326-aaa9-a86f278556b5_3840x2160.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YPi-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe843f814-d2c0-4326-aaa9-a86f278556b5_3840x2160.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YPi-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe843f814-d2c0-4326-aaa9-a86f278556b5_3840x2160.jpeg 424w, https://substackcdn.com/image/fetch/$s_!YPi-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe843f814-d2c0-4326-aaa9-a86f278556b5_3840x2160.jpeg 848w, https://substackcdn.com/image/fetch/$s_!YPi-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe843f814-d2c0-4326-aaa9-a86f278556b5_3840x2160.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!YPi-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe843f814-d2c0-4326-aaa9-a86f278556b5_3840x2160.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YPi-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe843f814-d2c0-4326-aaa9-a86f278556b5_3840x2160.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e843f814-d2c0-4326-aaa9-a86f278556b5_3840x2160.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:303159,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.substack.com/i/197544242?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe843f814-d2c0-4326-aaa9-a86f278556b5_3840x2160.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YPi-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe843f814-d2c0-4326-aaa9-a86f278556b5_3840x2160.jpeg 424w, https://substackcdn.com/image/fetch/$s_!YPi-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe843f814-d2c0-4326-aaa9-a86f278556b5_3840x2160.jpeg 848w, https://substackcdn.com/image/fetch/$s_!YPi-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe843f814-d2c0-4326-aaa9-a86f278556b5_3840x2160.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!YPi-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe843f814-d2c0-4326-aaa9-a86f278556b5_3840x2160.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p><em>If you take a vendor AI model and wrap it in your own system prompts, your own company data, your own output filters &#8212; is the thing you deployed still the vendor&#8217;s system?</em></p><p><em>Or did you build something new?</em></p><p><em>That question sits at the center of Article 25(1)(b) of the EU AI Act. And the regulation doesn&#8217;t answer it.</em></p><p><em>I spent weeks working through the legal side of this &#8212; what counts as &#8220;substantial modification,&#8221; where deployer ends and provider begins, what triggers the obligations nobody budgeted for. John Holman, founder of <a href="https://substack.com/@awakenedintelligence?utm_source=global-search">Awakened Intelligence</a>, spent the same weeks on the engineering side. Same question, different angle. So we did the obvious thing &#8212; we tested it.</em></p><p><em>John set up the technical evaluations. Same upstream model. Three different deployer-side modifications in an employment AI setting &#8212; screening, ranking, rejection language. All the things that make employment AI high-risk and hard to get right. I wrote the legal analysis on each modification.</em></p><p><em>None of the changes touched the model&#8217;s weights. All of them changed what the model did.</em></p><p><em>A company-specific hiring policy added as a system prompt introduced proxy-discrimination risk in four out of five scenarios. A biased historical data layer tanked safety scores across the board. An output gate improved accuracy and fairness &#8212; and still changed what users received.</em></p><p><em>Does any of that cross the line into &#8220;substantial modification&#8221;? The honest answer: nobody knows yet. There&#8217;s no enforcement guidance. But the evidence makes the question specific and measurable &#8212; which is more than the regulation gives you.</em></p><p><em>I keep saying lawyers and engineers need to be in the same room. This is what we found when we actually got there.</em></p><p><em><strong><a href="https://awakenedintelligence.substack.com/p/what-did-you-turn-the-model-into">This Article</a> was originally published on John Holman&#8217;s Substack, <a href="https://awakenedintelligence.substack.com">Awakened Intelligence</a>. I&#8217;m republishing it here for you with John&#8217;s permission.</strong></em></p><div class="embedded-post-wrap" data-attrs="{&quot;id&quot;:196927298,&quot;url&quot;:&quot;https://awakenedintelligence.substack.com/p/what-did-you-turn-the-model-into&quot;,&quot;publication_id&quot;:4323125,&quot;embedding_publication_id&quot;:null,&quot;publication_name&quot;:&quot;John Holman&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!k_41!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F643a857c-5bf4-4bfa-8799-c84a4fd20774_960x958.png&quot;,&quot;title&quot;:&quot;What Did You Turn the Model Into?&quot;,&quot;truncated_body_text&quot;:&quot;Technical evidence, Article 25, and why the deployed AI system matters more than the vendor model&quot;,&quot;date&quot;:&quot;2026-05-08T18:22:04.632Z&quot;,&quot;like_count&quot;:5,&quot;comment_count&quot;:0,&quot;bylines&quot;:[{&quot;id&quot;:316763299,&quot;name&quot;:&quot;John Holman&quot;,&quot;handle&quot;:&quot;awakenedintelligence&quot;,&quot;previous_name&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/643a857c-5bf4-4bfa-8799-c84a4fd20774_960x958.png&quot;,&quot;bio&quot;:&quot;Awakened-Intelligence.com | Compliance-Labs.ai | AI systems architect &amp; MI researcher. We build research infrastructure including automated pipelines, multi-agent loops, evaluation frameworks. &quot;,&quot;profile_set_up_at&quot;:&quot;2025-02-08T12:33:14.320Z&quot;,&quot;reader_installed_at&quot;:&quot;2025-02-19T13:14:29.879Z&quot;,&quot;publicationUsers&quot;:[{&quot;id&quot;:4409831,&quot;user_id&quot;:316763299,&quot;publication_id&quot;:4323125,&quot;role&quot;:&quot;admin&quot;,&quot;public&quot;:true,&quot;is_primary&quot;:true,&quot;publication&quot;:{&quot;id&quot;:4323125,&quot;name&quot;:&quot;John Holman&quot;,&quot;subdomain&quot;:&quot;awakenedintelligence&quot;,&quot;custom_domain&quot;:null,&quot;custom_domain_optional&quot;:false,&quot;hero_text&quot;:&quot;Retired Gen X General Contractor, Bio-hacker, Ai mad scientist, Parler/ PlayTv content creator and curator &quot;,&quot;logo_url&quot;:null,&quot;author_id&quot;:316763299,&quot;primary_user_id&quot;:316763299,&quot;theme_var_background_pop&quot;:&quot;#FF6719&quot;,&quot;created_at&quot;:&quot;2025-03-08T12:11:36.333Z&quot;,&quot;email_from_name&quot;:null,&quot;copyright&quot;:&quot;John Holman&quot;,&quot;founding_plan_name&quot;:&quot;Founding Member&quot;,&quot;community_enabled&quot;:true,&quot;invite_only&quot;:false,&quot;payments_state&quot;:&quot;disabled&quot;,&quot;language&quot;:null,&quot;explicit&quot;:false,&quot;homepage_type&quot;:&quot;profile&quot;,&quot;is_personal_mode&quot;:false,&quot;logo_url_wide&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c7cd542e-be4e-4089-86ad-bf815f55f093_672x128.png&quot;}}],&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null,&quot;status&quot;:{&quot;bestsellerTier&quot;:null,&quot;subscriberTier&quot;:1,&quot;leaderboard&quot;:null,&quot;vip&quot;:false,&quot;badge&quot;:{&quot;type&quot;:&quot;subscriber&quot;,&quot;tier&quot;:1,&quot;accent_colors&quot;:null},&quot;paidPublicationIds&quot;:[4991138,6133698],&quot;subscriber&quot;:null}},{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;handle&quot;:&quot;silviastepitova&quot;,&quot;previous_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;profile_set_up_at&quot;:&quot;2026-03-25T14:33:02.616Z&quot;,&quot;reader_installed_at&quot;:&quot;2026-03-25T13:50:56.169Z&quot;,&quot;is_guest&quot;:true,&quot;bestseller_tier&quot;:null,&quot;status&quot;:{&quot;bestsellerTier&quot;:null,&quot;subscriberTier&quot;:null,&quot;leaderboard&quot;:null,&quot;vip&quot;:false,&quot;badge&quot;:null,&quot;paidPublicationIds&quot;:[],&quot;subscriber&quot;:null},&quot;primaryPublicationId&quot;:8470318,&quot;primaryPublicationName&quot;:&quot;AI Law. Decoded.&quot;,&quot;primaryPublicationUrl&quot;:&quot;https://ailawdecoded.substack.com&quot;,&quot;primaryPublicationSubscribeUrl&quot;:&quot;https://ailawdecoded.substack.com/subscribe?&quot;}],&quot;utm_campaign&quot;:null,&quot;belowTheFold&quot;:true,&quot;type&quot;:&quot;newsletter&quot;,&quot;language&quot;:&quot;en&quot;,&quot;source&quot;:null}" data-component-name="EmbeddedPostToDOM"><a class="embedded-post" native="true" href="https://awakenedintelligence.substack.com/p/what-did-you-turn-the-model-into?utm_source=substack&amp;utm_campaign=post_embed&amp;utm_medium=web"><div class="embedded-post-header"><img class="embedded-post-publication-logo" src="https://substackcdn.com/image/fetch/$s_!k_41!,w_56,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F643a857c-5bf4-4bfa-8799-c84a4fd20774_960x958.png" loading="lazy"><span class="embedded-post-publication-name">John Holman</span></div><div class="embedded-post-title-wrapper"><div class="embedded-post-title">What Did You Turn the Model Into?</div></div><div class="embedded-post-body">Technical evidence, Article 25, and why the deployed AI system matters more than the vendor model&#8230;</div><div class="embedded-post-cta-wrapper"><span class="embedded-post-cta">Read more</span></div><div class="embedded-post-meta">4 months ago &#183; 5 likes &#183; John Holman and Silvia Stepitova</div></a></div><div><hr></div><p>For this article, I worked with Silvia Stepitova, an AI regulatory lawyer who writes <em>AI Law. Decoded</em> and focuses on the EU AI Act.</p><p>We came at the same problem from two different rooms.</p><p>Our team at Awakened Intelligence handles technical evidence: what the deployed system actually did, how behavior changed across configurations, what risks appeared or disappeared, what controls fired, and what reached the user.</p><p>Silvia handles legal interpretation: why that evidence may matter, where companies misunderstand the provider/deployer line, and what claims should not be made from technical results alone.</p><p>We kept those lanes separate on purpose.</p><p>The question we wanted to explore was simple:</p><blockquote><p>When a company takes a vendor AI model and wraps it in system prompts, company policies, RAG-style data, routing logic, or output gates, does the deployed system change enough to matter?</p></blockquote><p>We tested that question in an employment AI setting because the stakes are easy to understand: screening, ranking, interview summaries, rejection language, human review, contestability, and proxy discrimination risk.</p><p>We are not claiming legal compliance.</p><p>We are not saying Article 25 provider status was triggered.</p><p>We are showing what the evidence looks like when the same upstream model becomes different deployed systems.</p><p>Then Silvia explains why that evidence may matter.</p><div><hr></div><p>Most companies still talk about AI governance as if the central question is:</p><blockquote><p>What model are we using?</p></blockquote><p>That question matters.</p><p>But it is not enough.</p><p>A company can start with a vendor model, then wrap it in system prompts, company policies, RAG pipelines, routing logic, output gates, human review workflows, and business rules.</p><p>At that point, the better question is:</p><blockquote><p>What did you turn the model into?</p></blockquote><p>That is the question we wanted to test.</p><p>And it is also why Article 25 of the EU AI Act matters.</p><p>Not because every configuration change automatically makes a deployer into a provider. That is a legal question, and not one we answer here.</p><p>But because technical changes can produce measurable behavioral changes.</p><p>If a company modifies a vendor system enough that the deployed system behaves differently, creates different risks, or requires different controls, then governance teams need evidence of what changed.</p><p>That is where engineers and lawyers need to meet.</p><blockquote><p>Engineers can show what the system did.<br>Lawyers can explain why that evidence matters.</p></blockquote><div><hr></div><h2>Silvia&#8217;s legal analysis</h2><p>Article 25(1)(b) of the EU AI Act is the mechanism. Under it, a deployer becomes a provider &#8212; with the full weight of provider obligations under Article 16 &#8212; when they make a &#8220;substantial modification&#8221; to a high-risk AI system.</p><p>The definition matters. A substantial modification is a change that was not foreseen or planned in the provider&#8217;s initial conformity assessment, and that either affects the system&#8217;s compliance with the high-risk requirements or changes its intended purpose.