The EU AI Act: Everything You Need to Know

Member of the elcap team working at a computer

Let’s be honest, any business worth its salt has invested in AI (artificial intelligence) in the last 3 years.

Whether it’s ChatGPT, Claude, Breeze, or something else entirely, artificial intelligence has helped businesses around the world streamline admin and simply be more productive.

However, the AI Act will come into force throughout Europe in Summer 2026.

In this guide, we’ve broken down everything you need to know to make sure you’re compliant, answering:

  • What the EU AI Act is, and when it comes into effect.

  • What the four risk levels are, with examples and associated fines.

  • If the EU AI Act apply to the UK.

  • How to ensure AI compliance going forward.

 

What is the EU AI Act, and when does it come into effect?

The EU AI Act is the EU’s flagship AI law coming into effect on 2nd August 2026. This is the first comprehensive artificial intelligence regulation of its kind in the world.

Instead of bundling all AI usage together, which is what has been done previously, it sorts uses of AI into four different risk levels:

The EU AI Act pyramid, explaining the difference between prohibited, high risk, low risk and no risk systems.

  • Prohibited risk. Things too harmful to allow, like social scoring or manipulative AI models.

  • High risk, heavily regulated. Things like CV-Screening tools or credit scoring.

  • Low risk, transparency only. Things like chatbots and AI-generated content, where you just need to label the content as AI-generated.

  • No risk. This is most of the everyday AI usage, which is largely left alone.

For most businesses, ‘low risk’ is the one that matters most. This is governed by a specific part of the Act called Article 50. This doesn’t require your AI to be ‘high risk’ to be used incorrectly, but kicks in the moment you’re using AI to communicate with people, and not telling them, whether you’re deploying an AI chat bot, or generating content, or creating media.

It’s important to note that this law affects businesses of all shapes and sizes, as the act looks at what a system does, not the size or type of a business itself.

To stay compliant, disclose AI usage and avoid a fine, you need to better understand the four tiers, and what this means for your business.

 

Before 2nd August 2026, you need to understand your business's AI usage and any possible risk. To make sure you easily understand it, we’ve created a simple checklist that breaks down which band your business falls into. Download your copy for free now.

 

The four bands of the EU AI Act explained

There are four tiers under the act. And after 2nd August 2026, ‘we didn’t know’ won’t save you from a hefty fine if you’re non-compliant.

A business’s AI usage will fall into one or multiple of these categories, depending on what the system does:

Band 1: Prohibited risk

EU AI Act Pyramid, with the top, 'Prohibited Risk' highlighted.

What is prohibited risk in the EU AI Act, and what are examples of it?

These are practices that the EU has decided are simply too harmful to allow and are banned outright, regardless of safeguards. These include but are not limited to:

  • Social scoring systems that ranks or judges people based on behaviour or characteristics, used by public or private actors. (Note: this is not to be confused with a lead scoring system.)

     

  • AI that uses manipulative or deceptive techniques to distort someone’s decision-making in a way that causes harm.

     

  • AI that exploits vulnerabilities related to age, disability, or socio-economic situation.

     

  • Emotion recognition in workplaces or educational institutions, with few medical and safety exceptions.

     

  • Real-time remote biometric identification by law enforcement in public settings

If a business is caught in this band, they will be fined up to 7% of their global annual turnover or €35 million, whichever is higher.

For most businesses, however, this tier will not be an issue.

 

Four ways your business can avoid prohibited risk

Here’s four ways you can make sure your business is nowhere near this band:

  • Audit any AI used for scoring, ranking, or profiling people, make sure it's tied to a specific, relevant purpose (like lead scoring), not a general trustworthiness judgement.

     

  • Avoid AI tools that target people's emotions, vulnerabilities, or decision-making in ways that could be seen as manipulative, even in marketing.

     

  • If you use any emotion-recognition or biometric tools in the workplace, check whether they fall under the narrow medical/safety exceptions, or remove them.

     

  • When in doubt, ask: "could this practice unfairly disadvantage someone based on who they are, not what they've done?" If yes, stop and review.

 

Band 2: High risk

the EU AI Act pyramid, with 'High Risk AI Systems' highlighted.

What are high-risk systems in the EU AI Act, and what are some practical examples?

These are systems that are allowed, but only under strict controls, because of the risk they pose to people's rights and safety. They include but are not limited to:

  • CV-screening and recruitment tools that decide who gets shortlisted for a job.

  • Credit-scoring and lending systems that affect someone's access to finance.

  • Biometric identification systems, such as facial recognition used for ID verification.

  • AI used in critical infrastructure such as energy, water, or transport networks.

Businesses providing these systems must prove the tool is safe before it goes to market and continue to prove it throughout the AI’s life through conformity assessments, documentation, and registration in an EU database.

If a business is caught being non-compliant here, they will be fined up to 3% of their global annual turnover or €15 million, whichever is higher.

For most businesses, this tier is also unlikely to apply unless you're building or using tools that fall into categories like those above.

 

How to stay compliant within the EU AI Act using high-risk tools

Depending on whether you’re a provider or a user of these systems, how you stay compliant will look a little different.

As a rule of thumb:

  • Identify whether any tool you use or provide falls into a high-risk category (hiring, credit, biometric ID, critical infrastructure).

  • If you're a provider, budget time and resources for conformity assessment, documentation, and EU database registration well before 2 August 2026.

  • If you're a deployer, assign a named, trained person responsible for oversight. Don't leave it undefined.

If you’re a business using these systems, you’ll be audited too. From 2nd August 2026, you’ll have to:

  1. Follow the provider's instructions.

     

  2. Assign a trained person to oversee the system.

     

  3. Keep clear usage logs on file, not just in your inbox.

     

  4. Be able to step in or shut the programme down if something goes wrong.

 

Unsure which band your business’s AI usage will fall under? Download your free EU AI Act compliance checklist now to understand where your gaps are, not just whether you’ve got any.

 

Band 3: Low risk

The EU AI Act Pyramid, with 'Low Risk AI Systems' highlighted.

What is defined as 'low risk' under the EU AI Act?

This is the band that's less about what your AI does and more about how honest you are with your audience, or regulators once you’re audited. It covers situations like:

  • AI that talks directly to people (chatbots, virtual assistants) must say it's AI upfront.

     

  • AI-generated content (text, image, audio, video) must be detectable as AI-generated.

     

  • Emotion recognition or biometric categorisation must be disclosed to the people it's used on.

Unlike Bands 1 and 2, this is the tier that most ordinary businesses using AI content tools or chatbots will fall into.

If a business is caught being non-compliant here, they will be fined up to 3% of their global annual turnover or €15 million, whichever is higher.

 

How to stay compliant in Band 3

Here's four ways you can make sure you're actually disclosing AI use where it's needed:

  1. Make sure any chatbot or virtual assistant tells people it's AI at the very start of the conversation.

     

  2. Label any AI-generated image, audio or video that could pass as real. There are no exceptions for this one.

     

  3. For AI-written content published to inform the public on a public interest matter, either disclose it's AI-generated or make sure it's been through genuine human review with someone accountable for the final version.

     

  4. If you’re using emotion recognition or biometric categorisation, tell the people it’s being used on.

     

However, it’s important to be honest with your audience and label content as AI-generated rather than risk non-compliance in the future.

 

Band 4: No risk

The EU AI Act pyramid, with 'No Risk' systems highlighted.

How does the EU AI Act define ‘no risk’?

This is where the majority of everyday AI use sits. These are the tools that pose little to no risk to people's rights or safety, and the EU AI Act largely leaves them alone.

Examples include but are not limited to:

  • Spam filters and email categorisation.

     

  • AI-powered recommendation engines, like "you might also like" suggestions.

     

  • AI-enabled video games and generative art tools used for entertainment.

     

  • Most everyday productivity tools with AI features built in.

There's no conformity assessment, no registration, and no oversight requirement for tools in this category, and therefore, no fine. The main obligation that still applies across the board, including here, is AI literacy, making sure the people in your business who use AI tools understand what they can and can't do.

If most of what your team uses day to day looks like the list above, take this as the reassurance it's meant to be: you're not sitting on a hidden compliance risk here.

 

How to keep your business at no risk under the EU AI Act

Here's how to make sure your business sits at band four and close the gap that could turn "no risk" into a real problem.

  • Keep a simple internal list of what AI tools are approved for use, and which devices they're approved on.

     

  • Build basic AI literacy into onboarding, even a short internal guide on what your team's AI tools can and can't do.

     

  • Revisit the list periodically; tools move between tiers as features change, so "low risk" today isn't guaranteed forever.

That said, if your company allows AI use on work devices, but hasn't extended that policy to cover personal devices, or if an administrator has explicitly restricted certain tools, that boundary must be made clear and monitored. Employees using AI on personal devices to get around a company restriction puts usage outside any oversight your business has put in place, which means nobody can vouch for what data's gone in, what's come out, or where it's ended up.

Honestly? It’s not really an EU AI Act issue at that point. It's a wider data governance and accountability gap. But it's the kind of thing that turns a low-risk tool into a serious business risk (usually without anyone noticing until something's already gone wrong.)

 

Think your business falls under no risk? The first mistake is assuming you’re compliant. Make sure your business is safe by downloading a free copy of the EU AI Act compliance checklist now.

 

The elcap team, working in the office

Does the EU AI Act apply to the UK?

Although the UK is no longer in the European Union, and therefore the act doesn’t automatically apply, your business may still be audited under the EU AI Act.

The Act follows AI output, not the postcode of where your business is registered.

This means that the Act is automatically applied based on whether your content or AI systems respectively reach an EU audience, not where your company is based.

Ask yourself:

  1. Do you have EU-based customers, clients, or website visitors?

     

  2. Do you sell into EU markets?

     

  3. Is your content, including AI assisted, published somewhere an EU audience can see it and be influenced?

If you’re a genuine UK-only business with little EU reach, you’re significantly lower risk.

But if you’ve answered yes to any of these questions, being based in the UK does not make you automatically exempt from the EU AI Act.

Does this logic sound familiar? It should.

It’s the same reach GDPR already has. So, if your business has done any hefty GDPR work in the past, you’ll recognise the shape of this immediately. As a UK company, you can’t opt out of the EU data protection law just because you’re not physically in the EU.

The same principle is applied to the EU AI Act.

However, even if your business is not affected, it’s worth playing the long game and making sure still covered.

The UK has a track record of following the EU’s lead on these kinds of regulation, the UK’s GDPR regulations being a prime example of this, as it arrived a few years after the EU’s version and looked incredibly similar.

Getting ahead of this compliance now isn’t just making sure you’re safe for the EU AI Act from 2nd August 2026, it’s about not having to scramble to retrofit everything under a deadline in a few years’ time, when the UK almost inevitably introduces its own version.

 

How to make sure you’re compliant with the EU AI Act

Now you understand what the EU AI Act is and how to stay compliant, how can you easily know where you stand?

The fastest way to check is to run through all your AI usage properly, rather than just go through all the obligations in your head.

To help you audit your business, we’ve created a free, easy-to-use compliance checklist. It’s built for a proper, repeatable self-audit that covers:

  • Your business’ exposure

  • AI touchpoints

  • Your review process

It helps you see where the gaps are in your business, not whether you’ve got any.

One more thing worth noting: regardless of which band your AI use falls into, giving false or incomplete information to a regulator during an investigation carries its own fine, up to €7.5 million or 1% of global turnover.

If you're ever contacted by a regulator, respond honestly, hand over documentation when asked, and correct your paperwork if it's wrong rather than defending it. It's a fine that's entirely avoidable just by being straightforward.

To avoid an unnecessary fine, it’s vital to understand where you are now, so you can improve usage and stay ahead of the EU AI Act, or whatever comes next.

 

Free download: EU AI Act Compliance Checklist

Most agencies and marketing teams are closer to compliance than they think, but "probably fine" isn't the same as knowing.

Our free checklist walks you through your exposure, your AI touchpoints, your disclosure practices, and your review process, so you know exactly where you stand before it becomes a live issue.

Download your copy today.

Back to Insights

Related posts