# AI Act Material Scope — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/ai-act-material-scope
> Sources are cited per item. Verify against the official texts before relying on them.

The material scope defines which types of AI systems and activities fall within the regulation's coverage, including specific exclusions and definitional boundaries that merit dedicated coverage.

## Overview

## Legal Framework

The material scope of the AI Act is primarily governed by Article 2, which establishes that the regulation applies to AI systems placed on the market or put into service in the Union, regardless of whether the provider is established within or outside the EU. The regulation also covers deployers of AI systems located in the Union, and providers and deployers of AI systems where the output produced is used in the Union.

Article 3 provides the foundational definitions, most critically the definition of an "AI system" itself, which follows a machine-learning-centered approach: a machine-based system designed to operate with varying levels of autonomy and that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations, or decisions. This definitional boundary is the threshold question for any scope analysis.

Article 6 establishes the classification framework for high-risk AI systems, dividing them into two categories: systems used as safety components of regulated products (Annex I), and systems listed in Annex III covering specific use cases such as biometric identification, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice.

Article 25 addresses responsibilities along the AI value chain, allocating obligations between providers, distributors, importers, and deployers. Article 16 sets out the specific obligations imposed on providers of high-risk AI systems, including conformity requirements, quality management systems under Article 17, technical documentation under Article 18, and log retention under Article 19.

Key exclusions from material scope include AI systems developed or used exclusively for military, defense, or national security purposes, and AI systems used solely for scientific research and development. Free and open-source AI systems are also excluded from most obligations, except where they fall within the prohibited practices or high-risk categories.

## Key Developments

The AI Act entered into force on August 1, 2024, with phased application dates. Prohibited practices under Article 5 became applicable from February 2, 2025. The high-risk classification framework and corresponding provider obligations under Articles 16 through 25 will apply from August 2, 2026, with certain provisions for high-risk systems tied to regulated products applying from August 2, 2027.

The European Commission has begun preparatory work on implementing acts and guidance documents clarifying the boundaries of the AI system definition, particularly the distinction between traditional software and AI systems. The AI Office, established within the Commission, is tasked with issuing guidelines on the material scope, including the practical application of the open-source exemption and the military exclusion.

No enforcement decisions have yet been issued, as national competent authorities are still being designated across Member States. However, the European Data Protection Board has signaled coordination between GDPR supervisory authorities and AI Act competent authorities, particularly for AI systems processing special category data under GDPR Article 9.

## Practical Guidance

- Conduct a systematic scope assessment for every AI system your organization develops, deploys, or distributes, applying the Article 3 definition as the threshold filter before proceeding to risk classification under Article 6.

- Map value chain roles carefully under Article 25: a provider that places its name on a system or substantially modifies a high-risk system assumes full provider obligations under Article 16, even if it did not originally develop the system.

- Document the basis for any claimed exclusion — particularly the military, national security, or open-source exemptions — with reasoned analysis, as the exemptions are narrowly construed and carry significant evidentiary expectations.

- For systems that may qualify as high-risk under Annex III, begin conformity assessment preparations now, including quality management system design under Article 17 and technical documentation compilation under Article 18, given the August 2026 deadline.

- Establish log retention infrastructure compliant with Article 19 requirements, ensuring automatic logging capabilities are built into high-risk systems before market placement.

## Legislation (full text of key provisions)

### Responsibilities along the AI value chain

*Source: AI Act, aiact-art-25-en, 2024-06-12 — https://overview.legal/posts/92363*

### Recital 12 — AI system definition and characteristics

*Source: AI Act, aiact-rec-12-en, 2024-06-12 — https://overview.legal/posts/93706*

