Why the EU AI Act concerns more companies than expected
Many business owners assume the EU AI Act is a problem for technology giants and a handful of specialist developers. In practice, the regulation reaches far wider. The moment a company builds, sells, integrates or even just uses an AI system in its operations, it may fall within scope. A recruitment tool that screens candidates, a chatbot that handles customer enquiries, a credit-scoring model or an analytics service that profiles users can all bring obligations with them, often without anyone in the organisation having framed it as an “AI project”.
The AI Act is the world’s first comprehensive horizontal law on artificial intelligence. It does not regulate a single sector but applies across the economy, and it follows a logic that will be familiar to anyone who has worked with the GDPR: the more an AI system can affect people, the heavier the obligations become. This article explains how the law is structured, which rules apply and when, and how a company can prepare in a measured way rather than reacting to headlines.
A risk-based law, not a blanket ban
The central idea of the AI Act is that AI systems are sorted by the level of risk they pose, and that the requirements scale with that risk. Most everyday systems carry little or no regulatory burden, while a smaller number of high-impact uses carry significant obligations. Understanding which tier a system falls into is therefore the first practical step for any company.
Prohibited practices
At the top of the scale sit a limited number of practices that are simply prohibited. These include, for example, AI used for social scoring of individuals, certain forms of manipulative systems that exploit vulnerabilities, and untargeted scraping of facial images to build recognition databases. For most ordinary businesses these prohibitions are not a daily concern, but it is worth confirming that no tool in use crosses one of these lines.
High-risk systems
The heart of the regulation is the category of high-risk AI systems. These are uses where a malfunction or misuse could materially affect people’s safety or fundamental rights. The law lists areas such as AI used in recruitment and worker management, access to education, creditworthiness assessments, certain critical infrastructure and the operation of essential public and private services. A company that develops or deploys a system in one of these areas faces the most demanding requirements: risk management, data governance, technical documentation, human oversight, transparency towards users and a defined level of accuracy and robustness.
Limited-risk and minimal-risk systems
Below the high-risk tier sit systems with limited risk, where the main obligation is transparency. A chatbot, for instance, should make clear to the person that they are interacting with a machine, and certain artificially generated or manipulated content should be labelled as such. The large remainder of AI applications, from spam filters to recommendation features, fall into the minimal-risk category and carry no specific obligations under the Act, though general law continues to apply.
General-purpose AI and the role of the user
The Act also addresses general-purpose AI models, the large foundation models that sit behind many familiar tools. Providers of these models carry their own transparency and documentation duties, and additional obligations attach to the most capable models that could pose systemic risks. The rules on general-purpose AI began to apply from August 2025.
For most companies the more relevant question is not whether they build such a model, but how they use one. When a business integrates a general-purpose model into its own product or workflow, it needs to understand what it is responsible for. Deploying a model in a high-risk context can pull the company into the obligations that attach to that use, and relying on a third-party tool does not transfer away that responsibility. Knowing your role in the chain, as provider, deployer or distributor, is therefore central to assessing your duties.
When the rules apply: a timeline in motion
The AI Act entered into force in 2024 and is being phased in over several years rather than all at once. The prohibitions on unacceptable practices and the first requirements on AI literacy began to apply in early 2025. The obligations for general-purpose AI models followed in August 2025. The bulk of the remaining rules, including most of the high-risk requirements, were originally set to apply from August 2026.
A caveat is important here, and it reflects how quickly this area moves. During 2026 EU institutions reached a provisional agreement, often referred to as the Digital Omnibus, that would defer several of the high-risk deadlines, in particular pushing the application date for certain high-risk systems beyond 2026 and into late 2027. At the time of writing this change has not been finally adopted and published, so it remains a proposal rather than settled law. The sensible reading is that the direction of travel is clear but the exact dates may shift. A company should prepare on the assumption that high-risk obligations are coming, while keeping an eye on the final deadlines as they are confirmed.
Practical example: the recruitment tool nobody classified
Consider a growing company that buys an AI-based tool to screen job applications and rank candidates. The tool is convenient, saves the HR team hours each week and is adopted without much fuss. What nobody did was ask where this system sits in the AI Act’s risk model.
