Every time the EU AI Act’s penalties make the news we get the same call: “are we going to be fined €15 million?”. The answer is almost always no, and it is worth understanding why.
Provider does not mean “the one using it”
The Regulation assigns obligations by the role you play, not by whether you touch AI:
| Role | Who it is | Regulatory load |
|---|---|---|
| GPAI model provider | Develops and places a general-purpose model on the market | High: technical documentation, copyright policy, training-data summary |
| AI system provider | Develops a system and markets it under their own name | Medium, depending on the system’s risk |
| Deployer | Uses an AI system under their own authority | Low in most cases |
| Importer / distributor | Brings in or markets third-party systems | Conformity verification |
If your company calls a frontier model’s API to classify tickets, you are a deployer. You are not a GPAI provider. The model’s technical documentation, training-data summary and copyright policy are the problem of whoever trained it.
Where it does change: if you take an open-weight model, fine-tune it substantially and place it on the market under your own brand, you may become a provider. That is the scenario to review with a lawyer beforehand, not afterwards.
The dates that apply
- 2 August 2025 — GPAI model obligations, governance and the penalty regime took effect.
- 2 August 2026 — penalties specific to GPAI providers apply, up to €15 million or 3% of global turnover, whichever is higher.
- 2 August 2027 — deadline for GPAI models already on the market before August 2025 to come into line.
That last deadline explains why some older models still lack complete documentation: they have two years of runway.
What does apply to you as a deployer
The load is low, but it is not zero:
- Use the system according to the provider’s instructions. Use it for something the provider expressly excludes and you take on the liability.
- AI literacy for the staff operating it. An obligation since February 2025.
- Article 50 transparency where there is interaction with people or synthetic content.
- Human oversight where the system falls into a high-risk category.
- Retain logs the system generates automatically, where they are under your control.
The expensive mistake we see
Companies commissioning a high-risk conformity audit for a system that is not high risk. Classifying inbound email, drafting sales copy or summarising internal documentation do not fall under Annex III.
Before spending on compliance, spend half a day on classification. The right question is not “do we use AI?”, it is “what decision does this system make, and about whom?” If the answer affects a person’s access to employment, credit, education or essential services, then there is a conversation. If not, the load is what you have just read.
Sources
- Implementation Timeline — EU Artificial Intelligence Act
- EU AI Obligations for GPAI Providers: Compliance, Enforcement & Deadlines (2025–2027) — MediaLaws
- Latest wave of obligations under the EU AI Act take effect — DLA Piper
- EU AI Act Compliance Timeline: Key Dates by Risk Tier — Trilateral Research