OMX Helsinki — S&P 500 — DAX — NASDAQ 100 — STOXX 600 — EUR/USD — EUR/SEK — BTC/USD — ETH/USD — Euribor 3M — Euribor 12M —
The AI Act and AI legislation

The AI Act and AI legislation — a practical test of responsible AI begins for European companies

The AI Act isn't some distant future — it's already underway. The regulation classifies AI systems by risk level: the greater the risk to people, the stricter the requirements. You can use AI boldly, but not carelessly.

1. Introduction: from AI's Wild West to the age of rules

AI has advanced faster than many organizations have been able to build ground rules for it. First came the excitement. Chatbots, image generators, automatic summaries, recruiting tools, customer service bots and decision-making assistants landed on desks at a rapid pace.

Then came the next question: Who is responsible if AI makes a mistake?

If an AI system discriminates in hiring, makes an incorrect credit decision, misidentifies a person in camera footage or produces misleading content, it's no longer just about technology. It's about people, rights, money, safety and trust.

That need gave rise to the European Union's Artificial Intelligence Act, or AI Act. It is the world's first comprehensive, horizontal legal framework for AI. Its goal is simple but ambitious: AI may be developed and used, but it must be done safely, transparently and with respect for people's fundamental rights.

The European Commission's AI Act page states that the AI Act entered into force on August 1, 2024, and applies in stages: the rules on prohibited practices and AI literacy began on February 2, 2025, the obligations for general-purpose AI models on August 2, 2025, and the transparency obligations and regulatory oversight on August 2, 2026. The obligations for high-risk systems were postponed by Regulation (EU) 2026/1744: Annex III use cases to December 2, 2027, and Annex I products to August 2, 2028.[1][12]

So the AI Act is no longer some distant future. It's already underway.

2. What is the AI Act?

The AI Act, the EU's Artificial Intelligence Act, is a European Union regulation that governs the development, placing on the market and use of AI systems in the EU.

The regulation doesn't cover just one industry. It broadly covers the use of AI across sectors: work, education, finance, public services, healthcare, security, infrastructure and consumer services.

It's important to understand that the AI Act doesn't ban AI. Nor does it say that all AI is dangerous. Its logic is risk-based:

  • minimal risk → few or no specific obligations
  • transparency risk → users must be told that AI is being used
  • high risk → strict requirements
  • unacceptable risk → use is prohibited

That's what makes the AI Act interesting. It doesn't try to regulate AI as one big lump. Instead it asks: what is AI being used for, and what consequences can that use have?

The same technology can be harmless in one situation and very risky in another. AI that suggests blog headlines is not the same as AI that assesses a job applicant's suitability or creditworthiness.

3. Why did the EU want its own AI regulation?

AI regulation has two major goals that may seem contradictory but aren't necessarily.

The first is innovation. Europe wants AI to be developed and used. Companies need new tools, the public sector needs better services and citizens need useful applications.

The second is trust. If people don't trust AI, they won't want to use it. If companies don't know the rules, they may either take on too much risk or leave useful solutions unbuilt.

The European Commission's AI policy page sums up the EU's approach in two words: excellence and trust — both at once. The EU wants to strengthen competitiveness and technological sovereignty while ensuring that AI is human-centric and trustworthy.[2]

This is the political core of the AI Act. Europe is trying to build a market where AI can be trusted. That isn't just a legal goal. It's also a business goal. Trust can be a competitive advantage.

4. Risk-based thinking: the core of the AI Act

The most important idea in the AI Act is its risk-based approach. Not all AI systems are treated the same way. The obligations depend on how much risk a system can pose to people, society or fundamental rights.

Put simply, the AI Act divides AI use into four categories:

4.1 Unacceptable risk

Certain AI practices are banned outright because they are considered incompatible with EU values and fundamental rights.

4.2 High risk

AI may be used, but only in line with strict requirements. This applies, for example, to many systems used in situations that affect people's opportunities, rights or safety.

4.3 Transparency risk or limited risk

In certain situations, people must be told that they are interacting with AI or that content has been generated by AI.

