The Law HQ

EU AI Act

This is our guide to the EU AI Act for artificial intelligence developers, deployers and business owners leveraging this technology. We include the purpose of the law, a checklist for businesses, and details of penalties for non-compliance with the legislation.

EU AI Act

The European Union’s Artificial Intelligence Act is the world’s first comprehensive legal framework specifically regulating artificial intelligence. It affects organisations developing AI systems, companies integrating third-party AI into products and services, and businesses using AI in areas such as recruitment, customer service, marketing, finance, healthcare and workplace management.

The Act follows a risk-based approach. Rather than treating every AI application in the same way, it imposes progressively stricter obligations depending on the potential impact of the system on people’s safety, rights and opportunities.

Although the Regulation formally entered into force on 1 August 2024, most of its provisions became applicable on 2 August 2026. Prohibited AI practices and AI literacy requirements had already applied since February 2025, while rules for general-purpose AI models began applying in August 2025.

For business owners, developers and AI deployers, August 2026 therefore represents a major compliance milestone rather than the beginning of the law itself.

 

What is the purpose of the EU AI Act?

The Act aims to encourage the development and adoption of trustworthy, human-centred AI while protecting:

  • Health and safety
  • Fundamental rights
  • Privacy and personal data
  • Democracy and the rule of law
  • Consumers and workers
  • Environmental interests

It establishes harmonised rules covering the development, sale, deployment and use of AI systems within the EU. It also introduces market surveillance, enforcement powers and substantial financial penalties.

The law operates alongside existing legislation. Compliance with the AI Act does not remove obligations under the GDPR, consumer protection laws, employment legislation, intellectual property rules, product safety requirements or sector-specific regulations.

 

Which organisations are covered?

The Act has deliberately broad territorial reach. It can apply to:

  • Providers placing AI systems or general-purpose AI models on the EU market
  • Businesses using AI systems within the EU
  • Importers and distributors of AI systems
  • Product manufacturers incorporating AI into products
  • Non-EU providers whose AI systems are offered in the EU
  • Non-EU organisations where the output of an AI system is used within the EU

This means a software company based in the UK, US or elsewhere may still fall within scope when it supplies an AI-powered service to EU customers or produces AI output used in the EU.

Purely personal, non-professional use is generally excluded. Certain military, defence, national security and pre-market research activities also fall outside the Regulation, subject to specific conditions.

 

Understanding your role: provider or deployer

One of the first compliance questions is whether an organisation is acting as an AI provider, deployer or both.

 

AI providers

A provider develops an AI system or general-purpose AI model, or has one developed, and places it on the market under its own name or trademark.

This can include organisations that:

  • Develop an AI product from scratch
  • Fine-tune an existing model and market the resulting system
  • White-label an AI tool
  • Substantially modify a third-party AI system
  • Change the intended purpose of an existing system
  • Integrate AI into a regulated product

An organisation may therefore become a provider even when it did not create the underlying foundation model.

 

AI deployers

A deployer uses an AI system under its authority as part of a professional or commercial activity.

Examples include:

  • An employer using AI to screen job applicants
  • A retailer operating an AI customer-service chatbot
  • A bank using AI to assess creditworthiness
  • A publisher using generative AI to produce articles
  • A manufacturer using computer vision for quality control
  • A marketing agency creating AI-generated advertising materials

Using a well-known third-party platform does not eliminate the deployer’s responsibilities. Businesses remain responsible for how they configure, supervise and use the system.

 

The EU AI Act’s risk categories

The Act broadly divides AI systems into four levels of risk.

 

1. Prohibited or unacceptable-risk AI

Certain practices are considered incompatible with EU values and are prohibited.

These include, subject to detailed definitions and exceptions:

  • AI using harmful subliminal, manipulative or deceptive techniques
  • AI exploiting vulnerabilities associated with age, disability or particular social or economic circumstances
  • Certain forms of social scoring
  • Predictive policing based solely on profiling or personality traits
  • Indiscriminate scraping of facial images to build recognition databases
  • Certain emotion-recognition systems in workplaces and educational institutions
  • Biometric categorisation based on particularly sensitive characteristics
  • Most real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes, except in narrowly defined circumstances

These prohibitions have applied since 2 February 2025.

Businesses should not assume that a common commercial use case is automatically permissible. Emotion recognition, employee monitoring, behavioural influence and biometric classification require particularly careful legal review.

 

2. High-risk AI

High-risk AI systems are permitted, but they are subject to extensive governance, documentation, testing and monitoring requirements.

There are two main routes into the high-risk category.

