Mapping AI Act roles and risk classification
A client adding AI features to its product did not know whether it fell under provider obligations. Through an inventory, role analysis and risk classification, a compliance roadmap tied to the AI Act timeline was established.
Role first, then obligations
The same product could make the company a deployer or a provider depending on its configuration — the difference changed the set of obligations.
Investment decisions could not be made until it was clear which feature fell into which risk class.
Our Approach
Keeping the commercial objective at the centre, we broke the legal risks into measurable steps.
01 · Inventory
All AI components used and developed were gathered into a single list.
02 · Role and Class
For each component, the role and risk class were determined with reasoning.
03 · Roadmap
The obligations were tied to a phased timeline and to owners.
Chronology
The main stages of the process.
A scheduled compliance plan instead of uncertainty
The company gained a roadmap that knew which feature triggered which obligation and when, and that let it make investment decisions accordingly.
- A reasoned role determination
- A component-based risk classification
- A plan tied to a phased timeline
- A compliance narrative ready for customer questions
Services Involved in This Matter
Planning a similar transaction? Explore the services we provided in this matter.
Related Areas of Expertise
The practice and focus areas engaged on this matter.
Sectors
The sectors in which we most frequently advise on matters of this kind.
Related Publications
Our insights and guides related to this matter.

Product compliance when selling into the EU: GPSR, accessibility, and the new packaging regime
The new preconditions for selling into the EU go beyond legal texts: a responsible person under the GPSR, an accessible store under the BFSG, packaging registration under LUCID/PPWR. A seller's-eye map of the 2024–2026 wave.
Read more →
Being a marketplace seller: 7 legal topics, from account suspension to the 1% withholding
Amazon, Etsy, Trendyol: the law of marketplace selling starts with the contract, continues with DSA verification and GPSR fields, and is tested by withholding and suspensions. 7 topics from the seller's perspective.
Read more →
E-commerce from Türkiye to the EU: VAT, OSS/IOSS and GDPR checklist
The three compliance layers of selling online to consumers in the EU: VAT registrations (OSS/IOSS), GDPR and consumer rules. A market-entry checklist for Turkish e-commerce companies.
Read more →The Team on This Matter
Our multilingual team handling the matter.
Related Matters
A selection of similar transactional and advisory matters.
Uninterrupted legal counsel for a multinational supplier
Retainer-based support across day-to-day commercial operations, contract management and compliance processes.
Designing corporate governance across group companies
Single-source management and documentation of general assembly, board and compliance processes.
Building a single compliance programme for KVKK and GDPR
Establishing the data inventory, document set, transfer mechanisms and breach plan of a group selling in two markets within a single programme.
First we clarify the commercial objective, risk appetite, timeline and the decision-maker's needs. Then we break the work down into legal analysis, document/contract structure and implementation steps, and manage the process through a single point of contact.
Owing to the legal profession's duty of confidentiality and client privilege, the files are anonymised. In a meeting, within the limits of confidentiality, we can describe our comparable experience more concretely.
In a short preliminary meeting, we take in the objective, existing documents, parties, time pressure and critical risks. Then the scope, team, timeline and fee model are clarified.
To complete a similar matter with confidence.
Let us manage your process from start to finish with our experience in similar matters.


