← Course outline
Aavistus Training · ai-act · AIA.01

Scope, definitions and AI literacy

What you'll learn

What the AI Act regulates and for whom: subject matter and objectives; scope and exclusions (military, research, open-source carve-outs); the definition of an AI system and of the operator roles (provider, deployer, importer, distributor); the AI-literacy duty on providers and deployers.

Regulation — cited to the current EU text

Subject matter and objectives

The EU AI Act's stated purpose is to improve the functioning of the internal market and promote human-centric and trustworthy AI, while ensuring a high level of protection of health, safety, and fundamental rights enshrined in the Charter, including democracy, the rule of law and environmental protection, against harmful AI effects, and supporting innovation 32024R1689 Article 1@2024-06-13. Practically, this translates into seven distinct bodies of rules: harmonised rules for placing AI systems on the market, putting them into service, and their use in the Union; prohibitions on certain AI practices; requirements for high-risk AI systems and related operator obligations; transparency rules for certain AI systems; harmonised rules for the placing on the market of general-purpose AI models (GPAI); market monitoring, market surveillance, governance and enforcement frameworks; and measures to support innovation, with a particular focus on SMEs, including start-ups 32024R1689 Article 1@2024-06-13.

Territorial scope

The Regulation's reach is deliberately extraterritorial. It applies to providers placing on the market or putting into service AI systems, or placing on the market general-purpose AI models, in the Union, regardless of where they are established 32024R1689 Article 2@2024-06-13. Deployers are covered if they have their place of establishment or location in the Union 32024R1689 Article 2@2024-06-13. Third-country providers and deployers fall within scope where the AI system's output is used in the Union 32024R1689 Article 2@2024-06-13. Importers, distributors, product manufacturers placing on the market or putting into service an AI system together with their product and under their own name or trademark, and authorised representatives of non-Union providers are also covered 32024R1689 Article 2@2024-06-13.

Natural persons using AI in the course of a purely personal, non-professional activity are not subject to deployer obligations 32024R1689 Article 2@2024-06-13.

Exclusions

Three carve-outs are frequently tested in compliance analysis:

Military and national security. The Regulation does not apply to AI systems where and in so far as they are placed on the market, put into service, or used, with or without modification, exclusively for military, defence, or national security purposes, regardless of which type of entity carries out those activities 32024R1689 Article 2@2024-06-13. Member State competences in national security are expressly preserved 32024R1689 Article 2@2024-06-13.

Scientific research and pre-market development. AI systems or models developed and put into service solely for scientific research and development are excluded 32024R1689 Article 2@2024-06-13. Research, testing, or development activities prior to placement on the market or putting into service are likewise outside scope — but testing in real-world conditions is not covered by that exclusion and remains in scope 32024R1689 Article 2@2024-06-13.

Open-source. AI systems released under free and open-source licences fall outside the Regulation unless they are placed on the market or put into service as high-risk AI systems or fall under the prohibited practices or transparency provisions of Articles 5 or 50 32024R1689 Article 2@2024-06-13.

Definition of an AI system

The Act defines an AI system as "a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments" 32024R1689 Article 3@2024-06-13.

Two elements are analytically critical. First, the inference-from-input characteristic distinguishes AI systems from deterministic rule-based software, which transforms inputs by fixed logic rather than by learned inference. Second, the requirement that outputs can influence physical or virtual environments grounds the definition in real-world consequence rather than mere computation.

Operator roles

The Regulation distributes obligations across a structured supply chain. The umbrella term operator covers all of the following roles 32024R1689 Article 3@2024-06-13:

| Role | Core definition | |---|---| | Provider | Develops or has developed an AI system or a general-purpose AI model and places it on the market or puts it into service under its own name or trademark, for payment or free of charge 32024R1689 Article 3@2024-06-13 | | Deployer | Uses an AI system under its own authority, other than where the AI system is used in the course of a personal non-professional activity 32024R1689 Article 3@2024-06-13 | | Product manufacturer | Places on the market or puts into service an AI system together with their product and under their own name or trademark 32024R1689 Article 2@2024-06-13 | | Importer | Located or established in the Union; places on the market an AI system bearing the name or trademark of a non-Union natural or legal person 32024R1689 Article 3@2024-06-13 | | Distributor | Any other supply-chain actor, other than the provider or importer, that makes an AI system available on the Union market 32024R1689 Article 3@2024-06-13 | | Authorised representative | Located or established in the Union; holds a written mandate from a non-Union provider to carry out the Regulation's obligations on its behalf 32024R1689 Article 3@2024-06-13 |

Role determines obligation. Providers carry the heaviest compliance burden; deployers carry a materially different and narrower set of duties. A single entity can hold multiple roles simultaneously depending on how it positions and uses an AI system.

AI literacy duty

Article 4 imposes a positive obligation on both providers and deployers: they must take measures to ensure, to their best extent, a sufficient level of AI literacy among staff and other persons involved in the operation and use of AI systems on their behalf 32024R1689 Article 4@2024-06-13. What is sufficient is context-sensitive: the calibration must account for each person's technical knowledge, experience, education and training, the context of deployment, and the characteristics of the persons or groups on whom the AI systems are to be used 32024R1689 Article 4@2024-06-13. The duty sits on both sides of the supply chain — the entity that built the system and the entity deploying it each carry their own independent obligation.

Your operations manual

This block connects to your organisation's own AI governance policy. In the full product it shows, cited to your policy, how YOUR organisation implements the regulation above — private to your organisation. (Demo placeholder.)

Real-world context — illustrative only

The following items are labeled illustrative context only; they are not regulatory sources and carry no legal authority.

Training market response to Article 4 CASE-1. Ahead of the August 2026 compliance date, Mintra — a digital learning provider serving safety-critical industries — launched two structured online courses designed to help organisations meet their AI Act obligations CASE-1. This is a direct commercial response to the AI literacy duty: organisations seeking to demonstrate that adequate measures have been taken are turning to documented, structured training as the evidential record. The Mintra offering also illustrates that the duty extends beyond legal and technical staff to any personnel dealing with the operation and use of AI systems.

Synthetic AI performers and the system definition CASE-3. A synthetic AI "actor" engineered to appear in commercial feature films illustrates the breadth of the Article 3(1) definition in practice CASE-3. A system designed to generate audiovisual content outputs — images, voice, performance — on the basis of inputs, for commercial objectives, meets the inference-from-input and output-influencing-virtual-environments criteria squarely. The entity placing such a system on the market under its own name for commercial exploitation would be a provider under the Regulation, regardless of whether the product is marketed as a "digital actor" rather than an "AI system."

Large-scale providers and market placement CASE-2. Analysis of OpenAI's patent portfolio illustrates that major AI developers are actively protecting their AI system architectures through IP filings CASE-2. From an AI Act perspective, an entity placing GPAI models on the Union market — whether via API access, integrated products, or licensing — is a provider subject to the Regulation's scope provisions from the moment of that first making-available, irrespective of commercial framing.

Check your understanding

1. A deployer established outside the EU provides AI services to Union customers exclusively via a website. Under what condition does the EU AI Act bring this deployer within scope?

2. A research consortium releases an AI model under a free and open-source licence. In which situation does the EU AI Act still apply to that model?

3. A developer argues that their software is not an AI system under the Act because every output is produced by a fixed decision tree with no learned parameters. Which element of the statutory definition most directly supports that claim?

4. A university team builds an AI diagnostic tool and runs trials on hospital patients to study its real-world accuracy before any commercial launch. Is this activity covered by the EU AI Act?

5. Under Article 4, which party or parties bear an independent AI literacy obligation toward staff and other persons involved in operating or using AI systems?