Since the EU AI Act passed into force, the coverage has oscillated between two extremes: catastrophising about €35M fines on one side and dismissive “it won’t apply to us” optimism on the other. Neither is particularly useful.
This article is a practical briefing. What the Act actually requires, who it applies to, what the deadlines mean in practice, and the three decisions every EU business needs to make before August 2026.
First: The Act Applies to More Businesses Than Most Think
The EU AI Act applies to any organisation that:
- Places AI systems on the EU market or puts them into service in the EU
- Uses AI systems whose output affects EU residents
- Is established outside the EU but whose AI outputs are used within it
This is a broad scope. A non-EU company selling services to EU customers via an AI-powered platform is within scope. A German Mittelstand company using an AI-embedded SaaS tool for HR decisions is within scope. A marketing agency using AI to profile EU consumers is within scope.
The question is not “does AI touch our business?” Almost every business now uses AI in some capacity, often embedded in tools they consider standard software. The question is: what category of AI are you using, and what does that category require?
The Risk Tiers — Simplified
Unacceptable Risk — Prohibited. AI systems that manipulate people unconsciously, enable mass surveillance by public authorities, or use social scoring by governments. These are banned outright. Most businesses don’t touch these categories.
High Risk — Full Compliance Required. This is where most of the compliance work sits. High-risk AI includes systems used in: hiring and employment decisions, credit scoring and financial services, educational assessment, healthcare and medical devices, law enforcement, border control, and AI in safety-critical infrastructure. If you use AI in any of these contexts — or your AI vendor does — you have significant compliance obligations including technical documentation, human oversight procedures, and conformity assessment.
Limited Risk — Transparency Obligations.
Chatbots and AI that interacts directly with people must disclose that the user is talking to AI. This is the minimum bar — and one that many customer-facing AI deployments are not currently meeting.
Minimal Risk — No Specific Requirements.
Spam filters, AI-powered recommendation engines for content, most productivity AI tools. These sit here. But “minimal risk” doesn’t mean zero obligation — you still need to know what you’re running and be able to demonstrate you’ve assessed the risk.
The Deadlines That Actually Matter
The Act entered into force in August 2024. The compliance timeline is phased:
February 2025 (already passed):
Prohibited AI systems must be discontinued. GPAI (General Purpose AI) model obligations begin for providers.
August 2026:
High-risk AI system obligations become enforceable. This is the critical deadline for most businesses. Human oversight procedures, technical documentation, conformity assessments and governance frameworks must be in place.
August 2027:
High-risk AI embedded in regulated products (medical devices, machinery, vehicles) must comply.
August 2026 is 18 months away at the time of writing. For organisations with complex AI landscapes, 18 months is not a long time — especially if the first three months are spent understanding scope.
The Three Decisions Every EU Business Must Make
Decision One: Do we know what AI systems we’re running?
Most organisations don’t have a complete picture. AI is embedded in HR platforms, CRM systems, financial software, marketing tools and productivity suites — often without explicit labelling. The first step is an AI inventory: a structured register of every AI system in use, its purpose, its data inputs and its risk classification. Without this, you cannot comply — because you don’t know what you’re complying with.
Decision Two: Do any of our AI systems fall into High Risk?
If your organisation uses AI in hiring, credit, healthcare, education or safety-critical contexts, you need to treat those systems as high-risk. This means commissioning or producing technical documentation, implementing human oversight procedures, and conducting a conformity assessment. This is not lightweight work — it takes time and specialist expertise.
Decision Three: Who owns compliance?
AI Act compliance is not purely a legal question, not purely a technical question, and not purely a governance question. It sits at the intersection of all three. Most organisations have a gap here — legal teams who don’t understand AI systems deeply, technical teams who don’t understand regulatory requirements, and boards who haven’t yet assigned ownership. Deciding who owns this — and giving them the resource and mandate to act — is the prerequisite for everything else.
What "Good" Compliance Looks Like
Organisations that handle this well treat it as a governance programme rather than a one-off project. They build an AI inventory that stays current as new tools are adopted. They create an AI governance policy that applies to procurement as well as deployment — so new AI purchases trigger a classification assessment before they enter the business. They implement human oversight procedures that are documented and practiced, not just written down.
They also recognise that compliance and competitive AI deployment are not in tension. The organisations that build proper governance infrastructure are typically better at AI implementation overall — because the discipline that compliance requires is the same discipline that good AI project management requires.
The August 2026 deadline is real. The fines — up to €35M or 7% of global annual turnover — are real. But for most EU businesses, the path to compliance is clearer than the headlines suggest. It starts with knowing what you’re running.