Buzzmatic

The EU AI Act Explained Simply

The EU AI Act is the world's first comprehensive AI law. This overview covers the risk classes, the obligations by role, and what it practically means for your business.

Intermediate10 min readLast updated: August 20, 2026

What you will learn

  • What the EU AI Act regulates and the logic it uses to classify AI systems
  • The four risk classes and the obligations attached to each
  • Why your role — provider or deployer — determines the scope of your obligations
  • Which deadlines already apply and what's still to come
  • What small and medium-sized businesses realistically need to do

The EU AI Act in one sentence

The EU AI Act is an EU regulation that regulates artificial intelligence not by technology but by risk — the greater the potential harm to people, the stricter the obligations, ranging from an outright ban through extensive documentation requirements to no additional requirements at all.

It has applied since August 2024 and is taking effect in stages. Because it is a regulation rather than a directive, it applies directly in all member states — no one has to wait for a national implementation law. You're affected even if your company is based outside the EU, as long as the output of your AI system is used within the EU.

> Note: This article provides orientation, not legal advice. Assessing a specific system in your company requires legal review — the classification in individual cases depends on details that an overview article can't capture.

The four risk classes

The entire law hinges on a single question: What could go wrong if this system fails? That produces four tiers.

Risk class

Examples

What applies

**Unacceptable risk**

Social scoring by public authorities, targeted manipulation of vulnerable groups, emotion recognition in the workplace and in schools, untargeted scraping of facial images from the internet

**Banned** — since February 2025

**High risk**

AI in recruitment, credit scoring, education assessment, critical infrastructure, medical devices

Extensive obligations: risk management, data quality, technical documentation, logging, **human oversight**, conformity assessment

**Limited risk**

Chatbots, AI-generated images, text and video, deepfakes

**Transparency obligations**: people must be able to recognize that they're interacting with AI; synthetic content must be labeled

**Minimal risk**

Spam filters, AI in video games, recommendation systems in online shops, most marketing applications

No special obligations, voluntary codes of conduct

The most practically important takeaway for most businesses: most everyday work falls into the bottom two tiers. If you draft text, summarize meetings, or analyze campaigns with an AI assistant, you're not operating a high-risk system. The heavy obligations apply where AI helps decide people's access to work, money, education, or healthcare.

The four risk classes of the EU AI Act as a pyramid: the higher the risk, the stricter the obligations UNACCEPTABLE Social Scoring, Manipulation – banned HIGH RISK Hiring, credit lending, medicine LIMITED Chatbots, AI images – labeling requirement MINIMAL Spam filters, recommendations – no requirements OBLIGATIONS

The greater the potential harm to people, the stricter the requirements — most everyday applications fall into the bottom two tiers.

General-purpose AI: a category of its own

Large language models don't fit the risk grid because they can be used for almost anything. That's why the AI Act treats them separately, as General Purpose AI (GPAI). The providers of such models — OpenAI, Google, Anthropic, Mistral, and others — must provide technical documentation, supply information to downstream providers, respect EU copyright law, and publish a summary of their training data. For particularly powerful models with systemic risk additional obligations apply: model evaluations, incident reporting, and cybersecurity requirements.

For you as a user, this is mostly good news: these obligations sit with the model provider, not with you. It only becomes relevant once you modify a third-party model, or offer it under your own name, to the point where you become a provider yourself. What these models technically are and how they work is explained in the article How Does AI Work?.

Your role determines your obligations

The AI Act consistently distinguishes by role. The exact same software can have completely different consequences for two different companies.

  • Provider: You develop an AI system or place it on the market under your own name or brand. This is where the bulk of the obligations lies.
  • Deployer: You use an AI system professionally. Your obligations are considerably lighter — but they include using it as instructed, human oversight for high-risk systems, and informing affected individuals.
  • Importer and distributor: You bring systems from third countries into the EU or pass them along, and must verify that the conformity requirements are met.

A word of caution on the role boundary: A deployer can quickly become a provider. Anyone who redistributes a high-risk system under their own name, substantially changes its purpose, or substantially retrains a model takes on provider obligations. If you build your own assistant and roll it out internally, you should deliberately check this boundary — that also applies to homegrown systems, as Building AI Agents describes.

The timeline

The regulation entered into force in August 2024, but it takes effect in stages.

