It's still a common assumption that the EU AI Act only affects organizations engaged in AI development, or large technology enterprises. In reality, the regulation applies much more broadly.
Does the EU AI Act apply to my organization? Yes. If your organization develops, provides, deploys, imports, or distributes AI systems in the EU, the AI Act likely applies. The exact requirements depend on your role in the AI value chain and the risk level of the AI you use. For most businesses, the relevant role is AI deployer: an organization that uses AI in its operations.
Read more about what the AI Act is here.
Who does EU AI Act apply to?
The AI Act recognizes several roles across the AI value chain. Your role determines which obligations you carry. It is possible (and common) to hold more than one role at once.
AI providers
Providers develop AI systems or general-purpose AI (GPAI) models and bring them to the EU market under their own name or trademark. For example, AI software providers, SaaS companies whose services include AI features, and organizations that develop internal AI products for external use fall within the scope of AI.
These providers have the broadest compliance obligations. For high-risk AI systems, this includes, for example:
- establishing a risk management system covering the entire system lifecycle
- ensuring data quality and management, preparing technical documentation
- incorporating log data collection into the system
- human-performed monitoring and cybersecurity measures
- conducting conformity assessments
- providing clear user instructions to system operators.
Importers and distributors
Organizations that import or distribute AI systems developed by others also have responsibilities under the AI Act. This relates primarily to verifying the systems they place on the market or make available already comply.
AI deployers
Deployers leverage AI systems as part of their organization’s business operations. If, for example, your organization uses various AI systems (Copilot, Claude, ChatGPT, etc.) or AI-powered chatbots, translation tools, or meeting assistants, the EU AI Act may apply to your company.
Most organizations fall into this category.
Does EU AI Act apply to SMEs? Yes. EU AI Act does not exempt small and medium-sized businesses. Obligations depend on how AI is used, rather than the size of the organization. SMEs may benefit from simplified documentation formats, guidance, and support measures, but they are still expected to comply with the requirements that apply to them.
Who is responsible for what? Providers and deployers in the AI value chain
A useful way to think about the provider-deployer split: the provider is responsible for how the AI system is built; the deployer is responsible for how it is used.
The provider shall design the system to be compliant with the requirements. This includes
- a risk management system,
- technical safeguards,
- human-operated control mechanisms,
- and user manuals that explain to users how to use the system safely and for what purpose it is intended.
Deployer's responsibilities begin where the provider’s decision-making ends. A deployer of a high-risk AI system must, among other things:
- Use the system in accordance with the provider’s user instructions
- Designate qualified and trained personnel to perform oversight
- Ensure that the data under their control is relevant and representative for the intended purpose
- Monitor the system’s operation and notify the service provider of risks, malfunctions, and serious disruptions
- Retain the log data they manage themselves
For this reason, risk management under AI Act is a shared responsibility. The service provider cannot control every situation in which the system is used, nor can the user see the details of the system’s design. EU AI Act recognizes this tension and seeks to resolve it: The provider manages the risks it can anticipate during the design phase and communicates residual risks through user manuals; The deployer manages the risks that only become apparent during actual use and feeds their observations back into the operational chain.
What should every organization do?
Start with the universal requirements
Before we delve into roles, risk levels, and classifications, it’s important to know that the AI Act includes requirements that generally apply to all organizations using AI, regardless of their role or risk category. These should serve as the foundation for AI governance.
AI literacy. All organizations are expected to ensure that staff using AI have sufficient training in AI usage and, more generally, appropriate AI literacy. This means that employees should understand what AI tools they are using, what these tools are capable of and what they are not capable of, and what risks are associated with them in relation to their role and the context of use.
Voluntary codes of conduct. Organizations can also commit to the responsible use of AI by adopting voluntary codes of conduct. These allow organizations, including those whose use of AI is not subject to stricter obligations to demonstrate their systematic commitment to trustworthy AI, often by voluntarily applying elements of high-risk requirements to lower-risk systems.
Understanding risk the way the AI Act understands it
The AI Act flips the conventional direction of risk. In traditional security and risk management (for example, ISO 27001), organizations primarily manage risks that the outside world projects onto them: these typically include threats, breaches, disruptions, financial loss. The AI Act is largely uninterested in that direction. It is primarily concerned with the risks your organization's use of AI projects outward. In other words, it aims to regulate how your organisations AI usage affects individuals, groups, and society.
When an AI system endangers your business it is for the most part your problem. The greatest regulatory burden of the AI Act is reserved for areas where AI can endanger people's health, safety, or fundamental rights. Your duty as an organisation is therefore to manage the AI risks you project onto society, whether you are deploying or providing the AI system responsible for producing these risks.
