AITENCY — Custom AI Systems
Compliance

The EU AI Act: What It Means for Your Business

The EU AI Act is now law. The first prohibitions took effect in February 2025, governance and General-Purpose AI obligations apply from August 2, 2025, the bulk of the regulation applies from August 2, 2026, and high-risk system requirements under Annex I follow in 2027. If your company builds, deploys, imports, or distributes AI inside the European Union — or sells AI-driven services to EU customers from outside the bloc — the Act applies to you.

This guide explains what the EU AI Act covers, who it applies to, how the four risk categories work, what timelines you are accountable to, and the practical steps EU businesses should take this quarter. It is written for executives, founders, compliance officers, and operations leaders who need to understand the regulation without wading through 144 articles of legal text.

What is the EU AI Act?

The EU AI Act (Regulation (EU) 2024/1689) is the European Union's horizontal framework for artificial intelligence. It was adopted by the European Parliament in March 2024, formally entered into force on August 1, 2024, and applies in stages over a 36-month roll-out. It is the first comprehensive AI law of its kind anywhere in the world, and like the GDPR before it, it sets a regulatory benchmark that companies outside Europe will have to meet whenever they touch the EU market.

The Act takes a risk-based approach. Rather than regulating AI as a single category, it sorts AI systems into four tiers based on the harm they could cause to health, safety, fundamental rights, and democratic processes. Obligations scale with risk: a few practices are banned outright, a defined set of high-risk uses must meet detailed engineering and governance requirements, and most consumer applications carry only modest transparency duties.

It is useful to think of the EU AI Act and the GDPR as complementary, not duplicative. GDPR governs how personal data flows; the AI Act governs how AI systems are designed, documented, deployed, and overseen. Where they overlap — for example, in automated decision-making with legal effect — the AI Act adds engineering and lifecycle obligations on top of the GDPR's data-rights baseline. Both regulations share the same enforcement philosophy: traceability, accountability, and material penalties for failure.

Who does the EU AI Act apply to?

The Act regulates four distinct roles in the AI value chain, and it is common for a single company to occupy more than one of them at the same time.

  • Providers — organisations that develop an AI system or have one developed and place it on the EU market under their own name or trademark. This is the most heavily regulated role.
  • Deployers — organisations using an AI system under their own authority in the course of professional activity (formerly called "users" in earlier drafts). A bank using a third-party CV-screening tool is a deployer.
  • Importers — entities established in the EU that place an AI system from outside the EU on the market.
  • Distributors — anyone in the supply chain who makes an AI system available without modifying it.

The territorial scope is deliberately broad. The Act applies whenever:

  1. A provider places an AI system on the EU market, regardless of where the provider is established.
  2. The deployer is located in the EU.
  3. The output of the AI system is used in the EU, even if both the provider and the deployer sit outside the bloc.

This third clause is what gives the AI Act its extraterritorial reach. A US-based SaaS vendor selling AI features to a Cyprus-based bank is in scope. A Singapore analytics firm whose model output is consumed by a German manufacturer is in scope. Geography is not a shield.

A small number of activities are explicitly out of scope: AI used solely for military, defence, or national-security purposes; AI systems developed and used purely for scientific research and development; and free, open-source AI components, provided they are not placed on the market as part of a commercial product or fall into a high-risk category.

The four risk categories

Every AI system in scope must be classified into one of four tiers. Classification drives every other compliance decision.

1. Prohibited (Article 5)

A small set of practices is banned outright because they are considered incompatible with EU fundamental rights. These include:

  • Manipulative or deceptive techniques that materially distort behaviour and cause significant harm.
  • Exploitation of vulnerabilities based on age, disability, or socioeconomic status.
  • Social scoring by public authorities or on their behalf.
  • Predictive policing based solely on profiling individuals.
  • Untargeted scraping of facial images from the internet or CCTV to build facial-recognition databases.
  • Emotion recognition in workplaces and educational institutions, with narrow exceptions.
  • Biometric categorisation that infers race, political opinions, religious beliefs, or sexual orientation.
  • Real-time remote biometric identification in public spaces by law enforcement, save for narrowly defined exceptions.

These prohibitions have applied since February 2, 2025. Penalties are the highest in the regulation: up to €35 million or 7% of worldwide annual turnover, whichever is higher.

