EU AI Act for companies: what it requires, when it applies and how to prepare

Regulation (EU) 2024/1689 — the EU AI Act — is the European Union's first general law on artificial intelligence. It does not regulate “AI” in the abstract: it assigns specific obligations according to the role your company plays with respect to each system and to the risk of each use. It has been applying in phases since 2 February 2025, and it has been amended by Regulation (EU) 2026/1744, in force since 27 July 2026. This guide covers the essentials for a company that uses or procures AI.

What it is — and what it is not

The Regulation classifies AI uses by level of risk and distributes obligations among the actors in the chain: whoever develops and markets a system, whoever imports or distributes it, and whoever uses it in the course of business. It is not a data protection law — that remains the GDPR, which applies in parallel — nor does it require you to “certify” your company's AI: it requires, depending on the case, documenting, informing, overseeing and being able to demonstrate what you do.

Provider or deployer? The role goes system by system

The two central figures are the provider — whoever develops an AI system and places it on the market or puts it into service under its own name or trademark — and the deployer: whoever uses an AI system “under its authority”, except where the use is a personal, non-professional activity (Art. 3, point 4). That covers almost any company that procures AI-powered software.

The question “are we a provider or a deployer?” is badly framed: the Regulation assigns the role per system, not per company. Within the same inventory you can be the deployer of twelve tools and the provider of one.

And the role can change. Art. 25(1) sets out three circumstances in which a deployer comes to be considered a provider, and all three are confined to high risk: putting your name or trademark on a high-risk system already placed on the market; substantially modifying a high-risk system in such a way that it remains high-risk; or changing the intended purpose of a system that was not high-risk in such a way that it becomes so. Those three Article 25 scenarios are limited to high-risk AI systems. For other systems, placing your name or trademark on the system does not by itself trigger Article 25(1), but provider status must still be assessed against the general definition in Article 3(3).

Risk levels and transparency obligations

  • Prohibited practices (Art. 5): banned uses regardless of who carries them out, applying since 2 February 2025.
  • High risk (Art. 6 and Annexes I and III): permitted, with strict requirements for the provider and obligations of its own for the deployer.
  • Transparency obligations (Art. 50): not a risk level, but obligations triggered by the nature of the system — chatbots and synthetic-content generation, among others — which require informing or marking, whatever the system's classification.
  • Minimal risk: everything else. No specific obligations under this classification, although Art. 4 (AI literacy) and the GDPR still apply.

Classification is done system by system, with the rationale documented: it is the piece everything else rests on.

Art. 4 — AI literacy, in force since February 2025

Providers and deployers must take AI literacy measures reaching their staff “and other persons dealing with the operation and use of AI systems on their behalf”. As amended by Regulation (EU) 2026/1744 it is expressly a measures-based obligation: the article itself says that it “does not require providers or deployers to guarantee any specific level of AI literacy of any individual”. You comply by documenting which measures you took and the basis on which you determined their scope — not by piling up diplomas.

Guide to Art. 4: what AI literacy actually requires →

Art. 5 — prohibited practices

The Art. 5 list has been applying since 2 February 2025: harmful subliminal manipulation, exploitation of vulnerabilities, social scoring, and certain uses of biometric identification, among others. Regulation (EU) 2026/1744 added two new prohibitions — Art. 5(1), points (ba) and (bb), on non-consensual intimate content and child sexual abuse material generated with AI — applicable from 2 December 2026. It is the part of the Regulation where risk is not managed: it is eliminated.

Art. 50 — transparency, applying since August 2026

Paragraphs 1, 3 and 4 of Art. 50 apply since 2 August 2026: informing people that they are interacting with an AI, and disclosing certain uses such as deepfakes. The information duty of Art. 50(1) is the provider's; for a deployer, reasonable diligence is verifying that its tools comply. The marking of synthetic content under Art. 50(2) also applies from 2 August 2026, with a transitional regime: systems placed on the market before that date have until 2 December 2026 (Art. 111(4)).

High risk — Annex III, Art. 26 and the dates that matter

The obligations for high-risk systems under Annex III — including the deployer obligations of Art. 26: use in accordance with the instructions for use, human oversight entrusted to persons with the necessary competence, training and authority, monitoring and log-keeping — apply from 2 December 2027. For systems that are high-risk as regulated products under Annex I (Art. 6(1)), Art. 26 applies from 2 August 2028.

Two transitional rules worth knowing: high-risk systems already placed on the market before the date of application are only covered if they undergo significant changes in their designs (Art. 111(2)); and those deployed by public authorities before 2 December 2027 have 2 August 2030 as their horizon.

Annex III examples with direct impact on SMEs: recruitment and staff evaluation, access to essential services, credit scoring, education.

FRIA — the Art. 27 impact assessment, and who it actually binds

Before deploying certain high-risk systems under Annex III, some deployers must assess the impact on fundamental rights. The scope is narrower than it is usually told: it binds bodies governed by public law, private entities providing public services, and deployers of the systems in Annex III, point 5, letters (b) and (c). Its only date of application is 2 December 2027 — Art. 27 only reaches high-risk systems under Annex III, so the 2028 date for Annex I does not operate on it.

For most private companies, the FRIA will not be an obligation of their own. The honest thing is to say so — and it is still worth knowing what it is, because clients and tenders will mention it.

The FRIA is not the DPIA of Art. 35 GDPR: they are independent instruments, each with its own law. Since Regulation (EU) 2026/1744, Art. 27(4) expressly allows the FRIA to include cross-references to the relevant sections of the DPIA, or relevant parts of it, where an obligation is already met there — reusing material is enabled; the FRIA still has to be carried out, and conflating the instruments is not allowed.

General-purpose AI models (GPAI)

The obligations of the chapters on general-purpose models (Arts. 53–55) apply since 2 August 2025 and fall on the providers of those models. If your company uses them through commercial tools, your work is one of diligence: knowing which models sit behind your tools and what documentation each provider offers. Models already on the market before that date have a transitional regime until 2 August 2027 (Art. 111(3)).

The dates, at a glance

Already applying: Art. 4 and Art. 5 (2 February 2025) · GPAI and governance (2 August 2025) · Art. 50(1)/(3)/(4) and 50(2) (2 August 2026, with the 50(2) transitional period until 2 December 2026 for pre-existing systems). Upcoming: the new prohibitions of Art. 5(1), points (ba) and (bb) (2 December 2026) · GPAI transitional period and sandboxes (2 August 2027) · Annex III, Art. 26 and Art. 27 (2 December 2027) · Annex I (2 August 2028) · pre-existing high-risk systems of public authorities (2 August 2030).

Full EU AI Act timeline, with sources →

How to prepare, in five steps

  1. Inventory what is already in use — including what arrived without a contract. Inventory template →
  2. Assign the role per system: provider or deployer, row by row.
  3. Classify the risk of each use with the rationale in writing, its date and its author.
  4. Document your Art. 4 measures, already in force. AI literacy checklist →
  5. Keep traceable evidence of all of the above: it is what clients, auditors and authorities will ask you for — and it will arrive by email from a large client before it arrives by legal deadline.

Related reading

Dates under Art. 113 of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 (OJEU of 24 July 2026, in force since 27 July 2026). This content is informational and is not legal advice.