NO AI ACT.

Business · Roles · Risk · Deadlines

AI Act for business: which obligations and what to do

The regulation does not place the same duties on everyone. What a company must do depends on two answers: which role it holds towards the AI system, and which risk tier its use falls into. Only one obligation reaches almost anyone who uses AI at work — and it is also the first one to apply.

01First question: what is your company's role?

Most companies that “use AI” do not build it: they buy a product and put it to work. In that case the typical role is deployer. A company that develops a system, or places it on the market under its own name, is a provider. The role is not a fixed label — it can change along the way.

The role follows what you do to the system, not what you call yourself
SituationFirst readingWhat to check
You buy a product and use it in your businessNormally deployerThe concrete intended purpose, the provider's instructions, the quality of the data you feed in, who supervises.
You resell or distribute a system under your own brandYou may become a providerUnder whose name the system is placed on the market, and who carries the conformity obligations.
You substantially modify a high-risk system, or change its purposeYou may take on the provider roleThe extent of the change, the new intended purpose, the new classification, the documentation available.
You build a general-purpose model into your own productDepends on the purpose you give itIf the integration creates a system with a purpose of its own, that purpose must be classified afresh.

The guide on providers and deployers explains the role shift, and why it is worth settling before a contract is signed rather than after.

02Second question: which risk tier does it fall into?

“We use AI” is not a classification. What counts is the intended purpose, the context the system enters and the effect of its output on people. The same tool can be irrelevant in one department and high-risk in another.

  • Prohibited practices: some uses are not allowed at all, whatever safeguards you offer. Recognising them is the first filter, because no procedure cures them.
  • High risk: the uses listed in the regulation, among them recruitment, worker management, and access to credit and other essential services.
  • Transparency obligations: they apply when a person interacts with a machine or receives artificially generated content.
  • Minimal risk: most business uses. The general rules still hold — data protection, non-discrimination, employment law — which the AI Act does not replace.

The map of risk categories lays out the four tiers with concrete examples.

03The one obligation that reaches almost everyone: competence

The regulation asks those who provide and those who use AI systems to take measures so that the staff involved have a sufficient level of AI literacy, taking into account their role, the context, and the people the system affects. It is not a certification or an off-the-shelf mandatory course: it is a proportionate measure the company must be able to show it has taken.

  • Do the people using the tool know what it does, what it does not do, and where it most often gets things wrong?
  • Can they recognise a plausible but false output, and do they know what to do when they find one?
  • Do the people who decide to adopt a system know its limits, or did they stop at the sales pitch?
  • Is there a record of what was explained, to whom, and when?
Why it matters. It is the obligation that arrives first in the calendar, and the one no supplier can discharge on your behalf: it concerns your own people. The page on AI literacy explains what it means in practice.

04If the system is high-risk

The regulation gives the deployer of a high-risk system duties of its own, which cannot be pushed back onto the provider. In short, and simplified:

Typical obligations for a company using a high-risk system
Use as instructedThe system must be used according to the provider's instructions. Using it for a different purpose can change role and responsibility.
Human oversightAssigned to competent, authorised people who are genuinely able to act: time, information, and the power to stop the output.
Input dataWhere the input data is under your control, it must be relevant and sufficiently representative for the intended purpose.
Monitoring and logsOperation must be monitored over time, and the logs under your control kept for the period foreseen.
Informing peopleWorkers and affected persons must be told when a high-risk system is used on them or on decisions concerning them.
Incidents and risksIf a serious risk emerges, it must be reported to the provider and the authority, and use suspended.

The detail is on the page about high-risk AI systems. For companies using AI in recruitment or in managing employment relationships, AI at work and in hiring goes into the concrete case.

05If the system talks to people or generates content

Here the obligation does not follow the risk tier but the possible deception. Whoever receives content or interacts with a system must be able to understand what they are dealing with.

  • An automated assistant answering customers must make clear that it is a machine, where that is not already obvious.
  • Images, audio and video depicting real people, places or events in an apparently authentic way must be labelled as artificially generated or manipulated.
  • Text published to inform the public on matters of general interest, when generated by AI, must be disclosed as such.

The two reference pages are transparency obligations and deepfakes and transparency. If you use or integrate a general-purpose model, see general-purpose AI.

06When an impact assessment is required

The fundamental rights impact assessment does not apply to every company. The regulation requires it of certain deployers of high-risk systems — bodies governed by public law, private entities providing public services, and in cases tied to creditworthiness assessment and to risk assessment and pricing in life and health insurance.

Even where it is not owed, the question the FRIA asks is useful to anyone: who can be harmed by this system, how would anyone notice, and how is it put right. The page on the FRIA sets out its structure and its limits.

07The dates, in order of urgency

The regulation did not arrive all at once: the obligations are staggered, and that changes the order in which it makes sense to tackle them. Prohibitions and staff competence come first; the high-risk obligations come later, and they are the ones that take longest to prepare for.

The page on the application timeline lists the dates and what starts at each one. If you are planning, read it before deciding where to begin.

What is at stake if an obligation is missed — amounts, the SME rule, the authorities — is on AI Act penalties.

08Try it on a real case

The hard part is not reading the list of obligations: it is recognising which one applies to a concrete file, with documents that contradict each other. “The opaque tender” stages a public body that buys a system whose decisions nobody inside can explain — the supplier says it is certified, and refuses access.

09Official sources and limits

The reference text is Regulation (EU) 2024/1689 on EUR-Lex — in particular Articles 4, 25, 26, 27 and 50 — together with the European Commission FAQ. The concrete obligations change with the system, the purpose and sector-specific law.

Simplified educational version. This page describes the structure of the regulation for teaching purposes. It is not legal advice, a conformity assessment or a compliance checklist: for those you need a professional looking at your case.

Glossary · Risk categories · AI Act in public administration