Direct answer
We build an AI product for customers. What are a provider’s duties?
This falls under Article 16: the twelve duties of a provider of a high-risk AI system. That obligation applies from 2 December 2027. There is one exception you have to assess yourself.
This could go the other way
- A provider that considers an Annex III system not to be high-risk must document that assessment before placing it on the market and remains subject to the registration obligation of Article 49(2) (Article 6(4)). Where an AI system referred to in Annex III performs profiling of natural persons it is always considered high-risk (Article 6(3), final subparagraph).
First step: Assign an internal owner and a date to each point of Article 16.
You describe: Your organisation develops an AI system (or has it developed) and places it on the market under its own name. Likely role: provider (you place the system on the market).
This applies now
- Article 4: AI literacyApplicable
Coming up
- Article 16: the twelve duties of a provider of a high-risk AI systemfrom 2 December 2027
- Annex III: high-risk AIfrom 2 December 2027
- Article 12: logging and traceabilityfrom 2 December 2027
- Article 11: technical documentationfrom 2 December 2027
Depends on your situation
- Article 61: informed consent of test subjects for testing in real world conditionsArticle 60(4), point (i), with Article 61(1)
These provisions only apply once the stated fact is established. The locator says which provision settles it.
As provider you carry the heaviest set of duties. If your system generates content, machine-readable marking (Article 50(2)) is your job. Classify early: high-risk determines your entire development and documentation process towards 2 December 2027.
Your first actions
- Assign an internal owner and a date to each point of Article 16. Translate the twelve points (a) to (l) into twelve named owners with a start date, so that no point falls between product management, quality and legal.
- Justify the Article 6(3) exception against each individual condition. Name which of the four Article 6(3) conditions you invoke, with facts, and separately justify why the system poses no significant risk of harm to health, safety or fundamental rights and does not materially influence the outcome of decision making.
- Take role- and context-specific AI literacy measures. Determine for each role, system and context which combination of instruction, guidance, practice or training is appropriate.
Record this
- Provider dossier per high-risk AI system
- Article 49(2) registration record for the system assessed as not high-risk
- AI literacy measures record
retail and consumer
An induction call with the customer at the moment of go-live
Asimov AI is a micro organisation of at most fifteen people that supplies AI services for legislative work to government institutions and companies. With every new contract it holds one or more induction calls with the team leads and officials who will use the platform, explaining how the platform and the underlying models work and how hallucinations arise in this domain and can be mitigated.
Provenance: This practice was submitted by the organisation itself to the Commission living repository. The repository collects and shares practices; it does not approve them or set them as a standard.
This practice puts literacy where the risk arises: with the people who will operate the system, at the moment they start. For a small provider that is also the only workable moment, because there is no training department to redo it later. Anyone adopting it should record who attended and what was explained, because otherwise the effort survives only in the participants memory a year on.
Living repository of AI literacy practices, practice submitted by the organisation concerned
retail and consumer
Database query and standard spreadsheet without AI features
A customer service department runs a database query to find all customers who purchased a specific product last month, and calculates the average from a satisfaction survey in a standard spreadsheet. Every step follows predefined instructions.
Provenance: The Commission guidelines on the definition of an AI system use this case to draw the line between software that does and does not fall under the regulation. The document is non-binding.
If you rely on the basic data processing category, look at the whole lifecycle rather than the use phase alone, because that category assumes no learning, reasoning or modelling at any stage.
Commission Guidelines C(2025) 5053 final, 29.7.2025, borderline cases under the definition in Article 3(1)
retail and consumer
Security monitoring by a SaaS company: cybersecurity alone is not a safety component
A software company supplies a SaaS platform that monitors network traffic at an operator of critical digital infrastructure and reports anomalous patterns to that customer's security team. Its developers see that use at such an operator may fall under point 2 of Annex III and wonder whether their own product therefore becomes a high-risk AI system.
