complaia

EU AI Act

The EU AI Act: What Does It Mean for Your Business?

Last updated: 26 August 2026

A clear, practical guide to the EU AI Act. What it is, when it applies, and what it actually means for your business.

What is the EU AI Act?

The EU AI Act (Regulation (EU) 2024/1689) is the European Union's shared rulebook for developing and using AI systems. It's the first broad piece of legislation of its kind anywhere in the world, and it applies across all EU member states. The rules follow a risk-based model: the greater the risk an AI system poses to people's rights and safety, the more obligations apply to it.

The Act entered into force on 1 August 2024, but its rules are being phased in over several years. See our full timeline of the key dates for the complete picture.

Does the AI Act apply to your business?

For most businesses: probably yes, to some extent. The AI Act doesn't only apply to businesses that build AI. It also applies to businesses that simply use AI systems in their day-to-day operations: chatbots, AI-based recruitment tools, or generative AI for content, for example. The rules also reach businesses outside the EU if their AI systems are used by, or affect, people in the EU.

Exactly how much applies to you depends entirely on your role and the type of AI system involved. It's rarely all-or-nothing.

What role does your business have?

The AI Act mainly distinguishes between two roles:

  • Provider: the party that develops an AI system, or has one developed, and places it on the market or puts it into service under its own name.
  • Deployer: the party that uses an AI system in the course of its business, without being the provider itself.

Most small and medium-sized businesses are deployers of tools built by others, but it's worth checking your specific situation, since some businesses are both at once (for example, if you build on top of a third party's AI model and sell it as your own product).

What counts as an “AI system” under the law?

The AI Act defines an AI system broadly: a machine-based system designed to operate with some degree of autonomy, which infers from input how to generate outputs such as predictions, content, recommendations, or decisions. In practice, that covers everything from simple recommendation algorithms to advanced generative AI models: a much wider net than most people initially assume.

Prohibited AI practices

A short, specific list of AI uses has been banned outright since 2 February 2025, including social scoring of individuals, certain manipulative AI techniques, and biometric categorisation based on sensitive characteristics. That list is deliberately narrow: it isn't meant as a broad restriction on everyday business use of AI, but a ban on specific, particularly intrusive practices.

AI literacy

Since 2 February 2025, businesses that provide or use AI systems have been expected to ensure a reasonable level of AI literacy among their staff: typically a basic understanding of how the AI systems they use actually work and what risks they carry.

General-purpose AI models (GPAI)

Since 2 August 2025, providers of general-purpose AI models, the large models other systems are built on top of, have had obligations covering documentation and transparency among other things. These rules are aimed primarily at the organisations that develop and supply the models themselves.

If you use tools built on top of someone else's model, this typically isn't something you act on directly. The distinction is worth knowing, because the AI Act treats an AI model and an AI system as two different things.

Transparency obligations

Since 2 August 2026, certain AI systems have had to make it clear that people are dealing with AI (chatbots are the clearest example), and AI-generated or manipulated content, including deepfakes, must in certain cases be labelled. These rules come from Article 50 of the AI Act. We've put together a full, practical breakdown of what that means in our article on the transparency obligations.

High-risk AI systems

Stricter requirements apply to AI systems used in sensitive contexts: employment, credit scoring, education, or safety components in products, for example. These requirements were originally due to apply from August 2026/2027, but were deferred as part of the “Digital Omnibus” simplification package, which the Council gave final approval on 29 June 2026. Most high-risk AI systems are now expected to be covered from 2 December 2027, while high-risk AI embedded in already-regulated products (such as medical devices and machinery) is expected from 2 August 2028.

What should your business do now?

In practice, that usually means:

  • Getting a clear picture of which AI systems your business actually uses.
  • Working out whether your business is a provider, a deployer, or both.
  • Making sure staff working with AI have a basic level of AI literacy.
  • Checking that none of your current AI use falls into a prohibited category.
  • Meeting the transparency obligations, which now apply, if your business uses chatbots, AI-generated content or deepfakes.
  • Keeping an eye on whether any of your AI use could be classified as high-risk.

This is exactly the kind of overview Complaia is building a dedicated platform for. Read more about the platform we're building, launching in 2027.

What's coming towards 2027 and beyond?

The AI Act will continue rolling out in phases over the coming years, and the exact implementation may be adjusted further through upcoming guidance or amendments. See the full timeline with all the datesfor a complete view of what already applies and what's still to come.

Important to know

This page provides general information about the AI Act and is not legal advice. Whether and how the rules apply to your business depends on your specific circumstances, and we recommend seeking professional legal advice where it genuinely matters. This content has been prepared and reviewed by Complaia based on the AI Act's official text, published European Commission guidance, and the adopted “Digital Omnibus” simplification package, and is updated as the rules or official guidance change.