EU AI ACT · BUSINESS

EU AI Act for business: where to start without making everything complicated

The EU AI Act has already entered into force, but that does not mean every obligation applies at the same time or that every company must start by creating a huge compliance programme.

For most organisations, the practical starting point is much simpler: understand which AI systems they use, what those systems do and what role the organisation plays in relation to them.

The aim is not to solve everything in one week. It is to create enough order to make sensible decisions.

What does the EU AI Act mean for a business?

The Regulation follows a risk-based approach. Different systems and uses may trigger different obligations, while some practices are prohibited and some systems are subject mainly to transparency requirements.

The relevant question is not simply whether a company uses AI. It is what the system does, where it is used, who provides or deploys it and how it may affect people or decisions.

First step: know which AI systems the organisation uses

A company cannot classify or govern systems it has not identified. An initial inventory should include tools developed internally, systems purchased from providers, AI embedded in other software, pilot projects and relevant informal uses by teams.

The first version does not need dozens of fields. Record the system, its purpose, owner, provider, data, affected people and role in decision-making. That is enough to begin prioritising.

Provider or deployer: what role does your business play?

Obligations depend partly on the organisation’s role. A provider develops an AI system or has it developed and places it on the market or puts it into service under its name. A deployer uses an AI system under its authority, except for personal non-professional activity.

Many companies will mainly be deployers, but roles can change when a system is substantially modified, rebranded or developed for others. The answer should be documented rather than assumed.

For a more operational review, see which EU AI Act obligations a business using AI should check in practice.

How to classify AI systems under the AI Act

A practical order is to check prohibited practices first, then potential high-risk systems under Article 6 and Annexes I and III, then transparency obligations and, finally, other governance or contractual needs.

Classification must be based on the actual intended purpose and use of the system, not only on a supplier’s marketing description.

Prohibited practices: what should we check first?

Some AI practices are prohibited because the Regulation considers their risk unacceptable. A company should check early whether any current or planned use could fall within Article 5.

This review must be specific. Broad labels such as ‘chatbot’ or ‘analytics’ are not enough to determine whether a practice is prohibited.

High-risk AI systems: when closer attention is needed

High-risk systems may arise because they are safety components of regulated products or because they perform sensitive functions listed in Annex III, including certain uses in employment, education, essential services and law enforcement.

Being connected to an Annex III area does not always end the analysis. The function, influence on decisions, possible Article 6(3) exceptions and any profiling of natural persons must also be checked.

Roadmap for starting to manage EU AI Act compliance in a business

Transparency and AI literacy: obligations that already matter

Not every relevant obligation is limited to high-risk systems. Organisations should review transparency duties for certain systems and ensure an appropriate level of AI literacy among staff and others dealing with AI on their behalf.

Training should relate to people’s roles, the systems they use and the risks they may encounter. A generic presentation is not always enough.

A straightforward route to start complying

A manageable first route is to create the inventory, assign owners, describe intended uses, perform an initial classification, identify applicable obligations, prioritise higher-impact systems and preserve the evidence behind each decision.

This turns the AI Act from an abstract legal text into a set of specific actions connected to real systems.

Common mistakes when approaching compliance

Frequent mistakes include starting with policies before knowing which systems exist, relying entirely on supplier statements, treating all AI in the same way, ignoring informal use, confusing technology with risk and failing to record the reasoning behind decisions.

Another mistake is waiting for every detail to be perfect. A controlled first version that can be improved is usually more useful than an ambitious programme that never becomes operational.

What should a business have after this first review?

After the first phase, the organisation should have a usable inventory, identified owners, an initial classification, a list of priority systems, a view of applicable obligations and a record of the information and decisions used.

It will not mean that all compliance work is complete. It will mean the company finally has a reliable starting point.

Which AI Act obligations already apply in 2026?

The AI Act applies in stages. Prohibited practices and AI literacy provisions began applying before the full framework, while other requirements follow the Regulation’s timetable.

Because dates and guidance may evolve, organisations should keep their implementation plan under review and verify the rules applicable to each system and role at the relevant time.

Where should your business begin?

Begin with visibility. Identify the systems, their uses and their owners before producing large volumes of documentation.

Start the Céntrika assessment →
Use the Céntrika assessment to obtain an initial view of your organisation’s AI governance, risk and compliance.

The assessment provides initial guidance and does not replace a specific legal or technical evaluation.

You may also be interested in

Is your AI system high-risk? A straightforward way to start checking AI systems inventory: the starting point many businesses overlook ISO/IEC 42001: what it is and how to start implementing it in an organisation