EU AI Act: Complete Guide for Companies
Indsigt/EU AI Act: Complete Guide for Companies
AI Governance🇬🇧 English

EU AI Act: Complete Guide for Companies

September 2026·8 min read·Brian P.N. Tofft

The EU AI Act (Regulation 2024/1689) is the world's first binding, horizontal regulation of artificial intelligence. It entered into force in August 2024 and is being phased in gradually until 2027. Many companies still believe the EU AI Act primarily concerns those who build AI systems. That is incorrect. All companies that use AI systems in a professional context are subject to requirements as deployers. This means that most companies are already affected, often without realising it.

What is the EU AI Act, and who does it apply to?

The EU AI Act is an EU regulation that applies directly in all EU member states without national implementation. It covers all AI systems that produce output for use in the EU, regardless of whether the system was developed in Denmark, the US, or Asia. This makes the regulation a de facto global standard, much like the GDPR. The regulation applies to two types of actors: providers who develop and place AI systems on the market, and deployers who use AI systems in a professional context. Most companies are deployers. However, if you customise a third-party system for your own purposes, you may also be treated as a provider with the corresponding obligations.

EU AI Act timeline: when does what apply?

The EU AI Act is being phased in stages. August 2024: The regulation entered into force. February 2025: Prohibited AI systems (Chapter II, Article 5) had to be identified and decommissioned. August 2025: Rules for General Purpose AI models, including large language models such as GPT, entered into force. August 2026: Requirements for high-risk systems (Annex III) entered into force. This means documentation, risk assessment, human oversight, and registration in the EU database. August 2027: Requirements for AI systems regulated under existing sector legislation (Annex I, e.g. medical devices, aviation) will enter into force. We are now in September 2026. The most critical deadlines for most companies have already passed or have just come into effect.

The four risk classes explained

The EU AI Act divides AI systems into four risk classes based on their potential for harm. Unacceptable risk is prohibited: social scoring, manipulative AI, real-time biometric mass surveillance in public spaces, and AI that exploits psychological vulnerabilities. These systems had to be decommissioned by February 2025. High risk is permitted but subject to strict requirements: AI used in recruitment and HR, credit scoring, education, medical diagnostics, critical infrastructure, law enforcement, and migration. Limited risk requires transparency: chatbots must disclose that they are AI, deepfakes must be labelled, and emotion recognition systems must notify users. Minimal risk: no special requirements. This covers spam filters, AI in video games, and most productivity tools.

Requirements for high-risk systems

High-risk systems are the category requiring the most attention from most companies. AI used in recruitment, HR decisions, credit scoring, or customer segmentation typically falls here. Requirements include: a risk management system that continuously identifies and mitigates risks; data documentation ensuring that training data is relevant, representative, and free of known bias; technical documentation describing the system's purpose, design, and limitations; logging of the system's actions and decisions; transparency toward the humans using the system; human oversight ensuring the system can be overridden or rejected; robustness and accuracy documented through testing; and registration in the EU database EUAI.

Deployer responsibility: it is you, not the vendor

The most underestimated aspect of the EU AI Act is deployer responsibility. Many companies assume that compliance is the vendor's problem. It is not. As a deployer, you have independent responsibility to ensure that an AI system is used as prescribed; that there is human oversight for high-risk systems; that use is logged and documented; that employees working with the system are adequately trained; and that the system is not used for purposes it has not been approved for. This applies regardless of whether you purchased the system from SAP, Microsoft, a Danish software house, or a startup. And it applies to AI features activated in your existing systems, not only systems you have consciously procured as AI.

Many companies do not know their AI exposure

Experience from mapping engagements shows that most companies have significantly more AI systems than they are aware of. CRM systems with AI-based recommendation features. HR platforms that automatically screen CVs. Recruitment tools with AI scoring. Customer support systems with AI categorisation. Finance systems with anomaly detection. All of these are AI systems under the EU AI Act, and all of them were activated by the vendor in systems you already use. Mapping is not a trivial exercise. It requires identifying AI functionality across your entire system landscape, assessing the purpose, and classifying the risk. That is precisely what an AI Systems Audit delivers.

Fines and consequences for non-compliance

The EU AI Act has the teeth to enforce its requirements. Violations of the prohibition provisions can result in fines of up to 35 million euros or 7 percent of global turnover, whichever is higher. Violations of other requirements, including high-risk system requirements, carry fines of up to 15 million euros or 3 percent of turnover. Providers who supply incorrect information to supervisory authorities can be fined up to 7.5 million euros. Beyond fines, there is a risk of temporary prohibition on using the system, reputational damage, and loss of customer trust. The financial sector, healthcare sector, and public sector are under particular scrutiny.

The EU AI Act and GDPR: two frameworks, one system landscape

The EU AI Act and GDPR overlap but are not the same. The GDPR regulates the processing of personal data. The EU AI Act regulates AI systems, including those that process personal data. An AI system that processes personal data must comply with both frameworks, and they do not always give the same answer to the same question. The legal basis for processing under the GDPR and the risk assessment under the EU AI Act are separate processes that must be coordinated. This is one of the reasons why a holistic AI governance framework is necessary: you cannot think in only one regulatory framework at a time.

What is the first step?

Start with the mapping. You cannot classify what you do not know. An AI Systems Audit identifies all AI systems across your organisation, classifies them according to the EU AI Act's four risk categories, and delivers a concrete governance recommendation and 90-day action plan. It is a fixed-price deliverable that takes 1-2 weeks. The result is an overview you can act on, and a foundation on which to build the broader governance structure.

Brian P.N. Tofft

Brian P.N. Tofft

Managing Partner, We Lead Projects

Brian has more than 30 years of experience in project management and IT transformations across industries.

Related articles

Ready to get started?

Get in touch and find out how we can help with your next project.

Contact us