Which rules apply to your company under the EU AI Act,
for which AI system, how to assess your role, and
what to ask the vendor before you sign a contract.
Opening October 15, 2026.
You get asked whether the EU AI Act applies to a tool your company already bought. Then whether that makes you the provider or the deployer. Then whether the transparency rules apply. Then what to ask the vendor before legal signs anything.
Four questions. All of them are the same question.
What’s the scope?
Scoping is not new to you. Which entities, which processing, which jurisdictions, written down until somebody could rely on it. GDPR made everyone learn that whether they wanted to or not.
The AI Act asks the same kind of question about different objects. Which systems, which entities, which obligations.
It just isn't written down anywhere in your company, which is why the same argument keeps arriving at the same meeting and leaving it unresolved.
Scope is where it gets written down.
What Is Scope
Scope is a set of working documents for anyone who ended up owning AI governance.
Not explainers about the regulation. The documents themselves: the territorial determination, the regulation map, the role assignment, the vendor questions. Written to be used, and kept current as the law moves.
AI governance is not a task with an end date, which is the entire reason Scope is a subscription and not a download.
Everything arrives as a post you can read in your inbox, and as a file you can keep: PDFs, spreadsheets, templates. Download them, print them, put them in the folder where your evidence lives.
It covers the EU AI Act. That includes companies established outside the EU: if your system's output is used inside the European Union, the AI Act reaches you. Document one settles whether that is you.
What’s Available On October 15
Four documents. All of them there on launch day.
1. Does this reach you? Territorial scope, worked through. The three hooks in Article 2(1), the output test, and what “placing on the market” means when nothing physical crosses a border. Entity by entity, use by use, because a group can be in scope through one subsidiary and out through another. Includes when a third-country provider has to appoint an EU representative, and when it doesn’t.
2. The scope method and regulation map. Which rules bind the company at all, before anyone argues about a specific tool. The fixed layer that comes from what the company is, then the pull-in question for each use case.
3. Role assignment: provider or deployer. System by system. Run as sold, tuned to your specification, shipped under your own name, wired into your own data. Which of those changes your role, which doesn’t, and why the size of the behavior change is not the test.
4. The vendor questions. Twenty questions to ask before anyone signs. For each one: why it matters, what a good answer sounds like, what an evasive answer sounds like, and what you need in writing. Built for procurement, not for a seminar.
These are followed by the AI inventory spreadsheet, AI policy template and other resources in the coming months. You can start anywhere.
Two Excerpts From Scope
From Vendor Questions:
Are you the provider of this system under the EU AI Act, and will you say so in writing?
Why it matters. Provider obligations are heavier than deployer obligations, and the roles are not allocated by contract. They follow what each party actually does. A vendor who is the provider and will not say so is a vendor whose obligations may end up sitting with you.
What a good answer sounds like. “We are the provider. Here is our declaration, the reference for our technical documentation, and the contact for our authorised representative.”
What an evasive answer sounds like. “The EU AI Act doesn’t really apply to this product.” Or four paragraphs about their security certifications that never use the word provider.
What you need in writing. The role, stated plainly, and an undertaking to tell you if it changes. It can change: if they modify the system, or if you do, the allocation moves.
From Scope Method:
The fixed layer. The regulations that bind every AI use in your organization regardless of what the use is. This layer comes from what the company is: its sector, its legal entities, the jurisdictions it operates in. For an EU bank that layer is the AI Act, DORA, the Capital Requirements Regulation and Directive, and the GDPR. Every AI system in that bank sits on top of those, whether it is a credit scoring model or a chatbot on the careers page.
You build this layer once. It changes rarely, because the company’s identity changes rarely.
The pull-in layer. For each individual AI use case, one question: which additional law does this specific use pull in?
An HR screening tool pulls in employment law. A consumer lending decision pulls in consumer credit rules. Anything customer-facing pulls in consumer protection. The fixed layer tells you the floor. The pull-in question tells you what this particular system drags in on top of it.
You answer this per use case. You do not maintain it centrally, because there is nothing central about it.
Central for what’s common. Per use case for the rest.
