Skip to content

The EU AI Act: What Businesses Using AI Need to Know

by Cheryl Baldwin on 8 minutes to read

Summary: If your business uses AI for hiring, customer service, content, or lending, the EU AI Act may already apply to you. It covers two kinds of business: companies based in the EU that use AI, and companies outside the EU whose AI reaches people inside it. A chatbot your European customers talk to, or AI-generated content that reaches them, can be enough to bring you into scope. Everyday tools like writing assistants carry less risk than systems that affect hiring, credit, biometrics, or access to essential services. Start by knowing where AI is used across your business, who it affects, and who's responsible for it.

Key Highlights

  • AI risk depends on how a system is used. A tool that supports drafting carries different implications from one that influences hiring, credit, or access to essential services.
  • The EU AI Act rewards early preparation. Businesses that identify higher-impact systems, clarify responsibilities, and address gaps early will be better prepared as requirements take effect.
  • Transparency should be visible at the point of interaction. Chatbots, deepfakes, public-interest content, and certain biometric tools may require clear notices or identifiable AI-generated content.
  • A useful AI review produces decisions, not just an inventory. Leadership should know which systems need deeper review, who owns them, what disclosure gaps exist, and when each system should be reassessed.
  • Human oversight remains central to responsible AI use. Named owners, editorial review, and clear approval processes help protect customers, employees, and business trust.
  • Governance works best when it starts before procurement. Reviewing purpose, data use, vendor responsibilities, geography, and oversight before approving a tool reduces avoidable risk later.
The EU AI Act: What Businesses Using AI Need to Know
12:35

Your business doesn’t need an office in Europe for the EU AI Act to matter.

The EU AI Act sets risk-based rules for how AI is developed and used in the European Union. It may apply when a company offers or uses an AI system in the EU, or when AI output produced elsewhere is used there. That can include tools used for recruitment, customer service, content creation, lending, and other business activities.

The system’s purpose shapes the level of scrutiny. A writing assistant and a tool that ranks job applicants may rely on similar technology, but the hiring tool can influence who gets an interview. That use requires closer attention.

Visibility is the starting point. Clear disclosures, human oversight, and named ownership help protect customers, employees, and the trust they place in the business.

Start with four questions:

  • Use: What does the AI system do?
  • Impact: Who or what can its output affect?
  • Reach: Where is the system offered, used, or relied upon?
  • Ownership: Who approves, monitors, and documents it?

These questions give the business a practical way to decide which AI uses need attention first.

The Council has approved changes to the EU AI Act implementation timeline that give organizations more time to prepare for certain high-risk systems used in areas such as employment, education, essential services, biometrics, and law enforcement.

Transparency rules for certain chatbots and AI-generated or manipulated content follow an earlier timetable. Businesses can use the additional time to map current AI use and review the systems that have the greatest impact on people or important decisions.

Which AI Uses Need Closer Review Under the EU AI Act?

The EU AI Act uses a risk-based approach. The more an AI system can affect people’s safety, rights, or access to opportunities and services, the more scrutiny it receives.

The General Data Protection Regulation (GDPR) governs how organizations handle personal data. The EU AI Act focuses on AI systems and the risks created by how they’re used.

Prohibited AI practices

Some AI uses are banned because of the harm they can cause. These include certain forms of manipulation, exploitation of vulnerable people, and social scoring.

High-risk AI systems

AI may be considered high risk when it influences decisions in areas such as:

  • Employment and worker management

  • Education and vocational training

  • Credit and access to essential services

  • Biometrics

  • Law enforcement

  • Migration and border control

  • The administration of justice

AI Uses That Require Transparency

Some AI systems require businesses to tell people when AI is involved or make certain AI-generated content identifiable. These can include:

  • Chatbots and other systems that interact directly with people

  • Deepfake content

  • Certain AI-generated or manipulated content about news, elections, health, safety, or other matters of public interest

  • Tools that try to infer emotions or group people using biometric data

  • Systems that generate or alter content that may need machine-readable identification

Lower-risk business tools

Many everyday productivity and content tools won’t face specific risk-based obligations under the EU AI Act. Other rules covering privacy, employment, consumer protection, intellectual property, cybersecurity, and regulated industries may still apply.

For prohibited practices, penalties can reach €35 million or 7% of a company’s worldwide annual turnover for the previous financial year, whichever is higher. Lower maximum penalties apply to other violations.