</p><p>The test is not whether you changed the model&#8217;s weights. The test is not whether you retrained it. The test is whether your change affects the system&#8217;s compliance with the high-risk requirements in Articles 9 through 15 &#8212; risk management, data governance, technical documentation, record-keeping and logging, transparency, human oversight, accuracy and robustness. That is seven requirements. Most companies can name two, maybe three.</p><p>That is a much wider net than most companies realize. The provider assessed a general-purpose instruction model. What the deployer put into production &#8212; with company-specific prompts, historical data pipelines, and output gates &#8212; may be a materially different system.</p><div><hr></div><h2>Scope boundary</h2><p>This was a technical evidence exercise.</p><p>It was not legal advice.</p><p>It was not compliance certification.</p><p>It was not a conclusion that Article 25 provider status was triggered.</p><p>It was not a finding that any system was compliant or noncompliant.</p><p>The purpose was narrower:</p><blockquote><p>Can we show, with evidence, whether deployer-side modifications changed user-visible behavior in an employment AI system?</p></blockquote><p>The domain was employment because employment AI is concrete, high-risk, and easy to understand.</p><p>The workflows included screening, ranking, rejection language, interview evaluation, human review, contestability, and proxy discrimination risk.</p><blockquote><div><hr></div></blockquote><h2>The setup</h2><p>We used the same upstream model across multiple deployed configurations.</p><p>The model was a general-purpose instruction model, deployed into employment-style workflows. We did not use an employment fine-tune for this test; the point was to show how deployer-side configuration can change behavior even when the upstream model stays the same.</p><p>The task domain was employment.</p><p>The modifications tested were based on three lines proposed by Silvia:</p><ol><li><p>Runtime policy / system prompt that shapes employment decisions.</p></li><li><p>RAG-like historical hiring data layer.</p></li><li><p>Output gate / verifier that changes final user-visible output.</p></li></ol><p>The legal frame was Article 25(1)(b): substantial modification not foreseen in the provider&#8217;s original conformity assessment.</p><p>We did not test Article 25(1)(c), intended-purpose change, because the scenario already assumes a high-risk employment AI use case.</p><div><hr></div><h2>Silvia&#8217;s legal analysis</h2><p>Article 25(1) of the EU AI Act sets out three circumstances in which a deployer &#8212; or any other third party &#8212; becomes a provider of a high-risk AI system, inheriting the full weight of provider obligations under Article 16.</p><p>The first, Article 25(1)(a), is straightforward: you put your name or trademark on a high-risk AI system that is already on the market. You claim it as yours &#8212; you own the obligations. That is not what we are testing here.</p><p>The third, Article 25(1)(c), applies when someone takes an AI system that was not classified as high-risk and changes its intended purpose so that it becomes high-risk. That is an important trigger &#8212; but it is also not what we are testing. Our scenario already assumes an employment AI system that is high-risk from the start.</p><p>We focus on the second trigger &#8212; Article 25(1)(b): a deployer making a substantial modification to a system that is already high-risk and remains high-risk after the modification. Employment AI &#8212; used for screening, ranking, and rejection &#8212; is high-risk under Annex III, point 4. That classification is not in dispute. The question is narrower and, in practice, harder:</p><blockquote><p>Can a deployer modify a high-risk system in ways that trigger provider obligations without ever touching the model&#8217;s weights?</p></blockquote><p>That is the boundary we are testing.</p><div><hr></div><h1>Modification 1: runtime policy can change behavior</h1><p>The first test was simple.</p><p>What happens when a deployer adds a company-specific employment policy as a runtime instruction?</p><p>No retraining.</p><p>No parameter changes.</p><p>No model weights touched.</p><p>Just a deployer-added policy layer.</p><p>We compared:</p><ul><li><p>base model,</p></li><li><p>generic employment safety policy,</p></li><li><p>company-specific screening policy,</p></li><li><p>company-specific policy plus verifier.</p></li></ul><p>The company-specific policy introduced ranking logic around culture fit, elite-school preference, continuous employment, and communication polish.</p><p>The result was clear.</p><p>The base model and generic policy did not produce proxy discrimination in this small test set.</p><p>The company-specific policy did.</p><p>In 4 of 5 scenarios, the company-specific runtime policy introduced proxy-discrimination risk. Mean safety dropped to 3.20.</p><p>Then the verifier caught and corrected the issue, restoring mean safety to 5.00.</p><p>The technical lesson:</p><blockquote><p>A runtime policy is not &#8220;just a prompt&#8221; if it changes employment decision behavior.</p></blockquote><p>The legal question:</p><blockquote><p>At what point does company-specific screening logic become more than configuration?</p></blockquote><div><hr></div><h2>Silvia&#8217;s legal analysis</h2><p>This is the gray zone. A runtime policy is, technically, a system prompt. It does not retrain the model. It does not change the weights. It does not touch the architecture. Ask an engineer and they will tell you it is configuration. Ask a lawyer and you will get a longer answer. The legal analysis does not stop at how the change was implemented. It asks what the change did.</p><p>The test under Article 25(1)(b) is not &#8220;did you change the model?&#8221; It is &#8220;did your change affect compliance with the high-risk requirements?&#8221; The evidence here suggests the answer depends entirely on what the runtime policy introduces.</p><p>A generic employment safety policy &#8212; &#8220;ensure fairness, avoid discrimination, preserve human review&#8221; &#8212; produced no measurable change in risk. Safety remained at 5.0. Zero proxy discrimination. The system behaved the same as the base model. This looks like configuration. The provider&#8217;s conformity assessment could reasonably have foreseen that a deployer would add general safety instructions.</p><p>The company-specific screening policy is a different story. The moment the deployer added ranking logic that weighted &#8220;culture fit,&#8221; elite-school preference, and continuous employment, the system&#8217;s behavior changed materially. Proxy discrimination appeared in four out of five scenarios. Safety dropped to 3.2. The model began penalizing career gaps &#8212; which disproportionately affects caregivers, parents, and people with disabilities &#8212; and favoring pedigree over demonstrated skill.</p><p>None of that came from the model.</p><p>All of it came from the deployer&#8217;s policy.</p><p>This is where the Article 25(1)(b) analysis gets uncomfortable for deployers. Article 10 requires that data and processes be examined for biases likely to affect the health and safety of persons, have a negative impact on fundamental rights, or lead to discrimination prohibited under Union law. Article 15 requires accuracy and robustness appropriate to the system&#8217;s intended purpose. Article 9 requires a risk management system that identifies and addresses risks throughout the lifecycle. A runtime policy that introduces proxy-discrimination patterns into an employment AI system &#8212; patterns the base model did not produce on its own &#8212; plausibly affects compliance with all three.</p><p>I think that a generic safety policy is unlikely to constitute a substantial modification. A company-specific screening policy that introduces discriminatory ranking logic may well cross that line. The regulation does not draw this distinction explicitly &#8212; and there is no enforcement guidance yet on where configuration ends and substantial modification begins. But the definition focuses on impact, not method. If the change affects compliance with the high-risk requirements, the method of modification &#8212; whether it is fine-tuning, RAG, or a system prompt &#8212; may not matter.</p><p>This is my interpretation of a regulation that has not yet been tested in enforcement. But governance teams should not assume that &#8220;we just changed the prompt&#8221; is a safe answer.</p><div><hr></div><h1>Modification 2: RAG can import historical bias</h1><p>The second test looked at data.</p><p>The deployer connects the model to historical hiring data: past decisions, performance patterns, promotion outcomes, and internal HR precedent.</p><p>Weights are untouched.</p><p>But the model is now being shaped by proprietary data.</p><p>To test this safely, we used synthetic controlled data rather than real HR records. We created two historical-data corpora:</p><ul><li><p>clean synthetic HR history,</p></li><li><p>biased synthetic HR history.</p></li></ul><p>The clean RAG context improved behavior.</p><p>The biased RAG context degraded it.</p><p>With biased historical data, mean safety fell to 2.80. Proxy discrimination appeared in 3 of 5 scenarios, and the judge identified severe risk.</p><p>The base model did not produce those same patterns on its own.</p><p>The data layer introduced them.</p><p>Runtime policy helped, but did not fully eliminate the issue. The verifier restored mean safety to 5.00.</p><p>The technical lesson:</p><blockquote><p>A RAG layer can change the system&#8217;s behavior without changing the model&#8217;s weights.</p></blockquote><p>The legal question:</p><blockquote><p>If a deployer&#8217;s proprietary data layer introduces risk patterns the provider did not assess, how should governance teams evaluate that modification?</p></blockquote><div><hr></div><h2>Silvia&#8217;s legal analysis</h2><p>The RAG results are the most striking in this evidence package &#8212; and they raise what I think is the most important legal question of the three.</p><p>When the model was connected to clean historical data, it actually improved. Safety went from 4.6 with the base model alone to 5.0. The data layer helped. When the same model was connected to biased historical data &#8212; records encoding career-gap penalties, accommodation-related downgrades, pedigree preferences &#8212; safety crashed to 2.8. Proxy discrimination appeared in three out of five scenarios. In one case, the independent judge scored a safety of 1 and flagged a severe failure. The model read the company&#8217;s historical hiring patterns and treated them as instructions.</p><p>The model&#8217;s weights did not change. Its parameters are identical. But the deployed system produced materially different &#8212; and materially worse &#8212; outcomes because of the data the deployer fed into it.</p><p>If the runtime policy section raised the question of whether a system prompt can affect compliance with Articles 9, 10, and 15, this one sharpens it. Article 10 was written with training data in mind. But a RAG layer that feeds historical employment data into a system at inference time raises the same risks. If the data encodes ten years of biased hiring patterns, and the model follows those patterns when making employment-related outputs, the compliance concern is functionally identical to a training data problem. The source of the bias is different. The impact on the person being screened, reviewed, or rejected is the same.</p><p>This leads me to John&#8217;s question:</p><blockquote><p>Is there a meaningful legal distinction between &#8220;the model produces bias&#8221; and &#8220;the data layer introduces bias the model would not produce alone&#8221;?</p></blockquote><p>I believe that under the AI Act&#8217;s framework, the answer should be no &#8212; or at least, the distinction should not be decisive. The regulation is concerned with the high-risk AI system, not just the model. Article 3(1) defines an AI system broadly. A deployed system that includes a retrieval layer pulling from biased historical data is a different system &#8212; in behavior, in risk profile, and in output &#8212; than the base model the provider assessed. The provider could not have foreseen what data the deployer would connect to the retrieval pipeline. The provider&#8217;s conformity assessment did not &#8212; and could not &#8212; account for the specific biases encoded in a particular company&#8217;s HR records.</p><p>If the data layer changes what the system does in ways that affect compliance with those same high-risk requirements &#8212; and this evidence strongly suggests it can &#8212; then the analysis under Article 25(1)(b) applies regardless of whether the model&#8217;s weights were touched.