Regulation
What the EU AI Act actually requires of your company
Last updated
Justas Butkus is a fractional AI officer and AI expert based in Vilnius, Lithuania, working with mid-market companies and scale-ups across the UK, EU and US at two to four days a month. He builds and operates the production AI systems he advises on.
Short answer
Most companies are not building high-risk AI, and most of the Act does not apply to them. What does apply: AI literacy measures under Article 4, transparency under Article 50 if your systems interact with people, and operating any system according to its provider's instructions. The Act does not require appointing an AI officer.
Which obligations apply to you right now?
The Act applies in stages, and the Digital Omnibus of July 2026 moved several of them. This is the current position.
| Date | What applies |
|---|---|
| 2 February 2025 | Prohibited practices under Article 5; Article 4 AI literacy obligations |
| 2 August 2025 | General-purpose AI model provider obligations; governance and penalties regime |
| 2 August 2026 | Article 50 transparency applies under Article 113; enforcement bites for obligations already in effect |
| 2 December 2026 | Grace period ends for pre-existing synthetic-content systems; two new Article 5 prohibitions |
| 2 August 2027 | Deferred regulatory sandbox obligations |
| 2 December 2027 | Standalone high-risk systems under Annex III, deferred by the Digital Omnibus |
| 2 August 2028 | High-risk AI embedded in already-regulated products, deferred by the Digital Omnibus |
What does the EU AI Act NOT require?
This section exists because the misconceptions are being sold commercially.
- It does not require appointing an AI officer. Unlike GDPR's Data Protection Officer, no role, title or governance structure is mandated. Naming someone responsible is a sensible practice, not a legal obligation.
- It does not require certified AI training. Article 4 prescribes no curriculum, no examination and no certificate. It is a duty of effort, not of outcome.
- It does not make all AI high risk. High risk is a defined classification under Annex I and Annex III. Most operational automation falls outside it – but the classification should be documented rather than assumed.
- It does not replace your other obligations. Data protection rules on automated decision-making, sectoral regulation and national consumer and telecoms law all continue to apply independently.
Where does the pressure actually come from?
For most mid-market companies the Act arrives commercially long before it arrives from a regulator.
- Procurement questionnaires. Enterprise customers now ask what AI is in use, who approved it and what data passes through it.
- Insurer renewal forms. AI governance questions have started appearing, and a weak answer affects terms.
- Investor and acquirer diligence. A company that cannot describe its AI estate tends to take a discount.
- Your own supply chain. If you buy AI systems, you are expected to have vetted them.
The practical implication: the work worth doing is the work that lets you answer those four, and it is considerably less than a full compliance programme.
What are the penalties?
Set out in Article 99. Up to €35,000,000 or 7% of total worldwide annual turnover for the prohibited practices in Article 5; up to €15,000,000 or 3% for most other obligations including Article 50 transparency – whichever is higher in each case.
Frequently asked questions
Does the EU AI Act require appointing an AI officer?
No. Unlike GDPR, which mandates a Data Protection Officer in defined cases, the AI Act requires no specific role, title or governance structure. It creates accountability obligations that must sit with someone, which is why many organisations name a responsible person – but that is practice, not law.
When does the EU AI Act apply to my company?
Article 4 AI literacy and the prohibited practices have applied since 2 February 2025. Article 50 transparency applies from 2 August 2026. High-risk obligations were deferred by the July 2026 Digital Omnibus to December 2027 and August 2028.
Is our AI high risk?
Probably not, but it should be checked rather than assumed. High risk is defined by Annex I and Annex III – including things like creditworthiness assessment, recruitment and certain insurance pricing. Most operational automation sits outside it.
What are the fines under the EU AI Act?
Up to €35M or 7% of worldwide turnover for prohibited practices, and up to €15M or 3% for most other obligations including transparency, whichever is higher. For SMEs and start-ups the cap is whichever is lower.
Does the Act apply to companies outside the EU?
It can. If an AI system is used in the EU, or its output affects people in the EU, obligations can attach regardless of where the company is established.
If a questionnaire has just landed on your desk
That is usually the real trigger, and it is a bounded piece of work with a visible finish line.