The blogTake back control · Episode 2/5

The AI Act explained for people with no time: what Europe really expects of you

The big picture, the concrete impact on your business, and the pitfalls to avoid, without the legal jargon.

"Take back control" series, Episode 2/5 · 1. Sovereign AI in Europe · 3. GDPR and AI · 4. Building your first sovereign AI agent · 5. Scaling up


Let's start with a simple question

Does your business use a tool that screens CVs? A customer-facing chatbot? A credit or risk score? Software that evaluates how your people perform?

If you answered yes even once, you're not a spectator of the AI Act. You're affected. Not as an observer, as a participant, with real obligations.

And here's misconception number one, the one that will cost a lot of companies dearly: most people think the AI Act only concerns those who build AI. OpenAI, Mistral, Google. Wrong. The regulation also targets, and above all, by sheer volume, those who use it. You, most likely.

So let's take fifteen minutes to understand this text. Not to become a lawyer. To make informed decisions.


The core idea: you don't regulate the technology, you regulate the risk

If the AI Act boiled down to one sentence, it would be this: Europe doesn't judge what AI is, it judges what AI does to you.

The regulation (EU 2024/1689, in force since 1 August 2024, the world's first legal framework of its kind) never says "neural networks are banned" or "LLMs must do X." It sorts uses into four tiers, like a pyramid:

🔴 Tier 1, Unacceptable risk: banned. At the very top, what Europe rejects on principle, whatever the safeguards. Eight prohibited practices since February 2025: social scoring, subliminal manipulation, exploiting vulnerabilities (age, disability, hardship), mass scraping of faces to build facial-recognition databases... If you use one of these practices, even through a third party, you're already breaking the law.

🟠 Tier 2, High risk: allowed, but tightly controlled. The heart of the reactor. These are the AI systems that shape important decisions in people's lives: recruitment and HR management, access to credit and insurance, education (grading, guidance, cheating detection), health, justice, biometrics, critical infrastructure. These systems must prove they're serious: risk management, data quality, technical documentation, human oversight, traceability.

🟡 Tier 3, Limited risk: transparency required. Chatbots and AI-generated content. The rule is simple: don't deceive people. A human talking to a machine must know it. A deepfake must be flagged as one.

🟢 Tier 4, Minimal risk: move along. The spam filter, the AI in your video game, the assistant that summarises your internal meetings. The vast majority of uses, in reality. No specific obligation.

So the question to ask yourself isn't "do I use AI?" but: "does my AI influence decisions that significantly affect people's lives?" If yes, you're probably in the orange zone.


The UK: same continent, different rulebook

Before going further, a crucial point for any business operating on both sides of the Channel: the UK has no AI Act. There is no equivalent single, horizontal law.

Instead, the UK has chosen a pro-innovation, principles-based approach, driven by existing sector regulators rather than one overarching statute. Five cross-cutting principles (safety, transparency, fairness, accountability, contestability) are applied by the bodies that already govern each domain: the ICO (Information Commissioner's Office) for data protection, the FCA for financial services, the CMA for competition, Ofcom for online safety, the MHRA for medical devices, and so on. No fixed risk pyramid, no CE marking, no single European database to register in.

That doesn't mean a UK company can relax. Two things keep it firmly in scope:

  • Extraterritorial reach. The AI Act applies to any provider or deployer: wherever they're based, whose AI output is used in the EU. A UK software vendor selling an HR tool to a German or French client falls squarely under the regulation.
  • The single market reflex. If you sell into the EU, operate an EU establishment, or process the data of EU residents, EU rules follow the product, not the postcode.

In short: a UK reader has different obligations at home, lighter and more sector-specific for now, but remains fully concerned the moment they touch the EU market. The pragmatic move for cross-border firms is to treat the EU AI Act as the higher bar and build to it.


Provider or deployer: what's your role?

