AI Act and Scientific Research: The Exemption Does Not Cover Everything
The person who signs it answers for it.
The EU AI Act exempts certain AI systems built for research. It does not exempt people doing research. A researcher, a lawyer, a doctor or an analyst uses a commercial chatbot to draft, summarise or translate. That system was not developed for the sole purpose of scientific research. The person using it is a deployer of a general-purpose AI system. Responsibility for what they publish stays with them.
The short answer: the exemption protects the lab bench, not the everyday tool
Article 2 of the Regulation contains two research carve-outs. Paragraph 6 is about systems. Paragraph 8 is about activities. Neither is about the user.
The starting point is Article 2(1)(b). The Regulation applies to «deployers of AI systems that have their place of establishment or are located within the Union». A professional established in the Union who uses an AI system at work is inside scope. Before any exemption is argued.
What Article 2(6) actually says
The consolidated text reads: «This Regulation does not apply to AI systems or AI models, including their output, specifically developed and put into service for the sole purpose of scientific research and development.»
Two conditions. Both land on the system, not on the person.
First condition: the system must have been specifically developed for that purpose. Second condition: that purpose must be the only one.
An everyday chatbot passes neither. Article 3(66) defines a «general-purpose AI system» as one that «has the capability to serve a variety of purposes». That is the textual opposite of «sole purpose».
The exemption follows the system, not the working session. Using a commercial tool for a scientific task does not turn it into a research tool.
Article 2(8): before placing on the market, and why real-world testing stays in
The second carve-out is about activity: «This Regulation does not apply to any research, testing or development activity regarding AI systems or AI models prior to their being placed on the market or put into service.»
Before placing on the market or putting into service. Someone using an already-marketed model is not in that phase.
Then the same paragraph shuts the door: «Testing in real world conditions shall not be covered by that exclusion.» The moment the system meets real people and real data, the exclusion ends.
That leaves paragraph 10, the only private-use exit. It reads: «This Regulation does not apply to obligations of deployers who are natural persons using AI systems in the course of a purely personal non-professional activity.» Drafting a paper, an opinion, a clinical note or a client memo is professional activity. The paragraph does not cover the researcher. And it disapplies a natural person's deployer obligations, not the Regulation as a whole.
Anyone writing with ChatGPT, Claude or Gemini is a deployer of a general-purpose AI system
The Regulation names the role. Article 3(4): «'deployer' means a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity».
One duty already bites. Article 4(1) requires providers and deployers to take «measures to support the development of AI literacy of their staff». It has applied since 2 February 2025. It is not limited to high-risk. It covers universities, hospitals, professional firms and research institutes. And it is an obligation of effort, not of result: the same paragraph says it «does not require providers or deployers to guarantee a specific level of AI literacy for any individual».
The role can also move up. Article 25(1)(c) treats as a provider anyone who «modifies the intended purpose of an AI system, including a general-purpose AI system, which has not been classified as high-risk and has already been placed on the market or put into service in such a way that the AI system concerned becomes a high-risk AI system in accordance with Article 6». The threshold is high: drafting and summarising do not cross it. But the direction matters. Responsibility can move up. Never away.
Human oversight (Article 14): responsibility does not transfer to the model
Article 14 binds high-risk AI systems. On the Annex III (Annex 3) route it applies from 2 December 2027; for Annex I (Annex 1) from 2 August 2028. It is not a direct duty on someone using a chatbot. It is, however, the model the legislator chose to say where the final word sits.
Article 14(4)(d) requires that the person assigned human oversight be able «to decide, in any particular situation, not to use the high-risk AI system or to otherwise disregard, override or reverse the output of the high-risk AI system». Point (b) of the same paragraph names the risk outright: the tendency «of automatically relying or over-relying on the output», that is, «automation bias».
The ceiling is Article 14(5). It covers only Annex III (Annex 3) point 1(a) systems, remote biometric identification. No action or decision may be taken on the basis of the identification «unless that identification has been separately verified and confirmed by at least two natural persons with the necessary competence, training and authority». A second subparagraph disapplies that rule for systems used «for the purposes of law enforcement, migration, border control or asylum, in cases where Union or national law considers the application of this requirement to be disproportionate». This is not the everyday rule. It is the upper bound of what the legislator asks of human beings.
An Italian marker. On 4 August 2026 the Council of Ministers gave final approval to the legislative decrees adapting Italian law to the AI Act. The principle reads: «le decisioni restano dell'operatore ed è esclusa l'adozione di decisioni produttive di effetti giuridici negativi sulla sola base dell'elaborazione automatizzata», that is, the decision stays with the operator, and decisions producing negative legal effects may not be taken solely on automated processing. The same decrees designate the Agency for Digital Italy (AgID) as notifying authority and the National Cybersecurity Agency (ACN) as market surveillance authority.
