Regulation (EU) 2024/1689 is written for operators, and a software company can be several of them at once. Most of the Regulation's pages are for the provider of a high-risk system; most companies will never be one. This article sorts the six roles, says what applies to every company regardless of role, what applies only when a system is high-risk, where the general-purpose model line runs, and what the SME provisions are worth, with the dates as Regulation (EU) 2026/1744, the Digital Omnibus on AI, set them on 27 July 2026. It is read from the two texts on CELLAR on 12 September 2026 and is not legal advice.
First: is it an AI system
Article 3(1) defines an AI system as a machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments. Recital 12 draws the line at inference: the definition should not cover systems based on rules defined solely by natural persons to automatically execute operations, and the techniques that enable inference are machine learning and logic- and knowledge-based approaches. A pricing rule written by your product manager is not an AI system; a model that learned the rule from data is, and so is a large language model you call through an API. The Regulation applies to the system, so a product with one AI feature has one AI system in it.
The six roles, and which one a software company is
Article 3(8) calls the six of them operators: provider, product manufacturer, deployer, authorised representative, importer and distributor. For a software company, three matter.
You are the provider (Article 3(3)) of any system you develop, or have developed, and place on the market or put into service under your own name or trademark, whether for payment or free of charge. That includes a system built on someone else's model: when your product embeds a vendor's general-purpose model behind your feature and your name, you are the provider of the AI system, and the vendor remains the provider of the general-purpose AI model under Chapter V. Free tiers, betas and open-source releases are placings on the market too, subject to the Article 2(12) exception for free and open-source systems that are neither high-risk nor under Articles 5 or 50.
You are a deployer (Article 3(4)) of every system you use under your own authority in your operations, from the screening tool in recruitment to the coding assistant in engineering, except purely personal use. A company is usually the provider of a few systems and the deployer of many.
You may be an importer or a distributor if you place a third-country provider's system on the Union market under their name, or make a system available in the supply chain without being its provider (Article 3(6) and (7)); resellers and marketplaces sit here, with the Article 23 and 24 duties for high-risk systems. And a provider established outside the Union is reached anyway: Article 2(1)(c) applies the Regulation to third-country providers where the output is used in the Union, and Article 22 requires a provider of a high-risk system established in a third country to appoint an authorised representative in the Union before making it available.
One role can turn into another. Article 25(1) makes a deployer, distributor or importer the provider of a high-risk system when it puts its name on one, substantially modifies one, or changes the intended purpose of a system so that it becomes high-risk, and fine-tuning a licensed model for an Annex III use is that last case.
What applies to every company, whatever the role
Three parts of the Regulation do not wait for a risk class.
Article 4, AI literacy, since 2 February 2025. Providers and deployers take measures to support the development of AI literacy of their staff and others operating AI systems on their behalf, taking account of their knowledge, experience, education and training and the context of use; as rewritten on 27 July 2026, without any duty to guarantee a specific level of literacy of any individual. The Article 4 article has the text and a one-page programme.
Article 5, the prohibited practices, since 2 February 2025. Subliminal or manipulative techniques that distort behaviour and cause significant harm, exploitation of vulnerabilities, social scoring, predictive policing of individuals based on profiling, untargeted scraping of facial images, emotion recognition at the workplace and in education except for medical or safety reasons, biometric categorisation inferring protected characteristics, and real-time remote biometric identification for law enforcement outside narrow exceptions. From 2 December 2026 two more, inserted by the Omnibus: generating or manipulating intimate or sexually explicit material of an identifiable person without consent, and child sexual abuse material. A software company checks its product against the list once, and again whenever the intended purpose changes.
Article 50, transparency, since 2 August 2026. A provider's system that interacts with people says it is an AI; a provider's generative system marks its output so machines can detect it, with a transition to 2 December 2026 for systems already on the market; a deployer discloses deep fakes and AI-written text published on matters of public interest, and informs people exposed to emotion recognition or biometric categorisation. The Article 50 article covers the four duties and the Commission's code of practice.
What applies only when a system is high-risk
Article 6 gives two routes. Under Article 6(1), a system that is a safety component of a product covered by the Annex I legislation, or is itself such a product, and that product needs a third-party conformity assessment, is high-risk; the Omnibus added that a system used solely for non-safety aspects is not a safety component unless its failure would endanger health and safety, and that a third-party assessment owed only to radio spectrum or interference risks does not count. Under Article 6(2), a system intended for a use listed in Annex III is high-risk, unless it poses no significant risk and meets one of the four Article 6(3) conditions, and never where it profiles natural persons. For a software company the Annex III uses that come up are recruitment and worker management (point 4), creditworthiness and insurance pricing (point 5), education admission and assessment (point 3), and biometrics (point 1). The free determination walks the questions with the annex verbatim.
