EUAIACTUS.COM

Static scoping assessment

Does the EU AI Act apply to your company or AI system?

Use these questions to structure the facts before a formal scope analysis. This page intentionally does not generate an automatic legal conclusion.

Step 1

EU nexus

  • Do you place an AI system or GPAI model on the EU market?
  • Do you put an AI system into service in the EU?
  • Are you a provider or deployer outside the EU whose AI-system output is used in the Union?
  • Do EU customers, workers, applicants, students, consumers or other persons interact with or experience the system?
  • Are you part of an EU-facing distribution or supply chain for the system?

Step 2

Role in the AI value chain

  • Did you develop the AI system or have it developed under your name/trademark?
  • Do you use an AI system under your authority in a professional context?
  • Do you import or distribute another provider's AI system into the EU?
  • Do you provide a general-purpose AI model?
  • Could a downstream change or rebranding alter your role?

Step 3

Immediate 2026 checks

  • Could the use fall within a prohibited AI practice?
  • Does the system interact directly with natural persons?
  • Does it generate or manipulate image, audio, video or text content?
  • Do you deploy deepfakes, emotion recognition or biometric categorisation?
  • Do you publish AI-generated text on matters of public interest without qualifying human review/editorial responsibility?
  • Have you implemented measures supporting AI literacy for relevant staff and operators?

Step 4

High-risk readiness

  • Is the intended purpose connected to employment, education, biometrics, critical infrastructure, essential services, law enforcement, migration/asylum/border control or justice/democratic processes?
  • Is the AI a safety component of a regulated product or itself such a product?
  • Have you documented intended purpose and material exclusions?
  • Are you relying on an exception or non-high-risk rationale that should be evidenced?
  • What needs to be ready before the amended 2027/2028 high-risk dates?

Step 5

Evidence and implementation

  • Is there a current AI system inventory?
  • Are owners and decision rights assigned?
  • Are vendor/model documentation and contractual dependencies mapped?
  • Are transparency, human oversight, monitoring and incident processes evidenced?
  • Can the organisation show when the assessment was reviewed and against which legal version?

Interpretation

A “yes” does not automatically mean the same obligation set applies.

Scope, role, intended purpose, risk category, model relationships, effective dates and exceptions must be assessed together. The purpose of this assessment is to identify where deeper analysis is needed.