Legal status, scope and roles
This page explains the legal foundation that must be established before an assessor decides which substantive EU AI Act duties apply.
Source hierarchy
Section titled “Source hierarchy”Use sources in this order:
- The binding text of Regulation (EU) 2024/1689, including its annexes.
- Formally adopted amending law published in the Official Journal.
- Delegated or implementing acts in force.
- Court decisions and decisions of competent authorities where relevant.
- Commission guidelines as non-binding interpretive material.
- Codes of practice, standards and common specifications according to their legal status.
- Organisational policy and professional judgement.
Do not replace the Regulation with a vendor summary, blog, draft guideline or political agreement.
Gamut legal snapshot
Section titled “Gamut legal snapshot”The implemented methodology is reviewed as of 16 July 2026 and identifies itself as
EUAIA-2026-07-16-defensible-system-scope.
The documentation and official-source status were rechecked on 21 July 2026. The implemented identifier remains unchanged so saved assessments and workpapers stay reproducible. Formally adopted amendments require a versioned methodology update; political agreement, draft guidance or consultation material remains implementation intelligence until its legal status supports different treatment.
The record distinguishes the following:
| Status | Assessment treatment |
|---|---|
| In force | Included in the current-law conclusion when applicable |
| Future | Tracked as readiness; not counted as a current breach |
| Proposed change only | Shown as implementation intelligence, not binding law |
| Non-binding guidance | Used to inform interpretation and testing, clearly labelled |
Always show the snapshot date in exported workpapers. A legal conclusion without an “as of” date is incomplete.
Application timeline
Section titled “Application timeline”| Date | Position represented in Gamut |
|---|---|
| 1 August 2024 | Regulation entered into force |
| 2 February 2025 | Chapters I and II apply, including AI literacy and prohibited practices |
| 2 August 2025 | Governance provisions and GPAI provider duties apply |
| 2 August 2026 | General application date under the adopted Regulation, subject to specific exceptions and any formally adopted amendment |
| 2 August 2027 | Original Regulation date for Article 6(1) Annex I product-safety high-risk systems |
As of the Gamut snapshot, Commission materials describe political agreement on adjusted high-risk dates. Gamut tracks proposed dates as readiness information but does not silently substitute a political agreement for formally adopted and published law. Assessors should check the Commission implementation page and the Official Journal when making a live decision.
Territorial and material scope
Section titled “Territorial and material scope”Article 2 analysis should record, at minimum:
- Where each provider, deployer, importer and distributor is established.
- Where the system or GPAI model is placed on the market or put into service.
- Whether output produced by the system is used in the Union.
- The affected-person and customer geography.
- Whether the organisation is acting as a public authority, Union institution or private operator.
- Whether a statutory exclusion is claimed.
- The relevant system or model version and intended purpose.
The assessment must not infer “out of scope” merely because the supplier or infrastructure is outside the EU.
Exclusions
Section titled “Exclusions”Where relevant, assess and evidence exclusions such as:
- National-security, military or defence use within the statutory terms.
- Certain public-authority cooperation with third countries or international organisations.
- Research, testing or development before market placement or putting into service, subject to the statutory limits.
- Natural persons using AI in a purely personal non-professional activity.
- AI released under free and open-source licences, only to the extent and under the conditions the Regulation provides.
An exclusion is not a label of convenience. Record the exact legal provision, facts, boundary, owner, approver, evidence and reassessment trigger.
Is it an AI system?
Section titled “Is it an AI system?”Gamut requires an Article 3 definition analysis rather than assuming every automated tool is, or is not, an AI system.
Document:
- Machine-based nature.
- Degree of autonomy.
- Whether it may exhibit adaptiveness after deployment.
- Objectives, whether explicit or implicit.
- How inputs are used to infer outputs.
- Output types: predictions, content, recommendations or decisions.
- How those outputs influence physical or virtual environments.
- Intended purpose and actual deployed use.
The system boundary should include orchestration, retrieval, prompts, tools, human decision points and downstream effects where those elements determine the regulated functionality.
Intended purpose and reasonably foreseeable use
Section titled “Intended purpose and reasonably foreseeable use”The intended purpose affects high-risk classification, technical documentation, instructions, conformity and role transfer. Record:
- The provider’s stated purpose.
- The deployer’s actual use.
- Target persons and operating context.
- Excluded uses and technical restrictions.
- Marketing and contractual claims.
- Material changes since release.
- Foreseeable misuse relevant to risk management.
If actual use has moved beyond the documented intended purpose, reassess classification and whether the deployer or integrator has become a provider under Article 25.
Operator roles
Section titled “Operator roles”Roles are determined by facts, not job titles or contract labels.
| Role | Core question |
|---|---|
| Provider | Who develops, has developed, or places the system/model on the market under its name or trademark? |
| Deployer | Who uses the AI system under its authority in a professional context? |
| Importer | Who established in the Union places a third-country high-risk system on the Union market? |
| Distributor | Who makes the system available in the supply chain without being provider or importer? |
| Product manufacturer | Who places a product containing or using the high-risk system on the market under its name? |
| Authorised representative | Who is mandated and established in the Union to perform specified provider tasks? |
| GPAI model provider | Who develops or has developed and places the general-purpose AI model on the market? |
| Downstream provider | Who integrates a model into an AI system placed on the market or put into service? |
One organisation can hold several roles for one system. Different group entities can hold different roles.
Role transfer and substantial modification
Section titled “Role transfer and substantial modification”Article 25 can transfer provider obligations where a party:
- Places a high-risk system on the market under its own name or trademark.
- Makes a substantial modification.
- Changes the intended purpose so a system becomes high-risk.
Review fine-tuning, model replacement, safety-control changes, new tools, autonomy, data, user population, market claims and workflow changes. Contracts can allocate assistance and information but cannot contract away a statutory role.
Authorised representatives
Section titled “Authorised representatives”Keep these routes separate:
- Article 22: representative for a third-country provider of a high-risk AI system.
- Article 54: representative for a third-country GPAI model provider.
The mandate, tasks, documentation access and exceptions differ. Representative access should be purpose-bound, least-privilege, time-controlled and audited.
AI literacy
Section titled “AI literacy”Article 4 applies to providers and deployers. A defensible programme is role- and context-specific, not a generic annual awareness slide.
Inspect:
- Personnel and contractor roles.
- Technical knowledge, experience and education.
- System context and affected persons.
- Risks associated with the specific use.
- Training content, attendance and comprehension.
- Refresh triggers.
- Escalation and safe-use procedures.
Minimum scope-and-role record
Section titled “Minimum scope-and-role record”- Named system, version and boundary.
- Intended purpose and actual use.
- EU territorial nexus.
- Article 3 AI-system determination.
- Every operator role with supporting facts.
- Claimed exclusions with legal basis.
- Current and future application dates.
- Provider/deployer and GPAI value-chain relationships.
- Substantial-modification analysis.
- Owner, approver, evidence and review trigger.