Skip to content
01 / Compliance & Governance

EU AI Act compliance for companies that already use AI

The rules apply in stages, and several of them already bind any company that uses chatbots, AI assistants, automated screening or AI-generated content in the European Union. We turn the obligations into working systems and a paper trail, together with your legal advisers where a legal interpretation is required.

  • Chatbots and voice agents must say that they are AI
  • Staff who work with AI need AI literacy measures
  • Fines reach 35 million EUR or 7% of worldwide turnover
How we work

From inventory to living compliance

01Inventory and classification
02Controls built into the systems
03Living compliance

02Adoption and readiness in numbers

Adoption keeps rising; readiness lags behind

AI use in European companies rises every year. Readiness lags: in the 2026 assessments of a European compliance advisory firm, most of the companies assessed had no AI inventory and no compliance owner. Each figure below names its source and its scope.

1 in 5
EU enterprises used AI in 2025
20% of enterprises with 10 or more employees, up from 13.5% in 2024, and 55% among large enterprises. Source: Eurostat, December 2025.
83%
of assessed companies had no inventory of their AI systems
Without an inventory nobody can say which rules apply. Source: Vision Compliance, 2026 EU AI Act Readiness Analysis, based on the firm's client assessments across eight industries, not a representative survey.
74%
of assessed companies had nobody in charge of AI compliance
In the same assessments, 78% had taken no meaningful compliance step. No owner, no documentation, no answer when a client or an authority asks.
7%
of worldwide turnover, or 35 million EUR
Maximum fine for prohibited practices. Most other breaches: up to 15 million EUR or 3%. SMEs and small mid-caps pay whichever amount is lower. Source: Article 99 of the AI Act.

03The first question

Are you a provider or a deployer?

The Act assigns most duties by role, not by company size. Most of our clients are deployers, and some become providers without noticing.

Deployer: you use AI under your own authority

A chatbot on your website, an AI receptionist on your phone line, a screening tool in recruitment, AI features inside your CRM. You must use the system as instructed, make sure people know when they deal with AI, train the staff who operate it, keep the logs the system produces and assign human oversight to anything high-risk.

Provider: you build it or put your name on it

You develop an AI system, or you sell, rebrand or substantially modify one, including a fine-tuned model behind your own product. Providers carry the design duties: risk management, technical documentation, machine-readable marking of generated content, and conformity assessment for high-risk systems.

When we build AI features for you, the documentation states which role you hold for each system, so the question is answered before anyone asks it.

04What the law asks of you

The obligations most companies meet first

Not every rule applies to every system. These are the ones that reach a typical company using AI in sales, service, marketing or HR, with their current status.

01

AI literacy for your staff

Article 4. You must take measures so that everyone who operates or relies on an AI system on your behalf has a sufficient level of AI literacy: what the system does, where it fails and when to step in. Since the Digital Omnibus this is a duty of effort, judged on the measures you take: role-based training, written instructions, a named contact. Keep records of the training; they are your evidence.

Applies now
02

Prohibited practices

Article 5. Ten practices are banned outright, among them manipulative or deceptive techniques that cause harm, exploiting vulnerable groups, social scoring, emotion recognition in the workplace and in schools, and untargeted scraping of facial images. Two bans on generating non-consensual intimate content and child abuse material were added by the Digital Omnibus and apply from 2 December 2026.

Applies nowTwo new bans from 2 December 2026
03

Tell people they are talking to AI

Article 50(1). Chatbots, voice agents and avatars must make clear at the first interaction that they are AI, unless it is obvious to a reasonably attentive person. The design duty sits with the provider; as the deployer you must run the system so that the disclosure actually reaches your customers, and if you rebrand or substantially modify the tool, the provider duty becomes yours. A discreet line in the footer is not enough: the disclosure has to be clear, distinguishable and accessible.

Applies now
04

Mark and label generated content

Article 50(2) and 50(4). Providers must give generated text, images, audio and video a machine-readable mark, and deployers must visibly label deepfakes and AI-written text published on matters of public interest without human review; artistic works and text under editorial responsibility have their own exceptions. Systems that were already on the market get until 2 December 2026 for the machine-readable marking.

Applies now
05

Emotion recognition and biometrics

Article 50(3) and Article 5. If a system reads emotions or sorts people by biometric traits, the people concerned must be informed and their personal data handled under GDPR. In the workplace and in education, emotion recognition is banned altogether, except for medical or safety reasons.

Applies now
06

Human oversight of high-risk systems

Articles 14 and 26. For high-risk uses such as recruitment and HR decisions, credit scoring, insurance pricing, education and access to essential services, a competent and trained person must be able to understand the output, monitor it, and override or stop the system. Deployers keep the logs for at least six months, follow the provider's instructions and inform workers before use. The Digital Omnibus set these duties for 2 December 2027 for stand-alone systems and 2 August 2028 for AI built into regulated products; the preparation takes most of that time.

