The EU AI Act for companies that use AI: a deployer's guide

by
Dawid Winiarski
Last update:
July 17, 2026

If your company uses ChatGPT, Copilot, or any other AI tool for work, the EU AI Act (Regulation (EU) 2024/1689) applies to you. You are a deployer under the Act, whether or not you built anything yourself. For a 50-to-500-person company, though, far less of the scary headline applies than the coverage suggests. The heavy obligations attach to high-risk systems, and ordinary productivity use almost never qualifies.

What you owe right now is an AI literacy effort and a check that none of your AI use crosses the prohibited lines, both in force since February 2025. From August 2026, customer-facing AI needs to disclose itself. The heavier duties only land if you use AI for things like hiring decisions or credit scoring.

  • The EU AI Act assigns all AI systems to risk categories. Most general-purpose productivity tools (ChatGPT, Copilot, Gemini) land in the limited or minimal risk tiers. Specific use cases in HR, credit, and critical infrastructure can make you a high-risk deployer.
  • As of 2 February 2025, the prohibition on eight categories of AI practices applies to everyone, including ordinary businesses. Using AI in ways that cross these lines is illegal now.
  • As of 2 February 2025, the AI literacy duty (Article 4) applies. You must take measures to ensure sufficient AI literacy among staff and others who operate AI systems on your behalf.
  • As of 2 August 2026, transparency obligations for limited-risk systems and the remaining deployer obligations are fully enforceable, including the duty to disclose AI-generated content and AI chatbot interactions.
  • High-risk deployer obligations (Article 26) apply from 2 December 2027 for standalone Annex III systems and 2 August 2028 for AI embedded in Annex I regulated products, under the omnibus amendments, adopted by Parliament on 16 June 2026 and by Council on 29 June 2026, with publication in the Official Journal pending as of July 2026.
  • Penalties for violations of prohibited practices reach EUR 35 million or 7% of global annual turnover.

what the EU AI Act is and who it covers

The EU AI Act (Regulation (EU) 2024/1689) has been in force since 1 August 2024. It is the EU's single rulebook for AI systems across all sectors, and it applies to providers and deployers of AI systems operating in or placing systems on the EU market, wherever those organizations are headquartered.

The regulation operates on a risk-based model. It assigns AI systems and their uses to categories and attaches obligations to each category. The higher the potential harm, the heavier the requirements. The vast majority of AI tools in everyday business use land in the limited or minimal risk categories and face lighter requirements than the high-risk classification that gets the most coverage.

The Act covers any AI system used in a professional capacity within the EU. A German company using an American-built AI tool in its HR process is within scope. A Polish company deploying a customer-facing chatbot is within scope. Scope is determined by where the system is used, not by who built it.

As of July 2026, the Act's timeline has been adjusted by the Digital Omnibus, adopted by the European Parliament on 16 June 2026 and by the Council on 29 June 2026. It extends the deadlines for high-risk system obligations. The omnibus is pending publication in the Official Journal; the original 2 August 2026 date remains the operative legal text until publication occurs.

provider, deployer, and GPAI: the three roles

The Act defines three primary categories of actors. Understanding which one you are determines which obligations apply.

Provider (Article 3(3)). A provider is any person that develops an AI system or a general-purpose AI model and places it on the market or puts it into service under its own name or trademark. If your organization built the AI system and released it, you are a provider. Providers carry the heaviest obligations: conformity assessments, technical documentation, post-market monitoring, registration in the EU database, and more. Most mid-market organizations are not providers. They buy or subscribe to AI systems built by others.

Deployer (Article 3(4)). A deployer is any person that uses an AI system under its authority in a professional context, other than for personal use. If your company's employees use ChatGPT, Microsoft Copilot, or any other AI tool in their work, your organization is a deployer. Professional use is the threshold. Deployers do not need to have developed the system or licensed it through a formal enterprise agreement. The deployer category is the one most mid-market companies sit in, and the one most underestimated in early coverage of the Act.

GPAI model provider (Articles 51-56). General-purpose AI (GPAI) models are foundation models capable of performing a wide range of tasks. GPT-4, Claude, Gemini, Llama, and similar models are GPAI models. The organizations that train and distribute these models are GPAI providers. Organizations that use GPAI-based tools are deployers, not GPAI providers. GPAI provider obligations applied from 2 August 2025 and fall on the model builders, not on a company that uses a tool built on a GPAI model.

One practical note on the boundary: a company that fine-tunes a GPAI model for its own use and then makes the fine-tuned version available to others may cross from deployer into provider territory. The line is at whether the system is placed on the market or made available to others beyond internal use.

risk categories: where your tools land

The Act organizes AI systems into four risk tiers. The tier determines the obligations attached to the system.

Unacceptable risk (prohibited). Eight categories of AI practice are prohibited outright. They apply regardless of who is using the system, and have been in force since 2 February 2025.

