Skip to content

Guide

The EU AI Act: a practical guide for businesses

The EU AI Act is the first comprehensive law for artificial intelligence, and it reaches far beyond the EU. This guide explains what it is, whether it applies to you, what you have to do, and the deadlines that matter, with links to go deeper on each part.

What the EU AI Act is

The EU AI Act (Regulation (EU) 2024/1689) is the world’s first comprehensive law for artificial intelligence. It regulates AI by risk: it bans a small set of unacceptable uses outright, places strict obligations on high-risk systems, adds transparency duties for limited-risk uses, and leaves minimal-risk AI largely untouched. Penalties reach up to €35M or 7% of global turnover for the most serious breaches, so it is enforceable law, not guidance.

The EU AI Act for deployers

Does the EU AI Act apply to you?

Very possibly, even outside the EU. The Act reaches providers (who build or place AI on the market) and deployers (who use AI in the course of work), and it applies extraterritorially: if your AI system is used by people in the EU, or its output is used there, the obligations can attach wherever your business sits. A UK or US company is not automatically exempt. The fastest way to know is to classify your systems and check which duties apply.

Are you a deployer? What that means

The four risk tiers

Everything hinges on classification. The Act sorts AI into four levels: prohibited (banned, such as social scoring), high-risk (allowed but heavily regulated, such as AI in recruitment, credit or critical infrastructure), limited-risk (transparency duties, such as telling people they are talking to a chatbot), and minimal-risk (most other AI, no specific obligations). Your legal duties follow directly from the tier each system falls into.

How to classify your AI systems by risk

What you actually have to do

For deployers of high-risk systems that means human oversight, using the system per its instructions, monitoring and logging, and being able to demonstrate all of it. There are transparency duties for chatbots and AI-generated content, and the AI literacy duty (below) that applies whatever the risk level. The practical work is the same either way: know your AI, classify it, and hold the evidence that it is controlled.

Deployer obligations in plain English

The timeline and deadlines

The Act phases in between 2025 and 2027. The bans on prohibited practices and the AI literacy duty have applied since February 2025. General-purpose AI model rules landed in August 2025. The bulk of the high-risk and transparency obligations apply from 2 August 2026, with a final set for AI in regulated products in 2027. Some timing may still shift under the EU’s Digital Omnibus, which is not yet finally adopted.

EU AI Act deadlines, in plain English

AI literacy (Article 4)

The most-overlooked duty, and one of the first to bite. Since February 2025, providers and deployers must ensure the people using AI on their behalf understand it well enough to use it responsibly. It is not limited to high-risk AI, it applies broadly, and it is an active obligation you own and have to evidence, not a box to hope is ticked.

AI literacy: the Article 4 duty in practice

Human oversight (Article 14)

High-risk AI must be designed so a person can effectively oversee it: understand it, catch when it goes wrong, and override or stop it. A human who rubber-stamps the output is not oversight. Real oversight means competence, authority, time and information, matched to the risk, and it is a duty shared between the provider who builds it in and the deployer who staffs it.

Human oversight in practice (Article 14)

How ISO 42001 helps you comply

The Act tells you what you must do; ISO 42001, the international standard for an AI Management System, gives you a practical, auditable way to actually do it and prove it. Building to ISO 42001 produces the inventory, risk classification, human oversight, documentation and evidence the Act expects, in a structure a regulator or customer recognises. It is one of the cleanest routes to being ready for the Act.

ISO 42001 vs the EU AI Act: how they fit together

General-purpose AI (GPAI)

The Act has a separate regime for the foundation models underneath most AI, GPT, Claude, Gemini and the like. The obligations there fall on the model makers, not on the businesses that use them. If you deploy or build on GPAI you mostly rely on the provider, with one trap to watch: substantial fine-tuning can make you a provider yourself.

GPAI: what general-purpose AI obligations mean for you

Where do you stand against the EU AI Act?

A free, self-serve check that maps your situation to the obligations that actually apply to you.

10 min No email
Take the check

EU AI Act: common questions

Does the EU AI Act apply to UK or US companies? +

It can. The EU AI Act applies extraterritorially: if your AI system is used by people in the EU, or its output is used there, the obligations can attach wherever your business is based. Being outside the EU does not automatically exempt you, so UK and US companies serving EU users or markets should check their exposure.

When does the EU AI Act come into force? +

It phases in. The ban on prohibited practices and the AI literacy duty applied from February 2025, general-purpose AI model rules from August 2025, the bulk of the high-risk and transparency obligations from 2 August 2026, and a final set for AI in regulated products in 2027.

What are the EU AI Act risk categories? +

Four: prohibited (banned outright), high-risk (allowed but heavily regulated, such as AI in recruitment or credit), limited-risk (transparency duties, such as labelling chatbots and AI-generated content), and minimal-risk (most other AI, no specific obligations).

What is a deployer under the EU AI Act? +

A deployer is any organisation that uses an AI system in the course of its work, as opposed to a provider that builds or places one on the market. Most businesses are deployers, and deployers of high-risk systems carry real duties: human oversight, monitoring, logging and the evidence to demonstrate compliance.

How do I check if my business is compliant with the EU AI Act? +

Start by classifying each AI system you use against the Act’s risk tiers to see which obligations apply, then map what you already have in place against them. Our free EU AI Act check does the first pass in about ten minutes, with no email required.

Want the same for your governance more broadly? See our AI governance guide, or the free ISO 42001 check.