EU AI Act for product teams: who is in scope and which duties apply first

Regulation (EU) 2024/1689 is the EU AI Act. For a product team the useful cut is not “are we high-risk?” on day one. It is: does Article 2 put this feature in territorial scope, and which already-applicable duties (Article 50 transparency; Article 5 prohibitions; GPAI model duties if you train one) attach to the thing you shipped.

Educational resource only — not legal advice. scm.cc publishes a readiness report and engineering gap analysis for AI features. It does not give legal advice, represent you before a regulator, or state that a product is ready to ship under any law. This page is educational product guidance, not legal advice. It is not a readiness report, not an engineering gap analysis of your systems, and not a determination that any product meets a legal duty. Confirm current official text before you ship.

Last checked against official sources: .

Territorial scope in one paragraph

Article 2 applies the Regulation to providers who place AI systems or general-purpose AI models on the Union market, wherever they are established; to deployers established or located in the Union; and to providers and deployers in a third country where the output produced by the AI system is used in the Union. A Delaware company with a chatbot that EU residents use is reading the same Article 2 as an Amsterdam company.

The dates that actually move a backlog

Article 113: the Act entered into force on 1 August 2024. Prohibitions and AI-literacy duties applied earlier; Chapter IV transparency obligations (Article 50) and most remaining duties applied from 2 August 2026. High-risk duties for many Annex III systems follow the Article 113 timetable — confirm the consolidated text before you put a hiring or credit model on a 2026 vs 2027 engineering calendar.

Article 111(4): providers of generative systems already placed on the market before 2 August 2026 have until 2 December 2026 to meet Article 50(2) marking. That transition does not delay chatbot disclosure, deepfake disclosure, or public-interest text disclosure.

Provider vs deployer is a product decision

If you design and put the system on the market, you are a provider. If a customer turns your model on inside their own workflow, they are often a deployer — and you still have provider duties for the system you placed. Dual-role products (you host the model and you operate the customer-facing agent) need both Article 50(1)–(2) provider work and, where you publish outputs, Article 50(4) deployer work.

What this page does not decide

High-risk classification under Article 6 and Annex III (employment, credit, education, essential services) is a separate engineering and legal workstream. If your feature is a hiring ranker or a credit scorer, read the hiring-tools page and do not stop at Article 50. Transparency is the floor, not the ceiling.

Questions teams ask

We are a US startup with no EU entity. Are we out?
Not automatically. Article 2(1)(c) covers third-country providers and deployers when the output is used in the Union. The official Service Desk Article 2 page is the text to read next.
Does open-source code get a free pass?
Article 2 carves out some free and open-source systems, but not if they are placed on the market as high-risk systems or as systems that fall under Article 5 or Article 50. A public GitHub repo that you also ship as a hosted chatbot is not “just open source.”
Where is the official text?
The authentic instrument is Regulation (EU) 2024/1689 on EUR-Lex. The Commission’s AI Act Service Desk publishes article-level HTML from the consolidated version (the 27 July 2026 consolidation is the edition we last checked).

Related pages

Back to the AI law hub

Primary sources

Official text wins. Last checked 2026-10-11. This page is educational product guidance, not legal advice. It is not a readiness report, not an engineering gap analysis of your systems, and not a determination that any product meets a legal duty. Confirm current official text before you ship.