The provider and deployer categories are best understood as a subset of the risk categories. The risk level of the system sets the ceiling of the regulatory burden and your role determines your share of it. A provider of a limited-risk AI system faces a far lighter burden than a provider of a high-risk AI system. A deployer of a minimal-risk chatbot has very little to do; a deployer of a high-risk recruitment system has substantial operational obligations. Role alone tells you little. Your regulatory burden is determined by your role and your risk profile.
Can your AI use change your role?
For most organizations, the most important thing to understand is this: how AI is used can affect which category the organization falls into under the AI Act.
The line between the adopter and the provider is not fixed. Certain actions by the adopter may lead to a reclassification of its role. This means that the organization would have to assume the role of a provider. For many organizations, this would be a highly undesirable outcome, as providers are required to bear the full regulatory burden under the AI Act.
Generally speaking, a deployer (or importer, distributor, or other third party) is treated as a provider of a high-risk AI system if it:
- adds its own name or trademark to a high-risk AI system already on the market
- substantially modifies a high-risk AI system in a way not anticipated by the original service provider
- changes the intended use of the AI system, including modifying a general-purpose system so that it becomes a high-risk system
These are not rare or unlikely scenarios. White-labelling a vendor's tool as your own product, fine-tuning or significantly reworking a purchased system, or repurposing a general-purpose tool into into something else are extremely common practices. They can all cross the line when an AI system is involved. And that is when the obligations of a high-risk provider land on your organization. This includes additional risk management, technical documentation maintenance, conformity assessment and post-market monitoring. For most organisations this would be a singularly undesirable turn of events.
The most critical task for organizations is therefore to be able to answer the question: Which of our AI activities could plausibly trigger reclassification, and who reviews new AI use cases against that risk? This question is the line in the sand separating a manageable deployer compliance program from an unplanned provider-level one.
How should AI systems be managed?
You don't need to assess every AI system in detail on day one. For most, compliance starts with understanding how AI is used and establishing basic guidelines around this usage.
1. Create an AI inventory. Document which AI tools your organization uses and what they are used for.
2. Assign ownership. Someone should be responsible for AI governance, policies, and compliance.
3. Understand your role. Are you a provider, deployer, or both? Different roles have different obligations.
4. Identify high-risk AI. Most organizations won't use high-risk AI, but it's important to know if any systems fall into that category.
5. Review transparency requirements. If people interact with AI or receive AI-generated content, transparency obligations may apply.
6. Train employees. Employees should understand how AI can be used responsibly and securely.
EU AI Act implementation: Where are we now?
The EU AI Act is now well into its phased implementation. Several important obligations are already in force.
The next major milestones primarily affect organizations that develop or deploy high-risk AI systems.
- December 2027 – Most obligations for standalone high-risk AI systems are expected to apply under the revised implementation timeline.
- August 2028 – Remaining obligations for certain AI systems embedded in regulated products become applicable.
While these deadlines may seem distant, maturing their AI processes and building an AI inventory, assigning ownership, and documenting AI use sooner than later makes future compliance significantly easier.

Veelgestelde vragen
Does every company need an AI policy?
Not explicitly. However, documenting how AI may be used is a practical way to demonstrate governance and responsible AI use.
What is an AI inventory?
An AI inventory is a list of AI systems used across your organization, including their purpose, owner, and potential risks.
We only use ChatGPT or Microsoft Copilot. Does the AI Act still apply?
Usually, yes. Using general-purpose AI tools does not make your organization an AI provider, but it does make you an AI deployer.
This means you should:
- Know where AI is used
- Train employees on responsible AI use
- Meet applicable transparency requirements
- Establish basic AI governance
Note: Repurposing a general-purpose tool into a high-risk use case, or building it into a product under your own name, can change your classification. See the section on role reclassification above.
What is a high-risk AI system?
High-risk AI systems are used in areas such as employment, education, healthcare, law enforcement, and critical infrastructure. They are subject to stricter requirements than general-purpose AI tools because of their capacity to affect individuals, groups, and society. This is how the AI Act defines risk.
Can I ignore the AI Act if my company is outside the EU?
Not necessarily. The AI Act can apply to organizations outside the EU if their AI systems are placed on the EU market or their outputs are used within the EU.
Aan de slag
So where to begin? Cyberday helps organizations build AI governance using the same practical approach already familiar from standards like ISO 27001, NIS2, and GDPR. Instead of treating AI compliance as a separate project, organizations can integrate it into their existing security management processes.
A good starting point is answering three simple questions:
- Which AI systems do we use?
- Who is responsible for governing them?
- Are we meeting the transparency requirements that apply to us?
From there, organizations can gradually build an AI inventory, define responsibilities, document policies, and assess AI risks as their use of AI evolves.
The AI Act is in place to ensure AI is used responsibly, transparently and consistently across the organization. Organizations that establish these governance practices today will be well prepared as additional AI Act requirements come into force in the coming years. They will also promote safer and more responsible use of AI across the business.

