High risk (Annex III and Annex I). Annex I systems are AI embedded in regulated products already subject to EU legislation: medical devices, machinery, civil aviation equipment, motor vehicles, toys, and others, with a deadline of 2 August 2028 under the omnibus agreement. Annex III systems are standalone AI used in specific high-stakes domains: biometric identification, critical infrastructure management, education, employment and workforce management, access to essential private and public services, law enforcement, migration, and administration of justice. The deadline for standalone Annex III systems is 2 December 2027 under the omnibus agreement. For deployers, the key question is whether the use case, not just the tool, qualifies as high-risk. A general-purpose model used to summarize internal meeting notes is likely minimal risk; the same model used to screen job applications is potentially high-risk.

Limited risk. AI systems that interact directly with people and AI systems that generate or manipulate content fall here. The primary obligations are transparency: disclose that you are interacting with AI, label AI-generated content, notify individuals exposed to emotion recognition or biometric categorization. These obligations apply from 2 August 2026.

Minimal risk. AI used for spam filtering, content recommendation, and most back-office productivity tools. No mandatory requirements. The Act encourages voluntary codes of conduct.

what a deployer must actually do

Article 4: the AI literacy duty

Article 4 applies to all providers and deployers, regardless of the risk tier of the AI systems involved. It requires organizations to take measures to ensure a sufficient level of AI literacy among their staff and other persons who operate or use AI systems on the organization's behalf. The obligation has applied since 2 February 2025.

The required level of literacy is calibrated to the role: who is using the AI, in what context, and who is affected by the outputs. An employee using an AI writing tool to draft internal memos needs a different level of understanding than an HR manager using AI to screen candidate applications. The Act qualifies the duty with "to their best extent," which builds in proportionality. The practical minimum is an AI Acceptable Use Policy that employees can understand, combined with some form of documented training or briefing on how AI tools work and what data should not be put into them. AI literacy is also a precondition for the other obligations, because employees who do not understand what an AI system is doing cannot meaningfully exercise human oversight.

Article 5: prohibited practices that catch ordinary business use

The eight prohibited AI practices have been in force since 2 February 2025. They apply to all parties, including ordinary businesses that deploy AI tools. Most do not touch standard productivity use, but three categories warrant attention.

Subliminal manipulation (Article 5(1)(a)). AI systems that deploy subliminal techniques beyond a person's awareness to distort their behavior in harmful ways are prohibited. A customer-facing AI persuasion tool operating below conscious awareness to influence purchasing decisions could fall here.

Exploitation of vulnerabilities (Article 5(1)(b)). AI systems that exploit vulnerabilities based on age, disability, or social or economic situation are prohibited. An AI debt-collection tool targeting emotionally vulnerable individuals, or a marketing tool targeting people in financial distress with high-interest products, could raise questions.

Biometric categorization and real-time biometric ID in public spaces (Article 5(1)(c)-(h)). The Act prohibits AI that infers sensitive attributes (political opinions, religious beliefs, sexual orientation, race) from biometric data for categorization, and real-time remote biometric identification in publicly accessible spaces for law enforcement, with three narrow exceptions. Any biometric categorization deployment requires specific legal review first.

The penalty for violation of a prohibited practice is the highest in the Act: EUR 35 million or 7% of global annual turnover, whichever is higher.

Article 50: transparency obligations

Article 50 applies to deployers of AI systems that generate content, interact with natural persons, or use biometric or emotion recognition. The primary requirements are disclosure and labeling, enforceable from 2 August 2026. Deployers of AI that generates deepfake image, audio, or video must disclose that the content has been artificially generated, clearly and visibly. Deployers of AI intended to interact directly with people must inform them they are interacting with an AI system, unless this is obvious from context: a customer service chatbot that does not identify itself as AI is non-compliant once Article 50 applies. Deployers of emotion recognition or biometric categorization systems must inform the people exposed to them. The practical impact lands on customer-facing deployments and on any AI tool that generates external communications.

Article 26: high-risk deployer obligations

If your organization deploys a high-risk AI system as defined in Annex III (standalone) or Annex I (embedded in a regulated product), Article 26 attaches a specific set of deployer obligations. These apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, subject to formal adoption of the omnibus amendments. The requirements: use AI systems according to the provider's instructions; ensure human oversight by people with the competence, authority, and means to intervene; maintain and retain logs the system generates for at least six months; conduct a fundamental rights impact assessment (FRIA) before deploying certain Annex III systems and notify the relevant market surveillance authority; inform affected individuals that they are subject to a high-risk AI system; and monitor operation, identify malfunctions, and report serious incidents. The FRIA is separate from the GDPR Data Protection Impact Assessment (DPIA), though the two can be coordinated where a DPIA is already required.

how an SME using ChatGPT or Copilot is affected

A company with 200 employees using ChatGPT Teams, Microsoft 365 Copilot, or similar general-purpose tools is a deployer. In practice, starting from the obligations that already apply:

February 2025 (now in force). The Article 4 AI literacy duty applies. In practice this means an AI Acceptable Use Policy, documented training or awareness content, and some record that these measures exist. It does not require a formal training programme. A well-written policy communicated at onboarding and re-referenced annually is a proportionate starting point. The prohibited practices also apply. General-purpose productivity tools do not typically implicate them, but any use approaching social scoring, subliminal persuasion, biometric categorization, or exploitation of vulnerabilities requires a specific review.

