Does the EU AI Act Apply to Your Company? A Free Video Series
This free English-language video series works through Regulation (EU) 2024/1689, the EU Artificial Intelligence Act, article by article, in the version amended by Regulation (EU) 2026/1744, the Digital Omnibus on AI, in force since 27 July 2026. It is written for executives and in-house legal and compliance teams at US technology companies whose AI systems, or the output of those systems, reach the European Union. The legal position is stated as at September 2026.
The first nine episodes set out why the EU AI Act is built as product safety law rather than data protection law, and then work through the connecting factors in Art. 2, including the rule that reaches a provider or deployer in a third country where the output of the system is used in the Union. They cover the exclusions for national security, sole-purpose scientific research, pre-market development and free and open-source releases, each of which is narrower than it is commonly assumed to be, and the definition of an AI system in Art. 3(1). The operator roles follow, because every obligation in the Regulation is addressed to a role and not to a company; Art. 25 is treated in detail, since rebranding, a substantial modification or a change of intended purpose can turn a deployer into the provider of a high-risk system. Three episodes work through the ten prohibited practices in Art. 5, and Band 1 closes with the AI literacy duty in Art. 4, which has applied since 2 February 2025. Throughout, the series separates what already applies from what the Digital Omnibus deferred; descriptions of the timetable published before July 2026 no longer reflect the text.
The episodes last roughly ten to fifteen minutes, can be watched in any order, and each one names the provisions it discusses, so a single article can be found directly; no prior knowledge of European product safety law is assumed. The videos are free; no registration, account or email address is required, and no certificate is issued. The videos are in English, and the German terms of the Regulation are given where they diverge.
- Which connecting factor in Art. 2(1) reaches you, including the output rule in point (c)
- Whether your own software is an AI system under Art. 3(1) and where Chapter V applies as well
- Whether you act as provider or deployer, and when Art. 25 makes a customer the provider of a high-risk system
- Which of the ten prohibitions in Art. 5 a bought-in system can trigger, not only one you built
- Which duties bind you today under Art. 4 and Art. 5, and which begin in December 2026, 2027 and 2028
This series is general information on Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 and does not constitute advice on an individual matter. Advice is given on the law of the European Union and on German law, on the basis of admission to the German bar. There is no admission to practice in any jurisdiction of the United States.
As at 2026-09-19 · Rechtsanwalt Theo Funk, Rechtsanwaltskammer Bamberg
EU AI Act Article Index: Which Episode Covers Which Article
The table lists the provisions discussed in each episode. It follows the order of Regulation (EU) 2024/1689 and includes the amending provisions of Regulation (EU) 2026/1744 where an episode depends on them, so a single article can be found without watching the series in sequence.
| Articles | Topic | Episode |
|---|---|---|
| Art. 4-6, 40, 50, 101, 113 | EU AI Act Structure and the 2026 Reset | 01 |
| Art. 2; Annex I Sections A-B | Territorial and Material Scope under Article 2 | 02 |
| Art. 3(1), (63), (66); 51(2) | EU AI Act Definitions: AI System and GPAI Model | 03 |
| Art. 3(3)-(8), 16, 25, 26, 99(4)(da) | Provider or Deployer: The Article 25 Role Flip | 04 |
| Art. 22-24, 54, 99(4), 101 | Authorised Representatives, Importers and Distributors | 05 |
| Art. 5(1)(a), (b), (c), (d) | Prohibited AI Practices: Manipulation, Vulnerability and Social Scoring | 06 |
| Art. 5(1)(e)-(h), 5(2)-(7) | The Four Biometric Prohibitions of the EU AI Act | 07 |
| Art. 5(1)(ba)-(bb), 5(1a)-(1b), 99, 113 | Two New Prohibitions: Non-Consensual Imagery and AI-Generated CSAM | 08 |
| Art. 4(1)-(3), 26(2) | Article 4 AI Literacy and the Band 1 Sequence | 09 |
| Art. 6-49, 113 | EU AI Act High-Risk Regime: Architecture and Deadlines | 10 |
The EU AI Act Explained on Video
A free English-language series on Regulation (EU) 2024/1689 for executives and in-house teams at US companies, in the order of the articles.
