Sector guide
The EU AI Act for technology and software vendors
If you build the model or ship the system, obligations attach to you as provider — and general-purpose models carry their own regime in Articles 53 and 55, separate from the high-risk tiers entirely.
What the Act actually names in this sector
These are the provisions that reach technology and software vendors, quoted from the Official Journal. Everything below follows from them.
draw up and keep up-to-date the technical documentation of the model, including its training and testing process and the results of its evaluation
Article 53 →This shall not include AI systems intended to be used for biometric verification the sole purpose of which is to confirm that a specific natural person is the person he or she claims to be
Annex III, 1(a) →
Common use cases, classified
Transparency duty
Not high-risk, but people must be told. Disclosure and content-marking duties under Article 50.
- Building a synthetic media tool
As provider you must mark outputs machine-readably as artificially generated or manipulated.
Article 5(1)(ba) and (bb), inserted in 2026, prohibit systems generating intimate imagery without consent or child sexual abuse material — those are bans, not disclosure duties.
Article 50(2) →
Depends on the detail
The Act does not settle this from the description alone. The note says what decides it.
- Providing a general-purpose AI model
Providers of general-purpose AI models carry documentation, copyright-policy and training-data-summary duties under Article 53, which are separate from the high-risk regime.
A model meeting the Article 51 systemic-risk thresholds carries the further obligations in Article 55.
Article 53 → - Biometric verification (1:1 unlock)
Point 1(a) expressly excludes biometric verification whose sole purpose is confirming that a person is who they claim to be, so face or fingerprint unlock is not high-risk on that basis.
One-to-many identification against a gallery is a different system and is caught by point 1(a).
Annex III, 1(a) →
No specific duty
Not named in the Act's risk tiers. The AI literacy duty in Article 4 still applies, as does law outside the Act.
- Developer and productivity assistants
Internal productivity tooling is not named in Annex III and is not a safety component.
Article 4 still requires measures supporting AI literacy for staff using it, whatever the tier.
Article 6 →
What gets misread here
Over-classification is the quieter failure: treating something as high-risk when the Act carves it out costs real money and never triggers a complaint, so nobody catches it.
“Face unlock is biometric identification, so it is high-risk.”
Point 1(a) expressly excludes verification whose sole purpose is confirming someone is who they claim to be. One-to-many identification against a gallery is a different system and is caught.
Annex III, 1(a) →“We fine-tuned someone else's model, so they remain the provider.”
Substantial modification, putting your name on the system, or changing its intended purpose makes you the provider for the purposes of the Act.
Article 25 →
Dates that matter in this sector
- 2 Aug 2025General-purpose AI model obligations apply — Since 2 August 2025, providers of general-purpose AI models have had to publish training-data summaries, maintain technical documentation, and respect EU copyright law, with extra systemic-risk duties above the compute threshold.
- 2 Dec 2027Annex III high-risk obligations apply — Providers of Annex III high-risk systems (including AI used in employment, education, credit scoring, life and health insurance pricing, essential services, law enforcement and migration) must meet the full Chapter III requirements from 2 December 2027. (date changed by the Omnibus)
Dates are as amended by the Digital Omnibus. See the full timeline for what each one covers.
What the Commission has said
These guidelines are not binding, but they are the Commission’s own reading of the provisions above, and they are the first place a supervisory authority will look. Where they and this guide differ, follow them.
- Guidelines on prohibited AI practices ↗European Commission, February 2025 — interprets Article 5
- Guidelines on the definition of an AI system ↗European Commission, February 2025 — interprets Article 3, Article 6
- Guidelines on transparency obligations for providers and deployers ↗European Commission, 2025 — interprets Article 50
What to do next
Screen your own systems with the scope finder, run a single system through the risk classifier, or work the obligations in order with the checklist.
This guide points you at the provisions that govern your sector. It is not legal advice, and whether a particular system meets a provision turns on facts about that system and on whether you hold it as provider or deployer — see Article 3 and Article 25.