What determines an AI system's risk classification under the EU AI Act?
The EU AI Act's classification also turns on intended purpose, actual use case, and the role the system plays in decisions affecting individuals, so the same underlying technology can carry very different obligations depending on how a customer deploys it. See Regulation (EU) 2024/1689 (the "EU AI Act"), Arts. 3(12), 6, and Annex III.
A platform used to organize internal documents is a different analysis from the same technology used to rank job applicants, assess creditworthiness, or support decisions in education, even if the underlying model is identical.
Check your customer's use case. Pick how your product is actually being deployed and we'll show you the likely risk tier and fine exposure, no email required.
| Risk tier | Example | Maximum fine (Article 99/101) |
|---|---|---|
| Unacceptable (prohibited) | Certain social scoring, manipulative or exploitative systems | €35M or 7% of global turnover |
| High-risk | Employment, credit scoring, education, essential services (Annex III) | €15M or 3% of global turnover |
| Limited / GPAI transparency | Chatbots, deepfakes, general-purpose models | €15M or 3% of global turnover |
| Other non-compliance | Incorrect or misleading information to regulators | €7.5M or 1% of global turnover |
Why does a customer's use of my product become my regulatory risk?
Because your own product design, sales materials, documentation, onboarding process, and technical configuration can influence, or reveal, the uses you intend or reasonably expect a customer to make of your system, and that shapes your own obligations even though you don't control the customer's ultimate deployment.
This isn't a one-time exercise at launch. Providers should identify foreseeable regulated use cases early and decide whether to address them through product architecture, configuration controls, customer diligence, use restrictions, or other governance mechanisms, since a use case that looked unlikely at launch can become common once customers start building on the product.
Which customer use cases trigger high-risk status under the EU AI Act?
Employment, education, financial services, insurance, and other Annex III sectors draw heightened regulation whenever the system plays a role in a decision affecting an individual. A predictive model used for inventory forecasting is a different regulatory question from the same model used to evaluate an individual's creditworthiness. A behavioral-monitoring tool used for ordinary workplace analytics is a different question from the same tool deployed in an educational setting covered by Annex III. In some contexts, a particular feature may also raise prohibited-use concerns under Article 5.
Not every product with these capabilities is high-risk. What matters is whether you know which customer deployments are reasonably foreseeable and what those deployments mean for your own obligations.
When do these EU AI Act obligations actually take effect?
Some of them already have. Prohibited practices have been banned since February 2, 2025. GPAI obligations have applied since August 2, 2025, but fines for GPAI and transparency violations only became enforceable on August 2, 2026, per the European Commission. The Annex III high-risk conformity deadline, by contrast, was pushed to December 2, 2027 under the Digital Omnibus (Regulation 2026/1744, signed July 27, 2026).
These dates don't move together, and a provider whose product isn't Annex III high-risk can still be exposed right now, today, under the GPAI and transparency rules that are already enforceable, regardless of the later high-risk deadline.
| Date | What changes | Status |
|---|---|---|
| February 2, 2025 | Prohibited AI practices banned | In effect |
| August 2, 2025 | GPAI model obligations apply | In effect |
| August 2, 2026 | GPAI and transparency fines become enforceable | In effect |
| December 2, 2026 | Ban on AI tools generating non-consensual sexual deepfakes / CSAM | Upcoming |
| December 2, 2027 | Annex III high-risk conformity deadline (deferred by Digital Omnibus) | Upcoming |
Can a contract limit an AI provider's EU AI Act exposure?
Not entirely. Customer agreements can't eliminate statutory obligations under the AI Act, and customers may carry independent obligations of their own as deployers. But a contract can establish boundaries around authorized use and give the provider mechanisms for managing changes in deployment. Depending on the product, that can include:
01Intended and prohibited uses
Stated specifically rather than left implicit.
02Customer representations
About how the product will actually be deployed.
03Material-change-in-use-case provisions
So a shift in deployment triggers a check rather than going unnoticed.
04Implementation responsibilities and human oversight requirements
Allocated between provider and customer.
05Compliance cooperation and incident reporting
Obligations that keep both parties informed as risk develops.
06Rights to suspend or restrict
A deployment that creates material regulatory risk.
For a configurable AI product, the contract becomes part of the provider's broader governance framework, not just a liability-allocation document.
What questions should AI providers ask before launching or expanding into the EU?
01What customer workflows are we actually targeting?
Naming the real workflow, not the marketed one, is the starting point for everything else on this list.
02Which regulated decisions could our product influence?
Trace the output forward to the decision it actually feeds, not just the feature itself.
03Which uses are intended, reasonably foreseeable, or merely technically possible?
These three categories carry different weight for classification purposes, and conflating them is where providers get it wrong.
04Are our documentation and marketing materials consistent with those boundaries?
Sales language that invites a regulated use undercuts a contract that tries to restrict it.
05Should particular customers or use cases get additional review before onboarding?
Not every customer relationship carries the same regulatory profile.
06Can technical controls prevent or manage unacceptable deployments?
Configuration limits can do work that a contract clause alone can't.
These questions put product, engineering, sales, legal, compliance, and commercial teams in the same conversation, and let a provider address regulatory risk before it becomes a customer or enforcement problem.
What should a provider do about this?
You don't need to assume responsibility for every way a customer might use your technology. But you should have a clear view of the uses you're enabling, encouraging, and reasonably expecting, and build those assumptions into your product and commercial framework from the outset, not after a regulator or a customer's due diligence team asks about it first.
General Legal can help you assess which customer use cases apply to your product and translate that analysis into practical product controls, customer diligence, and contract terms. Contact the AI & technology practice to talk through where the risk actually sits.
Quick answers
- Does the EU AI Act classify systems by what they do or how they're used?
- Both. Intended purpose, actual use case, and the system's role in decisions affecting individuals all factor into classification.
- Can a provider be responsible for a customer's misuse of its product?
- Customer use can affect the provider's own risk profile, especially where product design, sales materials, or configuration options reveal or invite regulated uses.
- When do EU AI Act fines actually start?
- Fines for GPAI and transparency obligations became enforceable August 2, 2026. The Annex III high-risk conformity deadline was deferred to December 2, 2027.
- Can a contract eliminate an AI provider's statutory obligations?
- No, but it can set boundaries around authorized use and require notice before a customer's deployment changes materially.
- What's the single biggest risk for AI providers right now?
- Assuming the Annex III deferral means no exposure. GPAI and transparency obligations are enforceable today regardless of high-risk status.
Sources
- European Commission, "Commission starts enforcing AI Act rules and new transparency requirements on 2 August"
- Help Net Security, "EU begins enforcing AI Act, putting AI models under the microscope", August 2026
- Enterprise DNA, "EU AI Act Enforcement Is Live: Fines Now Real", citing the Digital Omnibus, Regulation 2026/1744
- Beam AI, "EU AI Act 2026: GPAI Enforcement & 3% Fines Begin", on Article 101 GPAI penalties
- DLA Piper, "AI Laws of the World: Enforcement / fines in the European Union"
