The EU AI Act is extensive. That, at first glance, isn't surprising. European regulations are rarely drafted with the ambition of fitting comfortably on the back of a postcard.
For companies, however, this raises a very practical question:
What obligations actually apply to our specific AI system?
The answer does not depend solely on whether artificial intelligence is used anywhere. Rather, the decisive factors are the company’s role, the system’s purpose, its risk class, and the way it is developed, offered, or deployed.
That's why AI Act compliance doesn't start with a folder full of policies.
It begins with classification.
Not all automated software is automatically an AI system as defined by the EU AI Act.
The regulation covers machine-based systems that operate with a certain degree of autonomy and use inputs to generate outputs such as predictions, content, recommendations, or decisions. These outputs, in turn, can influence real or virtual environments.
That sounds technical. In everyday business, however, it’s all about very specific applications:
Before discussing obligations, it is therefore necessary to clarify whether the specific use case falls under the definition at all.
After all, even regulation needs a point of entry. You just need to know which door to go through.
One of the most important questions in the EU AI Act is not: “Do you use AI?”
The question is: In what capacity are you acting?
Among other things, the AI Act distinguishes between providers, operators, importers, distributors, product manufacturers, and authorized representatives.
A supplier develops an AI system or has one developed and brings it to market under its own name. An operator deploys an AI system under its own responsibility. An importer brings a system from a supplier based outside the EU to the European market. Distributors make systems available within the supply chain.
These roles are not merely a legal formality. They determine which obligations apply.
A company that uses a ready-made AI chatbot internally is often in a different position than a company that offers its own AI service under its own brand.
On top of that, roles can change.
Anyone who significantly modifies an existing AI system, redefines its purpose, or markets it under their own name may become a provider themselves. What may seem like a minor adjustment can thus result in a significantly broader set of obligations.
So the EU AI Act does indeed recognize the moment when “We just made a minor adjustment” turns into a regulatory “Then you’re now responsible.”
The EU AI Act follows a risk-based approach. The greater the potential risk to health, safety, or fundamental rights, the more extensive the requirements are.
Certain practices are completely prohibited. These include, for example, various forms of manipulative AI, social scoring, and certain biometric or predictive applications.
In addition, there are high-risk AI systems. These may include systems in areas such as employment, education, critical infrastructure, medical applications, credit scoring, law enforcement, migration, or the justice system.
Whether a system is actually considered high-risk AI, however, does not depend solely on a broad industry classification.
Among other things, the following should be reviewed:
An AI system used in human resources is therefore not automatically considered high-risk simply because the word “application” appears somewhere. At the same time, a system that influences decision-making should not be labeled as a harmless assistant if it actually shapes selection decisions.
The classification must reflect actual use—not the most flattering description in the project proposal.
If an AI system is classified as high-risk, it is subject to comprehensive requirements.
Providers must take into account, among other things, risk management, technical documentation, data quality, logging, human oversight, accuracy, robustness, and cybersecurity. A conformity assessment may also be required before the product is placed on the market.
Operators must use high-risk systems in accordance with the instructions for use, monitor their operation, and assign appropriate personnel to oversee them. Depending on the area of application, additional information, documentation, or audit requirements may apply.
This shows that AI compliance is not a single legal document.
It combines law, technology, processes, information security, data protection, quality management, and corporate responsibility.
That is precisely why AI systems should not be evaluated from a legal perspective only shortly before their implementation. The relevant question is not, “Can we still document this in the end?”
Rather: “Did we make it manageable from the very beginning?”
Even AI systems that are not classified as high-risk can give rise to legal obligations.
Transparency requirements for interactive and generative AI systems are particularly relevant. People should be able to recognize when they are interacting directly with an AI system. In certain cases, generated or manipulated content must be technically labeled or disclosed in a way that is visible to those affected.
This applies, for example, to:
Here, too, it depends on the role. Providers must design their systems accordingly from a technical standpoint. In certain cases, operators must inform the individuals concerned or label the content.
So a text doesn't become "human" just because it's published without robot emojis.
One key requirement is already in place: Providers and operators must ensure an appropriate level of AI expertise.
This does not apply only to developers. Employees who operate AI systems, evaluate results, or base decisions on them must also have a sufficient understanding of their capabilities and risks.
The appropriate training depends on the operational context.
A marketing department that uses generative AI for design requires different skills than a human resources department that uses AI-powered evaluations. Executives, in turn, must understand the responsibilities they bear and the control structures that are necessary.
AI literacy, therefore, does not mean showing everyone the same presentation and then printing out a certificate of participation.
It must be role-based, practical, and easy to understand.
The EU AI Act does not generally require every company to appoint an AI officer.
Nevertheless, a feature like this can be very useful.
The AI Officer can coordinate:
However, the AI Officer does not replace data protection officers, information security, legal, compliance, or IT. Instead, it brings these perspectives together.
After all, many problems don't arise because no one is responsible. They arise because five people are each partially responsible, and each of them reasonably assumes that the others will take care of the rest.
Companies should start by compiling a comprehensive AI inventory.
It should include at least the following points:
Such an inventory does not in itself ensure full compliance. But without an inventory, any governance framework remains incomplete.
After all, you can only manage what you know. That doesn't automatically mean the rest is problem-free—it's just less well understood.
The EU AI Act cannot be effectively implemented using a single checklist for all systems.
Each exam begins with a specific use case:
Only then can it be determined which obligations actually apply.
An AI Officer can coordinate this process and ensure that classification, documentation, AI expertise, and ongoing monitoring do not operate in isolation from one another.
After all, under the EU AI Act, not every AI system is treated the same.
But each one deserves a thorough review.