EU AI Act for agencies: classifying AI used on client work
Updated: 2026-09
A firm deploying AI on client work, or building it into client products, can become a provider under the EU AI Act rather than only a deployer. That role question determines the entire set of obligations and belongs settled per engagement, not once for the agency.
Agencies and service providers use AI as a matter of course today: for copy, images, analysis, chatbots, customer classification. What rarely gets asked is the role question. The EU AI Act distinguishes providers from deployers of AI systems, and very different obligations hang on that.
For an agency that is uncomfortable, because the role can change per engagement. Operating somebody else’s AI tool for a client generally makes you a deployer. Building an AI system into a client product under your own name, or substantially modifying it, can make you a provider — with considerably broader obligations.
The second point is downstream questions. Clients increasingly ask which AI sits in the work delivered and how it is classified. An agency without an answer loses the engagement not for lack of compliance but for being unable to answer.
How it works
- 01
List every AI tool in use
Not only the obvious ones: text generators, image tools, AI features inside existing software, chatbots on client sites.
- 02
Determine the role per engagement
For each client project, establish whether the agency operates somebody else’s system or offers a system under its own name. That distinction is the switch point.
- 03
Classify under Article 6
Assess each system individually. A copywriting tool in marketing is not the same as candidate pre-selection for a client.
- 04
Check transparency duties
Establish where end users must be informed about the AI — with chatbots and generated content this frequently applies.
- 05
Export evidence per client
Keep the classification as a standalone report per engagement, so the client question becomes answerable before it is asked.
- 06
Repeat for new tools
An agency’s toolset changes fast. Classification belongs tied to the adoption process, not to an annual project.
Why it fits here
Team workspaces let you keep separate evidence per client engagement rather than mixing everything into one collective document.
White-label PDF reports are exactly the format a client asks for when they want to know which AI sits in the work delivered.
Article 6 classification with legal citations makes the assessment defensible to the client rather than merely asserted.
FAQ
Are we a provider or a deployer?
It depends on the case. Operating somebody else’s system usually makes you a deployer; offering it under your own name or substantially modifying it can make you a provider. Classification settles that per engagement.
Does this apply to simple text tools too?
The AI Act covers AI systems regardless of how simple they appear. Obligations follow the risk of the use, not the complexity of the tool.
Must we inform clients about AI use?
Transparency duties are a core element of the AI Act and apply particularly to chatbots and generated content. The specific duty follows from how the system is classified.
Is one assessment enough for the whole agency?
No. The AI Act attaches to the individual system and its purpose. The same tool can be classified differently in two engagements.
Does this replace legal advice?
No. Classification delivers the structured, reasoned assessment and documentation. On borderline cases, legal advice remains sensible.
AI Risk Check
Team workspaces let you keep separate evidence per client engagement rather than mixing everything into one collective document.
White-label PDF reports are exactly the format a client asks for when they want to know which AI sits in the work delivered.
Article 6 classification with legal citations makes the assessment defensible to the client rather than merely asserted.
