AccuroAI
Products
What We Do
Solutions
Company
Resources
Book demo
← Blog·Compliance13 min read

EU AI Act Compliance Guide for Enterprises: What You Need to Know

The EU AI Act creates a tiered compliance framework that applies to any enterprise deploying or using AI systems in the EU. Here is the practical guide for understanding your obligations.

S
Sofia Reyes
Head of Compliance
2026-02-20

Answer box

The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive, horizontal law for artificial intelligence. It entered into force on 1 August 2024 and rolls out in phases through 2027 and beyond. It regulates AI systems themselves — sorted into four risk tiers, with obligations attached to each tier and to specific roles in the supply chain. This guide is the foundational reference: what the law is, who it covers, how the risk architecture works, what penalties apply, and how the timeline sequences. For the operational to-do list, see the CISO action plan; for a date-by-date countdown, see the deadline countdown. Read this first if you are a board member, general counsel, or executive trying to understand what your company is subject to.

Why the EU passed this law (in 90 seconds)

The EU's approach to digital regulation is rights-based. GDPR (2018) treated personal data as an extension of fundamental rights, not commercial property. The AI Act extends that logic to algorithmic decisions: if a system can deny you a loan, screen you out of a job, or identify you on a public street, the EU treats that as a fundamental-rights question first and a market question second.

Drafting began in 2021, before generative AI became a consumer phenomenon. The original text focused on discriminative AI — credit scoring, biometric identification, predictive policing. When ChatGPT launched in late 2022 the regulation was already in trilogue; legislators grafted on the "general-purpose AI" (GPAI) chapter late, which is why GPAI provisions read slightly differently from the rest.

The Act's extraterritorial reach mirrors GDPR's. If your AI system's output is used inside the EU, you are covered — even with no European entity, no European servers, no European customers. Fundamental rights of EU residents do not stop at the border just because a vendor's IP address does.

Who's covered (and who isn't)

Article 3 defines four operator roles. Most enterprises are not just one — a company that builds an internal AI tool and resells a vendor's model is simultaneously Provider and Deployer. Getting role mapping right is the first compliance task, because obligations follow the role.

Role Definition Example Primary obligations
Provider Develops an AI system or has one developed and places it on the EU market under its name or trademark. A vendor selling a CV-screening model. An internal team building a credit-risk model used company-wide. Risk management (Art. 9), data governance (Art. 10), technical documentation (Art. 11), conformity assessment, CE marking, post-market monitoring.
Deployer Uses an AI system under its own authority in a professional context (was called "user" in earlier drafts). A bank using a third-party fraud-detection model on its customers. A hospital using a diagnostic AI on its patients. Use as intended, human oversight, input data relevance, logging, fundamental-rights impact assessment for certain Annex III systems (Art. 26).
Importer An entity established in the EU that places an AI system from a non-EU provider on the EU market. An EU subsidiary that brings a US-built AI product to European customers. Verify the provider's conformity assessment, documentation, CE marking before placing on market.
Distributor Anyone in the supply chain (other than provider or importer) that makes an AI system available on the EU market. A marketplace, reseller, or systems integrator. Verify CE marking and documentation exist before passing the system downstream.

Two scope notes. Article 2 covers AI systems placed on the market, put into service, or whose output is used in the Union — if your model runs in Virginia but its predictions are consumed in Berlin, you are covered. The Act does not apply to systems used exclusively for military, defence or national security, scientific R&D, or purely personal non-professional use. Those carve-outs are narrower than they sound and do not exempt commercial dual-use products.

The risk-tier architecture

The Act's central idea is that obligations should scale with risk to fundamental rights and safety, not with vendor size or revenue. There are four tiers. Every AI system you operate sits in exactly one of them. The tier is determined by what the system does, not who built it.

Unacceptable risk (prohibited under Article 5)

A small set of practices are banned outright: social scoring by public authorities, untargeted facial-image scraping for recognition databases, real-time remote biometric ID in public by law enforcement (narrow exceptions), emotion recognition in workplaces and schools, biometric categorisation inferring sensitive attributes, profile-only predictive policing, and AI exploiting vulnerabilities of specific groups. Prohibitions took effect 2 February 2025 — already binding law. There is no "high-risk" workaround; the system simply cannot be placed on the market.

