Insights
Does the EU AI Act apply to my company?
Probably, at least in part, and more likely than most mid-market leaders assume. The instinct is to file the EU AI Act under "a problem for the big technology firms building models." In practice it lands hardest on the companies that use AI, it reaches past the EU's borders, and several of its obligations are already in force. The question worth asking is which parts apply to you, and by when.
What follows is the shape of the law for a company that buys and deploys AI rather than builds it, so you can place yourself in it without wading through all 113 articles.
It reaches further than you think
The Act applies along two lines: what you do with AI, and where its effects land.
You can be caught as a provider, meaning you develop an AI system or have one built and put your name on it. Far more commonly for a mid-market business, you are caught as a deployer: you use an AI system in the course of your work. Deployers carry real obligations of their own. The law reaches well beyond the vendor.
The reach is also extraterritorial. It extends past companies established in the EU. If you are a provider or deployer whose AI system's output is used in the EU, you can fall within scope from the UK or the US just the same. A British firm screening applications from EU candidates, or serving EU customers through an AI tool, should assume it is in scope.
The four risk tiers
The Act sorts AI by risk, and your obligations follow the tier, not the technology.
| Tier | What it covers | Typical examples | What it means for you |
|---|---|---|---|
| Unacceptable | Practices judged a clear threat to rights | Social scoring, manipulative or exploitative systems, most real-time public biometric identification | Banned outright: do not deploy |
| High-risk | AI used in sensitive, consequential decisions | Recruitment and CV screening, credit scoring, access to essential services, safety components | The heavy obligations live here: risk management, human oversight, record-keeping, transparency |
| Limited (transparency) | AI people interact with, or that generates content | Customer chatbots, AI-generated images, audio, or text | Disclose it: tell people they are dealing with AI, and label synthetic content |
| Minimal | Everything else | Spam filters, AI in analytics, most productivity uses | No specific obligations under the Act |
Most mid-market AI use sits in the bottom two tiers. The trap is assuming all of yours does. The moment AI touches hiring, lending, or another consequential decision about a person, you have likely stepped into high-risk, where the requirements are substantial and the deployer shares them.
The dates that have passed and the ones coming
The Act entered into force in August 2024 and applies in phases, so "we'll deal with it when it lands" has already expired for the earliest duties.
- August 2024: the Act enters into force and the clock starts.
- February 2025: the bans on unacceptable-risk practices apply, and the AI-literacy duty begins. Providers and deployers must support the development of AI literacy among the staff who work with AI.
- August 2025: obligations for general-purpose AI models, plus the governance and penalty machinery, take effect.
- 2 August 2026: the Article 50 transparency duties apply, and the Digital Omnibus did not defer them. Tell people when they are dealing with an AI system, and mark AI-generated or manipulated content (image, audio, video, and text) as synthetic. If you run a customer chatbot or publish AI-made media, this is your most imminent obligation.
- 2 December 2026: a new prohibition takes effect, added by the omnibus, on AI systems that generate non-consensual intimate imagery or child sexual abuse material.
- 2 December 2027: the bulk of the high-risk regime applies. The Act originally set this at August 2026, but the Digital Omnibus, now law as Regulation (EU) 2026/1744 and in force from 27 July 2026, deferred it to this date.
- 2 August 2028: the deadline for high-risk AI built into products already covered by EU safety law, likewise pushed back by the omnibus.
Three of those dates are behind us, and the transparency duties are days away. The AI-literacy duty is the one companies most often miss: it is already live, though the omnibus softened it from ensuring a sufficient level of literacy to supporting your staff's development of it. If your people use AI and no one has been briefed, you are behind an obligation that already applies.
What a mid-market deployer actually has to do
Strip it back and, for most companies that buy rather than build, the near-term work is concrete.
Know where you stand. Inventory where AI is used across the business and sort each use into a tier. You cannot comply with obligations you have not mapped, and that inventory is the first artefact a regulator will ask for.
Meet the duties that are already live. Put AI literacy in place for the people who use these tools. Where you run limited-risk systems, make the disclosures: say when a customer is talking to AI, and label AI-generated content. The Commission has issued Guidelines on these Article 50 duties and a Code of Practice on marking AI-generated content: adopting the Code is treated as an adequate way to comply, and if you do not, you have to show your own approach is equivalently adequate.
Treat high-risk uses as a project rather than a checkbox. If you deploy AI in recruitment, credit, or another listed area, the deployer duties need owning before their deadline. Those duties include human oversight, keeping logs, using the system as the provider intends, and informing the people affected.
The penalties are sized to be noticed: up to €35m or 7% of global annual turnover for prohibited practices, and up to €15m or 3% for other breaches. Those figures are aimed at large firms. The obligations are not, and they apply at your scale too.
The reassuring part is that none of this asks you to become a compliance department overnight. It asks you to know which of your AI uses sit in which tier, to close the duties that are already live, and to have a plan for the high-risk ones before their date arrives.
Firestarter sorts your AI uses by tier, closes the duties that are already live, and readies the high-risk ones before their deadline. It runs in six weeks, reviewed against the EU AI Act.