The EU AI Act requires companies to classify each AI system by risk level and meet obligations tied to that tier, since the law entered into force on 1 August 2024 but phases in its duties over several years. Prohibited practices, such as social scoring and manipulative subliminal techniques, and the Article 4 AI literacy duty to train staff who operate AI have applied since 2 February 2025. Providers of general-purpose AI models have carried transparency and documentation obligations since 2 August 2025, and most obligations for high-risk systems, including risk management, human oversight, technical documentation, and conformity assessment, apply from 2 August 2026. Companies that only deploy AI rather than build it still carry duties such as monitoring for malfunction, keeping usage logs, and informing affected individuals when required. Non-compliance can trigger fines up to 35 million euros or 7 percent of global turnover for prohibited practices, and lower caps for other violations. This is general information and not legal advice, and classification should be confirmed against the specific use case. Nanobase AI, a Silicon Valley enterprise AI engineering company, helps clients map their AI systems to the correct risk tier and build the technical documentation regulators expect.
Provider or deployer: the distinction that sets your obligations
The EU AI Act splits duties by role, not by industry, and most confusion about "what do we have to do" traces back to skipping this step. A provider builds or substantially modifies an AI system and places it on the market; a deployer uses an AI system under its own authority in a professional context. A company that fine-tunes an open-weight model and sells access to it is a provider. A company that buys a vendor's HR screening tool and runs it on its own applicant pool is a deployer of that same system. Most companies using AI in 2026 are deployers, and deployer duties are narrower than provider duties, but narrower is not the same as none.
What applies right now versus what is still phasing in
The Act entered into force on 1 August 2024, but it does not impose every duty on that date. Obligations arrive in stages, and treating the whole regulation as a single 2026 deadline causes companies to either panic unnecessarily or miss earlier duties that already apply.
| Date | What activates |
|---|---|
| 1 August 2024 | Act enters into force; general provisions begin |
| 2 February 2025 | Prohibited practices banned; Article 4 AI literacy duty for staff |
| 2 August 2025 | GPAI model provider obligations (documentation, copyright policy, training summary) |
| 2 August 2026 | Most high-risk system obligations (risk management, human oversight, conformity assessment) |
| 2 August 2027 | Remaining high-risk obligations for AI embedded in regulated products |
The AI literacy duty under Article 4 already applies to every organization using AI, regardless of risk tier, which makes it the most commonly missed near-term obligation.
This is general information, not legal advice, and a company's actual obligations depend on how its specific systems are classified.
The four-step process that covers most deployer companies
- Inventory every AI system in use, including vendor tools and embedded features in existing software, not just custom-built models.
- Classify each system against the prohibited list and Annex III high-risk categories (employment, credit, essential services, biometric categorization, and others).
- For anything high-risk, confirm the vendor's conformity documentation and set up the deployer-side duties: monitoring, logging, and informing affected individuals.
- Train staff who operate AI systems on their capabilities and limitations, satisfying the Article 4 literacy requirement and creating a paper trail.
This sequence surfaces the systems that actually need work instead of treating the whole AI portfolio as equally urgent. Running this inventory-first sequence is what turns a vague sense of AI Act exposure into a short, prioritized list of systems that actually need work.
Where companies underestimate scope
Two blind spots come up repeatedly. First, "AI" under the Act is not limited to generative AI or chatbots; a resume-ranking algorithm or a fraud-scoring model qualifies just as much as an LLM-based assistant. Second, deployer duties do not disappear just because the AI system was purchased rather than built; a company deploying a high-risk system it did not develop still has to monitor it in operation and act on serious incidents. Buying instead of building reduces the compliance burden, but it does not eliminate the deployer's own obligations.
Frequently asked questions
Does the EU AI Act apply to a company with no EU offices?
Yes. The Act applies extraterritorially whenever an AI system is placed on the EU market or its output is used within the EU, similar to how GDPR reaches companies outside the bloc. Headquarters location does not determine scope; where the system operates or affects people does.
What is the fastest first step for a company that has done nothing yet?
Build an inventory of every AI system in use, including third-party tools, before attempting classification. Companies routinely discover they cannot classify systems accurately because no single team knows every AI feature already running across departments.
Are internal, non-customer-facing AI tools exempt?
No blanket exemption exists for internal use. An internal tool that makes decisions about employees, such as scheduling, performance scoring, or promotion recommendations, can still fall into a high-risk category under Annex III regardless of who the end user is.
How does this interact with GDPR obligations?
The two regimes apply in parallel and cover different things: GDPR governs personal data processing, while the AI Act governs the AI system itself. A single generative AI deployment processing personal data typically needs both a GDPR lawful basis and an AI Act risk classification, detailed further in this EU AI Act, GDPR, and KVKK compliance checklist.
How Nanobase AI helps
Nanobase AI works with engineering and compliance teams to inventory AI systems, classify them against the EU AI Act's risk tiers, and build the technical documentation regulators expect from providers and deployers alike. This sits alongside our broader AI security and compliance work and our experience deploying private, on-premise LLMs that keep sensitive processing inside a company's own infrastructure.
Ready to discuss your project? Contact Nanobase AI or email hello@bumu.tech.