Explainer

What the EU AI Act means if you only use model APIs

You may never train a model and still be a "provider" under the AI Act. How the roles work, which duties are live in October 2026, and a checklist for teams building on hosted models.

By ShajanthanUpdated 8 min read
ByShajanthanFounder & Editor
Published
Reading8 MIN
Flowchart showing how a company using model APIs can be a deployer, an AI system provider, a high-risk provider, or a GPAI model provider under the EU AI Act
In 20 seconds
  1. If you put an API-powered chatbot or tool on the market under your own name, the AI Act generally treats you as the provider of that AI system. The model vendor remains the provider of the general-purpose model.
  2. Duties already live for API builders: Article 50 transparency (AI disclosure, output marking), AI literacy measures, and the prohibited practices. High-risk rules start December 2, 2027.
  3. You become a GPAI model provider yourself only if your fine-tuning uses more than one-third of the original model's training compute, according to the Commission's guidelines.
Contents

Many teams assume the EU AI Act is a problem for OpenAI, Anthropic, Google and Mistral, not for the companies that call their APIs. That is only partly right. The heaviest obligations on general-purpose AI (GPAI) models do fall on the model vendors. But once you ship a product built on those models, the Act gives you a role, and since August 2, 2026 some of that role's duties are enforceable. This explainer covers how the roles work, which duties apply to API builders as of October 8, 2026, and when you could be reclassified as something heavier. For the full timeline, start with what the AI Act requires right now.

This is an explainer, not legal advice. Article 50 and the role definitions are being interpreted for the first time; get counsel for anything high-stakes.

The four roles you might hold

The Act assigns obligations by role. The definitions are in Article 3:

  • Provider (Art. 3(3)): anyone who develops an AI system or a GPAI model, or has one developed, and places it on the market or puts it into service under its own name or trademark, whether paid or free.
  • Deployer (Art. 3(4)): anyone who uses an AI system under its authority, other than for purely personal, non-professional use.
  • Putting into service (Art. 3(11)): supplying an AI system for first use, either to a deployer or for the provider's own use. A tool you build only for your own staff can still make you its provider.
  • GPAI model provider: the company that trained the underlying model, or that changed it substantially (see below).

The Act separates the model from the AI system. When you call a model through an API and wrap it in your own product, the model vendor remains the GPAI model provider. Our reading of Article 3 is that you are the provider of the AI system you built: your support bot, your writing assistant, your agent. If you simply buy and use a vendor's finished product, such as a hosted enterprise chatbot, you are a deployer of that product.

This distinction drives most of what follows.

What applies to you today

Last verified: October 8, 2026

1. Transparency under Article 50 (since August 2, 2026)

Article 50 is the duty most API builders will actually touch:

  • Tell people they're talking to an AI (providers, 50(1)). If your system interacts directly with people, it must be designed so they are told, unless it's obvious to a reasonably well-informed person. The Commission's Article 50 guidelines, published July 20, 2026, expect the disclosure to be built into the product at the first interaction. According to a Stephenson Harwood summary, that can mean a notice at the start of a session, a persistent badge or a spoken statement. A generic "assistant" label or a line in your terms and conditions is not enough, and AI agents should disclose on whose behalf they act.
  • Mark generated content (providers, 50(2)). Providers of systems that generate text, images, audio or video must ensure outputs are marked in a machine-readable way. According to the same summary, if your product is built on an API, the guidelines let you rely on marking built in at the model level by the upstream vendor, but you must be able to show that it works. Systems already on the EU market before August 2, 2026 have until December 2, 2026 for this duty. The AI Omnibus added that grace period.
  • Label deepfakes and public-interest text (deployers, 50(4)). If you publish AI-generated or manipulated images, audio or video resembling real people, places or events, you must disclose it. The same applies to AI-generated text published to inform the public on matters of public interest, unless a human reviewed it and someone holds editorial responsibility.
  • Emotion recognition and biometric categorisation (deployers, 50(3)). If you use these, you must tell the people exposed to them.

All of these disclosures must be "clear and distinguishable" and given no later than the first interaction or exposure (50(5)).

What the vendors are doing. On October 5, 2026, OpenAI said its text watermark is off by default in the API. Customers anywhere can opt in for select models, while EU ChatGPT and Codex output gets watermarking over the following weeks. If your product generates text for EU users through OpenAI's API, opting in is how you get the model-level marking. Check what your own vendor offers. Our news story on the marking rollout covers the latest. The Commission published a voluntary Code of Practice on marking and labelling AI-generated content on June 10, 2026.

2. AI literacy under Article 4 (since February 2, 2025, softened in 2026)

Providers and deployers must take measures to support AI literacy among staff and contractors who operate or use AI systems for them. The AI Omnibus (Regulation (EU) 2026/1744, in force July 27, 2026) replaced the original wording, which asked companies to ensure "to their best extent" a sufficient level of literacy. The new text says no one has to guarantee a specific level for any individual. In practice: train the people who use or build with AI, and keep a record of what you did.

