Search

EU AI Act Explained:
What Every Business Needs to Know in 2026

AI without governance is risk - understanding the EU AI Act

At a Glance

The EU AI Act entered into force on 1 August 2024.

  • AI literacy requirements have applied since 2 February 2025.
  • Transparency requirements became applicable from 2 August 2026.
  • High-risk AI obligations now apply from 2 December 2027.
  • UK businesses can still be affected if their AI systems or outputs are used in the EU.
  • There is no blanket exemption for small businesses.

The EU AI Act is the world’s first comprehensive law dedicated to regulating artificial intelligence. It introduces a risk-based framework that applies different requirements depending on how AI is used and the potential impact it could have on individuals and society. The legislation entered into force on 1 August 2024 and is being implemented in stages through to 2028.

While much of the discussion focuses on AI developers, the Act has much wider implications. Any organisation using AI tools, deploying AI-powered services, or selling products into the EU may have obligations under the legislation.

Here’s what you need to know.

What is the EU AI Act?

The EU AI Act (Regulation (EU) 2024/1689) establishes rules for the development, deployment and use of artificial intelligence systems within the European Union.

Rather than regulating every AI system equally, the Act categorises AI according to risk. The higher the level of risk, the greater the compliance requirements.

The legislation aims to ensure AI is:

  • Safe and trustworthy
  • Transparent where appropriate
  • Subject to human oversight
  • Developed and deployed responsibly

The framework is built around a risk-based approach set out in Articles 5 to 50 of the Act.

Does It Apply to My Business?

Potentially, yes.

The Act applies not only to organisations based in the EU, but also to providers and deployers whose AI systems or outputs are used within the EU market. This means many UK businesses may still be affected.

You may fall within scope if you:

  • Use AI-powered business tools
  • Deploy chatbots or virtual assistants
  • Use AI for recruitment or employee assessment
  • Create AI-generated content
  • Offer AI-enabled products or services to EU customers
  • Develop software containing AI functionality

Importantly, there is no blanket exemption for SMEs or micro-businesses. The compliance burden varies according to the risk level of the AI system rather than the size of the organisation.

Why This Matters Now

For many organisations, the biggest risk is not developing AI systems. It’s using AI without fully understanding where compliance obligations might exist.

Tools such as Microsoft Copilot, ChatGPT, AI recruitment platforms, customer service chatbots and AI-generated marketing content may all introduce governance, transparency or training requirements under the EU AI Act. Even where a tool falls into a lower-risk category, organisations are expected to understand how it is being used and ensure employees have the appropriate level of AI literacy.

The organisations that start preparing now will find it significantly easier to demonstrate AI compliance as further requirements come into force.

The AI Risk Levels

The legislation categorises AI systems according to risk.

Unacceptable Risk – Under Article 5, certain AI practices are prohibited outright due to the level of risk they pose.
Examples include:

    • Social scoring systems
    • Certain manipulative AI practices
    • Certain biometric categorisation systems
    • Certain workplace emotion-recognition applications

High-Risk AI – High-risk AI systems are permitted but subject to significant obligations under Title III of the Act.
Examples include:

    • Recruitment and CV screening
    • Employee performance assessment
    • Creditworthiness assessments
    • Critical infrastructure systems
    • Certain healthcare applications
    • Educational assessment systems

Organisations using or developing high-risk AI must implement extensive controls, documentation, risk management processes, and human oversight.

Limited-Risk AI – Many organisations will encounter this category.
Under Article 50, users must be informed when they are interacting with AI in certain circumstances.
Examples include:

    • Customer service chatbots
    • AI assistants
    • AI-generated content
    • Synthetic images and media

The main requirement is transparency, ensuring users understand when they are interacting with AI.

Minimal-Risk AI – Most everyday workplace AI tools face few additional regulatory requirements.
Examples include:

    • Spam filters
    • AI productivity tools
    • Meeting transcription tools
    • Internal business assistance systems

These systems face very limited regulatory obligations.

Key Dates

The AI Act is being introduced gradually.

1 August 2024 –  The legislation entered into force.

2 February 2025 – The first significant obligations became applicable.
This included prohibited AI practices (Article 5) and AI literacy requirements (Article 4). AI literacy requires organisations to ensure employees have an appropriate understanding of the AI systems they use.

