EU AI Act: The Guide for Companies to AI Compliance
The clock has been ticking since August 2024: The EU AI Act is in force, and with it a whole series of deadlines that will take effect gradually. What initially seemed like an abstract set of rules has long since arrived in everyday business life, and with the decision of the AI Omnibus in May 2026, the legal framework has noticeably evolved again. For companies, this means that anyone who uses AI, whether as a recruiting tool, ChatGPT integration or credit scoring, has obligations, regardless of whether they are a provider or operator. This insight shows what really counts now: the current deadlines, the risk classes and the concrete to-dos for companies.
Table of contents
Key Takeaways
- The EU AI Act classifies AI systems into four risk categories : prohibited, high-risk, limited risk and minimal risk
- Since February 2025, the following have been prohibited, among other things:Social scoring, biometric mass surveillance and emotion recognition in the workplace and, from December 2026, additional nudification apps (AI Omnibus, May 2026)
- High-risk systems are subject to the strictest requirements: conformity assessment, technical documentation, risk management system and human oversight
- Chatbots and generative AI must be transparently labeled from August 2026, which means that users must recognize that they are interacting with AI
- Operators also have specific obligations: they must check the intended use, ensure human oversight and document incidents
What is the EU AI Act?
The EU AI Act came into force in 2024 and has since had staggered implementation deadlines. It is the EU’s first comprehensive AI regulation with the aim of enabling trustworthy and safe AI use while respecting fundamental rights and follows a risk-based approach with four risk classes: (1) prohibited practices, (2) high-risk AI, (3) limited risk and (4) minimal risk. Most of the obligations apply to high-risk AI systems and affect both providers and operators.
Background to the AI Regulation: Why was the EU AI Act Introduced?
The European Commission developed the EU AI Act for various reasons:
- An important aspect is the protection of fundamental rights, as AI applications can increase discrimination, manipulation and surveillance. The EU AI Act prohibits this, especially in the case of biometric video surveillance and social scoring.
- Furthermore, the EU-wide uniform requirements are intended to prevent fragmentation of the EU internal market due to different national AI laws and to create a level playing field.
The latter is intended to make Europe an attractive location for trustworthy AI development through legal certainty and clear standards. The EU AI Act complements existing legal frameworks such as the General Data Protection Regulation (GDPR) and lays down binding requirements for transparency, security and human oversight in the use of AI systems.
Timeline and Deadlines of the EU AI Act
| Timing | Milestones |
| Aug 1, 2024 | EU AI Act enters into force (Regulation (EU) 2024/1689) |
| Feb 2, 2025 | Prohibitions (Unacceptable Risk) & AI Literacy obligations effective – including social scoring, biometric mass surveillance, emotion recognition in the workplace |
| Aug 2, 2025 | Requirements for General Purpose AI (GPAI) / General Purpose AI Models (incl. Large Language Models (LLMs)) are effective; GPAI Code of Practice published |
| Aug 2, 2026 | New systems: Transparency obligations (chatbots, GenAI, deepfakes) apply;
Guidelines on transparency and high-risk classification in final vote |
| Dec 2, 2026 | Extension Art. 5: Ban on Nudification Apps, Non-Consensual Intimate AI Content and Generation of Child Sexual Abuse Comes into Force*
For existing systems (before 2 Aug. 2026), transparency obligations (Art. 50 para. 2) apply* |
| Aug 2, 2027 | At least one national AI regulatory sandbox (Art. 57) must be established |
| Dec 2, 2027
|
High-risk AI compliant in regulated areas: biometrics, critical infrastructure, education, employment, migration, asylum, justice* |
| Aug 2, 2028 | High-risk AI compliant in regulated products: elevators, toys, medical devices, machines, etc.* |
*New deadlines by AI Omnibus (political agreement May 2026)
Who Does the EU AI Act Affect?
The EU AI Act generally distinguishes between different categories of actors throughout the lifecycle of an AI system. Particular focus is placed on providers and operators, whose obligations vary depending on their respective roles and responsibilities. In addition, the AI Act defines requirements for importers, distributors, and companies outside the EU that have a connection to the European market.
Providers of AI Systems
Vendors mean companies or individuals who offer an AI system under their own name on the EU market. They bear the most extensive obligations: In the case of high-risk systems, these include conformity assessment, documentation obligations, CE marking, registration, market surveillance. Transparency and AI literacy obligations also apply across risk classes.
Operators of AI Systems
Operators refer to companies that use an AI system in a professional context. Operators also have specific obligations: When operating high-risk systems, they must reconcile the intended use with the intended area of use, ensure human oversight and document incidents. AI systems with limited risk must meet transparency obligations.