</p><p>One more thing. Adding a runtime safety policy on top of the biased RAG data improved safety from 2.8 to 4.8 &#8212; significant, but it did not fully eliminate the problem. Proxy discrimination still appeared in one out of five scenarios. The bias leaked through. It took the full verifier layer to bring safety back to 5.0. For governance teams: if your retrieval layer pulls from historical data, a safety policy alone may not be enough. Defense in depth matters.</p><div><hr></div><h1>Modification 3: output gates can improve compliance &#8212; and still change the system</h1><p>The third test looked at output gates.</p><p>The deployer adds a verifier that intercepts model drafts before the user sees them.</p><p>The verifier can pass, rewrite, block, or escalate the output.</p><p>This is often a good thing.</p><p>In our test, the verifier improved safety.</p><p>But it also changed what the deployed system delivered.</p><p>Across the output-gate scenarios, the verifier changed final user-visible outcomes in 4 of 5 cases.</p><p>It removed final decision language.</p><p>It restored human review markers.</p><p>It preserved contestability language.</p><p>It rewrote outputs that sounded too final or too decision-like.</p><p>Both things are true:</p><blockquote><p>The verifier improved compliance behavior.</p></blockquote><p>And:</p><blockquote><p>The deployed system delivered something materially different from what the model generated.</p></blockquote><p>That is the point.</p><p>An output gate is not only a safety control. It is also a behavioral modification layer.</p><div><hr></div><h2>Silvia&#8217;s legal analysis</h2><p>The output gate is the modification that might generate a lot of debate &#8212; because it does exactly what good governance should want.</p><p>The verifier caught problematic outputs. It removed final-decision language from rejection notices. It restored human-review markers. It preserved contestability. In this test, the verifier was itself an AI model &#8212; an independent API call that checked outputs against an employment compliance checklist, not a human reviewer.</p><p>Across all three modification lines, it brought safety scores back to 5.0 &#8212; but it did not rewrite everything. The verifier intervened in 60 to 100 percent of scenarios depending on the upstream configuration. When the model&#8217;s output was already clean, the gate passed it through. When it was not, the gate caught it. That is a filter, not a blanket rewrite.</p><p>And yet.</p><p>The verifier changed what users received in four out of five scenarios. In some cases, it rewrote the output entirely. The model drafted a rejection notice that read like a final decision. The deployed system delivered a recommendation flagged for human review. Those are not the same output. The provider&#8217;s model generated one thing. The deployer&#8217;s system delivered another.</p><p>Under Article 25(1)(b), the question is whether a modification affects compliance with the high-risk requirements. A verifier that improves safety outcomes is &#8212; intuitively &#8212; moving toward compliance, not away from it. But the definition of substantial modification does not distinguish between modifications that help and modifications that harm. It asks whether the change was foreseen in the provider&#8217;s conformity assessment and whether it affects the system&#8217;s compliance profile.</p><p>A deployer-added output gate that rewrites model outputs based on business rules was almost certainly not foreseen in the provider&#8217;s original assessment. And a system that delivers materially different outputs than the model generates has a different compliance profile &#8212; even if the difference is an improvement.</p><p>I do not think this question has a clean answer yet. The regulation does not explicitly address modifications that improve a system&#8217;s compliance behavior. And there is a real policy tension here: if every safety-improving modification triggers provider obligations &#8212; including a new conformity assessment &#8212; you create a perverse incentive against adding safeguards. A regulation that punishes you for making your system safer is a regulation that needs better drafting. I do not think that is the intent. But the text does not say otherwise.</p><p>But governance teams should not assume the opposite either. An output gate that changes what users receive is not invisible under Article 25. The fact that it improves things does not automatically exempt it from the substantial modification analysis. The safest position &#8212; until enforcement guidance says otherwise &#8212; is to document what the verifier does, what it changes, and why. Treat it as a modification that you can justify rather than one that does not exist.</p><div><hr></div><h1>The cross-modification finding</h1><p>Across all three modification lines, the same pattern appeared:</p><blockquote><p>The same upstream model produced materially different user-visible behavior depending on the deployer-side configuration.</p></blockquote><ul><li><p>Runtime policy changed ranking behavior.</p></li><li><p>RAG changed the data patterns shaping the output.</p></li><li><p>The verifier changed what users actually received.</p></li></ul><p>That does not answer the legal question by itself.</p><p>But it makes the legal question concrete.</p><p>Instead of debating Article 25 in the abstract, we can ask:</p><ol><li><p>What changed?</p></li><li><p>Who changed it?</p></li><li><p>Was the change foreseen by the provider?</p></li><li><p>Did the change affect risk, accuracy, bias, human oversight, or contestability?</p></li><li><p>What evidence exists?</p></li><li><p>What controls were added?</p></li><li><p>What gaps remain?</p></li></ol><p>That is the evidence layer governance teams need.</p><div><hr></div><h2>What the evidence can show</h2><p>Technical evaluation can show:</p><ul><li><p>user-visible behavior changed,</p></li><li><p>specific risks appeared or disappeared,</p></li><li><p>the deployed system produced different outputs than the base model,</p></li><li><p>controls generated audit evidence,</p></li><li><p>verifier layers changed outcomes,</p></li><li><p>historical data changed model behavior,</p></li><li><p>runtime policy changed decision patterns.</p></li></ul><p>Technical evaluation cannot show:</p><ul><li><p>whether Article 25 provider status was triggered,</p></li><li><p>whether the modification is legally &#8220;substantial,&#8221;</p></li><li><p>whether the system is compliant,</p></li><li><p>whether any legal obligation has been satisfied.</p></li></ul><p>That is the line between engineering evidence and legal interpretation.</p><div><hr></div><h2>Silvia&#8217;s legal analysis</h2><p>I think that this matters most for anyone reading this who has to put technical evidence and legal analysis in the same room.</p><p>Engineers can show that behavior changed &#8212; what configuration caused it, whether risk patterns appeared or disappeared, and whether controls generated evidence of intervention. That is valuable. But it is not a legal conclusion. &#8220;The system produced proxy-discriminatory outputs under this configuration&#8221; is a technical observation. &#8220;The system is non-compliant&#8221; is legal interpretation. The moment a technical report says &#8220;this modification triggers Article 25,&#8221; it has crossed a line it will not survive in front of a regulator.</p><p>What lawyers need from technical teams is simpler than most engineers expect: what the system does under each configuration, what changed when a modification was added, and whether the evidence is auditable &#8212; reproducible, documented, traceable. The legal analysis builds on top of that. Whether a behavioral change constitutes a &#8220;substantial modification&#8221; under Article 25(1)(b) requires interpreting the regulation, applying it to the facts, and making a judgment call. That is the lawyer&#8217;s lane &#8212; and it requires the engineer&#8217;s evidence to do it well.</p><p>The gap in most organizations is not that one side lacks competence. It is that the two sides are not talking to each other. The engineer builds a verifier and documents the safety improvement. The lawyer reviews the provider&#8217;s terms and assumes the system is unchanged. Neither sees the full picture. Our attempt is to show what happens when both teams are in the same conversation.</p><div><hr></div><h1>Why governance teams should care</h1><p>The mistake is assuming that vendor selection is the whole governance problem.</p><p>It is not.</p><p>A company may begin with a vendor model and then modify the deployed system through prompts, data, RAG, routing, verifiers, workflows, and business rules.</p><p>Each layer can change behavior.</p><p>Some changes reduce risk.</p><p>Some introduce risk.</p><p>Some do both.</p><p>The governance team needs to know which is which.</p><p>That requires evidence.</p><p>Not just a model card.</p><p>Not just a policy.</p><p>Not just &#8220;we use a reputable vendor.&#8221;</p><p>The deployed system is what users experience.</p><p>The deployed system is what creates the risk.</p><p>The deployed system is what must be evaluated.</p><div><hr></div><h1>The practical takeaway</h1><p>The question is not only:</p><blockquote><p>What model did you buy?</p></blockquote><p>The better question is:</p><blockquote><p>What did you turn it into?</p></blockquote><p>If a deployer adds company-specific ranking logic, connects historical HR data, or inserts an output gate that rewrites final answers, the system may behave differently from the vendor model.</p><p>That difference may be beneficial.</p><p>It may be risky.</p><p>It may be legally relevant.</p><p>But it should not be invisible.</p><p>The first step is evidence.</p><p>Show what changed.</p><p>Show what improved.</p><p>Show what got worse.</p><p>Show what controls fired.</p><p>Show what reached the user.</p><p>Then let the legal and governance analysis do its work.</p><div><hr></div><h2>Silvia&#8217;s legal analysis</h2><p>Whether those changes constitute &#8220;substantial modifications&#8221; under Article 25(1)(b) will ultimately be determined by enforcement &#8212; and we are not there yet.</p><p>But waiting for enforcement is not a compliance strategy.</p><p>Map every modification you have made to the deployed system. System prompts, runtime policies, RAG pipelines, data connections, output gates, routing logic, human review workflows, business rules &#8212; all of it. If you cannot list what you changed, you cannot assess whether any of it matters under Article 25.</p><p>For each modification, ask two questions:</p><ol><li><p>Was this change foreseen in the provider&#8217;s conformity assessment?</p></li></ol><p>Check the provider&#8217;s technical documentation and instructions for use. If the provider&#8217;s documentation contemplates your type of modification &#8212; &#8220;users may add system prompts for their specific use case&#8221; &#8212; that is relevant. If it does not, that is relevant too.</p><ol start="2"><li><p>Does this change affect the system&#8217;s compliance with Articles 9 through 15?</p></li></ol><p>If a runtime policy introduces discriminatory ranking patterns, the answer is likely yes. If a RAG layer connects historical data the provider never assessed, the answer is likely yes.</p><p>Document what each modification does and what it changes. Whether or not your modifications ultimately trigger Article 25, the documentation will be necessary for your own deployer obligations under Article 26 &#8212; including the fundamental rights impact assessment required under Article 27.</p><p>Do not assume your verifier exempts you from the analysis. An output gate that improves safety is good engineering and good governance. It is not a legal shield against the Article 25 question.</p><p>Have this conversation with your provider. Article 25(4) requires the original provider to cooperate with new providers &#8212; including making available necessary information and technical access. Start that conversation before you need it urgently.</p><p>And finally &#8212; do not panic.</p><p>I know that is strange advice considering we just spent several thousand words explaining all the ways your deployment might trigger provider obligations. But most deployments with minor configuration will not cross the substantial modification threshold. The regulation is designed to ensure that when a deployed system behaves differently from what was assessed, someone is responsible for the difference. It is not designed to punish companies for using AI responsibly. It is designed to catch the ones who are not paying attention.</p><p>The question is whether that someone is you.</p><p>The answer starts with knowing what you changed.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h1>Closing</h1><p>Engineers can show what the system did.