EU AI Act obligations by role and risk class: a practical guide for small companies

The AI Act, Regulation (EU) 2024/1689, applies in full on 2 August 2026. The prohibitions have applied since 2 February 2025 and the general-purpose model duties since 2 August 2025. This guide walks through the questions the Regulation asks of each AI system, in the order it asks them, and what each answer obliges you to do. Summaries are in Bindler's words with the article cited; the Regulation controls. Not legal advice.

When does the AI Act apply?

Scope is set by Article 2. Three exclusions matter most for small companies: systems placed on the market or used for military, defence or national security purposes only; systems developed and used for scientific research and development only; and use by a natural person in a purely personal, non-professional activity (Regulation (EU) 2024/1689, Article 2).

Role is set by Article 3: a provider develops an AI system or model, or has it developed, and places it on the market or puts it into service under its own name. A deployer uses an AI system under its own authority, other than in a personal non-professional activity (Regulation (EU) 2024/1689, Article 3). A company that builds a tool and also uses it is both provider and deployer, and carries both sets of obligations.

The five outcomes, and the order they are tested in

The Regulation does not state a decision tree in one article, but its tests imply an order of precedence. This is the order the Bindler classifier and workbook apply:

What is banned outright

Article 5 lists eight practices. In summary: manipulative or deceptive techniques that distort behaviour and cause significant harm (5(1)(a)); exploiting vulnerabilities of age, disability or social or economic situation (5(1)(b)); social scoring (5(1)(c)); predicting criminal offending solely from profiling or personality traits (5(1)(d)); untargeted scraping of facial images to build facial recognition databases (5(1)(e)); inferring emotions in the workplace or in education, except for medical or safety reasons (5(1)(f)); biometric categorisation to deduce race, political opinions, trade union membership, religion, sex life or sexual orientation (5(1)(g)); and real-time remote biometric identification in public spaces for law enforcement, with narrow exceptions (5(1)(h)) (Regulation (EU) 2024/1689, Article 5).

These have applied since 2 February 2025 (Regulation (EU) 2024/1689, Article 113(a)). If a system in your register matches one, the obligation is to stop.

What counts as high-risk

The first route is Article 6(1): the system is a safety component of a product covered by the EU harmonisation legislation in Annex I, or is itself such a product, and that product needs a third-party conformity assessment (Regulation (EU) 2024/1689, Article 6(1)).

The second is Annex III, which lists 25 use cases across eight areas: biometrics; critical infrastructure; education; employment; access to essential services, including credit scoring of natural persons and life and health insurance pricing; law enforcement; migration and border control; and justice and democratic processes (Regulation (EU) 2024/1689, Article 6(2) and Annex III). For most small companies the live ones are employment (4(a) recruitment and selection, 4(b) decisions on terms, promotion, termination and performance monitoring), education (3(a) to 3(d)) and essential services (5(b) credit scoring, 5(c) insurance pricing).

An Annex III system escapes high-risk if it does not pose a significant risk of harm to health, safety or fundamental rights, which Article 6(3) narrows to four situations: the system performs a narrow procedural task; it improves the result of a previously completed human activity; it detects decision-making patterns or deviations without replacing or influencing a prior human assessment; or it performs a preparatory task for an assessment (Regulation (EU) 2024/1689, Article 6(3)). Two overrides: an Annex III system that performs profiling of natural persons is always high-risk (Article 6(3), last subparagraph), and a provider relying on the exemption must document its assessment before placing the system on the market and must still register it in the EU database (Regulation (EU) 2024/1689, Article 6(4), Article 49(2)).

Whether a system materially influences a decision, and whether an exemption holds, are judgement calls. Record the reasoning; the Commission guidelines under Article 6(5) refine the tests.

