What the EU AI Act means for technology licensing
Risk classification is now a contract-drafting question, not just a compliance one — how AI Act obligations should be allocated between provider and deployer.
The EU AI Act introduces a risk-based classification system — unacceptable, high, limited and minimal risk — that determines which obligations attach to a given AI system. For companies licensing AI capabilities into or out of Greece, the practical consequence is that risk classification has moved from being a compliance memo to being a term that needs to sit inside the licensing agreement itself: who classifies the system, on what basis, and what happens contractually if that classification changes.
Provider or deployer: the allocation question
The Act draws a distinction between providers (who place an AI system on the market or put it into service) and deployers (who use it under their own authority). A single licensing relationship can span both roles depending on how the technology is configured and marketed downstream — a SaaS platform licensing an embedded AI feature may be a provider for that feature while its customer is a deployer of the end product. Getting this allocation wrong in the contract does not change the regulatory position, but it does determine which party bears the compliance cost and the liability exposure if it turns out to be wrong.
High-risk systems and technical documentation
For systems that fall into the high-risk category — broadly, those used in areas like employment, credit scoring, law enforcement-adjacent contexts or critical infrastructure — the Act requires conformity assessment, technical documentation, and post-market monitoring. Licensing terms increasingly need to specify who maintains that documentation, who bears the cost of conformity assessment, and how the parties handle a regulatory finding that requires the system to be updated or withdrawn.
Interaction with GDPR and IP ownership
AI Act compliance rarely sits in isolation. Training data provenance intersects with GDPR where personal data is involved, and questions of IP ownership over model outputs — and over any fine-tuning performed on licensed data — are increasingly negotiated as part of the same technology licensing arrangement rather than left to general boilerplate. Contracts drafted before these questions were live in the market are worth revisiting, not because they are unenforceable, but because they were silent on points the Act now makes commercially material.
This article is for general information only and does not constitute legal advice. For advice on a specific matter, please contact us.