Quick answer
Almost certainly yes, if your company uses AI tools professionally and sells to or operates in the EU, whether or not you built the tools yourself. There is no size threshold. For most businesses the live obligations are modest: avoid a short list of banned AI practices, support staff AI literacy, and be transparent about chatbots and certain AI-generated content. The heavy “high-risk” regime applies only to specific use cases such as recruitment or credit scoring and has been postponed. Fines reach €35 million or 7% of global turnover, with lower caps for SMEs.
Most guides to the EU AI Act are written for companies that build AI. This one is for everyone else too: the online shop with a chatbot, the agency drafting copy with ChatGPT, the software company adding an AI feature, the non-EU business selling to European customers. The regulation’s main application date has now passed and, with a late amendment, the picture has settled. Here is what the Artificial Intelligence Act actually requires of an ordinary business.
What the Artificial Intelligence Act Is and Why It Matters
The AI Act, formally Regulation (EU) 2024/1689, is the world’s first comprehensive AI law (the current consolidated text is on EUR-Lex). As an EU regulation it applies directly in every member state, without national transposition. The AI regulation is built on a risk-based logic: the greater the potential impact of an AI system on people’s safety or fundamental rights, the stricter the obligations on those who develop and use it.
The Digital Omnibus on AI (Regulation (EU) 2026/1744) amended the Act shortly before its main application date. It postponed the high-risk deadlines, added two new prohibited practices, narrowed part of the high-risk definition and cut paperwork for smaller companies. The architecture, four risk levels and role-based duties, is unchanged.
Who Does the EU AI Act Apply To? A Four-Question Check
1. Is the tool an “AI system”? A rule-based algorithm with fixed, human-defined steps is not. The defining feature is inference: the system produces predictions, recommendations, decisions or content from data in ways not explicitly programmed. Chatbots, generative tools, scoring and recommendation engines qualify; a spreadsheet formula does not.
2. Is it used professionally? Private, non-professional use is out of scope. The moment an employee uses a tool on behalf of a company, the company is in scope.
3. Does it touch the EU? The Act applies if the AI system is placed on the EU market, used in the EU, or its outputs are used in the EU. A company outside the Union that serves EU customers is covered. There is no exemption for small businesses or start-ups; AI Act obligations scale with risk, not headcount.
4. Did you build it, or do you use it? This decides your role, and your role decides your duties.
| Role | Who it covers | Typical example |
|---|---|---|
| Provider | Develops an AI system or model and places it on the EU market under its own name, paid or free | A SaaS company shipping an AI feature to customers |
| Deployer | Uses an AI system in the course of its business | A company running a third-party chatbot, using ChatGPT at work, or screening CVs with an AI tool |
| Importer / distributor | Brings a non-EU AI system onto the EU market or makes it available there | A reseller of AI software developed outside the EU |
Most businesses are deployers under the AI Act. Using ChatGPT, Copilot or a vendor chatbot does not make you a provider, but it does make you a deployer, with the obligations described below. You can become a provider without intending to: if you substantially modify a system, integrate it into your own product or market it under your own brand.
One further rule for companies outside the EU: a non-EU provider must appoint an authorised representative established in the Union before making a high-risk AI system or a general-purpose AI model available there (open-source models without systemic risk are exempt).
AI Act Risk Categories: The Four Levels
| Risk level | What it means | Examples |
|---|---|---|
| Unacceptable | Prohibited outright | Social scoring, manipulative subliminal techniques, emotion recognition at work or in education, untargeted facial-image scraping, non-consensual intimate deepfakes |
| High | Permitted with strict compliance duties | AI in recruitment, worker management, credit scoring, education admissions, critical infrastructure, or as a safety component in regulated products |
| Transparency | Permitted with disclosure duties | Chatbots, AI-generated text, images, audio and video, deepfakes |
| Minimal | No specific obligations | Spam filters, recommendation engines, AI-assisted coding, translation |
The European Commission estimated when drafting the law that roughly 85% of AI systems fall into the minimal-risk category. For most service, software and e-commerce companies, only the first and third rows matter in practice.