The dates

WhatApplies fromReference
Entry into force1 August 2024Article 113
Scope, definitions, AI literacy, prohibited practices2 February 2025Article 113(a)
Notified bodies, general-purpose AI models, governance, penalties2 August 2025Article 113(b)
Everything else, including Annex III high-risk obligations and Article 50 transparency2 August 2026Article 113
Article 6(1) high-risk systems (Annex I product safety components)2 August 2027Article 113(c)
High-risk systems on the market before 2 August 2026Only when subject to significant design changes after that dateArticle 111(2)
General-purpose AI models on the market before 2 August 2025Comply by 2 August 2027Article 111(3)

Source: Regulation (EU) 2024/1689, Articles 111 and 113.

High-risk obligations for providers

A provider of a high-risk system carries the full regime under Article 16:

High-risk obligations for deployers

Article 26 is the list most small companies will face, because buying a high-risk tool from a vendor makes you a deployer:

Transparency duties under Article 50

These apply from 2 August 2026 alongside any high-risk duties. Providers must design interactive systems so that people know they are dealing with AI, unless obvious (Regulation (EU) 2024/1689, Article 50(1)), and mark synthetic audio, image, video or text output in a machine-readable, detectable way (Article 50(2)). Deployers must inform people exposed to emotion recognition or biometric categorisation, disclose deep fakes, and disclose AI-generated text published to inform the public (Article 50(3) and 50(4)).

General-purpose AI models

Providers of general-purpose AI models must keep technical documentation (Annex XI), inform downstream providers (Annex XII), have a copyright policy and publish a summary of the training content (Regulation (EU) 2024/1689, Article 53(1)). Models with systemic risk, presumed above 10^25 FLOP of training compute, add model evaluation, adversarial testing, risk mitigation, serious incident reporting and cybersecurity, and must notify the Commission within two weeks of meeting the threshold (Articles 52 and 55).

AI Act fines

Article 99 sets ceilings, not tariffs. Each is the higher of a fixed amount and a share of worldwide annual turnover for the preceding financial year:

BreachCeilingReference
A prohibited practice under Article 5EUR 35,000,000 or 7% of worldwide annual turnover, whichever is higherArticle 99(3)
Other operator obligations, including high-risk, transparency and importer or distributor dutiesEUR 15,000,000 or 3%, whichever is higherArticle 99(4)
Incorrect, incomplete or misleading information to notified bodies or authoritiesEUR 7,500,000 or 1%, whichever is higherArticle 99(5)
Providers of general-purpose AI models (fined by the Commission)EUR 15,000,000 or 3%, whichever is higherArticle 101(1)

For SMEs and start-ups, each ceiling is the lower of the amount and the percentage rather than the higher (Regulation (EU) 2024/1689, Article 99(6)). The actual fine depends on the circumstances in Article 99(7). For an SME with EUR 5,000,000 of turnover, the ceiling for a high-risk breach is therefore EUR 150,000.

A compliance checklist for a small company

The tool that does this

The EU AI Act Obligations Workbook ($39, /eu-ai-act-obligations/) is an Excel file with a Register that runs the classification above for up to 40 systems, an Obligations sheet with 23 duties by role and article, a Dates sheet, a Library of all 25 Annex III points and eight Article 5 practices, and a Summary with counts and the highest fine ceiling in the register, including the SME cap. Live formulas, no macros, no locked cells; works in Excel and Google Sheets.

The free EU AI Act classifier runs the same questions for one system at a time in your browser and returns the outcome, obligation set, application date and fine ceiling. A $19 licence key unlocks an unlimited register with CSV export.

EU AI Act Obligations WorkbookRegister every AI system, classify it under Regulation (EU) 2024/1689, and see the duties, application date and fine ceiling per row.
See the workbook, $39
Free toolTry it in your browser first.
Open the free tool

Search terms this page answers: eu ai act compliance checklist, ai act high risk obligations, ai act fines, when does the ai act apply.

New workbooks and updates by email

One email when a new workbook ships or a regulation changes a template. No filler. Sent through Gumroad, unsubscribe in one click.

You can unsubscribe from any email.