EU AI Act compliance starts with a complete list of AI systems and a defensible role analysis—not with a generic legal memo. Only then can a business determine which prohibitions, transparency, literacy, documentation or high-risk requirements apply.
Record every AI use case with its purpose, provider, model, data, affected people, decision influence and owner. Then determine the organisation's role under the Act, the risk category and the resulting duties. For many ordinary office use cases, the practical priorities are AI literacy, transparent use, privacy, supplier due diligence and documented human oversight; high-risk systems require substantially more formal evidence.
1. Determine your role first
The Act distinguishes providers, deployers, importers and distributors. A business using another company's standard tool internally is typically a deployer. A company may inherit provider obligations when it puts a system on the market under its own name, makes a substantial modification or changes the intended purpose in a legally relevant way. Assess the role per system and use, not once for the whole company.[1]
| Question | Potential consequence | Evidence |
|---|---|---|
| Do we use a third-party system internally? | Assess deployer duties | Provider, version, purpose, users |
| Do we market it under our name? | Provider duties may apply | Product role and accountability |
| Do we substantially change purpose or system? | Role may change | Change record and assessment |
| Are we part of a regulated supply chain? | Importer or distributor duties may apply | Contracts and declarations |
2. Classify the actual use
The Act applies a risk-based structure. Prohibited practices sit at the top. Certain uses can be high-risk, including specific systems that influence access to employment, education, essential services or public decisions. Other systems carry transparency obligations, for example direct AI interaction and defined forms of synthetic content. Many assistant functions remain outside the high-risk category but still require privacy, security, copyright and operational controls.
| Category | Example | First action |
|---|---|---|
| Prohibited | Defined manipulative or social-scoring practices | Do not deploy; escalate |
| High-risk | Certain employment or access decisions | Formal legal and conformity analysis |
| Transparency-related | Chatbots or defined synthetic content | Assess disclosure and labelling |
| Limited risk | Internal drafting without automated decisions | Governance, privacy, literacy and review |
3. Understand the timeline
The AI Act entered into force in 2024 and applies in stages. Prohibited practices and the AI literacy rule have applied since 2 February 2025. Governance and general-purpose AI provisions followed on 2 August 2025. Additional provisions, including defined transparency and enforcement rules, applied from 2 August 2026, while high-risk systems have separate and partly amended dates. Because the framework changed in 2026, teams should use the consolidated legal text for a live project.[2][3]
A deadline is not the date to begin. Inventory, role mapping, supplier evidence, training and controls require lead time. Auditability is created during operation, not retroactively on the due date.
4. Build one compliance record per system
- System, version, provider and owner
- Purpose, users and affected people
- Organisation's role under the Act
- Risk category and reasoning
- Data types, sources and locations
- Technical and organisational controls
- Human oversight and escalation
- Tests, approvals, changes and incidents
A standard productivity tool may only need a concise record. The purpose is to make the classification and resulting controls traceable. High-risk systems carry much more detailed requirements for risk, quality, data, logging and post-market processes.
5. AI literacy under Article 4
Providers and deployers must take measures relating to the AI literacy of people operating and using systems on their behalf. A role-based approach is practical: general users need safe input, verification and escalation rules; owners need risk and process knowledge; technical teams require data, evaluation, security and monitoring skills. The European Commission maintains a repository of practice examples.[4]
A 90-day implementation sequence
Weeks 1–2: inventory
Discover tools, embedded functions and shadow AI through procurement, SSO, interviews and process review.
Weeks 3–4: triage
Assess role, purpose, data, affected groups and decision influence; prioritise critical cases.
Weeks 5–8: controls
Define approvals, human review, transparency, supplier and privacy checks, and records.
Weeks 9–12: evidence
Train users, test samples, exercise the incident route and establish a recurring review.
Common business scenarios
Recruitment
A system that ranks candidates needs a far more rigorous assessment than a tool that only edits a job advertisement. The real effect on access and decision-making is decisive.
Customer chatbot
People should know they are interacting with AI unless this is obvious from the circumstances. Source constraints, escalation to a person, privacy and logging also belong in the operating process.
Internal knowledge search
The main issues are often permission-aware retrieval, data minimisation, citations, freshness and rules for reviewing an answer before external use.
Supplier due diligence before approval
A recognised vendor does not remove the deploying organisation's responsibility. Product tier, contract, model, configuration and connected data sources must all match the specific use.
- Which role does the vendor claim?
- Which model and product version is operated?
- Where are inputs and outputs stored?
- Are data used for vendor purposes or training?
- Which subprocessors and third-country access paths exist?
- Which logs, tests and declarations are available?
- How are changes and incidents communicated?
- How can data, accounts and connectors be terminated?
Connect every duty to an owner and evidence
| Work area | Lead | Typical evidence |
|---|---|---|
| Role and risk classification | AI coordination plus legal/privacy | Reasoned classification |
| Data and access | IT, security and business team | Data flow, role model and test |
| Human oversight | Business owner | Review instruction and escalation |
| Transparency | Product or process owner | User notice and approved pattern |
| AI literacy | HR and domain leadership | Role plan, content and attendance |
| Monitoring and incidents | Operations and governance | Metrics, incident and change log |
This allocation avoids two common failures: compliance does not sit solely with legal or privacy, and technical teams are not left to make business and domain risk decisions on their own.
Frequently asked questions
Does the EU AI Act apply to small businesses?
Yes. The Act does not generally exclude organisations by size, although relevance and scope depend on role, system and use, and some provisions include proportionate support or simplification.
Is ChatGPT automatically high-risk AI?
No. Classification depends on the specific use. A general-purpose model can be embedded in a high-risk process, while ordinary drafting is assessed differently.
Is an AI policy enough?
No. A policy sets rules but does not replace inventory, classification, controls, training, approval and monitoring.
Who owns compliance internally?
Leadership remains accountable. Operationally, name the business owner, IT/security, privacy or legal reviewers, and an AI coordination role.