EU AI Act for Mid-Market
The EU AI Act deadline is coming. Fines up to €35M. Here's the plain-English version of what it means for mid-market companies - no law degree required.
TL;DR
Risk-based, not technology-based. Four categories: unacceptable (banned), high-risk (strict), limited (transparency), minimal (no requirements). Most business AI is minimal or limited. High-risk adds 15-25% to project budget. Build compliance in from the start - retrofitting costs 3-5x more.
The regulation you can’t ignore
The EU AI Act is the first comprehensive AI regulation in the world. Fines reach up to €35M or 7% of global annual revenue - whichever is higher.
Most content about the EU AI Act targets enterprise legal teams. 200-page analyses. Law firm webinars. Compliance officer conferences.
This article is for you: the 50-500 employee company that uses or plans to use AI and needs to understand what the law requires - without a law degree.
I’m not a lawyer. I’m an engineer who complies with this regulation in systems I build. This is practical guidance, not legal advice. But it’s the guidance I wish someone had given me when I first tried to understand the Act.
What it regulates
The EU AI Act is risk-based, not technology-based. It doesn’t regulate AI technologies (LLMs, neural networks, etc.). It regulates AI use cases - what you do with AI, not how you build it.
Four risk categories:
- Unacceptable risk - Banned entirely
- High risk - Strict requirements
- Limited risk - Transparency requirements
- Minimal risk - No requirements
Your first step is classification: which category does your AI use case fall into? This determines everything else.
Risk classification
Unacceptable risk (banned)
- Social scoring by public authorities
- Manipulative or deceptive techniques
- Exploitation of vulnerabilities (age, disability, socio-economic)
- Real-time biometric surveillance in public spaces
- Emotion recognition in workplaces and schools
What this means for you: Almost certainly not relevant. These are primarily government and mass-surveillance use cases. If you’re a mid-market company, you’re not building these.
High risk (strict requirements)
- Employment decisions (hiring, promotion, termination)
- Credit and loan decisions
- Insurance pricing and eligibility
- Education enrollment and evaluation
- Critical infrastructure management
- Law enforcement assistance
- Migration and border control
What this means for you: If your AI system makes or supports decisions about people’s employment, credit, insurance, or education, it’s high-risk. This is the category with real compliance burden.
Limited risk (transparency only)
- Chatbots and virtual assistants
- AI-generated content (text, images, audio, video)
- Emotion recognition (with consent)
- Biometric categorization (with consent)
What this means for you: You must inform users they’re interacting with AI and label AI-generated content. That’s it. No risk management system, no conformity assessment. Just transparency.
Minimal risk (no requirements)
- Spam filters
- Recommendation engines
- Search algorithms
- Internal tools and productivity assistants
- Inventory optimization
- Predictive maintenance
- Document summarization
- Translation
What this means for you: Nothing. No requirements. Build and deploy freely. Most business AI falls here.
Most mid-market AI use cases are minimal or limited risk. The compliance burden is lower than you think - unless you’re in employment, credit, insurance, or education.
High-risk in practice
If your use case is high-risk, here’s what you need:
- Risk management system - Continuous process for identifying, evaluating, and mitigating risks throughout the AI system lifecycle
- Data governance - Training data must be relevant, representative, and free of errors. Document your data sources and quality checks
- Technical documentation - System architecture, model details, training methodology, performance metrics, limitations
- Record-keeping - Log every AI decision: input, output, timestamp, confidence
- Transparency - Users must know they’re interacting with AI. Decisions must be explainable
- Human oversight - A human can override every AI decision. No fully automated decisions without human review
- Accuracy, robustness, and security testing - Documented testing before deployment and periodically after
- Conformity assessment - Third-party assessment for certain high-risk systems
Cost impact: 15-25% of project budget. This isn’t optional spending - it’s legal compliance. Skip it and you’re risking €35M in fines.