Band 1: Foundations, Scope, Roles and Prohibited Practices (Episodes 1 to 9)
Episodes 1 to 9 cover the architecture of Regulation (EU) 2024/1689 as European product safety law, the seven categories of addressee in Art. 2(1), the definition of an AI system in Art. 3(1) together with the four categories of software that the Commission guidelines place outside it, and the operator roles in Art. 3, including the change of role under Art. 25. Episode 5 takes the Union-facing chain of authorised representative, importer and distributor and separates the two written mandates: the one in Art. 54 for providers of general-purpose AI models, which has applied since 2 August 2025, and the one in Art. 22 for high-risk systems, which follows the deferred high-risk timetable. Episodes 6 to 8 work through the ten prohibited practices in Art. 5, including the two inserted in July 2026, which apply from 2 December 2026, and Episode 9 closes the band with the AI literacy duty in Art. 4.
This episode introduces the EU AI Act as Regulation (EU) 2024/1689: product safety law rather than GDPR for AI. It separates the Article 5 prohibitions, the Annex I and Annex III high-risk tiers and Article 50 transparency from the parallel Chapter V track for general-purpose AI models, then sets out what Regulation (EU) 2026/1744 deferred in July 2026 — Annex III duties to 2 December 2027, Annex I duties to 2 August 2028 — and what binds a compliance team today.
This episode examines Article 2 of the EU AI Act: the seven addressee categories in Article 2(1) and the three connecting factors that reach a US company, including the Article 2(1)(c) rule that applies the Regulation where a system's output is used in the Union. It tests the exclusions in Article 2(3) to (12) for military, research, open-source and personal use, the Annex I Section B partial regime, and the five-step sequence for recording a scope decision per system.
This episode applies the EU AI Act definition of an AI system in Article 3(1) to a company's own software, using the seven elements in the Commission's guidelines and the four categories the guidelines place outside it. It then separates that term from the general-purpose AI model in Article 3(63), the general-purpose AI system in Article 3(66) and the systemic-risk presumption in Article 51(2), as both regimes can bind the same company.
This episode examines the operator roles in Article 3(3) to (8) of the EU AI Act and compares the provider duties in Article 16 with the lighter deployer duties in Article 26. It then works through Article 25: branding, substantial modification or a changed intended purpose can make a customer the provider of a high-risk system, and Article 99(4)(da) now fines breach of the Article 25(2) and (4) cooperation duties. Decide your role before white-labelling or fine-tuning.
This episode examines the EU AI Act's two authorised representative regimes for third-country providers: Article 54 for general-purpose AI models, since 2 August 2025, and Article 22 for high-risk systems, from 2 December 2027 or 2 August 2028. It covers the written mandate, ten-year retention, the duty to terminate and report, Article 54(6)'s exemption for open-source models without systemic risk, importer verification under Article 23, distributor duties under Article 24 and fines under Articles 99(4) and 101.
This episode covers four of the ten prohibitions in Article 5(1) of the EU AI Act, points (a), (b), (c) and (d): subliminal, manipulative or deceptive techniques, exploitation of age, disability or socio-economic vulnerability, social scoring, and criminal risk prediction based solely on profiling. Drawing on Commission Guidelines C(2025) 5052 final of 29 July 2025, it distinguishes the conduct each point prohibits and shows how to screen built and procured systems against Article 5.
This episode examines the four biometric prohibitions of the EU AI Act in Article 5(1)(e) to (h): untargeted scraping of facial images, emotion inference at work and in education, biometric categorisation by sensitive attributes, and real-time remote biometric identification in publicly accessible spaces for law enforcement. It explains why sentiment analysis of employee communications can fall under point (f), how narrow the medical-or-safety exception is, and why real-time use depends on national law.
