Business · Roles · Risk · Deadlines
AI Act for business: which obligations and what to do
The regulation does not place the same duties on everyone. What a company must do depends on two answers: which role it holds towards the AI system, and which risk tier its use falls into. Only one obligation reaches almost anyone who uses AI at work — and it is also the first one to apply.
01First question: what is your company's role?
Most companies that “use AI” do not build it: they buy a product and put it to work. In that case the typical role is deployer. A company that develops a system, or places it on the market under its own name, is a provider. The role is not a fixed label — it can change along the way.
| Situation | First reading | What to check |
|---|---|---|
| You buy a product and use it in your business | Normally deployer | The concrete intended purpose, the provider's instructions, the quality of the data you feed in, who supervises. |
| You resell or distribute a system under your own brand | You may become a provider | Under whose name the system is placed on the market, and who carries the conformity obligations. |
| You substantially modify a high-risk system, or change its purpose | You may take on the provider role | The extent of the change, the new intended purpose, the new classification, the documentation available. |
| You build a general-purpose model into your own product | Depends on the purpose you give it | If the integration creates a system with a purpose of its own, that purpose must be classified afresh. |
The guide on providers and deployers explains the role shift, and why it is worth settling before a contract is signed rather than after.
02Second question: which risk tier does it fall into?
“We use AI” is not a classification. What counts is the intended purpose, the context the system enters and the effect of its output on people. The same tool can be irrelevant in one department and high-risk in another.
- Prohibited practices: some uses are not allowed at all, whatever safeguards you offer. Recognising them is the first filter, because no procedure cures them.
- High risk: the uses listed in the regulation, among them recruitment, worker management, and access to credit and other essential services.
- Transparency obligations: they apply when a person interacts with a machine or receives artificially generated content.
- Minimal risk: most business uses. The general rules still hold — data protection, non-discrimination, employment law — which the AI Act does not replace.
The map of risk categories lays out the four tiers with concrete examples.
03The one obligation that reaches almost everyone: competence
The regulation asks those who provide and those who use AI systems to take measures so that the staff involved have a sufficient level of AI literacy, taking into account their role, the context, and the people the system affects. It is not a certification or an off-the-shelf mandatory course: it is a proportionate measure the company must be able to show it has taken.
- Do the people using the tool know what it does, what it does not do, and where it most often gets things wrong?
- Can they recognise a plausible but false output, and do they know what to do when they find one?
- Do the people who decide to adopt a system know its limits, or did they stop at the sales pitch?
- Is there a record of what was explained, to whom, and when?
04If the system is high-risk
The regulation gives the deployer of a high-risk system duties of its own, which cannot be pushed back onto the provider. In short, and simplified:
| Use as instructed | The system must be used according to the provider's instructions. Using it for a different purpose can change role and responsibility. |
|---|---|
| Human oversight | Assigned to competent, authorised people who are genuinely able to act: time, information, and the power to stop the output. |
| Input data | Where the input data is under your control, it must be relevant and sufficiently representative for the intended purpose. |
| Monitoring and logs | Operation must be monitored over time, and the logs under your control kept for the period foreseen. |
| Informing people | Workers and affected persons must be told when a high-risk system is used on them or on decisions concerning them. |
| Incidents and risks | If a serious risk emerges, it must be reported to the provider and the authority, and use suspended. |
The detail is on the page about high-risk AI systems. For companies using AI in recruitment or in managing employment relationships, AI at work and in hiring goes into the concrete case.
05If the system talks to people or generates content
Here the obligation does not follow the risk tier but the possible deception. Whoever receives content or interacts with a system must be able to understand what they are dealing with.
- An automated assistant answering customers must make clear that it is a machine, where that is not already obvious.
- Images, audio and video depicting real people, places or events in an apparently authentic way must be labelled as artificially generated or manipulated.
- Text published to inform the public on matters of general interest, when generated by AI, must be disclosed as such.
The two reference pages are transparency obligations and deepfakes and transparency. If you use or integrate a general-purpose model, see general-purpose AI.
06When an impact assessment is required
The fundamental rights impact assessment does not apply to every company. The regulation requires it of certain deployers of high-risk systems — bodies governed by public law, private entities providing public services, and in cases tied to creditworthiness assessment and to risk assessment and pricing in life and health insurance.
Even where it is not owed, the question the FRIA asks is useful to anyone: who can be harmed by this system, how would anyone notice, and how is it put right. The page on the FRIA sets out its structure and its limits.
07The dates, in order of urgency
The regulation did not arrive all at once: the obligations are staggered, and that changes the order in which it makes sense to tackle them. Prohibitions and staff competence come first; the high-risk obligations come later, and they are the ones that take longest to prepare for.
The page on the application timeline lists the dates and what starts at each one. If you are planning, read it before deciding where to begin.
What is at stake if an obligation is missed — amounts, the SME rule, the authorities — is on AI Act penalties.
08Try it on a real case
The hard part is not reading the list of obligations: it is recognising which one applies to a concrete file, with documents that contradict each other. “The opaque tender” stages a public body that buys a system whose decisions nobody inside can explain — the supplier says it is certified, and refuses access.
09Official sources and limits
The reference text is Regulation (EU) 2024/1689 on EUR-Lex — in particular Articles 4, 25, 26, 27 and 50 — together with the European Commission FAQ. The concrete obligations change with the system, the purpose and sector-specific law.
Glossary · Risk categories · AI Act in public administration