Field of law
Artificial intelligence
Classification comes before every duty, into the categories set out in the AI Act. It separates prohibited practices, high-risk systems and everything else. Beside those sit the general-purpose AI models as a category of their own. Equally relevant is the role as provider or deployer.
Classification comes before every duty
Which duties a system triggers is settled by its classification under the AI Act. The regulation orders systems neither by technology nor by provider, but by the risk of the use.
Three of the four entries order a system by its risk. The third is not a class at all, and that is where the classification usually slips.
Three classes for systems, plus the models
Prohibited practices
Art. 5(1) AI Act lists them exhaustively, among them social scoring and inferring emotions in the workplace. There is no balancing here and no consent, but a prohibition.
High-risk systems
Under Art. 6(1) AI Act the safety component of a product, under paragraph 2 the use cases in Annex III, such as employment and creditworthiness. Paragraph 3 takes a system out again on four conditions, but never where it performs profiling. Such a system adds separate duties for the provider and the deployer, unevenly distributed under Art. 16 and Art. 26 AI Act.
General-purpose AI models
This category concerns not a system but the model underneath it, and it sits beside the classes. Art. 51 AI Act classifies a general-purpose AI model as one with systemic risk where it has high-impact capabilities. Under Art. 51(2) AI Act that is presumed above a training compute of more than 10 to the power of 25 floating-point operations. Art. 53 AI Act places separate duties on the providers of such models, from technical documentation to a policy for complying with copyright. Merely building such a model into a system of one’s own does not make anyone a model provider.
Everything else
No particular duties from the risk classes. For a system under Annex III that is meant not to be high-risk, Art. 6(4) AI Act requires that assessment to be documented before placing on the market. The classification is therefore itself a record and not a train of thought. AI literacy under Art. 4 AI Act applies here as well, and data protection law in any event.
A general-purpose AI model therefore brings its duties into whichever system it sits in, whatever class that system has.
Transparency duties depend on the use
Beside the categorisation sits Art. 50 AI Act. The provision attaches not to the system but to the way it is used. The following examples show when transparency duties apply.
A chatbot answers customer queries
The provider ensures that it is apparent a person is interacting with an AI system, unless that is obvious anyway. Art. 50(1) AI Act.
A system generates or edits images
The provider marks the generated or altered content as artificial in a machine-readable format. Art. 50(2) AI Act.
A system detects emotions in a customer call
The deployer informs the people concerned about the use of the emotion recognition system. Art. 50(3) AI Act.
A video is altered with AI
The deployer discloses that image, audio or video content has been artificially generated or manipulated. Art. 50(4) AI Act.
A change of role under the AI Act as a stumbling block for high-risk duties
Whether a business is a provider or a deployer is read as a property of the contracting party. Under the regulation it is the consequence of one’s own conduct.
Two roles, one crossing point
| Deployer | Merkmal | Provider |
|---|---|---|
| Whoever uses a system under their own authorityArt. 3(4) AI Act. Private use is excluded. | Who it is | Whoever develops or has developed and supplies under their own nameArt. 3(3) AI Act. Developing it oneself is not required. |
| Stays a deployer as long as none of that happens | What tips the role | Own name, substantial modification or a new intended purposeArt. 25(1) AI Act, for high-risk systems. |
| Remains the provider | What becomes of the previous provider | No longer counts as the providerArt. 25(2) AI Act. The duties move across in full. |
The third row is the consequential one. Whoever takes on the role takes it on entirely, and the previous provider no longer answers for it.
Whoever changes role takes on the provider’s set of duties.
Under Art. 2(7) AI Act the General Data Protection Regulation remains unaffected. Every one of these questions therefore has a second side, and that is the one we look at first.
Practical questions on this
Classification and role
AI Act risk classification
A system is high-risk under Art. 6(1) AI Act where it is a safety component of a product under Annex I, or under paragraph 2 where it falls within one of the eight areas of Annex III, such as creditworthiness assessment under point 5(b).
Transparency duties under Art. 50 AI Act
Art. 50 AI Act allocates four duties to two addressees.
Using AI in line with data protection law
Training and use are two processing operations, each with a legal basis of its own.
Duties that cut across
AI literacy under Art. 4 AI Act
Art. 4 AI Act requires a sufficient level of AI literacy and names five circumstances by which that level is measured.
The AI policy at work
Under the Court of Justice a legal person is liable for infringements committed by any person acting in the course of its business.
AI governance
The roles are not free to allocate, because several provisions name their own addressee.
Individual systems in use
Microsoft 365 Copilot
Under the Court of Justice, a provision adopted on the basis of Art. 88(1) GDPR may not merely repeat the conditions in Art. 6 GDPR.
ChatGPT
The body that sets the task decides on purpose and means and is therefore the controller under Art. 4(7) GDPR, even where the account is private.
Claude
The purpose set at introduction limits every later use under Art. 5(1)(b) GDPR, and any extension has to be measured against Art. 6(4) GDPR.
Transcription and meeting assistants
Recording the non-publicly spoken word is a criminal offence under section 201(1) no. 1 of the German Criminal Code where it is unauthorised, and that is a question alongside the legal basis.
Particular fields of use
AI and works council participation
For section 87(1) no. 6 BetrVG the objective capacity to monitor suffices, provided the data can be attributed to individual employees.
AI in public administration
The second subparagraph of Art. 6(1) GDPR rules out the balancing exercise for authorities performing their tasks, so the legal basis has to come from sector law.
Frequently asked questions
From when does the AI Act apply?
In stages. Under Art. 113 AI Act it has applied since 02.08.2026, Chapters I and II with the prohibited practices and AI literacy since 02.02.2025, and Art. 6(1) AI Act with the duties for safety components only from 02.08.2027. Anyone examining this today is therefore not examining everything at once.
We only use ChatGPT. Does that make us a provider?
As a rule not. Anyone using a system unchanged and under someone else's name is a deployer under Art. 3(4) AI Act. A business becomes a provider under Art. 25(1) AI Act only once it puts its own name on a high-risk system, modifies it substantially or changes its intended purpose.
Our system is not high-risk. What is there to do?
Document the classification and meet the cross-cutting duties. Under Art. 6(4) AI Act the assessment is to be documented before placing on the market, and AI literacy under Art. 4 AI Act applies irrespective of the class. On top of that comes data protection law, which under Art. 2(7) AI Act remains unaffected.
May we analyse emotions in customer calls?
In the workplace and in education institutions, inferring emotions is prohibited under Art. 5(1)(f) AI Act, save on medical or safety grounds. Outside those areas the prohibition does not reach, but Art. 50(3) AI Act with its information duty does, as does data protection law.
Get in touch!
Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!
Contact usAlternatively you can request a call back.