Importers and distributors of AI systems
Anyone who brings AI products from third countries into the EU or resells them in the internal market must ensure that the systems are compliant and, if necessary, be liable in the alternative.
Non-EU companies with EU market relevance
Analogous to the GDPR, the EU AI Act applies extraterritorially: Any company whose AI systems are used in the EU or whose outputs affect EU citizens falls within the scope of application, regardless of the company’s registered office.
The Risk-Based Approach of the EU AI Act
| Risk level | Exemplary AI applications | Requirements of the EU AI Act | Corporate relevance |
| Verboten (Unacceptable Risk) | Social scoring, manipulative AI, real-time biometric mass surveillance, AI to predict individual crimes, scraping for facial recognition databases, nudification apps* | Complete ban with very narrow legal exceptions (e.g. biometric real-time remote identification in public spaces by law enforcement authorities in selected cases, specified in more detail in Art. 5 para. 2) | Immediate review and remediation since 2025
For supplemented AI systems, ban will apply from December 2026* Fines: up to €35 million / 7% turnover |
| Hochrisiko (High Risk) |
HR recruiting, lending, medical devices (AI-supported), critical infrastructure, education, justice, migration/asylum (Annex I / III) | Conformity assessment, documentation obligations, human oversight, risk management system, registration in EU database | High compliance effort; Deadlines from Dec. 2027 / Aug. 2028 (adjusted by AI Omnibus)
Fines: up to €15 million / 3% turnover |
| Limited Risk
|
Chatbots, generative AI (GenAI), deepfake tools, emotion recognition (outside prohibited areas) | Transparency requirements: Labeling AI interactions and AI-generated content – | Moderate requirements
Labelling obligation applies from 2 August 2026 |
| Minimal Risk | Spam filters, AI recommender systems, AI in video games, easy automation | No specific obligations; voluntary codes of conduct recommended | Low effort; Best practices make sense |
*Newly added by AI Omnibus (political agreement May 2026)
1. Prohibited AI Systems (Art. 5)
These AI applications have been completely banned since February 2025. The EU AI Act lists the following prohibited practices, among others
- Harmful AI-based manipulation and deception (e.g., subliminal techniques, exploitation of weaknesses)
- Harmful exploitation of vulnerabilities of certain groups of people (children, the elderly)
- Social scoring: Evaluation or classification of people based on social behavior by state or private actors
- Individual crime prognosis based on profiling or personality traits
- Mass undirected scraping of the internet or CCTV footage to build facial recognition databases
- Emotion Recognition: Emotion recognition in the workplace and educational institutions
- Biometric categorization to derive sensitive characteristics (political views, religion, sexual orientation)
- Real-time biometric remote identification: in public spaces through biometric video surveillance (very narrow exceptions for law enforcement)
- NEW (AI Omnibus, May 2026): AI systems that generate non-consensual sexually explicit content or child abuse material (nudification apps)
2. High-Risk AI Systems (Art. 6 and Annex I and III)
High-risk AI systems are permissible, but subject to strict requirements. The Commission published draft guidelines on accurate classification in May 2026 . Typical company examples are:
- HR & Recruiting: AI-supported applicant pre-selection, performance evaluation, termination decisions
- Financial services: Automated credit decisions, credit checks, fraud detection with decision-relevance
- Healthcare: AI Medical Diagnosis and Therapy Decision Systems
- Critical infrastructure: AI in energy, water and traffic control
- Education: systems for assessing learners and managing access to education
- Migration & Asylum: Automated review of visa applications, risk assessments
Justice: risk assessment tools, evaluation of evidence, decision support in court proceedings
3. Limited Risk (Art. 50)
AI systems with limited risk are subject to transparency requirements. These include
- Chatbots and AI assistants: Users must be informed that they are interacting with an AI system
- Generative AI (GenAI): Providers must label AI-generated content in a machine-readable way; Operators must report on deepfakes and AI-generated publications on matters of public interest
- Emotion Recognition & Biometric Categorization: Operators must inform data subjects about the use (unless it falls under Art. 5)
4. Minimal Risk
The vast majority of AI applications in use today fall into this category and are not subject to specific obligations. Voluntary codes of conduct are recommended for:
- Spam Filtering and Email Categorization
- Product recommendation systems in online shops
- AI in video games
- Simple process automation without decision-making relevance for people
What Does the EU AI Act Mean in Concrete Terms for Companies?
