The EU AI Act is the first comprehensive European law to establish rules governing the development and use of artificial intelligence. The law applies to organizations that offer, import, distribute, or use AI systems within the EU, regardless of where they are based. In this article, we answer the most frequently asked questions about the EU AI Act and what it specifically means for your organization.
Which organizations are subject to the EU AI Act?
The EU AI Act applies to any organization that offers, deploys, imports, or distributes AI systems within the European Union. This includes both companies based in the EU and companies outside the EU whose AI systems are used by EU users or whose output affects people in the EU.
The law distinguishes between different roles:
- Providers: organizations that develop and market AI systems. They bear the heaviest obligations.
- Deployers (data controllers): organizations that deploy an AI system under their own authority, such as a company that uses an AI chatbot from a third-party provider in its customer service department.
- Importers and distributors: entities that import or resell AI systems from outside the EU.
An important point to note: a deployer can automatically assume the role of provider as soon as they add their name to a system, make a substantial change to it, or alter its use in such a way that the system falls into the high-risk category. In practical terms, this means that virtually every organization currently using AI falls within the scope of the law and has at least the obligations of a deployer.
What are the four risk categories under the EU AI Act?
The EU AI Act classifies AI applications into four risk levels: unacceptable risk (prohibited), high risk (strictly regulated), limited risk (minimal transparency requirements), and minimal or no risk (unregulated). The category determines which obligations apply to your organization.
Here is an overview of the four levels:
- Unacceptable risk (prohibited): AI applications that seriously violate fundamental rights are completely prohibited. Examples include subliminal manipulation techniques, social scoring by governments, predictive policing based on profiling, emotion recognition in the workplace or in educational institutions, and the creation of facial recognition databases through indiscriminate scraping. These prohibitions have been in effect since February 2, 2025.
- High risk: Systems that could have a significant impact on fundamental rights or security. Examples include AI in biometrics, critical infrastructure, education, human resources management, access to essential services, law enforcement, and migration. Extensive obligations apply to this category (see the next section).
- Limited risk: Applications such as chatbots or deepfake generators. In these cases, the main requirement is transparency: users must know that they are interacting with AI.
- Minimal or no risk: The vast majority of current AI applications, such as spam filters or recommendation systems in non-sensitive contexts, fall outside the scope of regulation.
Please note: Systems that perform profiling of natural persons are always high-risk, regardless of the context.
What obligations apply to high-risk AI systems?
High-risk AI systems are subject to extensive obligations that affect both providers and deployers. Providers bear the greatest responsibility and must comply with a broad range of technical and organizational requirements throughout the system’s entire lifecycle.
Requirements for Providers of High-Risk AI
If your organization develops and markets a high-risk AI system, the following obligations, among others, apply:
- Establish and maintain a continuous risk management system.
- Working with training, validation, and test data that are representative and as free of errors as possible, including systematic investigation and mitigation of bias.
- Prepare technical documentation in accordance with Annex IV of the law.
- Enable automatic logging of events throughout the product lifecycle.
- Adopt a design that effectively enables human oversight, including awareness of automation bias.
- Implement a quality management system, conduct a conformity assessment, issue an EU declaration of conformity, apply the CE marking, and register the product in the EU database.
Requirements for Deployers of High-Risk AI
If your organization uses a high-risk system from an external provider, the obligations are less stringent but by no means optional:
- Use the system in accordance with the provider’s instructions for use.
- Assign human supervision to qualified and trained employees.
- Keep logs for at least six months.
- Inform employees before the equipment is put into service (Article 26(7)).
- Where applicable, conduct a data protection impact assessment (DPIA).
Under Article 86, individuals who are subject to a decision made by a high-risk AI system have the right to request an explanation of the factors that determined that decision.
When does my organization need to comply with the EU AI Act?
The EU AI Act will take effect in phases. The first obligations are already in effect, but the most far-reaching requirements for high-risk systems will not apply until 2026 and 2027. The exact deadline depends on your role and the type of AI system you use.
The implementation timeline is as follows:
- February 2, 2025: The prohibitions set forth in Article 5 (unacceptable risk) and the requirement for AI literacy (Article 4) are in effect.
- August 2, 2025: Requirements for GPAI models (large language models and similar systems), the European governance structure, and penalty provisions take effect. National supervisory authorities must have been designated.
- August 2, 2026: Most of the requirements for high-risk Annex III systems will take effect. For many organizations, this is the most important deadline.
- August 2, 2027: Requirements for high-risk AI used as a safety component in regulated products (Annex I) take effect. GPAI models that were on the market before August 2025 must therefore also be compliant.
The law will be evaluated in 2028 and 2029, with a final report on enforcement in 2031. Don’t wait until the deadline: achieving compliance takes time, especially if you have to set up a quality management system and risk documentation from scratch.
What are the fines for noncompliance with the EU AI Act?
The EU AI Act establishes a tiered penalty system in which the amount of the penalty depends on the severity of the violation. The most severe penalties apply to prohibited AI practices, followed by violations of obligations regarding high-risk systems.
The fine structure is organized as follows:
- Up to 35 million euros or 7% of global annual revenue (whichever is higher) for violations of the prohibitions set forth in Article 5, such as the use of prohibited manipulation techniques or real-time biometric identification in public spaces.
- Up to 15 million euros or 3% of global annual revenue for failure to comply with obligations regarding high-risk systems or GPAI models.
- Up to 7.5 million euros or 1.5% of global annual revenue for providing inaccurate information to regulatory authorities.