4.4 Minimal risk

Most everyday AI use falls under lighter regulation. For example, drafting text, brainstorming or internal productivity use isn't automatically a high-risk activity.

This risk model is practical, but it requires a new kind of thinking from organizations. It's no longer enough to ask: “Do we use AI?”

You have to ask: “What do we use AI for, whom does it affect and what harm could a mistake cause?”

5. Prohibited AI practices: what you can't do

The strictest part of the AI Act concerns prohibited AI practices. These are uses the EU considers so risky that they aren't allowed.

Article 5 of the AI Act states that the article on prohibited AI practices became applicable on February 2, 2025.[3]

Prohibited practices include, for example, using AI to manipulate or exploit people in ways that can cause significant harm. The regulation also targets certain forms of social scoring and other uses that are especially problematic from a fundamental rights perspective.

In practice, this means an organization has to be able to recognize when an AI solution enters territory where people's behavior is steered, evaluated or restricted in ways that may be unfair, discriminatory or opaque. This doesn't only apply to big tech companies — a smaller company can also end up in a risk area if it uses AI, for example, to evaluate the behavior of employees, customers or users in ways that have real consequences.

This is where the AI Act forces you to ask an uncomfortable but important question: Is AI helping people — or is it starting to steer them in ways they don't understand or can't push back against?

6. High-risk AI systems: where the obligations get tougher

From a practical standpoint, high-risk AI systems may be the most important part of the AI Act. They aren't banned, but they are subject to strict requirements. A high-risk system can arise, for example, when AI is used:

  • in recruiting
  • in evaluating employees
  • in access to education or assessing students
  • in assessing creditworthiness
  • in critical infrastructure
  • in law enforcement
  • in migration and border control
  • in the administration of justice
  • in biometric identification or categorization
  • in certain healthcare or safety use cases

The European Commission's AI Act Service Desk FAQ points out that if an AI agent is classified as a high-risk AI system, it is subject to additional requirements designed to ensure the system's safety and reliability for its intended purpose. These requirements begin to apply to Annex III use cases on December 2, 2027, and to Annex I products on August 2, 2028; Regulation (EU) 2026/1744 extended the original August 2, 2026 deadline. The transparency rules, by contrast, may already apply from August 2, 2026, if the agent is intended to interact with natural persons or to generate content.[4][12][1]

Here's the key message for companies: High risk isn't determined by whether the technology is impressive or complex. It's determined by the intended purpose and the impact.

Even a simple AI tool can be a high-risk system if it's used in a situation that affects a person's rights, opportunities or safety.

7. What is required of high-risk systems?

7.1 Risk management

The organization has to identify, assess and manage the system's risks throughout its lifecycle. That doesn't just mean a risk list at the start — it means an ongoing process. What could go wrong? Whom does it affect? How is the risk detected? What happens if the system behaves incorrectly?

7.2 Data governance and data quality

An AI system is only as good as its data. In high-risk systems, the data has to be fit for purpose, high quality and well governed. Particular attention must be paid to biases, gaps and whether the data could lead to discriminatory outcomes.

7.3 Technical documentation

The system must have adequate documentation: what it does, what it's used for, what data it was developed with, what its limitations are and how it's monitored. Documentation isn't just for the authorities — it's also the organization's own safety net.

7.4 Logging

High-risk systems must generate logs so that their use and operation can be traced. Logs matter if you later need to find out why the system made a particular recommendation or decision.

The AI Act text on EUR-Lex states, among other things, that providers of high-risk AI systems must keep automatically generated logs for an appropriate period of at least six months, unless other EU or national law provides otherwise.[5]

7.5 Human oversight

A high-risk AI system must not be a black box that operates without understandable human control.

Article 14 of the AI Act states that the aim of human oversight is to prevent or minimize risks to health, safety or fundamental rights that can arise from the use of a high-risk AI system.[6]

“A human oversees it” must not mean someone clicking an approve button without understanding what the system did. The person providing oversight needs the competence, the authority and a real opportunity to intervene.

7.6 Accuracy, robustness and cybersecurity

The system must work reliably in real-world conditions too. It has to withstand errors, anomalies and misuse attempts better than an ordinary experimental tool.

