The EU AI Act for the Downstream Provider: What You Owe When You Just Call an API
Most founders think the EU AI Act is the model provider's problem. If your output is used in the EU, you carry obligations of your own, and the enforcement machinery went live in August 2026.

Most founders building on someone else's model believe the EU AI Act is the model provider's problem. That belief is wrong in a specific and expensive way, and the part that trips people up is not the part they expect.
You do not need an EU entity. You do not need EU customers on paper. Article 2(1)(c) reaches providers and deployers "located in a third country, where the output produced by the AI system is used in the Union." The location of your company is irrelevant. The location where the output gets used is the trigger.
Verified as of 8 September 2026 against the regulation text on EUR-Lex, the Commission's AI Act Service Desk, and Commission press release IP/26/1714. Every article number below links to the source.
The date almost everyone gets wrong
The common summary is that the AI Act's rules for general purpose AI models started on 2 August 2026. That is not what happened, and the distinction matters if you are trying to work out what your model provider already owed you.
Chapter V, which carries the substantive obligations on general purpose AI (GPAI) model providers, applied from 2 August 2025. Model documentation, a copyright policy, and a public training-data summary have been legally required for over a year.
What changed on 2 August 2026 is narrower. Article 113 carved one provision out of the 2025 start date:
"Chapter III Section 4, Chapter V, Chapter VII and Chapter XII and Article 78 shall apply from 2 August 2025, with the exception of Article 101."
Article 101 is the Commission's power to fine GPAI providers. So the obligations arrived in 2025 and the ability to punish breaches of them arrived in 2026. The Commission's own announcement puts it plainly: "The AI Office can now enforce the AI Act's rules for providers of general-purpose AI (GPAI) models."
The practical read for a downstream company: your model provider has owed you documentation since August 2025. If you have never asked for it, you have been leaving evidence on the table for a year.
What your model provider owes you, and how to actually get it
Article 53(1)(b) requires a GPAI model provider to "make available information and documentation to providers of AI systems who intend to integrate" that model. The documentation has to give you "a good understanding of the capabilities and limitations" of the model. Its minimum contents are set by Annex XII.
Annex XII is the package you are entitled to: capabilities, limitations, integration instructions, the technical means needed to integrate, and the known risks that matter when you build on it.
Do not confuse it with Annex XI. That is the technical documentation the provider keeps for the AI Office and national regulators, covering training and evaluation. You are not entitled to it. Asking for the wrong annex is a fast way to get a polite refusal and conclude, wrongly, that the provider is stonewalling.
Requesting the Annex XII package is worth doing even if you never read it closely. The request, and the response, are the artifact that shows you did your own diligence when you classified your system.
Are you a provider or a deployer
The Act splits duties between two roles, defined in Article 3. A provider develops a system, or has one developed, and places it on the market "under its own name or trademark." A deployer is anyone "using an AI system under its authority" outside a personal, non-professional context.
Call an API, ship a feature, and you are a deployer of that model. This is the default, and for most B2B SaaS it stays the answer.
You become a provider of the resulting system through Article 25. It has three triggers. Putting your name or trademark on a high-risk system. Substantially modifying a high-risk system so it stays high-risk. Changing the intended purpose of a system so that it becomes high-risk.
Read all three carefully, because every one of them is scoped to high-risk systems. Article 25 does not convert you into a provider because you rebranded a chatbot. It fires when a high-risk system is involved. If your feature is not high-risk, this mechanism is not your problem, and a great deal of commentary implies otherwise.
Where a normal B2B feature actually lands
High risk is defined by Annex III, which lists eight areas: biometrics, critical infrastructure, education, employment and worker management, access to essential services including creditworthiness, law enforcement, migration, and the administration of justice.
A support-ticket summarizer touches none of them. It is not a near miss, it is not in scope at all, and the only Act obligation likely to attach is Article 50 disclosure.
Lead scoring is where I would slow down, because the answer depends entirely on who is being scored.
Scoring companies and accounts for pipeline prioritization is outside Annex III. Scoring individual job candidates, or filtering applicants, lands in Annex III point 4 on employment. Scoring a natural person's creditworthiness lands in point 5. Same engineering, same model, three different regulatory outcomes depending on whether the subject is a company or a person, and what the score decides.
Article 6(3) offers an escape valve. An Annex III system is not high-risk where it "does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons." The paragraph covers narrow procedural tasks and preparatory work.
