AI, explained

Does the EU AI Act apply to my business?

For most companies the honest answer is yes it applies, and no, it does not require very much, because your use case sits in the lowest tier.

Does the EU AI Act apply to my business? If you put an AI system on the EU market or use one in the EU, the Act applies to you, including companies outside the EU whose output is used here. What it demands depends on risk tier. Most business uses are minimal risk, where the real duty is transparency and staff competence.

The Act regulates uses, not technologies. The same model can be unregulated in one deployment and high risk in another, so the question is never whether you use AI. It is what you point it at, and whether you are the provider who builds it or the deployer who runs it.

The four tiers, in the order they matter to you

Provider or deployer

Obligations split by role. A provider develops the system or puts it on the market under its own name. A deployer uses it under its own authority. Deployers of high risk systems still carry duties: human oversight, using the system according to instructions, monitoring, keeping logs, and informing affected workers. Note that if you substantially modify a high risk system, or brand somebody else's as your own, you can become the provider.

What a normal company should actually do

  1. Write down every AI system in use, including the tools individual teams adopted without telling anyone.
  2. Classify each against the tiers above. Be honest about the recruitment and credit ones.
  3. Disclose clearly wherever a customer talks to a bot or sees generated media.
  4. Train the people who operate these systems. AI literacy for staff is an explicit duty, not a nice-to-have.
  5. Keep logs and a named human owner for anything that affects a person's rights, money or job.

Timing and a caution

The Act entered into force in 2024 and applies in phases, with prohibitions and AI literacy first, general purpose model rules next, and the high risk obligations later. The phasing has been actively debated and adjusted, so verify the current dates for your tier with your legal advisor rather than relying on any article, this one included. Separately, remember GDPR did not go anywhere and usually bites first.

If you want the inventory and classification done properly, that is a normal first step in a Digiton AI audit.

Frequently asked questions

Does the EU AI Act apply to my business?

If you place an AI system on the EU market or use one inside the EU, yes, and it reaches companies established outside the EU when the output is used here. The weight of the obligation depends entirely on risk tier, and most ordinary business uses land in the minimal risk tier.

Is a customer service chatbot high risk?

Normally no. A support chatbot sits in the limited risk transparency tier, so the requirement is that people can tell they are dealing with a machine. It moves toward high risk only when it starts making or materially shaping decisions about credit, employment, education or access to essential services.

What are the penalties?

The Act sets tiered fines calculated as the higher of a fixed amount or a percentage of worldwide annual turnover, with the largest band reserved for prohibited practices and lower bands for other breaches. Confirm the current figures with a lawyer, because the enforcement details continue to be refined.

Related

AI SEO in LisbonAI agency in LisbonBook an AI audit

Ready to put AI to work?

Book a discovery audit and we will map the highest-ROI AI agents and automations for your business.

Book a discovery audit →