The practical takeaway is to review higher-impact uses first, check whether customer-facing AI requires disclosure, and assign someone to oversee each important AI system.

When the EU AI Act Applies to Businesses Outside Europe

The law can reach businesses outside the EU when they offer or use AI there, or when AI output created elsewhere is used in the EU. A single European customer or website visitor does not automatically make every part of the Act applicable. The answer depends on what the system does, where it or its output is used, who it affects, and the role the business plays. 

Your Role Shapes Your Responsibilities

Your responsibilities depend partly on your role. A provider develops or sells an AI system under its own name or brand. A deployer is a business that uses the system in its operations. A company may be a provider for one system and a deployer for another.

Consider a US manufacturer using a third-party recruitment platform to rank applicants for jobs in Germany. The company may be acting as a deployer, and the hiring use may receive closer scrutiny because it can affect access to employment.

A customer-service chatbot available to European users raises a different set of questions. The business may need to disclose that people are interacting with AI, but the chatbot won’t automatically trigger the same requirements as a system used to rank job applicants or make credit decisions.

What the Revised EU AI Act Timeline Means for Businesses

Businesses now have more time to prepare for some high-risk AI requirements. The approved changes to the EU AI Act timeline affect systems used in areas such as hiring, education, essential services, biometrics, law enforcement, and regulated products. Transparency rules for chatbots and certain AI-generated content follow an earlier timetable.

Date What businesses should know
August 2, 2026 Most transparency requirements take effect, including rules covering direct interaction with AI and certain AI-generated or manipulated content.
December 2, 2026 Providers of certain AI systems that generate or manipulate content and were already available before August 2, 2026, must implement machine-readable marking that helps identify AI-generated or manipulated content. New bans also apply to AI used to create non-consensual intimate content or child sexual abuse material. 
December 2, 2027 Requirements begin for certain high-risk systems used in areas such as employment, education, essential services, biometrics, and law enforcement.
August 2, 2028 Requirements begin for high-risk AI built into products already covered by EU safety rules.

Source: Council of the European Union: changes to the AI Act implementation timeline

The extra preparation time is most useful when businesses use it to map their AI systems, identify which rules may apply, and strengthen oversight where needed. 

Make AI Use Clear to Customers and Employees

Some EU AI Act rules require businesses to tell people when they’re interacting with AI or seeing certain AI-generated or manipulated content. Article 50 sets out these requirements. For a practical first check, ask: Would a reasonable person know AI is involved?

Review these areas first:

  • Chatbots and virtual assistants: Check that people are told when they are interacting with AI, ideally at the start of the conversation.
  • Deepfake images, audio, or video: Confirm that the content is clearly labeled as AI-generated or manipulated.
  • AI-generated public-interest content: Check whether the content covers news, elections, health, safety, or other public matters, and whether human review and editorial responsibility apply.
  • Emotion-recognition and biometric-categorization tools: Check what notice people receive before the system is used.
  • Systems that generate or alter content: Ask the vendor how machine-readable marking and detection are handled.

You don’t need to label every AI-assisted email, blog post, ad, or image. The requirement depends on the type of content, how it’s used, and the role your business plays. Certain public-interest content may also qualify for an exception when a person reviews it and accepts editorial responsibility.

For customer-facing AI, place the disclosure where people will see it at the start of the interaction. Don’t rely on a note buried in a privacy policy.

Document who owns each disclosure decision, and review those decisions when the tool, vendor, or business use changes.

The European Commission’s final guidelines on AI transparency requirements and the Code of Practice on Transparency of AI-Generated Content provide more detail for organizations that need it. 

How to Review AI Use Across Your Business

Map where AI is already being used

Start with a simple inventory. Marketing, customer service, HR, finance, IT, and operations may all be using AI tools that leadership hasn’t reviewed together.

For each tool, record:

  • What it does and which team uses it
  • What data it receives
  • Who may be affected by its output
  • Where it’s used
  • What human review takes place
  • Who’s responsible for it

This gives you a clear view of what’s already in use and where the biggest gaps may be.

Review higher-impact uses first

Prioritize AI that can influence important decisions about people, including hiring, credit, education, essential services, biometrics, worker management, or legal rights. These systems deserve closer review because their outputs can affect access, opportunity, and fair treatment.

