Skip to content
Artificial intelligence

The EU AI Act: what to check before using AI in your business

The same AI service can draft an internal email, answer a customer, or help rank job applicants. Those uses create different responsibilities. Before buying another license or launching an AI feature, describe the actual workflow, who it affects, and what your company controls. That is a more useful starting point than asking whether a tool is simply AI Act compliant.

An EU AI Act business review organized around the use case, company role, and evidence for responsible operation

The EU AI Act is EU legislation with a defined territorial scope, not a worldwide rule for every AI application. A global business should check whether its systems, deployment, market activity, or outputs bring it within that scope, alongside the laws that apply elsewhere.

This guidance reflects the position checked on 3 October 2026. The AI Omnibus entered into force on 27 July 2026. It changed important high-risk deadlines and simplified some duties. Work from the enacted rules and your specific use case, with qualified legal review where classification or obligations require it.

01Describe the actual use before classifying the risk

Create an inventory of the AI your business uses or supplies. Include purchased assistants, embedded software features, customer-facing tools, and internal experiments with business data. Record the purpose, users, affected people, inputs, outputs, supplier, version, and actions the system can take.

Under Article 2 of the AI Act, scope includes providers bringing systems or general-purpose models to the EU market, EU deployers, and certain non-EU providers and deployers where outputs are used in the EU. Location alone does not resolve the question.

The Commission's risk overview distinguishes prohibited practices, high-risk uses, transparency duties, and lower-risk applications. Employment and certain essential-service decisions are examples requiring careful classification. Neither the underlying model's brand nor a claim that a human approves the result determines the complete classification.

Compare two workflows using similar technology. Drafting a routine support response needs controls for accuracy, data, and publication. Using an output to evaluate applicants affects a different decision and different people. Keep this distinction in procurement: an approval for one purpose should not silently authorize every use the product technically supports.

Screen for prohibited practices first. Existing prohibitions already apply; additional prohibitions introduced by the Omnibus have their own application date. A project should not proceed because someone assumes a later high-risk deadline suspends every other rule. Record uncertain cases and obtain a reasoned assessment before deployment.

02Work out whether you use a system or provide one

A deployer uses an AI system under its authority. A provider develops, or has developed, a system or model and brings it to market or puts the system into service under its own name or trademark. Your company can have different roles for different products. A software supplier's involvement does not automatically settle your role.

Document who controls the intended purpose, branding, system design, and changes. A company integrating AI into its own product needs a more careful assessment than a team using an existing tool as instructed. Particular modifications or changes of purpose can create provider responsibilities, especially for high-risk systems. Review the actual arrangement before relying on the supplier's label.

Distinguish the general-purpose model from the application built around it. A model supplier's documentation does not describe every downstream workflow, permission, retrieval source, or decision your application introduces. Ask for the information relevant to your system and define what your implementation partner must supply.

Keep a responsibility record with the business owner, technical operator, supplier contact, and reviewer. Name who approves a new use, changes permissions, updates notices, investigates problems, and suspends operation. Contracts should support that practical arrangement rather than leaving each party to assume the other handles it.

03Use the amended dates and the correct transition

Rule or categoryApplication dateWhat to check
Original prohibited practices and AI literacy2 February 2025Current scope and amended literacy wording
General-purpose AI model rules2 August 2025Provider role and any applicable model transition
Most remaining rules, including Article 50 transparency2 August 2026The specific duty, exception, and company role
Added prohibited practices under the Omnibus2 December 2026The newly added provisions, not a delay of existing prohibitions
Chapter III Sections 1 to 3 for Annex III high-risk systems2 December 2027Article 6(2) classification and relevant transition
Chapter III Sections 1 to 3 for Annex I high-risk systems2 August 2028Article 6(1) classification and product-law interaction
Status checked on 3 October 2026. This is a selected timeline, not every provision or exemption. Article 6(5) is excepted from the stated Chapter III postponement. Check the enacted text for your system.

The high-risk dates above are enacted changes, confirmed in the Commission's Omnibus announcement and Regulation (EU) 2026/1744. They should not be described as a pending proposal or used to defer unrelated requirements.

Article 111(4) gives providers of generating systems placed on the market before 2 August 2026 until 2 December 2026 for Article 50(2). It is not a blanket grace period for transparency or deployers. The separate high-risk transition in Article 111(2) depends on prior placement and significant design changes; do not assume every existing system is permanently exempt.

Keep dates attached to a responsibility and task. A timeline without a classified system, role, and owner is difficult to act on. Review it when the law, system purpose, or implementation changes, and verify any transition before building a launch decision around it.

04Design transparency into the real interaction

The Commission's current transparency guidance separates provider and deployer duties. Providers handle direct-interaction information and machine-readable marking within the applicable provisions. Deployers have particular duties for emotion recognition, biometric categorization, deepfakes, and certain public-interest text. There are defined exceptions; this is not a rule to put the same label on every AI-assisted sentence.

For a customer assistant, check what a person sees at the actual point of interaction and whether the applicable duty and obviousness exception are addressed. Do not bury useful information in a distant policy page. Also explain the assistant's practical limits, how to reach a person, and which actions require confirmation.

For generated images, audio, video, and published text, review the intended content and distribution. Machine-readable marking by a provider and visible disclosure by a deployer are different tasks. Check whether editing, exporting, translation, or a platform upload removes information the chosen process depends on.

Article 50 includes a public-interest text exception involving human review or editorial control and editorial responsibility. Do not generalize that to every content duty. Review the specific paragraph, the finished asset, and the publishing workflow rather than assuming one human approval clears every transparency question.

