The EU AI Act is Regulation (EU) 2024/1689, in force since August 1, 2024, laying down harmonised rules on artificial intelligence across the European Union. It does not regulate the code you write. It regulates the AI systems that someone, you or your client, places on the market or puts into use.
If you run a software house and use an assistant like Claude Code, Cursor, or Copilot to write software for a client, someone eventually asks whether the AI Act applies to you. In most cases the honest answer is that nothing changes on the regulatory side, and it is worth writing down, because almost nobody does: the pages that rank for this query explain the regulation, not what it means for a team that delivers code to a client.
What Does the EU AI Act Actually Cover, and What Does It Leave Out?
Regulation (EU) 2024/1689 sorts AI systems by risk level and sets different obligations for whoever builds them (the provider) and whoever uses them (the deployer). Some practices have been banned since February 2, 2025. General-purpose AI models, the GPAI models behind tools like Claude or GPT, have carried their own obligations since August 2, 2025, on whoever develops them, not on whoever uses them. Transparency duties, disclosing when content is AI-generated or manipulated, apply from August 2, 2026. The heavier obligations, the ones on high-risk systems (hiring, credit scoring, critical infrastructure), were just pushed back by the Digital Omnibus, in force since July 27, 2026: to December 2, 2027 for stand-alone high-risk systems, and to August 2, 2028 for ones embedded in already-regulated products. At no point does the regulation say anything about how the code was written.
Does Using an AI Assistant to Write Code Change Your Position?
When you open Claude Code, Cursor, or Copilot to write software for a client, under the AI Act you are, at most, a deployer of that tool: you use it under your own authority, in a professional capacity. The provider of the AI system, whoever develops it and places it on the market under its own name, is Anthropic, Cursor, or Microsoft, not you. Being a deployer of an assistant carries one real but narrow obligation: since February 2, 2025, you have to ensure an adequate level of AI literacy among the people who use it in your company, meaning they understand its capabilities and limits, not a certified course. What using the tool does not do, on its own, is make you the provider of an AI system. You become one only if the software you deliver is, or contains, an AI system that you place on the market under your own name: a back-office web app written by an agent is still a back-office web app, not an AI system, unless it already was one on its own terms.
Provider or Deployer: Why Does the Distinction Actually Matter?
The question that decides your role is not which tool wrote the code, it is what you deliver. If the client's product has its own AI features, a chatbot, a scoring model, a recommendation engine, and you deliver it under the client's brand, the client is normally the provider of that system. If instead you sell a product with an AI feature under your own brand to multiple clients, typically a SaaS with a built-in AI capability, you are the provider of that specific system, with the obligations and deadlines that follow, regardless of how it was built. The regulation also states that whoever puts its own trademark on an existing AI system, or substantially modifies it, inherits the provider's obligations for it: a question about what you do with the finished product, not the tool you used to write it.
What a Client Asks Anyway, Regardless of the Regulation
Even when the AI Act does not apply to you, a cautious client asks questions that look a lot like compliance questions, because they want an answer before someone else asks them first.
| Area | What the client tends to ask | What you need to answer it |
|---|---|---|
| Provenance of the code | How much of the code was written by an agent, and how much by a person | A record of what the agent produced and what a person wrote or changed |
| Human review | Confirmation that someone checked it before it merged into production | An approval tied to the commit, not just a statement that it happened |
| Role under the AI Act | If the product has AI features, who is the provider under the regulation | A contract clause that settles it before it becomes a dispute |
| Traceability of changes | Who authorized what, and when | A signable record, not a commit message |
The last two points do not depend on how much the AI Act actually covers you: they depend on what you can show, months later, that you knew was happening while it was happening. It is the same question that comes up when a vibe-coded session lands straight in production: the client is not asking for regulatory compliance, they are asking for proof.
What Is Worth Putting in Writing Now?
Three things, independent of whether the AI Act reaches you at all. First, document that your team has an adequate level of literacy on the AI tools it uses: it has already been a legal obligation since February 2, 2025, and a one-page written policy is worth more than a one-time training session. Second, settle by contract who the provider is if the delivered product has its own AI features: it is a sentence, not a chapter, and it closes an ambiguity that otherwise stays open until someone disputes it. Third, keep a record of what an agent wrote and what a person reviewed: not because the AI Act asks for it directly in most cases, but because it is the same proof you need for the client, for insurance, and for yourself, the day something breaks and you have to reconstruct fast what actually happened.
There is no need to sell AI Act compliance as if it were a product feature: for most software houses, in most cases, it simply does not apply. What matters is being able to answer who wrote it, who approved it, and who was accountable for each delivery. Detent, the end-to-end delivery system (detent-ai.com), keeps intent, authorized context, execution, and a human signature together from signal to release: it is the kind of record that turns that question into a five-minute answer instead of a reconstruction from memory.
