Software publishers · AI Act

Software publishers & AI Act: provider obligations

As soon as a software publisher develops or integrates an AI system placed on the market under its own brand, it becomes a provider within the meaning of the AI Act and bears the most demanding obligations under the regulation. Their intensity depends on the risk level of the system. This guide clarifies the qualification as a provider, the obligations by risk level, the regime for general-purpose models, and the implementation timeline.

DPO / CISO team — Data Comply One Updated on 15 June 2026

In brief

  • Regulation: AI Act.
  • Any publisher who markets an AI system under their own brand is a provider.
  • Classify the system.
  • Building the technical documentation.
  • Implementing a quality management system.
  • Up to €35M or 7% of global turnover for prohibited practices, €15M or 3% for failures to meet high-risk system obligations, and €7.5M or 1% for providing inaccurate information to authorities.

Regulatory deadlines

The key dates of this regulation.

August 2024

Entry into force

In force

February 2025

Ban on prohibited practices

In force

August 2025

General-purpose AI models (GPAI) & governance

In force

August 2026

High-risk system obligations (Annex III)

In force

August 2027

High-risk embedded in products (Annex I)

Upcoming

What does the AI Act cover?

The AI Act classifies systems as unacceptable risk, high risk, limited risk and minimal risk, and distinguishes between provider, deployer, importer and distributor. The provider is the party that develops the system, or has it developed, in order to place it on the market under their name.

High-risk systems include in particular those whose use is listed in Annex III (biometrics, employment, access to essential services, etc.) or that constitute a safety component of a regulated product.

Is the 'Software Publishers' sector concerned?

Any publisher that markets an AI system under its own brand is a provider. A publisher that merely integrates a third-party AI service without modifying it may only be a deployer — but it can also be reclassified as a provider if it substantially modifies the system or places it under its own brand.

General-purpose AI models integrated into the product additionally trigger specific documentation and transparency obligations, reinforced for models presenting systemic risk.

Detailed obligations

Classify the system

Determine the risk level (prohibited, high, limited, minimal), as it governs all applicable obligations.

Establish the technical documentation

Develop the Annex IV documentation: system description, training data, architecture, performance, risk management measures.

Implement a quality management system

Establish a quality and risk management system covering the entire AI system lifecycle.

Ensuring transparency and oversight.

Design the system to enable effective human oversight and inform users of its capabilities and limitations.

Assess compliance and mark

Carry out the required conformity assessment and affix the marking attesting compliance with the regulation.

Monitoring after market placement.

Implement post-market surveillance and a mechanism for reporting and handling serious incidents.

Sanctions & risks

Up to €35M or 7% of global turnover for prohibited practices, €15M or 3% for failures to meet high-risk system obligations, and €7.5M or 1% for providing inaccurate information to authorities.

For a vendor-publisher, the greatest risk is misclassifying a high-risk system: it exposes them both to sanctions and to product withdrawal from the market.

Application timeline

  • 1Entry into force. 1 August 2024.
  • 2Prohibited practices. Since 2 February 2025.
  • 3General-purpose AI models (GPAI). From 2 August 2025.
  • 4High-risk systems. From 2 August 2026, and 2027 for certain systems embedded in regulated products.

Common mistakes in the sector

  • 1Underestimated status. Believing you are a mere deployer when you affix the system under your own brand or substantially modify it.
  • 2Missing documentation. Not having the technical documentation required by Annex IV.
  • 3No post-market. Omitting post-market surveillance and incident handling.
  • 4GPAI ignored. Integrating a general-purpose model without addressing its own obligations.

Practical case

A software publisher integrates a language model to generate summaries and adds a module that automatically scores application files. The scoring module, listed as a high-risk use case, requires technical documentation, risk management and human oversight, while the summary function falls under limited risk. The publisher segments its obligations by feature rather than by entire product.

Compliance roadmap

  1. 1

    Inventory. Inventory all AI components of the product and their provenance.

  2. 2

    Qualify. Determine the risk level and status (provider or deployer) of each one.

  3. 3

    Document. Building the technical documentation (Annex IV) and the quality management system.

  4. 4

    Governing usage. Implement transparency, human oversight and a usage notice.

  5. 5

    Monitor. Organise post-market surveillance and incident handling.

Frequently asked questions

As soon as it places the system on the market under its own brand, develops it for market placement, or substantially modifies it. The mere use of an unmodified third-party service falls under the deployer.

Take action on AI Act

Free assessment or a chat with an expert dedicated to software publishers.

They already trust us

See how organisations in the software publishers sector secured their compliance with DCO.

See testimonials