How to Prepare Your Business for the EU AI Act (Without Being an AI Expert)

Pedro Colarejo

Pedro Colarejo

Head of R&D

8 min read • September 8, 2026

The main failure isn’t a lack of awareness; it’s treating this as a one-off audit rather than an ongoing process. Compliance in this case isn’t something you check off and are done with; it’s a habit you have to develop when assessing and deploying AI in the future.

Prepare Your Business for the EU AI Act

When companies hear about the “EU AI Act” they tend to think that it’s something that affects only companies like OpenAI or Google or those other organizations that create AI models. However, that is not true. If your business uses AI — especially in areas that can affect people, such as recruitment, credit, healthcare, or customer interactions — the AI Act may create obligations for you too. The positive point is that you don’t need a legal team or prior knowledge of machine learning in order to work out what is important. All you need is someone to explain it; that’s all. And that is precisely what this article seeks to do.

The act in one paragraph

The EU AI Act does not prohibit the use of AI; rather, it divides AI applications into different risk categories, each subject to specific rules. A number of practices are completely forbidden. More importantly, if something can in any way affect a person’s rights, safety, or opportunities, it can be deemed “high-risk” and must meet certain obligations, such as keeping records, ensuring human oversight, and conducting monitoring. Most ordinary AI — for example, spam filters or product recommendations — has very few or no formal requirements. The important point isn’t to remember all of the law; it is to know where your particular application falls.

The four tiers, with real examples

  • Unacceptable risk: Some uses of AI are prohibited altogether, including certain forms of social scoring, harmful manipulation, and exploitation of vulnerable people. 
  • High-risk: Certain AI systems used in sensitive areas include hiring, credit decisions, insurance pricing, medical devices, and applications involving critical infrastructure. These areas require relevant documentation, such as risk management records, human supervision, technical documentation, and incident logging.
  • Transparency risk: For some AI applications, such as chatbots, deepfakes, and AI-generated content, the only requirement is transparency — that is, informing people that they are speaking to a robot or that a video has been produced using AI.
  • Minimal risk: this applies to the vast majority of ordinary business use of AI. There are no formal duties involved, but it’s still a good idea to follow good practice.

“Provider” vs. “Deployer”: the distinction that most companies find difficult to grasp

If your company develops an AI system and makes it available under its own name, you will generally be acting as a provider and will have significant responsibilities under the AI Act.
If, instead, your company uses an AI system supplied by someone else — for example, a recruitment platform, credit-scoring service or diagnostic assistant — you will normally be acting as a deployer. And deployers have responsibilities too. Buying a system from a vendor that claims to be “AI Act compliant” does not automatically make your own use compliant. Particularly for high-risk systems, organizations may need to follow the provider’s instructions, ensure appropriate human oversight, monitor how the system is used, and retain relevant logs.

In other words, AI compliance cannot simply be outsourced to the vendor.

The timeline just changed, and that matters

This is information that you should know even if you’ve been delaying it: The EU adjusted the AI Act timetable in 2026, giving organizations more time to prepare for some of its most demanding requirements. The requirements for many high-risk AI systems, including those covered by Annex III, will apply from December 2027, while the high-risk requirements for AI embedded in regulated products, such as certain medical devices, will apply from August 2028.

That does sound like it gives you some breathing space, and it does. However, two measures are already in place and won’t be going away: the prohibition on the most harmful practices and the AI literacy requirements came into force in February 2025, and the rules applicable to general-purpose AI providers, along with the governance requirements, came into effect in August 2025. The transparency obligations, that is, the rule requiring people to be told that they are speaking to a bot, are still on schedule. Therefore, the delay only gives you time to address the most onerous, high-risk documentation, not a reason to completely ignore the law.

In practice, it takes most medium-sized companies a few months to map out every AI tool they are using, assess the associated risks, and amend their vendor contracts. It is much better to start now and have extra time than to be in a rush in late 2027 under pressure.

A practical starting checklist

  1. Check all the AI tools that are being used, not just the obvious ones. Even HR systems, support chatbots, fraud detection systems, and spreadsheet add-ins now incorporate AI features.
  2. Divide them by risk level. The majority will fall into the ‘minimal’ category. A small number of them, typically those involving hiring, credit, or health, will require more careful examination.
  3. Return to your vendors and ask them to provide documentation rather than offering reassurance. Saying that “we’re compliant” isn’t a valid response. You should find out what risk tier they have assigned to their product and what their part of the shared obligation is.
  4. Make human oversight clear. For high-risk AI systems, make sure appropriately trained people are responsible for supervising how the system is used and are able to question or override its outputs where necessary .
  5. Give reasons rather than merely listing the tools you have used; regulators and auditors are just as concerned about your decision trail as they are about your tech stack.

The mistake worth avoiding

The main failure isn’t a lack of awareness; it’s treating this as a one-off audit rather than an ongoing process. A tool that is low-risk at the present moment can become high-risk the very moment it is used in a new decision. Compliance in this case isn’t something you check off and are done with; it’s a habit you have to develop when assessing and deploying AI in the future.

How LOAD approaches this

At LOAD, we prefer to build AI governance into the architecture from the beginning rather than treating compliance as something to add at the end. That means thinking about oversight, traceability, data, documentation and accountability while the system is being designed — not when someone asks for evidence six months later.

The result is not just easier compliance. It is an AI system that your organization understands, controls, and can confidently explain.

If you’re unsure about your business’s position, let’s work it out together.

Pedro Colarejo

Pedro Colarejo

Head of R&D

I Have a Challenge
Would like to discuss your innovation challenge?

How did you find us?

20%

Bringing ideas to life...