2. High-risk (Annex III + Annex I product categories)

This is the tier most regulated companies will end up in. High-risk systems are not banned — they are permitted, but they must meet a defined set of engineering, documentation, governance, and oversight requirements before they can be placed on the market or put into service.

Annex III names eight high-risk use-case domains, including:

  • Critical infrastructure (energy, transport, water).
  • Education and vocational training (admissions, scoring, monitoring).
  • Employment, worker management, and access to self-employment (CV screening, performance evaluation, promotion decisions).
  • Access to essential private and public services (credit scoring, benefits eligibility, emergency triage).
  • Law enforcement, migration, and administration of justice.
  • Biometric identification and categorisation (where not prohibited).

In addition, AI systems that are themselves safety components of products already covered by EU product-safety legislation (medical devices, machinery, toys, lifts, in-vitro diagnostics) are automatically high-risk.

Obligations for high-risk systems include a risk-management system across the full lifecycle, data governance and bias testing, technical documentation, automatic event logging, human oversight by design, accuracy, robustness, and cybersecurity, post-market monitoring, registration in the EU AI database, and conformity assessment before market entry.

3. Limited risk (Article 50)

Limited-risk systems carry transparency obligations rather than full compliance machinery. The principle is simple: people interacting with AI should know that they are. This tier covers chatbots, AI-generated content (including deepfakes), emotion-recognition systems outside prohibited contexts, and synthetic media. Disclosure must be clear, accessible, and at first interaction.

4. Minimal risk (everything else)

The vast majority of AI systems — spam filters, AI-enabled video games, inventory-optimisation algorithms, recommendation engines for non-essential services — sit here. There are no mandatory obligations under the Act for this tier, although providers are encouraged to follow voluntary codes of conduct.

A separate, parallel set of rules applies to General-Purpose AI (GPAI) models, including most foundation models. Providers of GPAI models face transparency, copyright-compliance, and technical-documentation duties; models presenting "systemic risk" carry heavier obligations including model evaluations, adversarial testing, and incident reporting. These rules apply from August 2, 2025, with enforcement penalties for GPAI providers becoming applicable from August 2, 2026.

Key obligations and timeline

The Act phases in across four key dates. Plan your roadmap against them rather than the high-level "applies in 2026" headline.

DateWhat applies
August 1, 2024Act enters into force
February 2, 2025Prohibited practices ban + AI-literacy obligation for staff
August 2, 2025GPAI obligations (Chapter V) + governance rules + national competent authorities designated + penalty regime established
August 2, 2026Most general provisions apply (general application date); GPAI penalty enforcement begins
August 2, 2027High-risk system obligations under Annex I (regulated products) fully apply

Two consequences follow from this calendar. First, the AI-literacy obligation is already live: every organisation that operates AI in scope of the Act must ensure staff who develop, deploy, or oversee AI have a sufficient level of AI literacy, proportionate to their role. Second, if you are a GPAI provider your transparency, copyright, and technical-documentation duties are already binding (since August 2, 2025); and if you are a provider of a high-risk system, your conformity assessment, technical file, and post-market monitoring plan need to be ready before the general application date of August 2, 2026 — these are not deliverables you can compress into a final sprint.

Penalties scale with severity: up to €35M or 7% of global turnover for prohibited practices, up to €15M or 3% for high-risk non-compliance, and up to €7.5M or 1% for supplying incorrect information to authorities. SME-specific caps apply but do not eliminate exposure.

What businesses must do now

The single most common mistake we see is treating the AI Act as a 2027 problem. It is a 2026 problem with workstreams that need to start this quarter. Here is the practical sequence we use with clients.