EU AI Act Timeline: What Applies Now and What Was Postponed
| Applies from | What |
|---|---|
| 2 February 2025 | Prohibited AI practices; AI literacy duty |
| 2 August 2025 | Obligations for providers of general-purpose AI models |
| 2 August 2026 | Transparency obligations (Article 50); national authorities and enforcement powers active |
| 2 December 2026 | Two new prohibitions (non-consensual intimate imagery, child sexual abuse material); marking deadline for generative systems already on the market |
| 2 December 2027 | High-risk systems in Annex III (stand-alone use cases) |
| 2 August 2028 | High-risk AI embedded in regulated products (Annex I) |
EU AI Act Requirements Most Businesses Face Today
1. Do not use prohibited AI practices
Check that no tool in your business falls into a banned category. The most realistic trap for an ordinary company is emotion recognition of employees or customers, or biometric categorisation that infers sensitive traits such as ethnicity or political views. The Commission has published guidelines on prohibited practices for borderline cases.
2. Support AI literacy, and yes, write an AI policy
Providers and deployers must take measures that support AI literacy among the people who operate or use AI on their behalf. The Omnibus softened the wording: you no longer have to guarantee a particular level of competence for each person, but you must still act. The Act does not literally say “adopt an AI policy”, yet a short internal AI-use policy, documented training and a record of who completed it are the simplest way to evidence compliance. Since the duty applies to internal use too, this is the one obligation that reaches even companies whose AI never touches a customer.
3. Chatbot disclosure: tell people when they are talking to a machine
Under the transparency obligations, an AI system that interacts directly with people, such as a chatbot or voice assistant, must make clear that the user is dealing with AI, unless this is obvious from context. The duty sits with the provider who built the system. If you use a vendor chatbot on your website, the vendor must build the disclosure in, but you are the one facing your customers: confirm the notice is visible before or at the first interaction. A line such as “You are chatting with our AI assistant” is enough.
Do You Have to Label AI-Generated Content?
This is the AI content disclosure question businesses ask most, and the one most frequently answered wrongly. The rules distinguish between an invisible, machine-readable marking that the provider of a generative tool must embed, and a visible disclosure that the deployer, the business publishing the content, must add in specific cases only.
| Content you publish | Visible label required? | Why |
|---|---|---|
| AI-drafted product descriptions, ad copy, emails | No | Commercial text is not “information on matters of public interest” |
| AI-drafted blog post or article on a public-interest topic, published without human review | Yes | Public-interest text must be labelled unless a person reviewed it and holds editorial responsibility |
| The same post, edited and published under a named author | No | Editorial-review exception applies |
| Clearly unrealistic AI illustration (a dragon, a flying sphinx) | No | Not a deepfake: it could not exist in reality |
| Photorealistic AI image of a person, even a fictitious one | Yes | Counts as a deepfake: it resembles someone who could exist and appears authentic |
| AI-generated marketing image showing a product differently from reality | Yes | Deepfake under the Commission’s guidelines |
| AI voice or video replica of a real person | Yes | Deepfake |
| Content published before the rules applied | No | No retroactive labelling |
Two points to remember. First, intention does not matter: a realistic image must be labelled even if nobody meant to deceive. Second, the upstream watermark embedded by the AI tool does not discharge your own labelling duty; the disclosure must be perceivable by a person without any technical tool.
AI Act Compliance in Practice: Five Common Scenarios
| Scenario | Your role | Do now | Later |
|---|---|---|---|
| Software company adding an AI feature to its product | Provider | AI disclosure in the interface; machine-readable marking if the feature generates text or media; literacy measures; check the prohibited list | If the use case is in an Annex III area, prepare for the high-risk regime |
| Online shop using a vendor chatbot and AI-generated visuals | Deployer | Confirm the chatbot identifies itself; label photorealistic or reality-altering product images; literacy measures | Nothing further unless a high-risk tool is added |
| Agency or consultancy using ChatGPT, Claude or similar internally | Deployer | AI-use policy and training record; label unreviewed public-interest content; do not feed client personal data without a GDPR basis | None specific to the AI Act |
| Employer screening job applicants with an AI tool | Deployer of a high-risk system | Literacy measures; inform candidates; keep the vendor’s documentation | Human oversight, logging and use per vendor instructions from the postponed date |
| Non-EU company selling an AI product to EU customers | Provider | Same transparency and literacy duties as an EU provider; appoint an EU authorised representative if the system is high-risk or a general-purpose model | High-risk regime from the postponed date |
High-Risk AI Systems: Postponed, Not Cancelled
If your company provides or deploys AI in one of the Annex III areas, a much heavier set of high-risk AI requirements applies from the postponed dates. Providers must run a risk-management system, keep technical documentation and logs, design for human oversight and pass a conformity assessment before the system goes on the market. Deployers must use the system as instructed, assign trained people to oversee it and retain logs.
