BeaconAI Act
Back to lucarimediotti.com
AI Act · Reg. (EU) 2024/1689 · applicable from 2 August 2026

Does the AI Act apply to you?

Ten questions plus a page scan: it defines your perimeter, lists the obligations already in force and the deadlines. It matters from Switzerland too — art. 2(1)(c) reaches providers outside the EU whenever the system's output is used in the Union.

The address is used to look for chatbots, provenance markers and EU market signals on the page. Without it, the assessment uses only your answers.

Only the first two questions are mandatory, but an unanswered question is read as "no": answer them all for a complete perimeter.

Do you sell, offer services or have users in the European Union?

The indirect case counts too: if the AI system's output is used in the EU, the regulation applies anyway (art. 2(1)(c)).

What it means · examples

The AI Act does not look at where you are established, but at where the system's output ends up. A Swiss company with no EU branch is still covered if the output — the reply to a customer, the quote, the shortlist of candidates, the published text — is used in the EU. That is why this comes first: on its own it decides half of the verdict.

  • A Lugano firm sending an Italian company a quote prepared with AI → Yes: the output is used in the Union
  • Online shop with euro prices and Europe-wide shipping → Yes
  • Restaurant with an Italian-language chatbot, local customers, no sales abroad → No, Switzerland only
  • You don't know where your client's end customers are → Don't know: the most frequent case, and the tool treats it as "probably in scope" rather than letting you off
What is your role with respect to AI systems?

Deployer = you use an AI system under your own authority. Provider = you develop it or place it on the market under your name, even if the model is someone else's.

What it means · examples

This is the most misunderstood distinction in the regulation, and the heaviest: providers owe technical documentation, risk management and system conformity; deployers owe correct use, human oversight and transparency towards people. The line is not technical but about responsibility: whose name is on the system offered to others. Watch art. 25: put your brand on someone else's system, or change its intended purpose, and you become the provider.

  • You put a subscription chatbot on your site → I use it (deployer): the provider is whoever sells it to you
  • You call a model's API inside your own software, to work better yourself → I use it (deployer)
  • You package an assistant for your customers and offer it under your own brand → Provider, even if the underlying model is someone else's (art. 25)
  • You use AI in-house and also sell customers a tool of your own that embeds it → Both: the obligations add up, you do not pick one
Does an AI system interact directly with people?

Chatbot, voice assistant, automated answering on the site or by phone.

What it means · examples

This is about systems that address a person directly, not automation in general. If yes, art. 50(1) requires the person to know they are talking to a machine — at first contact and inside the widget itself, not in a line of the privacy policy. The only exception is when it is obvious to anyone: a button labelled "automated assistant" needs no further notice.

  • Support chatbot in the bottom-right corner of the site → Yes
  • Phone assistant that understands sentences and books appointments → Yes
  • Contact form sending an automatic confirmation email → No: that is automation, not an AI system holding a conversation
  • Chatbot introducing itself with a human name and never saying it is a bot → Yes, and precisely the case art. 50(1) exists to prevent
Do you publish text, images, audio or video generated with AI?

Partly generated or modified counts too.

What it means · examples

Generation counts, retouching does not: fixing the light and colour of your own photo is not synthetic content, having the image produced from nothing is. A yes triggers two distinct obligations that are often confused: machine-readable marking (art. 50(2), metadata in the file) and informing the audience (art. 50(4), the person reading or watching).

  • Blog cover images generated with Midjourney or DALL·E → Yes
  • Articles written by AI and then reworked → Yes (review counts for art. 50(4) subpara. 2, it does not exempt you from (2))
  • Your own photographs with exposure and colour corrected → No: correction is not generation
  • Automatically generated subtitles or voice-over → Yes
Do you develop or place on the market a general-purpose AI model?

Training or distributing your own model. Using GPT or Claude through an API does not make you the model's provider.

What it means · examples

General-purpose model obligations (art. 53-55: technical documentation, training-data summary, copyright compliance) fall on whoever places the model on the market, not on whoever uses it. Calling an API is use: the model provider is the party that trained and distributes it. In practice almost every SME answers no here.

  • You call the GPT, Claude or Gemini API from your software → No: the model provider is whoever trained it
  • You publish a model you trained on Hugging Face → Yes
  • You substantially fine-tune a model and distribute it → Yes, for the part you modified
  • You install an open-source model on your own server for internal use → No
Are there people using AI on behalf of your organisation?

Employees, contractors, agencies. This triggers the AI literacy duty (art. 4), already applicable.

What it means · examples

The most underestimated obligation and the only one applicable since 2 February 2025. It asks for neither certified courses nor budget: it asks that whoever uses AI for the organisation knows what they may and may not do, with training proportionate to the context. Written instructions, examples of mistakes to avoid, a person to ask: for a small business that already counts as compliance, provided it is documented.

  • Staff use ChatGPT to draft emails to customers → Yes
  • The agency running your social accounts writes copy with AI → Yes: it acts on your behalf
  • You use machine translation for documents you then send to customers → Yes
  • You work alone and you are the only AI user → Yes: the obligation still exists, but scaled to one person
Does AI take part in any of these decisions about people?

Multiple choice. If none apply, pick "None of these": it tells a no apart from a skipped question.

What it means · examples

These are the Annex III high-risk uses: cases where an automated decision affects access to employment, credit, education, essential services or fundamental rights. The obligations (risk management, data quality, human oversight, logging) are the heaviest in the regulation and start in 2027-2028: the point of asking now is that compliance takes months, not weeks. It is enough that the AI prepares or influences the decision — it need not decide alone.

  • Software that ranks or filters incoming CVs, even just for a first pass → Recruitment
  • Automated score deciding who may pay in instalments → Creditworthiness
  • Face recognition for entry to the premises → Biometric identification
  • Chatbot answering about opening hours, prices and availability → None of these
Does the system do any of these?

Practices prohibited by art. 5, banned since 2 February 2025. Multiple choice: if you do none of them, pick "None of these".

What it means · examples

There is no compliance path here: the art. 5 practices have been prohibited since 2 February 2025, and a system doing one of them must be stopped, not brought into line. For a commercial business the normal answer is none. Two clarifications: the emotion-recognition ban covers the workplace and education and has narrow exceptions on medical or safety grounds; untargeted scraping of faces is prohibited even where the images are public.

  • Software inferring employees' mood or attention from camera footage → Emotion recognition at work
  • A general score on people, built from behaviour unrelated to the service, used to treat them differently → Social scoring
  • An archive of faces scraped from the internet or CCTV to build a recognition database → Untargeted scraping of faces
  • None of the above → None of these: the expected answer in the vast majority of cases