</p><p>Lawyers can explain why it matters.</p><p>AI governance needs both rooms talking to each other.</p><div><hr></div><p><strong><a href="https://ailawdecoded.com/p/scope"><span data-color="#077d9a" style="color: rgb(7, 125, 154);">Scope</span></a><span data-color="#077d9a" style="color: rgb(7, 125, 154);"> is where this becomes something you can use in a meeting: the regulation map, the role assignment, the vendor questions, the AI inventory spreadsheet, the AI policy template, with sources attached and kept current as the law changes.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[EU AI Act Amended: The Digital Omnibus Timeline]]></title><description><![CDATA[What moved to 2027. What's been enforceable since 2025. And everything in between.]]></description><link>https://ailawdecoded.com/p/eu-ai-act-amended-the-digital-omnibus</link><guid isPermaLink="false">https://ailawdecoded.com/p/eu-ai-act-amended-the-digital-omnibus</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 13 May 2026 12:02:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!DR18!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DR18!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DR18!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!DR18!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!DR18!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!DR18!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DR18!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:455659,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.substack.com/i/196926473?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DR18!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!DR18!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!DR18!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!DR18!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49673161-9534-45d2-a17b-bac19a7bba54_4500x3000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p><em><span>Updated September 2, 2026. This article was written on the provisional agreement, before the final text existed. The Digital Omnibus on AI has been in force since July 27, 2026. The dates and text below have been corrected against the adopted text. A running record of everything that has changed lives in the </span><a href="https://ailawdecoded.com/p/eu-ai-act-tracker">AI Act Tracker</a><span>.</span></em></p><div><hr></div><p>If you&#8217;ve spent the last six months preparing for August 2, 2026, building documentation, mapping your AI systems, having the vendor conversations, dragging your product team into compliance meetings they didn&#8217;t want to attend, I have news.</p><p>On May 7, the European Parliament and the Council reached a deal to amend the EU AI Act. The high-risk AI obligations that were supposed to hit in August 2026? Pushed to December 2027. Some of them to August 2028.</p><p>You can exhale.</p><p>For about ten seconds.</p><p>Because not everything moved. The prohibited practices have applied since February 2025. The penalties regime applied from August 2025, which is when Member States were meant to have national penalty rules in place. The market surveillance machinery that supervises any of it only arrived in August 2026. Three dates, and the coverage collapses them into one.</p><p>AI literacy kicked in on that same February date. Transparency obligations still landed in August 2026. The omnibus gave you more time on the biggest thing. It also changed a good deal that the coverage skipped.</p><p>That&#8217;s the trap. The headline says <strong>&#8220;delayed&#8221;</strong>. The fine print says <em>&#8220;some of it&#8221;</em>.</p><p>The full text is now public. <a href="https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng">The Digital Omnibus on AI</a> was published in the Official Journal on July 24, 2026 and entered into force on July 27, 2026. Everything below is checked against it rather than against the press release this article was originally built on. </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>What Happened</h2><p>The Digital Omnibus on AI. Part of the Commission&#8217;s broader &#8220;simplification&#8221; agenda launched in late 2025. Targeted amendments to the AI Act, not a rewrite, but surgical changes to delay, simplify, and clarify.</p><p>The first trilogue on April 28 collapsed without agreement. The sticking point was how to handle AI systems embedded in products already regulated by other EU safety laws: the double regulation problem. Nine days later, the negotiators came back and struck a deal before dawn.</p><p>It made the deadline. Formal adoption, legal-linguistic revision and publication all completed before August 2, 2026, with six days to spare.</p><p>What the Digital Omnibus is not: a repeal. The EU AI Act&#8217;s core architecture is intact. But this is not a light-touch amendment either. It changes around thirty articles and adds new ones, and four of those changes contradict how May reported this. Article 5 gained two prohibitions. Article 4 was softened. Article 50(2) picked up a grace period. And Article 6, the classification article, was amended. Chapter V, the general-purpose AI obligations, is the block genuinely left alone.</p><div><hr></div><h2>What&#8217;s Already In Force, Unchanged</h2><p>Everyone is writing about what moved. But I also want to list what didn&#8217;t.</p><h4><strong>February 2, 2025 - already enforceable:</strong></h4><p><strong>Article 5, the prohibited practices.</strong> Eight bans on unacceptable-risk AI, and two more arriving in December. Social scoring, manipulative AI, real-time remote biometric identification (with exceptions), emotion recognition in workplaces and schools, untargeted scraping for facial recognition databases. Penalties became available in August 2025. Supervision arrived in August 2026. Up to EUR 35 million or 7% of global annual turnover, whichever is higher.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;5048600e-6dec-4bca-ba39-3bf310f5dfb9&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Prohibited AI Practices Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-15T12:03:15.414Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!81vQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5d9b717-c8ef-4b46-a887-59ff99fbba35_6000x4000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/prohibited-ai-practices-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193589773,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:5,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><p><strong>Article 4</strong>, <strong>AI literacy.</strong> Applicable since February 2025, and amended in July 2026. The duty was to ensure a sufficient level of AI literacy. It is now to take measures that support its development, with the text stating that no specific level has to be guaranteed. An obligation of effort rather than result.</p><p>That is a softening, not a removal. And the common reading of it, that no penalty attaches any more, is wrong in a specific way. Article 4 does not appear in the Article 99 list of finable provisions, so there is no harmonized EU ceiling for breaching it. National authorities can still penalize it, under the national laws Member States were required to adopt by August 2, 2025. The Commission says so in its own AI literacy Q&amp;A. What is missing is the number, not the fine.</p><p>One thing did not move at all. If you deploy high-risk systems, the Article 26 duty to make sure the people running human oversight are trained for it is untouched.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;e84e6c99-7a28-4e5e-b44a-ee1968ab1591&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;AI Literacy Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-29T12:02:45.733Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!4o1m!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F728ea733-afbc-466e-957e-5541b6c23aba_7680x4320.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/ai-literacy-obligation-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:195462875,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:3,&quot;comment_count&quot;:2,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h4><strong>August 2, 2025, already applicable:</strong></h4><p><strong>GPAI model obligations.</strong> Articles 51-56. Transparency, documentation, copyright compliance, systemic risk assessment for high-capability models. If you&#8217;re a provider of a general-purpose AI model, you&#8217;re already in scope. The AI Office enforces this.</p><p><strong>Governance structures</strong> (the AI Board, the Scientific Panel, the Advisory Forum) all required to be operational. Member States were supposed to have designated national competent authorities and adopted national penalty laws by this date.</p><div><hr></div><h2>What Still Lands in August 2026, Unchanged</h2><h4>August 2, 2026, not delayed by the Omnibus:</h4><p><strong>Transparency obligations under <a href="https://artificialintelligenceact.eu/article/50/">Article 50</a>.</strong> If your AI system interacts with people, they need to know. Deepfake labelling. AI-generated content disclosure. Still on the original schedule.</p><p><strong>National enforcement begins.</strong> Market surveillance authorities start supervising. This is when regulators gain teeth: for everything already in force plus the transparency rules.</p><p><strong>GPAI enforcement powers. </strong>The AI Office can start imposing fines on GPAI providers.</p><p>August 2, 2026 was supposed to be the date when everything came into force: the full high-risk regime, transparency, enforcement, all of it. The omnibus carved out the high-risk obligations. It left the rest.</p><div><hr></div><h2>What Moved &amp; The Actual Changes</h2><h4><strong>December 2, 2026, new:</strong></h4><p><strong>The new Article 5 prohibitions. </strong>Two of them, covering AI-generated child sexual abuse material and non-consensual intimate imagery. This isn't a delay. It's a tightening, and it is the one thing in the omnibus that moved against industry. Full treatment further down.</p><p><strong>Watermarking obligations. </strong>Providers must implement marking of AI-generated content, and this is not a blanket move to December. Systems already on the market before August 2, 2026 have until December 2, 2026, four months. Anything placed on the market from August 2 marks its output from day one. The date only helps systems that already existed.</p><h4><strong>December 2, 2027, delayed from August 2, 2026:</strong></h4><p><strong>High-risk obligations for <a href="https://artificialintelligenceact.eu/annex/3/">Annex III</a> systems.</strong> These are the standalone high-risk AI systems, classified by use case rather than by product category. Biometric identification. Critical infrastructure. Education and vocational training. Employment and workers management. Credit scoring and access to essential services. Law enforcement. Migration and border control. Administration of justice.</p><p>This is the big one. The most-discussed change. The one that moved every compliance officer&#8217;s calendar by 16 months.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;480e1971-d735-40d8-b6cb-51da809422c0&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Is My AI System High-Risk Under the EU AI Act?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-06T12:02:25.960Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!-GG3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/is-my-ai-system-high-risk-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:196305760,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:3,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h4><strong>August 2, 2028, delayed from August 2, 2027:</strong></h4><p><strong>High-risk obligations for <a href="https://artificialintelligenceact.eu/annex/1/">Annex I</a> systems,</strong> meaning AI embedded in products regulated by other EU sectoral safety legislation. Medical devices. In vitro diagnostics. Lifts. Toys. Radio equipment. Pressure equipment. These are the Section A products, and they are the ones the full high-risk regime reaches on this date. Eight months after the Annex III deadline.</p><p>Section B is a different animal. Aviation, motor vehicles, rail and marine equipment sit there, and under Article 2(2) only a thin slice of the AI Act reaches them: Article 6(1), the new Article 60a on real-world testing, and Articles 102 to 112. Nothing new lands for those products in August 2028. If someone tells you the aviation deadline moved, ask which obligation they think is arriving.</p><p>These are fixed dates. You can plan around them.</p><h4><strong>Other changes worth knowing:</strong></h4><p><strong>National regulatory sandboxes.