The EU Artificial Intelligence Act came into force in August 2024. It is binding law across all 27 EU member states — and its first deadlines have already passed. For UK companies that develop or use AI systems reaching European users, it applies regardless of where the company is registered.

This guide covers what the AI Act actually regulates, who it applies to, how it classifies risk, and what the fines look like.

What the AI Act regulates (and what it does not)

The AI Act regulates artificial intelligence systems based on the risk they pose to people — not based on the technology they use. Whether your product uses neural networks, large language models or computer vision does not matter: what matters is what it does and in what context.

Outside scope: systems used exclusively for military or national security purposes, R&D systems without commercial deployment, and purely personal systems with no impact on third parties.

The risk pyramid: four levels, four sets of obligations

Unacceptable risk — prohibited

The AI Act bans outright: subliminal manipulation causing harm, exploitation of vulnerabilities based on age, disability or socioeconomic situation, social scoring by public authorities, real-time biometric identification in public spaces (with very narrow law enforcement exceptions), emotion recognition in workplaces and educational settings, and inferring sensitive attributes from biometric data.

These prohibitions have been in force since February 2025.

High risk — strict requirements

The most relevant category for technology companies. Systems fall here if they make or assist decisions in: hiring and HR management, access to education, credit and financial services, healthcare and diagnosis, critical infrastructure (energy, water, transport), law enforcement, and migration management.

Requirements: documented risk management system, data governance (quality and representativeness of training data), technical documentation, active human oversight, robustness and cybersecurity certification, and automatic activity logging.

Limited risk — transparency obligations

Systems interacting with people must identify themselves as AI. If your app has a chatbot, users must be told they are talking to an automated system. Deepfakes and realistic synthetic content have specific labelling requirements.

Minimal risk — no additional obligations

Most AI systems fall here: spam filters, content recommendation engines, text correction tools, generative AI for internal use without impact on decisions about people. No AI Act-specific requirements beyond existing law.

Who the AI Act applies to

  • Providers: companies that develop AI systems and place them on the EU market, including via API or as a component of another product
  • Deployers: companies that use third-party AI systems in professional contexts with impact on people
  • Importers and distributors: companies bringing to the EU market AI systems developed outside it
  • Companies outside the EU: if your system affects EU users, the AI Act applies regardless of where your company is incorporated

Key deadlines: what is already in force

DateMilestone
August 2024AI Act enters into force
February 2025Prohibited AI systems — already applicable
August 2025Obligations for general-purpose AI models (GPAI) such as GPT-4 or Gemini
August 2026Requirements for high-risk AI systems (most tech companies)
August 2027Additional deadlines for systems already in use before the regulation

Fines: three tiers depending on the infringement

InfringementMaximum penalty
Using prohibited AI systems€35M or 7% of global annual turnover (whichever is higher)
Non-compliance with high-risk system requirements€15M or 3% of global turnover
Providing incorrect information to authorities€7.5M or 1.5% of global turnover

For SMEs, the fixed amounts are proportionally reduced: the lower of the fixed cap and the turnover percentage always applies.

Practical first step: classify your AI systems

Before investing in compliance, the most useful exercise is an inventory of all AI systems your company develops or uses — including those contracted from third parties — and classifying each one according to the AI Act risk pyramid.

If any falls into high risk, the specific requirements kick in: risk management system, technical documentation, activity logging and human oversight. If limited risk, the main obligation is informing users. If minimal risk, nothing AI Act-specific is required.

How Yeeply can help

At Yeeply we work with certified software development companies that are already adapting their processes and architectures to the AI Act. Whether you are building an AI system from scratch or need to audit an existing one, we can connect you with the right technical team for your sector and risk level.

For budget-conscious projects, we also work with specialist teams offering the same technical guarantees at 30 to 40% lower cost. Use the Request a quote button at the top of yeeply.com/en or write to sales@yeeply.com.

Tags