This episode examines the two prohibitions added to Article 5(1) of the EU AI Act by the Digital Omnibus: point (ba) on non-consensual intimate imagery and point (bb) on AI-generated child sexual abuse material. It explains the scoping tests in Article 5(1a) and (1b), which decide whether a capable generative system may be placed on the Union market, the 2 December 2026 application date in Article 113, and the penalty position under Article 99.
Article 4 of the EU AI Act has bound providers and deployers since 2 February 2025; the Digital Omnibus recast it from an obligation of result into one of means, not a repeal. The episode sets out a programme that holds up as evidence: roles differentiated, contractors covered by contract, content tied to the AI estate and records. It adds the human oversight competence and training Article 26(2) requires of deployers of high-risk systems, and closes Band 1 in seven steps.
When Rebranding or Modification Changes the Role
Art. 25(1) turns a customer into the provider of a high-risk system in three cases: putting its own name on a system that is already high-risk, substantially modifying one already on the market, or changing the intended purpose of a system so that it becomes high-risk. Only the first case can be allocated differently by contract, and at model level Chapter V applies instead. Where a product plan touches any of the three, the role is better settled before the release than after it.
Request a callBand 2: The High-Risk Regime and Its 2027 and 2028 Deadlines (from Episode 10)
Episode 10 opens Band 2 with the structure and the dates of the high-risk regime. Chapter III runs from Art. 6 to Art. 49 in five sections, and Art. 113(3)(c), as amended, applies Sections 1 to 3, with the exception of Art. 6(5), from 2 December 2027 to systems classified as high-risk under Art. 6(2) and Annex III and from 2 August 2028 to systems classified under Art. 6(1) and Annex I. Those are fixed calendar dates; the co-legislators rejected making them conditional on the availability of harmonised standards. The episode also sets out why the additional time is shorter than it appears: as at September 2026 no harmonised standard had been cited in the Official Journal, so the presumption of conformity in Art. 40 is not available, and for Annex III point 1 systems Art. 43 leaves the internal control route open only where standards or common specifications have been applied.
This episode maps Chapter III of the EU AI Act, Articles 6 to 49 in five sections, against the amended dates in Article 113: Sections 1 to 3 now apply from 2 December 2027 for Annex III systems and from 2 August 2028 for Annex I systems. It explains why the deferral is only partial, and why biometric providers keep the internal control route under Article 43 only where harmonised standards or common specifications have been applied, and otherwise take the Annex VII route.
Planning Ahead of the 2027 and 2028 Dates
Chapter III, Sections 1 to 3 bind Annex III systems from 2 December 2027 and Annex I systems from 2 August 2028, and those are fixed calendar dates. What that leaves is less than it looks: classification under Art. 6, the quality management system, the technical documentation and the conformity assessment have to be in place on the day, not started on it. Companies that expect a classification under Annex III or Annex I therefore tend to begin well before those dates.
Arrange a conversationFurther Episodes
Ten of the twenty-six episodes are published on this page. The remaining episodes cover the requirements for high-risk systems, the Chapter V track for general-purpose AI models, the transparency duties in Art. 50, and governance, enforcement and penalties. They have been recorded but are not yet published here.
Get in touchQuestions About the EU AI Act
Does the EU AI Act apply to US companies with no establishment in the EU?
Yes, where one of the connecting factors in Art. 2(1) is met. The Regulation applies to providers who place an AI system on the Union market or put it into service, expressly irrespective of whether they are established in the Union or in a third country; to deployers established or located in the Union; and to providers and deployers in a third country where the output produced by the system is used in the Union. Incorporation outside the Union is not in itself a defence, and the exclusions in Art. 2 are separate and narrow.
Our AI runs only on US servers. Does the EU AI Act still apply?
It may. Art. 2(1)(c) applies the Regulation to providers and deployers established in a third country where the output produced by the AI system is used in the Union. It requires neither placing the system on the Union market, nor an establishment in Europe, nor any European infrastructure: the connecting factor is where the output is used. A screening model hosted in the United States whose decisions are acted upon in the Union falls within it. Whether a given output is used in the Union is a question of fact, and the provision has not yet been tested in case law.
