Commercializing AI Systems: Obligations and Classifications
This contribution is the last part of the series "Unpacking the EU AI Act", by Patrick Brunner. It concludes the series with an in-depth look at the Act’s approach to "placing on the market" and "putting into service" activities, along with the responsibilities tied to these actions.
As we conclude the series, we turn to the pivotal activities of “placing an AI system on the market” and “putting it into service,” dissecting the obligations and classifications under the EU AI Act. The final post in this series explores what happens when exemptions under the AI Act no longer apply to an AI system. Specifically, it explains the rules and obligations tied to the activities of “placing on the market” and “putting into service”. These obligations are determined by the risk-based classification of AI systems, which dictates the regulatory requirements.
The AI Act divides AI systems into three categories based on their potential risks:
- Prohibited AI practices
- High-risk AI systems
- Certain AI systems requiring transparency obligations
Each category has unique implications for providers and deployers, which are detailed below.
1. Prohibited AI Practices
The AI Act bans certain AI systems that are deemed particularly harmful and incompatible with EU values, such as respect for human dignity and fundamental rights. These prohibited practices include:
- Subliminal and manipulative AI systems (Art. 5 (1)(a)),
- AI systems that exploit vulnerabilities (Art. 5 (1(b)),
- Social scoring systems (Art. 5 (1)c)),
- AI systems used for predictive policing (Art. 5 (1) (d)),
- AI systems for untargeted facial image scraping (Art. 5 (1)(e)),
- Emotion recognition systems in workplaces or schools (Art. 5 (1)(f)),
- AI systems for biometric categorization of sensitive personal attributes (Art. 5 (1)(g)), and
- AI systems used for real-time biometric identification in public spaces for law enforcement (Art. 5 (1)(h)).
Each case must be assessed individually, requiring collaboration between legal and technical experts to ensure compliance.
2. High-Risk AI Systems
High-risk AI systems are those with a significant impact on safety or fundamental rights. The AI Act outlines two pathways for classifying high-risk systems:
a) Union Harmonization Legislation (Annex I)
AI systems are high-risk if they are:
Safety components of products, listed under Annex I, Section A or B, or
- Products themselves regulated under Annex I, Section A or B.
Examples (Section A):
- Medical devices, lifts, personal protective equipment, machinery, or in vitro diagnostic tools.
Examples (Section B):
- Motor vehicles, rail systems, or aviation security equipment.
b) Use Cases in Specific Sectors (Annex III)
Annex III lists high-risk AI systems in the following areas:
- Biometrics (where legally permitted),
- Critical infrastructure,
- Education and vocational training,
- (Self-)Employment and workforce management,
- Access and enjoyment of essential services,
- Law enforcement, migration, asylum and border control,
- Administration of justice and democratic processes.
Providers may apply for exemptions under strict conditions (Art. 6 para. 3), provided they document their assessments and register the system in the EU high-risk AI database.
Obligations for Providers of High-Risk AI Systems
Providers of high-risk AI systems must comply with several obligations (Art. 16), including among others:
- Lifecycle Compliance: Ensuring the system adheres to the requirements in Articles 8–15.
- Conformity Assessment: Conducting evaluations before market placement or deployment (Art. 43).
- Technical Documentation and Transparency: Maintaining records and providing clear information about the system’s functionality.
For research institutions providing high-risk systems, these assessments must involve legal and technical expertise to avoid non-compliance.
Which AI Systems Are Requiring Transparency?
The AI Act also imposes transparency requirements for certain systems, even if they are not high-risk. Under Article 50, providers and deployers must ensure transparency for:
- Emotion recognition or biometric categorisation AI systems
- AI systems that interact directly with people,
- AI systems generating synthetic content (e.g., deepfakes),
- AI systems manipulating image, audio, video content or text that is published for public information.
Deployers using these systems must clearly disclose their nature to users and ensure compliance with transparency obligations.
Conclusion
This part of the AI Act highlights the layered approach to regulating AI systems based on their risks and potential impacts. By focusing on prohibited practices, high-risk classifications, and transparency obligations, the AI Act seeks to balance innovation with public safety and trust. Providers and deployers must thoroughly understand their roles, as compliance depends on the classification and intended use of their systems.
This concludes our blog series on the EU AI Act, offering a comprehensive view of how this regulation shapes the development and provision of AI technologies. Whether as a researcher, provider, or deployer, understanding these requirements is essential for navigating the evolving AI regulatory landscape.