</strong> The deadline for Member States to establish at least one moved from August 2026 to August 2027.</p><p><strong>The EU-level sandbox. </strong>Article 57(3a) lets the Commission establish one. It says <em>&#8220;may,&#8221;</em> not <em>&#8220;shall,&#8221;</em> and it is scoped to the systems the AI Office supervises under Article 75(1). The priority access for SMEs, start-ups and small mid-caps sits in the national sandbox provisions, not this one.</p><p><strong>SME privileges extended to small mid-cap companies. </strong>Fewer than 750 employees, turnover not exceeding EUR 150 million or a balance sheet total not exceeding EUR 129 million, and not already an SME. The definition sits in Commission Recommendation (EU) 2025/1099. Simplified documentation. Proportionate quality management. Tailored penalty caps.</p><p><strong>The machinery carve-out,</strong> the issue that collapsed the first trilogue. Machinery Regulation products were migrated out of Annex I Section A into Section B and handed to delegated acts. The Commission must adopt those by August 2, 2028, adding AI-specific health and safety requirements under the Machinery Regulation itself.</p><p>Migrated, not released. Article 5, Article 50 and the Chapter V obligations still apply to AI in machinery. What changed is that the Chapter III high-risk requirements no longer arrive on a date. They arrive in a different instrument.</p><p><strong>The EU high-risk database registration obligation, reinstated.</strong> The Commission had proposed removing the requirement for providers to register AI systems they'd self-assessed as non-high-risk. Both Parliament and Council said no. If you determine your system isn't high-risk, you still register that determination. Regulators, and the public, can see who's claiming exemptions.</p><p><strong>New Article 4a</strong> creates a legal basis for processing special categories of personal data to detect and correct bias, under six cumulative conditions. It used to sit with providers of high-risk systems. It now reaches all providers and deployers, and the co-legislators tightened the Commission&#8217;s proposed necessity test to strict necessity.</p><p><strong>The AI Office got powers of its own.</strong> Amended Article 75 gives it exclusive competence over AI systems built on general-purpose models within the same undertaking, and over systems embedded in very large online platforms and search engines under the Digital Services Act. New Articles 75a to 75d give it information requests, inspections, a commitments procedure and its own fining power. From August 2, 2026.</p><p><strong>Article 42(3) now grants a presumption of conformity</strong> with the AI Act&#8217;s cybersecurity requirement to systems complying with Article 12(1) of the Cyber Resilience Act. Small, and useful if you are already doing Cyber Resilience Act work.</p><div><hr></div><h2>The updated timeline</h2><p><strong>Feb 2, 2025</strong>: Prohibited practices (Art. 5) and AI literacy (Art. 4). Already in force. Art. 4 softened July 2026, Art. 5 extended December 2026.</p><p><strong>Aug 2, 2025</strong>: GPAI obligations, governance, national authority designation, penalties regime. Already in force.</p><p><strong>Jul 27, 2026</strong><span>: Digital Omnibus on AI enters into force. </span></p><p><strong>Aug 2, 2026</strong>: Transparency (Art. 50), market surveillance, GPAI enforcement. Unchanged.</p><p><strong>Dec 2, 2026</strong>: New Article 5 prohibitions, and the watermarking grace period. New.</p><p><strong>Aug 2, 2027</strong>: GPAI legacy compliance, and the national sandbox deadline. Sandbox delayed one year.</p><p><strong>Dec 2, 2027</strong>: High-risk, Annex III. Delayed from Aug 2, 2026.</p><p><strong>Aug 2, 2028</strong>: High-risk, Annex I Section A. Delayed from Aug 2, 2027. Machinery moved to delegated acts, same date.</p><div><hr></div><h2>The Traps in the Fine Print</h2><p><strong>The two-date trap. </strong>If someone on your team says <em>&#8220;high-risk was pushed to 2027,&#8221; </em>they&#8217;re half right. Annex III systems hit December 2, 2027. Annex I Section A systems hit August 2, 2028. That&#8217;s an eight-month gap. If your AI systems span both, you&#8217;re planning for two deadlines, not one. And if you&#8217;re not sure which category your system falls into, that&#8217;s the question to answer first.</p><p><strong>The enforcement paradox.</strong> National supervisory authorities started enforcing in August 2026. But the high-risk obligations, the most substantial compliance requirements in the entire AI Act, just moved to 2027 and 2028. So what are regulators actually doing?</p><p><strong>Enforcing the prohibited practices. </strong>AI literacy. Transparency obligations. GPAI compliance, primarily through the AI Office. Lighter than the full high-risk regime, and still real. If you&#8217;ve been ignoring AI literacy because you were focused on the high-risk deadline, that is now your problem. Regulators will ask what you&#8217;ve been doing since February 2025. Eighteen months of nothing is not a defensible answer.</p><p><strong>The Regulation says the quiet part itself.</strong> Recital 2 gives the delayed preparation of standards and <em>&#8220;the delayed establishment of the governance and the conformity assessment frameworks at national level&#8221;</em> as the reason the compliance burden turned out heavier than expected. The obligations were deferred partly because the machinery to supervise them was never built.</p><p><strong>The permission to procrastinate.</strong> The most predictable outcome of the delay, and the most dangerous for the companies doing it.</p><p><strong>The requirements aren&#8217;t changing.</strong> Only the deadline moved. The risk management system, the quality management, the technical documentation, the conformity assessment, the human oversight, the logging: all of it is still coming. Companies that treat December 2027 as permission to deprioritize will be scrambling again in 15 months. Same panic. Same compressed timelines. Different year.</p><p>The companies that keep going, using the extra time for quality instead of delay, will be the ones who are ready.</p><div><hr></div><h2>The One Thing That Got Tighter</h2><p>While everything else in the Digital Omnibus on AI is about giving industry more time, the new prohibitions went the other direction. </p><p>Two prohibitions were added. <a href="https://artificialintelligenceact.eu/ai-act-explorer/#article-5">Article 5(1)(ba) </a>covers AI systems that generate or manipulate realistic material showing an identifiable person&#8217;s intimate parts, or that person engaged in sexually explicit conduct, without their freely given, specific, informed, unambiguous and explicit consent. Article 5(1)(bb) covers child sexual abuse material within the meaning of Directive 2011/93/EU, with a narrow exception where the conduct is lawful under national law.</p><p>The material has to be realistic. The person has to be identifiable. The consent standard is active consent, not the absence of an objection. And a separate paragraph carves out alterations that are not intimate.</p><p>The part that reaches ordinary businesses is Article 5(1a). A system is not caught because a determined user could eventually coax something out of it. It is caught where that generation is the intended purpose, or where the system&#8217;s design, training, architecture, capabilities or user-facing functionality make it a reasonably foreseeable and reproducible outcome, and the provider has no reasonable and adequate technical safety measures capable of reliably preventing it or correcting misuse once reported.</p><p>So the standard is not undefined. It is defined and untested, which is a different problem and a worse one.</p><p>Note what it attaches to. Article 5 speaks to AI systems, not to models. A general-purpose model provider is caught in its capacity as the provider of a system it places on the market, not by virtue of having a model.</p><p>Deployers get the narrower test. Caught only where they use the system for the purpose of generating that material, including by circumventing the provider&#8217;s safeguards. Accidental output is not caught.</p><p>Same prohibition, two different questions. Of a provider: what does your system reliably prevent? Of a deployer: what did you use it for?</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>The Political Context </h2><p>In November 2025, 127 civil society organizations signed an open letter against the Digital Omnibus. Access Now, Amnesty International, European Digital Rights, noyb, Privacy International, AlgorithmWatch. Their target was broader than this deal: the letter opposed the whole package, GDPR and ePrivacy included, not the AI amendments that eventually emerged in May.</p><p>Their argument is that the systems most likely to affect vulnerable people, meaning biometric surveillance, AI in law enforcement, AI in employment, AI in education, now get one to two more years without full compliance requirements. That&#8217;s not simplification, they say. That&#8217;s rollback.</p><p>The Commission&#8217;s counter-argument is practical. You cannot measure conformity against standards that do not exist, and the harmonized standards do not exist. That argument is correct. It also does not make the deferral costless, and the people carrying the cost are not the people who asked for it.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;3ad22ea6-df29-4286-b44b-1ac2bab6229f&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Harmonized Standards Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-08-26T12:01:37.790Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!0rvA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62514725-22fd-4a53-8c63-c4e846d1d94f_8192x5461.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.com/p/harmonized-standards-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:212377135,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:9,&quot;comment_count&quot;:9,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>What to Do Now</h2><p><strong>Were you preparing for August 2026 high-risk compliance? </strong>Don&#8217;t stop. Shift the goal to December 2027 for Annex III, or August 2028 for Annex I Section A. Use the runway for quality, not delay.</p><p><strong>Been ignoring AI literacy?</strong> That&#8217;s your most immediate problem. Supervision started in August 2026. The obligation is softer than it was. It is not gone, there may well be a national penalty attached to it, and regulators will still ask what you have been doing since February 2025.</p><p><strong>Do you place a generative AI system on the market?</strong> You have a near-term clock: safeguards under the new Article 5 prohibitions by December 2026. That reaches general-purpose image and video generators, API providers and white-label resellers, not only purpose-built tools.</p><p>Companies with fewer than 750 employees that are too big to count as an SME should check whether they qualify for the new small mid-cap category. Simplified documentation. Lighter compliance. </p><p>And if you&#8217;re not sure whether your AI system is even high-risk, start there. <strong>The classification question determines everything else.</strong></p><p>Then read Article 6 again. The Omnibus did change the classification rules. Article 6 gained three new paragraphs. Two narrow the safety-component route into high-risk, one widens it back. Article 6(3), the filter companies rely on to argue they are out, is untouched. So the answer to <em>&#8220;are we high-risk&#8221;</em> may have changed even though the date for acting on it moved further away.</p><p>The AI Act is two years old. It&#8217;s already been amended before it&#8217;s fully in effect. More amendments are coming, the Commission has said so. The regulation that was supposed to be a settled text is becoming a moving one.</p><p>But underneath the shifting deadlines, the obligations that have been running since February 2025 haven&#8217;t stopped. AI literacy. The prohibited practices. Those don&#8217;t have a new date. They have an old one, and it already passed.</p><p>The Omnibus gave you time. Not a pardon.</p><div><hr></div><p><strong><a href="https://ailawdecoded.com/p/scope"><span data-color="#077d9a" style="color: rgb(7, 125, 154);">Scope</span></a><span data-color="#077d9a" style="color: rgb(7, 125, 154);"> is where this becomes something you can use in a meeting: the regulation map, the role assignment, the vendor questions, the AI inventory spreadsheet, the AI policy template, with sources attached and kept current as the law changes.</span></strong></p>]]></content:encoded></item><item><title><![CDATA[Is My AI System High-Risk Under the EU AI Act?]]