High-risk (Title III)

Most of the regulation's weight falls here. A system is high-risk if (a) it is a safety component of a product covered by EU product-safety legislation in Annex I (medical devices, machinery, toys), or (b) it falls into an Annex III use case (covered below). High-risk systems are not banned — they must be built, documented and operated under a strict regime: risk management, data governance, technical documentation, logging, transparency to deployers, human oversight, accuracy/robustness/cybersecurity, conformity assessment, EU database registration, and post-market monitoring.

Limited risk (transparency obligations)

Systems that interact with humans, generate synthetic content, or perform emotion recognition or biometric categorisation outside prohibited contexts must disclose what they are. A chatbot must tell users it is an AI. Generated images, audio and video must be machine-readably marked as artificial. These obligations sit in Article 50 and apply regardless of the underlying tier.

Minimal risk

Everything else — spam filters, product-catalogue recommenders, AI in video games, inventory forecasting. No specific obligations, though general EU law (GDPR, consumer protection, product liability) still applies.

General-purpose AI models sit in a parallel regime. All GPAI providers have transparency and copyright-compliance duties. GPAI models posing "systemic risk" — currently a compute threshold of 10^25 FLOPs at training — carry additional obligations: model evaluations, adversarial testing, serious-incident reporting, cybersecurity. The EU AI Office enforces GPAI rules directly rather than via national authorities.

The August 2024 → December 2027 enforcement timeline

The Act entered into force on 1 August 2024 but is enforced in waves. The original schedule pulled high-risk obligations forward to August 2026; the Digital Omnibus adopted December 2024 pushed several deadlines out — see our analysis of the delay. Consolidated timeline:

Date What becomes enforceable Legal basis
1 Aug 2024 Regulation enters into force. Clock starts on phased application. Article 113
2 Feb 2025 Prohibitions in Article 5 apply. AI literacy duty for staff (Article 4) applies. Title II, Article 4
2 Aug 2025 GPAI obligations apply (transparency, copyright policy, systemic-risk duties). National competent authorities designated. Penalty regime active. Chapter V, Title XII
2 Aug 2026 (original) Originally: most high-risk obligations (Annex III systems) apply. Pushed by Digital Omnibus. Article 113(c) — superseded
Dec 2027 Revised application date for most Annex III high-risk obligations under the Digital Omnibus amendments. Digital Omnibus 2024
2 Aug 2028+ High-risk obligations for AI systems that are safety components of Annex I products. Review clauses trigger for amendments to Annex III. Article 113, Article 112

Two practical points. Prohibitions and literacy are already live — not future problems. And the delay to December 2027 applies to obligations, not classification: a system you build today still is high-risk; you just have more runway before the conformity-assessment machinery binds.

What "high-risk" actually means under Annex III

Annex III is the operative list. A system used in any of these contexts is presumed high-risk and must meet Title III obligations:

  • Biometric ID and categorisation — remote biometric ID not outright prohibited, biometric categorisation outside Article 5. Example: airport ID-verification kiosks.
  • Critical infrastructure — AI as safety component in road traffic, water, gas, heating, electricity, digital infrastructure. Example: grid-balancing that can trigger load shedding.
  • Education and vocational training — admissions, evaluation of learning outcomes, exam monitoring, institutional allocation. Example: automated grading of standardised tests.
  • Employment and worker management — recruitment screening, promotion/termination decisions, task allocation, performance monitoring. Example: CV-ranking models.
  • Access to essential services — benefits eligibility, creditworthiness (narrow fraud-detection exception), life/health insurance pricing, emergency dispatch triage.
  • Law enforcement — risk assessment of individuals, evidence reliability evaluation, profiling in criminal investigations. Subject to additional safeguards.
  • Migration, asylum and border control — risk assessment of incoming persons, asylum-application examination, travel-document verification.
  • Justice and democratic processes — AI used by judicial authorities to research and interpret facts and law, AI used to influence electoral outcomes.

If you operate in any of these spaces — even adjacent — assume your AI is high-risk until a documented analysis says otherwise. For sector specifics, our healthcare AI security playbook shows how Annex III intersects with medical-device regulation.

The penalty architecture

Article 99 sets three tiers of administrative fines. Like GDPR, each tier is expressed as the greater of a fixed cap or a percentage of worldwide annual turnover for the preceding financial year:

  • €35 million or 7% of global turnover — for violations of the Article 5 prohibitions. The highest tier in any EU digital regulation to date.
  • €15 million or 3% of global turnover — for non-compliance with most other obligations, including the bulk of high-risk requirements (risk management, data governance, documentation, transparency to deployers, human oversight) and GPAI obligations.
  • €7.5 million or 1% of global turnover — for supplying incorrect, incomplete or misleading information to authorities or notified bodies.