2 August 2025 – Rules applicable to General Purpose AI (GPAI) model providers took effect.
These requirements primarily impact the developers of foundation models and large language models.

2 August 2026 – Transparency obligations under Article 50 are now applicable.
Businesses using customer-facing AI systems should ensure users know when they are interacting with AI and when content has been generated synthetically where required under Article 50.

2 December 2027 – Most high-risk AI system obligations have been deferred until this date under the AI Omnibus changes adopted in 2026.

2 August 2028 – Requirements for AI embedded within regulated products such as medical devices become applicable.

What This Means in Practice

For most businesses, AI compliance starts with visibility.

Ask:

  • What AI tools are currently being used?
  • Are any customer-facing?
  • Are any involved in recruitment or employee assessment?
  • Are staff trained on safe and responsible AI use?

It starts with understanding where AI is already being used.

Practical considerations include:

  • Creating an inventory of AI tools used across the organisation
  • Identifying customer-facing AI systems
  • Implementing AI usage policies
  • Providing employee training and AI literacy programmes. Employee awareness and training are already expected under Article 4.
  • Ensuring customers understand when AI is being used
  • Reviewing relationships with AI vendors and providers
  • Establishing governance and oversight processes

For organisations using AI-generated content, chatbots, virtual assistants, or AI-powered customer interactions, transparency is becoming increasingly important. Users should be informed when they are interacting with or consuming content created by AI. If you run a website chatbot, now is the time to review the wording and ensure users understand they are interacting with AI. If you use AI-assisted recruitment or employee assessment tools, begin understanding the forthcoming high-risk requirements before the 2027 deadline.

What is AI Governance?

AI governance refers to the policies, processes and controls that help organisations use artificial intelligence responsibly.

In practice, this means understanding:

  • What AI tools are being used across the organisation
  • Who is responsible for approving and monitoring those tools
  • What business risks exist
  • How data is being handled
  • How employees are trained to use AI safely and effectively

Good AI governance is becoming increasingly important regardless of whether your organisation falls into the higher-risk categories under the EU AI Act. It provides a framework for balancing innovation with compliance, security and accountability.

What About Microsoft Copilot and ChatGPT?

For most organisations, the everyday use of tools such as Microsoft Copilot, ChatGPT and AI meeting assistants is unlikely to fall into the high-risk category.

However, organisations remain responsible for ensuring employees understand how these tools should be used, what data can be entered into them, and how AI-generated outputs should be reviewed before being relied upon for business decisions.

This aligns closely with the AI literacy requirements introduced under Article 4 of the EU AI Act.

Fines

The financial penalties are significant and, in some circumstances, exceed the maximum penalties available under GDPR.

Depending on the infringement, organisations could face fines of up to:

  • €35 million; or
  • 7% of worldwide annual turnover

whichever is higher.

However, the legislation includes provisions intended to ensure enforcement remains proportionate for SMEs and smaller organisations. Regulators may take factors such as company size, turnover and the nature of the infringement into account when determining penalties.

Next Steps

If you’re unsure where your business stands, focus on five practical actions:

  1. Create an inventory of AI tools currently in use.
  2. Work out the risk category of each
  3. Add an AI disclosure to your website or chatbot ahead of August 2026 deadline.
  4. Deliver AI literacy training to staff. This is a legal requirement!
  5. Review recruitment and HR related AI tools use ahead of December  2027.

The organisations that start building good AI governance now will be in a much stronger position as future obligations come into force.

Compliance is only one part of the puzzle. Discover why tech giants say the cybersecurity status quo isn’t enough in our article: The World’s Biggest Tech Companies Are Warning About Cybersecurity. Is Your Business Listening?.

Accelerate Your AI Journey with Redsquid

Reading legislation is one thing. Turning it into practical action is another.

Whether you’re wondering if Microsoft Copilot falls within scope, checking whether your chatbot needs disclosure notices, reviewing AI use in recruitment, or building an internal AI governance framework, Redsquid can help you translate legislation into practical business actions.

Redsquid can provide focused, jargon-free guidance tailored to your organisation. In just one session, you’ll gain clarity on your responsibilities, identify opportunities to use AI more effectively, and leave with practical next steps that align with your business goals.

Contact us and leave with a clear action plan for AI adoption, governance and compliance within your organisation.

 

 

 

Sources used