ChatGPT / OpenAI

ChatGPT, the OpenAI API and who is responsible.

"Our staff use ChatGPT" and "we built on the OpenAI API" are different questions with different answers. Conflating them is how teams either panic or miss something.

Last updated 21 August 2026 · Regulation (EU) 2024/1689 as amended by the June 2026 Omnibus · Self-assessment, not legal advice

The question arrives in two very different forms, and they have different answers. "Our staff use ChatGPT - does the AI Act apply to us?" is usually a small problem. "We built our product on the OpenAI API - are we a provider?" is a real one. This page separates them, because conflating the two is how teams end up either panicking or ignoring something they shouldn't.

If your staff just use ChatGPT

Using ChatGPT the way you'd use a search engine or a word processor - drafting, summarising, brainstorming - makes you a deployer of an AI system under Article 3(4), and almost always a deployer of a minimal risk one. The heavy Chapter III obligations do not attach.

What does attach, today:

Nothing about internal ChatGPT use makes you a provider. OpenAI is the provider of ChatGPT. You are downstream, and GDPR is the more pressing question - what your staff are pasting into it - not the AI Act.

If you built on the OpenAI API

Here the answer changes. Shipping a feature to your users that runs on GPT under the hood makes you the provider of that feature, even though the model is OpenAI's. You put it on the market under your own name; that is what Article 3(3) turns on.

Two separate questions follow, and teams routinely merge them:

QuestionAnswerWhose duty
Are you a GPAI model provider under Article 53?Almost certainly not, if you call the API or fine-tune lightly in-domainStays with OpenAI - training-data summary, copyright policy
Are you the provider of an AI system?Yes, for the feature you shipYou - classification, Article 50 disclosure, and Chapter III if it's high-risk

The first is what everyone worries about and rarely applies. The second is what actually applies and is rarely discussed. Where the GPAI line sits · Provider vs deployer in full.

What the API does not remove

Article 50 disclosure. If your GPT-powered feature talks to users, it must say it's an AI system at first interaction. OpenAI's terms don't discharge this for you - it's a duty on the provider of the system the user is actually interacting with, which is yours. Article 50, in detail.

Classification by what your product does. The Act classifies your system by its intended purpose, not by whose weights are underneath. A GPT-powered CV screener is high-risk under Annex III point 4 exactly as much as one you trained yourself.

Content marking. Article 50(2) requires AI-generated output to be marked machine-readably. For plain API output this generally sits with the model provider - but if you generate, assemble or re-encode media yourself, verify rather than assume.

When you would cross into being a GPAI provider

Fine-tuning does not automatically do it. What can: substantial retraining that materially changes the model's general capability, or repurposing it into a new task domain. Prompt engineering, RAG, and light in-domain fine-tuning ordinarily keep you downstream. The four factors that decide it are set out on the Article 53 page.

If you do cross the line, the obligations are OpenAI-scale: technical documentation, a copyright policy, a public training-data summary, and cooperation with the AI Office. This is worth knowing before a retraining project, not after.

The short version

Which side of that line are you on?

The free check establishes your role and tier per feature - two minutes, no account.

Start the free scan

No card, no account. Full gap report from €59. See a real report first.

Self-assessment, not legal advice. This page and the Reglynn report are a structured self-assessment based on the EU AI Act (Regulation 2024/1689, as amended by the June 2026 Omnibus). They indicate where you likely stand and what to verify with a qualified advisor. Reglynn is not a notified body and issues no certification.

How this was made. Reglynn reports are generated by an AI system built on Anthropic's Claude and reviewed before delivery. Reglynn is a Limited Risk AI system under Article 50; we disclose AI involvement wherever it occurs, including in our chat assistant. Our own self-assessment.