The EU AI Act for business: find your role, find your risk
Your obligations depend on who you are in the AI supply chain and what your system does.
Background
The EU AI Act organises obligations around two variables: the role a company plays in the AI supply chain and the risk level of the system it builds or deploys. Getting both right is the foundation of any compliance programme.
Three key points
1. Know your role. Providers develop or place AI systems on the market. Deployers use them in their own products or services. Providers of general-purpose AI models have separate obligations. A company can be both a provider and a deployer at different points in its operations, and the obligations that follow from each role are different.
2. Know your risk level. A short list of AI uses is banned outright. High-risk systems — in employment, education, credit, essential services and law enforcement — face the strictest requirements: conformity assessments, risk management systems, human oversight, documentation and registration in a public EU database. The Omnibus extended SME-style simplifications to small mid-cap companies. Most AI carries no additional obligations.
3. Know the penalties. Banned practices can attract fines of up to 35 million euros or 7 percent of global turnover. Most other violations carry penalties of up to 15 million euros or 3 percent of turnover. SMEs pay whichever is lower.
Why this matters
High-risk compliance deadlines start in December 2027, which sounds distant. Conformity assessments, documentation and supply chain reviews take time. The inventory and role classification need to happen well before the deadline, and the Commission's AI Act Service Desk offers a Compliance Checker to help.
Sources: EU AI Act, EUR-Lex; Commission AI Act Service Desk; EU AI Act Compliance Checker.