Insights
Does the EU AI Act apply to my company?
Probably, at least in part — and more likely than most mid-market leaders assume. The instinct is to file the EU AI Act under "a problem for the big technology firms building models." In practice it lands hardest on the companies that use AI, it reaches past the EU's borders, and several of its obligations are already in force. So the useful question is not whether it applies, but which parts apply to you, and by when.
What follows is the shape of the law for a company that buys and deploys AI rather than builds it, so you can place yourself in it without wading through all 113 articles.
It reaches further than you think
The Act applies along two lines: what you do with AI, and where its effects land.
You can be caught as a provider — you develop an AI system, or have one built and put your name on it — or, far more commonly for a mid-market business, as a deployer: you use an AI system in the course of your work. Deployers carry real obligations of their own. This is not a law that only touches the vendor.
The reach is also extraterritorial. It is not limited to companies established in the EU. If you are a provider or deployer whose AI system's output is used in the EU, you can fall within scope from the UK or the US just the same. A British firm screening applications from EU candidates, or serving EU customers through an AI tool, should assume it is in the conversation.
The four risk tiers
The Act sorts AI by risk, and your obligations follow the tier, not the technology.
| Tier | What it covers | Typical examples | What it means for you |
|---|---|---|---|
| Unacceptable | Practices judged a clear threat to rights | Social scoring, manipulative or exploitative systems, most real-time public biometric identification | Banned outright — do not deploy |
| High-risk | AI used in sensitive, consequential decisions | Recruitment and CV screening, credit scoring, access to essential services, safety components | The heavy obligations live here: risk management, human oversight, record-keeping, transparency |
| Limited (transparency) | AI people interact with, or that generates content | Customer chatbots, AI-generated images, audio, or text | Disclose it: tell people they are dealing with AI, and label synthetic content |
| Minimal | Everything else | Spam filters, AI in analytics, most productivity uses | No specific obligations under the Act |
Most mid-market AI use sits in the bottom two tiers. The trap is assuming all of yours does. The moment AI touches hiring, lending, or another consequential decision about a person, you have likely stepped into high-risk, where the requirements are substantial and the deployer shares them.
The dates — the ones already passed, and the ones coming
The Act entered into force in August 2024 and applies in phases, so "we'll deal with it when it lands" has already expired for the earliest duties.
- August 2024 — the Act enters into force; the clock starts.
- February 2025 — the bans on unacceptable-risk practices apply, and the AI-literacy duty begins: providers and deployers must ensure the staff who work with AI have a sufficient understanding of it.
- August 2025 — obligations for general-purpose AI models, plus the governance and penalty machinery, take effect.
- August 2026 — the bulk of the high-risk regime applies.
- August 2027 — the extended deadline for high-risk AI embedded in products already covered by EU safety law.
Two of those dates are behind us. The AI-literacy duty in particular is easy to miss and already live: if your people use AI and no one has been trained, you are out of step with an obligation that is in force now.
What a mid-market deployer actually has to do
Strip it back and, for most companies that buy rather than build, the near-term work is concrete.
Know where you stand. Inventory where AI is used across the business and sort each use into a tier. You cannot comply with obligations you have not mapped, and that inventory is the first artefact a regulator will ask for.
Meet the duties that are already live. Put AI literacy in place for the people who use these tools. Where you run limited-risk systems, make the disclosures — say when a customer is talking to AI, and label AI-generated content.
Treat high-risk uses as a project, not a checkbox. If you deploy AI in recruitment, credit, or another listed area, the deployer duties — human oversight, keeping logs, using the system as the provider intends, and informing the people affected — need owning before their deadline, not after.
The penalties are sized to be noticed: up to €35m or 7% of global annual turnover for prohibited practices, and up to €15m or 3% for other breaches. The figures are aimed at large firms, but the obligations are not — they apply at your scale too.
The reassuring part is that none of this asks you to become a compliance department overnight. It asks you to know which of your AI uses sit in which tier, to close the duties that are already live, and to have a plan for the high-risk ones before their date arrives.
Placing every AI use in the right tier, closing the duties that are already live, and readying the high-risk ones before their deadline is the governance groundwork Firestarter runs in its six-week accelerator — reviewed against the EU AI Act, and written where it is absent.