If you are not established in the EU. The two layers work anywhere. What changes is only what goes in the fixed layer, and whether the AI Act belongs in it at all.
What It Saves You
The meeting you’ve had three times. Once the map exists, “does that even apply to us” has a written answer with sources attached. The argument doesn’t get won. It stops being available.
The number of AI systems. You think there are four AI systems. IT knows about eleven. Procurement has a twelfth on a corporate card. The inventory doesn’t create the systems, it just ends the disagreement about how many there are.
A classification you can defend, which is not “we decided we’re a deployer” but a written record of which facts you tested, which way each one pointed, and where the line sits when it moves.
And twenty vendor questions in a document you forward, rather than an email you write from scratch every time, in a hurry, on a Friday.
The folder. When a customer’s security team, your DPO, or eventually an authority asks how you decided, the answer is a document with dates on it. Work nobody wrote down didn’t happen, as far as anyone asking is concerned.
You also get something less comfortable: documented gaps. Once the map and the inventory exist, the things no one owns are visible and written down. In my experience people stop disputing them and start avoiding eye contact.
Assigning owners still takes someone senior making it non-optional, and no document does that part for you.
Who Is This For
The in-house lawyer, the compliance lead, the product manager, or whoever got handed “the AI thing” because they seemed least busy. In the EU, or outside it with output landing inside it.
Not every company needs the full version. A twenty-person startup running one off-the-shelf tool needs a page and a decision, not a program. If that is you, don’t subscribe. The free articles below will get you there.
Scope covers the EU AI Act and covers it properly, rather than covering several regimes badly.
If Your Company Isn’t in the EU
A company established in the EU falls under the EU AI Act, and the only real question is which parts apply to which AI systems.
Being established somewhere else does not settle the question.
One of the ways the EU AI Act reaches a company established outside the EU is when the output of its AI system is used in the EU. Not where your servers are, not where you are incorporated, not where the model was trained. Where the output lands.
That is one route in. A third-country provider putting a system on the Union market is caught without anyone looking at output at all.
A Delaware company with European customers, an Indian services firm building systems for a European client, a UK company selling into the single market: all of them can be in scope while having no EU presence at all.
The first document in Scope is the one that settles this. If you are established in the EU, it takes you five minutes and you move on to the second. If you are not, it is the only document that matters until you have worked through it.
The free version of the argument is here: Why the EU AI Act Matters Even If You’re Not in the EU. Three hooks in Article 2(1), five scenarios where you are caught, four where you are not, and when a third-country provider has to appoint an EU representative. If none of it lands on you, Scope is not for you yet.
Why Not Just Hire Someone
There is a version of this you can buy. A fixed-fee audit that maps your AI estate and hands you a report. A platform with a module for every regulation. A consultancy engagement that starts in five figures and is scoped for a company with three hundred AI systems, not six.
The question is what you are paying for. Usually it is not expertise you lack. You read contracts for a living, or you ship software, or you own risk at a company that already got through GDPR with its dignity mostly intact. What you are buying is three uninterrupted months, and that is the one thing nobody can actually sell you.
Scope works the other way round. You get the documents, kept current by someone whose job it is to watch the Official Journal. You do the thinking, which you were going to have to do anyway: whoever writes the report leaves, and you are still there owning the responsibility.
If your estate is large and properly chaotic, hire someone. I’ll say so if you ask me.
Why Not Just Use the Free Resources
The free resources are good. artificialintelligenceact.eu is the best public guide to the EU AI Act and I use it constantly. Law firms publish alerts. A chatbot will summarize Article 25 for you in about four seconds.
None of them can tell you what your company is.
And the questions that cost the most are the ones a model answers confidently and wrongly. Whether bolting RAG and internal data onto a vendor’s model makes you a provider. Whether a third party fine-tuning on your behalf changes your role. Whether a use the vendor never intended flips your obligations.
I will tell you where the line sits. Where it isn’t settled, I will say that too.
Public guides explain the law. Scope gives you the documents that say which parts of it bind you, what role you are actually in, and what to put in front of procurement. One is a reference to the regulation. The other is a reference to the work.