If the system is high-risk, the role decides the duties. The provider owes Article 16: the requirements of Articles 8 to 15 on risk management, data, documentation, logging, transparency, human oversight, accuracy, robustness and cybersecurity, the Article 17 quality management system, the conformity assessment of Article 43, the declaration, CE marking and registration of Articles 47 to 49, and post-market monitoring and incident reporting under Articles 72 and 73; the AI Act mapping shows which ISO/IEC 42001 controls produce the evidence. The deployer owes Article 26, twelve paragraphs from human oversight to log retention and worker information, read in order in the Article 26 article. Chapter III applies from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems (Article 113 as amended), with the Article 111(2) grace period for types and models already on the market whose design does not change significantly.
The general-purpose model line
If you train and release a model rather than a system, Article 3(63) makes you a provider of a general-purpose AI model where it displays significant generality and can be integrated into a variety of downstream systems, and Chapter V has applied to you since 2 August 2025: technical documentation, information for downstream providers, a copyright policy and a training-content summary under Article 53, and the systemic-risk duties of Article 55 above the compute threshold of Article 51, with the Commission's code of practice as the way to demonstrate compliance. Most software companies are on the other side of that line, as providers of systems built on someone else's model, and their duty towards the model provider is the written agreement of Article 25(4) as amended, which specifies the information, capabilities, technical access and assistance a high-risk provider needs.
The SME and small mid-cap provisions
The Regulation defines SMEs by reference to Recommendation 2003/361/EC (Article 3(14a), inserted 2026) and adds small mid-caps under Recommendation (EU) 2025/1099 (Article 3(14b)). Five provisions follow. Article 62: member states give SMEs, including start-ups, priority access to regulatory sandboxes, tailored awareness and training, dedicated channels for advice, and reduce conformity assessment fees in proportion to their size, and the AI Office runs a single information platform with standardised templates. Article 63(1) as amended: SMEs, including start-ups, without partner or linked enterprises may comply with certain elements of the Article 17 quality management system in a simplified manner, on guidelines the Commission is to issue. Article 17(2) as amended: the quality management system is proportionate to the provider's size, SMEs and SMCs named. Article 11(1) as amended: SMEs, start-ups and SMCs may provide the technical documentation on a simplified form the Commission establishes, which notified bodies must accept. And Article 99(6) and (6a): where a fine ceiling is a choice between an amount and a percentage, an SME or an SMC pays whichever is lower, not higher.
Who owes what, from when
| You are | It applies | From |
|---|---|---|
| Any provider or deployer | Article 4, AI literacy; Article 5, the prohibitions | 2 February 2025; the two new prohibitions 2 December 2026 |
| Provider of a system that interacts with people or generates content | Article 50(1) and (2) | 2 August 2026; marking for systems already on the market 2 December 2026 |
| Deployer that publishes generated content, or runs emotion recognition or biometric categorisation | Article 50(3) and (4) | 2 August 2026 |
| Provider of a general-purpose AI model | Chapter V, Articles 53 to 55 | 2 August 2025 |
| Provider of a high-risk system | Article 16, with Articles 8 to 15, 17, 43, 47 to 49, 72 and 73 | 2 December 2027 (Annex III), 2 August 2028 (Annex I) |
| Deployer of a high-risk system | Article 26, and Article 27 for public bodies and credit and insurance deployers | 2 December 2027 (Annex III), 2 August 2028 (Annex I) |
| Third-country provider of a high-risk system | Article 22, an authorised representative in the Union | Before making the system available |
What to do this quarter
Write the register: every AI system you provide and every one you deploy, with its intended purpose, the model behind it, and the role you hold. Run the high-risk determination for each and file the result, the negative ones too, since Article 6(4) makes the reasoning a record where the Annex III derogation is relied on. Check the register against Article 5 and Article 50, and put the interaction disclosure and the output marking on the product roadmap with the vendor's marking layers named. Take the Article 4 measure, per system and per group of people, and record it. If any system is high-risk and you provide it, the quality management system of Article 17 is a management system in the ISO sense, and ISO/IEC 42001 is its shape; the SME simplifications reduce what it must contain, not whether it must exist.