3. Prohibited practices under Article 5 (since February 2, 2025)

These apply to everyone. Building any of them on a vendor's API does not shift responsibility to the vendor. The list in Article 5 includes:

  • manipulative or deceptive techniques that cause significant harm;
  • exploiting vulnerabilities linked to age, disability or social and economic situation;
  • social scoring;
  • predicting criminality solely from profiling;
  • untargeted scraping of facial images;
  • emotion recognition in workplaces and schools, except for medical or safety reasons;
  • biometric categorisation that infers sensitive traits;
  • most real-time remote biometric identification in public spaces for law enforcement.

From December 2, 2026, the Omnibus adds bans on AI systems that generate non-consensual intimate imagery of identifiable people or child sexual abuse material. If your product lets users generate images or video, check your safeguards before then.

When you become a high-risk provider

Most chatbots, coding tools and writing assistants are not high-risk. A use case is high-risk when it falls into one of the eight Annex III areas: biometrics, critical infrastructure, education, employment (CV screening, worker monitoring), essential services (credit scoring, life and health insurance pricing), law enforcement, migration and border control, and justice and democratic processes.

Article 25(1) says a deployer or other third party becomes the provider of a high-risk system if it:

  1. puts its name or trademark on a high-risk system already on the market;
  2. makes a substantial modification to such a system; or
  3. modifies the intended purpose of an AI system, including a general-purpose one, so that it becomes high-risk.

The third point is the trap for API builders. Wire a general-purpose model into a tool that ranks job applicants or scores loan applications, and you are the provider of a high-risk AI system. The obligations include risk management, data governance, technical documentation, logging, human oversight, a conformity assessment and registration. Since the Omnibus, those obligations apply from December 2, 2027. That is extra time, not an exemption.

When fine-tuning makes you a model provider

Calling an API, prompt engineering, RAG and light fine-tuning do not make you a GPAI model provider. According to summaries by WilmerHale and Slaughter and May of the Commission's July 18, 2025 GPAI guidelines, a downstream modifier becomes a provider of the modified model only when the modification uses more than one-third of the original model's training compute. If that figure isn't known, the fallback is one-third of 10^23 FLOP, or one-third of 10^25 FLOP if the original model carries systemic risk.

A fine-tuning job run through a vendor's API typically uses a small fraction of the compute that went into the original model, so crossing one-third of it is unlikely. Still, record what you use. The calculation looks different if you take open weights and do large-scale continued pre-training. For that path, see our comparison of frontier APIs and open models and the license terms you'd be bound by.

What to get from your model vendor

GPAI providers must give downstream companies documentation that helps them meet their own obligations (Article 53(1)(b), with the minimum contents listed in Annex XII). Ask for:

  • Model documentation covering capabilities, limitations and intended uses. Many vendors publish model or system cards; check them against Annex XII.
  • Marking support: whether outputs are watermarked or carry metadata, whether it's on by default, and how to turn it on (for example, OpenAI's opt-in API setting).
  • Code of Practice status: whether the vendor signed the GPAI Code of Practice, which the Commission treats as an adequate way to show compliance. As of the Commission's October 7, 2026 update (unchanged on October 9), the list included Amazon, Anthropic, Google, IBM, Microsoft, Mistral AI and OpenAI; xAI (now publishing as SpaceXAI) had signed only the safety chapter. See our AI Act timeline explainer for the full list.
  • Your contract and DPA: the data processing agreement covers GDPR, not the AI Act. Check whether the vendor's terms include AI Act-specific commitments such as documentation, incident cooperation or acceptable-use restrictions that affect your use case. We did not review individual vendors' contract terms for this article.

A practical checklist

Last verified: October 8, 2026

  1. Inventory every AI feature you ship or use internally. For each one, note the model vendor, whether EU users are affected, and your role (provider of the system, deployer, or both).
  2. Screen for prohibited uses, including the December 2, 2026 additions if you generate images or video.
  3. Screen for Annex III use cases. If any match, plan for high-risk compliance by December 2, 2027.
  4. Add AI disclosure to chatbots, voice agents and autonomous agents at first interaction. A line in your terms of service is not enough.
  5. Turn on output marking, or confirm the vendor already applies it, for generated text, images, audio and video served to EU users. Systems already on the market have until December 2, 2026.
  6. Label deepfakes and unreviewed public-interest text if you publish them.
  7. Run AI literacy training for staff who build with or use AI, and keep a record of it.
  8. Collect vendor documentation (Article 53(1)(b)) and record each vendor's Code of Practice status.
  9. Track your fine-tuning compute if you modify open-weight models at scale.
  10. Re-check in 2027. Guidance and standards for high-risk systems are still being written.

What's confirmed and what isn't

Confirmed: the role definitions, Article 50 and Article 25 wording, and the August 2, 2026, December 2, 2026 and December 2, 2027 dates, all from official texts.

Interpretation: that an API-wrapping product makes you the provider of an AI system is our reading of Article 3. Commission guidance quoted in this article doesn't state it in those words, and no regulator has yet applied it in an enforcement decision.

Second-hand: the details of the Article 50 guidelines and the one-third compute rule come from law-firm summaries of Commission documents. We cite them as such.

Penalties for breaching Article 50 or other operator duties can reach €15 million or 3% of worldwide turnover under Article 99. For SMEs and, since the AI Omnibus, small mid-caps, the lower of those two figures applies.

About this storyBased on the sources linked below. Editorial standards

Was this useful?Report an error
Comments
0

More on EU AI Act & policy

The Week in AI

New guides and explainers, every Friday.

0