Another key to reading the text. The regulation distinguishes several roles, but two cover the vast majority of companies:

  • The provider: the one who develops or brings an AI system to market. It carries most of the heavy obligations (documentation, CE marking, registration).
  • The deployer: the one who uses an AI system in a professional setting. Lighter obligations, but very real ones: use the tool in line with its instructions, ensure human oversight, inform the people affected, keep the logs.

The classic trap: the SME that buys a CV-screening SaaS and thinks it's off the hook because "the vendor handles it." No. As a deployer of a high-risk system, you have your own obligations. And beware of role creep: if you substantially modify the tool or use it under your own brand, you can become a provider, with the full package of obligations that comes with it.

One last point on scope, often underestimated: the regulation also applies to companies outside the EU as soon as their AI is used in Europe. An American company selling HR software to European clients is in scope, and, as we just saw, so is a British one.


The timeline: what's already in force, what's coming

This is where you have to be precise, because the timeline has shifted recently. The "Digital Omnibus" package (political agreement between the Council and Parliament on 7 May 2026) rescheduled several deadlines to give the technical standards time to mature.

Already in force, no debate:

  • Since February 2025: the prohibited practices (penalties applicable) and the "AI literacy" obligation (Article 4), your teams who use AI must be trained on its risks and limits. Yes, training is already a legal obligation.
  • Since August 2025: the obligations for providers of general-purpose AI models (GPAI: OpenAI, Mistral, Anthropic...), transparency, traceability of training data.

On 2 August 2026: general application of the regulation, activation of enforcement powers, transparency obligations (chatbots, generated content, with a deadline of 2 December 2026 for the technical marking of content).

Postponed by the Omnibus:

  • 2 December 2027: full compliance for "standalone" high-risk systems under Annex III (HR, credit, education, biometrics...).
  • 2 August 2028: high-risk systems embedded in CE-regulated products (medical devices, machinery, vehicles).

The Omnibus also brought two notable reliefs: AI embedded in products already CE-certified is largely exempt from the high-risk regime (only registration remains), and the facilities designed for SMEs (regulatory sandboxes, lighter documentation) are extended to a new European category, "small mid-caps" (companies with fewer than 750 employees, defined by the Commission in May 2025).

Beware the lazy reading of this delay: it is not a pause. The fundamentals, prohibitions, training, transparency, are active or imminent. Several national regulators, including data-protection authorities across the EU, have signalled they will step up scrutiny of HR systems from late 2026 onwards.


The concrete impact on your business

Let's translate all this into operational reality.

If you simply use off-the-shelf AI tools (assistants, content generators, augmented office software): your exposure is low. Two things to do: train your teams (an obligation already in force) and flag the AI nature when your customers interact with a bot or generated content.

If you use AI in HR, credit, or high-stakes customer relations: you're a high-risk deployer. You need to: check that your provider is compliant (and put it in the contract, if they fall short, your own liability can be triggered), guarantee genuine human oversight (not a human clicking "approve" without looking), inform the people affected, keep the usage logs.

If you develop or resell AI solutions: you're a provider. The bulk of the work is on you: a risk-management system, data-quality governance, technical documentation, registration in the European database, CE marking for high risk.

And the crux of it all, the penalties, graduated by severity:

  • Prohibited practices: up to €35M or 7% of worldwide turnover.
  • Non-compliant high risk: up to €15M or 3%.
  • Transparency breaches: up to €7.5M or 1%.

In each EU member state, enforcement is shared among national authorities, typically the data-protection authority (personal data, biometrics), the consumer-protection body (commercial practices), and the media/content regulator (generated content). The UK, by contrast, has no such single AI enforcement regime: your first port of call there is the sector regulator that already oversees your activity, often the ICO where personal data is involved.

A word of hope in the middle of all this: if you survived the GDPR, you already know the method. The AI Act is the GDPR of AI, and the two texts are complementary and apply simultaneously whenever an AI processes personal data (the EU GDPR in the EU, the UK GDPR in Britain). A well-run compliance project quickly becomes second nature.