The notion of ‘AI system’ in this Regulation should be clearly defined and should be closely aligned with the work of international organisations working on AI to ensure legal certainty, facilitate international convergence and wide acceptance, while providing the flexibility to accommodate the rapid technological developments in this field. Moreover, the definition should be based on key characteristics of AI systems that distinguish it from simpler traditional software systems or programming approaches and should not cover systems that are based on the rules defined solely by natural persons to automatically execute operations. A key characteristic of AI systems is their capability to infer. This capability to infer refers to the process of obtaining the outputs, such as predictions, content, recommendations, or decisions, which can influence physical and virtual environments, and to a capability of AI systems to derive models or algorithms, or both, from inputs or data. The techniques that enable inference while building an AI system include machine learning approaches that learn from data how to achieve certain objectives, and logic- and knowledge-based approaches that infer from encoded knowledge or symbolic representation of the task to be solved. The capacity of an AI system to infer transcends basic data processing by enabling learning, reasoning or modelling. The term ‘machine-based’ refers to the fact that AI systems run on machines. The reference to explicit or implicit objectives underscores that AI systems can operate according to explicit defined objectives or to implicit objectives. The objectives of the AI system may be different from the intended purpose of the AI system in a specific context. For the purposes of this Regulation, environments should be understood to be the contexts in which the AI systems operate, whereas outputs generated by the AI system reflect different functions performed by AI systems and include predictions, content, recommendations or decisions. AI systems are designed to operate with varying levels of autonomy, meaning that they have some degree of independence of actions from human involvement and of capabilities to operate without human intervention. The adaptiveness that an AI system could exhibit after deployment, refers to self-learning capabilities, allowing the system to change while in use. AI systems can be used on a stand-alone basis or as a component of a product, irrespective of whether the system is physically integrated into the product (embedded) or serves the functionality of the product without being integrated therein (non-embedded).

### Recital 88 — AI value chain supplier cooperation

*Source: AI Act, aiact-rec-88-en, 2024-06-12 — https://overview.legal/posts/93858*

Along the AI value chain multiple parties often supply AI systems, tools and services but also components or processes that are incorporated by the provider into the AI system with various objectives, including the model training, model retraining, model testing and evaluation, integration into software, or other aspects of model development. Those parties have an important role to play in the value chain towards the provider of the high-risk AI system into which their AI systems, tools, services, components or processes are integrated, and should provide by written agreement this provider with the necessary information, capabilities, technical access and other assistance based on the generally acknowledged state of the art, in order to enable the provider to fully comply with the obligations set out in this Regulation, without compromising their own intellectual property rights or trade secrets.

### Recital 100 — general-purpose AI system definition and integration

*Source: AI Act, aiact-rec-100-en, 2024-06-12 — https://overview.legal/posts/93882*

When a general-purpose AI model is integrated into or forms part of an AI system, this system should be considered to be general-purpose AI system when, due to this integration, this system has the capability to serve a variety of purposes. A general-purpose AI system can be used directly, or it may be integrated into other AI systems.

### Recital 89 — open source AI tools exempt

*Source: AI Act, aiact-rec-89-en, 2024-06-12 — https://overview.legal/posts/93860*

Third parties making accessible to the public tools, services, processes, or AI components other than general-purpose AI models, should not be mandated to comply with requirements targeting the responsibilities along the AI value chain, in particular towards the provider that has used or integrated them, when those tools, services, processes, or AI components are made accessible under a free and open-source licence. Developers of free and open-source tools, services, processes, or AI components other than general-purpose AI models should be encouraged to implement widely adopted documentation practices, such as model cards and data sheets, as a way to accelerate information sharing along the AI value chain, allowing the promotion of trustworthy AI systems in the Union.

### Recital 20 — AI literacy for informed decisions

*Source: AI Act, aiact-rec-20-en, 2024-06-12 — https://overview.legal/posts/93722*

In order to obtain the greatest benefits from AI systems while protecting fundamental rights, health and safety and to enable democratic control, AI literacy should equip providers, deployers and affected persons with the necessary notions to make informed decisions regarding AI systems. Those notions may vary with regard to the relevant context and can include understanding the correct application of technical elements during the AI system’s development phase, the measures to be applied during its use, the suitable ways in which to interpret the AI system’s output, and, in the case of affected persons, the knowledge necessary to understand how decisions taken with the assistance of AI will have an impact on them. In the context of the application this Regulation, AI literacy should provide all relevant actors in the AI value chain with the insights required to ensure the appropriate compliance and its correct enforcement. Furthermore, the wide implementation of AI literacy measures and the introduction of appropriate follow-up actions could contribute to improving working conditions and ultimately sustain the consolidation, and innovation path of trustworthy AI in the Union. The European Artificial Intelligence Board (the ‘Board’) should support the Commission, to promote AI literacy tools, public awareness and understanding of the benefits, risks, safeguards, rights and obligations in relation to the use of AI systems. In cooperation with the relevant stakeholders, the Commission and the Member States should facilitate the drawing up of voluntary codes of conduct to advance AI literacy among persons dealing with the development, operation and use of AI.