August 2026 (upcoming). Transparency obligations under Article 50 apply. If the company uses an AI chatbot to interact with customers, or sends AI-generated content to external parties, disclosure requirements activate. Customer-facing AI configurations need to be reviewed before this date.

December 2027 / August 2028 (under omnibus agreement). High-risk deployer obligations apply. For most SMEs using general-purpose productivity tools, this date will not trigger additional obligations. The exception is any company using AI in employment decisions, financial assessments, biometric processes, or critical infrastructure management.

The most common gap for SMEs is a missing inventory. Article 4 and the Article 50 transparency duties require knowing which AI tools are in use and how they are used. Most organizations using AI extensively do not have a complete picture of what is actually in their environment.

penalty tiers and SME reliefs

The Act establishes three penalty tiers under Article 99, each tied to the severity of the violation. Tier 1, EUR 35 million or 7% of global annual turnover (whichever is higher), covers violations of the prohibited practices in Article 5. Tier 2, EUR 15 million or 3%, covers other obligations including those for high-risk systems, GPAI model requirements, and transparency duties. Tier 3, EUR 7.5 million or 1%, covers supplying incorrect, incomplete, or misleading information to authorities.

For SMEs and startups, each fine applies as the percentage or amount in each tier, whichever is lower. This means an SME pays the lower of the absolute figure or the percentage of turnover, not the higher. The Act also requires supervisory authorities to take into account the economic viability of SMEs and startups when setting fines. Market surveillance authorities are required to be established and operational by 2 August 2026, which is also when penalty enforcement becomes fully active.

how the Act interacts with GDPR and NIS2

The EU AI Act does not replace GDPR. For AI systems that process personal data, both regulations apply simultaneously, and compliance with one does not satisfy the other. The most significant interaction is in the impact assessment obligations: GDPR already requires a DPIA for processing likely to result in high risk to individuals, and the AI Act adds the FRIA for deployers of certain high-risk systems. The European Data Protection Board has indicated these assessments can be coordinated, but they address distinct legal bases and cannot be fully collapsed into one another. Where an AI system is used for automated decision-making with legal or similarly significant effects, both GDPR Article 22 and AI Act Article 26 may apply in parallel.

NIS2 (Directive (EU) 2022/2555) and the AI Act address different risk surfaces but overlap. NIS2 Article 21(2)(d) requires essential and important entities to assess and manage supply-chain cybersecurity, and AI tools in your stack are part of that supply chain, so the AI tool vetting the Act encourages satisfies part of the NIS2 requirement. NIS2 Article 21(2)(i) requires access control and asset management, and an AI tool inventory is the same asset inventory NIS2 requires. The AI literacy duty under Article 4 runs alongside NIS2 Article 21(2)(g) on cyber hygiene and training. For organizations in scope for both, treating AI Act and NIS2 compliance as parallel workstreams with shared documentation reduces the overhead on both.

what works: building toward compliance

The work that covers the most ground in the shortest time for a typical mid-market deployer follows a clear sequence. It starts with an AI system inventory: every AI tool in use across the organization, including tools IT deployed, tools teams adopted independently, personal AI accounts used for work, AI capabilities embedded in software you already use (Copilot in Microsoft 365, Gemini in Google Workspace, AI features in Salesforce, Notion, or Slack), and AI browser extensions on managed devices. Pulling the identity provider's OAuth grant list and filtering for AI-related applications is the fastest starting point. This inventory is the input for every obligation that follows.

From there, each tool's use cases are classified against the risk categories. For most general-purpose tools this is quick: limited or minimal risk for productivity and content generation, with high-risk investigation reserved for anything touching employment decisions, financial assessments, biometric data, or critical infrastructure. The classification question is about the use case, not the tool name. Actual deployments are checked against Article 5's eight prohibitions, with specific legal advice sought for any ambiguous case. AI literacy is addressed through a written AI Acceptable Use Policy that names approved tools, classifies data that cannot enter external models, and explains why the rules exist. Customer-facing AI chatbots and any AI generating external communications are reviewed against Article 50 so that chatbots identify as AI and AI-generated content reaching customers is labeled. And for any high-risk use case, the Article 26 work (fundamental rights impact assessment, human oversight processes, log retention, and mandatory notification) is scoped well before the deadline.

Subscribe to unshadowed.

Subscribe to receive the latest blog posts to your inbox and stay up to date with

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

let's start with a conversation

Most first conversations start with not quite knowing what you have or where to begin. That's normal, and it's exactly where we're useful.

Tell us what prompted this. An upcoming audit, an incident, a client's security questionnaire, or just a sense that things have gotten messy.

We'll take it from there

Julian Machowski
Head of Technical Sales
+48 783 762 997
julian@unshadowit.com
Let's connect on LinkedIn
Message received. We'll be in touch soon.
Something failed. Try again or call us directly.