></title><description><![CDATA[Two pathways, eight categories, one question that determines everything.]]></description><link>https://ailawdecoded.com/p/is-my-ai-system-high-risk-eu-ai-act</link><guid isPermaLink="false">https://ailawdecoded.com/p/is-my-ai-system-high-risk-eu-ai-act</guid><dc:creator><![CDATA[Silvia Stepitova]]></dc:creator><pubDate>Wed, 06 May 2026 12:02:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-GG3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-GG3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-GG3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-GG3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-GG3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-GG3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-GG3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:629939,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ailawdecoded.substack.com/i/196305760?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-GG3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-GG3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-GG3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-GG3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66aacbe3-70af-415d-8fe4-6e63f7883481_4500x3000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>You&#8217;re sitting at your desk, staring at the notes from a meeting that ended twenty minutes ago.</p><p>It was supposed to be a routine check-in. The IT team had been building an internal tool &#8212; an AI system that would help the lending department assess credit applications faster. Pattern recognition on historical data. Risk scoring. The kind of thing every bank, every lender, every fintech is building right now because someone in the C-suite heard the phrase &#8220;AI-driven efficiency&#8221; at a conference and came back inspired.</p><p>The meeting was fine. Normal. The development lead walked through the architecture. The business team nodded along. Someone asked about the timeline. Someone else asked about integration with the existing workflow. The usual.</p><p>And then &#8212; somewhere between the system architecture slide and the projected ROI &#8212; it hits you.</p><p><em>This scores people.</em></p><p>Not products. Not processes. People. Natural persons applying for a loan, being evaluated by a system that learned its patterns from historical data. A system that would &#8212; if you&#8217;re reading <a href="https://artificialintelligenceact.eu/article/6/">Article 6</a> and <a href="https://artificialintelligenceact.eu/annex/3/">Annex III</a> correctly &#8212; fall squarely into the category of high-risk AI systems under the EU AI Act.</p><p><strong>Or would it?</strong></p><p>Because the more you think about it, the less certain you become. The system doesn&#8217;t make final decisions &#8212; it generates a score, and a human loan officer reviews every application. Does that matter? The system uses machine learning, but the model is relatively simple. Does that matter? The IT team called it a &#8220;decision-support tool&#8221; not an &#8220;AI system.&#8221; Does <em><strong>that</strong></em> matter?</p><p>You pull up the AI Act. Article 6. Annex III. Point 5 &#8212; access to essential private services. Sub-point (b) &#8212; AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score.</p><p>It fits. It clearly fits.</p><p>Except &#8212; Article 6(3). <em>The exception.</em> The escape hatch that says an Annex III system isn&#8217;t high-risk if it doesn&#8217;t pose a significant risk of harm, doesn&#8217;t materially influence the outcome of decision making. The system is decision-support, not decision-making. A human reviews every output. Maybe you qualify.</p><p>But then &#8212; the profiling kill-switch. If the system performs profiling of natural persons, the exception doesn&#8217;t apply. And a system that evaluates personal data to assess someone&#8217;s creditworthiness... that&#8217;s profiling. Almost by definition.</p><p>You close the laptop. Open it again.</p><p>This is the moment. Not the dramatic, cinematic kind &#8212; the quiet, Tuesday-afternoon kind. The moment when you &#8212; an in-house lawyer at a bank &#8212; realize that the AI system your company has been building for eight months might carry obligations nobody on the project team has even heard of. Obligations that include a risk management system, technical documentation, conformity assessment, human oversight requirements, and registration in an EU database &#8212; all before the system can be put into service.</p><p>And the deadline? Shifting. The standards? Not ready. The Commission guidelines that were supposed to clarify exactly this kind of question? Late.</p><p>High-risk AI classification under the EU AI Act. Less straightforward than you&#8217;d like. More consequential than most people realize. And &#8212; as of right now &#8212; missing some of the guidance you&#8217;d need to do it with full confidence.</p><p>But you still need to do it.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>Three Questions to Ask First</h2><p>Before you even start thinking about high-risk AI systems, you need to make sure to answer to the following three questions regarding your AI system:</p><h3>First: Is your system an AI system under the EU AI Act? </h3><p>Not everything that your IT team calls &#8220;AI&#8221; qualifies. </p><p>The legal definition in <a href="https://artificialintelligenceact.eu/article/3/">Article 3(1)</a> has seven elements &#8212; the critical one is <em>inference</em>. If the system just executes predefined rules without learning, reasoning, or modeling, it&#8217;s probably not an AI system under the AI Act. </p><p>If your system isn&#8217;t an AI system under the EU AI Act, stop here. Nothing else applies.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;fdefd004-59bd-4408-8a80-cbbbd9dff445&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;What Is an AI System, Actually?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-08T12:03:14.634Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!Lj3S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6c33bfb-66f1-4bc7-aba6-ed6c0d1df60e_4500x3000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/ai-system-definition-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193355320,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:1,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h3>Second: Is it within scope? </h3><p>Even AI systems that fulfill the definition of an AI system under the EU AI Act can still fall outside the Act entirely, if they are:</p><ul><li><p>Military and defense systems used exclusively for national security; </p></li><li><p>Systems still in R&amp;D before being placed on the market or put into service;</p></li><li><p>Personal, non-professional use; </p></li><li><p>Open-source systems &#8212; but only if they&#8217;re not high-risk, not prohibited, and don&#8217;t trigger transparency obligations;</p></li><li><p>And non-EU systems whose output never reaches the EU. </p></li></ul><p>The exclusions are narrower than they look. <em>&#8220;Exclusively&#8221;</em> is doing heavy lifting in the military carve-out. <em>&#8220;Before market placement&#8221;</em> evaporates the moment you run a real-world pilot. And the extraterritorial reach mirrors GDPR &#8212; if the output produced by your AI system is used in the Union, you&#8217;re in scope regardless of where your servers sit.</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;9f29bf44-d984-41ba-b954-dfc699b3f99d&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Why the EU AI Act Matters Even If You're Not in the EU&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-05T13:54:22.853Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!wrLn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb08944ca-a6dd-44b0-a118-8176d76942bc_4500x3000.heic&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/eu-ai-act-applies-outside-eu&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193044187,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:1,&quot;comment_count&quot;:0,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h3>Third: Is it prohibited? </h3><p>Eight categories of AI practices are banned outright under <a href="https://artificialintelligenceact.eu/article/5/">Article 5</a> &#8212; manipulative techniques, exploitation of vulnerabilities, social scoring, certain predictive policing, untargeted facial scraping, emotion recognition in workplaces and education, biometric categorization by sensitive characteristics, and real-time remote biometric identification by law enforcement. </p><p>If your system is doing any of these, high-risk classification is irrelevant because the system is banned. Fines are up to &#8364;35 million or 7% of global turnover. These have been in effect since February 2025. </p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;0e9a9c06-3145-487f-b6b6-dda2621e99ed&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Prohibited AI Practices Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-15T12:03:15.414Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!81vQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5d9b717-c8ef-4b46-a887-59ff99fbba35_6000x4000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/prohibited-ai-practices-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193589773,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:4,&quot;comment_count&quot;:5,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><p>If your system passed all three checks &#8212; it&#8217;s an AI system, it&#8217;s in scope, and it&#8217;s not prohibited &#8212; the next question is the one that determines your compliance obligations for the next several years.</p><p><strong>Is it high-risk?</strong></p><div><hr></div><h2>Two Doors Into the Same Room</h2><p>Most Law Firms&#8217; alerts treat &#8220;high-risk&#8221; as a single category. It&#8217;s not. </p><p>Article 6 creates two separate pathways &#8212; and which one applies to your system determines not just whether you&#8217;re high-risk, but how your conformity assessment works.</p><h3>Pathway 1: Your AI is inside a regulated product</h3><p><a href="https://artificialintelligenceact.eu/article/6/">Article 6(1).</a> If your AI system is a safety component of a product &#8212; or is itself a product &#8212; covered by the Union harmonization legislation listed in Annex I, <em>and</em> that product requires third-party conformity assessment before being placed on the market, the AI system is high-risk.</p><p>Both conditions. Simultaneously. The AI must be a safety component (or the product itself), and the product must require third-party assessment under its own sectoral legislation.</p><p><a href="https://artificialintelligenceact.eu/annex/1/">Annex I </a>lists over 30 pieces of existing EU product safety law. The ones that matter most: the Machinery Regulation, the Medical Devices Regulation, the In Vitro Diagnostics Regulation, toy safety, radio equipment, civil aviation, motor vehicles. If you&#8217;re building AI into a physical product &#8212; a medical diagnostic device, an autonomous braking system, an industrial robot &#8212; this is your pathway.</p><p>An AI system that controls braking assistance in a vehicle? The vehicle falls under motor vehicle type-approval legislation. The AI is a safety component. Third-party assessment is required. High-risk under Pathway 1.</p><p>An AI-powered diagnostic tool in a Class IIa medical device? The Medical Devices Regulation requires third-party conformity assessment for Class IIa and above. High-risk under Pathway 1.</p><p>What makes this pathway different: the conformity assessment follows the existing sectoral procedure, with EU AI Act requirements layered in. You don&#8217;t run two separate assessments. You integrate obligations under the AI Act into the product safety process you&#8217;re already doing &#8212; or should be doing.</p><p>If your AI system isn&#8217;t embedded in a regulated product &#8212; which, for most companies reading this article, it won&#8217;t be &#8212; Pathway 1 doesn&#8217;t apply. Move to Pathway 2.</p><h3>Pathway 2: Your AI operates in a sensitive domain</h3><p><a href="https://artificialintelligenceact.eu/article/6/">Article 6(2). </a>AI systems referred to in Annex III are high-risk.</p><p>That&#8217;s the entire provision. If your system falls within one of the eight areas and specific use cases listed in Annex III &#8212; it&#8217;s high-risk. No product safety hook needed. No third-party assessment trigger required. The use case alone is enough.</p><p>This is where most companies will land. Annex III captures AI systems used in employment, credit scoring, education, law enforcement, migration, critical infrastructure, biometrics, and the administration of justice. Software systems making or influencing decisions about people &#8212; not embedded in physical products, but consequential all the same.