Transparency for generated text: what Article 50 asks of whoever publishes
Article 50 has applied since 2 August 2026. The Digital Omnibus, Regulation (EU) 2026/1744, in force since 27 July 2026, moved the high-risk deadlines, not transparency.
Two sides, two different duties.
The provider marks. Article 50(2) requires providers of systems generating synthetic text to ensure the outputs are «marked in a machine-readable format and detectable as artificially generated or manipulated». For systems already placed on the market before 2 August 2026, that marking obligation applies from 2 December 2026.
The deployer discloses. Article 50(4), second subparagraph: «Deployers of an AI system that generates or manipulates text which is published with the purpose of informing the public on matters of public interest shall disclose that the text has been artificially generated or manipulated.» Then comes the exception, in the same provision: the duty does not apply «where the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content».
You buy your way out of the label by taking responsibility. That is this article's whole thesis, written into the Regulation. More: the Article 50 transparency obligations.
When research meets high-risk: the Annex III (Annex 3) edge cases
Some uses put research next to high-risk: scoring students, screening applications, supporting decisions about people. If the use falls under Annex III (Annex 3), everything changes. Article 26(2) requires that «deployers shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support». A named person. Not a policy PDF.
The classification rules are still being written. The targeted consultation on the draft guidelines for classifying high-risk AI systems closed in July 2026. The final guidelines are expected by the end of 2026. Do not wait for them to work out who answers. The duties already in force do not depend on that classification.
For orientation: how a system is classified under Annex III, and a worked case, schools and Annex III point 3.
Checklist: five checks before you sign work written with AI
- Name your role. Provider or deployer? Almost always deployer.
- Test the exemption against the system, not against yourself. Was it developed for the sole purpose of scientific research and development? A general commercial product was not.
- Check every fact, every citation and every number before you sign.
- If you publish generated text on matters of public interest, disclose it, or document the human review and name who holds editorial responsibility.
- Write down who supervised. A name and a date, not «the team».
Two more steps: the EU AI Act checklist and monitoring AI systems over time.
Frequently asked questions
Does the AI Act exempt scientific research?
Only in part. Article 2(6) exempts AI systems specifically developed and put into service for the sole purpose of scientific research and development. The exemption is about the system, not the person. Someone doing research with a general commercial tool does not fall under that exclusion.
I use ChatGPT to write a scientific paper. Am I exempt?
No. A general chatbot is a general-purpose AI system, built to serve a variety of purposes. It was not developed for the sole purpose of scientific research. Whoever uses it at work is a deployer under Article 3(4) and answers for the text they publish.
Does paragraph 8 not cover research and testing?
It covers the research, testing and development of an AI system before it is placed on the market or put into service. Using an already-marketed model is not that phase. The same paragraph adds that testing in real world conditions is not covered by the exclusion.
Do I have to disclose that a text was written with AI?
If you publish generated text with the purpose of informing the public on matters of public interest, yes. Article 50(4), second subparagraph, requires it since 2 August 2026. The duty does not apply where the content has undergone human review or editorial control. A natural or legal person must also hold editorial responsibility for it.
Which AI Act duties already apply to me today?
AI literacy under Article 4 has applied since 2 February 2025 to providers and deployers, high-risk or not. Article 50 transparency has applied since 2 August 2026. The high-risk rules for Annex III (Annex 3) systems will apply from 2 December 2027.
Related resources
- Article 50 AI Act: transparency duties and free disclosure templates
- Annex III (Annex 3) classification: how to tell whether a system is high-risk
- EU AI Act compliance software: how LandingRed covers the AI Act obligations
This article provides information, not legal advice. Quotations are taken from the consolidated text of the AI Act in force from 27 July 2026 (CELEX 02024R1689-20260727) as published on EUR-Lex. For your own situation, consult a professional.
See where your everyday AI use meets the AI Act. Drop a ChatGPT, Claude or Gemini export into the free AI usage scan. It runs in your browser and uploads nothing. You get a map of the domains your AI use touches, the data the tool sees, and where the obligations start. Run the AI usage scan.
Reviewed and published under the editorial responsibility of AB Corporate Advisory S.R.L.
LandingRed automates all of this
Stop managing compliance in spreadsheets. Classify, document, assess, and monitor your AI systems from one platform.