EU AI Act: The AI Compliance Guide for Businesses in 2026
The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive law regulating artificial intelligence, and it applies to any company, European or not, that develops, distributes, or uses AI systems whose output is used within the European Union. For a company that already relies on ChatGPT, Claude, or in-house machine learning models, the question is no longer whether the regulation applies, but which obligations follow and when.
What does the EU AI Act require from SMEs?
The AI Act does not introduce a blanket ban on artificial intelligence: it adopts a risk-based approach, where obligations are proportionate to a system's potential impact on fundamental rights, safety, and health. This means an SME using a chatbot to answer customer questions faces very different obligations than a company using AI to screen job candidates or assess creditworthiness. Company size does not exempt anyone from the rules, but the regulation does provide lighter documentation requirements for SMEs and startups.
What are the AI Act risk levels?
The regulation classifies AI systems into four levels of increasing risk, and the level determines which obligations apply.
- Unacceptable risk: practices banned outright, such as social scoring, subliminal manipulation, or emotion recognition in the workplace, with limited medical or safety exceptions.
- High risk: systems used in critical areas such as recruitment, credit scoring, medical devices, critical infrastructure, or student assessment; these require full compliance before being placed on the market.
- Limited risk: systems such as chatbots, deepfakes, and generative tools, mainly subject to transparency obligations toward the end user.
- Minimal risk: most everyday AI applications, such as spam filters, recommendation engines, and video games, with no specific obligations beyond general good practice.
How do I know if my company is in scope?
The first step is understanding which role your company plays with respect to a given AI system: 'provider' if you develop or commission a system to place it on the market under your name, or 'deployer' if you use it internally under your own professional responsibility. Most companies that integrate ChatGPT or Claude into an internal process act as deployers of a system supplied by a third party, not as providers. This simplifies some documentation duties, but it does not remove the responsibility to assess the risk of the specific use case: the same language model can be minimal risk when used to summarize internal documents, and high risk when used to screen résumés for a hiring decision.
What concrete obligations apply at each level?
Obligations differ substantially between high-risk and limited-risk systems, and this is where most companies need to focus their compliance effort.
Obligations for high-risk systems
- Documented risk management system, kept up to date over time
- Training datasets tracked and checked for quality and bias
- Detailed technical documentation and activity logging
- Effective human oversight before decisions with significant impact
- Conformity assessment and registration in an EU database
Obligations for limited-risk systems
- Clearly inform users they are interacting with an AI system
- Label artificially generated content (images, audio, video)
- Disclose when text is AI-generated or AI-modified, where relevant
- Maintain an internal acceptable-use policy for AI tools
- No formal conformity assessment required
What does the compliance timeline mean for companies already using AI?
The AI Act's deadlines are staggered: some obligations, such as the bans on unacceptable-risk practices, are already fully applicable; others, related to high-risk systems and governance of general-purpose AI models, are being phased in progressively over the course of 2025-2026, as the regulatory deadlines take effect. For a company that has already put AI tools into production, the priority is not chasing an exact date on a calendar, but starting an inventory and assessment process now, so it doesn't have to scramble once the obligations become binding for its specific use case.
How do you build an internal AI governance process?
An effective AI governance process doesn't necessarily require a dedicated legal department: for an SME, a structured five-step path is enough.
- AI inventory: catalog every AI system in use, including 'shadow' tools adopted by individual teams without central approval.
- Risk assessment: classify each system under the AI Act's four risk levels and identify your own role, provider or deployer.
- Documentation: draft usage policies, logs of relevant automated decisions, and instructions for internal users.
- Human oversight: define who reviews critical outputs before they affect customers, employees, or third parties.
- Transparency toward end users: clearly communicate when content or a response is AI-generated or AI-assisted.
What are the most common mistakes companies make?
- Treating AI compliance as a purely legal problem, without involving IT and product teams.
- Failing to inventory AI tools adopted informally by employees, so-called shadow AI.
- Confusing a vendor's compliance, such as OpenAI's or Anthropic's, with your own compliance as a user.
- Postponing risk assessment until a specific regulatory deadline is imminent.
- Not setting up a human oversight channel for high-impact decisions generated by AI.