European business in the digital transition: preparing for AIs legal compliance

Views: 6

Among biggest practical changes in the European AI legislation for businesses are those of compliance: including requirements for a company’s digital facilities and used AI models, developing or hiring algorithms, selling AI-powered services and/or providing a GPAI model, etc. The law also applies to companies outside the Union if they place AI systems or GPAI models on the EU market, or if the output of their AI system is used in the EU member states.  

Background
European AI Act has a particular focus on small and medium-sized enterprises, SMEs. Suffice it to say that SMEs were mentioned in the law about forty times, compared to only seven for “industry” and about ten times for “civil society”. More important is that the EU AI law has revealed a number of measures specifically designed to support and simplify SME compliance with the product safety rules of the AI Act.
Under the EU law, SMEs are an overarching category of enterprises consisting of three subcategories; a) medium-sized enterprises, having less than 250 employees and with an annual turnover of less than €50 million and/or not more than €43 million on their annual balance sheet; b) small enterprises, that employ less than 50 persons and have an annual turnover and/or balance of less than €10 million; and c) microenterprises, that employ less than 10 persons and have an annual turnover and/or balance of less than €2 million.
It is vital that the AI Act explicitly mentions start-ups as part of SMEs throughout the whole text, even though there is currently no separate or single definition of a start-up under EU law.
Source: https://artificialintelligenceact.eu/small-businesses-guide-to-the-ai-act/

    Bottom-lime: the EU AI Act is likely to affect – in some way – all corporate entities residing in the EU-27 and using the AI-powered products or services for personal or business matters. Some of the examples are already evident: e.g. labels or disclosures indicating that an image, video, audio clip, or other content was generated or manipulated using AI on platforms like Instagram or TikTok. These requirements have been become applicable from the beginning of August 2026 as part of the EU AI Act’s transparency rules, and they are part of a much broader legal clauses that are being introduced in stages during 2027-28. The EU AI Act also bans certain uses of AI, places strict requirements on systems considered high-risk, and sets rules for companies developing, providing, or using AI, with different provisions taking effect at different times.
More about the EU AI Act, the AI systems that it covers, as well as the consequences for the European-wide corporate community and the digital providers outside the EU, in:
https://artificialintelligenceact.eu/ai-act-explorer/

Legal provisions “tailored” for the SMEs
= Regulatory sandboxes: the law provides some frameworks for testing AI products and services outside normal regulatory structures, with exemptions from administrative fees. Testing may also be facilitated in real world conditions. SMEs in the member states will have priority access to sandboxes free of charge, and the procedures shall be simple and clear.
= Reducing compliance costs and fees: assessment fees shall be proportional to the size of SMEs and the Commission will regularly assess and intend to lower compliance costs.
= Standard setting and governance: the Commission and the EU member states shall facilitate participation of SMEs in standard setting and in within the European AI advisory forum; the Advisory Forum is a general advisory body to the European Commission and the AI Board, established to provide technical expertise, advise them and contribute to the law’s implementation.
= Simplified documentation and training: the Commission will develop simplified SME technical documentation forms that are accepted by national authorities for conformity assessments and provide training activities tailored to SMEs to support compliance.
= Dedicated communication: the law provides guidance and response to queries through dedicated channels to support SMEs in complying with the AI Act.
= Proportionality: obligations for providers of general-purpose AI models should be commensurate and proportionate to the type of a model provider. For example, there will be separate key performance indicators for SMEs under the Code of Practice.
More in: https://michael-culture.eu/ai-acts-code-of-practice-second-draft-transparency-copyright/28/2025/

Thus, basically, to prepare for and maintain compliance with the EU AI legislation, the businesses should do the following:
= Know what AI is used, keeping track of AI systems used across the business teams (including third-party tools), and understand what they are being used for. This can include AI used in HR, customer service, marketing, security, analytics and other business processes.
= Determine the corporate’s “digital roles”: e.g. establish whether the business in question is a provider that develops or sells an AI system, a deployer that uses one, or an importer or distributor. Hence, different corporate obligations are applied to each “role”.
More in: https://artificialintelligenceact.eu/small-businesses-guide-to-the-ai-act/

