EU AI ACT FOR MSPS
Deployer duties, human oversight, log retention, and penalties up to 35,000,000 EUR or 7% of global turnover. Here is what actually applies to MSPs running AI for clients, written in English instead of regulator-speak.
Schedule a CallThis is operational guidance, not legal advice. The AI Act is enforceable across the EU with a phased timeline running through 2027. If you deploy AI for EU clients, EU users, or process EU personal data, you are in scope even if your MSP sits outside the EU. Get a qualified lawyer for anything high-risk.
THE FOUR RISK TIERS
| Tier | Examples | What it means for MSPs |
|---|---|---|
| Prohibited | Social scoring, untargeted facial scraping, manipulative systems. | Stay out. If a client asks, the answer is no and the answer is written down. |
| High risk | HR screening, credit decisions, critical infrastructure, biometric ID. | Heavy obligations: risk management, logging, human oversight, conformity assessment. Most MSPs should not be the deployer here without specialist counsel. |
| Limited risk | Chatbots, generated content, emotion or biometric categorization. | Disclosure obligations. Users must know they are interacting with AI or seeing AI-generated content. |
| Minimal risk | Spam filters, basic recommendation, productivity assistants. | Voluntary codes of conduct. Still log usage and document decisions. |
DEPLOYER DUTIES YOU ACTUALLY HAVE TO DO
When an MSP runs an AI system for a client, the MSP is usually the deployer. Sometimes the client is. Either way, somebody is, and the duties do not disappear because the contract is vague.
- Use the system according to the provider's instructions, in writing.
- Assign human oversight to someone with the competence and authority to intervene.
- Monitor operation and report serious incidents to the provider and authority.
- Keep automatically generated logs for the period set by the provider, minimum six months.
- Inform affected workers and their representatives before deploying high-risk systems at work.
- For certain public-interest deployers, complete a fundamental rights impact assessment.
PENALTY EXPOSURE
Prohibited AI practices
Up to 35,000,000 EUR or 7% of worldwide annual turnover.
Most other obligations
Up to 15,000,000 EUR or 3% of worldwide annual turnover.
Supplying incorrect information to authorities
Up to 7,500,000 EUR or 1% of worldwide annual turnover.
Fines are calibrated to global turnover, not EU turnover. SMEs get a "lower of" treatment, which is still ruinous for most MSPs. Document everything. Decisions, logs, oversight assignments, vendor attestations.
WHAT TO DO THIS QUARTER
- Inventory every AI system in production for every client. Owner, model, vendor, data, purpose.
- Classify each one into a risk tier. Write down the reasoning.
- Assign a named human overseer for anything beyond minimal risk.
- Turn on log retention. Six months minimum. More if the provider specifies it.
- Update client contracts to clarify provider, deployer, and oversight responsibilities.
- Train at least one person on the team to act as your internal AI compliance lead.
Tie the cost of doing this into your automation packaging. Compliance work is not free, and the contract should say so.
KEEP READING THE PILLAR
Compliance is one of the deciding factors in the RPA versus AI choice. The pillar guide covers the full trade-off, including when boring deterministic automation is the safer bet.
Read the RPA vs AI PillarNEED A SECOND PAIR OF EYES ON YOUR AI EXPOSURE?
Bring your AI inventory and your client contracts. We will tell you where you are most exposed and what to fix first. No legalese, no scare tactics.
Schedule a Call