AI Act実務ガイド

EUでAIサービスを提供する企業向けガイド

EU顧客にAIシステムまたはAI機能付きサービスを提供するプロバイダー、SaaS企業、モデル利用事業者、マーケットプレイス、EU域外チーム向けの実務的な導入ページです。

Provider role High-risk screening EU market access Article 22 representative trigger

Start here

The first question is not "Do we need an AR?" It is "What role do we play?"

The EU AI Act applies differently depending on whether you are the provider of an AI system, a deployer using it in your organisation, an importer, a distributor, a product manufacturer, or a general-purpose AI model provider. A company selling AI services in the EU can hold more than one role in practice.

For lead qualification, the important first step is to identify who controls the AI system, who places it on the EU market, who makes substantial modifications and who is named toward EU customers.

1. Identify your EU AI Act role

Common roles for AI service businesses

Provider

You develop or have an AI system developed and place it on the market or put it into service under your name or trademark.

Deployer

You use an AI system under your authority in a professional context, for example in HR, education, credit or customer decision workflows.

Importer or distributor

You make a third-country AI system available in the EU supply chain and may have checks before offering it to customers.

2. Screen whether the system is high-risk

High-risk status drives the most important compliance route

Many AI services are not high-risk. But if your system is used in areas such as employment, education, essential private or public services, biometrics, migration, law enforcement or justice, you should perform a structured Annex III screening.

Employment and HR

Recruitment, candidate ranking, employee monitoring, performance evaluation and work allocation tools can raise high-risk questions.

Education

Admission, assessment, access to education or training and student evaluation use cases need careful classification.

重要サービス

Credit, insurance, access to public benefits, emergency services and similar decisions may require a stricter route.

Open the high-risk AI overview →

3. Build the evidence file early

Even before final obligations apply, buyers will ask for evidence

EU customers often ask AI vendors for documentation earlier than the legal deadline because procurement, risk management and supplier onboarding already need answers. Prepare a practical evidence package before enterprise sales conversations.

System description

What the AI system does, intended users, intended purpose, EU customer types and supported decisions.

Risk classification

Why the system is or is not high-risk, including Annex III reasoning and product-regulation links where relevant.

Governance contacts

Who owns compliance, incident handling, customer communication and regulatory responses.

4. Know when an EU authorised representative becomes relevant

Article 22 is mainly a trigger for non-EU providers of high-risk AI systems

If the provider is established outside the EU and provides a high-risk AI system into the Union, Article 22 may require an authorised representative established in the EU. The AR is appointed by written mandate and acts as the EU point of contact for competent authorities.

QuestionWhy it matters
Is the provider established outside the EU?Article 22 targets third-country providers of high-risk systems entering the Union market.
Is the AI system high-risk?Representative obligations are tied to high-risk AI systems, not every AI tool.
Will the system be placed on the market or put into service in the EU?The EU market route determines whether an EU representative contact point is needed.

5. Understand timing

2 December 2027 is important, but procurement pressure starts earlier

For Annex III high-risk AI systems, core Chapter III obligations are expected to apply from 2 December 2027 after Regulation (EU) 2026/1744. That date is not a reason to wait. Classification, documentation, customer evidence, governance and representative planning take time.

1

Now

Map AI systems, EU customers, intended use and provider/deployer roles.

2

Before procurement

Prepare risk classification and a concise evidence pack for EU buyers.

3

Before EU launch

Confirm whether a high-risk route, conformity evidence and 第22条AR are needed.

4

After launch

Maintain records, monitoring, incident workflows and authority response channels.

Practical checklist

Information to collect before asking for help

  • Provider legal entity and country of establishment.
  • AI system name, intended purpose and target EU users.
  • Whether the system affects employment, education, essential services, biometrics or other Annex III areas.
  • Whether EU customers already requested AI Act evidence.
  • Whether technical documentation or conformity work has started.
  • Whether an importer, distributor or EU customer is involved in the route to market.

FAQ

Common questions from AI service providers

Does every AI service offered in the EU need an authorised representative?

No. The Article 22 representative route is primarily relevant for non-EU providers of high-risk AI systems.

Can a SaaS provider be a provider under the AI Act?

Yes, if the company places the AI system on the market or puts it into service under its name or trademark. The details matter.

Is general-purpose AI treated the same way?

General-purpose AI models have separate obligations and may involve different representative triggers. This guide focuses on AI systems and high-risk market access triage.

What should we do if a buyer asks for AI Act evidence?

Prepare a concise classification note, role analysis, documentation status and responsible contact. If you are a non-EU high-risk provider, also confirm the Article 22 representative route.

Check your EU AI Act route

Tell us where the provider is established, what the AI system does, and whether Annex III may apply. We will qualify whether an Article 22 representative discussion is relevant.

無料の該当性チェック