The first covers AI used as a safety component of certain regulated products, or AI that is itself such a product. Examples can include machinery, medical devices, vehicles, aviation systems, lifts, toys and protective equipment where third-party conformity assessment is required.

The second covers specified sensitive use cases, including AI used in:

  • Biometric identification and categorisation
  • Critical infrastructure
  • Education and vocational training
  • Employment, worker management and access to self-employment
  • Access to essential private and public services
  • Credit scoring and certain insurance assessments
  • Law enforcement
  • Migration, asylum and border control
  • Administration of justice
  • Certain democratic processes

Under the current implementation timetable, many requirements for high-risk systems listed in Annex III are scheduled to apply from 2 December 2027, while requirements for AI embedded in regulated products have a longer transition period extending to 2 August 2028.

 

Typical provider obligations for high-risk systems

Providers may need to establish:

  • A documented risk-management system
  • Data governance and data-quality controls
  • Technical documentation
  • Automatic event logging
  • Instructions for deployers
  • Human oversight mechanisms
  • Appropriate accuracy, robustness and cybersecurity
  • Quality-management systems
  • Conformity assessment procedures
  • Registration in the relevant EU database
  • Post-market monitoring
  • Serious incident reporting

The system must be assessed throughout its lifecycle, not simply approved once before launch.

 

Typical deployer obligations for high-risk systems

Deployers may need to:

  • Follow the provider’s instructions
  • Assign suitably qualified human oversight
  • Monitor the operation of the system
  • Maintain logs under their control
  • Ensure input data is relevant and sufficiently representative
  • Report serious incidents and risks
  • Suspend use where the system presents a significant risk
  • Inform workers or representatives where workplace AI is introduced
  • Conduct a fundamental rights impact assessment in certain circumstances
  • Inform affected people when AI is used to make or support decisions about them

For employers, lenders, education providers and public-service organisations, these responsibilities can be as important as the technical obligations placed on developers.

 

3. Transparency-risk AI

Article 50 contains some of the most immediately relevant provisions for ordinary businesses using generative or interactive AI. These rules apply from 2 August 2026.

They cover four principal situations.

 

Chatbots and directly interactive AI

Providers must design AI systems intended to interact directly with people so that users are informed that they are interacting with AI.

Disclosure is not required where this would be obvious to a reasonably well-informed, observant and circumspect person in the circumstances.

In practice, companies should not rely too heavily on the “obvious” exception. A prominent statement such as “You are chatting with an AI assistant” is normally safer than assuming customers will recognise the technology.

The disclosure must be given no later than the first interaction and must be clear, distinguishable and accessible.

 

Machine-readable marking of AI content

Providers of systems that generate synthetic text, audio, images or video must ensure that outputs are marked in a machine-readable format and are detectable as artificially generated or manipulated.

The technical measures should be effective, interoperable, robust and reliable as far as technically feasible. The law allows consideration of implementation costs, the nature of the content and the state of the art.

This obligation primarily falls on the provider of the generative system. However, business customers should confirm that purchased tools support compliant marking and that internal processes do not strip out relevant metadata or provenance information.

Standard assistive editing that does not substantially alter the meaning of user-supplied content may fall outside this requirement. Minor photo correction or grammar assistance may therefore be treated differently from fully generated articles, synthetic voices or fabricated video.

 

Deepfake disclosure

Deployers publishing or distributing artificially generated or manipulated image, audio or video content constituting a deepfake must disclose its artificial nature.

Artistic, fictional, satirical and creative works receive more flexible treatment. Disclosure is still required, but it may be presented in a way that does not unreasonably disrupt the audience’s enjoyment of the work.

Businesses should apply this rule to areas such as:

  • Synthetic presenters
  • AI-generated customer testimonials
  • Digitally recreated executives
  • Voice cloning
  • Manipulated product demonstrations
  • Political or public-affairs content
  • AI-generated training scenarios depicting real people

Consent, personality rights, consumer protection and advertising rules may also apply.

 

AI-generated public-interest text

Deployers must disclose when AI-generated or AI-manipulated text is published for the purpose of informing the public about matters of public interest.

There is an important exception where the content has undergone human review or editorial control and a natural or legal person accepts editorial responsibility for it.

A publisher that merely performs a superficial check should be cautious about relying on this exception. Businesses should be able to demonstrate meaningful review, fact-checking and responsibility for the final publication.

 

Emotion recognition and biometric categorisation

Deployers operating emotion-recognition or biometric-categorisation systems must inform the people exposed to them.

Any associated personal-data processing must also comply with the GDPR or other applicable data-protection legislation.

