MSP Compliance & Risk

    EU AI ACT FOR MSPS

    Deployer duties, human oversight, log retention, and penalties up to 35,000,000 EUR or 7% of global turnover. Here is what actually applies to MSPs running AI for clients, written in English instead of regulator-speak.

    Schedule a Call

    This is operational guidance, not legal advice. The AI Act is enforceable across the EU with a phased timeline running through 2027. If you deploy AI for EU clients, EU users, or process EU personal data, you are in scope even if your MSP sits outside the EU. Get a qualified lawyer for anything high-risk.

    THE FOUR RISK TIERS

    TierExamplesWhat it means for MSPs
    ProhibitedSocial scoring, untargeted facial scraping, manipulative systems.Stay out. If a client asks, the answer is no and the answer is written down.
    High riskHR screening, credit decisions, critical infrastructure, biometric ID.Heavy obligations: risk management, logging, human oversight, conformity assessment. Most MSPs should not be the deployer here without specialist counsel.
    Limited riskChatbots, generated content, emotion or biometric categorization.Disclosure obligations. Users must know they are interacting with AI or seeing AI-generated content.
    Minimal riskSpam filters, basic recommendation, productivity assistants.Voluntary codes of conduct. Still log usage and document decisions.

    DEPLOYER DUTIES YOU ACTUALLY HAVE TO DO

    When an MSP runs an AI system for a client, the MSP is usually the deployer. Sometimes the client is. Either way, somebody is, and the duties do not disappear because the contract is vague.

    • Use the system according to the provider's instructions, in writing.
    • Assign human oversight to someone with the competence and authority to intervene.
    • Monitor operation and report serious incidents to the provider and authority.
    • Keep automatically generated logs for the period set by the provider, minimum six months.
    • Inform affected workers and their representatives before deploying high-risk systems at work.
    • For certain public-interest deployers, complete a fundamental rights impact assessment.

    PENALTY EXPOSURE

    Prohibited AI practices

    Up to 35,000,000 EUR or 7% of worldwide annual turnover.

    Most other obligations

    Up to 15,000,000 EUR or 3% of worldwide annual turnover.

    Supplying incorrect information to authorities

    Up to 7,500,000 EUR or 1% of worldwide annual turnover.

    Fines are calibrated to global turnover, not EU turnover. SMEs get a "lower of" treatment, which is still ruinous for most MSPs. Document everything. Decisions, logs, oversight assignments, vendor attestations.

    WHAT TO DO THIS QUARTER

    1. Inventory every AI system in production for every client. Owner, model, vendor, data, purpose.
    2. Classify each one into a risk tier. Write down the reasoning.
    3. Assign a named human overseer for anything beyond minimal risk.
    4. Turn on log retention. Six months minimum. More if the provider specifies it.
    5. Update client contracts to clarify provider, deployer, and oversight responsibilities.
    6. Train at least one person on the team to act as your internal AI compliance lead.

    Tie the cost of doing this into your automation packaging. Compliance work is not free, and the contract should say so.

    KEEP READING THE PILLAR

    Compliance is one of the deciding factors in the RPA versus AI choice. The pillar guide covers the full trade-off, including when boring deterministic automation is the safer bet.

    Read the RPA vs AI Pillar

    NEED A SECOND PAIR OF EYES ON YOUR AI EXPOSURE?

    Bring your AI inventory and your client contracts. We will tell you where you are most exposed and what to fix first. No legalese, no scare tactics.

    Schedule a Call