Tsoukala & Partners
Athens · Greece
← All news
3 April 20262 min readAI & Technology Licensing

What the EU AI Act means for technology licensing

Risk classification is now a contract-drafting question, not just a compliance one — how AI Act obligations should be allocated between provider and deployer.

The EU AI Act introduces a risk-based classification framework, with different categories and obligations depending on the nature and use of the system. For companies licensing AI capabilities into or out of Greece, the practical consequence is that risk classification has moved from being a compliance exercise to becoming a contractual issue that needs to be addressed in the licensing agreement itself: who is responsible for assessing the system's classification, on what basis that assessment is made, and what happens contractually if the classification or intended purpose of the system changes.

Provider or deployer: the allocation question

The Act draws a distinction between providers (who place an AI system on the market or put it into service) and deployers (who use it under their own authority). A single licensing relationship can span both roles depending on how the technology is configured and marketed downstream. For example, a SaaS provider may act as the provider of an AI system or AI feature, while its customer acts as the deployer in its use of that system.

Getting this allocation wrong in the contract does not change the parties' regulatory status under the Act, but it may determine which party ultimately bears the compliance costs, remediation burden and liability exposure if that allocation proves to be incorrect.

High-risk systems and technical documentation

For AI systems that fall within the high-risk category, including certain use cases relating to employment, credit assessment, law enforcement and critical infrastructure, the AI Act may impose obligations relating to conformity assessment, risk management, technical documentation and post-market monitoring.

For technology licensing arrangements, this makes it important to address expressly who is responsible for maintaining or providing technical documentation, who supports conformity assessment and regulatory monitoring, who bears the associated costs, and how the parties respond if a regulator requires the system to be modified, updated or withdrawn.

Interaction with GDPR and IP ownership

AI Act compliance rarely sits in isolation. Training data provenance intersects with GDPR where personal data is involved, and questions of IP ownership over model outputs — and over any fine-tuning performed on licensed data — are increasingly negotiated as part of the same technology licensing arrangement rather than left to general boilerplate.

These questions are not determined solely by the AI Act. They sit at the intersection of AI regulation, data protection, intellectual property and contract. Licensing agreements drafted before these issues became commercially material may therefore warrant review, particularly where they are silent on responsibility for regulatory compliance, data use, model modification or changes to the applicable regulatory classification.

This article is for general information only and does not constitute legal advice. For advice on a specific matter, please contact us.

Related practice area
Get in touch