From 2 December 2027
07

Where your data lives

The AI Act does not prescribe a hosting location. GDPR restricts moving personal data outside the EU, and prompts, transcripts and CRM records in sales, service and HR almost always contain personal data. EU-hosted models and storage, a processing agreement that rules out training on your data, and a data protection impact assessment where the risk warrants it, are the controls we recommend: they avoid transfer assessments for that data and answer the questions that enterprise clients and tenders ask first.

Applies now
08

Records that prove it

An inventory of every AI system, including the ones inside your SaaS tools, with its role and risk class, instructions of use, training records, logs, incident notes and the assessments you performed. When a client, an auditor or the market surveillance authority asks, the answer is a document, not a meeting.

Applies now

05How we work

From inventory to living compliance

We are engineers, not a law firm. We build the controls into your systems and produce the evidence; where a legal interpretation is needed we work with your legal advisers.

01 / Weeks 1 to 2

Inventory and classification

We list every AI system you use or sell, including the AI features inside your CRM, marketing and HR tools, decide the role you hold for each one, assign the risk class and map the articles that apply. You receive a gap report and a prioritised plan.

02 / Weeks 3 to 8

Controls built into the systems

AI disclosure in chat, voice and email. Labels and marking for generated content. Human approval steps and a stop switch in automated workflows. Logging with retention rules. EU hosting and processing agreements. Instructions of use and technical documentation. AI literacy training per role.

03 / Ongoing

Living compliance

A compliance dashboard that shows the status per system, an incident procedure, a regulatory watch for guidelines, standards and delegated acts, quarterly reviews, board-level reporting and training for new staff.

06Compliance & Governance

EU AI Act: questions we hear most

Does the EU AI Act apply to a small company?
Yes, if the company uses or sells AI systems that affect people in the EU. The duties scale with the risk of the system, not with the size of the company. SMEs and small mid-caps benefit from lower maximum fines, simplified technical documentation and priority access to regulatory sandboxes, but the bans, the AI literacy duty and the transparency duties apply to them in full.
Is our website chatbot or AI phone agent covered?
Yes. A chatbot or voice agent that talks to customers must make clear that it is AI, from the first message or the first seconds of a call, and the people operating it need AI literacy measures. If the same assistant also takes decisions with legal or similarly significant effects, for example screening job applicants or deciding on credit, it moves into the high-risk category with its own obligations.
Do we have to host our AI in the EU?
The AI Act does not require it. GDPR restricts transfers of personal data outside the EU, and AI systems process personal data in prompts, transcripts and records, so hosting in the EU with a provider that does not train on your data is the simplest way to avoid transfer assessments for that data and to answer the questions that corporate clients and tenders ask. We specify EU hosting for the systems we deploy and document any exception.
What are the penalties?
Article 99: up to 35 million EUR or 7% of worldwide annual turnover for prohibited practices, up to 15 million EUR or 3% for breaching most other obligations, and up to 7.5 million EUR or 1% for supplying incorrect information to authorities. For SMEs and small mid-caps the lower of the two amounts applies. Fines are imposed by the national market surveillance authorities.
How does the EU AI Act relate to GDPR?
They apply side by side. GDPR governs the personal data an AI system processes: legal basis, information to the data subject, impact assessments, transfers. The AI Act governs the system itself: whether it is allowed, how it must be designed and documented, how people are informed and supervised. One inventory and one set of records can serve both, which is why companies with a working GDPR programme find the AI Act easier.
What did the Digital Omnibus change?
The Digital Omnibus on AI (Regulation (EU) 2026/1744), adopted in June 2026 and in force since 27 July 2026, postponed the obligations for high-risk systems to 2 December 2027 for stand-alone systems and to 2 August 2028 for AI built into regulated products. It added two prohibited practices, turned the AI literacy duty into a duty of effort, extended the SME reliefs to small mid-caps, gave systems already on the market until 2 December 2026 for machine-readable marking, and reinforced the AI Office. It rolled back nothing already in force: the bans, AI literacy and the transparency duties for chatbots and generated content stand.
What does PremiumClients.ai do, and what does it not do?
We map your AI systems, build the disclosure, oversight, logging and hosting controls into them, write the technical documentation and instructions of use, train your staff and monitor the status afterwards. We do not give legal advice: where an interpretation of the law is required, we work with your legal advisers and hand them a complete, current file.

Find out what applies to you before someone else asks

A free assessment covers your AI systems, your role for each one, the rules that apply and the gaps. You receive a written summary you can share with your management and your legal advisers.