EU AI Act compliance starts with a complete list of AI systems and a defensible role analysis—not with a generic legal memo. Only then can a business determine which prohibitions, transparency, literacy, documentation or high-risk requirements apply.

Short answer

Record every AI use case with its purpose, provider, model, data, affected people, decision influence and owner. Then determine the organisation's role under the Act, the risk category and the resulting duties. For many ordinary office use cases, the practical priorities are AI literacy, transparent use, privacy, supplier due diligence and documented human oversight; high-risk systems require substantially more formal evidence.

1. Determine your role first

The Act distinguishes providers, deployers, importers and distributors. A business using another company's standard tool internally is typically a deployer. A company may inherit provider obligations when it puts a system on the market under its own name, makes a substantial modification or changes the intended purpose in a legally relevant way. Assess the role per system and use, not once for the whole company.[1]

QuestionPotential consequenceEvidence
Do we use a third-party system internally?Assess deployer dutiesProvider, version, purpose, users
Do we market it under our name?Provider duties may applyProduct role and accountability
Do we substantially change purpose or system?Role may changeChange record and assessment
Are we part of a regulated supply chain?Importer or distributor duties may applyContracts and declarations

2. Classify the actual use

The Act applies a risk-based structure. Prohibited practices sit at the top. Certain uses can be high-risk, including specific systems that influence access to employment, education, essential services or public decisions. Other systems carry transparency obligations, for example direct AI interaction and defined forms of synthetic content. Many assistant functions remain outside the high-risk category but still require privacy, security, copyright and operational controls.

CategoryExampleFirst action
ProhibitedDefined manipulative or social-scoring practicesDo not deploy; escalate
High-riskCertain employment or access decisionsFormal legal and conformity analysis
Transparency-relatedChatbots or defined synthetic contentAssess disclosure and labelling
Limited riskInternal drafting without automated decisionsGovernance, privacy, literacy and review

3. Understand the timeline

The AI Act entered into force in 2024 and applies in stages. Prohibited practices and the AI literacy rule have applied since 2 February 2025. Governance and general-purpose AI provisions followed on 2 August 2025. Additional provisions, including defined transparency and enforcement rules, applied from 2 August 2026, while high-risk systems have separate and partly amended dates. Because the framework changed in 2026, teams should use the consolidated legal text for a live project.[2][3]

Important

A deadline is not the date to begin. Inventory, role mapping, supplier evidence, training and controls require lead time. Auditability is created during operation, not retroactively on the due date.

4. Build one compliance record per system

A standard productivity tool may only need a concise record. The purpose is to make the classification and resulting controls traceable. High-risk systems carry much more detailed requirements for risk, quality, data, logging and post-market processes.

5. AI literacy under Article 4

Providers and deployers must take measures relating to the AI literacy of people operating and using systems on their behalf. A role-based approach is practical: general users need safe input, verification and escalation rules; owners need risk and process knowledge; technical teams require data, evaluation, security and monitoring skills. The European Commission maintains a repository of practice examples.[4]

A 90-day implementation sequence

01

Weeks 1–2: inventory

Discover tools, embedded functions and shadow AI through procurement, SSO, interviews and process review.

02

Weeks 3–4: triage

Assess role, purpose, data, affected groups and decision influence; prioritise critical cases.

03

Weeks 5–8: controls

Define approvals, human review, transparency, supplier and privacy checks, and records.

04

Weeks 9–12: evidence

Train users, test samples, exercise the incident route and establish a recurring review.

Common business scenarios

Recruitment

A system that ranks candidates needs a far more rigorous assessment than a tool that only edits a job advertisement. The real effect on access and decision-making is decisive.

Customer chatbot

People should know they are interacting with AI unless this is obvious from the circumstances. Source constraints, escalation to a person, privacy and logging also belong in the operating process.

Internal knowledge search

The main issues are often permission-aware retrieval, data minimisation, citations, freshness and rules for reviewing an answer before external use.

Supplier due diligence before approval

A recognised vendor does not remove the deploying organisation's responsibility. Product tier, contract, model, configuration and connected data sources must all match the specific use.

Connect every duty to an owner and evidence

Work areaLeadTypical evidence
Role and risk classificationAI coordination plus legal/privacyReasoned classification
Data and accessIT, security and business teamData flow, role model and test
Human oversightBusiness ownerReview instruction and escalation
TransparencyProduct or process ownerUser notice and approved pattern
AI literacyHR and domain leadershipRole plan, content and attendance
Monitoring and incidentsOperations and governanceMetrics, incident and change log

This allocation avoids two common failures: compliance does not sit solely with legal or privacy, and technical teams are not left to make business and domain risk decisions on their own.

Frequently asked questions

Does the EU AI Act apply to small businesses?
Yes. The Act does not generally exclude organisations by size, although relevance and scope depend on role, system and use, and some provisions include proportionate support or simplification.

Is ChatGPT automatically high-risk AI?
No. Classification depends on the specific use. A general-purpose model can be embedded in a high-risk process, while ordinary drafting is assessed differently.

Is an AI policy enough?
No. A policy sets rules but does not replace inventory, classification, controls, training, approval and monitoring.

Who owns compliance internally?
Leadership remains accountable. Operationally, name the business owner, IT/security, privacy or legal reviewers, and an AI coordination role.