Smaller companies get real relief: simplified technical documentation for SMEs, start-ups and the new “small mid-cap” category; simplified quality management for all SMEs; and fine caps at the lower of the fixed amount or the turnover percentage. There is also an exclusion: a system in an Annex III area is not high-risk if it only performs a narrow procedural or preparatory task and does not materially influence decisions. Two caveats apply. Any system that profiles natural persons is always high-risk, and a provider relying on the exclusion must document its assessment and still register the system in the EU database.
Penalties, Enforcement and the GDPR Overlap
Enforcement is shared. The European AI Office supervises providers of general-purpose AI models; each member state designates a market surveillance authority for AI systems; data-protection authorities continue to supervise personal data used by AI. The Commission’s AI Act Service Desk answers questions from businesses in English.
Penalties for non-compliance are tiered: up to €35 million or 7% of worldwide annual turnover for prohibited practices; up to €15 million or 3% for most other duties, including transparency; and up to €7.5 million or 1% for supplying incorrect information to authorities. For large companies the higher of the two figures is the ceiling; for SMEs and start-ups, the lower.
The AI Act sits alongside the GDPR, not instead of it. The AI Act regulates the system and its use; the GDPR regulates the personal data flowing through it. A tool can be fully compliant with one and still breach the other. Where the AI Act requires a fundamental-rights impact assessment, it may draw on an existing data-protection impact assessment rather than duplicating it.
A Practical AI Compliance Checklist for Businesses
Good AI governance does not require a legal department. For most companies, these nine steps cover the current AI Act requirements and prepare the ground for the high-risk rules later:
- Inventory: list every AI tool in use, including features embedded in SaaS products and general-purpose models used by staff.
- Role: decide for each tool whether you are a provider, a deployer or both.
- Classification: check each tool against the prohibited list and the Annex III areas; write down the result.
- Chatbots: confirm every customer-facing AI assistant identifies itself.
- Content: apply the labelling table above to what you publish.
- Literacy: adopt an AI-use policy and keep training records.
- Data protection: align AI use with your existing GDPR documentation.
- EU presence: if you are outside the EU and provide a high-risk system or a general-purpose model, appoint an authorised representative.
- Roadmap: if anything is high-risk, plan for the postponed dates rather than wait for them.
AI Act Compliance and EU Company Set-Up with Eesti Firma
The Artificial Intelligence Act rewards businesses that build compliance in from the start, and for companies outside the Union it makes an EU presence a practical necessity. Eesti Firma supports AI-driven businesses at both ends: establishing an EU entity through fully digital company formation in Estonia, including formation through e-Residency for founders who never need to visit Estonia, and helping the company meet its obligations once it operates in the EU market.
Our lawyers prepare legal opinions on whether a specific AI system falls within scope and which role and risk level it triggers, and our legal services team drafts the AI-use policies and disclosures a company needs to evidence AI literacy, transparency and data-protection compliance.
Frequently Asked Questions
Yes. There is no employee or revenue threshold. Obligations depend on how AI is used, not on company size, although SMEs benefit from simplified documentation and lower fine caps.
Yes, as a deployer. The transparency rules only bite when AI output reaches people outside your company, but the AI literacy duty and the prohibited-practice rules apply to internal use as well.
Yes, if they place an AI system on the EU market or its outputs are used in the EU. Non-EU providers of high-risk systems and general-purpose models must also appoint an authorised representative in the Union.
The Act does not use those words, but an AI-use policy with training records is the simplest way to evidence the AI literacy duty and to show a regulator that AI use is governed.
Product descriptions and ad copy: no. A blog post on a public-interest topic: only if it was published without human review and editorial responsibility. See the labelling table above for images, audio and video.
The platform must build the disclosure in; you must make sure it is actually shown to your customers. In practice, check it before you go live.
Up to €35 million or 7% of worldwide turnover for prohibited practices, up to €15 million or 3% for most other obligations including transparency, and up to €7.5 million or 1% for supplying incorrect information to authorities. SMEs and start-ups face the lower of the two figures.
No, only postponed. The requirements are unchanged; see the timeline above for the two new application dates.