---
title: "EU AI Act: It Affects Your Business, Not Just AI Makers"
description: "The EU AI Act doesn't only target those who build the models, but those who use AI in business. What applies from 2 August 2026 and what moves to 2027-2028."
url: "https://volcanicminds.com/en/insights/eu-ai-act-deployer-business"
lang: "en"
type: "second_level_page"
updated: "2026-09-04"
alternate: "https://volcanicminds.com/insights/eu-ai-act-deployer-business"
---

# European AI Act who does it really affect?

## Sure, that's OpenAI and Anthropic's problem

It's the first thing we hear when we bring up the **EU AI Act** with a business owner. It's also the most dangerous misconception. **Regulation (EU) 2024/1689** doesn't only hit those who _build_ the models: it mainly hits those who _use_ them in their own processes. If you've embedded an assistant in customer care, an agent that reads your ERP, or a system that triages cases, you're most likely a **deployer**. And the obligations around oversight, logging and compliant use fall on you, not on the model's vendor.

## Provider or deployer: a difference that matters

The Regulation separates whoever develops the model (the _provider_) from whoever puts it into operation under their own authority (the _deployer_). The second group is far more crowded than the first: it includes practically every company that has taken AI beyond the demo stage. You don't need to have trained an LLM to carry responsibility. Using one to decide, filter or automate a process that affects people, customers or employees is enough.

## The deadline almost no one is preparing for

From **2 August 2026**, transparency, governance, penalties and the powers of national authorities apply. The obligations for high-risk systems, however, have been postponed by Regulation (EU) 2026/1744 (the Digital Omnibus, in force since 27 July 2026): 2 December 2027 for Annex III, 2 August 2028 for Annex I. In Italy the picture is already shifting: **Law 132/2025** is in force, and the implementing decrees on the way are building a regime of liability (criminal and corporate too) for those who ship AI without control. The precise dates, the penalties and the exact legal references, with all the official sources, are collected on our dedicated **[EU AI Ac**t](https://volcanicminds.com/en/eu-ai-act) page.

## You can't buy your way to compliance

Here's the uncomfortable part. AI Act compliance isn't solved by filling in an 80-page PDF or buying a compliance dashboard licence. The theoretical obligations have to be translated into **concrete technical choices inside the software**: deterministic validation around LLM calls, immutable traceability of operations, human checkpoints on high-risk decisions. This is what we call **Compliance by Design**: a non-functional requirement of the architecture, not paperwork bolted on at the end of the project. Every non-architectural shortcut is debt you pay back during an inspection.

## What we've prepared for you

We've put two things in writing. The first is a hands-on **EU AI Act guide** built for decision-makers, not lawyers: what changes, who's involved, and the four technical pillars — guardrails, observability, human-in-the-loop and data sovereignty — that real compliance hinges on. The second is a set of **[frequently asked question**s](https://volcanicminds.com/en/services/frequently-asked-questions) that clears up the most concrete doubts: who's liable, how to bring existing systems into compliance, and why "easy compliance" is a bluff.

And if you want to know where you're genuinely exposed, we offer a **free assessment**: we map your AI systems against the four pillars and hand you the priority gaps against the Regulation's obligations. No strings attached, and no 80-page PDF nobody reads.

One necessary note: ours is an engineering contribution, not legal advice. For an assessment of your specific case, we bring a qualified professional to the table, together with you.

## Questions this raises

Working out whether and how much it applies

### How do we tell whether we are a deployer or a provider?

What matters is what you do with the system, not who wrote it. If you use it under your own authority for a business activity you are a deployer, even when the model is a third party's and even when a supplier configured it for you.

You become a provider if you place it on the market under your own brand or substantially change its intended purpose. In practice many companies are deployers without knowing it, because AI tools were introduced department by department without a formal decision.

### What applies already and what has been postponed?

From 2 August 2026 transparency obligations, general-purpose model governance, penalties and national authority powers apply. Regulation (EU) 2026/1744, the Digital Omnibus, moved Annex III high-risk systems to 2 December 2027 and Annex I ones to 2 August 2028.

The postponement covers high-risk,** not everything else: reading it as a general extension is the most common mistak**e.

### Is an internal policy enough to be compliant?

No, and it is an important point. A policy states what should be done; compliance is demonstrated by what the software actually does: decision logs, traceability of sources, human approval points, technical limits on what a model can touch.

Legal advice is necessary, but it has to be translated into engineered controls, otherwise it stays a document that can hardly be verified.

## Find out where your AI is exposed

Adopting AI shouldn't turn into a legal gamble. Book a conversation: we start from your real systems and work out what you actually need, now that the first block of obligations already applies.
