💻 AI rules: Software and IT services
If you build or resell AI, you are a provider, importer or distributor — with duties depending on risk — and your software now falls under the CRA and product liability.
Typical AI uses and their risk level
Say it is AI; mark generated content machine-readably if you provide generation.
You are the provider of a high-risk system: full requirements from 2 Dec 2027.
Minimal; keep secrets out of prompts; check licences.
Transparency for end users; DPA with your client.
What to do
- Classify every AI feature by AI Act risk and document it.
- Set up CRA vulnerability handling and ENISA reporting.
- Contract: roles (provider/deployer), liability, model supplier terms, data use.
- Offer customers documentation they need as deployers.
Common pitfalls
- Free and open-source components are partly exempt, but your commercial product built on them is not.
Examples
The agency (or the bank, if under its name) is the provider of the AI system; OpenAI is the model provider. Transparency, testing and a DPA chain are needed.
Rules that apply
Applies to anyone who develops AI (provider), uses AI in their business (deployer), imports or distributes it in the EU — also to companies outside the EU if the output is used in the EU. Private, non-professional use is excluded.
Applies in phasesCyber Resilience ActAI software and devices with AI are products with digital elements. A high-risk AI system that meets the CRA’s essential requirements is presumed to meet the AI Act’s cybersecurity requirement.
Coming soonProduct Liability DirectiveIf an AI product causes injury, damage to property or loss of data, the injured person can claim compensation without proving fault. A substantial modification (e.g. retraining or an update) can make you a manufacturer.
In forceGDPRFor most companies GDPR matters more than the AI Act: it decides whether you may put customer or employee data into an AI tool at all. In Slovenia it is supplemented by ZVOP-2 and supervised by the Information Commissioner.
In forceCopyright and AIProviders of general-purpose AI models must have a copyright policy that respects opt-outs and publish a summary of training content (AI Act, Art. 53). Pure AI output without human creative input is generally not protected by copyright.
In forceNIS2AI tools and AI suppliers are part of your ICT supply chain: include them in risk analysis, access control and incident response — e.g. what happens if staff paste confidential data into an external AI.
General information, not legal advice — consult a lawyer for borderline cases. Regulations reviewed on 29 Sep 2026.