AI Act Hub · scope and applicability
Does the EU AI Act apply to my business?
The short answer is: it may. The Act can cover the way a business uses AI, not just where the business is based. Here is a practical way to understand the starting point without needing a law degree.
The one-sentence version
The GDPR is mainly concerned with personal data. The AI Act is concerned with certain uses of AI, including systems that make or influence decisions about people and systems that generate content people see.
That does not mean every use of AI creates the same obligations. The first job is to identify what you use and how you use it.
Two roles, both regulated
The Act distinguishes between providers and deployers.
- Providers place AI systems on the market. This can include software companies and agencies that build systems for clients.
- Deployers use AI systems in their own operations. You may be a deployer if you run a chatbot, use AI to screen CVs or automate a decision about customers or staff.
One arrangement can involve both roles. An agency may be the provider of a chatbot, while your business is the deployer using it on your website. Buying a system from a vendor does not automatically remove your responsibilities.
You do not need an EU office to be affected
The Act can reach businesses outside the EU when the outputs of their AI systems are used by people in the EU. In broad terms:
- A UK business serving EU customers may need to consider both UK requirements and the EU regime.
- A US business may be in scope when people in the EU are affected by its AI, particularly in areas such as healthcare, finance, HR, critical infrastructure or education.
- A business in the DACH region is directly within the EU framework and should plan for the relevant national enforcement arrangements.
The exact answer depends on the system, the role your business plays and the people affected.
The timeline
| Date | Position to check |
|---|---|
| 1 August 2024 | The Act entered into force. |
| 2 February 2025 | Prohibited practices and the AI-literacy provisions began to apply. |
| 2 August 2025 | Governance and general-purpose AI provisions began to apply. |
| August 2026 | Transparency provisions for chatbots and AI-generated content are scheduled to apply. Check the current official guidance for the exact date and any transitional arrangements. |
| 2 December 2027 | The main obligations for high-risk AI systems are scheduled to apply from this date, following the agreed delay. Check the current official guidance for the final position. |
| 2 August 2028 | High-risk AI embedded in regulated products is scheduled to follow by this date. |
The important point is that a later deadline does not remove the preparation work. Inventory, classification, documentation and oversight take time to put in place.
What it can cost to ignore
The Act provides for maximum penalties of up to €40 million or 7% of worldwide annual turnover for certain prohibited practices, with lower bands for other breaches. Maximum figures are ceilings, not forecasts: the practical point is that the obligations are worth understanding before an incident, complaint or tender asks you to show your position.
A 60-second self-check
You are likely to need a closer look if any of these apply:
- You use AI to screen applicants or evaluate staff.
- You use AI in credit, pricing or access-to-service decisions about people.
- You run a customer-facing chatbot.
- You publish AI-generated content.
- People in the EU interact with the outputs.
This guide is a readiness overview, not legal advice. Where formal legal sign-off is needed, we work with partner law firms in the UK and Germany.