### Recital 114 — systemic risk AI model obligations

*Source: AI Act, aiact-rec-114-en, 2024-06-12 — https://overview.legal/posts/93910*

The providers of general-purpose AI models presenting systemic risks should be subject, in addition to the obligations provided for providers of general-purpose AI models, to obligations aimed at identifying and mitigating those risks and ensuring an adequate level of cybersecurity protection, regardless of whether it is provided as a standalone model or embedded in an AI system or a product. To achieve those objectives, this Regulation should require providers to perform the necessary model evaluations, in particular prior to its first placing on the market, including conducting and documenting adversarial testing of models, also, as appropriate, through internal or independent external testing. In addition, providers of general-purpose AI models with systemic risks should continuously assess and mitigate systemic risks, including for example by putting in place risk-management policies, such as accountability and governance processes, implementing post-market monitoring, taking appropriate measures along the entire model’s lifecycle and cooperating with relevant actors along the AI value chain.

### Recital 165 — voluntary codes of conduct for non-high-risk AI

*Source: AI Act, aiact-rec-165-en, 2024-06-12 — https://overview.legal/posts/94012*

The development of AI systems other than high-risk AI systems in accordance with the requirements of this Regulation may lead to a larger uptake of ethical and trustworthy AI in the Union. Providers of AI systems that are not high-risk should be encouraged to create codes of conduct, including related governance mechanisms, intended to foster the voluntary application of some or all of the mandatory requirements applicable to high-risk AI systems, adapted in light of the intended purpose of the systems and the lower risk involved and taking into account the available technical solutions and industry best practices such as model and data cards. Providers and, as appropriate, deployers of all AI systems, high-risk or not, and AI models should also be encouraged to apply on a voluntary basis additional requirements related, for example, to the elements of the Union’s Ethics Guidelines for Trustworthy AI, environmental sustainability, AI literacy measures, inclusive and diverse design and development of AI systems, including attention to vulnerable persons and accessibility to persons with disability, stakeholders’ participation with the involvement, as appropriate, of relevant stakeholders such as business and civil society organisations, academia, research organisations, trade unions and consumer protection organisations in the design and development of AI systems, and diversity of the development teams, including gender balance. To ensure that the voluntary codes of conduct are effective, they should be based on clear objectives and key performance indicators to measure the achievement of those objectives. They should also be developed in an inclusive way, as appropriate, with the involvement of relevant stakeholders such as business and civil society organisations, academia, research organisations, trade unions and consumer protection organisation. The Commission may develop initiatives, including of a sectoral nature, to facilitate the lowering of technical barriers hindering cross-border exchange of data for AI development, including on data access infrastructure, semantic and technical interoperability of different types of data.

### Recital 21 — non-discriminatory application to all AI providers

*Source: AI Act, aiact-rec-21-en, 2024-06-12 — https://overview.legal/posts/93724*

In order to ensure a level playing field and an effective protection of rights and freedoms of individuals across the Union, the rules established by this Regulation should apply to providers of AI systems in a non-discriminatory manner, irrespective of whether they are established within the Union or in a third country, and to deployers of AI systems established within the Union.

### Recital 85 — general purpose AI provider cooperation obligations

*Source: AI Act, aiact-rec-85-en, 2024-06-12 — https://overview.legal/posts/93852*

General-purpose AI systems may be used as high-risk AI systems by themselves or be components of other high-risk AI systems. Therefore, due to their particular nature and in order to ensure a fair sharing of responsibilities along the AI value chain, the providers of such systems should, irrespective of whether they may be used as high-risk AI systems as such by other providers or as components of high-risk AI systems and unless provided otherwise under this Regulation, closely cooperate with the providers of the relevant high-risk AI systems to enable their compliance with the relevant obligations under this Regulation and with the competent authorities established under this Regulation.

## Related topics

- **AI Value Chain Actors and Roles** — https://overview.legal/topics/ai-value-chain-actors
  The content focuses on responsibilities distributed across different actors in the AI value chain. A dedicated topic for understanding the various actors, their
- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection
- **GPAI Systemic Risk** — https://overview.legal/topics/general-purpose-ai-models-systemic-risk
  This new topic is needed because the content specifically addresses the classification and identification of general-purpose AI models that present systemic ris
- **Provider Obligations for AI Systems** — https://overview.legal/topics/provider-obligations-ai
  The content specifically addresses obligations imposed on providers of high-risk AI systems, which is a distinct and important category of requirements that des
- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals
- **Conformity Assessment for AI Systems** — https://overview.legal/topics/conformity-assessment-ai
  Provider obligations typically include conformity assessment procedures and documentation requirements, which is a specific compliance mechanism under the AI Ac

---
Generated by overview.legal · https://overview.legal/topics/ai-act-material-scope · 2026-08-22