Check customer-facing AI

Review chatbots, virtual assistants, synthetic media, and other AI that customers or employees interact with directly.

Check whether people are told when AI is involved, where that notice appears, what the system generates, and who reviews its output. A disclosure at the start of an interaction is clearer than a note buried in a privacy policy.

Assign ownership and review new tools early

Each important AI use should have a named business owner. That person should understand why the tool is used, what data it receives, who relies on its output, and what human oversight is in place.

Ownership doesn’t have to sit with IT. The team responsible for the business process often has the clearest view of how the tool affects customers, employees, or decisions.

Build the same checks into procurement before a new AI tool is approved. Review its purpose, data use, vendor responsibilities, human-oversight features, and geographic reach before it becomes part of daily operations.

Once you’ve mapped current AI use, the next step is to turn that information into a practical process. Our guide to building AI governance that works explains how to set clear policies, approve tools, train employees, and review AI use over time.

What Your First AI Review Should Produce

By the end of the first review, leadership should have:

  • A current list of AI tools and vendors

  • A named owner for each important AI use

  • A shortlist of systems that need deeper review

  • A record of customer-facing disclosure gaps

  • Clear rules for employee use and buying new AI tools

  • A schedule for reviewing systems when the tool, purpose, data, or vendor changes

This gives the business a clear order of work: what needs attention now, what can wait, and who owns the next step. It also helps leadership make better technology decisions, strengthen oversight, and use AI with greater confidence.

Get Help Reviewing Your AI Use

Most businesses already use more AI than leadership realizes. The first step is to map where it’s being used, what decisions it supports, and who’s responsible for it.

A WSI AI Consultant can help you review:

  • Active AI tools, vendors, and business uses

  • Customer-facing systems and data flows

  • Human oversight and employee guidance

  • Procurement controls and vendor responsibilities

  • Connections to customers, employees, or operations in the EU

You’ll leave with a prioritized action plan showing what needs attention now, what can wait, and where legal or compliance advice may be needed.

Talk with a WSI AI Consultant about reviewing your AI use, risks, and next steps.


Editor’s note: This article was reviewed on July 20, 2026. It reflects the European Commission’s final guidelines on AI transparency requirements, the final Code of Practice on Transparency of AI-Generated Content, and the EU AI Act implementation timeline available on that date. Check the EU AI Act Service Desk for current requirements.

This content provides general business information and doesn’t constitute legal advice. Confirm formal legal and compliance decisions with qualified counsel. 


FAQs — Applying the EU AI Act to Your Business

Does the EU AI Act apply to businesses outside Europe?
It can. A business outside the European Union may fall within scope when it offers or uses an AI system in the EU, or when AI output produced elsewhere is used there. The answer depends on the system’s purpose, where it is used, who it affects, and the role the business plays.
Does using one AI tool mean my business is covered by the entire EU AI Act?
No. The EU AI Act applies different requirements based on the type of AI system, how it is used, and the level of risk involved. A writing assistant, customer-service chatbot, and applicant-ranking system may each create different responsibilities.
Which AI systems should a business review first?
Start with systems that can affect employment, credit, education, essential services, biometrics, worker management, or legal rights. Customer-facing AI also deserves early attention because some systems require clear disclosures when people interact with AI or view AI-generated content.
Do businesses need to label every piece of AI-assisted content?
Not every AI-assisted email, blog post, advertisement, or image requires a label. The requirement depends on the type of content, how it is used, and whether it falls within specific transparency rules for deepfakes, public-interest content, or machine-readable identification.
What is the difference between an AI provider and an AI deployer?
A provider develops or sells an AI system under its own name or brand. A deployer uses an AI system as part of its business operations. A company may act as a provider for one system and a deployer for another.
What should an AI inventory include?
An AI inventory should record what each tool does, which team uses it, what data it receives, who may be affected by its output, where it is used, what human review takes place, and who owns it. This helps leadership identify higher-impact systems and decide where deeper review is needed.
Who should be responsible for AI oversight inside a business?
Each important AI use should have a named business owner. That person does not always need to sit in IT; the team responsible for the underlying business process may be better placed to understand how the system affects customers, employees, or decisions.
When should a business seek legal or compliance advice?
Specialist advice may be needed when AI affects hiring, credit, essential services, biometrics, regulated products, or people in the European Union. Legal counsel can help confirm how the Act applies to a specific system, business role, and use case.