Tech & Legal Updates

Short, executive level legal and commercial updates for founders and leaders of scaling technology businesses.

EU AI Act Introduces Direct Compliance Duties for Providers

The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) establishes binding obligations for providers of high-risk AI systems, including risk management, data governance, technical documentation, and post-market monitoring. The European Commission has clarified that non-EU providers placing AI systems on the EU market fall within scope. Scaling technology businesses embedding AI in SaaS products should classify systems early and adjust contractual risk allocation, warranties, and liability structures.

Classification is the decision everything else follows from

The obligations attached to a high-risk classification are demanding, but the more consequential step happens earlier. Classification determines which regime applies, and it is a decision most businesses make implicitly, by assuming their product is not high-risk, rather than explicitly, by working through what the system does and in what context it is deployed.

That assumption is worth testing early, because classification is difficult to revisit once a product has been built, sold and deployed on the basis of it. The cost of reclassifying late is not the compliance work. It is the retro-fitting of documentation, monitoring and technical controls into a product that was not designed to produce them.

What to check

  • Whether anyone has documented why the product is or is not high-risk, or whether it has simply been assumed.
  • Whether the classification would still hold if a customer deployed the product in a context the business did not anticipate.
  • Whether customer contracts restrict deployment contexts, or permit any use the customer chooses.
  • Whether the business could produce technical documentation and post-market monitoring evidence if asked during a deal.

Where this lands in the contract

Confirmation that non-EU providers placing systems on the EU market fall within scope removes the geographic argument that many businesses were quietly relying on. Where a system is or may become high-risk, the allocation of responsibility between provider, deployer and any embedded AI vendor needs to be explicit rather than inferred, and warranties drafted before the classification question was settled are worth revisiting.