AI used to evaluate candidates in recruitment is precisely the kind of application the law treats as high-risk, because it can shape people’s access to employment. That classification brings obligations around human oversight, transparency to candidates, documentation and the quality of the data the system relies on. It also overlaps with GDPR duties on automated decision-making and with discrimination law if the model produces biased outcomes. The company that simply switched the tool on, without assessing any of this, has quietly taken on a compliance exposure that a short review before purchase would have surfaced and made manageable.
Common mistakes companies make
The first mistake is assuming the law does not apply because the company is “not an AI company”. The Act follows the use, not the label. A business that has never written a line of model code can still be a deployer of a high-risk system simply by using one.
The second mistake is treating the AI Act as separate from everything else. In reality it overlaps heavily with the GDPR, with sector rules and with employment and consumer law. An AI system that processes personal data raises questions under both regimes at once, and a compliance effort that looks at only one will leave gaps.
The third mistake is waiting for the final deadline before doing anything. Building documentation, mapping which systems are in use and clarifying responsibilities take time. Companies that start when the deadline arrives tend to discover that the groundwork should have begun much earlier.
Legal risks
The AI Act is backed by a sanction regime comparable in ambition to the GDPR. The most serious infringements, such as using a prohibited practice, can lead to administrative fines at the highest tier, calculated as a substantial fixed ceiling or a percentage of global annual turnover, whichever is higher. Breaches of the high-risk obligations carry lower but still significant maximum penalties.
As with data protection, the financial penalty is not the only exposure. A supervisory authority can require a non-compliant system to be withdrawn or brought into line, which may mean replacing a tool the business depends on. There is reputational risk where an AI system is shown to treat people unfairly, and there is commercial risk, since larger customers and public buyers increasingly ask suppliers to demonstrate responsible and documented use of AI.
Recommended actions
Start by creating an inventory of the AI systems your organisation builds, buys or uses, including features embedded in larger software you already rely on. Without this map it is impossible to know which obligations apply. For each system, identify your role, whether you are a provider, a deployer or something in between, and place the system in the right risk tier.
For anything that falls into the high-risk category, begin building the supporting structure early: human oversight arrangements, documentation, data-quality checks and transparency towards the people affected. Treat AI and data protection together rather than in separate silos, since the same system usually raises both sets of questions. Invest in basic AI literacy across the teams that use these tools, and document the assessments you make. Finally, keep the review recurring and watch the evolving deadlines, because both your own use of AI and the legal position will continue to change.
Frequently asked questions about the EU AI Act
Does the AI Act apply to us if we only use AI tools rather than build them?
Quite possibly, yes. The Act places obligations on deployers, not only developers. If you use an AI system in a high-risk context, such as recruitment or credit assessment, duties around oversight, transparency and documentation can apply to you even though you did not build the tool.
How do we know if a system is high-risk?
High-risk uses are defined by the area of application, such as employment, education, creditworthiness, essential services and certain safety-critical products. The practical step is to compare each system you use against these areas. Where there is doubt, it is wise to assess it carefully rather than assume the lighter category applies.
When do the rules actually start to apply?
The Act is being phased in. Prohibitions and AI-literacy provisions applied from early 2025 and general-purpose AI rules from August 2025. Most high-risk obligations were set for August 2026, though a provisional 2026 agreement may defer several of these dates into 2027. Because this is still being finalised, you should prepare for the obligations while confirming the exact deadlines as they settle.
How does the AI Act relate to the GDPR?
They are separate laws that frequently apply at the same time. An AI system that processes personal data must satisfy the GDPR’s requirements on lawful basis, transparency and automated decision-making as well as the AI Act’s requirements. The most efficient approach is to address both together rather than as unrelated projects.
Conclusion
The EU AI Act is not a niche concern for developers but a framework that touches almost any company using modern software. The challenge is rarely bad intent; it is that AI has entered everyday tools so quietly that few organisations have stopped to ask which systems they use, what those systems do and who is responsible for them. Companies that map their systems, classify them honestly and document their reasoning will be well placed, and will avoid unpleasant surprises when a customer, an authority or a deadline starts asking questions.
Lawgent helps companies understand how the AI Act applies to their specific tools, classify their systems correctly and build a compliance structure that holds even as the deadlines and details continue to move. We combine experienced business-law advice with AI-driven efficiency, so that you reach secure and documented compliance faster and more cost-effectively than at a traditional firm. Want to know where your AI use stands under the new rules? Contact Lawgent for a review of your AI systems.