Web Analytics Made Easy - Statcounter

Artificial Intelligence

EU AI Act Compliance: Risk, Penalties, Timeline & Checklist For Business Implementing AI

9 minutes

This practical EU AI Act guide explains whether the Act applies to you, what to assess, and how to approach compliance throughout the project.

In 2025, one in five EU enterprises used AI, up from 13.5% in 2024. That growth now carries compliance implications: bans on certain AI practices, AI literacy duties, general-purpose AI model rules, and transparency requirements that already apply.

If your business develops, purchases, or deploys AI in the EU, it’s critical for you to know how the regulation affects your project before key technical decisions are made.

What Is EU AI Act Compliance?

EU AI Act compliance refers to the legal requirements your business must meet based on an AI system’s intended purpose, risk level, and your role in the AI supply chain.

The EU AI Act may apply to your business if you place an AI system or general-purpose AI model on the EU market, use an AI system in the EU, or operate elsewhere while the system’s output is used in the EU.

What happens if the EU AI Act applies to your business?

If that’s the case for you, the real question is which obligations apply. The Act distinguishes between:

  • Provider: You’re generally a provider if you develop an AI system, have one developed, and release it under your name
  • Deployer: You’re a deployer if you use one under your authority for work

A substantial modification or new purpose can change your role.

For instance, a customer service chatbot may need to tell people that they’re interacting with AI. Or a system that screens job applications can qualify as high-risk because its output may affect access to employment.

Please also remember that if your business uses ChatGPT, Copilot, or another third-party AI tool, the company supplying it isn’t the only party with obligations under the Act.

You may be a deployer when you use the tool under your authority for professional purposes. Therefore, check whether its output influences decisions about employment, credit, education, or healthcare since these uses can attract additional requirements.

EU AI Act Compliance Checker: Does the Act Apply to Your Business?

The flowchart below offers an initial scope check:

EU AI Act Compliance Checker

Note: You still need to confirm exclusions, your role, and the system’s risk level.

EU AI Act Explained: Risk Categories

Once you know that the Act may cover your business, it’s time to classify the intended use. The EU AI Act risk categories focus on possible effects on safety, livelihoods, and fundamental rights. Here’s what that looks like:

Risk categoryCommon examplesWhat it means for your business
Unacceptable riskHarmful manipulation, exploitation of vulnerable people, social scoring, profiling-based criminal-risk prediction, and certain biometric practicesThese practices are prohibited, subject to limited exceptions in the Act. The prohibitions have applied since February 2025.
High riskAI used for recruitment, education admissions, creditworthiness, essential services, critical infrastructure, medical devices, law enforcement, migration, or justiceProviders face requirements covering risk management, data governance, records, human oversight, performance, security, conformity assessment, and registration. Deployers must follow instructions, assign oversight, monitor performance, and respond to risks.
Transparency risk, often called limited riskChatbots, deepfakes, emotion recognition, biometric categorization, and certain AI-generated contentPeople may need to know that they are interacting with AI or viewing generated content. Some outputs require machine-readable marking. The transparency rules have applied since August 2026.
Minimal or no riskSpam filters, AI-enabled games, and low-impact administrative toolsThe AI Act imposes no mandatory requirements specific to most of these systems, although other laws and voluntary codes may still matter.

What Non-Compliance With the EU AI Act Could Cost Your Business

Your role and obligations establish where non-compliance can occur. The Act sets maximum penalty thresholds, while regulators consider factors such as severity, duration, negligence, cooperation, company size, and harm when deciding the final amount.

InfringementMaximum threshold
Prohibited practices or certain data-related requirements€35 million or 7% of worldwide annual turnover
Other specified obligations, including provider, deployer, and transparency requirements€15 million or 3% of worldwide annual turnover
Incorrect, incomplete, or misleading information supplied to authorities€7.5 million or 1% of worldwide annual turnover

Enforcement can also affect whether you can continue using or offering the system. Authorities may require you to take corrective action and, if non-compliance persists, restrict, prohibit, withdraw, or recall the system.

Your maximum penalty also depends on the size of your business. If you represent a larger company, the higher of the fixed amount or turnover percentage applies. If you represent an SME or startup, the lower figure applies.

For example, if your business is an SME with €2 million in worldwide annual revenue, the second threshold would cap the penalty at €60,000 rather than €15 million. The final amount would depend on the circumstances.

You can read more about these thresholds as set out in the EU’s current penalty guidance.

EU AI Act Timeline: Key Dates for Your Business

The following EU AI Act timeline shows which requirements apply now and where your business still has preparation time:

DateWhat changedWhat you should do
February 2, 2025Prohibited practices, definitions, and AI literacy provisions began to applyStop prohibited uses and train relevant employees.
August 2, 2025Governance and general-purpose AI model obligations began to applyConfirm documentation, copyright, and risk duties if you provide a model.
August 2, 2026Broad application, transparency rules, and enforcement powers took effectReview disclosures, content marking, governance, and current AI uses.
December 2, 2027High-risk requirements begin for Annex III use casesPrepare systems used in recruitment, education, credit, and essential services.
August 2, 2028High-risk requirements begin for regulated products under Annex ICoordinate AI Act work with the product’s conformity process.

