Who the AI Act applies to. You don't choose your role, what you do decides it.
Almost everyone stops at the distinction between those who build and those who use, and for most businesses that is enough. There is, however, an article that moves a company from the second box to the first without anyone deciding it, and it is the most ignored in the regulation.
The categories covered are seven, listed in Article 2. An Italian SME using other people's tools sits in the second, that of deployers established in the Union.
The regulation also reaches outside the Union. It is enough for the system's output to be used here, regardless of where the company and the server are.
The roles defined are six, not two. Provider, deployer, manufacturer, authorised representative, importer, distributor. The regulation calls them all operators.
Whoever puts their own brand on a high-risk system becomes its provider. Article 25 says so, and it also applies to whoever changes the purpose of a general-purpose tool.
This piece sits within the guide to the AI Act obligations for companies and SMEs and looks more closely at its scope. It is written for whoever runs a business, and it ends where a lawyer's work begins.
The seven categories of Article 2
Article 2(1) lists who the regulation applies to, and the list is wider than people think. It includes providers placing on the market or putting into service AI systems in the Union, established here or in a third country, and deployers that have their place of establishment or are located in the Union.
It continues with providers and deployers from third countries when the output reaches the Union, importers and distributors, product manufacturers placing an AI system on the market together with their product and under their own name, authorised representatives of providers not established in the Union, and affected persons located in the Union.
The last item surprises, and it matters. The people on whom the system is used have no obligations, they have standing: the regulation names them because they are the parties the rules protect, and complaints come from there.
The criterion that takes the regulation outside Europe
Point (c) of paragraph 1 is the provision that makes the AI Act a rule with global effects. It covers providers and deployers established in a third country, where the output produced by the system is used in the Union.
The criterion is where the result goes, not the geography of the infrastructure. An American provider serving European customers falls within it, and so does a non-European company using a system whose outputs end up here. For an Italian SME the practical consequence is reassuring: the tools you buy are subject to the regulation even when the seller is overseas, and you can ask them for it in the contract.
The guide's pillar page explains the same principle applied to the transparency obligations of Article 50. Here the point is more general, and applies to the whole regulation.
Six roles, not two
Article 3 defines the figures, and the regulation groups them under the term operator. Knowing them matters because obligations aren't distributed at random: they follow the role, and the role follows from the facts.
| Role | The regulation's definition | When it is yours |
|---|---|---|
| ProviderArticle 3, point 3 | Whoever develops an AI system, or has it developed, and places it on the market or puts it into service under their own name or trademark, whether for payment or free of charge. |
If you build or have built a tool and put it into circulation under your name. Even for free. |
| DeployerArticle 3, point 4 | Whoever uses an AI system under their own authority, except in the course of a personal non-professional activity. |
The case of almost all SMEs. You buy third-party tools and use them in the company. |
| ImporterArticle 3, point 6 | Whoever is established in the Union and places on the market a system bearing the name or trademark of a party established in a third country. |
If you resell in Europe a tool from a non-European maker, keeping its brand. |
| DistributorArticle 3, point 7 | Whoever is in the supply chain, other than the provider or importer, and makes a system available on the Union market. |
If you resell or integrate other people's tools for your customers. |
| Authorised representativeArticle 3, point 5 | Whoever is established in the Union and has received and accepted a written mandate from a provider to carry out the obligations on their behalf. |
Only with a written mandate. It isn't a role you end up in by chance. |
| Product manufacturerArticle 2, point (e) | Whoever places a product on the market together with an AI system, under their own name or trademark. |
If you produce machines or devices with an intelligent component inside. |
The practical difference between the two main roles lies in the quantity of obligations. The provider answers for Article 16 and the whole compliance framework; the deployer of high-risk systems answers for Article 26, much lighter. Below high risk, the deployer has mainly information obligations.
The role also matters when it comes to consequences. Article 99(4) puts in the same band, up to €15 million or 3% of total worldwide annual turnover, both the obligations of providers under Article 16 and those of deployers under Article 26. It changes how many obligations you have, not how much it costs to get them wrong, and for SMEs the lower of the two amounts applies.
When whoever uses becomes whoever provides
It is Article 25, and it changes a company's position without anyone signing anything. A distributor, an importer, a deployer or another third party is considered a provider of a high-risk system, with all the obligations of Article 16, in three circumstances.
«They put their name or trademark on a high-risk AI system already placed on the market or put into service, without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated.»
Regulation (EU) 2024/1689, Article 25(1)(a)
The second circumstance is a substantial modification of a high-risk system already in circulation. The third is the most insidious: changing the intended purpose of a system not classified as high-risk, including a general-purpose system, in such a way that it becomes high-risk under Article 6.
Translated into a real case: a company takes a generic generative model and uses it to filter applications for a job. That use falls under point 4 of Annex III, so it has changed the purpose by bringing the system into high risk, and Article 25 puts the company in the provider's shoes. The full picture of classification is on the page about AI Act risk levels.
Paragraph 2 closes the circle: when this happens, the initial provider is no longer considered the provider of that system, and must cooperate by making available the information and reasonably expected technical access. Point (a) is without prejudice to contractual arrangements, which makes the contract with your provider a document worth reading before rebranding anything.
Who the regulation doesn't apply to
The exclusions are in the same Article 2, and they are narrower than they are made out to be. The regulation does not apply to systems placed on the market, put into service or used exclusively for military, defence or national security purposes, regardless of who carries out the activity.
It doesn't apply to systems developed and put into service for the sole purpose of scientific research and development, nor to research, testing and development activities prior to placing on the market. On the latter there is a clear limit: testing in real-world conditions isn't covered by the exclusion.