The penalty provisions will take effect on August 2, 2025. For small and medium-sized enterprises, there are revenue-based caps that are proportional to the size of the business. National regulators will monitor compliance and have the authority to conduct investigations and impose sanctions.
How can an organization prepare for the EU AI Act?
Proper preparation for the EU AI Act starts with understanding: which AI systems do you use or develop, which risk category do they fall into, and what obligations arise from that? Based on that understanding, you can build the necessary governance and documentation step by step.
A practical approach consists of the following steps:
- Create an AI inventory: Identify all AI applications that your organization uses or develops, including tools from third-party vendors.
- Classify the risk: Determine the risk level for each system based on the four categories. Keep in mind that systems that perform profiling are always high-risk.
- Determine your role: Are you a supplier, deployer, importer, or distributor? Your role determines what obligations you have.
- Establish governance: Implement a risk management system, prepare technical documentation, designate individuals responsible for human oversight, and develop a policy on AI literacy for employees.
- Review contracts with AI vendors: As a deployer, you rely on your vendor’s documentation and user guides. Ensure that contracts include the appropriate provisions regarding logging, explainability, and compliance.
- Plan for the deadlines: Start preparing now for the requirements that will apply to high-risk Annex III systems as of August 2, 2026.
Organizations that already comply with ISO 27001 (information security), ISO 9001, or ISO 26000 have a head start: the process-based approach of these standards aligns well with the governance requirements of the EU AI Act.
How Pegamento Helps with EU AI Act Compliance
We understand that the EU AI Act is a complex challenge for many organizations, especially if you’re also looking to use AI to improve your customer service. Pegamento helps you combine these two goals: using AI intelligently and responsibly, while ensuring compliance.
What we can do for your organization:
- Responsible AI Implementation: Our Agentic AI for customer service is designed with human oversight as a core principle, which directly aligns with the requirements of the EU AI Act for high-risk applications.
- Transparent technology: We use proven, documented modules that support the legal requirements for explainability and logging.
- Everything under one roof: From implementation to management and support, you have a single point of contact and no complex supply chain to complicate compliance.
- Certified Process: As an ISO 27001-, ISO 9001-, and ISO 26000-certified company, we already operate in accordance with the governance principles required by the EU AI Act.
- No costly custom development, just a smart combination of proven modules: Our solutions are flexible and scalable, allowing you to act quickly without major investment risks.
Would you like to know where your organization stands right now and what steps you can take? Contact us, and we’d be happy to help you figure it out.
Frequently Asked Questions
Does the EU AI Act also apply to small and medium-sized enterprises (SMEs)?
Yes, the EU AI Act generally applies to all organizations that use AI within the EU, regardless of their size. However, there are some mitigating measures for SMEs: fines are capped based on revenue, and the European Commission is working on simplified documentation requirements. Nevertheless, even as an SME, it’s wise to start an AI inventory and risk classification early on, so you won’t be caught off guard as the deadlines approach.
What if my organization uses AI tools from major providers such as Microsoft, Google, or OpenAI—am I still responsible?
As a deployer, you are responsible for how you deploy the AI system, even if you use tools from major third-party providers. You are required to deploy the system in accordance with the provider’s user manual, ensure human oversight, and retain logs for at least six months. In addition, review your contracts with these suppliers: they must provide sufficient information about the operation, limitations, and compliance status of their systems to enable you, as the deployer, to meet your own obligations.
How do I know if my AI system falls into the high-risk category?
An AI system is considered high-risk if it falls within the areas of application listed in Annex III of the law, such as biometrics, human resources management, education, access to essential services, or law enforcement. In addition, systems that perform profiling of natural persons are always high-risk, regardless of the context. If you’re unsure about the classification of a specific system, consult a legal or compliance advisor with knowledge of the EU AI Act, or use the risk assessment tools provided by the European Commission.
What exactly does the AI literacy requirement (Article 4) entail, and how do I address it?
Article 4 requires organizations to ensure that employees who use or manage AI systems have sufficient knowledge and skills to do so responsibly. In practice, this means you must offer training tailored to the employee’s role: an end user needs different knowledge than a system administrator or a decision-maker who relies on AI output. Start by conducting a baseline assessment of the current level of AI knowledge within your organization and build a targeted training program from there—this requirement has been in effect since February 2, 2025.
What is the difference between the EU AI Act and the GDPR, and how do they relate to each other?
The GDPR regulates the protection of personal data, while the EU AI Act specifically addresses the risks posed by AI systems as such—even when no personal data is involved. In practice, however, the two laws overlap significantly: many high-risk AI systems process personal data, meaning that both GDPR and EU AI Act obligations apply. A DPIA (Data Protection Impact Assessment) that you’re already conducting under the GDPR can also provide input for the risk management required by the EU AI Act—so the two frameworks reinforce each other.
Can my organization be fined for AI systems that were already in use before the law took effect?
Existing high-risk AI systems that were already on the market before August 2026 will, in principle, have until August 2027 to comply with the requirements, but this applies only if no substantial changes are made to the system. However, there is no transition period for prohibited AI applications (Article 5): these are prohibited as of February 2, 2025, regardless of when the system was implemented. It is therefore wise to start assessing existing AI applications against the prohibited categories now.
How do I properly document my AI systems without deploying an entire compliance team?
Start with a simple but structured AI inventory: for each system, note what it does, what data it uses, who is responsible for it, and what risk level applies. For high-risk systems, the law requires technical documentation in accordance with Annex IV, but the threshold is lower for deployers than for providers. Take advantage of existing frameworks such as ISO 27001 or ISO 9001 if your organization already uses them—their process-based structure aligns well with the documentation requirements of the EU AI Act and saves you from duplicating work.