Who Am I
I'm an AI regulatory lawyer. Six years at Amazon, where I led a GenAI contract review project that the Wall Street Journal covered. I now build the AI governance framework inside a regulated financial institution.
I’m not writing about this from the outside. I’m working through the same questions, against the same deadlines, from the same half-finished guidance you are.
I wrote these documents because I needed them.
What You Are Paying For
Maintenance.
Every document carries the date it was last checked. Each one is reviewed at least quarterly, and where the law moves in a way that changes what a document says, the update lands within 30 days. That is the commitment.
New documents arrive on top of that. The order below is the plan rather than a promise:
The AI inventory spreadsheet. A working template with the columns that matter: system, owner, the decision it touches, the vendor, the role, the data. Classification only works once you know what you are classifying, and the inventory is harder than the regulation map.
Article 50 transparency. Which disclosures you owe, to whom, and what “clearly and distinguishably” has come to mean in practice.
AI literacy documentation. What a defensible Article 4 record looks like, sized three ways: startup, mid-size, large. Written against the updated EU AI Act text.
The AI governance framework checklist. Everything that belongs in a complete framework, listed, so you can see at a glance what you have, what you are missing, and what you can defensibly skip.
The AI policy template. The internal policy itself. What has to be in it, what is optional, and what people put in that does nothing except create obligations they then breach.
The deployment patterns, one at a time. Run as sold. Fine-tuned. Wrapped. RAG and internal data. Agentic and employee-built tools.
Then one more each month, chosen from what subscribers are actually stuck on.
The inventory, the vendor questions and the deployment patterns are jurisdiction-neutral by construction. They work the same whether your floor is the EU AI Act or something else entirely.
How you get them. Each document is a post in the Scope section with a file attached. Everything published before you join is there when you arrive, so a subscription started in month five gets the whole set, not only what ships afterwards.
If you cancel. You keep whatever you downloaded. You stop getting the updates, and the updates are the reason the documents stay usable.
What Scope Isn’t
Not legal advice. Not a community. No calls, no forum, no office hours.
You read the documents and you use them.
These documents are information, not legal advice. Reading them creates no lawyer-client relationship, and you apply your own judgment to your own situation. They are independently authored, written outside my employment and unconnected to any employer’s work product.
If You Want to See How I Work First
Everything on AI Law. Decoded. stays free. Three articles to start with:
What’s Your Role Under the EU AI Act? Practical Decision Tree — provider, deployer, importer, distributor, authorized representative, and how to work out which one you are.
Your Role Classification Is Only as Honest as Your AI Inventory — the AI Act never tells you to build an inventory. Every obligation in it assumes you already have one.
The EU AI Act’s Loophole With No Expiry Date — Article 111(2), and which high-risk systems will never have to comply.
If those are useful to you, Scope is the same thinking in a form you can hand to someone else.
The Early Rate
$15 a month, or $150 a year, if you pledge before Scope opens on October 15. That rate stays yours for as long as you stay subscribed, and Substack holds it automatically.
The day after launch it becomes $30 a month, or $300 a year.
How pledging works: you enter your card and nothing is charged. No money moves until October 15. If it never launches, you are never billed.
Organization rate: $800 a year. The same documents, with permission to circulate them inside your company: the vendor questions to procurement, the inventory template in a shared drive, the regulation map attached to a board paper. The license comes stated in writing, so it can sit in the file next to the documents when somebody asks who was allowed to use what. On Substack this is the Founding Member option. Their label, not mine.
The individual rate is for your own work: use it, quote it, cite it.
Neither rate permits republishing publicly or reselling.
For Expensing It
Most subscribers will put this on a company card. Something along these lines usually helps get an easy sign-off from management:
A maintained regulatory reference for our EU AI Act obligations, covering which regulations apply to us, role classification per system, and vendor due diligence for procurement. Updated as guidance changes. $150 a year (which is roughly one hour of external counsel).
Someone at your company will have to write all of this down eventually. The only real question is whether it happens before somebody asks, or after.