  1. Inventory every AI system in your organisation. This includes models you build, third-party tools you embed, SaaS products with AI features, and shadow-IT pilots that nobody flagged. Until you have the list, you cannot classify, and until you classify, you cannot scope work.
  2. Classify each system into a risk tier. Use Annex III against your inventory. Decisions made about people — hiring, credit, healthcare, education, access to services — are the most likely to land in high-risk. Document the rationale for each classification: regulators will want to see the reasoning, not just the conclusion.
  3. Build a compliance documentation baseline. Even minimal-risk systems benefit from a one-page system card describing purpose, data sources, model type, owner, and review cadence. For high-risk systems, you will need full technical documentation in line with Annex IV.
  4. Stand up AI governance. Assign a named owner. Define an approval gate for new AI systems. Set a review cadence. Connect AI governance to your existing GDPR, information-security, and product-safety processes — do not build a parallel kingdom.
  5. Train your people. The AI-literacy obligation under Article 4 is already in force. Practical, role-specific training (different for executives, developers, operators, and end-users) is more defensible than a one-off awareness slide deck.
  6. Run vendor due diligence. Most companies' AI exposure comes through suppliers. Update procurement templates to require providers to declare risk tier, conformity status, technical documentation, and incident-reporting commitments. This is also where deployer obligations get easier or harder depending on what you contract for.
  7. Set up post-market monitoring for high-risk systems. Logging, drift detection, incident reporting, and a feedback loop to your risk-management process are not optional once a high-risk system is in production.

A useful rule: any AI system that *makes or materially shapes a decision about a person* is presumptively high-risk until you can prove otherwise. Start there.

Sector examples

The Act lands differently depending on your industry. Four short sketches.

HR and recruitment. AI used for CV screening, ranking candidates, scheduling interviews, or evaluating employee performance is high-risk under Annex III. The deployer (the employer) carries significant obligations: human oversight at the decision point, transparency to candidates, bias monitoring, and the right of affected individuals to receive an explanation. Plug-and-play sourcing tools that promised "AI hiring" are now compliance objects.

Healthcare. Clinical-decision-support systems, AI-driven diagnostic tools, and AI used in triage are high-risk through both Annex III (essential services) and Annex I (medical-device legislation). Compliance dovetails with MDR/IVDR — but does not replace it. Documentation, clinical evaluation, and human oversight are non-negotiable.

Financial services. Credit-scoring and creditworthiness assessment for natural persons is explicitly high-risk. Risk-pricing in life and health insurance is high-risk. Fraud detection, KYC enrichment, and algorithmic trading sit in lower tiers but inherit governance obligations through DORA and existing prudential frameworks.

Manufacturing and industrial automation. Most predictive-maintenance, quality-inspection, and process-optimisation AI is minimal-risk. The exception: AI as a safety component of machinery covered by the Machinery Regulation is automatically high-risk. The classification question turns on whether the AI is making safety-critical decisions or simply optimising throughput.

The pattern across sectors is consistent: the Act regulates AI used to make decisions that affect people. Internal-efficiency AI rarely climbs the risk ladder; customer-facing or workforce-facing AI almost always does.

How AITENCY helps with EU AI Act compliance

AITENCY is a Cyprus-based, EU-jurisdiction AI consultancy. Every engagement we run is GDPR-native and EU AI Act–aware by default. We work with EU-based and EU-serving businesses that want compliance treated as an engineering deliverable rather than a legal opinion.

Our approach is audit-first, documentation-backed, and methodology-driven:

  • AI inventory and classification. We map every AI system across your organisation — built, bought, embedded — and classify each one against the Act's risk tiers, with documented rationale.
  • Gap assessment. For each high-risk and limited-risk system, we benchmark current state against Article 9–15 obligations and produce a prioritised remediation plan.
  • Governance build-out. We design the AI governance you actually need: a named owner, an approval gate, review cadence, vendor due-diligence templates, and integration with your existing GDPR and ISO frameworks.
  • Documentation as deliverable. Technical files, system cards, post-market monitoring plans, and conformity-assessment-ready dossiers — produced in formats your auditors and regulators recognise.
  • AI-literacy training. Role-specific training for executives, builders, deployers, and operators that satisfies the Article 4 obligation and produces a defensible training record.

We do not sell legal opinions. We work alongside your legal counsel and translate regulatory requirements into systems, processes, and documentation. See our five-phase methodology and our EU-jurisdiction infrastructure stance for how we operate.

If you want to know where you actually stand against the Act, book a free process audit. We will spend 60 minutes mapping your AI surface and identifying the three most material compliance gaps — no slide deck, no upsell.

→ Explore AI Consulting & Compliance services · All AITENCY services

Common Questions

Frequently asked questions

Have a question we didn't cover? Get in touch and we'll route it to the right specialist.

Where Do You Actually Stand Against the EU AI Act?

Book a free 60-minute process audit. We'll map your AI surface and identify the three most material compliance gaps — no slide deck, no upsell.