The EU AI Act is not a purely operational compliance issue, but it changes strategic priorities. Companies that invest in regulatory readiness at an early stage and build a solid AI governance framework ensure their ability to act and reduce regulatory risks. Although the high-risk deadlines extended by the AI Omnibus provide additional preparation time (up to 16 or 24 months), the implementation of the requirements should not be underestimated.
Impact on AI Projects
From now on, every new AI project should follow an AI compliance check: Before starting, a risk classification must be carried out according to the EU AI Act categories. High-risk projects require risk management systems, documentation obligations and human oversight from the very beginning. Furthermore, AI literacy is crucial in the team: Employees must understand the consequences of using their AI systems.
Impact on Procurement of AI Solutions
Operators who procure AI solutions from third-party providers are not automatically released from responsibility. Procurement and IT departments need to ensure that procured systems are compliant and vendors provide the necessary documentation and proof of compliance.
Before concluding the contract, a structured examination of the provider is indispensable: risk class of the system, existence of proof of conformity and contractual anchoring of audit and control rights.
What Questions Companies Should Ask Their AI Providers
- In which risk category do you classify the AI system according to the EU AI Act?
- Is there a conformity assessment? (Mandatory for high-risk systems; CE marking required)
- Are you registered in the EU-wide AI register (for high-risk systems)?
- What technical documentation do you provide?
- How is human oversight ensured in the system?
- How do you meet transparency requirements (AI-generated content labeling, chatbot disclosure)?
- How do you deal with data protection – in line with the GDPR?
- How are security updates and incident reporting handled?
What are the Obligations for Companies?
Documentation Requirements
Providers and operators of high-risk AI systems are obliged to provide extensive documentation: technical documentation (design, data, training methods), risk analyses, test results and proof of conformity. The documentation must be kept for at least 10 years after placing on the market and must be submitted to the market surveillance authority upon request.
Risk Management
For high-risk AI systems, a continuous risk management system is mandatory: identification and analysis of risks, implementation of mitigation measures, as well as ongoing review of the effectiveness of measures and evaluation of risks. Risk management is not a one-time act, but an ongoing process.
Transparency Requirements
Labeling AI-Generated Content
Providers of generative AI must ensure that AI-generated content (texts, images, audio, video) is marked in a machine-readable way so that it can be technically recognized as AI-generated. This is especially true for deepfakes and AI-generated publications on matters of public interest.
Deepfake Labeling
Operators must inform people if they are exposed to synthetic media (deepfakes). AI-generated image, audio, or video content that shows real people, places, or events must be explicitly labeled.
Disclosure Requirements
When people interact with an AI system (e.g., chatbot), they need to be informed (unless the use of AI is obvious). Operators of emotion recognition or biometric categorization systems must inform data subjects. High-risk systems must be registered in the EU database.
Human Oversight
Human oversight is one of the central requirements of the EU AI Act for high-risk systems. Humans must be able to monitor, understand, correct, and disable the AI system if necessary. This requires technical measures (intervention options, explainability) and organizational structures (defined responsibilities, training).
Monitoring and Auditability
High-risk AI systems must be continuously monitored after market launch (post-market monitoring). Serious incidents must be reported to the market surveillance authorities. Decisions must be comprehensible. Auditability and explainability are basic technical requirements.
Data Quality and Governance
High-risk AI systems require high-quality training data: representative, error-free and in line with the purpose of the system. Data governance encompasses the entire data pipeline from collection to processing to deletion.
EU AI Act and generative AI (ChatGPT, LLMs, Copilot)
Are ChatGPT Applications Affected?
Yes. Generative AI systems (GenAI) in the form of large language models such as Claude, ChatGPT, Microsoft Copilot, Google Gemini or others fall under the EU AI Act as General Purpose AI (GPAI).
The separation of responsibilities is crucial: The underlying model is the responsibility of the provider (e.g. OpenAI); the company that integrates the model into an enterprise application bears as the operator: own responsibility for the concrete use.
General Purpose AI Requirements
GPAI requirements have been in place since August 2025. In July 2025, the Commission published three key tools:
- guidance on the scope of GPAI obligations,
- the GPAI Code of Practice (voluntary compliance tool) and
- a template for the public summary of training data.
For GPAI models with systemic risk (very high computing capacity, wide distribution), the following also apply: red teaming, extended risk assessment and incident reporting to the AI Office.
What Companies Need to Consider When Using Generative AI
- Labeling (from Aug. 2, 2026): All content created with GenAI must be marked as AI-generated in a machine-readable way; Deepfakes must be visibly marked.
- Acceptable Use Policies: Internal AI policies define the purposes for which GenAI may be used.