Here the AI Act reminds companies of one basic point: If AI affects people's lives, you can't treat it like a beta version.

8. Transparency obligations: when do people need to be told about AI?

Not all AI Act obligations relate to high-risk systems. In many situations, the key requirement is transparency. People must know if they are interacting with AI, or if content has been generated by AI in certain situations covered by the regulation.

The European Commission's FAQ on transparency obligations explains that Article 50 of the AI Act sets transparency obligations for providers and deployers of certain AI systems, including generative and interactive AI systems as well as deepfakes. The purpose of these obligations is to reduce the risks of deception, impersonation and disinformation and to strengthen trust in the information ecosystem.[7]

In practice, this can mean, for example:

  • a chatbot must disclose that it is AI if that isn't obvious
  • content generated or edited with AI may require labeling
  • transparency is especially important for deepfake content
  • users must understand when they are dealing with a machine rather than a person

This isn't just a legal detail. It's a question of trust. If customers find out afterward that they were talking to AI when they thought they were talking to a person, trust can break quickly.

9. General-purpose AI models (GPAI): why are ChatGPT-style models a question of their own?

The AI Act has its own regulatory layer for general-purpose AI models. These are often called GPAI models, short for general-purpose AI models.

These are models that can be used for many different purposes. They aren't systems built for just one application. The same general-purpose model can end up in customer service, coding, content production, analytics, teaching, decision support or as part of a high-risk application.

Under the AI Act timeline, the obligations for general-purpose AI models began to apply on August 2, 2025.[1]

From a company's point of view, this means two things. First, model providers have obligations of their own. Second, an organization using the model can't assume that responsibility disappears because “we're just using an off-the-shelf tool.”

If a general-purpose model becomes part of recruiting, credit decisions, employee evaluation or another high-risk use, the whole setup has to be assessed based on its intended purpose. The technology can be the same. The risk level changes with the use case.

10. The AI Act timeline: what already applies and what comes next?

August 1, 2024 — the AI Act entered into force

The regulation entered into force on August 1, 2024. That started the transition period.

February 2, 2025 — prohibited practices and AI literacy

The rules on prohibited AI practices and the AI literacy obligations began to apply.[1]

August 2, 2025 — general-purpose AI models

The obligations for GPAI models began to apply.

August 2, 2026 — transparency and oversight

The transparency obligations become applicable. From this date, the AI Office and the member states' authorities are responsible for implementing and supervising the regulation and ensuring compliance with it.[1]

December 2026 — a new prohibited practice

A ninth prohibited practice, added by the Digital Omnibus regulation, takes effect.[1]

December 2, 2027 — high-risk use cases (Annex III)

High-risk use cases in sensitive areas — including recruiting, education, credit decisions and biometrics — become applicable. The original deadline was August 2, 2026, and the transition period was extended by Regulation (EU) 2026/1744.[1][12]

August 2, 2028 — high-risk products (Annex I)

High-risk AI systems embedded in regulated products got the longest transition period. The European Commission's standardization page describes the next steps related to standardization and application timelines for high-risk systems.[1][12][8]

The timeline changed partway through implementation. On July 8, 2026, the European Parliament and the Council adopted Regulation (EU) 2026/1744, which amends the AI Act and postpones the application of the high-risk obligations. If you read about the AI Act timeline earlier, the high-risk dates you saw are probably out of date. The change is also reflected in the Commission's Navigating the AI Act FAQ.[9][12]

Even so, companies shouldn't sit and wait. If your organization may have high-risk AI use, start preparing now — the extended transition period is extra time to get ready, not a reason to put it off.

11. AI literacy: a small article, a big change

AI literacy is one of the most interesting parts of the AI Act, because at first glance it looks like a soft obligation. In reality, it can change organizations' day-to-day work a lot.

AI literacy means that providers and deployers of AI systems must ensure that the people using AI have sufficient competence relative to the context of use. That doesn't mean everyone has to know how to code. It means people need to understand, for example, what AI is suited for, where its limits are, what risks its use involves, how to evaluate its answers, when a human needs to step in, what data can be given to AI, when sources need to be checked and what the organization's own rules say.

