AI Act Material Scope
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.The material scope defines which types of AI systems and activities fall within the regulation's coverage, including specific exclusions and definitional boundaries that merit dedicated coverage.
Overview
9 sources · Jul 23, 2026Legal Framework
The material scope of the AI Act is primarily governed by Article 2, which establishes that the regulation applies to AI systems placed on the market or put into service in the Union, regardless of whether the provider is established within or outside the EU. The regulation also covers deployers of AI systems located in the Union, and providers and deployers of AI systems where the output produced is used in the Union.
Article 3 provides the foundational definitions, most critically the definition of an "AI system" itself, which follows a machine-learning-centered approach: a machine-based system designed to operate with varying levels of autonomy and that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations, or decisions. This definitional boundary is the threshold question for any scope analysis.
Article 6 establishes the classification framework for high-risk AI systems, dividing them into two categories: systems used as safety components of regulated products (Annex I), and systems listed in Annex III covering specific use cases such as biometric identification, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice.
Article 25 addresses responsibilities along the AI value chain, allocating obligations between providers, distributors, importers, and deployers. Article 16 sets out the specific obligations imposed on providers of high-risk AI systems, including conformity requirements, quality management systems under Article 17, technical documentation under Article 18, and log retention under Article 19.
Key exclusions from material scope include AI systems developed or used exclusively for military, defense, or national security purposes, and AI systems used solely for scientific research and development. Free and open-source AI systems are also excluded from most obligations, except where they fall within the prohibited practices or high-risk categories.
Key Developments
The AI Act entered into force on August 1, 2024, with phased application dates. Prohibited practices under Article 5 became applicable from February 2, 2025. The high-risk classification framework and corresponding provider obligations under Articles 16 through 25 will apply from August 2, 2026, with certain provisions for high-risk systems tied to regulated products applying from August 2, 2027.
The European Commission has begun preparatory work on implementing acts and guidance documents clarifying the boundaries of the AI system definition, particularly the distinction between traditional software and AI systems. The AI Office, established within the Commission, is tasked with issuing guidelines on the material scope, including the practical application of the open-source exemption and the military exclusion.
No enforcement decisions have yet been issued, as national competent authorities are still being designated across Member States. However, the European Data Protection Board has signaled coordination between GDPR supervisory authorities and AI Act competent authorities, particularly for AI systems processing special category data under GDPR Article 9.
Practical Guidance
Conduct a systematic scope assessment for every AI system your organization develops, deploys, or distributes, applying the Article 3 definition as the threshold filter before proceeding to risk classification under Article 6.
Map value chain roles carefully under Article 25: a provider that places its name on a system or substantially modifies a high-risk system assumes full provider obligations under Article 16, even if it did not originally develop the system.
Document the basis for any claimed exclusion — particularly the military, national security, or open-source exemptions — with reasoned analysis, as the exemptions are narrowly construed and carry significant evidentiary expectations.
For systems that may qualify as high-risk under Annex III, begin conformity assessment preparations now, including quality management system design under Article 17 and technical documentation compilation under Article 18, given the August 2026 deadline.
Establish log retention infrastructure compliant with Article 19 requirements, ensuring automatic logging capabilities are built into high-risk systems before market placement.