EU AI Act · Executive overview

The EU AI Act for mid-sized companies

What the EU AI law requires, who it applies to, which deadlines apply and what companies should do now.

The EU AI Act (Regulation (EU) 2024/1689) governs the use and placing on the market of AI according to the risk of the use case: the more AI affects people – for example in hiring, lending or safety – the stricter the obligations. It concerns not only AI vendors but also companies that use AI or integrate it into processes. Violations can lead to fines of up to 35 million EUR or 7% of worldwide annual turnover.

Last updated: October 2026

Who does the EU AI Act apply to?

For mid-sized companies it applies as soon as you use AI in one of these ways:

Use

You use AI

For example chatbots, text and image generators, analytics, HR tools or copilots.

Integrate

You integrate AI into processes

Such as customer service, sales, HR or production.

Offer

You offer AI on the market

You build AI into your own products or services and provide them to customers.

Four risk levels

The EU AI Act classifies AI applications by risk. The level determines which obligations apply.

Prohibited

Unacceptable risk

Certain practices are banned, e.g. social scoring or manipulative AI that exploits people’s vulnerabilities.

High risk

High risk

E.g. AI in recruitment, credit scoring, education or critical infrastructure – with extensive obligations on risk management, documentation and human oversight.

Transparency

Limited risk

E.g. chatbots or AI-generated content: people must be able to recognise that they are interacting with AI.

Minimal

Minimal risk

Most applications such as spam filters or recommendations – no specific obligations, but user AI literacy is still required.

Key deadlines

The EU AI Act applies in stages. Early phase, transition phase, full application – the key dates:

  1. 1 Aug 2024

    Entry into force

    The regulation is in force; obligations apply step by step.

  2. 2 Feb 2025

    Prohibitions and AI literacy

    Prohibited AI practices are banned. Companies must ensure sufficient AI literacy among their staff (Art. 4).

  3. 2 Aug 2025

    General-purpose AI models

    Obligations for providers of general-purpose AI models, set-up of supervisory structures and penalty rules.

  4. 2 Aug 2026

    High risk (Annex III) and transparency

    Most obligations take effect, including those for high-risk systems under Annex III and the transparency obligations.

  5. 2 Aug 2027

    High risk in regulated products

    Obligations for AI as a safety component in products already covered by EU product legislation (Annex I).

With the so-called “Digital Omnibus”, the European Commission has proposed adjustments to individual high-risk deadlines. The applicable legal status is decisive – regardless, inventory, rules and responsibilities are the foundation for everything else.

What the EU AI Act expects from companies

Transparency

Make it recognisable when AI is involved – for example in a customer chatbot.

Responsibility & control

Important decisions must not be delegated to AI without review; human oversight is required.

Risk orientation

Higher requirements in sensitive areas such as HR or access to services.

Documentation & evidence

Make it traceable which AI is used for what and how risks are managed.

Supplier and procurement discipline

Clarify evidence, usage limits and responsibilities with the vendor of AI software.

AI literacy

Train staff and managers in safe use, limits and escalation.

What you should do now

Eight tasks that lay the foundation for EU AI Act compliance:

1

Create an AI inventory

Which AI is used where – including “unofficial” tools?

2

Classify use cases

Uncritical or sensitive / highly relevant (e.g. HR)?

3

Introduce an AI policy

What is allowed, what is prohibited? Which data may be entered?

4

Appoint responsible persons

Business unit, compliance/legal, data protection and IT security – not an IT-only task.

5

Define control points

Where must a human review or decide?

6

Check suppliers

What does the vendor guarantee, which documents do they provide, what is in the contract?

7

Train

Train managers and staff in safe use, limits and escalation.

8

Define an incident process

How to handle errors, complaints, data leaks or unusual results.

Possible fines

Depending on the severity of the violation, the higher of the two amounts applies:

€35m / 7%

for prohibited AI practices

€15m / 3%

for violations of other obligations, e.g. for high-risk AI

€7.5m / 1%

for incorrect or incomplete information supplied to authorities

Percentages refer to worldwide annual turnover; for SMEs and start-ups the lower amount applies. Additionally possible: prohibition or restriction of AI use, remediation orders and indirect contractual and market damage, such as exclusion from tenders.

The risks when AI is not under control

Besides fines, there is liability, data leakage and reputational damage. And more and more customers and tenders require evidence of AI compliance.

How to implement AI governance
  • Legal and fine risk due to incorrect classification
  • Liability for wrong decisions, e.g. in HR
  • Data leakage through “shadow AI”
  • Reputational damage from AI failures made public
  • Business risk: missing evidence in tenders

Note: This page provides a general overview and does not constitute legal advice.

Frequently asked questions about the EU AI Act

Questions about the EU AI Act?

Briefly describe your AI applications – together we will assess what applies to you.