What is the EU AI Act? A plain-English guide for businesses

EEU AI Compliance team · 2026-07-06

The EU AI Act is the first broad law in the world that regulates artificial intelligence. If your business builds, sells or uses AI in the European Union, it likely affects you. Here is what it does, who it covers, and what you need to do about it, without the legal jargon.

The core idea: risk-based rules

The Act sorts AI systems into four risk levels, and your obligations depend on where your system lands.

  • Unacceptable risk: banned outright, for example social scoring by governments.
  • High risk: allowed, but with strict duties. Risk management, documentation, human oversight, logging. This covers areas like hiring, credit scoring, medical devices and critical infrastructure.
  • Limited risk: transparency duties. If users interact with a chatbot or see AI-generated content, they must be told.
  • Minimal risk: most AI systems, such as spam filters and recommendation engines. No new obligations.

Who does it apply to?

It applies to providers (you build or sell the AI), deployers (you use it in your business), importers and distributors. It reaches companies outside the EU too, if their AI is used in the EU. So a US SaaS with EU customers is in scope.

What about general-purpose AI (GPAI)?

Models like large language models get their own rules. Providers of general-purpose models must publish technical documentation, summarize training data, and respect copyright. The most capable models carry extra duties around safety and security.

When does it start?

The Act entered into force in 2024 and applies in stages. Bans on unacceptable-risk AI came first, GPAI obligations follow, and the full high-risk regime phases in over the following years. The practical takeaway: the timeline is short enough that you should know your position now.

What should you do next?

  1. Find out if it applies to you. Most companies are unsure whether they are even in scope. A structured applicability check answers that in minutes.
  2. Classify your risk. Your obligations depend entirely on your risk category. Get it right before you spend on compliance work you may not need.
  3. Document your position. If you are high-risk or a GPAI provider, you need audit-ready documentation. This is where automated tools save you weeks of consultant time.

You do not need a six-figure consulting engagement to get started. Run the free applicability check, see where you stand, and only then decide what compliance work you actually need.

This guide is general information, not legal advice.

Put this into practice with Compliance Audit
Full audit and report · 249 €
Try it