AI, explained
Does the EU AI Act apply to my business?
For most companies the honest answer is yes it applies, and no, it does not require very much, because your use case sits in the lowest tier.
The Act regulates uses, not technologies. The same model can be unregulated in one deployment and high risk in another, so the question is never whether you use AI. It is what you point it at, and whether you are the provider who builds it or the deployer who runs it.
The four tiers, in the order they matter to you
- Prohibited. Social scoring, untargeted scraping of facial images to build recognition databases, emotion inference in workplaces and schools, certain manipulative or exploitative systems. If you are here, stop.
- High risk. The tier that catches ordinary companies by surprise. It covers AI used in recruitment and candidate screening, decisions on promotion or termination, access to education, creditworthiness assessment for individuals, risk pricing in life and health insurance, essential public services, plus AI embedded as a safety component in regulated products.
- Limited risk, transparency duties. Chatbots must make clear a person is talking to a machine. Synthetic image, audio and video content must be marked as artificially generated.
- Minimal risk. Everything else, which in practice is most internal automation, document processing, marketing content, search and analytics.
Provider or deployer
Obligations split by role. A provider develops the system or puts it on the market under its own name. A deployer uses it under its own authority. Deployers of high risk systems still carry duties: human oversight, using the system according to instructions, monitoring, keeping logs, and informing affected workers. Note that if you substantially modify a high risk system, or brand somebody else's as your own, you can become the provider.
What a normal company should actually do
- Write down every AI system in use, including the tools individual teams adopted without telling anyone.
- Classify each against the tiers above. Be honest about the recruitment and credit ones.
- Disclose clearly wherever a customer talks to a bot or sees generated media.
- Train the people who operate these systems. AI literacy for staff is an explicit duty, not a nice-to-have.
- Keep logs and a named human owner for anything that affects a person's rights, money or job.
Timing and a caution
The Act entered into force in 2024 and applies in phases, with prohibitions and AI literacy first, general purpose model rules next, and the high risk obligations later. The phasing has been actively debated and adjusted, so verify the current dates for your tier with your legal advisor rather than relying on any article, this one included. Separately, remember GDPR did not go anywhere and usually bites first.
If you want the inventory and classification done properly, that is a normal first step in a Digiton AI audit.
Frequently asked questions
Does the EU AI Act apply to my business?
If you place an AI system on the EU market or use one inside the EU, yes, and it reaches companies established outside the EU when the output is used here. The weight of the obligation depends entirely on risk tier, and most ordinary business uses land in the minimal risk tier.
Is a customer service chatbot high risk?
Normally no. A support chatbot sits in the limited risk transparency tier, so the requirement is that people can tell they are dealing with a machine. It moves toward high risk only when it starts making or materially shaping decisions about credit, employment, education or access to essential services.
What are the penalties?
The Act sets tiered fines calculated as the higher of a fixed amount or a percentage of worldwide annual turnover, with the largest band reserved for prohibited practices and lower bands for other breaches. Confirm the current figures with a lawyer, because the enforcement details continue to be refined.
Related
Ready to put AI to work?
Book a discovery audit and we will map the highest-ROI AI agents and automations for your business.
Book a discovery audit →