Skip to content
AIRAS Cloud

Scope

Does the EU AI Act apply to my business?

Most organisations are deployers, most deployers underestimate their exposure, and role determines obligation.

Short answer

The EU AI Act applies to providers placing AI systems on the Union market, to deployers established in or located in the Union, and to providers and deployers in third countries where the output produced by the system is used in the Union. Most organisations are deployers rather than providers, but an organisation that puts its name on a system, substantially modifies one, or repurposes a general-purpose model for a high-risk use can become a provider with the full provider obligation set.

Reviewed 2026-08-02. General information for governance planning, not legal advice.

Key points

  • Role, not size, determines the obligation set
  • Extraterritorial reach applies where output is used in the Union
  • Deployers can become providers through modification or rebranding
  • Personal non-professional use and certain research uses are outside scope
  • Military, defence and national security uses are excluded
  • Free and open-source components have partial, conditional treatment

Four questions that usually settle it

  • Do we place an AI system on the Union market under our own name or trademark?
  • Do we use an AI system in the course of our professional activity?
  • Is the output of a system we operate used inside the Union?
  • Have we substantially modified, fine-tuned or repurposed a supplied system?

The deployer trap

Organisations frequently assume that buying AI transfers responsibility to the vendor. It does not. Deployers carry duties around use in accordance with instructions, human oversight, input data relevance, monitoring, logging and informing workers, and these apply in the deployer's own operational context, which the vendor cannot evidence for them.

The reverse trap is quieter. Rebranding a supplied system, or substantially modifying it, can convert a deployer into a provider, at which point conformity assessment, technical documentation and post-market monitoring duties attach.

Determining scope defensibly

Scope should be determined per system and recorded with the reasoning, the evidence relied on and the date. An organisation-level statement that 'the Act does not apply to us' is not a determination; it is an assumption that will not survive a single counterexample from within the estate.

AIRAS Cloud runs applicability and role determination as an explicit, versioned stage per system, so scope decisions carry the same evidential weight as risk classifications.

Frequently asked questions

We are outside the EU. Does it still apply?
It can. The Regulation reaches providers and deployers established outside the Union where the output produced by the AI system is used within the Union.
We only buy AI, we do not build it. Are we exempt?
No. Deployers carry their own obligations, particularly for high-risk systems, covering oversight, monitoring, input data, logging and informing affected workers.
Does the Act apply to internal productivity tools?
Professional use is in scope, though obligations for minimal-risk systems are limited, principally AI literacy and any applicable transparency duties. The exposure grows sharply where a tool touches employment, credit, education or essential services.
How do we prove a system is out of scope?
With a recorded determination: the system's function, the scope test applied, the reasoning, the ruleset version used, the assessor and the date. A conclusion without reasoning is not evidence.

Primary sources

How AIRAS Cloud supports this

Complete AI inventory, including embedded vendor AI
Role and applicability determination per system
Deterministic, versioned classification reasoning
Append-only audit record of every decision

Related answers

Turn the regulation into an operating record

AIRAS Cloud gives Irish and EU organisations one accountable place to discover AI, determine scope, classify defensibly, assign controls and evidence every decision.

No pricing commitment. No confidential information required.