Has the EU AI Act been delayed?
In part. Regulation (EU) 2026/1744 deferred Chapter III, Sections 1 to 3 — classification, the high-risk requirements and the operator duties — to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. Nothing else moved. The Art. 5 prohibitions and the Art. 4 AI literacy duty have applied since 2 February 2025, except the two inserted in July 2026, Art. 5(1)(ba) and (bb), which apply from 2 December 2026. Chapter V, governance and penalties have applied since 2 August 2025, the Art. 101 fines and the Art. 50 transparency duties since 2 August 2026.
What is the Digital Omnibus on AI, and what did it change?
Regulation (EU) 2026/1744 was adopted on 8 July 2026, published in the Official Journal on 24 July and in force since 27 July 2026. It is an amending regulation, so there is no separate omnibus regime; the EU AI Act now reads differently. Besides the deferral it softened Art. 4 from ensuring a sufficient level of AI literacy to supporting its development, narrowed the safety component definition, inserted two prohibitions on non-consensual intimate imagery and AI-generated child sexual abuse material, which apply from 2 December 2026, not from entry into force, and added proportionality relief for small mid-cap enterprises.
Am I a provider or a deployer under the EU AI Act?
The roles turn on conduct, not on size or sector. A provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge (Art. 3(3)). A deployer uses a system under its own authority, outside a purely personal, non-professional activity (Art. 3(4)). The obligation sets are asymmetric: for a high-risk system the provider carries the twelve points of Art. 16 and the deployer the narrower duties of Art. 26, in each case from 2 December 2027 or 2 August 2028. One group can hold both roles for different systems.
Can rebranding or modifying someone else's AI system make us the provider?
It can. Under Art. 25(1) a distributor, importer, deployer or third party is considered the provider of a high-risk AI system where it puts its name or trademark on a high-risk system on the market, substantially modifies such a system, or modifies the intended purpose of a system, including a general-purpose AI system, so that it becomes high-risk. The first trigger is subject to contrary contractual allocation. The initial provider then owes the cooperation duties in Art. 25(2) unless it has clearly specified that its system is not to be changed into a high-risk one. At model level the provider question follows Chapter V, not Art. 25.
What counts as an AI system under the EU AI Act?
Art. 3(1) covers a machine-based system designed to operate with varying levels of autonomy, which may exhibit adaptiveness after deployment and which, for explicit or implicit objectives, infers from its input how to generate outputs such as predictions, content, recommendations or decisions influencing physical or virtual environments. Inference is the hinge, and adaptiveness is optional. The Commission guidelines on the definition, C(2025) 5053 final of 29 July 2025, place four categories of software outside it, among them basic data processing and classical heuristics, but state at paragraph 7 that they are not binding.
What are the penalties under the EU AI Act?
Art. 99(3) sets the ceiling for breach of the Art. 5 prohibitions at EUR 35 million or 7 percent of total worldwide annual turnover for the preceding financial year, whichever is higher. Art. 99(4) covers breach of the other operator obligations at EUR 15 million or 3 percent, and Art. 99(5) sets EUR 7.5 million or 1 percent for supplying incorrect, incomplete or misleading information to authorities. For SMEs and start-ups the lower figure applies; for small mid-caps only under Art. 99(4) and (5). Member States set and apply these penalties; Art. 101 reserves separate fines for providers of general-purpose AI models to the Commission.
Does the EU AI Act require AI training for our staff?
Art. 4 binds providers and deployers of AI systems and has applied since 2 February 2025. In the version amended by Regulation (EU) 2026/1744 it requires them to support the development of a sufficient level of AI literacy among their staff and other persons operating systems on their behalf, taking account of technical knowledge, experience, education and training and the context of use. That recast turns an obligation of result into one of means; it is not a repeal. With Art. 5 it is one of the few duties that bind irrespective of risk class. No certificate, external course or fixed number of hours is prescribed.