Examples could include systems intended to infer:

  • Customer sentiment
  • Employee engagement
  • Attention during online training
  • Emotional responses during interviews
  • Stress or fatigue
  • Demographic or biometric categories

Some uses, particularly emotion recognition in workplaces and education, may already be prohibited rather than merely subject to transparency.

 

4. Minimal or no-risk AI

Most AI systems currently used in the EU are expected to fall into the minimal or no-risk category. Examples can include spam filters, AI-enabled games, basic recommendation tools and certain administrative systems.

The AI Act does not impose a comprehensive mandatory regime on these applications, although other laws still apply.

Organisations may also voluntarily adopt codes of conduct, risk assessments and transparency practices for lower-risk systems.

 

General-purpose AI models

General-purpose AI models, or GPAI models, are models capable of performing a broad range of tasks and supporting many downstream systems.

Providers of GPAI models have obligations including:

  • Maintaining technical documentation
  • Providing information to downstream system providers
  • Establishing a policy for compliance with EU copyright law
  • Publishing a sufficiently detailed summary of the content used for training
  • Cooperating with the European Commission and AI Office

Providers of models presenting systemic risk face additional obligations involving model evaluation, adversarial testing, systemic-risk assessment, incident reporting and cybersecurity.

The substantive GPAI obligations began applying in August 2025, while the Commission’s enforcement powers became operational from 2 August 2026. Legacy models placed on the market before August 2025 have a longer compliance period extending to August 2027.

Businesses building applications on top of a GPAI model should obtain sufficient information from the model provider to understand limitations, intended uses, risks and compliance responsibilities.

 

AI literacy is a legal obligation

Article 4 requires providers and deployers to take measures, to the best of their ability, to ensure an adequate level of AI literacy among employees and other people operating AI systems on their behalf.

Training should reflect:

  • The person’s role
  • Technical knowledge and experience
  • The context in which the AI is used
  • The risks associated with the system
  • The people or groups affected by its use

A one-off generic awareness course is unlikely to be sufficient for every organisation. Recruitment staff using candidate-screening AI need different knowledge from software engineers, marketing teams or customer-service employees.

An effective programme should cover approved AI tools, prohibited uses, data protection, human review, hallucinations, bias, intellectual property, cybersecurity, incident reporting and escalation procedures.

 

Why transparency matters beyond labelling

Transparency is not merely a requirement to add a small “AI-generated” notice.

Recent research highlighted by EUobserver found that people using chatbots to explore political questions may find it harder to distinguish their own views from interpretations introduced by the system. The researchers warned that chatbot responses can shape how users understand policies and candidates, with training-data imbalances potentially underrepresenting minority perspectives.

This illustrates a wider issue for businesses. AI can influence users even when it does not issue an explicit instruction or make a formal decision.

A customer-service bot may frame the available remedies. A financial assistant may influence attitudes to risk. A recruitment tool may determine which experience appears relevant. A learning assistant may present one interpretation as authoritative.

Responsible transparency should therefore explain not only that AI is present, but where appropriate:

  • What the system is intended to do
  • What information it uses
  • What its main limitations are
  • Whether a human can review its output
  • How a person can challenge a decision
  • Where to report a concern

 

Penalties for non-compliance with the AI Act

The maximum penalties vary according to the infringement.

Use of prohibited AI practices can result in fines of up to:

  • €35 million, or
  • 7% of total worldwide annual turnover for the preceding financial year

Breaches of several other obligations, including Article 50 transparency obligations, can result in fines of up to:

  • €15 million, or
  • 3% of total worldwide annual turnover

Supplying incorrect, incomplete or misleading information to authorities can result in fines of up to:

  • €7.5 million, or
  • 1% of total worldwide annual turnover

For undertakings, the applicable maximum is generally whichever is higher. For SMEs, including start-ups, the lower of the relevant percentage or fixed amount applies. Actual penalties must be effective, proportionate and dissuasive, with factors such as severity, duration, cooperation and mitigating action taken into account.

Reputational damage, contractual disputes, product withdrawal, corrective orders and GDPR penalties may create additional exposure.

 

A practical compliance checklist for business deployers

1. Create an AI inventory

Record every AI system used across the organisation, including unofficial or departmental tools.

For each system, document:

  • Business owner
  • Supplier and model
  • Intended purpose
  • People affected
  • Data processed
  • Outputs produced
  • Integration points
  • Geographic use
  • Whether the organisation modifies or rebrands it

 

2. Classify each use case

Determine whether the system is:

  • Prohibited
  • Potentially high-risk
  • Subject to Article 50 transparency duties
  • A lower-risk system
  • Based on a GPAI model

Classification should focus on the intended purpose and real use, not simply the supplier’s marketing description.