The same paragraph contains the override that swallows a lot of the relief: a system that performs profiling of natural persons is high-risk regardless. Profiling here carries its GDPR meaning, evaluating personal aspects like economic situation, reliability, or behavior. A scoring model that reads individual behavioral signals about a person is doing exactly that, whatever the product page calls it.
Your Article 50 obligations, split by role
Article 50 is the transparency provision that started applying on 2 August 2026, and it is the one most B2B products actually have to do something about.
As a provider, you must design systems that interact directly with people so those people are told they are dealing with an AI. The exception is where that would be obvious to a reasonably well-informed person. If your system generates synthetic audio, image, video, or text, those outputs must be "marked in a machine-readable format." The solutions must be "effective, interoperable, robust and reliable as far as this is technically feasible."
As a deployer, you must disclose deepfakes, and disclose AI-generated text published on matters of public interest, with carve-outs for artistic and satirical work and for content under human editorial responsibility.
Note what that leaves out. A summary shown inside your product to your customer's own staff is not published content on a matter of public interest. The public-interest text limb is aimed at publishing, not at internal enterprise tooling. The obligation that does reach most B2B products is the plain one: tell people when they are talking to an AI, at the latest at first interaction.
On machine-readable marking, the statute sets the standard of care and not the technique. The technical detail is being worked out through the Code of Practice on Transparency of AI-Generated Content, which is guidance, not statutory text. Anyone telling you the Act mandates a specific watermarking scheme is overstating what the regulation says.
The penalty numbers, in the right order
Most summaries lead with 35 million euro or 7% of global turnover. That tier is real and it is also the one least likely to apply to you.
Under Article 99(3), the 35 million or 7% ceiling covers only prohibited practices under Article 5. Social scoring, subliminal manipulation, exploiting vulnerabilities, certain biometric categorization. It is the narrowest category in the Act.
The tier that covers ordinary compliance failure is Article 99(4), at 15 million euro or 3%, and it explicitly names Articles 16, 22 through 26, 31, 33, 34, and 50. Article 50 transparency failures sit here. So do most high-risk obligation failures.
For GPAI model providers specifically, Article 101 sets the same 15 million or 3% ceiling, and that is the provision whose enforcement switched on last month.
Article 99(6) matters if you are small: for SMEs and startups, each tier is capped at the lower of the fixed amount or the percentage, rather than the higher.
The deadlines moved, and that is settled
The high-risk timeline changed this summer, and it is now law rather than a proposal. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It replaced Article 113(c).
Annex III high-risk systems now apply from 2 December 2027. High-risk AI embedded in already-regulated products under Annex I applies from 2 August 2028. Both were previously 2 August 2027.
Separately, new prohibitions on AI systems generating non-consensual sexually explicit content and child sexual abuse material apply from 2 December 2026.
Treat these as fixed. The live uncertainty in this area is in the standards and guidance being written underneath the dates, not in the dates themselves.
What to do now, and what to only document now
Build now: the Article 50 disclosure, if people interact with your AI directly. It is a UI change and a copy change, it applies today, and it is the cheapest item on this list.
Ask now: your model provider for its Annex XII documentation. It has owed you that since August 2025.
Document now, build later: your risk classification. Write down which Annex III categories you considered, why your feature does or does not fall in one, and specifically whether anything you score is a natural person. If a regulator or an enterprise buyer asks in 2027, the artifact you want is a dated memo showing you reasoned it through, not a scramble to reconstruct the logic.
One caution on that memo. No court has yet interpreted "substantially modified" or "materially influencing the outcome of decision making." These are statutory tests without case law behind them. Anyone who tells you exactly where the line falls is guessing with more confidence than the current state of the law supports.
The question I would start with is narrower than "are we compliant." It is this: in your product today, is anything you score a natural person, and does that score change what happens to them?
More from Deepak Gupta
Every page on guptadeepak.com is hand-curated by Deepak Gupta. Pick a thread:
- About Deepak Gupta
Founder, cybersecurity architect, and writer at guptadeepak.com.
- My journey
From LoginRadius (2013, 1B+ users) to GrackerAI, in milestones.
- Publications & patents
Books, free e-books, a journal special issue, and five granted patents.
- Research Hub
Curated research, buyer's guides, vendor comparisons, and technical deep-dives.
Get the newsletter
New writing on identity, AI security, and building software, delivered when it ships. No tracking pixels, no funnels, unsubscribe with one click.