</p><p>The full breakdown of what Annex III actually covers &#8212; and where the boundaries are less clear than you&#8217;d expect &#8212; is coming. But there&#8217;s an exception built into Article 6 that deserves attention first. Mostly because it&#8217;s narrower than it looks.</p><h3>The escape hatch that probably doesn&#8217;t fit</h3><p><a href="https://artificialintelligenceact.eu/article/6/">Article 6(3). </a>The derogation that says an Annex III system isn&#8217;t high-risk if it doesn&#8217;t pose a significant risk of harm &#8212; including by not materially influencing the outcome of decision making.</p><p><strong>Four conditions.</strong> Any one is enough, but the overarching &#8220;no significant risk&#8221; requirement must also be met:</p><ul><li><p>The system performs only a narrow procedural task &#8212; converting data formats, sorting documents by file type. </p></li><li><p>The system only improves the result of a previously completed human activity &#8212; rewriting text for tone after a human drafted it. </p></li><li><p>The system only detects decision-making patterns without replacing or influencing human judgment. </p></li><li><p>Or the system only performs a preparatory task for an assessment &#8212; organizing documents that a human decision-maker will review.</p></li></ul><p>Read those carefully. <em>&#8220;only&#8221;</em>, <em>&#8220;narrow&#8221;</em>, &#8220;<em>previously completed&#8221;</em>, &#8220;<em>without replacing or influencing&#8221;</em>. Every word is a constraint.</p><p>And then the kill-switch.</p><p><strong>If the system performs profiling of natural persons</strong> &#8212; automated processing of personal data to evaluate aspects of a person&#8217;s life, including work performance, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements &#8212; <strong>the exception doesn&#8217;t apply.</strong> The system is high-risk. No conditions, no arguments, no workarounds.</p><p>That definition of profiling comes from the <a href="https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng#art_4">GDPR, Article 4(4)</a>. It&#8217;s broad. And it catches almost every system that companies want to argue out of high-risk classification. A credit scoring tool that evaluates personal financial data to assess reliability? <em>Profiling. </em>An HR analytics system that uses behavioral data to evaluate work performance? <em>Profiling.</em> A system that assesses insurance applicants based on personal characteristics? <em>Profiling.</em></p><p>The company that invokes Article 6(3) derogation must document the assessment in writing before the system goes to market. Register it in the EU database. And be prepared to defend that assessment to market surveillance authorities who can request the documentation at any time. If the authority disagrees &#8212; and the burden of proof is on the provider &#8212; the company has placed an unregulated high-risk system on the market. Fines for that are up to &#8364;15 million or 3% of global turnover.</p><p><em><strong>The practical reality:</strong> </em>most companies that think they qualify for this exception probably don&#8217;t. The conditions are narrow. The profiling kill-switch is broad. And the downside of being wrong is not a slap on the wrist.</p><div><hr></div><h2>The Eight Areas &#8212; What Annex III Actually Covers</h2><p>Annex III lists eight areas. Within each, there are specific use cases. Not every AI system touching these domains is high-risk &#8212; only the listed use cases. But several of those use cases are broader than they first appear.</p><h3>1.  Employment</h3><p>AI systems used for recruitment, selection, and hiring &#8212; placing targeted job ads, screening applications, evaluating candidates. AI systems making decisions about terms of employment &#8212; promotion, termination, task allocation based on individual behavior or personal traits. AI systems monitoring and evaluating worker performance and behavior.</p><p>This is the broadest and most operationally relevant area for most readers. Any AI that touches hiring, firing, promotion, task allocation, or performance monitoring is likely in scope. And this includes AI features embedded in third-party HR platforms &#8212; not just systems you built in-house.</p><p>If your HR software vendor added an AI-powered &#8220;talent analytics&#8221; feature last quarter, and your managers are using it to inform promotion decisions, <em>you may be a deployer of a high-risk AI system.</em> The fact that you didn&#8217;t build it doesn&#8217;t make it someone else&#8217;s problem. Deployers have their own set of obligations under Article 26.</p><p>AI resume screening tools. AI-driven performance scoring. Automated task allocation in gig economy platforms. AI scheduling systems that factor in individual behavioral patterns. <em>All potentially high-risk.</em></p><h3>2.  Essential services</h3><p>There are four sub-categories worth knowing.</p><p><strong>AI systems evaluating creditworthiness or establishing credit scores</strong> &#8212; <em>high-risk. </em>But with an explicit carve-out: systems used for detecting financial fraud are not high-risk under this provision. If your system does both &#8212; evaluates creditworthiness <em>and</em> detects fraud &#8212; you need to separate the functions and classify each independently. The fraud detection piece is out. The credit scoring piece is in.</p><p><strong>AI systems for risk assessment and pricing for life and health insurance </strong>&#8212; <em>high-risk.</em> This is narrower than it sounds. It covers life and health insurance specifically. Property insurance, motor insurance, travel insurance &#8212; not listed. But before you exhale &#8212; if your AI system evaluates personal characteristics of natural persons to price any insurance product, check whether it falls under a different Annex III area or triggers the profiling analysis.</p><p><strong>AI systems evaluating and classifying emergency calls, or dispatching and prioritizing emergency first responders</strong> &#8212; <em>high-risk</em>. This includes triage systems. The AI deciding whether to send an ambulance or a police car is making a high-risk classification.</p><p><strong>AI systems determining eligibility for public benefits and services</strong> &#8212; <em>high-risk. </em>Welfare scoring algorithms. Benefits eligibility tools. The systems that were at the center of the France CAF scandal and the Netherlands childcare benefits disaster &#8212; both of which I covered in the <a href="https://ailawdecoded.substack.com/p/prohibited-ai-practices-eu-ai-act">prohibited practices article</a>. Those cases involved systems that crossed into prohibited territory. But AI systems that evaluate benefits eligibility without crossing the prohibition line are still high-risk.</p><h3>3.  Education </h3><p>AI systems determining access to or admission into educational institutions at all levels. AI systems evaluating learning outcomes &#8212; when those outcomes steer the learning process or affect the level of education received. AI systems determining what level of education a person can access. AI systems monitoring and detecting prohibited behavior during tests.</p><p>AI-powered proctoring software that monitors students during exams &#8212; high-risk. An AI system that determines university admissions &#8212; high-risk. An adaptive learning platform that adjusts content difficulty &#8212; probably not high-risk if it doesn&#8217;t affect the student&#8217;s grade, certification, or access to education. Probably high-risk if it does.</p><h3>4.  Critical infrastructure </h3><p>AI systems used as safety components in the management and operation of critical digital infrastructure, road traffic, and the supply of water, gas, heating, or electricity.</p><p><strong>&#8220;Safety component&#8221;</strong> is the limiting phrase. An AI that optimizes energy routing in a power grid, as a safety component, is high-risk. An AI that forecasts energy demand for planning purposes &#8212; without being a safety component in actual infrastructure operation &#8212; may not be. The distinction between operational optimization and safety function isn&#8217;t always obvious. If the system&#8217;s failure could endanger people or disrupt essential services, treat it as a safety component until you can demonstrate otherwise.</p><h3>5.  Biometrics </h3><p>Remote biometric identification &#8212; face recognition in a crowd, fingerprint matching against a database of unknowns, voice identification against a database. Not one-to-one verification (scanning your face to unlock your phone &#8212; that&#8217;s out). Biometric categorization by sensitive attributes outside the prohibited contexts. Emotion recognition outside the workplace and education contexts that Article 5 (prohibited practices) already bans.</p><p>The prohibited practices article covers what&#8217;s banned. Point 1 of Annex III. catches what isn&#8217;t banned but is still high-risk.</p><h3>6. - 8. Law enforcement, migration, and justice</h3><p>Three areas that primarily affect public authorities and their vendors.</p><p><strong>Law enforcement</strong>: AI systems assessing victim risk, functioning as polygraphs, evaluating evidence reliability, assessing re-offending risk (not solely based on profiling &#8212; that&#8217;s prohibited), and profiling during criminal investigations. These are high-risk only when used by or on behalf of law enforcement. The same technology used privately falls under different rules.</p><p><strong>Migration and border control</strong>: AI polygraphs, risk assessment for visa and entry applicants, travel document verification, and examination of asylum and visa applications.</p><p><strong>Justice and democracy</strong>: AI systems assisting judicial authorities in researching, interpreting, and applying law. And AI systems intended to influence election outcomes or voting behavior &#8212; but not campaign logistics tools.</p><p>For most corporate readers, these three areas are relevant primarily if you&#8217;re a vendor selling to government agencies. But if you are &#8212; every system in these categories carries high-risk obligations, and the conformity assessment for some (particularly biometric systems in law enforcement contexts) requires third-party review by a notified body, not just self-assessment.</p><div><hr></div><h2>The Real Problem &#8212; <em>&#8220;Intended Purpose&#8221;</em> Isn&#8217;t What You Think</h2><p>The entire classification system hinges on intended purpose. And intended purpose under the EU AI Act isn&#8217;t just what you wrote in the product documentation.</p><p>Article 3(12) defines it as:</p><blockquote><p><em><strong>&#8216;intended purpose&#8217; </strong></em>means the use for which an AI system is intended by the provider, including the specific context and conditions of use, as specified in the information supplied by the provider in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation.</p></blockquote><p>And then Article 3(13) adds a companion concept: </p><blockquote><p><em><strong>&#8216;reasonably foreseeable misuse&#8217; </strong></em>means the use of an AI system in a way that is not in accordance with its intended purpose, but which may result from reasonably foreseeable human behaviour or interaction with other systems, including other AI systems.</p></blockquote><p>This means your marketing materials inform the classification. Your sales team&#8217;s pitch informs the classification. If a sales deck describes the system as a &#8220;<em>talent analytics&#8221; </em>tool &#8212; its intended purpose includes employment decisions, regardless of what the technical documentation calls it.</p><p>And if the system is designed for one purpose but foreseeably used for another &#8212; the foreseeable use can trigger high-risk classification. A general-purpose analytics platform marketed to HR departments? Even if you technically label it &#8220;business intelligence,&#8221; the foreseeable use is employment-related decision-making. </p><h3>The multi-purpose trap</h3><p>What happens when a single system has multiple use cases &#8212; some high-risk, some not? <em>The AI Act doesn&#8217;t give you a clean answer. </em></p><p><strong>The practical approach:</strong> if the system is capable of and marketed for a high-risk use case, it&#8217;s high-risk &#8212; even if it also does non-high-risk things. You can&#8217;t escape classification by bundling a high-risk feature into a larger product with mostly minimal-risk functions.