= Classify AI by risk: check whether any AI use is prohibited, high-risk, subject to transparency requirements, or minimal risk. Thus, e.g. in using AI to screen job applicants, the rules are considerably stricter than for AI spam filters.
= Stop prohibited AI uses: the company shall audit AI tools and workflows for any banned practices and disable or replace systems that “cross the line”. It shall focus especially on AI used to monitor employees, profile people, analyze biometric data, manipulate behavior and/or make sensitive assessments about individuals.
= Train employees who use AI: the digital providers and deployers must take measures to support AI literacy among employees and others who operate AI systems on their behalf. Training should reflect how AI is actually being used and the risks involved.
= Meet AI transparency requirements: the company’s CEOs may need to tell people when they are interacting with AI, label certain AI-generated or manipulated content, or inform people when permitted emotion recognition or biometric categorization systems are being used.
= Apply stricter controls to high-risk AI: the providers must manage risks, use appropriate data, keep documentation and logs, ensure human oversight and meet accuracy, security and reliability requirements. They may also need to complete conformity assessments and register the system. Businesses using high-risk AI must follow the provider’s instructions, monitor how it performs and keep the required records.
= Check GPAI obligations: if a company provides GPAI models, it has had separate requirements covering technical documentation, information for downstream developers, copyright compliance and summaries of training content. Models that pose systemic risk face additional safety and cybersecurity requirements.
= Review AI suppliers: if a company uses third-party AI, it is obliged to check the AI systems provided by vendors, how they are classified, what documentation is available and who is responsible for complying with each part of the EU AI Act. Modifying or rebranding certain AI systems can also transfer provider’s responsibilities in the business.
= Keep AI governance up to date: it is obvious that the AI systems, their uses and the law can change. Thus, businesses should document how AI is used, monitor systems for new risks or incidents and reassess compliance when an AI system is substantially changed or repurposed.
= Compliance with the AI Act does not replace other legal obligations. Businesses using personal data, copyrighted material or AI in regulated sectors may also need to comply with laws such as the GDPR, EU copyright rules, consumer protection law and sector-specific regulations.
Additional info in: https://proton.me/blog/eu-ai-act#timeline

More to know about the EU AI Act and GDPR
The EU-wide AI law is about to regulate the “whole AI’s area”. Formally known as the EU Regulation 2024/1689, its goal is to make AI safer, more transparent, trustworthy and human-centric while protecting fundamental rights and allowing innovation and adoption of AI in the EU member states. The EU AI Act can be regarded as the “GDPR for AI”; although with slightly different approaches: e.g. the GDPR primarily governs how personal data is collected and processed, while the EU AI Act governs how AI systems are developed, provided, deployed and used, particularly when they could affect people’s rights, safety or vital citizens’ decisions.

Note. The European Union’s General Data Protection Regulation, GDPR is a comprehensive privacy and security law that standardizes data protection rules across EU member states and applies to any organization worldwide that processes the personal data of individuals in the EU. ChatGPT is regarded as the AI tool; developed by OpenAI, it is a conversational generative AI chatbot that uses machine learning and natural language processing to understand prompts and write human-like text, code and other content. Instead of regulating all AI issues in the same way, the European AI law takes a risk-based approach, which is classified at four levels: – unacceptable (banned) risks, – high-risks, – limited (transparency) risk, and – low (or no risk). The first eight bans came into force in February 2025, while the last one takes effect in December 2026. Generally, the greater the potential harm an AI system can cause, the stricter are the rules: hence, the EU law does not formally define four “risk levels,” but the “risks’ rules” are often grouped into four broad categories to make them easier to understand.
More on GDPR regulation in: https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R0679, as well as in: https://gdpr-info.eu/

Obligations for companies using GPAI models
GPAI (general-purpose AI) models are AI models designed to handle many different tasks rather than one specific and narrow purpose. Examples of GPAI models include, e.g. the large language models (LLMs) that power ChatGPT, Gemini, Claude and Meta AI models. They can generate or analyze content and can be integrated into other AI systems and applications.
GPAI models are subject to their own requirements under the AI Act. The model providers must maintain technical documentation, give downstream developers information about the model’s capabilities and limitations, comply with EU copyright rules and publish a public summary describing the data types (such as text, images, audio or video) and sources (e.g. public datasets, private datasets, scraped websites, user data or synthetic data) used to train the model.
GPAI models that pose systemic risk (i.e. powerful or widely used creating problems and causing large-scale harm across the EU states), face additional requirements, including model evaluations and adversarial testing, ongoing risk management, incident reporting and stronger cybersecurity protections.
More info on Meta AI: https://proton.me/blog/turn-off-meta-ai-facebook

Special risk-requirements in specific applications
= In critical infrastructures: the AI models managing digital infrastructure, road traffic, or the supply of water, gas, heating, or electricity are considered having high-risks. E.g. in August 2024, Prague deployed an AI traffic control system that adjusted traffic light timing in real time based on current conditions and prioritizing the public transport and emergency vehicles, which was one of the first large-scale deployments of this kind in Europe.
= In high-risk AI: the high-risk AI systems are allowed on the EU market as long as the provider meets a demanding set of obligations. An AI system is considered high-risk in one of two ways: a) it is a product or the safety component of a product already covered by EU product-safety law, and b) it is subject to a third-party conformity assessment, such as medical devices, machinery, lifts or toys. These systems are classified as high-risk under the AI law’s art. 6(1) and Annex I, and will become subject to the high-risk obligations starting from August 2028.
If the AI model falls into one of the specific use-case categories listed in Article 6(2) and Annex III, the obligations for this group will begin in December 2027.
More about the “digital risks” and watering marks in: https://www.integrin.dk/2026/08/25/watermarking-ai-generated-text-effects-for-the-public-and-businesses/

 

 

Leave a Reply

Your email address will not be published. Required fields are marked *

1 × three =