AI for business · Industry guide

💻 AI rules: Software and IT services

If you build or resell AI, you are a provider, importer or distributor — with duties depending on risk — and your software now falls under the CRA and product liability.

Typical AI uses and their risk level

Transparency
A SaaS with a built-in AI assistant

Say it is AI; mark generated content machine-readably if you provide generation.

High risk
HR, credit or education software with AI decisions

You are the provider of a high-risk system: full requirements from 2 Dec 2027.

Minimal
Developers using coding assistants

Minimal; keep secrets out of prompts; check licences.

Minimal
RAG chatbot over a client’s documents

Transparency for end users; DPA with your client.

What to do

  • Classify every AI feature by AI Act risk and document it.
  • Set up CRA vulnerability handling and ENISA reporting.
  • Contract: roles (provider/deployer), liability, model supplier terms, data use.
  • Offer customers documentation they need as deployers.

Common pitfalls

  • Free and open-source components are partly exempt, but your commercial product built on them is not.

Examples

A Slovenian agency builds a chatbot for a bank on top of GPT

The agency (or the bank, if under its name) is the provider of the AI system; OpenAI is the model provider. Transparency, testing and a DPA chain are needed.

General information, not legal advice — consult a lawyer for borderline cases. Regulations reviewed on 29 Sep 2026.