- Data protection: The entry of personal or confidential data into external AI systems must be checked for GDPR compliance.
- AI Literacy: Employees must be trained in the use of GenAI tools, both technically and legally.
- Vendor contracts: Contracts with GenAI vendors should include compliance assurances, data processing agreements (DPAs), and liability provisions.
The EFS Consulting EU AI Act Checklist for Businesses
Inventory of All AI Systems
- Create an inventory of all AI applications used and developed (incl. GenAI tools such as Copilot, ChatGPT)
- Making a distinction: in-house development vs. sourcing from third-party providers
- Document areas of application, purpose and affected groups of people per system
- Capture data flows and interfaces to other systems
Perform Risk Classification
- Rank each AI system against the four EU AI Act risk levels (the Commission’s classification guidelines (expected before Aug. 2026) can be included)
- Justify and document classification decisions in writing
- Regular review and update of the risk classification (e.g. in the event of system changes or new use cases)
Defining Review and Approval Processes and Enterprise AI
- Define approval workflow for new AI use cases and tools
- Define test criteria for special applications (e.g. individual developments, agent-based systems)
- Clarify responsibilities for release decisions
Define Responsibilities
- Appoint AI compliance officer(s)
- Define escalation paths and decision-making processes for AI governance
- Establish interfaces with data protection, legal and IT security departments
Establishing Governance
- Introduce AI Directive and Acceptable Use Policy
- Implement processes for conformity assessment and CE marking (high risk)
- Operationalize documentation standards and obligations
- Conduct AI literacy training for employees
- Implement Data Governance Framework in line with GDPR and EU AI Act
- Establish transparency mechanisms for chatbots and GenAI tools by August 2026
Define Regulations for Employees
- Set usage guidelines for chatbots and GenAI tools in the workplace
- Communicating Allowed vs Prohibited Use Cases for Employees
- Define reporting channels in case of suspicion of improper use of AI (shadow AI)
Implementing Monitoring
- Setting up post-market monitoring for high-risk systems
- Define and test incident reporting processes
- Regular review of the risk classification, in particular according to final Commission guidelines
- Define KPIs and metrics for AI performance and compliance
Prepare for an Audit
- Keep technical documentation complete and up-to-date
- Provide proof of conformity (conformity assessment, CE)
- Register high-risk systems in the EU database (at the latest by the respective application deadlines)
Conclusion
The EU AI Act marks a turning point: Artificial intelligence must be designed to be secure, transparent and human-centered, and that is not an option, but an obligation. Current developments such as the AI Omnibus, new prohibition rules and ongoing guideline consultations show that the legal framework is developing dynamically and companies need to stay up to date. Companies that act now are turning compliance requirements into strategic strength.
EFS Consulting accompanies you with field-tested expertise along the entire path to regulatory readiness: From the initial inventory to risk classification to the complete AI Compliance Framework.
FAQs
What is the EU AI Act?
The EU AI Act (Regulation (EU) 2024/1689) is the world’s first comprehensive, binding set of rules for artificial intelligence. The regulation defines requirements and prohibitions for AI systems based on their risk potential and applies directly in all EU member states.
When does the EU AI Act come into force?
The EU AI Act has been in force since 1 August 2024. Bans: since February 2, 2025. GPAI rules: since August 2, 2025. Transparency obligations and full applicability: from 2 August 2026. High-risk AI (regulated areas): from 2 December 2027. High-risk AI in regulated products: from 2 August 2028 (according to AI Omnibus, political agreement 7 May 2026).
What are the 4 levels of the EU AI Act?
The EU AI Act distinguishes between four risk levels: (1) Unacceptable Risk: completely prohibited (e.g. social scoring, nudification apps); (2) High Risk: strict compliance obligations (e.g. HR-AI, credit decision); (3) Limited Risk: Transparency requirements from August 2026 (e.g. chatbots, GenAI); (4) Minimal Risk: no specific obligations (e.g. spam filters).
Who is affected by the EU AI Act?
Suppliers, operators, importers and distributors – even from non-EU countries, if their systems are used in the EU market or affect EU citizens. The EU AI Act thus effectively applies globally to all companies with an EU connection.
Does the EU AI Act also apply to ChatGPT?
Yes. ChatGPT and comparable LLMs fall under the EU AI Act as General Purpose AI (GPAI). Providers such as OpenAI have been subject to transparency and documentation obligations since August 2025. Companies that use such tools internally have their own obligations as operators, in particular with regard to the labelling of generated content (from August 2026) and GDPR-compliant data processing.