Skip to content

Published · 7 min read

How Your Customers' Use of AI Becomes Your EU AI Act Problem

For AI providers, customer deployment can create regulatory and contracting consequences that should be addressed before a product

Joy FullerJoy FullerSenior Counsel

What determines an AI system's risk classification under the EU AI Act?

The EU AI Act's classification also turns on intended purpose, actual use case, and the role the system plays in decisions affecting individuals, so the same underlying technology can carry very different obligations depending on how a customer deploys it. See Regulation (EU) 2024/1689 (the "EU AI Act"), Arts. 3(12), 6, and Annex III.

A platform used to organize internal documents is a different analysis from the same technology used to rank job applicants, assess creditworthiness, or support decisions in education, even if the underlying model is identical.

Check your customer's use case. Pick how your product is actually being deployed and we'll show you the likely risk tier and fine exposure, no email required.

Risk tierExampleMaximum fine (Article 99/101)
Unacceptable (prohibited)Certain social scoring, manipulative or exploitative systems€35M or 7% of global turnover
High-riskEmployment, credit scoring, education, essential services (Annex III)€15M or 3% of global turnover
Limited / GPAI transparencyChatbots, deepfakes, general-purpose models€15M or 3% of global turnover
Other non-complianceIncorrect or misleading information to regulators€7.5M or 1% of global turnover
Prohibited AI practices carry the EU AI Act's steepest fines Bar chart comparing maximum fixed fines under EU AI Act Article 99: 35 million euros for prohibited practices, 15 million euros for high-risk or GPAI violations, and 7.5 million euros for providing incorrect information, whichever is higher against a percentage of global turnover. Hover each bar for detail. Prohibited AI practices carry the steepest fines Maximum fixed fine by violation tier, EU AI Act Article 99 (hover a bar) €7.5M Info failures €15M High-risk / GPAI €35M Prohibited practices Each tier is capped at the fixed euro amount or a percentage of global turnover, whichever is higher. Source: Regulation (EU) 2024/1689, Article 99 and Article 101

Why does a customer's use of my product become my regulatory risk?

Because your own product design, sales materials, documentation, onboarding process, and technical configuration can influence, or reveal, the uses you intend or reasonably expect a customer to make of your system, and that shapes your own obligations even though you don't control the customer's ultimate deployment.

This isn't a one-time exercise at launch. Providers should identify foreseeable regulated use cases early and decide whether to address them through product architecture, configuration controls, customer diligence, use restrictions, or other governance mechanisms, since a use case that looked unlikely at launch can become common once customers start building on the product.

Which customer use cases trigger high-risk status under the EU AI Act?

Employment, education, financial services, insurance, and other Annex III sectors draw heightened regulation whenever the system plays a role in a decision affecting an individual. A predictive model used for inventory forecasting is a different regulatory question from the same model used to evaluate an individual's creditworthiness. A behavioral-monitoring tool used for ordinary workplace analytics is a different question from the same tool deployed in an educational setting covered by Annex III. In some contexts, a particular feature may also raise prohibited-use concerns under Article 5.

Not every product with these capabilities is high-risk. What matters is whether you know which customer deployments are reasonably foreseeable and what those deployments mean for your own obligations.

When do these EU AI Act obligations actually take effect?

Some of them already have. Prohibited practices have been banned since February 2, 2025. GPAI obligations have applied since August 2, 2025, but fines for GPAI and transparency violations only became enforceable on August 2, 2026, per the European Commission. The Annex III high-risk conformity deadline, by contrast, was pushed to December 2, 2027 under the Digital Omnibus (Regulation 2026/1744, signed July 27, 2026).

These dates don't move together, and a provider whose product isn't Annex III high-risk can still be exposed right now, today, under the GPAI and transparency rules that are already enforceable, regardless of the later high-risk deadline.

DateWhat changesStatus
February 2, 2025Prohibited AI practices bannedIn effect
August 2, 2025GPAI model obligations applyIn effect
August 2, 2026GPAI and transparency fines become enforceableIn effect
December 2, 2026Ban on AI tools generating non-consensual sexual deepfakes / CSAMUpcoming
December 2, 2027Annex III high-risk conformity deadline (deferred by Digital Omnibus)Upcoming

Can a contract limit an AI provider's EU AI Act exposure?

Not entirely. Customer agreements can't eliminate statutory obligations under the AI Act, and customers may carry independent obligations of their own as deployers. But a contract can establish boundaries around authorized use and give the provider mechanisms for managing changes in deployment. Depending on the product, that can include:

01Intended and prohibited uses

Stated specifically rather than left implicit.

02Customer representations

About how the product will actually be deployed.

03Material-change-in-use-case provisions

So a shift in deployment triggers a check rather than going unnoticed.

04Implementation responsibilities and human oversight requirements

Allocated between provider and customer.

05Compliance cooperation and incident reporting

Obligations that keep both parties informed as risk develops.

06Rights to suspend or restrict

A deployment that creates material regulatory risk.

For a configurable AI product, the contract becomes part of the provider's broader governance framework, not just a liability-allocation document.

What questions should AI providers ask before launching or expanding into the EU?

01What customer workflows are we actually targeting?

Naming the real workflow, not the marketed one, is the starting point for everything else on this list.

02Which regulated decisions could our product influence?

Trace the output forward to the decision it actually feeds, not just the feature itself.

03Which uses are intended, reasonably foreseeable, or merely technically possible?

These three categories carry different weight for classification purposes, and conflating them is where providers get it wrong.

04Are our documentation and marketing materials consistent with those boundaries?

Sales language that invites a regulated use undercuts a contract that tries to restrict it.

05Should particular customers or use cases get additional review before onboarding?

Not every customer relationship carries the same regulatory profile.

06Can technical controls prevent or manage unacceptable deployments?

Configuration limits can do work that a contract clause alone can't.

These questions put product, engineering, sales, legal, compliance, and commercial teams in the same conversation, and let a provider address regulatory risk before it becomes a customer or enforcement problem.

What should a provider do about this?

You don't need to assume responsibility for every way a customer might use your technology. But you should have a clear view of the uses you're enabling, encouraging, and reasonably expecting, and build those assumptions into your product and commercial framework from the outset, not after a regulator or a customer's due diligence team asks about it first.

General Legal can help you assess which customer use cases apply to your product and translate that analysis into practical product controls, customer diligence, and contract terms. Contact the AI & technology practice to talk through where the risk actually sits.

Quick answers

Does the EU AI Act classify systems by what they do or how they're used?
Both. Intended purpose, actual use case, and the system's role in decisions affecting individuals all factor into classification.
Can a provider be responsible for a customer's misuse of its product?
Customer use can affect the provider's own risk profile, especially where product design, sales materials, or configuration options reveal or invite regulated uses.
When do EU AI Act fines actually start?
Fines for GPAI and transparency obligations became enforceable August 2, 2026. The Annex III high-risk conformity deadline was deferred to December 2, 2027.
Can a contract eliminate an AI provider's statutory obligations?
No, but it can set boundaries around authorized use and require notice before a customer's deployment changes materially.
What's the single biggest risk for AI providers right now?
Assuming the Annex III deferral means no exposure. GPAI and transparency obligations are enforceable today regardless of high-risk status.

Sources