EU AI Act compliance for engineering teams using GitHub Copilot
Engineering teams tend to assume compliance regulation is somebody else’s problem. Under Regulation (EU) 2024/1689, a company whose developers use GitHub Copilot is a deployer of an AI system, and the AI literacy obligation reaches the people writing code with it.
The classification itself is straightforward. Documenting it is the work, and the document has been due since February 2025.
Are you a provider or a deployer?
GitHub and OpenAI sit on the provider side. Your company is the deployer, which means literacy and documentation rather than conformity assessment.
How this is classified under the Act
Code completion and suggestion does not appear in Annex III. It affects software quality rather than a person’s access to employment, credit, education, or public services, so the memo records minimal risk.
What changes the answer: If the software your team ships is itself an AI system placed on the EU market, your company becomes a provider for that product, which is a heavier set of duties than deployer status. That is a separate assessment from your use of Copilot.
Want this checked against your own setup?
Run the free 6-question check →Documents you need
- AI Literacy Policy Article 4
A written policy covering which AI tools you use, which roles interact with them, what those people need to understand, who owns the document, and how it gets updated. Enforceable since 2 February 2025.
- Risk Classification Memo Articles 6, 9 and Annex III
A documented assessment placing each AI system in the Act’s risk tiers, including the Article 5 prohibited-practice check and the Article 6(3) exception assessment, with article citations.
Obligations that apply
- Article 4 Literacy for developers and reviewers
Developers need to understand that suggested code can be insecure, licence-encumbered, or subtly wrong, and that review responsibility stays with the human. Write down what that expectation is.
- Articles 6 and 9 Documented classification
Record the assessment showing the coding assistant is outside Annex III, including the Article 5 prohibited-practice check, so there is evidence you considered it.
Common mistakes
- Assuming the AI Act only touches customer-facing AI. Internal developer tooling still creates deployer obligations.
- Skipping the written policy because the risk tier is low. The tier determines how much you must do, never whether documentation applies.
- Missing the provider question entirely when the team is shipping AI features in the company’s own product.
Where the deadlines stand
The AI literacy obligation under Article 4 and the Article 5 prohibitions have been enforceable since 2 February 2025. General-purpose AI model rules applied from 2 August 2025. The Omnibus, published in the Official Journal on 24 July 2026, moved the high-risk dates: standalone high-risk systems under Annex III to 2 December 2027, and high-risk AI embedded in regulated products under Annex I to 2 August 2028. Article 50 transparency obligations still apply from 2 August 2026. Only the narrower Article 50(2) duty on general-purpose models generating synthetic content moved, to 2 December 2026, which is also when the new prohibition on AI-generated intimate imagery and child sexual abuse material takes effect.
The delay applies to the high-risk obligations. It does not move Article 4, which is why a written AI literacy policy is the document most companies are missing today.
Generate your 2 documents in about 30 minutes
Answer a short questionnaire and get every document above, pre-filled with your company details and article citations, in 11 EU languages. Preview free, download for €99 one-time. No subscription.
This page describes obligations under Regulation (EU) 2024/1689 as amended by the Omnibus published in the Official Journal on 24 July 2026, and was verified on 29 July 2026. It is general information rather than legal advice, and classification depends on your specific configuration and use. Review by qualified legal counsel is recommended before formal adoption of any compliance document.