EU AI Act compliance starts with knowing which AI systems you use or build and what role you play: provider, deployer, importer or distributor. The Act sorts AI into prohibited, high-risk, limited-risk (transparency) and minimal-risk categories, with obligations phasing in from 2025 to 2027. Most businesses need an AI inventory, risk classification, AI literacy training, transparency for chatbots and AI-generated content, vendor checks and, for high-risk uses, risk management, human oversight, documentation and monitoring.
For years, AI regulation was a topic for policy papers. Now it is law. The European Union’s Artificial Intelligence Act is the world’s first comprehensive AI regulation, and its obligations are phasing in through 2025, 2026 and 2027. It affects not only European companies but any business whose AI systems are placed on the EU market or whose AI outputs are used in the EU.
EU AI Act compliance does not mean stopping AI projects. For most businesses, it means knowing which AI systems they use, understanding the risk level of each, training staff, being transparent with users and choosing trustworthy vendors. For high-risk uses, it means more formal risk management, documentation and human oversight. Done well, these practices also make AI more reliable and easier to scale.
This guide explains who the Act applies to, how risk categories work, the key dates, obligations for different roles, and a practical governance plan. It is a business overview, not legal advice; for specific situations, consult qualified legal counsel.
Who the EU AI Act applies to
The Act defines several roles, and your obligations depend on which apply to you:
- Provider: develops an AI system or general-purpose AI model and places it on the market or puts it into service under its own name
- Deployer: uses an AI system under its authority in a professional capacity
- Importer and distributor: bring AI systems from outside the EU or make them available on the EU market
- Product manufacturer: integrates AI into regulated products
Most businesses are deployers: they use AI tools built by others for customer service, marketing, HR, finance or operations. Companies that build AI products or significantly modify AI systems for others may become providers, with heavier obligations.
The Act has extraterritorial reach. A company based in India, Canada or the United States can be covered if it provides AI systems to EU customers or if outputs of its AI systems are used in the EU.
The risk-based approach
The Act groups AI uses into categories:
Prohibited practices
Certain uses are banned outright, including manipulative techniques that cause significant harm, exploiting vulnerabilities of specific groups, social scoring, certain predictive policing based solely on profiling, untargeted scraping of facial images to build recognition databases, emotion recognition in workplaces and education (with limited exceptions) and some uses of biometric categorisation and real-time remote biometric identification.
High-risk AI systems
These include AI used as safety components of regulated products and AI used in specific sensitive areas, such as:
- Employment and worker management, including recruitment, screening and promotion decisions
- Access to education and assessment of students
- Access to essential private and public services, such as creditworthiness assessment and some insurance pricing
- Critical infrastructure
- Law enforcement, migration and justice
- Certain biometric uses
High-risk systems carry the strictest obligations.
Transparency obligations
Some systems must meet specific transparency requirements, for example:
- People must be informed when they interact with an AI system such as a chatbot, unless obvious
- AI-generated or manipulated content such as deepfakes must be disclosed
- Synthetic audio, image, video and text content should be marked in a machine-readable way by providers where required
Minimal risk
Most everyday AI uses, such as spam filters, writing assistance or internal productivity tools, fall here, with no specific new obligations beyond general rules such as AI literacy.
General-purpose AI models
Providers of general-purpose AI models, such as large language models, have separate obligations around documentation, copyright policies and training data summaries, with extra duties for models posing systemic risk. Businesses that only use these models are generally not providers of the model, but they may still have obligations as deployers of systems built on them.
Key dates
| Date | What applies |
|---|---|
| August 2024 | The Act enters into force |
| February 2025 | Prohibited practices banned; AI literacy obligations apply |
| August 2025 | Obligations for general-purpose AI models; governance structures and penalties framework |
| August 2026 | Most remaining obligations, including many high-risk and transparency requirements |
| August 2027 | High-risk rules for AI in certain regulated products |
Regulators may issue guidance, standards and amendments that affect timing and details, so track official updates from the EU institutions and national authorities.