Four AI Act assumptions to check: a tool label does not classify the use, supplier compliance does not define your role, delayed high-risk dates do not suspend all duties, and a human click does not prove effective oversight
Classification, roles, dates, and effective review are separate decisions. Keep evidence for each.

05Support AI literacy with training people can use

The amended Article 4 requires providers and deployers to take measures supporting AI literacy for relevant staff and people acting on their behalf, considering knowledge and context. It does not require guaranteeing a specific level for each individual. Simplification does not abolish the duty.

Make training specific to the task. A support team needs to recognize invented answers, unsafe disclosure, escalation cases, and actions requiring review. A developer integrating a model needs to understand permissions, untrusted inputs, evaluation, and failure handling. Someone approving employment-related use needs the context of that decision and the review process.

Practice with realistic mistakes and exceptions. Show an answer that sounds convincing but is unsupported, a request containing confidential information, and a tool action that exceeds the intended permission. Ask staff to identify the correct response and whom to contact. A generic presentation is less useful than a short exercise tied to their daily work.

Keep a practical record of the measures, materials, roles, and follow-up. Update it when the system or task changes. Avoid treating a certificate as proof that every future decision will be correct. Give people a usable route to ask questions, report an error, and pause an uncertain action.

06Check data, supplier evidence, and meaningful oversight

Assess privacy separately. Where the GDPR applies, AI use does not remove requirements around lawful processing, purpose, minimization, security, and applicable safeguards. Other jurisdictions may impose different obligations. Map what enters prompts, retrieved documents, logs, and supplier services.

Ask what the supplier does with inputs and outputs, which retention and training settings are available, who can access the information, and what happens when you delete it. Review the agreement and the actual configuration. A product's general privacy page may not describe the plan, deployment, or subprocessor arrangement you are purchasing.

Request evidence relevant to the intended use: instructions and limits, version information, evaluation context, failure cases, monitoring, and change notifications. For a potentially high-risk system, obtain a specific legal and technical review of the applicable evidence and duties. Do not substitute a broad marketing declaration for a documented assessment.

Give a reviewer enough information, time, authority, and competence to reject or correct the result. A button marked approve can become a routine click when staff cannot inspect the relevant evidence. Define escalation and fallback behavior, including which actions stop when the model, retrieval source, or monitoring fails.

Limit consequential actions and sensitive access to the approved workflow. Our business AI agent guide covers the practical action boundary, while data security in custom software provides wider security context. Neither a legal classification nor a human review eliminates ordinary application risks.

07Turn the review into an operating process

Four-step AI use review: inventory systems and data, assess scope and role, verify controls and supplier evidence, and approve a monitored workflow with change reviews
Start with one workflow, keep uncertain points explicit, and review changes after approval.
  1. Inventory the use. Record purpose, system, users, affected people, data, outputs, actions, and ownership.
  2. Assess scope and role. Review EU connections, prohibited practices, classification, responsibilities, dates, and any claimed transition.
  3. Verify the operation. Check supplier evidence, notices, data settings, review authority, permissions, staff preparation, and fallback behavior.
  4. Approve and monitor. Document the approved purpose, unresolved limits, incident route, change controls, and the next review.

Begin with a use whose boundaries your team can explain and operate. Do not copy its approval to a new purpose without review. A manageable record of decisions is more useful than a policy that permits every tool broadly but gives nobody responsibility for a customer-facing error or an unapproved decision.

08Questions about the EU AI Act and business use

Does the EU AI Act apply to businesses outside the EU?

It can, depending on the defined scope, market activity, and use of outputs in the EU. Check the actual system and role. It is not automatically a universal rule for every non-EU business or every AI use.

Is buying a compliant tool enough?

Assess the intended workflow, your role, configuration, data, and operation. Supplier evidence can help, but a product label does not describe every downstream use or assign all your responsibilities.

Have all AI Act duties been postponed?

No. The Omnibus changed specified high-risk dates and particular provisions. Most remaining rules applied from 2 August 2026, with earlier and later exceptions. Check the duty and any relevant transition individually.

Was AI literacy abolished?

No. The amended duty is to take measures supporting relevant staff literacy with regard to context and knowledge. It does not require guaranteeing a particular level for every individual. Tailored practical preparation remains useful.

Do we label everything touched by AI?

Review the specific transparency duty, content, role, and exception. Provider marking and deployer disclosure differ. A universal label rule overlooks the distinctions in Article 50.

Does human approval make any use acceptable?

No. Classification, prohibitions, data requirements, and other duties still need assessment. Review must also be meaningful: the person needs evidence, time, competence, authority, and a route to reject or escalate.

What should we prepare for the first review?

One documented workflow, its supplier and version, intended purpose, affected people, data flows, permissions, current notices, review process, and owners. Record uncertainties and get specialist review where needed before approving the use.

LISTIFY teamWebsites, apps and marketing from Prague since 2008

More articles

All articles →
Artificial intelligenceOctober 2, 2026 · 22 min read

AI agents for business: what they actually handle, what they cost and where they fail

Artificial intelligenceSeptember 29, 2026 · 18 min read

Anthropic Is Going Public and Warns AI Could Threaten Humanity. What the Prospectus Reveals and What It Means for Businesses

Artificial intelligenceSeptember 28, 2026 · 13 min read

ChatGPT Ads: How They Work, Where They’re Available and What They Mean for Businesses

Share this page

By email

Got an idea?

On a short call, we'll find out what you need and suggest the next step. Then you'll get a proposal with a fixed price and a timeline.

+420 771 166 199Mon to Fri, 8:30 a.m. to 4:00 p.m. (Prague time) · info@listify.cool

When should we call you?

Pick a day and a time window. We'll call you, and it takes about 15 minutes.

Day