Guide

The EU AI Act,
in plain language

Written for the person who has to answer for it — not for a legal journal. What the Act asks of you, what you must be able to produce on request, and where most companies are quietly non-compliant.

For deployersNot legal adviceReviewed Q2 2026

What the Act is

The EU AI Act is product-safety law applied to software. It does not ask whether your AI is good. It asks whether you can show what it did, who was accountable, and what you did when it was wrong.

That distinction matters more than any technical requirement in it. A company with a mediocre model and a complete evidence trail is in better shape than a company with a brilliant model and none.

This page is not legal advice

It is an operational reading, written by people who had to comply. Use it to ask your counsel better questions, not to replace them.

Are you a provider or a deployer?

Almost every company reading this is a deployer: you use an AI system in the course of your business. Providers build and place systems on the market. The duties are different, and deployer duties are the lighter set — but they are not nothing.

  • Deployer — you use it. You owe oversight, monitoring, transparency to affected people, and logs.
  • Provider — you build it or put your name on it. You owe conformity assessment, technical documentation, a quality management system.
  • Watch this — substantially modifying a high-risk system, or putting your brand on someone else’s, can turn a deployer into a provider.

If you fine-tune a model on your own data and deploy it for hiring decisions, get advice before assuming you are still just a deployer.

The four risk tiers

  • Unacceptable — prohibited outright. Social scoring, manipulative techniques causing harm, most real-time remote biometric identification in public. If you are here, stop.
  • High-risk — permitted with substantial obligations. Employment and worker management, access to education, creditworthiness, essential services, critical infrastructure, law enforcement and migration.
  • Limited risk — transparency duties. People must know they are dealing with a machine; synthetic content must be marked.
  • Minimal risk — no specific duties. Most internal productivity use lands here.

The uncomfortable truth for most mid-market companies: your current AI use is probably minimal or limited risk, and your next use case is where high-risk creeps in. CV screening is the classic example — it feels like productivity and is legally employment.

Your obligations as a deployer

AI literacy (Article 4)

Applies to everyone, at every risk level. Staff who use AI systems must have sufficient understanding to use them sensibly. This is the obligation companies most often miss, because it does not feel like a compliance task. A record of who was trained, on what, and when, is enough.

Human oversight (Article 14 duties in practice)

High-risk systems must be used under human oversight, by people who are competent to exercise it and empowered to override. “A human clicked approve” is not oversight if that human had no realistic basis to disagree.

Logging (Articles 12 and 19)

Automatically generated logs, retained for an appropriate period — at least six months unless other law says longer. The logs must be sufficient to reconstruct what happened. Prompt-and-response pairs alone rarely are; you also need which model, which jurisdiction, which data, which human.

Monitoring and incidents

Monitor operation against instructions for use. Suspend use and inform the provider when you identify a risk. Report serious incidents. Keep the evidence.

Transparency to affected people

Where a high-risk system is used in decisions about individuals, inform them. Where they ask for an explanation of a decision, be able to give one.

Data governance

GDPR did not go away. Where you run a DPIA, the AI Act obligations sit alongside it rather than replacing it.

Timeline

The deadlines are staggered, and the early ones already passed

Prohibitions and AI literacy came into application first. General-purpose model obligations followed. High-risk obligations are the last major tranche. Check current dates with counsel — the Commission has adjusted timing more than once.

Practically: prohibitions and literacy are live obligations today, not future ones. If you have no training record, that is a present gap.

What you must be able to produce

Ignore the article numbers for a moment. A regulator, a customer’s procurement team, or your own auditor will ask for some version of these six things.

  1. An inventory. Every AI system in use, its purpose, its risk classification, and who owns it.
  2. A log you cannot quietly edit. What ran, when, on whose behalf, against which model, in which jurisdiction.
  3. Evidence of human oversight. Who reviewed what, what they changed, and what they rejected.
  4. A training record. Who has been made AI-literate, covering what, and when it was refreshed.
  5. Data residency and processor documentation. Where data went, which sub-processors touched it, under what terms.
  6. An incident record. What went wrong, what you did, how long it took.

If producing any of these would take you more than a day, that is the gap to close first.

Where it usually goes wrong

  • Policy instead of enforcement. A document saying “do not put customer data in ChatGPT” is not a control. If the only thing between regulated data and a US endpoint is a sentence in Confluence, you do not have a control.
  • Logs that live in the vendor. If your evidence is a dashboard you cannot export, you cannot hand it over.
  • Shadow deployment. Half your staff already pay for an AI tool personally. That is your inventory problem, not theirs.
  • Skipping literacy. Cheapest obligation, most commonly unmet.
  • Assuming minimal risk forever. Classification follows use, and use drifts.

Checklist

Twelve questions. If you cannot answer one with a document rather than an opinion, it is a gap.

We have an inventory of every AI system in use

Including the ones bought on someone’s personal card.

Each system has a documented risk classification

And a named owner who agrees they own it.

Sensitive data cannot technically reach a non-EU endpoint

Enforced at a gateway, not requested in a policy.

Logs are append-only and exportable by us

Not a vendor dashboard we can only look at.

Logs record model, jurisdiction, actor and data scope

Prompt and response alone will not reconstruct a decision.

Retention is set deliberately, at least six months

And written into the DPA rather than assumed.

Human review is recorded, including rejections

What was changed is more useful evidence than what was approved.

Reviewers are competent and empowered to override

Oversight nobody can act on is not oversight.

We have an AI literacy training record

Who, what, when, and when it is refreshed.

Affected individuals can be informed and given an explanation

Before someone asks, not after.

We have a sub-processor list and current DPAs

For every model provider in the chain.

There is an incident procedure someone has actually rehearsed

Including who calls the provider.

Want to see how much
of this we cover for you?