 

3. Establish organisational roles

Assign accountability across:

  • Senior leadership
  • Legal and compliance
  • Data protection
  • Information security
  • Procurement
  • Human resources
  • Product development
  • Marketing and communications
  • Operational teams

Avoid treating AI compliance solely as an IT project.

 

4. Review suppliers

Request information about:

  • AI Act role and classification
  • Training data and copyright controls
  • Technical documentation
  • Human oversight features
  • Logging and auditability
  • Machine-readable content marking
  • Security testing
  • Incident history
  • Model updates
  • Subcontractors
  • Data retention
  • EU representation where applicable

Contracts should allocate responsibilities for regulatory change, incidents, documentation and cooperation with authorities.

 

5. Introduce human oversight

Define when employees must:

  • Review AI output
  • Reject or override recommendations
  • Escalate unusual results
  • Obtain specialist approval
  • Inform an affected person
  • Stop using the system

Human oversight must be meaningful. Requiring an employee to click “approve” without enough information, time or authority is unlikely to provide effective protection.

 

6. Implement Article 50 disclosures

Check customer-facing chatbots, synthetic media, AI-generated articles, voice systems and biometric technologies.

Ensure disclosures are:

  • Timely
  • Prominent
  • Understandable
  • Accessible
  • Appropriate to the channel
  • Preserved when content is republished

 

7. Build an AI literacy programme

Provide role-specific training and maintain records showing:

  • Who received training
  • What was covered
  • When it was completed
  • How understanding was assessed
  • When refresher training is due

 

8. Create incident and complaint procedures

Employees and customers should know how to report:

  • Discriminatory output
  • Unsafe recommendations
  • Hallucinations
  • Security weaknesses
  • Misleading AI content
  • Unexpected model behaviour
  • Privacy concerns
  • Failure of human oversight

 

9. Retain evidence

Maintain evidence of classification decisions, risk reviews, supplier assessments, human review, disclosures, testing, incidents and corrective action.

Compliance must be demonstrable, not merely asserted.

 

10. Monitor changes

AI systems can change through model updates, new data, fine-tuning, integrations and altered use cases.

A low-risk tool used for drafting internal notes could become significantly more regulated if it is later used to assess employees, determine access to services or publish public-interest information.

 

A practical compliance checklist for AI developers and providers

Developers and providers should:

  1. Define and document the system’s intended purpose.
  2. Identify foreseeable misuse.
  3. Determine whether the organisation is providing an AI system, GPAI model or high-risk system.
  4. Build regulatory requirements into the development lifecycle.
  5. Document training, validation and testing data.
  6. Test for bias, robustness, accuracy and cybersecurity.
  7. Design effective human oversight.
  8. Implement logging and traceability.
  9. Add compliant machine-readable markings to synthetic output.
  10. Provide clear instructions and limitations to deployers.
  11. Establish post-market monitoring.
  12. Create incident-reporting and corrective-action procedures.
  13. Review whether modifications create a new system or change its classification.
  14. Maintain evidence supporting conformity and compliance.
  15. Ensure sales and marketing claims match the documented intended purpose.

The Commission’s voluntary Code of Practice on Transparency of AI-generated Content provides one route for demonstrating compliance with relevant marking and labelling obligations. Organisations that do not follow the Code must be prepared to demonstrate compliance through other adequate measures.

 

What businesses should do now

The most important immediate step is to stop treating “AI use” as a single activity.

An organisation may simultaneously be:

  • A deployer of a commercial chatbot
  • A provider of a customised internal model
  • A publisher of AI-assisted content
  • An employer using AI-supported recruitment
  • A buyer of a high-risk system
  • A supplier producing AI output for EU clients

Each activity can attract different responsibilities.

Businesses should prioritise their most consequential use cases first: systems affecting employment, credit, essential services, health, safety, education, biometrics or public information. They should then address high-volume generative AI use, particularly where customers cannot easily tell whether they are dealing with a person or machine.

The EU AI Act should not be approached simply as a barrier to innovation. Organisations with clear governance, trained employees, traceable decisions and transparent customer communications may be able to adopt AI more confidently than competitors relying on uncontrolled experimentation.

The central compliance principle is straightforward: know which AI systems the organisation uses, understand how they affect people, allocate responsibility and preserve evidence that risks are being actively managed.

 

This guide provides general information and is not a substitute for legal advice relating to a particular AI system, product or deployment.

 

Scroll to Top