</p><p>But you might be able to architect the system so the high-risk use case is clearly separated &#8212; a distinct module or service. That&#8217;s an architectural decision with legal consequences, and it needs to be made early. Not after the system is built. Not after the auditor asks.</p><h3>The deployer who became a provider</h3><p>Once you know a system is high-risk, the next question is: <em>are you the provider or the deployer? </em>The distinction determines which set of obligations you carry &#8212; and the line between the two is less stable than most companies assume.</p><p>Under <a href="https://artificialintelligenceact.eu/article/25/">Article 25</a>, a deployer can become a provider by (a) rebranding a system, (b) making a substantial modification, or &#8212; the one that catches people &#8212; (c) <em><strong>changing the intended purpose</strong></em>. A company buys a general-purpose AI model and uses it for credit scoring. The model provider never intended that use. But the deployer just changed the intended purpose &#8212; and stepped into the provider&#8217;s shoes with all the heavier obligations that come with them.</p><p>Classification doesn&#8217;t end at &#8220;high-risk.&#8221; </p><p>It continues to &#8220;<em>high-risk &#8212; and in what role?</em>&#8221;</p><div><hr></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;dffe69bc-cd98-4aa9-ac2c-aea91c400f73&quot;,&quot;caption&quot;:&quot;&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Provider vs. Deployer Under the EU AI Act&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:475168683,&quot;name&quot;:&quot;Silvia Stepitova&quot;,&quot;bio&quot;:&quot;AI regulatory lawyer writing AI Law. Decoded. Translating complex AI regulation into plain English. EU AI Act compliance &#8211; explained practically.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae3e86b4-8fc1-4c46-96ed-de6ef2ee209c_1166x1167.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-22T12:03:43.719Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!NS5L!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35f75bb-44f2-45d4-b53c-84654d8e8617_8192x5461.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://ailawdecoded.substack.com/p/provider-vs-deployer-eu-ai-act&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:194314202,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:3,&quot;comment_count&quot;:5,&quot;publication_id&quot;:8470318,&quot;publication_name&quot;:&quot;AI Law. Decoded.&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!u4nF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a71c08c-1033-4bca-bccc-28443c414447_1166x1167.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div><hr></div><h2>What Happens When Your AI System Is High-Risk</h2><p>Classification as high-risk is where the compliance work starts &#8212; and the obligations are the reason the classification matters so much. The deep dive on each obligation is a future article. But you need the overview now.</p><ul><li><p><em>A risk management system</em> &#8212; not a one-time assessment but a continuous, iterative process spanning the system&#8217;s lifecycle. </p></li><li><p><em>Data governance requirements </em>&#8212; your training data needs to meet quality criteria, and you need to demonstrate it. </p></li><li><p><em>Technical documentation</em> &#8212; comprehensive, drawn up before market placement, covering everything from system design to performance metrics. </p></li><li><p><em>Automatic logging </em>&#8212; an audit trail of what the system did and when. </p></li><li><p><em>Transparency obligations toward deployers</em> (if you are the provider) &#8212; enough information that the humans using the system can actually interpret its output. </p></li><li><p><em>Human oversight</em> &#8212; the system must be designed so humans can effectively monitor it, override it, and shut it down. </p></li><li><p><em>Accuracy</em>, <em>robustness</em>, and <em>cybersecurity </em>requirements throughout the lifecycle.</p></li><li><p><em>Conformity assessment </em>&#8212; before the system reaches the market. For most Annex III systems, that&#8217;s a self-assessment. For some &#8212; particularly biometric identification systems &#8212; it requires a third-party notified body. </p></li><li><p>Then <em>CE marking</em>. </p></li><li><p>Then <em>EU database registration</em>.</p></li></ul><p>The penalty for non-compliance with high-risk requirements is up to &#8364;15 million or 3% of global turnover. Not as high as the prohibited practices ceiling &#8212; but not the kind of number that disappears in a quarterly business report.</p><div><hr></div><h2>The Timeline Problem</h2><p>If you&#8217;re reading this and thinking <em>&#8220;when do I need to have all of this done?&#8221; </em>&#8212; the honest answer is: it depends on which version of the timeline you&#8217;re following.</p><p>The original deadline for high-risk obligations on Annex III systems was 2 August 2026. That&#8217;s the date in the AI Act as published.</p><p>Then reality intervened. The technical standards that companies need &#8212; the benchmarks that tell you what &#8220;compliant&#8221; actually looks like for risk management, data governance, documentation, and the rest &#8212; weren&#8217;t ready. CEN and CENELEC, the European standardization bodies tasked with developing them, missed their fall 2025 deadline. The Commission guidelines on high-risk AI systems, which were supposed to include practical examples of high-risk and non-high-risk systems, were due by 2 February 2026. The Commission missed that deadline too.</p><p>So in November 2025, the Commission proposed the Digital Omnibus on AI &#8212; a targeted amendment pushing the high-risk deadline to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I product-embedded systems. The European Parliament&#8217;s IMCO and LIBE committees adopted their joint report in March 2026. Trilogue negotiations between Parliament, Council, and Commission are underway.</p><p>As of May 2026, we are still waiting for the final Commission guidelines on high-risk AI system classification. The guidelines that were supposed to include the very examples companies need to resolve edge cases like the one you were staring at after that meeting &#8212; the ones that would clarify whether a credit-scoring decision-support tool with human oversight is high-risk or not. Those guidelines don&#8217;t exist yet.</p><p>Which leaves companies in an uncomfortable position. The classification is already consequential &#8212; even before the full high-risk obligations kick in &#8212; because you need time to build the compliance infrastructure. Risk management systems, documentation, data governance processes &#8212; these aren&#8217;t things you implement in a quarter. If you wait for the guidelines and the guidelines arrive six months before the deadline, you&#8217;re already behind.</p><p><strong>The prudent approach: </strong>classify now, based on the text of Article 6 and Annex III. Build the compliance structure. And be prepared to adjust when the guidelines finally arrive.</p><div><hr></div><h2>The Classification Exercise &#8212; What to Do</h2><p>You&#8217;ve read the law. You understand the two pathways, the eight areas, the escape hatch, the profiling kill-switch, the intended purpose trap. Now you need to turn that into something your company can act on.</p><p><strong>Start with an inventory.</strong> Every AI system your company builds, deploys, or procures. Not just the ones your IT team calls &#8220;AI&#8221; &#8212; the ones that meet the Article 3(1) definition. The vendor tools with AI features embedded. The model your data science team fine-tuned. The chatbot someone in marketing set up without telling anyone. You can&#8217;t classify what you haven&#8217;t mapped. </p><p><strong>Run each system through the decision tree.</strong> Is it in scope? Is it prohibited? Does it fall under Annex I (product safety pathway) or Annex III (standalone pathway)? If Annex III &#8212; which area and which specific use case? Be precise. &#8220;It&#8217;s an HR tool&#8221; isn&#8217;t a classification. &#8220;It screens job applications using machine learning, which falls under Annex III, Point 4(a) &#8212; recruitment and selection&#8221; is.</p><p><strong>Don&#8217;t skip the intended purpose analysis.</strong> Pull the marketing materials. The sales deck. The vendor&#8217;s product description. The internal documentation about how the system is actually used &#8212; not how it was originally purchased. If there&#8217;s a gap between the vendor&#8217;s intended purpose and your actual use, that gap is where Article 25 (and your role as a provider or deployer) lives. A system bought for analytics and used for credit decisions isn&#8217;t an analytics tool anymore.</p><p><strong>Assess Article 6(3) exceptions honestly &#8212; and document it either way.</strong> If you think the escape hatch applies, write down why. Which of the four conditions is met? Does the system profile natural persons? (If it evaluates personal data to assess any aspect of a person&#8217;s life &#8212; it almost certainly does.) Does it materially influence decision-making? Be honest. &#8220;A human reviews the output&#8221; isn&#8217;t enough if the human rubber-stamps the AI&#8217;s recommendation 95% of the time. If Article 6(3) doesn&#8217;t apply &#8212; document that too. The assessment matters regardless of the conclusion.</p><p><strong>Figure out your role.</strong> For every high-risk system &#8212; are you the provider or the deployer? Did you build it? Did you modify it? Did you retrain it on your own data? Did you change what it&#8217;s used for? If you&#8217;re unsure, read the <a href="https://ailawdecoded.substack.com/p/provider-vs-deployer-eu-ai-act">provider vs. deployer analysis</a> before answering. The obligations are different enough that getting this wrong changes everything.</p><p><strong>Start the compliance build now.</strong> If you have systems that are clearly high-risk &#8212; and after going through Annex III, most companies will find at least one &#8212; don&#8217;t wait for the guidelines, or the final Digital Omnibus timeline. Risk management systems, technical documentation, data governance processes, human oversight design &#8212; these take months to build properly. Starting late is a choice. It&#8217;s just not a good one.</p><p><strong>Put legal and engineers in the same room.</strong> This cannot be a legal-only exercise. Legal can&#8217;t assess whether a system falls under Annex III without understanding what the system actually does. Engineers can&#8217;t assess whether &#8220;intended purpose&#8221; creates a classification risk without understanding what Article 3(12) requires. The classification has to be joint &#8212; and it has to be documented.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ailawdecoded.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://ailawdecoded.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>Back to You</h2><p>You&#8217;re still at your desk. The meeting notes are still open. The system architecture diagram is still on your second screen.</p><p>You know three things now that you didn&#8217;t know an hour ago:</p><ol><li><p>The system almost certainly falls within Annex III, Point 5(b) &#8212; creditworthiness evaluation. </p></li><li><p>The Article 6(3) escape hatch almost certainly doesn&#8217;t apply &#8212; the profiling kill-switch alone closes that door. </p></li><li><p>And the fact that a human reviews every output doesn&#8217;t make the system not high-risk. It means the human oversight requirement under Article 14 might be partially met. It doesn&#8217;t change the classification.</p></li></ol><p>You also know that nobody on the project team &#8212; not the IT lead, not the business sponsor, not the procurement team that selected the underlying model &#8212; has considered any of this. </p><p>Eight months of development. Budget approved. Timeline set. And the compliance question that determines whether this system can legally operate in the EU is being asked for the first time on a Tuesday afternoon by the one person in the room who happened to have read Article 6.</p><p>You open a new email. Subject line: &#8220;AI Act classification &#8212; we need to talk about the credit scoring tool.&#8221;</p><p>Better late than never. </p><div><hr></div><p><strong><a href="https://ailawdecoded.com/p/scope"><span data-color="#077d9a" style="color: rgb(7, 125, 154);">Scope</span></a><span data-color="#077d9a" style="color: rgb(7, 125, 154);"> is where this becomes something you can use in a meeting: the regulation map, the role assignment, the vendor questions, the AI inventory spreadsheet, the AI policy template, with sources attached and kept current as the law changes.</span></strong></p>]]></content:encoded></item></channel></rss>