The extensions apply to the EU AI Act high risk requirements scheduled for 2027 and 2028; the earlier milestones in this timeline remain unchanged.

A Practical EU AI Act Compliance Checklist for Your AI Project

Here’s how to translate the EU AI Act requirements into project decisions across the software development lifecycle:

1. Before development

The first step is to write a precise intended-purpose statement covering what the AI system will do, who will use it, who may be affected, where it will operate, and which decisions its output will support.

For example: “The system summarizes support tickets for a human agent; it doesn’t approve refunds or restrict customer accounts.”

Use this scope to confirm whether you’re a provider, deployer, or another regulated party. Classify the risk, map related requirements such as the GDPR, and assign responsibility.

Record the system in an AI inventory with its owner, provider, intended purpose, operating region, affected groups, external models or APIs, and current risk classification. Update the record whenever the system or its use changes.

2. During development

Next, create compliance evidence alongside the technical work. That means you need to record your data sources, permitted uses, preparation steps, assumptions, known model limitations, foreseeable misuse, and material system changes.

Establish controls for data quality, access, logging, human review, and transparency.

In addition, make your testing requirements measurable. For each accuracy, fairness, robustness, or security requirement, specify the metric, test dataset, acceptance threshold, and action your team must take if the system falls short.

3. Before deployment

Then, test the system against its intended purpose using representative cases and realistic edge cases. Record each result, required correction, and final approval owner.

Give reviewers incorrect, biased, and uncertain outputs to confirm that they can identify problems, override or stop the system, and follow the escalation process.

Where required, complete the conformity assessment or registration. If you deploy a high-risk system, check whether you must also conduct a fundamental rights impact assessment) before its first use.

Train the employees responsible for using or supervising the system, and collate how they should report incidents and unexpected behavior.

4. After deployment

In the end, decide what you’ll monitor, who will review it, how frequently reviews will occur, and which thresholds will trigger investigation. Your indicators may include performance, drift, complaints, unsafe outputs, override rates, and recurring failures.

Retain the required logs, investigate incidents, apply corrective measures, and report serious incidents where necessary. Reassess compliance whenever you change the model, data, purpose, users, operating region, or decision-making authority.

Stop Building AI Twice: Address EU AI Act Compliance From the Start

The cost of addressing EU AI Act compliance rises once your architecture, data pipelines, and operational workflows have been implemented.

Reviewing the requirements during project scoping therefore helps your technical and legal teams agree on constraints before development begins, reducing late changes and avoidable remediation.

As an EU AI Act-ready AI development partner, we’ve delivered 54+ AI systems for production use, including agentic LLMs, computer vision pipelines, predictive models, and automation workflows.

Our senior-led engagements begin under NDA and can include GDPR-aligned data handling, DPAs, custom security reviews, penetration testing, and jurisdiction-specific requirements.

Want to find out more about this service? Schedule your free 30-minute EU AI Act readiness call with our team. We’ll take you through the process step-by-step.

FAQs

What is the EU AI Act?

The EU AI Act is the EU’s risk-based law governing AI systems and general-purpose AI models. It sets compliance obligations based on an AI system’s intended purpose, risk level, and your role in the AI supply chain — covering prohibited practices, transparency duties, and high-risk system requirements.

Who does the EU AI Act apply to?

The Act applies if you place an AI system or general-purpose AI model on the EU market, use an AI system in the EU, or operate elsewhere while the system’s output is used in the EU — including non-EU businesses.

What are the EU AI Act’s risk categories?

The Act sorts AI uses into four tiers: unacceptable risk (banned practices like social scoring), high risk (recruitment, credit, education, essential services), transparency or limited risk (chatbots, deepfakes, AI-generated content), and minimal risk (spam filters, games), which carries no AI Act-specific mandatory requirements.

What are the penalties for non-compliance?

Penalties scale by violation type: up to €35 million or 7% of global turnover for prohibited practices or data violations, €15 million or 3% for other obligations, and €7.5 million or 1% for misleading information to authorities. SMEs face the lower of the two figures.

Does using third-party AI tools like ChatGPT or Copilot make my business responsible under the Act?

Yes. If you use ChatGPT, Copilot, or another third-party AI tool under your authority for professional purposes, you’re typically a deployer with your own obligations — the vendor supplying the tool isn’t solely responsible. Check whether its output affects employment, credit, education, or healthcare decisions.

Insights

Proof Before Praise

Guides, benchmarks, and the math behind our claims.

AI use cases and applications by industry

Article

Guide

Artificial Intelligence

AI Use Cases & Applications by Industry: Cost, ROI, and Real Examples

Jul 2026

24 min read
AI Agent Workflows: Top 5 Use Cases, Examples & Implementation Guide [2026]

Article

Guide

Artificial Intelligence

AI Agent Workflows: Top 5 Use Cases, Examples & Implementation Guide [2026]

Apr 2026

23 min read
AI Readiness Assessment 2026: The Five Dimension Enterprise Scorecard

Article

Guide

Artificial Intelligence

AI Readiness Assessment 2026: The Five Dimension Enterprise Scorecard

Jun 2026

14 min read
See all Articles