Insights

Does the EU AI Act apply to my company?

For risk & compliance leadsVerified July 2026

Probably, at least in part — and more likely than most mid-market leaders assume. The instinct is to file the EU AI Act under "a problem for the big technology firms building models." In practice it lands hardest on the companies that use AI, it reaches past the EU's borders, and several of its obligations are already in force. So the useful question is not whether it applies, but which parts apply to you, and by when.

What follows is the shape of the law for a company that buys and deploys AI rather than builds it, so you can place yourself in it without wading through all 113 articles.

It reaches further than you think

The Act applies along two lines: what you do with AI, and where its effects land.

You can be caught as a provider — you develop an AI system, or have one built and put your name on it — or, far more commonly for a mid-market business, as a deployer: you use an AI system in the course of your work. Deployers carry real obligations of their own. This is not a law that only touches the vendor.

The reach is also extraterritorial. It is not limited to companies established in the EU. If you are a provider or deployer whose AI system's output is used in the EU, you can fall within scope from the UK or the US just the same. A British firm screening applications from EU candidates, or serving EU customers through an AI tool, should assume it is in the conversation.

The four risk tiers

The Act sorts AI by risk, and your obligations follow the tier, not the technology.

Tier What it covers Typical examples What it means for you
Unacceptable Practices judged a clear threat to rights Social scoring, manipulative or exploitative systems, most real-time public biometric identification Banned outright — do not deploy
High-risk AI used in sensitive, consequential decisions Recruitment and CV screening, credit scoring, access to essential services, safety components The heavy obligations live here: risk management, human oversight, record-keeping, transparency
Limited (transparency) AI people interact with, or that generates content Customer chatbots, AI-generated images, audio, or text Disclose it: tell people they are dealing with AI, and label synthetic content
Minimal Everything else Spam filters, AI in analytics, most productivity uses No specific obligations under the Act

Most mid-market AI use sits in the bottom two tiers. The trap is assuming all of yours does. The moment AI touches hiring, lending, or another consequential decision about a person, you have likely stepped into high-risk, where the requirements are substantial and the deployer shares them.

The dates — the ones already passed, and the ones coming

The Act entered into force in August 2024 and applies in phases, so "we'll deal with it when it lands" has already expired for the earliest duties.

  • August 2024 — the Act enters into force; the clock starts.
  • February 2025 — the bans on unacceptable-risk practices apply, and the AI-literacy duty begins: providers and deployers must ensure the staff who work with AI have a sufficient understanding of it.
  • August 2025 — obligations for general-purpose AI models, plus the governance and penalty machinery, take effect.
  • August 2026 — the bulk of the high-risk regime applies.
  • August 2027 — the extended deadline for high-risk AI embedded in products already covered by EU safety law.

Two of those dates are behind us. The AI-literacy duty in particular is easy to miss and already live: if your people use AI and no one has been trained, you are out of step with an obligation that is in force now.

What a mid-market deployer actually has to do

Strip it back and, for most companies that buy rather than build, the near-term work is concrete.

Know where you stand. Inventory where AI is used across the business and sort each use into a tier. You cannot comply with obligations you have not mapped, and that inventory is the first artefact a regulator will ask for.

Meet the duties that are already live. Put AI literacy in place for the people who use these tools. Where you run limited-risk systems, make the disclosures — say when a customer is talking to AI, and label AI-generated content.

Treat high-risk uses as a project, not a checkbox. If you deploy AI in recruitment, credit, or another listed area, the deployer duties — human oversight, keeping logs, using the system as the provider intends, and informing the people affected — need owning before their deadline, not after.

The penalties are sized to be noticed: up to €35m or 7% of global annual turnover for prohibited practices, and up to €15m or 3% for other breaches. The figures are aimed at large firms, but the obligations are not — they apply at your scale too.

The reassuring part is that none of this asks you to become a compliance department overnight. It asks you to know which of your AI uses sit in which tier, to close the duties that are already live, and to have a plan for the high-risk ones before their date arrives.

Placing every AI use in the right tier, closing the duties that are already live, and readying the high-risk ones before their deadline is the governance groundwork Firestarter runs in its six-week accelerator — reviewed against the EU AI Act, and written where it is absent.

Sources and verification. This guide summarises the structure and timeline of Regulation (EU) 2024/1689 — the EU AI Act — as understood in July 2026. It is general information, not legal advice, and the Act's detailed requirements and guidance continue to evolve. Confirm the current obligations and dates against the official EU sources, or with qualified counsel, before you make a compliance decision.

  • Risk & security lead

    How is shadow AI affecting my company?

    Shadow AI, the use of unapproved AI tools by employees, has become one of the fastest-growing data-governance risks for mid-market firms. A risk manager's guide to detecting it and protecting the business.

    Read the guide

  • Risk & security lead

    Does AI train on my business data?

    Whether an AI provider trains on your business data depends almost entirely on which plan you buy. A risk manager's guide to the safe tiers across Anthropic, OpenAI, Google, and Microsoft.

    Read the guide

  • Risk & security lead

    Which AI is right for my company?

    A cost and risk comparison of AI from Anthropic, OpenAI, Google, and Microsoft for business: API and per-seat pricing, plus which fits a manufacturing, financial services, or software company.

    Read the guide

  • Risk & compliance lead

    What does an AI policy need to say?

    A good AI policy fits on a page and gets followed. A risk lead's guide to the essentials — approved tools, the data line that matters most, disclosure, and accountability — without the forty pages nobody reads.

    Read the guide

  • Chief financial officer

    Why do AI pilots fail to pay back?

    Most AI pilots never reach production, and fewer still return value the board can see. A CFO's guide to why AI pilots stall short of payback, and the four things the ones that pay back do differently.

    Read the guide

  • Chief executive

    How do I build a board-ready business case for AI?

    A board funds a decision, not a demo. A chief executive's guide to the four things an AI business case must contain — value, cost, risk, and the ask — and how to size it so the board can act.

    Read the guide

  • Change & people lead

    Why do employees resist AI?

    AI adoption stalls on people, not technology. A change lead's guide to the four real reasons employees resist AI, why training alone doesn't move them, and what actually changes behaviour.

    Read the guide

  • IT & data lead

    Is my data ready for AI?

    Whether your data is ready for AI depends entirely on what you ask AI to do with it. An IT lead's guide to the four things that actually matter, the permissions trap that catches everyone, and where to start.

    Read the guide

  • Operations lead

    What is an AI agent, and what should we automate first?

    An AI agent does more than answer — it takes actions across steps and systems. An operations lead's guide to what agents actually are, where they help and where they don't, and how to choose what to automate first.

    Read the guide