Deadline

What applies

**February 2025**

Prohibited practices are banned; the **AI literacy obligation** under Article 4 applies

**August 2025**

Obligations for general-purpose AI models, governance structures, and penalty rules

**August 2026**

Most of the regulation — including transparency obligations for AI content and the high-risk rules under Annex III

**August 2027**

High-risk AI as a safety component of regulated products; transitional period for older general-purpose models ends

Since late 2025, discussions have been underway at EU level about simplifications and possible deadline shifts for parts of the high-risk rules. When assessing a specific project, always check the current status — the underlying logic of risk classes and roles remains unaffected, but individual dates may shift.

The EU AI Act timeline: five key dates from August 2024 to August 2027 AUG 2024 Entry into force FEB 2025 Bans + AI literacy AUG 2025 General-purpose AI, Governance, sanctions AUG 2026 Transparency + high risk under Annex III AUG 2027 Product high risk, legacy models

The AI Act takes effect in stages: the bans and the literacy obligation have long applied, with the bulk of the rest following in 2026.

What this means for small and medium-sized businesses

The common worry is: „We're no longer allowed to use AI.“ The reality is the opposite — for most SMEs, the effort stays manageable once four things are clarified.

1. Get an overview. List which AI systems are actually in use across the company — including tools individual teams have adopted without approval. Without this inventory, nothing can be classified.

2. Assign each system a risk class. In most cases, you'll land on minimal or limited risk. Exactly one category deserves special attention: anything to do with job applications, performance evaluation, or HR decisions. That's explicitly high-risk.

3. Sort out labeling. If customers are talking to a chatbot, they need to know it. AI-generated images and videos must be recognizable as such. For marketing teams, this is the single most practically relevant obligation.

4. Build AI literacy. Article 4 requires everyone who works with AI to have a sufficient understanding of it. This obligation already applies and affects practically every company using AI — details are covered in The Training Obligation Under Article 4 of the EU AI Act.

A sensible next step is a written internal policy that records responsibilities, approved tools, and approval processes. How to structure such a document is shown in An AI Policy for Your Company.

Fines: the framework

Penalties are tiered and are based on whichever is higher: a fixed amount or a percentage of revenue:

  • Prohibited practices: up to €35 million or 7% of global annual turnover
  • Violations of most other obligations: up to €15 million or 3%
  • False or misleading information provided to authorities: up to €7.5 million or 1%

For small and medium-sized businesses, the lower of the two values applies — the ceilings are designed for large corporations, not for SMEs. More important than the scary number is the message behind it: the harshest sanctions target prohibited practices, not documentation gaps.

AI Act and GDPR: two laws, one project

The AI Act doesn't replace data protection — it comes on top of it. Both apply independently: an AI system can be AI Act-compliant and still violate data protection law, for example if personal data flows into a US model without a legal basis. What data protection additionally requires is covered in the article AI and Data Protection. In practice, it pays to handle both topics in a single project, since the system inventory, role clarification, and documentation are needed for both anyway.

Conclusion

The EU AI Act is considerably less dramatic than the coverage of it suggests — but it's also not something you can simply wait out. The logic is simple: assess the risk, clarify the role, derive the obligations. For most businesses, that means a system inventory, an honest classification, transparency around AI content, and trained staff. Companies that have these four points covered are on solid ground — and can keep using AI instead of banning it out of uncertainty.

FAQ

Frequently Asked Questions

To everyone who offers, places on the market, or professionally uses AI systems in the EU — regardless of where the company is based. Even a provider from the US or Asia falls under it as soon as their system's output is used in the EU. Purely private use is exempt, as is research prior to market launch and military and national security purposes.

No. Using general AI assistants for writing, research, or analysis typically falls under minimal or limited risk. The obligations for the model itself lie with the provider. What you need to contribute is transparency toward customers, trained staff, and compliance with data protection.

Providers develop an AI system or place it on the market under their own name and bear most of the obligations. Deployers use a third-party system professionally and have significantly fewer requirements — essentially, using it as intended, human oversight, and informing affected individuals. Anyone who substantially modifies or rebrands a system can turn from a deployer into a provider.

Banned practices include social scoring by public authorities, AI that specifically exploits the vulnerabilities of certain groups of people, emotion recognition in the workplace and in educational institutions, the untargeted collection of facial images to build recognition databases, and — with narrow exceptions — real-time remote biometric identification in public spaces.

Create an inventory of all the AI tools in use, assign each one a risk class, and pay particular attention to anything related to HR decisions. Then sort out labeling for AI content and chatbots, and ensure demonstrable AI literacy across the team. For most SMEs, these four steps cover the bulk of what needs to be done.

Quiz

Test Your Knowledge

Five questions on the EU AI Act's risk classes, roles, and deadlines.

Question 1 of 5

What principle does the EU AI Act use to regulate?