The EU AI Act became law in August 2024. Full enforcement is phased over two years, but several provisions, including bans on certain AI practices and requirements for high-risk systems, are already active or soon will be. If your business uses AI tools, deploys AI-powered products, or operates in any EU market, this regulation applies to you whether you are based in the EU or not.
This is not a compliance document. It is a practical briefing for business leaders who need to understand what the law requires, how to assess their exposure, and what to do about it without getting lost in the legislative text.
Why This Matters Beyond Compliance
Most regulation creates compliance obligations. The EU AI Act does that, but it also does something more significant: it establishes a framework that other jurisdictions are likely to follow. The UK, Canada, Brazil, and several APAC regulators are watching closely. Getting to grips with the EU Act now positions you to adapt as global AI governance converges around similar principles.
There is also a commercial dimension. Organisations that can demonstrate responsible AI use, documented governance, clear risk assessments, human oversight mechanisms, will find it easier to win enterprise contracts and build trust with customers. Compliance is a floor. Governance is a differentiator.
The Four Risk Tiers
The Act classifies AI systems into four risk categories. Where your systems fall determines what you must do.
Unacceptable Risk — Prohibited
Certain AI applications are banned outright. These include social scoring systems used by governments, real-time biometric surveillance in public spaces (with narrow law enforcement exceptions), AI that exploits vulnerabilities in specific groups (cognitive impairment, age, disability), and subliminal manipulation techniques designed to cause harm. If you are deploying anything in this territory, stop. The prohibition applies from August 2024.
High Risk — Significant Compliance Requirements
High-risk AI systems face the most extensive requirements. This category covers AI used in critical infrastructure, education and vocational training, employment and HR decisions, essential private and public services, law enforcement, migration control, and administration of justice. It also covers safety components of regulated products (medical devices, vehicles, industrial machinery).
If you use AI for CV screening, performance management, credit scoring, insurance underwriting, or clinical decision support, you are likely operating in high-risk territory. Requirements include conformity assessments before deployment, technical documentation, logging and auditability, human oversight mechanisms, and registration in a public EU database.
Limited Risk — Transparency Obligations
AI systems that interact with users must disclose that they are AI. Chatbots must identify themselves. AI-generated content (deepfakes, synthetic media) must be labelled. Emotion recognition and biometric categorisation systems face additional transparency requirements. These obligations apply to a large number of common business tools.
Minimal Risk — No Specific Requirements
The majority of AI applications, spam filters, recommendation engines, AI-assisted document drafting, fall into the minimal risk category. No specific compliance requirements apply here, though general product liability and data protection law still governs their use.
Who the Act Applies To
The EU AI Act has extraterritorial reach, similar to GDPR. It applies to:
- Providers who place AI systems on the EU market or put them into service in the EU (regardless of where the provider is established)
- Deployers — organisations that use AI systems in a professional context within the EU
- Any organisation placing AI systems into service that affect people in the EU, even if operating from outside
If you are a UK-based business selling into EU markets, deploying AI tools with EU employees, or building products used by EU customers, you are within scope. The territorial reach is broad and intentionally so.
The Compliance Timeline
The Act phases in over two years from August 2024:
- February 2025 — Prohibition on unacceptable risk AI applies
- August 2025 — Obligations for general-purpose AI (GPAI) models apply; governance and transparency rules for high-risk AI providers begin
- February 2026 — High-risk AI systems in Annex I (regulated products) must comply
- August 2026 — Full application: all high-risk AI systems covered by Annex III must comply
If you are reading this in mid-2026, the full framework is now in effect. Organisations that have not yet conducted an AI inventory and risk classification are behind the compliance curve.
General Purpose AI: A Special Category
The Act includes specific provisions for general-purpose AI (GPAI) models, foundation models like the large language models underlying most modern AI tools. Providers of GPAI models must provide technical documentation, comply with copyright law, and publish summaries of training data. Models deemed to pose systemic risk (those trained with more than 10^25 FLOPs) face additional obligations including adversarial testing and incident reporting.
For most organisations, this is not directly your problem, it applies to the organisations building foundation models, not those using them. However, it does affect your vendor selection: GPAI providers operating in the EU must meet these obligations, and their compliance posture affects your own.
What to Do Now: An Audit Framework
Whether you are starting from scratch or need to review existing practices, the same five steps apply.
1. Inventory Your AI Systems
List every AI system your organisation uses or deploys, purchased tools, vendor-supplied features, custom-built models, and AI components embedded in third-party software. Most organisations discover they have more AI in use than they thought, including tools adopted without central oversight.
2. Classify Risk
For each system in your inventory, determine which risk tier it falls into. The key question for high-risk classification is whether the system is used in a regulated sector (health, financial, employment, education) or whether it makes or significantly influences decisions affecting individuals' legal rights or access to services.
3. Identify Compliance Gaps
For high-risk systems, assess your current state against the requirements: Do you have technical documentation? Are logs maintained? Is there a human review mechanism? Are systems registered in the EU database? For limited-risk systems, check whether transparency disclosures are in place.
4. Assign Accountability
Designate someone responsible for AI Act compliance. This does not need to be a dedicated role in most organisations, it can sit with your AI governance lead, your DPO, or a senior technology executive. What matters is that someone owns it.
5. Create or Update Your AI Policy
If you do not already have one, now is the time. An AI policy that addresses sanctioned tools, data classification, human oversight requirements, and review processes provides the governance scaffolding that regulators will expect to see if questions arise.
The Penalties
Non-compliance carries significant financial exposure. Violations relating to prohibited AI practices can attract fines of up to €35 million or 7% of global annual turnover, whichever is higher. Violations of other obligations can attract fines up to €15 million or 3% of turnover. For SMEs, capped amounts apply where they would be disproportionate.
Regulators have indicated that initial enforcement priority will focus on high-risk sectors and systemic violations rather than technical non-compliance by smaller organisations acting in good faith. But documented good faith, showing you conducted an inventory, assessed risk, and put governance in place, is your best protection.
What This Means in Practice
For most business leaders, the EU AI Act does not require wholesale changes to how you use AI. It does require you to know what AI you are using, understand the risk profile, and have governance in place proportionate to that risk.
The organisations that will struggle most are those that have adopted AI broadly and rapidly without governance, where tools have proliferated across departments without inventory, where data handling has been informal, and where no one person owns the question of AI risk. The Act is as much a prompt to get organised as it is a specific compliance framework.
Start with the inventory. Everything else follows from knowing what you have.