⚠ Medium compliance impact for SMEs
WHAT THE ARTICLE IS ABOUT
The legal dictionary of the AI Act
Article 3 contains the official definitions for all key terms used in the EU AI Act. These definitions are legally binding — they determine precisely who is obligated, what systems are covered, and how the rules apply in practice.
WHAT IT SAYS
The most important definitions
- An AI system is defined as a machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness, and that infers from inputs how to generate outputs such as predictions, recommendations, decisions or content that influence real or virtual environments
- A provider is any natural or legal person that develops or has an AI system developed and places it on the market or puts it into service under their own name
- A deployer is any natural or legal person that uses an AI system under their authority in a professional context — this includes most businesses using third-party AI tools
- A high-risk AI system refers to systems listed in Annex III or safety components under EU harmonisation legislation
- Other key definitions include: general purpose AI model, reasonably foreseeable misuse, placing on the market, putting into service, conformity assessment, and post-market monitoring
WHO IS AFFECTED
Everyone subject to the Act
- Everyone subject to the Act — the definitions determine your role and therefore your obligations
- Legal and compliance teams interpreting the regulation
- Businesses determining whether their tools qualify as AI systems under the Act’s definition
WHAT IT MEANS FOR SMES
The deployer definition catches most small businesses
- The definition of AI system is deliberately broad — most software using machine learning, neural networks, or statistical inference will qualify
- The deployer definition catches most SMEs: if you use ChatGPT, an AI hiring tool, an automated customer service system, or any AI-powered SaaS in a business context, you are a deployer
- Being a deployer carries real obligations under the Act — it is not a passive role
- Check carefully whether your vendor is the provider and you are the deployer — this split determines who is responsible for what
Related Articles
- Article 2 — Scope (uses these definitions to determine who is covered)
- Article 6 — High-risk classification (relies on the AI system definition)
- Article 50 — Transparency obligations (relies on the deployer definition)
