What is the EU AI Act?
+
The EU AI Act is Regulation (EU) 2024/1689, the European Union's law on artificial intelligence. It sorts AI systems into four risk tiers — prohibited, high-risk, limited-risk and minimal-risk — and attaches obligations to each tier and to each operator role: provider, deployer, importer and distributor. It has 113 articles and 13 annexes and has been in force since 01.08.2024.
Who does the EU AI Act apply to?
+
Anyone who places an AI system on the EU market or uses one in the EU in a professional capacity: providers (who build or brand it), deployers (who use it), importers and distributors. Like the GDPR it reaches organisations outside the EU whenever the system's output is used in the Union. Purely personal, non-professional use is out of scope.
What is the difference between a provider and a deployer?
+
A provider develops the system, or has it developed, and places it on the market under its own name. A deployer uses it under its own authority. The distinction decides your obligations: providers carry Articles 8–15 and the conformity route; deployers carry Article 26. A deployer that puts its own name on a high-risk system, changes its intended purpose or substantially modifies it becomes the provider under Article 25.
When does the EU AI Act apply?
+
In stages. Prohibited practices and AI-literacy duties have applied since 02.02.2025; GPAI model obligations and the penalty regime since 02.08.2025; Article 50 transparency since 02.08.2026. Two new Article 5 prohibitions apply from 02.12.2026. High-risk (Annex III) obligations apply from 02.12.2027 and AI in Annex I regulated products from 02.08.2028 — both deferred by Regulation (EU) 2026/1744, the Digital Omnibus, in force since 27.07.2026.
What counts as a high-risk AI system?
+
Two routes. Annex III lists eight areas — biometrics, critical infrastructure, education, employment, essential services such as credit and insurance, law enforcement, migration and border control, justice and democratic processes. Article 6(1) adds AI that is a safety component of a product covered by the Annex I product laws, such as medical devices or machinery. Article 6(3) lets a provider document that an Annex III system does not pose a significant risk — unless it profiles natural persons, in which case it is high-risk regardless.
What are the penalties for non-compliance?
+
Prohibited practices (Art. 5): up to €35m or 7% of worldwide annual turnover, whichever is higher. Most other obligations (e.g. high-risk duties): up to €15m or 3% of worldwide annual turnover, whichever is higher. Incorrect/incomplete/misleading info to authorities: up to €7.5m or 1% of worldwide annual turnover, whichever is higher. For SMEs and start-ups the lower of the two figures applies (Art. 99(6)).
Does the EU AI Act apply to AI tools we use but did not build?
+
Yes — as a deployer. Using a third-party recruitment screener, credit model or chatbot in a professional context brings Article 26: use it according to the provider's instructions, assign human oversight, keep the logs, tell workers and affected people, and, for public bodies and certain private deployers, run a fundamental rights impact assessment under Article 27 before first use.
Are SMEs exempt from the EU AI Act?
+
No. The obligations apply regardless of size. What SMEs get is proportionality: fines capped at the lower of the amount or percentage (Art. 99(6)), priority access to regulatory sandboxes (Art. 62), simplified technical-documentation forms for microenterprises, and lighter quality-management expectations. The classification and the core high-risk duties are the same.