The first question any business asks about a new law is the simplest one: does it apply to us? For the EU’s AI Act (Regulation 2024/1689), two years after its entry into force, a remarkable number of companies still cannot answer it. Not because they have not tried, but because the Act makes the question genuinely hard. And when they do conclude that the law applies, a second question immediately follows that is harder still: which parts?
Scope is the foundation on which everything else rests, making this a serious obstacle to overcome. A company that wrongly believes it is outside the Act faces fines of up to 7% of worldwide turnover. A company that wrongly believes it is inside wastes money on compliance it never owed — money that, for a small firm, may be the difference between shipping a product and shelving it.
What is an “AI system” anyway?
The problem begins with the definition.. The Act covers “AI systems,” defined as machine-based systems that operate with some autonomy, may adapt after deployment, and infer from inputs how to generate outputs such as predictions, recommendations, or decisions (Article 3(1)). This was deliberately written to be technology-neutral and future-proof but the price of future-proofing is vagueness in the present.
The Commission published guidelines on the definition in February 2025, conceding that systems based on “basic statistical methods” may fall outside the Act — but the guidelines are non-binding, illustrative rather than exhaustive, and explicitly leave the final word to courts that have not yet spoken. The result is that thousands of companies running ordinary predictive software are paying lawyers to tell them, in effect, “probably, but we cannot be sure.” Does a credit-scoring model built on plain logistic regression “infer”? Does an Excel macro with a decision tree? Does decades-old fraud-detection software that a bank has run since before anyone said “machine learning” out loud?
Which hat are you wearing?
Suppose your clears the first hurdle and your software is an AI system. The Act now asks what you are: a provider, a deployer, an importer, a distributor, or a product manufacturer (Article 3). Each role carries radically different obligations. Providers — those who develop a system and place it on the market — bear the heavy load: conformity assessments, technical documentation, quality management, post-market monitoring. Deployers — those who merely use a system in a professional capacity — carry a much lighter one.
It’s simple enough on paper but, in practice the roles blur immediately. A company that licenses a general-purpose model, fine-tunes it on its own data, puts its own brand on it, or changes its intended purpose may silently transform from deployer into provider, inheriting the full provider obligations (Article 25). Many businesses doing routine customization of AI tools have no idea they may have crossed this line. Compliance teams report spending weeks debating whether their organization is a provider or a deployer — and the honest answer is often “both, for different systems, and sometimes for the same system at different moments in time.”
Add the extraterritorial reach: the Act applies to providers and deployers outside the EU whenever the output of their system is used in the Union (Article 2). Read literally, a US company whose chatbot answers a question from a customer in Paris is in scope. Nobody believes the law will be enforced that way, nobody can prove it will not be.
A product law for something that is not a product
The deepest source of confusion is structural, and it deserves more attention than it gets. The AI Act is, at its core, product safety legislation. It is modelled on the EU’s “New Legislative Framework” — the regime that governs toys, lifts, machinery, and medical devices. That framework assumes a particular world: a manufacturer makes a discrete thing, the thing is “placed on the market” at an identifiable moment, it is tested against standards, given a CE mark, and shipped. Responsibility follows the object down a linear chain from factory to shelf.
AI does not live in that world. Most AI today is not a product but a service: a model accessed through an API, billed by the token, updated continuously and silently by its developer. When is a system that changes every week “placed on the market”? Which version was assessed? The product-safety toolkit — conformity assessment, CE marking, the very notion of a finished article — strains against software that is never finished.
It strains even harder against the modern AI supply chain. A typical application stacks a foundation model from one company, fine-tuning by a second, an orchestration layer from a third, and deployment by a fourth into a workflow the first three never imagined. The Act tries to manage this with a dedicated regime for general-purpose AI models and with duties of cooperation along the value chain (Article 25), but the seams show. If a downstream app behaves badly, is the fault in the base model, the fine-tuning, the integration, or the use? The Act’s answer is, roughly, “whoever substantially modified it or changed its purpose” — which simply relocates the uncertainty rather than resolving it. The contractual fallout is visible everywhere: enterprises and vendors trading indemnities over regulatory risk that neither can actually price.
The same mismatch explains why “which parts apply” is so difficult. The Act is not one regime but several stacked on top of each other: outright prohibitions (in force since February 2025), rules for general-purpose models (since August 2025), transparency duties for chatbots and synthetic content, and the heavy machinery for “high-risk” systems — itself split between systems embedded in regulated products (Annex I) and standalone use cases like hiring, credit, or education (Annex III). A single company can sit in three of these boxes at once. And whether a system is “high-risk” under Annex III can depend on a self-assessed carve-out — that it performs only a “narrow procedural task” or merely supports human decision-making (Article 6(3)) — a judgment the company makes itself, at its own peril.
Uncertainty about the uncertainty
In 2026 the picture acquired a final twist: uncertainty about the rules became uncertainty about when the rules even apply. With harmonized standards running late and industry warning it could not comply with obligations whose technical content did not yet exist, the Commission proposed the “Digital Omnibus” — and on 7 May 2026, the Council and Parliament provisionally agreed to push the Annex III high-risk obligations from August 2026 to December 2027, and the Annex I obligations to August 2028. Companies that had spent millions preparing for an August 2026 deadline watched it dissolve weeks before it arrived. Those that had bet on a delay were rewarded for ignoring the statute book. Whatever one thinks of the postponement on the merits, it taught the market a corrosive lesson: in EU digital law, even the dates are negotiable.
The record
None of this means the AI Act was a mistake. The case for regulating AI is real. Some uses — social scoring, manipulative systems exploiting vulnerable people — deserve prohibition, and the Act prohibits them. High-risk uses in hiring, credit, policing, and welfare genuinely affect people’s lives, and requiring documentation, human oversight, and accuracy testing there is not bureaucratic excess; it is what we already demand of cars and medicines. A single EU-wide rulebook is better than twenty-seven national ones. And there is a market value to trust: firms that can credibly show their AI is compliant may find that certification sells.
But benefits must be weighed against what this particular statute costs, and the largest cost is the uncertainty documented above. Uncertainty is applied uniformly but Google and Microsoft can absorb definitional ambiguity with in-house counsel. A ten-person startup cannot, and so it over-complies, under-builds, or leaves. Uncertainty also undermines the Act’s own goals: a law whose scope cannot be determined cannot reliably protect anyone, and a deadline that moves teaches firms to discount the next one. The EU set out to export legal certainty as a competitive advantage — the famed “Brussels effect.” What it has exported so far, in the AI field, is confusion.
An honest conclusion would be conditional. If the Commission’s guidelines harden into predictable practice, if standards arrive on time for the new 2027 deadline, and if regulators enforce against substance rather than ambiguity, the Act’s protections may yet justify the friction. If not, Europe will have built a law whose chief output is advice about the law — protection on paper, paralysis in practice. The next eighteen months will decide which.
(References: Regulation (EU) 2024/1689; Commission Guidelines on the definition of an AI system, C(2025) 924; Council–Parliament provisional agreement on the Digital Omnibus on AI, 7 May 2026.)
