The EU AI Act does not ask businesses to comply with one single rule; it asks them to first work out which risk tier their AI system falls into, since that classification determines almost everything that follows. A system used for internal document search carries far lighter obligations than one used to screen job applicants or score creditworthiness. This guide walks through the practical steps a business actually needs to take, in the order they typically need to happen, rather than repeating the Act's legal text.
What changed in 2026
- Staggered deadlines are now active rather than theoretical. Obligations for prohibited-practice bans, general-purpose AI model duties, and high-risk system requirements phase in on different schedules, and several of those windows have already opened.
- Enforcement guidance became more concrete. Regulators published more detailed expectations on what counts as adequate documentation and human oversight, narrowing some of the ambiguity that made early planning difficult.
- General-purpose AI model obligations split more clearly from deployer obligations. Businesses building on top of a foundation model increasingly need to understand what the model provider has already done versus what remains their own responsibility as a deployer.
- Cross-border enforcement expectations firmed up. Companies outside the EU offering AI systems into the EU market are seeing clearer signals that extraterritorial reach is being taken seriously, not treated as a formality.
The compliance process, step by step
- Classify the system's risk tier. Determine whether the system falls into a prohibited category, the high-risk category (tied to specific use cases like employment, credit, law enforcement, and critical infrastructure), limited-risk (mainly transparency duties), or minimal risk.
- Identify your role. A business can be a provider (building or substantially modifying a system), a deployer (using a system built by someone else), or both, and obligations differ meaningfully by role.
- Inventory every AI system in actual use, not just the flagship one. Shadow deployments, embedded AI features inside third-party software, and internal tools built on top of a general-purpose model all count and are commonly missed in a first pass.
- Build the required technical documentation for anything high-risk. This includes a description of the system's purpose, the data used, known limitations, and the risk-management measures in place, maintained as a living document rather than a one-time filing.
- Put human oversight measures in place. High-risk systems need a defined process for a human to review, override, or halt an automated decision, not just a theoretical ability to do so.
- Complete a conformity assessment where required. Certain high-risk categories require third-party assessment before deployment; others allow self-assessment against the required criteria.
- Set up post-market monitoring. Compliance is not a one-time gate; high-risk systems need ongoing monitoring for drift, incidents, and unexpected behavior after launch.
- Document vendor obligations separately from your own. If a business is a deployer using a third-party general-purpose model, get clarity in writing on what the model provider has already handled versus what remains the deployer's responsibility.
Obligations and penalties by category
| Category |
Core obligation |
Maximum penalty exposure |
| Prohibited practices |
Outright ban, no compliance path |
Among the highest fixed and percentage-of-revenue penalties in the Act |
| High-risk systems |
Documentation, oversight, conformity assessment, monitoring |
Substantial percentage-of-global-turnover penalties |
| General-purpose AI models |
Provider-side transparency and, for the largest models, systemic-risk obligations |
Significant penalties tied to the specific violation category |
| Limited-risk systems |
Disclosure that content or interaction is AI-generated or AI-driven |
Lower fixed penalties, still enforceable |
Exact figures and thresholds continue to be clarified through guidance, so treat this table as a structure for reasoning about exposure, not a final legal reference.
Common mistakes
- Classifying the flagship product but missing embedded AI elsewhere. A vendor-supplied AI feature buried inside HR software or a support tool is still in scope and is one of the most commonly missed compliance gaps.
- Treating documentation as a one-time deliverable. Technical documentation and risk assessments need to be kept current as the system changes, not filed away after initial launch.
- Assuming a compliant foundation model means a compliant application. Provider-level compliance covers the model; a business's specific deployment and use case still carries its own separate obligations as a deployer.
- Waiting for final enforcement guidance before starting. Given staggered deadlines, waiting for perfect clarity on every detail before beginning the classification and documentation work risks missing an already-active deadline.
FAQ
Does the EU AI Act apply to a business outside the EU?
Yes, if the AI system's output is used within the EU or the system is placed on the EU market, extraterritorial reach generally applies regardless of where the provider or deployer is based.
Is a chatbot automatically high-risk?
Not automatically. Risk tier depends on the use case, not the technology; a chatbot used for general customer support sits in a different tier than one used to make employment or credit decisions.
Who is liable if a business uses a general-purpose AI model that turns out to violate the Act?
Liability can be shared between the model provider and the deploying business depending on what each party controlled, which is why documenting the division of responsibility in writing matters.
How does this compare with AI regulation elsewhere?
The EU's approach is notably more prescriptive and risk-tiered than several other major jurisdictions. See our comparison of AI regulation by country for how the approaches differ.
Where to go next
For the broader regulatory and audit context, see our guides to AI regulation by country, what an AI audit actually involves, and AI bias detection tools.