The exclusion most often invoked inappropriately is paragraph 10, on the obligations of deployers who are natural persons using AI systems in the course of a purely personal non-professional activity. It concerns private use at home. An owner using a generative model for their company's work isn't in that case, even if they use it from their own laptop.
Areas outside the scope of Union law are also excluded, and the regulation is without prejudice to the rules on the liability of intermediary service providers, those on consumer protection and product safety, or the GDPR, as the page on AI Act and GDPR explains.
The line that leaves room for States on workers
Article 2(11) says something that has already had effects in Italy. The regulation doesn't prevent the Union or Member States from maintaining or introducing provisions more favourable to workers regarding the use of AI systems by employers, or from encouraging more favourable collective agreements.
It is the door through which Article 11 of Law 132/2025 passes, requiring the employer or client to inform the worker of the use of artificial intelligence, in the cases and ways set out in Legislative Decree 152 of 1997.
For an Italian company it means that looking only at the European regulation isn't enough to know what it must do towards its own employees. On that front the rule to read is Italian, and it contains an obligation the AI Act doesn't.
How to establish your own role in ten minutes
The role follows from the facts, so the quickest way is to answer three questions for each system you have in-house. They should be asked per system, because the same company can be the deployer of one tool and the provider of another.
One, whose name is on it. If the tool arrives and is used under the brand of whoever built it, you are a deployer. If you put your own name on it in front of customers, look at Article 25 before going further.
Two, what you make it do. The real purpose of use, not the catalogue one. If you have brought a generic tool into an Annex III case, the role has changed with the use.
Three, who comes after you. If you resell, integrate or make the tool available to others, you are also distributors, and the obligations add up instead of replacing each other.
The human step, and what we sign before building
When a system is custom-built, the question of who the provider is must be decided before the first line of code, not after. Article 25(1)(a) expressly preserves contractual arrangements that allocate obligations differently, and that step is written into the contract or doesn't exist.
In the systems we build the operating rule is written together with the scope: every message that commits the company, that is, offers, quotes, prices and confirmations, goes out only after a person has read and approved it. Replies on information already approved by the owner can go out on their own, the owner switches the function on and off channel by channel, and the reply states that it is a system as Article 50 requires, applicable from 2 August 2026.
The extended scope, with what we never do, is in the AI principles, and the list of systems we actually use is on the AI transparency page.
Questions and answers
Who does the AI Act apply to?
Article 2(1) lists seven categories: providers placing systems in the Union even if established elsewhere; deployers established or located in the Union; providers and deployers from third countries when the output is used in the Union; importers and distributors; product manufacturers placing a system on the market under their own brand; authorised representatives; and affected persons located in the Union.
An Italian SME using third-party tools almost always falls into the second category, that of deployers.
Does it also apply to companies outside the European Union?
Yes. Point (a) covers providers placing systems on the Union market regardless of where they are established. Point (c) goes further: it covers providers and deployers from third countries where the output produced by the system is used in the Union.
What counts is where the result ends up, not where the company or the server is. For those buying tools, the useful consequence is that the regulation applies even when the seller is overseas.
Can whoever uses a system become its provider?
Yes, under Article 25, in three circumstances: if they put their own name or trademark on a high-risk system already in circulation, unless contractual arrangements provide otherwise; if they make a substantial modification to it; or if they change the intended purpose of a non-high-risk system, including a general-purpose one, in such a way that it becomes high-risk.
When this happens, whoever placed it on the market is no longer considered its provider, and must cooperate by providing information and technical access.
Who doesn't it apply to?
It doesn't apply to systems used exclusively for military, defence or national security purposes, to those developed for the sole purpose of scientific research and development, or to research, testing and development activities prior to placing on the market. Testing in real-world conditions, however, remains within scope.
Paragraph 10 excludes the obligations of deployers who are natural persons in a purely personal non-professional activity: it concerns private use, not use in a company from your own laptop.
What roles does the regulation provide for?
Article 3 defines six, which the regulation collectively calls operators: provider, deployer, product manufacturer, authorised representative, importer, distributor.
The provider develops and places on the market under their own name, even free of charge. The deployer uses the system under their own authority. Obligations follow the role, and the role follows from the facts instead of being chosen.
Notes on sources
- Regulation (EU) 2024/1689 (AI Act), EUR-Lex: Article 2 for scope and exclusions, Article 3 for the definitions of the roles, Article 16 for the provider's obligations, Article 25 for responsibilities along the value chain, Article 26 for the obligations of deployers of high-risk systems.
- Law No 132 of 23 September 2025, Italian Official Gazette No 223 of 25 September 2025: Article 11 on the obligation to inform the worker, which builds on the room left to Member States by Article 2(11) of the regulation.
- The definitions of the roles are given in summary form and in our own words, beyond the short quotation. For a qualification that has legal effects, the full text of Article 3 should be read, because each definition contains details this page doesn't report in full.
- This page doesn't list the obligations arising from each role, because they are the subject of Chapters II and III and change according to the system's risk level.
This article is an operational overview, not a legal opinion. On the qualification of your role in a specific case, which has contractual consequences, the answer comes from a professional who looks at your company.
The role is decided before building. Afterwards it is inherited, and it costs.
If you are about to put your name on a system, or to use a generic one inside a process that touches candidates or customers, the position you take before the regulation changes. Deciding it beforehand costs a conversation, discovering it afterwards costs a redesign. It is fifteen minutes on a call, with the Cruscotto open.