If you develop an AI system that is available in the EU, you have legally binding obligations under the EU AI Act. These obligations apply whether you are a sole developer at home or a multi million dollar corporation. They apply whether you run a local model or rely on a service provided by a large company.
If you build it, adapt it, fine tune it or make it available to others, you are a provider under the Act. This page explains what you must do to stay compliant.
The obligations are the same whether you are a sole developer or a large corporation. The Act assigns responsibility based on what you deploy, not who you are.
You are a provider if you:
If EU users can reach your system, you are in scope.
You must produce documentation that explains what the system does, how it works, what data it uses, what risks it creates and how those risks are controlled. This documentation must be complete enough for regulators to understand and audit your system.
You must ensure that your training data is relevant, representative and appropriate. You must document data sources, manage data quality and track known limitations. Poor or undocumented data is a compliance failure.
You must test your system before release, and the EU AI Act expects this testing to reflect how the system will be used in real conditions. Testing means full behavioural evaluation, not one off prompt checks or isolated examples.
Your system must be tested as it would be used by real users, in real workflows, under real load.
If you cannot show evidence of full behavioural testing, you are non compliant.
You must keep logs that allow regulators to understand how the system was used, trace decisions and investigate incidents. Missing logs is a direct violation.
You must provide clear information to users about what the system does, how to use it safely, what its limitations are and when they are interacting with AI.
You must design your system so that humans can understand its outputs, intervene when needed and override decisions. If your system cannot be supervised, it cannot be deployed in high risk contexts.
You must ensure your system is protected against tampering, model extraction, data poisoning and adversarial inputs. Weak security is a compliance failure.
After release, you must monitor the system, track incidents, update documentation, fix emerging risks and report serious incidents to regulators. Compliance does not end at launch.
These obligations are enforceable. If you miss documentation, skip testing, fail to log or ignore risks, you can be fined even if no harm occurs. The Act expects developers to take responsibility for the systems they create, regardless of scale.
For further resources on checking your liability, getting started with compliance and testing your AI systems, go to the Inquisitor Labs EU AI Act hub on Leanpub. You will find:
These resources give you a clear starting point for understanding your obligations, reducing your exposure under the Act and evaluating your AI systems in real conditions.
Get Compliant Now(C) William Argo