Provenance: The Commission draft guidelines of 19 May 2026 state that point 2 of Annex III lists AI systems intended to be used as safety components in the management and operation of, among other things, critical digital infrastructure, and that Recital 55 draws a clear distinction between a safety component and a cybersecurity component. To fall within point 2, an AI system must not be used solely for cybersecurity purposes; without a direct safety role it cannot be a safety component in critical infrastructure and therefore cannot be classified as high-risk under Article 6(2). As examples of systems used solely for cybersecurity and thus falling outside point 2, they list an AI honeypot that identifies and neutralises cyber threats in real time, technology that actively engages with potential attackers to learn new attack patterns, a system supporting the detection of unauthorised access, and a system that detects suspicious email addresses and identifies stolen data. They add that an AI system is classified as a safety component in critical infrastructure only where it is used by an entity identified as a critical entity by a Member State under the CER Directive, and that this interpretation does not require that status to be disclosed to a third-party provider. The document is a consultation version: non-binding and not yet final.
We read this passage as a line drawn function by function rather than customer by customer: the fact that your client operates critical digital infrastructure does not by itself turn your monitoring product into a safety component. What we cannot settle from the text is where mere flagging ends and a safety function begins, because the same guidelines also count monitoring and detecting situations that may directly lead to physical harm among the safety functions. The open question is therefore whether your SaaS platform stands apart from the systems that drive physical control, or in practice becomes part of them. So record, per product function, what the system performs and what it expressly leaves to the operator, because that distinction carries your entire classification and is hard to reconstruct after the fact.
Draft guidelines on the classification of high-risk AI systems, 19 May 2026, annex on Annex III, paragraphs (187), (188), (190) and (191)
retail and consumer
Static estimation of resolution time and daily sales
A service desk shows customers an expected resolution time calculated as the mean from historical tickets. A retail chain uses a trivial predictor to estimate how many units of a product it will sell each day, as a starting point for purchasing planning.
Provenance: The Commission guidelines on the definition of an AI system use this case to draw the line between software that does and does not fall under the regulation. The document is non-binding.
Keep testing whether your estimate really does no more than return an average, because as soon as you build in more complex relationships you lose the basis for this exception.
Commission Guidelines C(2025) 5053 final, 29.7.2025, borderline cases under the definition in Article 3(1)
No mandatory course format, no certificate, no exam and no AI officer
The Commission Q&A on AI literacy states that there is no one size fits all when it comes to AI literacy and that no strict requirements or mandatory trainings are imposed. On certification, the Q&A states literally that there is no need for a certificate and that organisations can keep an internal record of trainings or other guiding initiatives. On assessment, it states that Article 4 of the AI Act does not entail an obligation to measure the AI knowledge of employees. On governance, it states that no specific governance structure is mandated to comply with Article 4, so that unlike the data protection officer under the GDPR, no AI officer needs to be appointed. On the level, the Q&A states that following the Digital Omnibus amendment AI literacy remains an obligation for providers and deployers of AI systems, but that no specific or sufficient level is mandated and that the Regulation does not require guaranteeing any specific level of AI literacy of any individual. Against that, the Q&A states that simply relying on the AI systems' instructions for use or asking staff to read them might be ineffective, and that organisations should take into account general AI understanding within the organisation, whether they are a provider or a deployer, the risks associated with the systems deployed, staff knowledge gaps considering technical knowledge, experience, education and training, and contextual factors such as sector, purpose and affected populations. The Q&A further states that organisations may implement different levels of training or learning approaches depending on knowledge, experience, education and role, and that staff with a degree or experience in AI development are normally considered AI literate, while the organisation must still verify that those persons understand the specific AI systems of the organisation, know how to deal with them and are aware of all risks.