For SMEs and startups, the lower of the two figures applies — a deliberate choice to avoid extinction-level fines for early-stage companies. Penalties are imposed by national supervisory authorities designated by each member state. The EU AI Office has direct enforcement power over GPAI providers regardless of where they are established. The European Artificial Intelligence Board coordinates enforcement to prevent forum-shopping.

Enforcement is administrative, not criminal. But the Act sits inside a broader liability ecosystem — the revised Product Liability Directive and the proposed AI Liability Directive — that opens civil claims for individuals harmed by AI systems. Article 99 is the floor of your exposure, not the ceiling.

How to use this guide vs. the CISO checklist vs. the countdown

This post is the definitional reference: the law's structure, scope, and architecture. Start here if you are a board member, general counsel, or executive. Once you know which roles you occupy and which tiers your systems fall into, the operational work begins. For the step-by-step to-do list — inventory, gap analysis, documentation, oversight controls — see the CISO 10-point action plan. For week-by-week sequencing toward the next milestone, see the deadline countdown. For parallel NIST AI RMF or ISO/IEC 42001 work, the unified compliance crosswalk shows where controls overlap.

FAQ

Does this apply to ChatGPT, Claude, or Gemini if we just use them through their consumer products?

Yes and no. Foundation-model providers carry the GPAI obligations as of August 2025 — that is on them, not you. But your use can pull you in as a Deployer. Wrap a chatbot around one of these APIs in front of EU residents and you owe Article 50 disclosures. Use it to screen job applicants, score creditworthiness, or evaluate students and you become Deployer of a high-risk system owing Article 26 obligations — regardless of how the underlying model was built.

What's the difference between "Provider" and "Deployer"?

A Provider develops or commissions an AI system and puts it on the EU market under its name. A Deployer uses an AI system in the course of professional activity. The litmus test is authorship and branding: your logo on the product or built for internal use means Provider. Bought from someone else and operated on your users means Deployer. Providers carry the heavier load — conformity assessment, technical documentation, post-market monitoring — but Deployers are not passive: human oversight, logging, fundamental-rights impact assessments for some Annex III systems, and a duty to use the system as the Provider instructs.

If we're a US company with no EU operations, are we covered?

Possibly. Article 2 captures you if you (a) place an AI system or GPAI model on the EU market, (b) put one into service in the EU, or (c) your AI's output is used in the EU. The third leg is the trap. A US-only SaaS whose API is called by a customer's European subsidiary is in scope. The clean way to scope out is a documented technical or contractual barrier — geofencing, ToS restricting EU use, IP blocking — and to enforce it. Marketing disclaimers are not enough.

Can we voluntarily comply with Annex III obligations even if we're not high-risk?

Yes. Article 95 encourages voluntary codes of conduct, and many Providers of limited or minimal-risk systems meet high-risk standards as a procurement differentiator. EU buyers in regulated sectors increasingly require documentation and oversight evidence even where the law does not. It is also a hedge: Annex III can be amended by the Commission, and a system that is minimal-risk today may not be in two years.

How does enforcement actually work — who knocks on the door?

Each member state designates national competent authorities and a single market surveillance authority for AI. Those bodies handle complaints, investigate, and impose fines for non-GPAI obligations — demanding documentation, requiring remediation, restricting or withdrawing products, and fining under Article 99. For GPAI, the EU AI Office acts directly. Cross-border cases run through the European Artificial Intelligence Board. Individuals and consumer-protection bodies can lodge complaints, which authorities are obliged to examine.

What's the relationship between EU AI Act and GDPR?

Complementary, not overlapping. GDPR governs personal data — collection, processing, lawful basis, data-subject rights. The AI Act governs AI systems — how they are built, what they do, what risks they pose — regardless of personal data. A system on synthetic data is outside GDPR but can still be high-risk. A system on personal data must satisfy both: Article 10 data governance and GDPR's lawful basis and purpose limitation. For high-risk personal-data systems, you typically need a GDPR DPIA and, under Article 27, a Fundamental Rights Impact Assessment. The two can share evidence but cannot substitute for each other.

See AccuroAI in action.
30-minute demo tailored to your top AI risk.
Book a demo
More from the blog
See AccuroAI in action.

Book a 30-minute demo and see how security teams use AccuroAI to discover, govern, and protect every AI asset across their organization.

Book a demoTalk to security