I wrote this article because EU AI Act scope decisions are too important to rest on convenient assumptions. Compliance practitioners need a practical way to determine which requirements apply to each AI system, model, use case and operator role, while recognising that organisations outside the EU and users of free and open-source AI may still be in scope.
Many organisations begin their EU AI Act assessment with one of two assumptions:
Neither assumption is a safe basis for a compliance decision.
For most compliance practitioners, the immediate priority will be determining how the EU AI Act applies to AI systems developed, supplied or used within their own EU-based organisation. However, a reliable scope assessment must look beyond the organisation’s location and beyond the licence attached to the technology.
The EU AI Act applies through a combination of factors, including:
The practical message is straightforward: assess scope for each relevant AI system, model, use case, legal entity, and operator role. It should not be inferred from one fact alone.
This is the practical problem NORVA is designed to solve. NORVA helps compliance teams answer one simple question:
“Are we meeting the requirements that apply to us?”
Answering that question begins with a clear, evidence-based determination of scope, role, exclusions and classification. Without that foundation, organisations can overlook obligations, activate the wrong assessment path or rely on an exclusion that does not apply.
For organisations established in the EU, location is an important starting point, but it is not the complete assessment.
Article 2 brings several different participants within the Act’s scope, including:
An EU-based organisation may therefore need to assess more than whether it “uses AI”.
It may be:
The organisation’s role can determine which obligations apply. A role assessment should therefore consider contracts, branding, supply arrangements, operational authority and what happens in practice, not merely the description used by the organisation or its technology supplier.
The EU AI Act is an EU regulation, but its scope is not restricted to organisations incorporated or physically located in the EU.
It applies to providers placing AI systems on the EU market, putting AI systems into service in the EU or placing general-purpose AI models on the EU market, regardless of whether those providers are established in the EU or in a third country. It can also apply to providers and deployers located outside the EU where the output produced by the AI system is used in the EU.
Recital 22 explains the reasoning. An EU operator might contract with an organisation outside the EU to perform an activity using AI. The overseas system could process data transferred from the EU and return its output to an EU organisation without the system itself being placed on the EU market or used directly within the EU. The Act addresses that possibility by extending scope to third-country providers and deployers where the output is intended for use in the EU.
This means that an organisation outside the EU should not base its scope conclusion solely on the absence of:
Instead, it should examine whether it:
This remains an important implication for global organisations and international supply chains. However, it should form part of the overall scope assessment rather than being treated as the entire EU AI Act story.
The use of free and open-source AI does not automatically remove an organisation or every affected system from the EU AI Act.
Article 2 provides that the Regulation does not apply to AI systems released under free and open-source licences unless they are placed on the market or put into service as:
This qualification is critical.
A compliance practitioner should not stop the assessment after confirming that software, a model or another AI component is described as “open source”. The practitioner must still determine:
The licence is therefore one part of the assessment. It does not replace role determination, use-case analysis or risk classification.
H3: Open-source components and deployed systems are not necessarily the same thing
Compliance teams should also distinguish between:
An organisation may use open-source technology as one component of a commercial or operational AI system. The finished system may have a different intended purpose, operating context and risk classification from the underlying component.
For example, the relevant compliance issue may not be the licence attached to the base model. It may be how the completed system is used to:
The correct question is not simply, “Is this open source?”
It is:
What is the resulting AI system, what is it intended to do, who performs each operator role, and which EU AI Act provisions apply to that particular use?
The free and open-source provision is not the only area in which organisations may reach an overbroad conclusion.
Article 2 also addresses circumstances involving:
These provisions contain specific conditions.
For example:
A defensible assessment should record:
A reliable scope assessment should follow a structured sequence.
Define what is being assessed. Avoid treating an entire technology portfolio, supplier relationship or business unit as one undifferentiated item.
Record who develops, provides, imports, distributes, modifies or uses the system, and where each relevant entity is established.
An organisation may perform several roles. Each role and its resulting obligations should be assessed separately.
Determine where the system or model is supplied, made available, put into service and used. Where an overseas organisation is involved, trace where the system’s output is intended to be used.
Identify the exact provision, confirm every condition and retain evidence supporting the conclusion.
Determine whether the system:
The Act uses a risk-based approach that includes prohibited practices, requirements for high-risk AI systems and transparency obligations for certain other systems.
A scope assessment should produce an actionable outcome. It should identify which further compliance requirements apply, who owns them, and what must be assessed next.
Scope and role conclusions may change when the organisation changes:
The EU AI Act’s scope cannot be reduced to a simple test of organisational location or software licensing.
For EU organisations, the central task is to understand their systems, use cases, roles, classifications and supply-chain relationships.
For organisations outside the EU, the absence of an EU establishment does not automatically place them outside the Act. Market activity, operator roles, and the intended use of AI output within the EU may still bring them within scope.
For organisations using free and open-source AI, the licence does not automatically remove every EU AI Act requirement. High-risk systems and systems falling under Articles 5 or 50 remain expressly outside the general open-source exclusion.
The better approach is to ask:
That is the difference between assuming an organisation is out of scope and producing a clear, traceable and supportable EU AI Act determination.
Do not leave EU AI Act scope, role, and classification decisions to assumption.
NORVA’s Excel-native compliance assessment tools help organisations and advisers work through complex applicability questions in a familiar, structured format, with regulatory source links, practical assessor guidance, evidentiary support and automatically generated reporting. They help teams move from the core question, “Are we meeting the requirements that apply to us?”, to a clear, traceable and supportable assessment outcome.
Clear compliance assessment. Practical evidence. No heavy GRC platform required.
This article is based primarily on Regulation (EU) 2024/1689, including Article 2 and the relevant recitals. It is written for practical compliance-assessment purposes and should be reviewed against the current consolidated legal text, applicable European Commission guidance and relevant regulatory or judicial developments before publication or reliance. Organisations should obtain qualified legal advice where scope, operator role, an exclusion or classification remains uncertain.
This article provides general information and does not constitute legal advice.