EU AI Act compliance for firms: what to do now - AI Institute

The EU AI Act is the world's first comprehensive law on artificial intelligence, and many organisations are unsure whether it applies to them, what it demands, or when. This guide is an explanation of EU AI Act compliance: who it affects, the timeline that matters, what the risk categories mean, and the practical steps to take. It is educational rather than legal advice. For your specific situation, always check the official sources and, where needed, take professional guidance.
What is EU AI Act compliance, and who does it apply to?
EU AI Act compliance means meeting the obligations set out in the EU's Artificial Intelligence Act for how AI systems are developed, provided and used. It applies far more widely than 'EU tech companies'.
The Act uses a risk-based approach and applies to both providers (those who develop or place AI systems on the market) and deployers (organisations that use AI systems in their work). Crucially, its scope can reach organisations outside the EU. If your use of AI affects people within the European Union, the Act may apply to you even if you are based in the UK or Ireland and serving EU clients or citizens. That extraterritorial reach is why so many non-EU firms need to pay attention, and it is a point worth checking carefully for your own circumstances.
What are the key EU AI Act deadlines?
The Act entered into force on 1 August 2024 and applies in stages rather than all at once. As things stand, the phased timeline runs roughly like this:
- From 2 February 2025: bans on a set of unacceptable-risk' AI practices took effect, and the obligation to ensure staff AI literacy (Article 4) began to apply.
- From August 2025: obligations for providers of general-purpose AI models started to apply.
- From 2 August 2026: most obligations for 'high-risk' AI systems apply.
- Into 2027: certain remaining high-risk obligations phase in.
Timelines and detail can change, so treat this as an orientation rather than the final word, and confirm against the official European Commission guidance for your situation. The headline for most organisations: the AI-literacy duty is already live, and the bigger high-risk obligations are approaching, not distant.
What counts as 'high-risk' AI under the Act?
The Act sorts AI uses into risk tiers, and your obligations depend on which tier you are in. In simple terms:
- Unacceptable risk: a small set of uses that are banned outright (for example, certain kinds of social scoring or manipulative systems).
- High risk: AI used in sensitive areas such as recruitment and employment decisions, access to essential services, education, or critical safety contexts. These carry the heaviest obligations: risk management, data governance, human oversight, documentation and more.
- Limited risk: uses that mainly carry transparency duties, such as telling people they are interacting with AI.
- Minimal risk: the majority of everyday AI uses, which carry few specific obligations
The practical point: most everyday business use of tools like Copilot or Claude falls into the lower tiers, but specific uses, especially anything touching hiring, staff or people's access to services, can be high-risk and demand real diligence. Working out which category your uses fall into is the foundation of compliance.
What steps does EU AI Act compliance require?
For most organisations, a sensible, practical path looks like this:
1. Inventory your AI uses
You cannot govern what you cannot see. List where AI is actually being used across the organisation, including the unofficial tools people have adopted on their own.
2. Classify the risk
For each use, work out which risk tier it falls into. This tells you where you have real obligations and where you do not, so you can focus effort proportionately.
3. Ensure AI literacy
The literacy obligation is already in force, and it is the most immediate, universal duty. Genuine AI literacy training for staff who use AI is both a legal requirement and a sensible risk-reducer in its own right.
4. Put governance and controls in place
Human oversight, documentation, data governance and risk management, especially for any higher-risk uses. This is exactly what an AI governance framework provides, which is why compliance and good governance go hand in hand.
5. Review and keep records
Keep a simple record of your AI uses, their risk classification, and the training and controls you have applied. If a question ever arises, that record is your evidence that you took the duty seriously.
What are the penalties for non-compliance?
The Act has real teeth, which is part of why it is getting attention. Penalties are tiered by the seriousness of the breach. Engaging in a banned, 'unacceptable-risk' practice can attract fines of up to €35 million or 7% of total worldwide annual turnover, whichever is higher. Breaching other obligations (for example, the requirements on high-risk systems) can attract up to €15 million or 3% of worldwide turnover. Supplying incorrect or misleading information to authorities can bring up to €7.5 million or 1%. Actual penalties take account of the circumstances, and figures should be confirmed against the current text, but the scale makes the point: this is regulation to take seriously, not a box-ticking exercise.
How does the EU AI Act relate to the UK's approach?
For UK organisations, it is worth understanding the difference. As of 2026, the UK has not introduced a single, cross-cutting AI law equivalent to the EU AI Act. Its stated approach has been' pro-innovation' and principles-based, asking existing sector regulators to apply a set of common principles rather than creating one new AI statute. That does not put UK firms out of reach of the EU Act, though. If your AI use affects people in the EU, the EU rules can still apply to you. So a UK organisation may need to consider both its own evolving domestic framework and the EU Act's extraterritorial reach. Confirm the current position for your circumstances, as both are still developing.
What are the common EU AI Act compliance mistakes?
Two stand out. The first is assuming it does not apply because you are not an EU tech company, when in fact the Act reaches deployers and non-EU organisations whose AI affects people in the EU. The second is treating compliance as a one-off legal task rather than an ongoing operational one. Obligations phase in over time, your AI uses change, and your inventory and controls need to keep pace. A third mistake, easy to miss, is ignoring the AI-literacy duty that is already in force because it feels less urgent than the high-risk rules that are still approaching.
How do responsible AI and good governance make compliance easier?
Compliance is far less painful for organisations that already take AI seriously. If you have genuine responsible AI habits and a working governance approach, most of what the Act asks for, human oversight, risk management, record-keeping and staff literacy, is already part of how you operate. Seen that way, EU AI Act compliance is not a separate burden bolted on. It is largely the formalising of practices that good AI capability includes anyway. The organisations that struggle are usually the ones that treated governance and responsible use as optional until a deadline forced the issue.
Where can you find authoritative EU AI Act guidance?
Because detail matters and timelines shift, it is worth going to primary sources rather than second-hand summaries. The European Commission's own pages on the regulatory framework are the authoritative starting point, and independent trackers that follow the Act' simplementation are useful for keeping up with dates and guidance as they are published. Treat any overview, including this one, as orientation, and confirm the specifics that apply to your organisation against those official sources before you act. When obligations carry penalties of the scale the Act sets out, getting the detail right is worth the effort.
FAQ
Does the EU AI Act apply to Irish and UK firms?
It can. Irish firms are directly in scope, and UK firms may be caught where their AI use affects people within the EU. The Act's reach extends beyond EU borders, so check your specific situation.
What is the first EU AI Act compliance step?
Inventory where AI is used across your organisation, then ensure staff AI literacy. That obligation is already in force under Article 4. From there, classify risk and put proportionate governance in place.
When are the main deadlines?
The Act entered into force in August 2024 and phases in through 2025 to 2027. Prohibited-use and AI-literacy rules applied from February 2025, and most high-risk obligations apply from August 2026. Confirm current detail against official sources.
Is this legal advice?
No. This is an educational overview. For your specific obligations, consult the official European Commission guidance and, where needed, qualified legal advice.
Where to start
Begin with visibility. Inventory where AI is used, ensure your people have genuine AI literacy (the duty that is already live), and classify your uses by risk so you know where the real obligations sit. That trio covers most of the near-term exposure and gives you a foundation to build proper governance on. It is also simply good practice, regulation aside. You cannot manage AI you cannot see.
Get compliance-ready with us, or read more about our responsible, ethical approach to AI adoption on our about page.





.jpg)

.webp)