The five watch-outs (where it hurts)

1. Deployer denial. "We don't have AI, we just use tools." This is the most widespread and most costly mistake. A CRM with scoring, an ATS (Applicant Tracking System, the software that screens job applications) that pre-sorts CVs, a chatbot: you're in scope. The reflex: the inventory. List every tool with an AI component, including the ones your teams adopted without asking (the famous shadow AI). It's step number one recommended by the Commission and by industry bodies alike, and it takes a few weeks.

2. Training, the invisible obligation. Article 4 has been in force since February 2025 and almost no one knows it. It doesn't only target developers: HR, managers, buyers, business lines, anyone who uses AI must understand its risks and limits. It's the cheapest obligation to meet and the first one an inspector will check.

3. The contract with your providers. The deployer's challenge is largely contractual: demand compliance guarantees, documentation and transparency commitments from your AI vendors. A provider who can't answer these questions today is a risk for tomorrow. And remember the lesson from episode 1: a sovereign European provider (Mistral, Scaleway, OVHcloud...) mechanically simplifies the demonstration, traceability, data localisation and GDPR (EU and UK) fall into line on their own, whereas a vendor subject to the US Cloud Act forces you to document twice as much, because data held by a US-controlled provider can be compelled by US authorities regardless of where it sits.

4. Cosmetic human oversight. The text demands genuine oversight: someone trained, able to understand the system, spot when it goes off the rails and override its decisions. A human rubber stamp validating in bulk will protect no one, neither the people affected, nor you in an inspection.

5. Wait-and-see dressed up as prudence. "The timeline was pushed back, let's wait." Bad maths, for three reasons: the baseline obligations are already active; deployed systems take years to bring into compliance, not weeks; and an early-activation clause exists, if the standards are ready sooner, deadlines can be brought forward. Compliance protects those who start early. It penalises those who wait for the penalty.


Where to start: the five-step method

  1. Inventory every AI use across the organisation, including shadow AI. (A few weeks.)
  2. Classify each use against the risk pyramid. Most will land in the green zone: good, and now it's documented.
  3. Appoint an AI lead (often attached to the DPO, given how tightly the two texts interlock).
  4. Put governance in place: a systematic risk assessment for every new AI project, contractual clauses with providers, logging.
  5. Train, and document that you did.

The first three steps fit in a single quarter. And they already cut your exposure considerably.


The bottom line

The AI Act is often presented as a European brake on innovation. Allow me a different reading.

This text raises a question every serious company should ask itself even without a law: do you know what your machines are deciding on your behalf, and can you justify it? The companies that can answer, inventory up to date, providers vetted, teams trained, won't just have dodged a fine. They'll have built something more valuable: trust. The trust of their customers, their candidates, their regulators.

The GDPR taught us one thing: compliance taken early is an investment; taken late, it's a crisis. And note that this holds on both sides of the Channel, whether you answer to the EU AI Act or to the UK's principles-based, regulator-led approach, the underlying discipline is the same.

Did you answer yes to any of those when you opened this article? Then you know what's left to do this week: open a spreadsheet, and start the list of your AI tools.

That's all. And it's everything.


📖 In the same series, Episode 1: "Sovereign AI in Europe in 2026" (state of play, roadmap, self-hosting vs API) · Episode 3: "GDPR and AI" (legal bases, DPIA, data-subject rights, because when your AI processes personal data, both texts apply at once) · Episode 4: "Building your first sovereign AI agent" (taking the plunge, in 7 steps) · Episode 5: "Scaling up" (from the first agent to infrastructure that holds).


*Main sources: Regulation EU 2024/1689 (official text), European Commission, the "Digital Omnibus" political agreement of 7 May 2026, EU data-protection authorities, the UK's pro-innovation AI regulation framework and ICO guidance. The post-Omnibus timeline remains subject to publication in the Official Journal of the EU: verify the official deadlines before any decision, and have your situation checked by legal counsel, this article explains, it does not replace a lawyer's advice.

← Back to the blog