It's still a common assumption that the EU AI Act only affects organizations engaged in AI development, or large technology enterprises. In reality, the regulation applies much more broadly.
Does the EU AI Act apply to my organization? Yes. If your organization develops, provides, deploys, imports, or distributes AI systems in the EU, the AI Act likely applies. The exact requirements depend on your role in the AI value chain and the risk level of the AI you use. For most businesses, the relevant role is AI deployer: an organization that uses AI in its operations.
Read more about what the AI Act is here.
Who does EU AI Act apply to?
The AI Act recognizes several roles across the AI value chain. Your role determines which obligations you carry. It is possible (and common) to hold more than one role at once.
AI providers
Providers develop AI systems or general-purpose AI (GPAI) models and bring them to the EU market under their own name or trademark. For example, AI software providers, SaaS companies whose services include AI features, and organizations that develop internal AI products for external use fall within the scope of AI.
These providers have the broadest compliance obligations. For high-risk AI systems, this includes, for example:
- establishing a risk management system covering the entire system lifecycle
- ensuring data quality and management, preparing technical documentation
- incorporating log data collection into the system
- human-performed monitoring and cybersecurity measures
- conducting conformity assessments
- providing clear user instructions to system operators.
Importers and distributors
Organizations that import or distribute AI systems developed by others also have responsibilities under the AI Act. This relates primarily to verifying the systems they place on the market or make available already comply.
AI deployers
Deployers leverage AI systems as part of their organization’s business operations. If, for example, your organization uses various AI systems (Copilot, Claude, ChatGPT, etc.) or AI-powered chatbots, translation tools, or meeting assistants, the EU AI Act may apply to your company.
Most organizations fall into this category.
Does EU AI Act apply to SMEs? Yes. EU AI Act does not exempt small and medium-sized businesses. Obligations depend on how AI is used, rather than the size of the organization. SMEs may benefit from simplified documentation formats, guidance, and support measures, but they are still expected to comply with the requirements that apply to them.
Who is responsible for what? Providers and deployers in the AI value chain
A useful way to think about the provider-deployer split: the provider is responsible for how the AI system is built; the deployer is responsible for how it is used.
The provider shall design the system to be compliant with the requirements. This includes
- a risk management system,
- technical safeguards,
- human-operated control mechanisms,
- and user manuals that explain to users how to use the system safely and for what purpose it is intended.
Deployer's responsibilities begin where the provider’s decision-making ends. A deployer of a high-risk AI system must, among other things:
- Use the system in accordance with the provider’s user instructions
- Designate qualified and trained personnel to perform oversight
- Ensure that the data under their control is relevant and representative for the intended purpose
- Monitor the system’s operation and notify the service provider of risks, malfunctions, and serious disruptions
- Retain the log data they manage themselves
For this reason, risk management under AI Act is a shared responsibility. The service provider cannot control every situation in which the system is used, nor can the user see the details of the system’s design. EU AI Act recognizes this tension and seeks to resolve it: The provider manages the risks it can anticipate during the design phase and communicates residual risks through user manuals; The deployer manages the risks that only become apparent during actual use and feeds their observations back into the operational chain.
What should every organization do?
Start with the universal requirements
Before diving into roles, risk levels, and classifications, it's worth knowing that the AI Act contains requirements that apply universally — to every organization that uses AI, regardless of role or risk category. These should be the starting point for managing AI.
AI literacy. All organizations are expected to ensure that personnel using AI have adequate training on AI usage and an appropriate level of AI literacy in general. This means employees should understand what AI tools they are using, what those tools can and cannot do, and what risks come with them — proportionate to their role and the context of use.
Voluntary codes of conduct. Organizations can also commit to responsible use of AI by adopting voluntary codes of conduct. These allow organizations — including those whose AI use falls outside the stricter obligation categories — to demonstrate a structured commitment to trustworthy AI, often by voluntarily applying elements of the high-risk requirements to lower-risk systems.
Understanding risk the way the AI Act understands it
The AI Act flips the conventional direction of risk. In traditional security and risk management (for example, ISO 27001), organizations primarily manage risks that the outside world projects onto them: these typically include threats, breaches, disruptions, financial loss. The AI Act is largely uninterested in that direction. It is primarily concerned with the risks your organization's use of AI projects outward. In other words, it aims to regulate how your organisations AI usage affects individuals, groups, and society.
When an AI system endangers your business it is for the most part your problem. The greatest regulatory burden of the AI Act is reserved for areas where AI can endanger people's health, safety, or fundamental rights. Your duty as an organisation is therefore to manage the AI risks you project onto society, whether you are deploying or providing the AI system responsible for producing these risks.
