By Rafael Luque Ocaña

Does the AI Act even apply to you? Article 2 answers before any classification

If your company is in the EU and uses AI in its operations, the answer is yes — and none of the article's exclusions change that. It's worth knowing what they are, because three of them are almost always cited wrong.

Before classifying anything, there's an earlier question worth answering — and it's the one almost nobody asks explicitly: does the Regulation even apply to me?

It's in Article 2, and it has twelve paragraphs. The first says who it reaches; the remaining eleven, who it doesn't. And among those eleven there are three exclusions that get cited as a free pass, and aren't.

The short answer, for a company in the EU

Article 2(1) lists seven categories of subject. The one that affects you is this:

"(b) deployers of AI systems that have their place of establishment or are located within the Union."

Nothing more. There's no size threshold, no turnover threshold, no sector, no minimum number of systems. If your organisation is in the EU and uses AI under its authority, you're in scope.

One other subject deserves a mention, because it's surprising: letter (c) reaches providers and deployers located in third countries "where the output produced by the AI system is used in the Union". The Regulation doesn't stop at who is here — it extends to what is used here.

The three exclusions that get cited wrong

"It's open source"

Article 2(12) excludes systems released under free and open-source licences. But read it in full:

"…unless they are placed on the market or put into service as high-risk AI systems or as an AI system that falls under Article 5 or 50."

Three exceptions to the exclusion. In other words: an open-source licence doesn't protect you in high risk, doesn't protect you against the prohibited practices, and doesn't protect you against transparency. Exactly the three places where someone would want to rely on it.

And there's a nuance that gets lost: the exclusion looks at how the model is released, not how you use it. If you deploy an open model in a high-risk use case, your obligations as the deploying company are the same as with a closed one.

"It's research"

There are two paragraphs on this, and they shouldn't be mixed up.

2(6) excludes systems and AI models "specifically developed and put into service for the sole purpose of scientific research and development". The word that decides is "sole".

2(8) excludes research, testing or development activity prior to being placed on the market. And it ends with a line that's rarely quoted:

"Testing in real world conditions shall not be covered by that exclusion."

So an internal pilot with real data and real users — which is what almost everyone calls "we're still testing" — is not excluded. The exclusion covers development, not testing against reality.

"Everyone uses it on their own"

2(10) excludes the obligations of deployers "who are natural persons using AI systems in the course of a purely personal non-professional activity".

Two cumulative conditions, and both fail in the case people try to shelter under: someone on your team using an AI tool for their job is not engaged in a personal non-professional activity, and the organisation remains the deployer. The exclusion is for domestic use, not for individual use inside a company.

The exclusions that actually are clean

Two, and a private company doesn't usually get any use out of them.

National security, defence and military purposes — Article 2(3), worded very broadly: "with or without modification exclusively for military, defence or national security purposes, regardless of the type of entity." It also reaches systems whose output is used in the Union for those exclusive purposes.

Public authorities of third countries and international organisations, in the context of law enforcement and judicial cooperation — Article 2(4), subject to conditions.

What the article makes clear and people tend to forget

Three paragraphs that exclude nothing, but that put the rest of the map in order.

The GDPR still applies just the same. Article 2(7) says so expressly: the Regulation "shall not affect" Regulation (EU) 2016/679. There's no substitution, no overlap that resolves anything — they're two legal frameworks that coexist.

Consumer protection and product safety rules don't fall away either — Article 2(9).

And more favourable labour protections are preserved — Article 2(11), which expressly preserves the possibility of laws, regulations, administrative provisions or collective agreements more favourable to workers regarding employers' use of AI systems. Relevant in Spain, where an information right over algorithms that doesn't wait for the AI Act already exists.

What this means in practice

That the question "does it apply to me?" has a boring answer — yes — and that the useful question is a different one: what applies to you.

And there the split is very uneven: Article 4 and Article 5 reach everyone from 2 February 2025; the high-risk regime reaches few, and not before 2 December 2027. Almost everything a company needs to decide sits between those two things.

So looking for an exclusion is usually wasted effort, and asking the right question costs less: what systems you have and what each one does.

Content in line with Articles 2, 4 and 5 and Annex III of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 (Official Journal of the EU, 24 July 2026).

This article is for informational purposes only and does not constitute legal advice.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (CIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es). More information in the privacy policy.