Limited risk in practice
Much simpler:
- Inform users they’re interacting with AI (“This response is generated by an AI assistant”)
- Label AI-generated content (images, video, audio)
- Allow users to request human assistance
That’s it. A disclaimer and content labeling. Days of work, not months.
The deadline problem
The EU AI Act phases in over time:
- February 2025: Prohibited practices (unacceptable risk) are banned
- August 2026: High-risk systems and GPAI (general-purpose AI) requirements apply
- 2027: Full application of all requirements
Retrofitting compliance costs 3-5x more than building it in from the start. If you deploy a high-risk system without compliance documentation and try to add it later, you’re doing archaeology - trying to reconstruct decisions, data sources, and testing that should have been documented as they happened.
Build compliance into your development process from day one. It’s cheaper, safer, and gives you a documentation trail that stands up to regulatory review.
Important: Using a vendor’s AI doesn’t transfer compliance responsibility. If you use OpenAI’s API in a high-risk use case, you’re still responsible for compliance - not OpenAI. The Act regulates the deployer (you), not just the provider.
Practical checklist
- Inventory your AI systems. What AI are you using or planning? List every system, vendor, and use case.
- Classify by risk. Which category does each system fall into? When in doubt, classify higher and document your reasoning.
- Start high-risk documentation. If you have high-risk systems, start the risk management system and technical documentation now. Don’t wait for the deadline.
- Implement transparency. For limited risk: add disclaimers, label AI content. Simple but required.
- Assign a compliance owner. Someone in your organization must own AI compliance. Not a committee - a person.
- Build compliance into your dev process. Documentation, testing, and review should be part of your AI development lifecycle, not an afterthought.
- Schedule regular reviews. Compliance isn’t one-time. Systems change, data changes, regulations evolve. Review quarterly.
Compliance as advantage
Most mid-market companies are ignoring the EU AI Act. They think it doesn’t apply to them, or they’ll deal with it later, or it’s too complex to understand.
This creates an opportunity:
- Market advantage. If you’re compliant before your competitors, you can serve EU customers they can’t.
- Contract eligibility. Enterprise customers increasingly require AI compliance documentation from their vendors. Being compliant opens doors.
- No fines. €35M is an existential threat for most mid-market companies. Compliance is insurance.
- Quality signal. Compliance documentation is a quality standard. It shows you take AI seriously and build responsibly. That’s a differentiator.
Compliance isn’t a burden. It’s a standard of quality that most of your competitors won’t meet.
FAQ
We’re not in the EU. Does this affect us? Yes, if your AI system is used in the EU or affects EU citizens. The Act has extraterritorial reach, similar to GDPR. If you serve EU customers, you need to comply.
We’re just using the OpenAI API. Are we responsible? Yes. The Act regulates the deployer (you) for how you use AI, not just the provider (OpenAI). Using an external API doesn’t transfer compliance responsibility.
How much does compliance cost?
- Minimal risk: near zero - no requirements
- Limited risk: days of work - disclaimers and labeling
- High-risk: 15-25% of project budget - documentation, testing, oversight, assessment
Ready to apply this to your situation?
Book a Compliance Readiness Call30-min call. No pitch. You leave with one concrete next step - even if it’s not us.
Jacek Trefon
AI engineering leader. 28 years building technology, 4+ years building production AI systems. I help companies assess, architect, build, and deploy AI that actually ships. Based in Spain, working globally.
Keep Reading
All articles →AI Projects I Turn Down
Every consultant says they're honest. Few prove it. Here's my proof: a list of AI projects I've turned down, why I said no, and what I recommended instead.
The CEO's Guide to AI
Most CEOs don't understand AI. They pretend they do in board meetings while secretly Googling 'what is a large language model.' Here's what you actually need to know.
How to Evaluate an AI Vendor
Every AI vendor sounds the same in the sales call. The difference shows up in week 8 when the demo breaks. Here are the 10 questions that separate builders from talkers.