Free guide · Francisco Arrieta · 8 min

Work out whether the EU AI Act applies to you

Ten minutes to find out whether you're in scope, which role you're in, and what you would have to show

The date was 2 August 2026. That’s three weeks ago, and it’s when most of the EU AI Act started applying, including the rules about telling people when they’re looking at something a machine made.

Two beliefs keep owners from checking, and both are wrong.

The first is that it’s a European problem. It isn’t, or rather it isn’t only. The Act reaches businesses established outside the EU when the output of their AI system gets used inside it. Where you’re sitting isn’t the test. Where the output lands is.

The second is that it’s a big-company problem. Small businesses are mentioned in the Act 38 times, and the relief they get is real but narrow: simpler documentation, and fines capped at the lower of two bounds. That’s a discount, not an exemption.

This is a triage, not legal advice. What it gives you is an honest answer to whether you need to take this seriously, and a short list of what somebody might ask you to show. If the answer comes back yes and you’re doing anything consequential, that’s the point at which a lawyer is worth paying, and you’ll be paying them for an hour instead of a day because you arrived with the answers.

Before you start

Ten minutes and a text file. Nothing to install.

Two words you need, because everything downstream hangs on them. A provider builds an AI system or puts one on the market under their own name. A deployer uses one under their own authority. Most owners reading this are deployers, and it’s worth knowing that before you decide the Act is somebody else’s problem.


Step 1

Work out whether you’re in scope at all

Answer these in order and stop at the first yes.

Do you have customers, users or staff in the EU? If your product is used there, output produced by your AI system is being used there.

Does anything you publish reach people in the EU? Content, a chatbot on your site, an assistant that answers email. Reach is the test, not where you’re incorporated.

Do you sell to a business that operates in the EU? Their obligations flow to you through contract long before any regulator does. This is how most small operators actually meet the Act.

The scope rule in Article 2 is deliberately wide. It covers providers placing systems on the EU market regardless of where they’re established, and deployers in a third country where the output is used in the Union.

If every answer is genuinely no, you’re out, and knowing that with a reason beats assuming it. Write down the reason. Somebody will ask.


Step 2

Work out which role you’re in

You can be both at once, on different systems. Do this per system, not per company.

You’re a deployer if you use somebody else’s AI under your own authority: a chatbot on your site, an assistant summarizing support tickets, a tool that drafts your copy. Almost everything an owner does is this.

You’re a provider if you build an AI system, or put one on the market under your own name, or take somebody else’s and rebadge it as yours. Wrapping a model in your product and selling it under your brand puts you here, which surprises people.

The distinction matters because the obligations split, and some of them land on providers while others land on deployers.


Step 3

Check what’s already live

These are in force now, not coming.

AI literacy, Article 4, since February 2025. If your staff use AI, they need enough understanding to use it sensibly. There’s no certificate and no register. It’s a real obligation with a soft shape, and the evidence is that you did something deliberate rather than nothing.

Transparency, Article 50, since 2 August 2026. Four rules, and note who each one lands on:

A person talking to your AI has to know it’s an AI.
Provider obligation, unless it’s obvious to a reasonably informed person.
Synthetic output has to be marked
in a machine-readable way, detectable as generated. Provider obligation.
Emotion recognition or biometric categorization means telling the people exposed to it.
Deployer obligation.
Deepfakes and AI-generated content have to be disclosed as artificially generated.
Deployer obligation.

That last one has an exception worth knowing if you publish: AI-generated text that has gone through human editorial review, where somebody holds editorial responsibility, is treated differently. So is artistic and satirical work, which only has to disclose that the exception exists.


Step 4

Write down what you’d show

This is the step that turns an opinion into a position, and it takes five minutes.

For each AI system you listed, write one line: what it is, whether you’re provider or deployer, whether people interact with it, and whether it produces content you publish.

Then write what you’d hand over if asked. Not a policy document. Evidence: the notice on your chatbot, the line in your terms, the note that says your team was briefed and when.

Your vendor’s compliance is not your compliance. A deployer has obligations of their own, and a supplier’s certificate answers a question nobody asked you.


Step 5

Check the one thing most owners actually have

If you run a chatbot or an assistant that talks to customers, go and look at it right now.

Does a first-time visitor know they’re talking to software? Not from your internal knowledge that it’s obvious. From the screen, at the first interaction, in plain words.

The disclosure has to arrive at the latest at the point of first interaction, and be clear and accessible. If yours says nothing, that’s a sentence of work and it’s the single most likely gap between you and Article 50.


Step 6

Note what isn’t your problem yet

Being accurate about what you don’t have to do is half the value of doing this.

Article 6(1) applies from 2 August 2027. The high-risk classification rule and its obligations aren’t fully in play yet.

Most owners aren’t running high-risk systems at all. That category is about things like recruitment, credit scoring, education access and critical infrastructure. Using AI to write your marketing copy isn’t in it.

SME relief is real. Simplified technical documentation is coming from the Commission, and fines for SMEs are capped at the lower of the two bounds rather than the higher.

Write the date you did this triage next to your list. When something changes, and it will, you’ll want to know what you were looking at.


A boundary worth knowing about

This tells you whether to worry. It does not tell you that you’re compliant.

The Act is a regulation with recitals, national implementation, guidance still being written, and standards still being finalized. A ten-minute triage against the article text is enough to know whether you’re in the room. It is not enough to certify that you’re fine, and anybody who tells you a checklist does that is selling something.

The other edge: the EU isn’t alone. Other jurisdictions are moving, and a business that only ever checks Europe will get caught by whichever one moves next. What transfers isn’t the answer, it’s the habit of asking.


If you have staff

Article 4 is about them, not about you. AI literacy is an obligation on the organization for the people using the tools. A short internal briefing, dated, with a note of who attended, is a proportionate answer for a small team and it is evidence.

Somebody should own the list from step 4. Not maintain a compliance programme. Just keep one page current, so that when a client’s questionnaire arrives, the answer takes an hour rather than a fortnight.


The short version

  1. In scope if anyone in the EU uses your output, wherever you’re based
  2. Work out provider or deployer, per system. Most owners are deployers
  3. Live now: AI literacy since Feb 2025, and Article 50 transparency since 2 Aug 2026
  4. Write one line per system plus what you’d actually show. Your vendor’s certificate isn’t yours
  5. Look at your chatbot. Does a first-time visitor know it’s an AI?
  6. Article 6(1) waits until Aug 2027. SME relief is documentation and fine caps, not exemption

Sources

  • Implementation timeline, EU Artificial Intelligence Act — the phased dates: prohibitions and AI literacy from 2 February 2025, GPAI and penalties from 2 August 2025, the remainder except Article 6(1) from 2 August 2026, and Article 6(1) from 2 August 2027
  • Article 2, Scope — that the Act covers providers placing systems on the EU market irrespective of where they are established, and deployers in a third country where the output is used in the Union
  • Article 50, Transparency obligations — the four disclosure rules, which land on providers and which on deployers, the timing at first interaction, and the exception for AI-generated text under human editorial responsibility
  • Small businesses’ guide to the AI Act — SMEs mentioned 38 times, simplified technical documentation, and fines capped at the lower bound

Written August 2026. Dates and article contents checked against the AI Act text on 23 August 2026. This is the one guide in this library most likely to age badly, because guidance and standards are still being written. Re-check before relying on it.

Prints to PDF from your browser — colours and all.