The EU AI Act is in force. If you run a company that uses — or wants to use — artificial intelligence, the question is legitimate: what do we need to do?
The short answer: probably less than you think. But not nothing.
This article is written for business leaders and IT managers, not lawyers. No legalese, no 200-word paragraphs. Just what you need to know to stay compliant.
What is the AI Act in 3 sentences
It's the EU regulation that classifies artificial intelligence systems based on risk. The higher the risk, the stricter the obligations. It applies to anyone who develops, deploys, or uses AI systems in the European Union.
Risk classification made simple
Minimal risk
Most AI systems used in business. Website chatbots, document search assistants, report generators, automatic suggestions. No specific obligations — just common sense and transparency.
Limited risk
Systems that interact with people and must declare it. The chatbot must say it's a chatbot. AI-generated content must be identifiable. Transparency obligation.
High risk
Systems that make decisions about people — CV screening, credit assessment, access to essential services. Strict obligations: technical documentation, risk assessment, human oversight, periodic audits.
Unacceptable risk
Prohibited systems. Social scoring, subliminal manipulation, mass biometric surveillance. If you use them, stop. But it's unlikely they apply to your company.
What companies actually need to do
If you use minimal or limited risk AI (most cases):
- Inform users they're interacting with an AI (if applicable)
- Document which AI systems you use and for what purpose
- Ensure there's always the possibility of human intervention
- Monitor that the AI does what it's supposed to — and nothing else
If you use or want to use high-risk AI:
- Everything above, plus:
- Formal risk assessment (FRIA — Fundamental Rights Impact Assessment)
- Detailed technical documentation of the system
- Quality management system for the AI lifecycle
- Logs of all decisions made by the system
- Periodic audits by notified bodies (for the most critical cases)
What you DON'T need to do (myth-busting)
Myth 1: "We need to certify every AI use"
False. Only high-risk systems require formal procedures. The chatbot that answers customer FAQs doesn't need certification.
Myth 2: "We need to stop using ChatGPT"
False. ChatGPT and similar tools are minimal-risk systems. Use them — with common sense. Don't input sensitive data, don't base critical decisions solely on AI output.
Myth 3: "We need a specialized AI lawyer"
It depends. For most mid-market companies, no. You need to understand where you fall in the risk classification and document your use. If you use AI for CV screening or decisions about people, then yes — get advice.
Key deadlines
Update, 12 August 2026. The high-risk deadlines have changed. Regulation (EU) 2026/1744, adopted on 8 July 2026 and in force since 27 July, pushed them back by more than a year. Note carefully, though: transparency was not postponed, and it already applies.
- February 2025: bans on unacceptable risk systems and the AI literacy obligation (in force)
- August 2025: obligations for general-purpose AI models (GPAI)
- October 2025: in Italy, the duty to inform workers about AI use (Law 132/2025)
- 2 August 2026: Article 50 transparency obligations — a chatbot must declare it is a chatbot, synthetic content and deepfakes must be labelled. Fines up to 15 million euro or 3% of worldwide turnover. Already applicable
- 2 December 2026: end of the four-month transition for marking generative systems already on the market before 2 August 2026
- 2 December 2027: obligations for Annex III high-risk systems — recruitment, credit scoring, essential services (was August 2026)
- 2 August 2028: obligations for high-risk AI embedded in regulated products (was August 2027)
The postponement covers a part that did not apply to most SMEs in the near term anyway. Anyone who stopped at the headline "Europe delays the AI Act" and concluded there was nothing to do has misread it: the transparency obligations have started, and they apply to companies that merely buy AI too.
GDPR and NIS2 interplay
The AI Act doesn't exist in isolation. If your AI processes personal data, GDPR still applies — with all its requirements for lawful basis, data minimization, and rights of data subjects. If you're in a critical sector, NIS2 cybersecurity obligations overlay as well.
The good news: compliance frameworks overlap. A well-documented, privacy-by-design AI system already checks most boxes across all three regulations. Our cybersecurity division helps companies navigate this landscape.
How Aitaky handles compliance
Every solution we build is compliant by design:
- Data stays on-premise — no transfers to third parties
- Human oversight built into every workflow
- Technical documentation included in the deliverable
- Transparency: every AI output is traceable to the source data
We don't sell "compliant AI" as an add-on feature. It's how we work.
Want to check if your AI use is compliant? Let's talk →
Related articles: