Business Consulting

EU AI Act for Businesses: What Leaders Need to Know

The EU AI Act for businesses is now an operational issue, not a future policy debate. Most of the Regulation has applied since 2 August 2026, while some high-risk obligations follow later. What your organisation must do depends on its role, the AI system, its intended purpose and its risk classification.

Regulatory information checked: 1 September 2026. This article provides general information, not legal advice. Obtain specialist legal advice for decisions about your organisation’s specific obligations.

Executive summary: five points for business leaders

  • “Using AI” is not one legal category. An organisation may be a provider, deployer, importer or distributor, and may hold different roles for different systems.
  • Risk depends on purpose and context. A recruitment system, customer-service chatbot and internal writing assistant can attract very different obligations.
  • Several duties already apply. Prohibited-practice rules, AI literacy, general-purpose AI obligations and most of the Act are in application.
  • High-risk deadlines were extended in July 2026. Annex III rules generally apply from 2 December 2027; rules for high-risk AI embedded in regulated products generally apply from 2 August 2028.
  • Governance must reach everyday work. An inventory, policy, software platform or generic course can help, but none alone resolves role, risk, oversight, documentation and operational-accountability questions.

What is the EU AI Act?

The EU AI Act is Regulation (EU) 2024/1689, as amended. It establishes harmonised rules for placing AI on the EU market and for developing and using AI in the EU. Its stated objectives combine better functioning of the internal market with human-centric, trustworthy AI and strong protection for health, safety and fundamental rights.

The law prohibits specified unacceptable practices, regulates high-risk systems, creates transparency duties and places obligations on providers of general-purpose AI models. Minimal-risk uses may escape additional AI Act rules, although the GDPR, equality, consumer and employment law can still apply.

For Irish organisations, the AI Office of Ireland coordinates implementation alongside sectoral authorities. Ireland’s Regulation of Artificial Intelligence Act 2026 establishes the domestic enforcement architecture.

Which organisations may be affected?

The Act can affect organisations that develop, commission, sell, import, distribute or use AI systems in the EU. It can also reach some providers and deployers outside the EU where system output is used in the EU.

A company does not fall outside the Act simply because it did not build a model. A business using AI to shortlist candidates, route customer requests, monitor staff or automate decisions may be a deployer with relevant duties. Substantially modifying a system, changing its intended purpose or marketing it under the company’s name may create provider responsibilities.

Start with four facts for every use case: what the system is, what it does, where its output is used and which legal role the organisation holds.

Provider, deployer, importer and distributor in plain English

RolePlain-English meaningBusiness example
ProviderDevelops an AI system or general-purpose AI model—or has one developed—and places it on the market or puts it into service under its own name or trademark.A software company sells an AI recruitment product under its brand.
DeployerUses an AI system under its authority in a professional activity. Personal, non-professional use is treated differently.An employer uses a third-party tool to rank job applications.
ImporterAn EU-established party that places on the market an AI system bearing the name or trademark of a provider outside the EU.An Irish distributor introduces a US provider’s AI product to the EU market.
DistributorMakes an AI system available in the EU supply chain without being the provider or importer.A technology reseller supplies an established provider’s AI product to customers.

These are legal classifications, not job titles. One organisation can hold different roles for different systems, so classify each system separately.

How the AI Act’s risk structure works

Prohibited AI practices

Prohibited practices are uses the law considers incompatible with EU values and fundamental rights. Eight original prohibitions have applied since 2 February 2025. They include specified forms of harmful manipulation, social scoring, untargeted scraping to build facial-recognition databases and emotion recognition in workplaces or education, subject to the precise statutory wording and exceptions. The 2026 AI Omnibus added a ninth prohibition covering AI systems that generate non-consensual sexually explicit or intimate content or child sexual-abuse material; that prohibition applies from December 2026.

The Commission’s guidelines on prohibited practices provide practical examples, but guidance does not replace the enacted text.

High-risk AI systems

High-risk classification is not a label for every powerful or sensitive-looking tool. It covers specified systems connected to regulated products in Annex I and specified use cases in Annex III, subject to statutory conditions and exceptions.

Annex III includes certain uses in biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and justice. AI used to filter applications or evaluate candidates may be high-risk; a tool that merely improves a job advertisement’s grammar has a different purpose and risk profile.

Providers face requirements covering risk management, data governance, documentation, records, transparency, oversight, accuracy, robustness and cybersecurity. Deployers have separate duties. The Commission published draft, non-binding classification guidelines in 2026; check whether a final version has since been adopted.

Transparency obligations

Article 50 transparency duties have applied since 2 August 2026. People may need to be told they are interacting with AI; synthetic outputs may need machine-readable marking; and deepfakes or certain public-interest text may require disclosure.

People should generally know when a customer-service chatbot is AI unless this is obvious. The duties are mandatory; the Commission’s Code of Practice on Transparency of AI-generated Content is a voluntary implementation tool.

Minimal- or no-risk systems

The Commission says most EU AI systems are minimal- or no-risk, including spam filters and AI-enabled games. The Act generally adds no mandatory rules, but data protection, confidentiality, intellectual property, discrimination, security and contracts still matter.

General-purpose AI models

General-purpose AI models perform many tasks and often underpin downstream systems. Model-level duties fall mainly on GPAI model providers, not automatically on every company using a chatbot built on one. Applicable since 2 August 2025, they cover documentation, downstream information and copyright policy; additional duties apply to models with systemic risk.

The voluntary GPAI Code of Practice offers providers a recognised way to demonstrate how they address relevant obligations; it is not a blanket compliance guarantee.

EU AI Act implementation timeline

DateLegal positionExecutive implication
1 August 2024The AI Act entered into force.Organisations began preparing for phased application.
2 February 2025The original prohibited-practice rules and AI literacy obligations began applying.Check for prohibited uses and support context-appropriate AI literacy.
2 August 2025Governance rules and GPAI-provider obligations began applying.Model providers and actors in their value chains needed to address applicable duties.
27 July 2026Regulation (EU) 2026/1744—the AI Omnibus—entered into force.Use the amended law and revised deadlines, not an older checklist.
2 August 2026Most provisions and Article 50 transparency duties became applicable; EU and national enforcement structures assumed their roles.AI governance is now an active operational responsibility.
December 2026The new prohibition concerning non-consensual intimate content and child sexual-abuse material begins applying.Relevant product and content controls must reflect the added prohibition.
2 December 2027Rules for Annex III high-risk use cases apply under the amended timeline.Employment, education and other listed uses need a readiness plan well before this date.
2 August 2028Rules for high-risk AI embedded in Annex I regulated products apply.Product manufacturers and supply-chain partners should align AI and product-compliance work.

What AI literacy means in practice

AI literacy is the knowledge and understanding needed to make informed use of AI, considering the people involved, the organisation’s role, the system’s risk and the context of use. Following the 2026 amendment, Article 4 still requires providers and deployers to support AI literacy, but it does not mandate one universal course or guarantee of a particular individual level.

A practical programme should be role-based. Employees using content tools need to understand hallucination, confidentiality and review. Managers need to recognise automation bias and escalation triggers. HR, technical and governance teams require deeper knowledge suited to their responsibilities.

The Commission’s AI literacy Q&A says Article 4 requires neither a certificate nor a specific governance structure. Internal records are sensible evidence. A generic course may contribute, but context and behaviour matter.

Human oversight, documentation and accountability

Human oversight is not achieved by placing an approval button after an automated decision. The responsible person must have enough competence, authority, information and time to understand limitations, detect anomalies, avoid over-reliance and intervene where appropriate.

In recruitment, this may mean documenting purpose, testing how ranking affects groups, defining when a recruiter must challenge an output and retaining evidence of review. In customer service, it may mean human escalation when confidence is low or consequences are significant.

Documentation should be proportionate. An inventory is a starting point, not an end state. Leaders also need ownership, authorised purposes, decision boundaries, monitoring and processes for change and incidents.

Five questions the executive team should ask now

  1. Where is AI actually being used? Include approved tools, embedded features, pilots and unofficial employee use.
  2. What role do we hold for each system? Do not assume the organisation is always only a customer or deployer.
  3. What purpose and people are affected? Recruitment, access to services and employee monitoring deserve different scrutiny from internal drafting.
  4. What is already legally applicable? Check prohibited practices, AI literacy, transparency, GPAI and any sector-specific duties against current sources.
  5. Who owns safe operation and evidence? Assign decisions, human oversight, supplier review, monitoring, escalation and periodic reassessment.

For the implementation sequence, use Dadakai’s EU AI Act compliance roadmap.

Responsible AI can support adoption and innovation

Governance should separate useful experimentation from uncontrolled risk. Approved uses, reliable information, proportionate review and visible accountability show employees where AI helps and where judgement must remain human.

This matters commercially as well as legally. Understandable purposes, limitations and escalation paths support trust, while better evidence helps leaders stop weak use cases before they scale.

Where consultancy or training may help

Specialist support can help an organisation map AI use, translate legal roles into operational ownership and build role-specific learning. Legal counsel should determine legal interpretation where required; governance, process and training specialists can help turn advice into working routines.

Dadakai can help organisations connect responsible AI with workflow improvement, practical governance, role-based learning and internal capability building. Read how Dadakai supports AI compliance consulting and training. Dadakai does not certify or guarantee legal compliance.

Frequently asked questions

Does the EU AI Act apply to every business using ChatGPT or another AI assistant?

The Act can apply to providers and deployers of AI systems, but obligations vary by role, system, purpose and risk. Routine use of a writing assistant is not automatically high-risk, although AI literacy and other laws may still matter.

Is every recruitment AI system high-risk?

Certain AI used to recruit or select people, filter applications or evaluate candidates is listed as high-risk, subject to the Act’s conditions and exceptions. Classification requires examination of the actual purpose and operation.

Is AI literacy training legally required?

Providers and deployers must support AI literacy under amended Article 4. The law does not prescribe one universal course or certificate; measures should reflect people’s roles, knowledge, context and the systems’ risks.

Does buying compliance software make an organisation compliant?

No. Software can support discovery, records and monitoring, but accountability, role classification, risk decisions, human oversight, operational controls and legal interpretation still require organisational action.

Who enforces the EU AI Act in Ireland?

The AI Office of Ireland coordinates implementation, while designated national competent authorities oversee relevant sectors and activities. The European AI Office has particular responsibilities for general-purpose AI models.

Move from awareness to proportionate action

The Act does not treat every AI use as high-risk. Organisations should understand their systems, roles and regulated uses, support AI literacy and create meaningful accountability around AI-enabled work.

Begin with evidence, not fear: identify the systems, purposes, people and decisions involved. Then focus specialist effort where consequences and obligations are greatest. If your organisation needs help turning regulatory expectations into practical governance and capable everyday use, Dadakai can support an initial conversation about the right next step.

What’s the Opportunity You’re Seeing?

Bring us a challenge, an idea or simply a question. We’ll bring an experienced perspective and explore where it could lead.

Book an Intro Call ↓

Have a quick question first? Send us a message

No hard sell. No pressure. No mailing list. No relentless follow-up.

Official sources and further reading