← Back to all posts

The EU AI Act Now Applies: What Your Business Actually Has to Do

12 August 2026 · 3 min read

The EU AI Act (Regulation (EU) 2024/1689) has been rolling out in stages since it entered into force in 2024. The stage that matters most for ordinary businesses arrived on 2 August 2026, when the bulk of its obligations became applicable. If you use AI anywhere in your operations — and most companies now do, often without calling it that — this is the point where “we’ll look at it later” stops being a viable plan.

You are probably in scope, even if you don’t build AI

The most common misconception is that the AI Act only applies to companies that train models. It doesn’t. The regulation distinguishes between providers (who develop and place an AI system on the market) and deployers (who use one under their own authority). Most businesses are deployers, and deployers carry real obligations too.

If you use an AI tool to screen job applicants, score creditworthiness, monitor staff, or make decisions that materially affect people, you are in the part of the regulation with teeth.

The four risk tiers, briefly

The Act sorts AI systems by risk rather than by technology:

  • Unacceptable risk — banned outright. Social scoring, manipulative systems that exploit vulnerabilities, most real-time remote biometric identification in public spaces. These prohibitions have applied since February 2025.
  • High risk — permitted, but heavily regulated. This covers AI used in employment, education, credit scoring, essential services, and similar areas. Expect risk management, data governance, logging, human oversight, and technical documentation.
  • Limited risk — transparency obligations. If people interact with a chatbot or see AI-generated content, they must be able to know that.
  • Minimal risk — the overwhelming majority of business uses. Spam filters, recommendation engines, most internal productivity tooling. No specific obligations.

The practical consequence: most of your AI use is probably minimal risk, but you cannot claim that until you have actually looked.

What the penalties look like

The numbers are deliberately attention-getting. Breaching the prohibited-practice rules can reach €35 million or 7% of global annual turnover, whichever is higher. Most other breaches top out at €15 million or 3%. Supplying incorrect or misleading information to authorities carries up to €7.5 million or 1%.

Smaller companies face proportionally lower caps, but “proportionally lower” is not the same as “survivable if ignored”.

Four things worth doing this quarter

  1. Inventory your AI. List every tool in the business that uses AI, including features quietly added to software you already pay for. Most companies are surprised by the length of this list.
  2. Classify each one. Which tier does it fall into? Are you the provider or the deployer? Write the reasoning down — being able to show your working is itself part of compliance.
  3. Close the transparency gaps. If customers interact with AI, say so. This is usually the cheapest obligation to satisfy and the most visible one to miss.
  4. Assign an owner. Compliance that belongs to everybody belongs to nobody. See AI governance for smaller businesses for what a workable internal policy looks like.

Where to start if this feels like a lot

It usually feels worse than it is. For most growing businesses the honest answer after a proper review is “you are mostly minimal risk, two systems need transparency notices, and one needs a closer look” — but you need the review to be able to say that with confidence, and to evidence it if anyone asks.

That is precisely what we built SynoCheck for: a fast, structured compliance check that tells you where your software actually stands against the AI Act, before a regulator asks the question for you.

New to the underlying technology? Start with What Is AI? and What Is an AI Agent? for the plain-English groundwork.

Want to know where you stand? Get in touch and we’ll walk you through it.