EU AI Act: What Does It Actually Mean for Your Business?

TL;DR

Milestone Date Status
Act enters into force Aug 1, 2024 In effect
Prohibited practices + AI literacy Feb 2, 2025 In effect
GPAI models, governance, penalties Aug 2, 2025 In effect
Broad applicability Aug 2, 2026 In effect
High-risk (Annex III use cases) Dec 2, 2027 Transition
High-risk in regulated products Aug 2, 2028 Transition

For most companies, the practical starting point is to identify where AI is being used, determine the organisation's role, classify the relevant systems and risks, and maintain evidence showing how those risks are being managed.

Key Takeaways

  • The EU AI Act does not treat every AI system the same. Obligations depend on the organisation's role, the AI system, and its intended use.
  • The AI Act entered into force on August 1, 2024, while its requirements are being introduced progressively.
  • Prohibited AI practices began applying on February 2, 2025, while governance and general-purpose AI model obligations began applying on August 2, 2025.
  • The Act is broadly applicable from August 2, 2026, but certain high-risk AI rules now have extended transition periods under the 2026 Digital Omnibus.
  • Penalties can reach €35 million or 7% of worldwide annual turnover, depending on the infringement.
  • The practical starting point is an AI inventory that identifies systems, vendors, use cases, owners, data, human oversight, and evidence of controls.

The EU AI Act is here, and parts of it are already starting to take effect. But for most companies, the real question is not "what does the law say?" It is "what does this actually mean for me?"

What Does the EU AI Act Mean for Your Business?

The answer depends on what you are doing with AI. Are you building an AI system? Using one internally? Selling AI into the EU? Using a general-purpose AI model? Putting AI in a product that touches hiring, credit, education, law enforcement, healthcare, safety, or other regulated areas? The AI Act does not treat all AI the same. Your obligations depend on your role, your use case, and the level of risk.

The AI Act entered into force on August 1, 2024. The first rules started applying on February 2, 2025, including AI literacy obligations and a comprehensive set of prohibited AI practices, meaning banned AI practices had to stop by that date. General-purpose AI model obligations, governance rules, and penalties began applying on August 2, 2025, subject to certain transition periods. From there, the phasing continues: most remaining obligations apply from August 2, 2026, while certain high-risk AI systems now have extended transition periods under the 2026 Digital Omnibus, including high-risk AI systems embedded in regulated products, such as medical devices and machinery, which have until August 2, 2028. Certain high-risk use cases covered by Annex III have until December 2, 2027. So the work now is less about waiting for “the AI Act deadline” and more about figuring out which parts apply to your business, in what role, and when.

EU AI Act: Practical Starting Point

  1. What AI are we using?
  2. Are we building it, deploying it, or relying on a vendor?
  3. Does it touch customers, employees, or regulated decisions?
  4. Is it prohibited, high-risk, GPAI, transparency-related, or lower-risk?
  5. What evidence do we have that it is being managed?

How Should Companies Start an EU AI Act Compliance Inventory?

The work starts with an inventory. Not a perfect spreadsheet that gets stale in a month, but a real map of where AI shows up in the business. This includes product features, internal tools, vendor systems, and workflows that affect customers, employees, or regulated decisions. That means understanding where AI is generating, classifying, recommending, summarizing, detecting, scoring, or deciding.

From there, the question becomes ownership. Who knows what the system does? What data does it use? Who is the vendor? Which humans review the output? What logs exist? What happens when the system is wrong?

Why Is AI Governance an Evidence Exercise?

That is the real shift under the EU AI Act. AI governance is no longer just a policy statement or a procurement checklist. It is an evidence exercise. Companies will need to show that they know where AI is being used, how risk is being classified, what controls are in place, and whether those controls are actually working.

The companies that are best prepared will be the ones that can connect their AI policies to real controls, evidence, and accountability.

What Are the Potential EU AI Act Penalties?

The financial exposure can be significant. For certain infringements involving prohibited AI practices or specific data requirements, fines can reach €35 million or 7% of a company's total worldwide annual turnover for the preceding financial year, whichever is higher. Other breaches can attract fines of up to €15 million or 3% of worldwide annual turnover, while supplying incorrect, incomplete, or misleading information can result in fines of up to €7.5 million or 1%.

For companies, this makes classification, documentation, oversight, and evidence more than administrative exercises. They are part of the practical compliance framework.

FAQ

Does every company using AI have the same obligations?

No. Obligations depend on factors including the organisation's role, the AI system involved, and the system's intended purpose and risk classification. The AI Act uses a risk-based framework rather than imposing identical requirements on every AI use case.

Is AI literacy still an EU AI Act obligation?

Yes. Article 4 still requires providers and deployers to take measures to support the development of AI literacy among relevant staff and other people operating or using AI systems on their behalf. The 2026 Digital Omnibus amended the requirement so that organisations do not have to guarantee a specific level of AI literacy for an individual.

What should a company document for AI governance?

At a practical level, companies should be able to identify where AI is used, what each system does, who owns it, what data it uses, which vendors are involved, what human oversight exists, what risks have been identified, and what controls and evidence support the relevant compliance position.

Where should a company start with EU AI Act compliance?

Start with an inventory of AI systems and uses across products, internal processes, vendors, and workflows. Then determine the organisation's role, assess the relevant risk classification and obligations, assign ownership, document controls, and establish evidence that those controls operate in practice.