What the EU AI Act actually requires from your business
AI Compliance April 2026 · 8 min read
When the EU AI Act was passed in 2024, most businesses dismissed it as something that would only affect technology companies building AI systems. Two years later, with enforcement already active, the reality is very different. The regulation applies to any business that uses AI — not just those that build it. And the majority of European businesses are using AI right now, often without realising it.
This article explains what the EU AI Act actually requires, who it applies to, and what practical steps businesses need to take before the deadline.
What is the EU AI Act?
The EU AI Act (Regulation EU 2024/1689) is the world’s first comprehensive legal framework for artificial intelligence. It creates a risk-based classification system for AI systems — meaning the stricter the rules, the higher the risk of the system in question. Think of it as GDPR, but for AI rather than personal data.
Like GDPR, the Act applies to all businesses operating in the EU, regardless of where they are based. A Portuguese accounting firm, a Belgian logistics company, a Spanish law firm — all of them fall under the regulation if they use AI in their operations.
“The majority of European businesses are already using AI — many without knowing it. The question is no longer whether the Act applies. It is whether you are prepared.”
The four risk levels
The Act classifies AI systems into four categories, each with different obligations:
| Risk Level | Examples | Obligations |
|---|---|---|
| Prohibited | Social scoring by public authorities, subliminal manipulation, real-time biometric surveillance in public spaces | Complete ban — no exceptions |
| High Risk | CV screening tools, credit scoring, medical diagnostics, educational assessment systems | Full compliance documentation, human oversight, registration in EU database |
| Limited Risk | Chatbots, AI-generated content, virtual assistants | Transparency obligations — users must know they are interacting with AI |
| Minimal Risk | Spam filters, autocorrect, recommendation engines | No specific obligations — good practice recommended |
Who is actually affected?
The short answer: almost every business. Here is why.
The Act covers any organisation that deploys or uses an AI system — not just those that develop them. If your business uses any of the following, you have obligations under the Act:
- ChatGPT, Microsoft Copilot, or similar generative AI tools used by employees for work tasks
- Accounting or ERP software with automatic categorisation, anomaly detection, or forecasting features (PHC, Sage, Primavera)
- CRM platforms with lead scoring or customer behaviour prediction (Salesforce, HubSpot)
- Website chatbots that interact with customers or prospects
- HR software with any form of automated CV screening or employee assessment
- Any tool described as having “smart”, “intelligent”, “predictive”, or “automatic” features
The obligations that apply to most businesses
Transparency with employees and clients
Article 50 of the Act requires that when a person interacts with an AI system, they must be informed. This means chatbots must identify themselves as AI. Emails, reports, or proposals generated with AI assistance must include a disclosure note. The obligation is not burdensome — but it must be in place.
An internal AI policy
Businesses need a written policy governing how AI is used internally. This document should define which systems are approved, what data can be entered into them, and what decisions cannot be made by AI alone. It must be communicated to all employees.
An inventory of AI systems
You cannot manage what you have not mapped. The Act requires organisations to know which AI systems they use, what data those systems process, and how they classify in terms of risk. This inventory must be kept up to date.
Supplier due diligence
If the AI system is provided by a third party — which is almost always the case — you need to understand how that supplier handles your data. Are their servers within the EU? Do they use your data to train their models? Do they have documentation showing their system complies with the Act? These are questions you are now legally responsible for asking.
What happens if you do not comply?
The financial penalties mirror GDPR in their severity. Article 99 sets fines at up to €35 million or 7% of global annual turnover for the most serious violations, and up to €15 million or 3% for general non-compliance. For a small business with €500,000 in annual revenue, that upper limit represents €15,000 — for not having an AI policy document.
Beyond fines, the commercial risk is significant. Large companies are already including AI compliance clauses in their supplier contracts, mirroring what happened with GDPR. A business without documentation risks losing contracts with clients that require proof of compliance.
Where to start
The most important first step is understanding where you stand. An AI compliance audit maps your current AI exposure, identifies which systems carry which level of risk, and produces a prioritised action plan. From there, the work is methodical: draft the policy, build the inventory, contact your software suppliers, and add transparency notes to your communications.
None of this requires a legal team or a technology department. It requires clarity about what you use, and a structured approach to documenting it.
The regulation is active. Businesses that act now arrive prepared — with their documentation complete and their operations protected.