What the EU AI Act means when you're buying AI
The EU AI Act applies to organisations that buy and deploy AI, not only to the providers who build it. If you commission an AI system and run it in the EU, you can carry "deployer" obligations that scale with the system's risk category — from light transparency duties to substantial requirements for high-risk uses. The practical first step on any project is agreeing the risk category and putting the documentation and transparency responsibilities into the contract.
This guide is general information for buyers, not legal advice. Obligations depend on your specific use case and jurisdiction — confirm them with qualified counsel.
Almost all EU AI Act coverage is written for the companies that build AI. If you're the business commissioning it, you need the other half of the picture: what you're responsible for once the system is yours and running.
You may be a 'deployer', not just a customer
The Act distinguishes providers (who build and place AI on the market) from deployers (who use it professionally). Commissioning a custom system and running it in your business can make you a deployer, with your own obligations — which is why buyer-side awareness matters, not just the agency's.
Your obligations scale with risk category
A minimal-risk internal tool carries little; a system used in a high-risk context carries substantially more, including around human oversight, record-keeping and transparency. The first practical step on any project is agreeing which category your use case falls into.
Transparency duties can apply even at limited risk
Systems that interact with people, or generate or manipulate content, can carry duties to disclose that AI is involved. These are easy to design in from the start and expensive to retrofit.
Documentation is a shared responsibility
As a deployer you may need technical documentation, instructions for use, and a record of the data and evaluation behind the system. Agree in the contract that the agency produces and hands these over — don't discover the gap during an audit.
It overlaps with, but isn't, GDPR
GDPR governs personal data; the AI Act governs AI systems and their risks. Most real projects touch both. Handle them together in your data and compliance terms rather than assuming one covers the other.
What to put in the Statement of Work
Make compliance explicit rather than assumed: have the agency help classify the risk category, produce the technical documentation and instructions for use you may need as a deployer, evidence how the model was trained and evaluated, and build in any user-facing transparency. This sits naturally alongside your GDPR terms — see the questions to ask an AI agency and the wider vetting checklist.
Choosing an agency that can support compliance
Agencies serving European enterprises should be fluent in these obligations, not learning them on your project. NorthBridge AI is built for European buyers — agencies are vetted and every engagement runs on a Statement of Work where data-handling and compliance responsibilities can be set out clearly. See how it works.
Frequently asked questions
Does the EU AI Act apply to companies that buy AI, not just build it?
Yes. The EU AI Act places obligations on 'deployers' — organisations that use an AI system in a professional capacity — not only on providers who build it. If you commission an AI system from an agency and deploy it in the EU, you can carry deployer obligations, and the level depends on the system's risk category. This article is general information, not legal advice; confirm your specific obligations with qualified counsel.
What are the EU AI Act risk categories?
The Act sorts AI systems into tiers: unacceptable-risk uses that are prohibited, high-risk systems that carry the heaviest obligations (for example certain uses in employment, credit, or critical infrastructure), limited-risk systems with transparency duties (such as telling users they're interacting with AI), and minimal-risk systems with few obligations. Your duties as a buyer scale with the category your use case falls into.
What should I require from an AI agency for EU AI Act compliance?
Ask the agency to help you classify the system's risk category, document the data used and how the model was trained and evaluated, provide the technical documentation and instructions for use you may need as a deployer, and support transparency requirements such as user disclosure. Put these in the Statement of Work so the responsibilities are explicit.
Hire AI agencies built for European compliance
Vetted agencies and clear, contractual data terms on NorthBridge AI.
Browse verified agencies