Back to Insights

    Insights · 5 min read ·

    The EU AI Act – what businesses need to know

    The EU AI Act is the world's first comprehensive law on artificial intelligence. It concerns not only those who build AI, but also companies that use it. For most businesses it's worth understanding the main points – even if the impact is smaller than the headlines suggest.

    A risk-based regulation

    The law divides AI use into levels by risk. Some applications are banned, one category is classed as high risk with strict requirements, some fall under lighter transparency rules, and the great majority sit under minimal risk with few or no special rules.

    The logic is simple: the greater the potential impact on people, the stricter the requirements.

    It helps to picture the four tiers with everyday examples. At the top sits the small set of uses that are simply not allowed. Think of systems that score and rank people by their general behaviour to grant or deny everyday services, or that try to read emotions in a workplace to judge staff. Most companies will never go near this tier, but it's worth knowing it exists so you can recognise it if a vendor's proposal starts drifting in that direction.

    High risk is the tier that carries real weight. It covers AI used in decisions that materially affect someone's life or rights – sifting job applications, setting credit terms, or making calls that touch on health, education or access to essential services. Use here is allowed, but it comes with obligations: keeping humans in the loop, documenting how the system works, watching its accuracy, and being able to explain its decisions.

    Limited risk is mostly about transparency. If you run a chatbot that handles customer questions, people should be able to tell they're talking to a machine. If you publish images, audio or video that are AI-generated or heavily edited, that should be clear too. The requirement is honesty about what people are looking at, not a heavy compliance burden.

    Minimal risk is where most day-to-day business use lands. Drafting a first version of a text, summarising a long document, tidying up a spreadsheet or generating ideas for a campaign carry few or no special rules. The same tool can sit in different tiers depending on what you do with it, which is why it pays to look at the use case rather than the brand name on the software.

    What it means for ordinary use

    For most companies using AI for productivity, analysis or go-to-market, the requirements are modest. They mainly concern transparency – being clear about when content is AI-generated and when someone is interacting with an AI system.

    It's use in areas such as recruitment, credit assessment and the like that may be classed as high risk and therefore carry heavier requirements for documentation and control.

    In practice this means the honest, visible step matters more than the paperwork. Label AI-generated content where a reader might otherwise assume a person made it. Tell customers when a conversation is handled by an assistant rather than a colleague. Keep a short note of which tools you use and for what. None of this slows down a marketing, sales or analysis team in any meaningful way.

    The line to watch is when a tool starts making or strongly shaping a decision about a specific person – who gets hired, who gets a loan, who gets prioritised. That's when the lighter transparency expectations give way to the heavier high-risk obligations, and when it's worth pausing to check where you stand before you roll something out.

    How to take stock of your AI use

    A simple way to get an overview is to work through the following for each place AI shows up:

    • Where AI is used – list every tool and workflow, from the obvious assistants to the AI features quietly built into software you already pay for.
    • Who is affected – note whether a use touches customers, candidates, employees or only internal work, since the more it affects people, the more attention it deserves.
    • What data it touches – record whether personal data, customer information or sensitive details flow into the tool, and where that data ends up.
    • Whether it is disclosed – check that people can tell when they're dealing with AI or AI-generated content, and add a clear note where they can't.
    • Which risk tier it likely falls under – place each use in minimal, limited, high or banned, using the decision it influences as your guide rather than the technology itself.
    • Who owns it internally – name a person responsible for each tool, so questions about accuracy, updates and disclosure have a clear home.

    The timeline and how to prepare

    The rules take effect in stages: the banned applications are already in force and the rules for general-purpose models are in place. In June 2026 the EU adopted an amending package – the Digital Omnibus on AI – that adjusted the timeline for the heavier requirements. Rules for Annex III systems (recruitment, credit, education and so on) apply from 2 December 2027, and for Annex I systems (medical devices, machinery) from 2 August 2028.

    A sensible first step is to take stock of where you actually use AI, assess the risk level for each case, and document it. Most of it is easy to handle if you start in time.

    The phased timeline is good news, not a deadline to dread. The August 2026 deadline that some companies had been preparing for no longer exists. The extra runway to December 2027 is an opportunity to build sound governance habits without a scramble, not a reason to put off getting your AI use in order.

    Preparing is mostly a matter of habit. Keep the inventory above up to date as you adopt new tools, fold a quick risk check into how you evaluate any new system, and write down the few decisions that matter. Companies that treat this as light, ongoing housekeeping will find the later milestones are a formality rather than a project.

    This is an overview, not legal advice – but it gives a picture of what you should keep track of.

    If you'd like a clearer view of where AI sits in your business and which risk levels apply, we're happy to help. We can map your current use, sort it into the right tiers, and leave you with a simple, documented picture to build on. Get in touch with us at Nodal and we'll take it from there.

    Want to know more?

    Get in touch and we'll have an open conversation about what fits you best.

    Contact us