What Is the EU AI Act? What It Means for Non-EU Companies

The debate about regulating AI has run for two years; this month a concrete threshold was crossed. As of 2 August 2026, most of the EU AI Act's obligations for high-risk systems began to apply.
That can look like something happening only in Europe. But the logic of its scope is the same as the digital product passport we wrote about last week: what matters is not where something was built, but where it is used.
This article is for information only and is not legal advice. For scope, exemptions and dates, rely on the European Union's official texts and consult your own legal adviser.
What is the AI Act?
The AI Act regulates AI systems according to their level of risk. Rather than applying one rule set to everyone, it looks at what a system does and scales the obligations accordingly.
There are four tiers:
- Unacceptable risk: prohibited practices. For these it is not about compliance but about not using them.
- High risk: uses that directly affect people's rights, safety and opportunities. This is where the weight of the obligations sits.
- Limited risk: uses that mainly require transparency — a person knowing they are talking to an AI, or that content was AI-generated.
- Minimal risk: most everyday tools. No additional obligations.
That tiering is genuinely useful in practice: your team summarising a document and a system producing a hiring decision are not in the same category.
Why does it concern a company outside the EU?
The AI Act is not domestic law elsewhere. But its reach is extraterritorial: obligations can arise if your AI system is placed on the EU market or its output is used in the EU.
Typical cases:
- A SaaS product built outside the EU and sold to EU customers.
- A supplier sitting in an EU company's chain, feeding data or model output into their system.
- A recruitment tool screening candidates in the EU.
And what arrives before legislation is usually a contract: your EU customer needs documentation to support their own compliance. A supplier who cannot produce it drops off the list. For most small businesses, then, the real risk is not a penalty but lost business.

How did the timeline work?
The law came into effect in stages rather than all at once:
- 1 August 2024: the Act entered into force.
- 2 February 2025: prohibited practices and the AI literacy obligation for staff.
- 2 August 2025: general-purpose AI (GPAI) obligations and governance provisions.
- 2 August 2026: most obligations for the high-risk uses listed in Annex III.
Note the second item: AI literacy is written in as an obligation. Your team using these tools knowingly is no longer merely good practice. We described how to build that in our AI literacy guide.
Which uses count as high risk?
From the Annex III list, those most relevant to ordinary businesses are:
- Employment and HR: CV screening, candidate ranking, promotion and performance assessment.
- Creditworthiness assessment and certain financial services.
- Education: exam scoring, placement.
- Critical infrastructure management.
- Law enforcement and migration applications.
The distinction becomes clear here: having a chat assistant draft a proposal is out of scope; a system that produces a decision about a person, or feeds that decision directly, is in scope.
The obligations expected of a high-risk system group into seven headings: risk management, data governance, record-keeping, transparency, human oversight, accuracy and cybersecurity.
That list should feel familiar. Narrowing an agent's permissions, keeping logs and holding a human approval step on outward actions is exactly the arrangement we described in protecting personal data while using AI. The inventory logic from our data privacy compliance guide pays off again here.
Are you a provider or a deployer?
This is the most frequently confused part of the Act. Obligations do not fall equally on everyone; they follow your role.
A provider develops the system and places it on the market. The heavier duties sit here: technical documentation, conformity assessment, record-keeping, monitoring the system in use.
A deployer runs the system in their own operations. The expectations there are lighter but real: operate the system according to its instructions, make sure input data is appropriate, actually apply human oversight, and monitor performance and report problems.
Most small businesses sit in the second group. But note: if you take a ready-made system and offer it under your own brand, or substantially change its purpose, the role can shift. If you build software and hand your customer a module that produces decisions, you are in the first group — a new dimension of the custom software or off-the-shelf debate.
Four things you can do today
There are steps worth taking before launching a compliance project:
1. Build an AI inventory. Which tool is used in which process, with which data? Include AI features inside software you bought — that is the most commonly forgotten place.
2. Mark each item "does it produce a decision?" Tools that draft text on one side, systems that produce outcomes about people on the other. The high-risk conversation starts with the second group.
3. Clarify your EU connection. Do you sell into the EU, do you sit in an EU customer's chain, is your output used in the EU? If the answer is no, you may have no direct obligation today; if yes, start preparing early.
4. Put human oversight and logging in place now. These are both what the rules ask for and what should exist anyway; adding them later is always more expensive.
Not panic, but order
The first reaction to reading about this regulation is usually anxiety about whether you are in scope. For most small businesses the practical answer is: the bulk of your everyday AI use stays in the minimal-risk category.
What makes the difference is systems producing decisions about people, and products touching the EU market. And even there, what is asked for is not magical technology — it is records, oversight and transparency.
If you would like us to build your AI inventory, work out together which uses fall into the decision-producing class, or add logging and human approval steps to your systems, get in touch; you can also look through our services to see how we work.
Frequently Asked Questions
- What is the EU AI Act?
- The AI Act is the European Union's law regulating AI systems according to their level of risk. It separates systems into unacceptable (prohibited), high-risk, limited-risk (subject to transparency duties) and minimal-risk, and the weight of the obligations follows that classification. It entered into force on 1 August 2024 and its provisions apply on a phased timeline.
- Does the EU AI Act apply to companies outside the EU?
- It is not domestic law elsewhere, but its reach is extraterritorial. Obligations can arise if your AI system is placed on the EU market or its output is used in the EU — software built outside the EU and sold to EU customers, or sitting in an EU company's supply chain, are typical cases. In practice the demand usually arrives contractually first: your EU customer asks you for documentation to support their own compliance.
- Which uses of AI count as high risk?
- The areas listed in Annex III are treated as high risk. Those most relevant to ordinary businesses are employment and HR (CV screening, promotion and performance decisions), creditworthiness assessment, education, critical infrastructure and law enforcement. Drafting text with a chat assistant does not fall in scope; systems that produce decisions about a person do.
- What changed on 2 August 2026?
- The AI Act applies in phases: prohibited practices and the AI literacy duty for staff started on 2 February 2025, and general-purpose AI plus governance provisions on 2 August 2025. 2 August 2026 is the date on which most obligations for the high-risk uses listed in Annex III began to apply.
Need help with this topic?
Contact Us