Article 4 of the AI Act covers AI literacy and has applied since February 2, 2025. It requires providers and deployers to take measures to ensure a sufficient level of AI literacy, taking into account factors such as technical knowledge, experience, education and the context of use.

That's a big message for leadership. AI training is no longer just a “nice extra.” It's part of adopting AI responsibly.

12. What does the AI Act mean for companies in practice?

For a company, the AI Act doesn't primarily mean that the legal department reads the regulation and writes a memo. It means mapping how AI is used.

The first task is to find out: Where are we already using AI?

In many organizations, the answer is surprising. AI can be found in HR tools, marketing platforms, customer service, CRM systems, analytics, document processing, security tools, production processes, recruiting systems, employee performance evaluation, content production and internal chatbot solutions.

The second task is to classify the use cases by risk. The third task is to build a governance model. In practice, this can mean an AI register, risk classification, designated owners, approval processes, privacy and security assessments, procurement criteria, staff training, guidelines for using generative AI, documentation of high-risk systems, logging and defining human oversight.

The European Commission's AI Pact page encourages organizations to prepare for implementing the AI Act ahead of time. The AI Pact is a voluntary initiative designed to help organizations plan how to put the AI Act's requirements into practice.[10]

Here's a good practical principle: Don't start with the articles. Start with the use cases. Once you know where AI is being used, you can assess which rules apply.

13. Startups and the AI Act: a drag or a competitive advantage?

In the startup world, regulation often stirs mixed feelings. On the one hand, regulation can feel like a drag. A small team doesn't have unlimited lawyers, compliance experts or documentation resources. On the other hand, the AI Act can also be a competitive advantage.

If a startup builds an AI product from the start that is transparent, documented, secure and risk-aware, it can be in a stronger position, especially in enterprise sales. B2B customers will increasingly ask: What data is the system based on? How are risks managed? Can the system discriminate? How does human oversight work? Is the system a high-risk use case? How are logging and documentation handled? How has the AI Act been taken into account?

For a startup, that may sound heavy. But it can also set a serious player apart from an experimental project.

Especially if a startup operates in HR, education, finance, health, security or the public sector, the AI Act can't be left for later.

A good rule of thumb for startups: If your product affects people's opportunities, rights or safety, build compliance in from the early stages of product development. It's cheaper than fixing everything afterward.

14. A practical checklist for organizations

14.1 Take an AI inventory

List all AI systems and tools that use AI. Ask: Where is AI used? Who uses it? For what purpose? Is the use internal or external? Does it affect customers, employees or citizens?

14.2 Classify use cases by risk

Assess whether the use falls under prohibited practices, high-risk systems, transparency obligations or minimal-risk use.

14.3 Take a close look at high-risk areas

If you use AI in recruiting, employee evaluation, educational admissions, student assessment, credit decisions, insurance or financing decisions, biometric identification, critical infrastructure, security, healthcare or to support decisions by public authorities, look into it especially carefully.

14.4 Assign responsibilities

Who owns the AI risks? At a minimum, you need business ownership, technical ownership, data protection ownership, security ownership, legal review, user training and leadership oversight.

14.5 Build documentation

For high-risk systems, documentation isn't a voluntary extra. Document: intended purpose, data sources, risks, testing, human oversight, logging, vendors, updates, incidents and user instructions.

14.6 Train your staff

AI literacy needs to be proportionate to the role. The marketing team needs different training than HR, legal, IT or customer service.

14.7 Update your procurement criteria

When you buy an AI tool, ask the vendor: Does the system fall under the AI Act? What is its intended purpose? Has a risk assessment been done? What documentation is available? How is data processed? How does logging work? How is human oversight designed? How can the system be audited?

14.8 Create an approval process for high-risk use

No one should roll out a high-risk AI system on their own as an experiment. You need a clear gate before deployment.

