The EU AI Act for mid-sized companies
What the EU AI law requires, who it applies to, which deadlines apply and what companies should do now.
The EU AI Act (Regulation (EU) 2024/1689) governs the use and placing on the market of AI according to the risk of the use case: the more AI affects people – for example in hiring, lending or safety – the stricter the obligations. It concerns not only AI vendors but also companies that use AI or integrate it into processes. Violations can lead to fines of up to 35 million EUR or 7% of worldwide annual turnover.
Last updated: October 2026
Who does the EU AI Act apply to?
For mid-sized companies it applies as soon as you use AI in one of these ways:
You use AI
For example chatbots, text and image generators, analytics, HR tools or copilots.
You integrate AI into processes
Such as customer service, sales, HR or production.
You offer AI on the market
You build AI into your own products or services and provide them to customers.
Four risk levels
The EU AI Act classifies AI applications by risk. The level determines which obligations apply.
Unacceptable risk
Certain practices are banned, e.g. social scoring or manipulative AI that exploits people’s vulnerabilities.
High risk
E.g. AI in recruitment, credit scoring, education or critical infrastructure – with extensive obligations on risk management, documentation and human oversight.
Limited risk
E.g. chatbots or AI-generated content: people must be able to recognise that they are interacting with AI.
Minimal risk
Most applications such as spam filters or recommendations – no specific obligations, but user AI literacy is still required.
Key deadlines
The EU AI Act applies in stages. Early phase, transition phase, full application – the key dates:
1 Aug 2024
Entry into force
The regulation is in force; obligations apply step by step.
2 Feb 2025
Prohibitions and AI literacy
Prohibited AI practices are banned. Companies must ensure sufficient AI literacy among their staff (Art. 4).
2 Aug 2025
General-purpose AI models
Obligations for providers of general-purpose AI models, set-up of supervisory structures and penalty rules.
2 Aug 2026
High risk (Annex III) and transparency
Most obligations take effect, including those for high-risk systems under Annex III and the transparency obligations.
2 Aug 2027
High risk in regulated products
Obligations for AI as a safety component in products already covered by EU product legislation (Annex I).
With the so-called “Digital Omnibus”, the European Commission has proposed adjustments to individual high-risk deadlines. The applicable legal status is decisive – regardless, inventory, rules and responsibilities are the foundation for everything else.
What the EU AI Act expects from companies
Transparency
Make it recognisable when AI is involved – for example in a customer chatbot.
Responsibility & control
Important decisions must not be delegated to AI without review; human oversight is required.
Risk orientation
Higher requirements in sensitive areas such as HR or access to services.
Documentation & evidence
Make it traceable which AI is used for what and how risks are managed.
Supplier and procurement discipline
Clarify evidence, usage limits and responsibilities with the vendor of AI software.
AI literacy
Train staff and managers in safe use, limits and escalation.
What you should do now
Eight tasks that lay the foundation for EU AI Act compliance:
Create an AI inventory
Which AI is used where – including “unofficial” tools?
Classify use cases
Uncritical or sensitive / highly relevant (e.g. HR)?
Introduce an AI policy
What is allowed, what is prohibited? Which data may be entered?
Appoint responsible persons
Business unit, compliance/legal, data protection and IT security – not an IT-only task.
Define control points
Where must a human review or decide?
Check suppliers
What does the vendor guarantee, which documents do they provide, what is in the contract?
Train
Train managers and staff in safe use, limits and escalation.
Define an incident process
How to handle errors, complaints, data leaks or unusual results.
Possible fines
Depending on the severity of the violation, the higher of the two amounts applies:
€35m / 7%
for prohibited AI practices
€15m / 3%
for violations of other obligations, e.g. for high-risk AI
€7.5m / 1%
for incorrect or incomplete information supplied to authorities
Percentages refer to worldwide annual turnover; for SMEs and start-ups the lower amount applies. Additionally possible: prohibition or restriction of AI use, remediation orders and indirect contractual and market damage, such as exclusion from tenders.
The risks when AI is not under control
Besides fines, there is liability, data leakage and reputational damage. And more and more customers and tenders require evidence of AI compliance.
How to implement AI governance- Legal and fine risk due to incorrect classification
- Liability for wrong decisions, e.g. in HR
- Data leakage through “shadow AI”
- Reputational damage from AI failures made public
- Business risk: missing evidence in tenders
Note: This page provides a general overview and does not constitute legal advice.
Frequently asked questions about the EU AI Act
Yes. Deployers – companies that use AI – also have obligations, for example on transparency, human oversight and AI literacy. They are particularly strict in sensitive areas such as HR.
Prohibitions and the AI literacy obligation have applied since 2 Feb 2025, obligations for general-purpose AI models since 2 Aug 2025. From 2 Aug 2026 most obligations take effect, including high-risk systems under Annex III; AI in regulated products follows from 2 Aug 2027. The European Commission has proposed adjustments to individual high-risk deadlines.
Up to 35 million EUR or 7% of worldwide annual turnover for prohibited practices, up to 15 million EUR or 3% for other violations and up to 7.5 million EUR or 1% for incorrect information. For SMEs the lower amount applies.
Create an AI inventory, roughly classify the use cases and appoint responsible persons. Inventory, rules and responsibilities are the foundation for everything else.
With a free 30-minute risk triage, fixed-price consulting packages (starting from 12k EUR), AI governance software and role-based training under Art. 4. We do not provide legal advice or certification.
Questions about the EU AI Act?
Briefly describe your AI applications – together we will assess what applies to you.
