In brief
- Regulation: AI Act.
- Any publisher who markets an AI system under their own brand is a provider.
- Classify the system.
- Building the technical documentation.
- Implementing a quality management system.
- Up to €35M or 7% of global turnover for prohibited practices, €15M or 3% for failures to meet high-risk system obligations, and €7.5M or 1% for providing inaccurate information to authorities.
Regulatory deadlines
The key dates of this regulation.
August 2024
Entry into force
In forceFebruary 2025
Ban on prohibited practices
In forceAugust 2025
General-purpose AI models (GPAI) & governance
In forceAugust 2026
High-risk system obligations (Annex III)
In forceAugust 2027
High-risk embedded in products (Annex I)
UpcomingWhat does the AI Act cover?
The AI Act classifies systems as unacceptable risk, high risk, limited risk and minimal risk, and distinguishes between provider, deployer, importer and distributor. The provider is the party that develops the system, or has it developed, in order to place it on the market under their name.
High-risk systems include in particular those whose use is listed in Annex III (biometrics, employment, access to essential services, etc.) or that constitute a safety component of a regulated product.
Is the 'Software Publishers' sector concerned?
Any publisher that markets an AI system under its own brand is a provider. A publisher that merely integrates a third-party AI service without modifying it may only be a deployer — but it can also be reclassified as a provider if it substantially modifies the system or places it under its own brand.
General-purpose AI models integrated into the product additionally trigger specific documentation and transparency obligations, reinforced for models presenting systemic risk.
Detailed obligations
Classify the system
Determine the risk level (prohibited, high, limited, minimal), as it governs all applicable obligations.
Establish the technical documentation
Develop the Annex IV documentation: system description, training data, architecture, performance, risk management measures.
Implement a quality management system
Establish a quality and risk management system covering the entire AI system lifecycle.
Ensuring transparency and oversight.
Design the system to enable effective human oversight and inform users of its capabilities and limitations.
Assess compliance and mark
Carry out the required conformity assessment and affix the marking attesting compliance with the regulation.
Monitoring after market placement.
Implement post-market surveillance and a mechanism for reporting and handling serious incidents.
Sanctions & risks
Up to €35M or 7% of global turnover for prohibited practices, €15M or 3% for failures to meet high-risk system obligations, and €7.5M or 1% for providing inaccurate information to authorities.
For a vendor-publisher, the greatest risk is misclassifying a high-risk system: it exposes them both to sanctions and to product withdrawal from the market.
Application timeline
- 1Entry into force. 1 August 2024.
- 2Prohibited practices. Since 2 February 2025.
- 3General-purpose AI models (GPAI). From 2 August 2025.
- 4High-risk systems. From 2 August 2026, and 2027 for certain systems embedded in regulated products.
Common mistakes in the sector
- 1Underestimated status. Believing you are a mere deployer when you affix the system under your own brand or substantially modify it.
- 2Missing documentation. Not having the technical documentation required by Annex IV.
- 3No post-market. Omitting post-market surveillance and incident handling.
- 4GPAI ignored. Integrating a general-purpose model without addressing its own obligations.
Practical case
A software publisher integrates a language model to generate summaries and adds a module that automatically scores application files. The scoring module, listed as a high-risk use case, requires technical documentation, risk management and human oversight, while the summary function falls under limited risk. The publisher segments its obligations by feature rather than by entire product.
Compliance roadmap
- 1
Inventory. Inventory all AI components of the product and their provenance.
- 2
Qualify. Determine the risk level and status (provider or deployer) of each one.
- 3
Document. Building the technical documentation (Annex IV) and the quality management system.
- 4
Governing usage. Implement transparency, human oversight and a usage notice.
- 5
Monitor. Organise post-market surveillance and incident handling.
Frequently asked questions
As soon as it places the system on the market under its own brand, develops it for market placement, or substantially modifies it. The mere use of an unmodified third-party service falls under the deployer.
Take action on AI Act
Free assessment or a chat with an expert dedicated to software publishers.
They already trust us
See how organisations in the software publishers sector secured their compliance with DCO.