Insights · Guide

The EU AI Act for companies: what to do now, in plain language.

The EU AI Act is the first comprehensive law on artificial intelligence, and it applies to almost every company that uses AI in the EU, not only to those who build it. This guide explains the roles, the risk tiers, the AI literacy duty and the timeline in plain language, and ends with a seven-step action plan for a typical company.

01

The basics

What the AI Act is

The EU AI Act (Regulation (EU) 2024/1689) is a product-safety style regulation for artificial intelligence. It does not regulate AI as a technology; it regulates specific uses according to the risk they pose to people's health, safety and fundamental rights. Most uses carry few or no specific obligations. A defined set of practices is prohibited, another set is classified as high-risk with substantial duties, and some uses trigger transparency duties. As an EU regulation it applies directly in every member state, with national authorities responsible for supervision and enforcement.

Who it applies to: providers, deployers and non-EU companies

The regulation defines several roles, but two matter for most companies. A provider develops an AI system, or has it developed, and places it on the market or puts it into service under its own name. A deployer uses an AI system under its own authority in a professional context. The software company selling a recruiting tool with an AI ranking feature is a provider; the Mittelstand company using that tool to screen applicants is a deployer. Deployers have fewer duties than providers, but they are not exempt.

Two points surprise many companies. First, the regulation applies to companies outside the EU when they place AI systems on the EU market or when the output of their system is used in the EU, so a Swiss or US company serving EU customers is in scope. Second, a deployer can become a provider: if you put your own brand on a high-risk system, substantially modify it or change its intended purpose so that it becomes high-risk, the provider obligations move to you. Building your own AI agents does not automatically make you a provider, but you cannot point to a vendor for the system's behaviour.

02

Risk tiers

The risk tiers, with examples that matter to a normal company

The tier depends on the use, not the technology. The same language model is minimal risk when it drafts marketing copy and high-risk when it ranks job applicants.

Risk tiers of the EU AI Act
TierWhat falls into itExamples in a typical companyYour duties in short
ProhibitedPractices considered unacceptable, such as manipulative techniques that cause harm, social scoring, and emotion recognition in the workplace and in education (with narrow exceptions)Analysing employees' emotions in video calls; scoring customers' trustworthiness from unrelated behaviourDo not use them. These bans have applied since February 2025
High-riskUses listed in the regulation's high-risk annex: biometrics, critical infrastructure, education, employment and worker management, access to essential services such as credit and insurance, plus AI safety components in regulated productsScreening or ranking applicants; monitoring performance to allocate tasks or decide promotions; assessing creditworthiness; grading examsProviders: risk management, data governance, documentation, conformity assessment, registration. Deployers: use as instructed, human oversight by trained people, monitoring, logs, informing workers and affected persons
Limited risk (transparency)Systems that interact with people or generate contentCustomer chatbots; AI-generated images, video and audio; AI-written texts on matters of public interestTell people they are dealing with AI; label AI-generated or manipulated content; inform people when emotion recognition or biometric categorisation is used
Minimal riskEverything elseSpam filters, internal drafting assistants, document summarisation, most process agents that support rather than decideNo specific duties beyond AI literacy; voluntary codes of conduct

For most companies the practical work sits in the second and third rows: find out whether anything you use touches employment decisions, credit, education or critical infrastructure, and make sure every chatbot and every published AI-generated asset carries the right disclosure.

General-purpose AI models

General-purpose AI models, the large models behind the products of OpenAI, Anthropic, Google, Mistral and others, have their own chapter. The obligations sit mainly with the model providers: technical documentation, information for downstream developers, a copyright policy, a summary of training content, and additional duties for models with systemic risk. These have applied since August 2025.

For a company building agents or products on such a model, the consequence is indirect but real: you rely on the provider's documentation for your own duties and remain responsible for the system you build. Ask vendors for their AI Act documentation.

03

Duties for everyone

The AI literacy duty applies to every organisation

Article 4 is the part of the regulation most companies overlook. Since February 2025, providers and deployers must ensure a sufficient level of AI literacy among their staff and other people who operate or use AI systems on their behalf. The required level depends on the person's role, technical knowledge and the context in which the system is used, including the people it affects.

There is no prescribed certificate, and the duty is proportionate: an accountant who uses an AI assistant for drafting needs different training from the HR team that operates a screening tool. What you need is a role-based training concept, evidence that it was delivered and a way to keep it current. Our AI training formats are built around this duty, from a leadership briefing to hands-on sessions for teams that work with agents every day.