Commission Q&A on AI literacy, sections on required level, training formats, certificates, assessment of knowledge and governance structures (consulted 9 August 2026)
Article 4 reaches beyond your own staff, and the national supervisor enforces it
The Commission Q&A on AI literacy states that Article 4 applies to providers and deployers of AI systems and in addition to other persons dealing with the operation and use of AI systems on their behalf, covering persons broadly within the organisational remit, with a contractor, a service provider and a client given as examples. On clients, the Q&A states that they may need AI literacy depending on the specific risk, reasoning that affected persons should understand how decisions taken with the assistance of AI will have an impact on them. On geographic scope, the Q&A states that the AI Act's legal framework applies to both public and private actors inside and outside the EU as long as the AI system is placed on the Union market, used in the Union, or its use has an impact on people located in the EU. On supervision, the Q&A states that the supervision and enforcement of Article 4 is not with the AI Office but under the remit of national market surveillance authorities, and that supervision and enforcement began on 2 August 2026, while Article 4 itself entered into application on 2 February 2025. On sanctions, the Q&A states that national market surveillance authorities could impose penalties and other enforcement measures for infringements of Article 4, that this will be based on national laws that Member States were due to adopt by 2 August 2025, that any sanction must be proportionate and based on the individual case taking into account factors such as the nature and gravity of the infringement and its intentional or negligent character, and that sanctions are more likely if there is proof of an incident due to a lack of appropriate training and guidance. Article 4 is not listed in the enumeration in Article 99(4) of the AI Act, which covers only Articles 16, 22, 23, 24, 26, 31, 33(1), (3) and (4), 34 and 50, so the level of any penalty for Article 4 follows from national law rather than from the Regulation's own ceilings. The Q&A further states that Article 4 reinforces the transparency provisions of Article 13 and the human oversight provisions of Article 14 and indirectly contributes to the protection of affected persons, and that for deployers of high-risk systems the Article 26 obligation to ensure staff are trained to ensure human oversight is a distinct requirement; that requirement becomes applicable on 2 December 2027 for standalone Annex III systems and on 2 August 2028 for Annex I systems.
Commission Q&A on AI literacy, sections on target groups, geographic scope, supervision and enforcement, and sanctions (consulted 9 August 2026)
Article 6 has two separate routes to high-risk
The European Commission's draft guidelines on the classification of high-risk AI of 19 May 2026, which are expressly non-binding, state in paragraph (7) that an AI system is high-risk in two scenarios: first, where it is intended to be used as a safety component of a product, or is itself a product, covered by the Union harmonisation legislation listed in Annex I and required to undergo third-party conformity assessment; and second, where it falls within one of the use cases in the areas listed in Annex III. Paragraph (448) of those same draft guidelines notes that the Article 113 application dates have been postponed by the AI Omnibus to 2 December 2027 for the Article 6(2) route and 2 August 2028 for the Article 6(1) route.
Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II, paragraph (7); section V, paragraph (448)
Broadly positioned and general purpose AI systems: a disclaimer is not enough
According to the non-binding draft guidelines of 19 May 2026 on the classification of high-risk AI, paragraph (12) provides that where the instructions for use, contractual arrangements, terms of service, usage policy, promotional and sales materials or technical documentation present the AI system as broadly applicable across a generality of contexts and functions, and do not consistently limit its application or exclude high-risk uses, the system's intended purpose will be deemed to also encompass high-risk use cases and therefore qualify as high-risk. Under these draft guidelines this applies in particular where such uses are feasible and reasonably foreseeable given the system's functionalities and capabilities. The same paragraph states that merely asserting, for example in the terms of service, that high-risk uses are excluded is insufficient where the provider's overall presentation, examples or product positioning effectively provides for or promotes such uses, and that any limitations of use must be described clearly, concretely and coherently across all materials.
Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.2, paragraph (12)
prEN 18229-1: AI trustworthiness framework part 1, logging
prEN 18229-1 (AI trustworthiness framework, Part 1: Logging) is the JTC 21 deliverable under M/613 for Article 12 of the AI Act: high-risk AI systems must technically allow for the automatic recording of events over their lifetime. As at June 2026 the deliverable was at the Enquiry stage. It has not yet been published as an EN and is not cited in the Official Journal.
General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.
Full map for your situation