Because obligations arrive in stages, EU AI Act compliance is best treated as a programme rather than a one-off project. Some duties, such as avoiding prohibited practices and providing AI literacy, already apply. Others, such as many high-risk requirements, take time to prepare, so starting early avoids a rush as deadlines approach. Assign someone to monitor developments, including official guidance, harmonised standards and codes of practice, and update your plan when they change.
Obligations for deployers
If you use AI systems in your business, key duties include:
- AI literacy: ensure staff who use or operate AI systems have sufficient understanding of how they work, their limits and risks
- Use as intended: follow the provider’s instructions for use
- Human oversight: for high-risk systems, assign competent people to oversee operation and intervene when needed
- Input data: for high-risk systems, ensure input data under your control is relevant and representative
- Monitoring and logs: monitor high-risk systems, keep logs for the required period and report serious incidents
- Transparency: inform people when they interact with AI or are subject to certain AI-assisted decisions
- Workplace information: inform workers and their representatives before using high-risk AI in the workplace
- Impact assessments: certain deployers, such as public bodies and some private service providers, must assess fundamental rights impacts for specific high-risk uses
Obligations for providers of high-risk systems
If you build or substantially modify high-risk AI systems, you must, among other things:
- Establish a risk management system across the lifecycle
- Apply data governance to training, validation and testing data
- Prepare technical documentation and keep records
- Design for logging, transparency and human oversight
- Achieve appropriate accuracy, robustness and cybersecurity
- Operate a quality management system
- Complete conformity assessment, register the system where required and apply CE marking
- Monitor performance after launch and report serious incidents
Penalties
Fines are significant. Breaches of prohibited practices can lead to fines of up to 35 million euros or 7% of worldwide annual turnover, whichever is higher. Other breaches carry lower maximum fines, and providing incorrect or misleading information to authorities is also penalised. Proportionate treatment applies to SMEs and start-ups, but the risk is real for every company.
A practical EU AI Act compliance plan
Step 1: Build an AI inventory
List every AI system you use or provide, including tools embedded in software you buy, such as AI features in your CRM, HR platform or customer service software. For each, record its purpose, users, data used, vendor and whether outputs affect people in the EU.
Step 2: Classify each system
Determine your role (provider or deployer) and the risk category. Flag anything that might be prohibited or high-risk for detailed review.
Step 3: Deliver AI literacy training
Train staff who use AI on how the tools work, their limits, risks such as errors and bias, data protection and when to escalate. Tailor depth to roles.
Step 4: Implement transparency
Disclose chatbots and AI interactions to users, label AI-generated content where required and update privacy notices.
Step 5: Review vendors
Ask providers about their EU AI Act compliance, documentation, instructions for use, data handling and support for deployer obligations. Update contracts accordingly.
Step 6: Apply controls for high-risk uses
For high-risk systems, set up human oversight, logging, monitoring, incident reporting and, where required, impact assessments. Consider whether a lower-risk alternative could meet the business need.
Step 7: Establish AI governance
Appoint accountable owners, create an AI policy, set an approval process for new AI uses and review the inventory regularly.
Step 8: Document everything
Keep records of classifications, decisions, training, vendor assessments and controls. Documentation is your evidence of compliance. Keep it in one shared place, update it whenever systems change and review it at least once a year, so you can answer questions from regulators, clients and auditors quickly and confidently.
Common business scenarios
A customer service chatbot
A company deploys an AI chatbot on its website to answer customer questions. This is typically not high-risk, but transparency rules apply: customers should be told they are interacting with AI unless it is obvious. The company should also train staff who manage the chatbot, keep conversation logs in line with privacy rules and provide an easy route to a human. See our AI chatbot vs live chat guide for design advice.
AI-generated marketing content
A brand uses AI to create images, videos and copy for campaigns. Where content could be mistaken for real people or events, such as deepfake-style video, disclosure is required. Even where not strictly required, labelling AI-generated content and keeping records of how it was produced is good practice and protects brand trust.
AI in recruitment
A company uses an AI tool to screen CVs or rank candidates. Employment uses are listed as high-risk, so the company, as deployer, must use the system according to instructions, ensure qualified human oversight of decisions, monitor its operation, keep logs, inform candidates and workers as required and work with a provider that meets high-risk obligations. Many organisations decide to keep AI in a supporting role, such as summarising applications, while people make all screening decisions.
