The EU AI Act Is Now Enforced: What Every Business Using AI Needs to Do Before It's Too Late
The EU AI Act's enforcement phase has begun. Even if your business isn't based in Europe, if you have EU customers or use AI in decisions that affect them, you're in scope. Here's your compliance checklist.
The EU AI Act — the world's first comprehensive binding legal framework for artificial intelligence — is no longer a future concern. Enforcement has begun, and the extraterritorial scope of the regulation means that businesses well outside Europe's borders may be subject to its requirements. If your product or service uses AI in ways that affect EU residents, you need to understand what's required now — not at the next funding round or product launch.
Who Is Actually in Scope
The Act applies to providers and deployers of AI systems that are placed on the EU market or used in the EU — regardless of where those providers are based. That means a US startup building an AI-powered hiring tool used by a European client is subject to the Act's requirements for that use case. A Canadian company deploying AI in customer-facing decisions for EU users falls under its provisions.
The risk-based framework assigns requirements based on the stakes of the application: minimal risk (most AI applications, including recommendation systems and spam filters), limited risk (chatbots and certain decision-support tools), high risk (AI used in hiring, lending, education assessment, law enforcement, and healthcare), and unacceptable risk (applications that are flatly prohibited, including real-time biometric surveillance in public spaces).
High-Risk AI: What's Required
If your AI application falls into the high-risk category, the compliance requirements are substantial. You must maintain comprehensive technical documentation, implement human oversight mechanisms, ensure the system can be monitored and corrected, conduct conformity assessments before deployment, and register the system in a new EU database. These are not checkbox exercises — regulators will examine whether oversight mechanisms are functional, not just documented.
Transparency Obligations for All Businesses
Even for lower-risk applications, the Act creates disclosure requirements. AI-generated content must be identifiable as such. Chatbots must disclose they are AI systems when a user could reasonably be confused. Deepfake content requires clear labeling. These apply across categories.
The Penalties Are Designed to Get Attention
Fines for prohibited practices can reach €35 million or 7% of global annual turnover, whichever is higher. For high-risk violations, fines go up to €15 million or 3% of turnover. These are not starting points for negotiation — they reflect enforcement targets calibrated to create genuine deterrence even for large organizations.
What This Means for Small Businesses
For most small businesses, the immediate action items are: first, audit which of your AI applications are used by or affect EU residents. Second, classify each application by risk tier using the Act's framework. Third, for any high-risk applications, begin the documentation and oversight requirements immediately. Fourth, implement basic transparency disclosures for any AI-facing customer interactions.
Don't wait for enforcement actions to begin in your sector before taking this seriously. Regulators have historically targeted early high-profile cases in new enforcement areas, and being caught unprepared is reputationally as well as financially damaging.
Practical takeaway: If you have EU customers and use AI in any automated decision-making, run an AI system inventory this week. Map each application to the risk tier. Focus compliance effort on high-risk applications first — that's where enforcement will concentrate.
- 1Inventory every AI system you build or deploy and classify each by EU AI Act risk tier — prohibited, high-risk, limited-risk, or minimal — this quarter.
- 2Flag any AI touching hiring, credit, education, or biometrics as high-risk, and start assembling technical documentation, logs, and human-oversight controls now.
- 3Add AI Act clauses to vendor contracts requiring suppliers to disclose model details, training data provenance, and conformity evidence on request.
Ready to implement AI in your business?
Our team builds the AI systems you just read about. Start with a free 30-minute discovery meeting.