14.9 Keep up as the rules are clarified

The practical application of the AI Act is being clarified through guidelines, standards and interpretations by the authorities. The European Commission's standardization page states that harmonized standards are being developed for areas such as the requirements for high-risk AI systems. Once the standards are finalized and published in the Official Journal of the EU, they can provide a presumption of conformity.[11]

In practice, this means: The AI Act isn't just one law. It's an evolving ecosystem of regulation and standards.

15. Common misconceptions about the AI Act

Misconception 1: “The AI Act only applies to big tech companies”

It doesn't. It can also apply to ordinary companies if they use AI systems for purposes covered by the regulation.

Misconception 2: “If we use an off-the-shelf tool, the vendor is responsible”

Not necessarily. The vendor may have obligations, but the deployer may also have obligations of its own. The intended purpose in particular makes a big difference.

Misconception 3: “Generative AI is always high-risk AI”

It isn't. Using a chatbot for brainstorming isn't automatically a high-risk activity. But the same technology can become part of a high-risk use if it's used, for example, to evaluate job candidates.

Misconception 4: “AI literacy means technical training”

Not only that. AI literacy is also the ability to assess risks, understand limits, verify information and use AI responsibly.

Misconception 5: “Regulation kills innovation”

Bad regulation can slow things down. But clear ground rules can also increase trust and speed up adoption. Enterprise customers don't want to buy a black box that could cause legal or reputational harm.

Misconception 6: “We can deal with this later”

A dangerous idea. If AI is already part of recruiting, employee evaluation, customer classification or decision support, it pays to do a risk assessment right away.

16. Conclusions: responsible AI isn't paperwork — it's building trust

The AI Act is changing how AI is adopted in Europe. It doesn't mean AI development stops. It means AI can no longer be rolled out on enthusiasm alone if its impact on people is significant.

These are the key takeaways:

  1. The AI Act is already in force. The regulation entered into force on August 1, 2024. Some obligations, such as prohibited practices and AI literacy, have applied since February 2, 2025. The obligations for GPAI models began on August 2, 2025, and the transparency obligations and regulatory oversight on August 2, 2026. The high-risk obligations begin on December 2, 2027 (Annex III) and August 2, 2028 (Annex I).
  2. Not all AI carries the same risk. The risk-based approach is the core of the entire regulation.
  3. High-risk use has to be identified in time. Recruiting, education, employee evaluation, credit decisions, biometrics and critical infrastructure are areas where organizations need to be especially careful.
  4. Documentation, risk management and human oversight aren't bureaucracy. They are ways to make sure AI works correctly, mistakes can be traced and humans keep real control.
  5. AI literacy is a basic organizational skill. People who use AI need to understand what they're doing.
  6. For startups, responsibility can be a competitive advantage.
  7. Now is the time to take inventory. Where do we use AI? What does it affect? Who is responsible? What needs to be checked before August 2026?

The practical summary

If your organization uses AI in recruiting, education, employee evaluation, credit decisions, biometric identification or critical infrastructure, find out early whether it might be a high-risk AI system.

High-risk systems require, among other things: risk management, documentation, logging, high-quality data governance, human oversight, transparency and continuous monitoring.

In the end, the AI Act's big message is this: You can use AI boldly, but not carelessly.

Europe's AI era won't be built on efficiency alone. It will be built on trust.

Sources

  1. AI Act — Shaping Europe's digital future, European Commission
  2. European approach to artificial intelligence — European Commission
  3. Article 5: Prohibited AI Practices — EU Artificial Intelligence Act
  4. AI Act Service Desk — Frequently Asked Questions
  5. Regulation (EU) 2024/1689 — EUR-Lex, European Union
  6. Article 14: Human Oversight — EU Artificial Intelligence Act
  7. Guidelines and Code of Practice on transparent AI systems — European Commission
  8. Standardisation of the AI Act — European Commission
  9. Navigating the AI Act — European Commission
  10. AI Pact — European Commission
  11. Understanding the standardisation of the AI Act — European Commission
  12. Regulation (EU) 2026/1744 of July 8, 2026, amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonized rules on artificial intelligence (Digital Omnibus on AI) — EUR-Lex
Open the AI assistant chat. The chat loads only when you open it.