Credit and insurance decisions
Lenders and insurers using AI to assess creditworthiness or set certain insurance prices face high-risk obligations, plus existing financial regulation. Strong documentation, fairness testing, explainability and human review are essential.
Internal productivity tools
Staff using AI assistants to draft emails, summarise documents or write code are generally in the minimal-risk category. The main obligations are AI literacy and sensible data protection policies, such as not sharing confidential client data with unapproved tools.
Working with your vendors
Most companies rely on AI built by others, so vendor management is central to EU AI Act compliance. Useful questions for providers include:
- How have you classified this system under the AI Act?
- What documentation and instructions for use do you provide to deployers?
- How do you support human oversight, logging and transparency?
- How is our data used, stored and protected?
- How will you notify us of changes, incidents or updates relevant to compliance?
Record the answers and include key commitments in contracts.
How AI governance supports the business
Strong governance is often seen as a cost, but it brings real benefits:
- Better AI quality through testing, monitoring and human oversight
- Faster approvals for new projects when a clear process exists
- Client trust, especially in B2B, where customers increasingly ask about AI practices
- Reduced legal and reputational risk
- Readiness for other regulations around the world, many inspired by the EU approach
What good AI literacy training covers
AI literacy is one of the earliest obligations and one of the most broadly applicable. Effective training is practical and role-based, covering:
- What AI systems the company uses and why
- How these systems work at a basic level, including that outputs can be wrong
- Common risks: errors, bias, privacy breaches, overreliance and manipulation
- What data may and may not be shared with AI tools
- How to check outputs and when to escalate concerns
- Specific responsibilities for people overseeing higher-risk systems
Keep records of who has been trained and refresh training when tools or rules change. Short, regular sessions with real examples from your business work better than a single long course.
Building compliance into new AI projects
The easiest way to stay compliant is to design for it from the start. For every new AI project, add a short checkpoint covering: the intended purpose, the risk category and your role, the data used, transparency needs, the level of human oversight, how performance will be tested and monitored, and who owns the system. Projects that pass through this checkpoint launch faster and with fewer surprises than those that try to add compliance at the end.
Common mistakes
- Assuming the Act only applies to EU companies
- Ignoring AI features embedded in purchased software
- Treating all AI as high-risk, or none of it
- Skipping AI literacy training for staff
- Relying on vendors without checking their compliance and documentation
- No clear owner accountable for AI governance
- Waiting for the last deadline instead of building sensible governance practices now, while there is time to do it well
The bottom line
EU AI Act compliance is achievable for most businesses with a structured approach: inventory your AI, classify risk and roles, train staff, be transparent, check vendors, apply strong controls to high-risk uses and document your decisions. These steps protect your business and make AI more trustworthy and effective. For complex or high-risk cases, combine practical governance with expert legal advice.
Explore how we build AI systems with governance and human oversight built in, or read about private AI on your own data and agentic AI for business.
Frequently asked questions
Does the EU AI Act apply to companies outside the EU?
Yes, in many cases. It applies to providers placing AI systems on the EU market and to organisations whose AI system outputs are used in the EU, regardless of where the company is based.
What are the main risk categories in the EU AI Act?
Prohibited practices, high-risk AI systems, systems with specific transparency obligations such as chatbots and deepfakes, and minimal-risk systems with no specific new obligations.
When do EU AI Act obligations apply?
The Act entered into force in August 2024. Prohibitions and AI literacy obligations applied from February 2025, general-purpose AI model obligations from August 2025, and most remaining obligations from August 2026, with some high-risk rules for regulated products from August 2027. Check for any official updates to these dates.
What is a deployer under the EU AI Act?
A deployer is an organisation that uses an AI system under its authority in a professional context, for example a company using an AI tool to screen job applications or answer customers.
What are the penalties for non-compliance?
Fines can reach up to 35 million euros or 7% of global annual turnover for prohibited practices, with lower maximum fines for other breaches.
Do small businesses need to comply?
Yes, but obligations depend on how AI is used. Most small businesses using everyday AI tools face mainly AI literacy and transparency duties, while high-risk uses bring heavier requirements. The Act includes some support measures for SMEs.