The timeline

Phased application of the EU AI Act (original schedule; verify the current status)
DateWhat applies
1 August 2024The regulation enters into force
2 February 2025Prohibited practices and the AI literacy duty apply
2 August 2025Obligations for general-purpose AI models; governance structures and penalty rules in place
2 August 2026Originally scheduled: most remaining obligations, including transparency duties and the high-risk rules for the annex use cases
2 August 2027Originally scheduled: high-risk rules for AI embedded in regulated products such as machinery and medical devices

At the time of writing, proposals to postpone parts of the high-risk obligations have been under discussion at EU level. Treat the 2026 and 2027 dates as the original schedule, not as settled, and check the current status before you plan your compliance work against them. What is not in question: the prohibitions, the literacy duty and the general-purpose model rules already apply.

How the AI Act and the GDPR fit together

The GDPR applies whenever personal data is processed, regardless of the AI Act tier. In practice the two overlap on the same questions: is there a legal basis for the data, are people informed, is a data protection impact assessment needed, and are decisions with legal or similarly significant effects made solely by a machine. The AI Act adds the product view: is the system documented, tested, overseen and logged.

For companies in Germany a third layer matters: the works council has co-determination rights for technical systems that can monitor performance or behaviour, which covers many AI tools. The efficient approach is one intake process for every new AI use that answers the GDPR, AI Act and co-determination questions together, rather than three separate reviews that arrive in the wrong order.

04

Action plan

A seven-step action plan for a typical company

  1. Inventory. List every AI system in use, including features inside SaaS products, employees' own tool use and internal agents. Record purpose, vendor, data involved, who uses it and who is affected.
  2. Classify. For each entry, decide your role (provider or deployer) and the risk tier. Flag anything that touches employment, credit, education, biometrics or critical infrastructure for a closer look, and identify every chatbot and generated-content use for transparency duties.
  3. Write an AI policy. Acceptable use, prohibited uses, how new use cases are requested and approved, who owns AI governance. Keep it to a few pages that people will actually read.
  4. Train by role. Deliver AI literacy training proportionate to each role, document attendance and content, and repeat when systems or rules change.
  5. Fix the vendor contracts. Ask for AI Act documentation, model information, data processing terms and notification of material changes. Clarify who is the provider of what.
  6. Design human oversight. For every use that decides or acts, define who oversees it, what they can see, what authority they have to intervene and how their decisions are logged. Our guide on guardrails for AI agents covers the technical side.
  7. Document and monitor. Maintain the inventory as a living register, keep logs, define an incident process and review the whole set on a fixed cadence.

None of this requires a large programme. For a mid-sized company the first pass through all seven steps typically takes a few weeks, and it produces something useful beyond compliance: a clear picture of where AI is already used and where it should be. Our AI governance service runs exactly this process and leaves you with the register, the policy and the oversight design.

05

Frequently asked questions

Does the AI Act apply to a small company that only uses tools like Microsoft Copilot or ChatGPT?

Yes, as a deployer. For minimal-risk use the concrete duties are limited to AI literacy and, where a chatbot faces customers, transparency. The regulation is deliberately proportionate, but “we only use it a bit” is not an exemption, and an inventory is the only way to know that you really are in the minimal-risk tier.

Is our HR chatbot a high-risk system?

A chatbot that answers policy questions for employees is normally a transparency case, not high-risk. It becomes high-risk if it takes part in decisions about recruitment, promotion, task allocation, monitoring or termination. The line is drawn by the purpose, so document what the system is and is not used for.

What do we have to do about AI-generated content?

Content generated or manipulated by AI must be marked as such in machine-readable form by the provider, and deployers must disclose deepfakes and, with some exceptions, AI-generated text published to inform the public. Marketing copy revised by a person under editorial responsibility is generally treated differently from a synthetic video. When in doubt, disclose.

What are the penalties?

The regulation provides for fines calculated as a fixed amount or a share of global annual turnover, whichever is higher, with the highest tier reserved for prohibited practices. Enforcement sits with national authorities, and for most companies the more immediate risk is contractual: customers and partners increasingly ask for AI Act evidence.

Do we need an AI officer?

The regulation does not prescribe one. Someone must own the inventory, the policy and the oversight design, and that person needs enough seniority to say no. In smaller companies this is often the data protection officer or the head of IT; larger ones create a dedicated role. A fractional Chief AI Officer is one way to cover it without a full-time hire.

06

Related services and reading

Next step

Let's find the first workflow worth automating.

A 30-minute intro call, no slides and no obligation. We listen, ask about your processes, and tell you honestly where AI agents would pay off and where they would not.