Who does the EU AI Act apply to?
For mid-sized companies, the EU AI Act is relevant if you …
- use AI – for example chatbots, text and image generators, analytics, HR tools or copilots,
- integrate AI into processes – such as customer service, sales, HR or production,
- build AI into products or services and offer them on the market.
What does the EU AI Act require?
- Transparency: make it recognisable when AI is involved (e.g. a customer chatbot).
- Responsibility & control: important decisions must not be delegated to AI without review; human oversight is required.
- Risk orientation: higher requirements in sensitive areas such as HR or access to services.
- Documentation & evidence: make it traceable which AI is used for what and how risks are managed.
- Supplier and procurement discipline: clarify evidence, usage limits and responsibilities for AI software.
What are the risks if AI is not under control?
- Legal and fine risk due to incorrect classification or missing obligations.
- Liability for wrong decisions, such as unfair HR decisions or incorrect customer information.
- Data and trade secret protection: employees enter sensitive data into external AI tools (“shadow AI”).
- Reputational damage from discrimination, security incidents or AI failures made public.
- Business risk: customers and tenders increasingly require evidence of AI compliance.
What companies should do now
- Create an AI inventory: which AI is used where – including “unofficial” tools?
- Roughly classify use cases: uncritical or sensitive / highly relevant (e.g. HR).
- Introduce an AI policy: what is allowed, what is prohibited? Which data may be entered?
- Appoint responsible persons: business unit, compliance/legal, data protection and IT security – not an IT-only task.
- Define control points: where must a human review or decide?
- Check suppliers: what does the vendor guarantee? Which documents do they provide? What is in the contract?
- Train: prepare managers and staff for safe use, limits and escalation.
- Incident process: define how to handle errors, complaints, data leaks and unusual results.
Timeline: early phase, transition phase, full application
- Early phase (since 2 Feb 2025): certain AI practices are prohibited; companies must establish transparency, ground rules and staff AI literacy.
- Transition phase: obligations for many applications apply step by step – especially where AI significantly affects people (including high-risk systems under Annex III from 2 Aug 2026).
- Full application: requirements are comprehensively in effect; evidence, processes and responsibilities must be established.
Rule of thumb: set up inventory, rules and responsibilities early – they are the foundation for everything else.
All deadlines on the EU AI Act pageWhat penalties apply?
Violations can lead to high fines: depending on severity, up to 7% of worldwide annual turnover or fixed maximum amounts (up to 35 million EUR), depending on the category of violation. In addition, certain AI uses may be prohibited or restricted, remediation may be ordered, and indirect contractual and market damage may occur, such as exclusion from tenders.
Note: This text provides a general overview and does not constitute legal advice.
