The EU AI Act – What you need to know now

The world's first comprehensive AI regulation affects your company too. Here is everything you need to know.

What is the EU AI Act?

The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive regulation for artificial intelligence. The regulation was adopted in August 2024 and takes effect in stages until August 2026.

The goal is to make the use of AI in the EU safe and trustworthy – without slowing down innovation. The risk-based approach distinguishes between four risk levels: minimal, limited, high and unacceptable.

Companies that develop, operate or use AI systems must meet different obligations depending on the risk level – ranging from a simple transparency requirement to a full conformity assessment.

The four risk levels of the EU AI Act

1

Minimal risk

Spam filters, AI in video games. No special obligations. Voluntary codes of conduct recommended.

2

Limited risk

Chatbots, deepfakes. Transparency obligation: users must know when they are interacting with AI.

3

High risk

HR tools, credit scoring, medical AI. Strict requirements: risk management system, data governance, documentation.

Affects most companies

4

Unacceptable risk

Social scoring, real-time biometric surveillance. Banned in the EU. No exceptions.

Which companies are affected?

Short answer: almost all. The EU AI Act applies not only to AI developers, but also to companies that use AI systems ("deployers"). This means:

  • If your employees use ChatGPT, Copilot or similar tools, you are affected.
  • If you use AI for HR decisions, customer analytics or process automation, you are affected.
  • If you offer a SaaS product with AI components, you are affected.

The EU AI Act is particularly relevant for companies in human resources, financial services, healthcare, education and public administration.

Timeline: when do which rules apply?

Aug 2024

Regulation enters into force

The EU AI Act was published in the Official Journal of the EU.

Feb 2025

Bans take effect

AI systems with unacceptable risk are banned effective immediately (social scoring, etc.).

Aug 2025

GPAI rules apply

Obligations for providers of General Purpose AI (such as GPT-4, Claude, Gemini).

Aug 2026

Full application

All rules apply – including high-risk AI obligations. Fines of up to €35 million.

How does Guardlane help with the EU AI Act?

Three steps to compliance – without external consultants.

1

Take inventory

Run the discovery survey. In 10 minutes, you know which AI tools are being used and where the risks are.

2

Implement measures

The automatically generated 30-day action plan shows what needs to be done first. Work through it sprint by sprint.

3

Prove & report

PDF reports for management and the works council. AI Registry as the central inventory. Everything documented and audit-ready.

August 2026 is coming faster than you think

Start your AI governance now. Self-hosted in your own infrastructure.