The provider and deployer categories are best understood as a subset of the risk categories. The risk level of the system sets the ceiling of the regulatory burden and your role determines your share of it. A provider of a limited-risk AI system faces a far lighter burden than a provider of a high-risk AI system. A deployer of a minimal-risk chatbot has very little to do; a deployer of a high-risk recruitment system has substantial operational obligations. Role alone tells you little. Your regulatory burden is determined by your role and your risk profile.
Can your AI use change your role?
For most organizations, the single most important thing to understand is this: how you use AI can change how you are classified under the AI Act.
The boundary between deployer and provider is not fixed — certain actions by a deployer can trigger a role reclassification. This means the organization must assume provider status. For many organisations this would be an extremely undesirable outcome, because providers face the full weight of the regulatory burden under the AI Act.
In broad terms, a deployer (or importer, distributor, or other third party) is treated as the provider of a high-risk AI system if it:
- Puts its own name or trademark on a high-risk AI system already on the market
- Substantially modifies a high-risk AI system in a way not foreseen by the original provider
- Changes the intended purpose of an AI system — including a general-purpose one — so that it becomes a high-risk system
These are not rare or unlikely scenarios. White-labelling a vendor's tool as your own product, fine-tuning or significantly reworking a purchased system, or repurposing a general-purpose tool into into something else are extremely common practices. They can all cross the line when an AI system is involved. And that is when the obligations of a high-risk provider land on your organization. This includes additional risk management, technical documentation maintenance, conformity assessment and post-market monitoring. For most organisations this would be a singularly undesirable turn of events.
The most critical task for organizations is therefore to be able to answer the question: Which of our AI activities could plausibly trigger reclassification, and who reviews new AI use cases against that risk? This question is the line in the sand separating a manageable deployer compliance program from an unplanned provider-level one.
How should AI systems be managed?
You don't need to assess every AI system in detail on day one. For most, compliance starts with understanding how AI is used and establishing basic guidelines around this usage.
1. Create an AI inventory. Document which AI tools your organization uses and what they are used for.
2. Assign ownership. Someone should be responsible for AI governance, policies, and compliance.
3. Understand your role. Are you a provider, deployer, or both? Different roles have different obligations.
4. Identify high-risk AI. Most organizations won't use high-risk AI, but it's important to know if any systems fall into that category.
5. Review transparency requirements. If people interact with AI or receive AI-generated content, transparency obligations may apply.
6. Train employees. Employees should understand how AI can be used responsibly and securely.
EU AI Act implementation: Where are we now?
The EU AI Act is now well into its phased implementation. Several important obligations are already in force.
The next major milestones primarily affect organizations that develop or deploy high-risk AI systems.
- December 2027 – Most obligations for standalone high-risk AI systems are expected to apply under the revised implementation timeline.
- August 2028 – Remaining obligations for certain AI systems embedded in regulated products become applicable.
While these deadlines may seem distant, maturing their AI processes and building an AI inventory, assigning ownership, and documenting AI use sooner than later makes future compliance significantly easier.

Frequently asked questions
Does every company need an AI policy?
Not explicitly. However, documenting how AI may be used is a practical way to demonstrate governance and responsible AI use.
What is an AI inventory?
An AI inventory is a list of AI systems used across your organization, including their purpose, owner, and potential risks.
We only use ChatGPT or Microsoft Copilot. Does the AI Act still apply?
Usually, yes. Using general-purpose AI tools does not make your organization an AI provider, but it does make you an AI deployer.
This means you should:
- Know where AI is used
- Train employees on responsible AI use
- Meet applicable transparency requirements
- Establish basic AI governance
Note: Repurposing a general-purpose tool into a high-risk use case, or building it into a product under your own name, can change your classification. See the section on role reclassification above.
What is a high-risk AI system?
High-risk AI systems are used in areas such as employment, education, healthcare, law enforcement, and critical infrastructure. They are subject to stricter requirements than general-purpose AI tools because of their capacity to affect individuals, groups, and society. This is how the AI Act defines risk.
Can I ignore the AI Act if my company is outside the EU?
Not necessarily. The AI Act can apply to organizations outside the EU if their AI systems are placed on the EU market or their outputs are used within the EU.
Getting started
So where to begin? Cyberday helps organizations build AI governance using the same practical approach already familiar from standards like ISO 27001, NIS2, and GDPR. Instead of treating AI compliance as a separate project, organizations can integrate it into their existing security management processes.
A good starting point is answering three simple questions:
- Which AI systems do we use?
- Who is responsible for governing them?
- Are we meeting the transparency requirements that apply to us?
From there, organizations can gradually build an AI inventory, define responsibilities, document policies, and assess AI risks as their use of AI evolves.
The AI Act is in place to ensure AI is used responsibly, transparently and consistently across the organization. Organizations that establish these governance practices today will be well prepared as additional AI Act requirements come into force in the coming years. They will also promote safer and more responsible use of AI across the business.

















