The AI Act doesn't only bind big tech. It reaches most organisations that build or use AI touching the EU — often by a role you may not realise you hold. Two quick checks tell you where you stand: are you in scope, and which role are you. Then you can jump straight to the obligations that are actually yours.
A plain-language orientation — not legal advice. Every duty links to the official text.
The Act applies directly in every EU member state — and it reaches beyond the EU's borders. If any one of these is you, you're in scope:
You're established or located in the EU and you make or use AI.
You're outside the EU but you place an AI system or general-purpose AI model on the EU market.
You're outside the EU but your AI system's output is used inside the EU.
If none of these describes you, the Act likely doesn't reach you today. But its definitions are broad — so it's worth checking the roles below before you rule it out.
The Act assigns duties by role, not by industry — and you can hold more than one at once (a company that builds a tool and also uses it is both a provider and a deployer). Find the one that fits, then open its obligations.
You develop an AI system or a general-purpose AI model — or have one developed — and put it on the market or into service under your own name or trademark. Building it, or badging someone else's system as your own, makes you a provider.
See a Provider's obligations →You use an AI system in the course of your business or work, under your own authority — a CV-screening tool, a customer chatbot, an AI decision aid your team relies on. Most organisations that simply use AI are deployers. (Purely personal, non-professional use doesn't count.)
See a Deployer's obligations →You're established in the EU and a provider outside the EU has appointed you, in writing, to act on their behalf for their obligations under the Act.
See a Authorised Representative's obligations →You're a conformity-assessment body that has been notified (officially designated) to carry out third-party assessments of high-risk AI systems.
You carry out conformity-assessment activities — the testing, certification and inspection of AI systems against the Act's requirements.
The European Commission and its AI Office, with duties that run across the whole Act.
National competent authorities, market-surveillance authorities and other public bodies that supervise and enforce the Act.
Other parties named in specific obligations of the Act.
Not every AI system carries the same weight. The Act scales its rules to risk — from a handful of outright bans to no new duties at all for everyday tools.
A short list of practices is banned outright (for example social scoring, or AI that manipulates people to their harm). If your system does one of these, it can't be used in the EU.
Allowed, but with the Act's strictest obligations: risk management, data governance, documentation, human oversight and conformity assessment. Think AI used in hiring, credit, safety components, or biometric identification.
You mainly have to be open about it: tell people when they're interacting with AI, and label AI-generated or manipulated content such as deepfakes.
The vast majority of AI — spam filters, recommendation engines, AI in games — carries no new obligations under the Act.
Found your role? Open its obligations, browse the Act article by article, or search it in plain language — all free, no account needed.
Get notified when new obligations, deadlines, or guidance are added — or ask us how the caveauAI Compliance Workbench can track this for your organization.