§ Guide · EU AI Act

    The EU AI Act: from law to practice for AI-driven enterprises.

    The legal frameworks for artificial intelligence are set in stone. For tech leads and CIOs, the AI Act is not a halt on innovation, but a mandatory architectural requirement: AI Agents and LLM applications demand a design that guarantees transparency, security, and legal viability from day one.

    01 — Timeline

    What is the AI Act and when does it apply?

    The EU AI Act formally came into effect in mid-2024 and introduces a phased rollout. Instead of an abrupt transition, you face hard deadlines per risk level and technology type. Therefore, the compliance trajectory requires system adjustments right now.

    1 Aug 2024The AI Act officially came into effect.
    2 Feb 2025Ban on systems with unacceptable risk and enforcement of the AI literacy requirement (Art. 4).
    2 Aug 2025Obligations for General-Purpose AI (GPAI) models such as LLMs take effect, including governance structure and the fine regime.
    2 Aug 2026The majority of high-risk obligations (Annex III) come into force, including transparency obligations (Art. 50).
    2 Aug 2027Enforcement of obligations for high-risk systems serving as safety components in legally regulated products (Annex I).

    02 — Risk categories

    The four risk categories

    01

    Unacceptable risk

    Systems banned due to incompatibility with fundamental EU rights. Examples include social scoring, cognitive behavioural manipulation, and remote real-time biometric identification (such as facial recognition) in public spaces by law enforcement, except in highly specific exceptional cases.

    02

    High risk

    AI systems with a significant impact on safety or fundamental rights (Annex III). Think of applications in recruitment, HR, education, credit scoring algorithms, critical infrastructure, and law enforcement. Heavy compliance requirements apply here, such as mandatory logging, strict data governance, and formal risk assessments.

    03

    Limited risk

    This encompasses the transparency obligations from Article 50. Users must explicitly know they are interacting with an AI system. This affects chatbots, automated AI Agents, and systems generating synthetic content like deepfakes or generated text and audio, which must be consistently labelled.

    04

    Minimal risk

    Systems with no significant impact, such as spam filters or basic recommendation algorithms. The AI Act imposes no strict requirements here, although voluntary codes of conduct are highly encouraged.

    03 — GPAI

    General-purpose AI (GPAI) and systemic risk

    Alongside the risk approach, the Act dictates specific rules for General-Purpose AI (GPAI) models, such as large Foundation Models. A model is classified as having a 'systemic risk' when the computing power required to train it exceeds the threshold of 10^25 FLOPs.

    All GPAI providers must maintain technical documentation, enforce an up-to-date copyright policy, and provide a substantive summary of the training data. For models with systemic risk, strict cyber security requirements, structured red teaming, model evaluations, and acute incident reporting are added.

    Are you integrating an existing GPAI model into your own application or enterprise AI Agent? Ensure your vendor is compliant. As a downstream deployer (or even a new provider, in the event of heavy fine-tuning), you remain responsible for the specific context in which you release the model in practice.

    04 — Enforcement

    Fines and enforcement

    Unacceptable AI practices (Art. 5)maximum of €35 million or 7% of global annual turnover
    Violation of other obligations (high-risk, GPAI)maximum of €15 million or 3% of global annual turnover
    Providing incorrect information to authoritiesmaximum of €7.5 million or 1% of global annual turnover

    Note: for start-ups and SMEs, the lower amount is generally applied as the maximum; national oversight falls partly to the Data Protection Authority and the RDI, while at the European level, the EU AI Office monitors GPAI models.

    05 — Roles

    Provider or deployer — what are you?

    Responsibilities under the AI Act are not equal for all parties, but directly depend on the role a company plays in the life cycle of the AI system. That determines which checklist you must tick off.

    01

    Provider

    The party that develops the AI system or GPAI model, or has it developed, and places it on the market or puts it into service under its own name or trademark. This bears the heaviest (High-Risk/GPAI) obligations.

    02

    Deployer

    The organisation deploying the AI system operationally under its own responsibility in a professional context. Personal, non-professional consumption does not fall under Deployer duties.

    03

    Importer / distributor

    Companies bringing systems from outside Europe onto the internal EU market perform a control function and must ensure the original provider has complied with the AI Act prior to market introduction.

    04

    Note: a deployer can become a provider

    Do not underestimate this. When you, as a deployer, make a substantial modification to a trained model, market the AI system under your own brand name, or use it for a fundamentally different and high-risk purpose, your legal status upgrades to 'provider'. Consequently, you inherit the corresponding heavy compliance obligations.

    06 — Practical

    What does this mean for your AI Agents in production?

    1. 01

      Immediately classify every AI system: formally record the risk category, the supplier role, and the use case per implementation.

    2. 02

      Ensure AI literacy in accordance with Art. 4, a broad obligation already in effect since 2 February 2025; employees processing data via Agents or managing these systems must be adequately trained.

    3. 03

      Focus on data governance and logging: in high-risk scenarios, dataset decisions, the training process, and operational output must be inspectable and explicable in audit logs.

    4. 04

      Implement the transparency rules of Art. 50: end users, both internal and external, must be informed immediately that they are speaking with an AI Agent or chatbot rather than a human.

    5. 05

      Guarantee human oversight: for high-risk functionality, an Agent must never be the final, unchecked actor. Human-in-the-loop is now a mandatory design principle.

    6. 06

      Record the origin of the data: required copyright policy-making and transparency around training data summaries is a strict GPAI requirement for your foundation models.

    7. 07

      Set up processes for post-market monitoring and escalation; the law thus enforces acute incident reporting procedures for failing AI Agents.

    07 — Our role

    How TAG helps with this

    At The Automation Group, we build advanced, enterprise-grade AI Agents primarily based on the principle of compliance-by-design. We do not fix audits with an afterthought checklist; instead, we organically align the AI infrastructure architecture with normative frameworks like the AI Act, GDPR, and NIS2 directives.

    In concrete terms, a project starts with an AI Act readiness assessment and accurate system classification. To eliminate data risks and third-party exposure, we also deploy models on-premise or in a private cloud via OpenClaw for pure data residency. Furthermore, we push our Agents into production with strict human-in-the-loop triggers, automated integrity evaluations (evals), and flawless audit logs. Additionally, we provide the required Art. 4 AI literacy training tailored for your operational and technical teams.

    Want to know where you stand with the AI Act?

    The implementation deadlines are passing in rapid succession. Ensure you are not caught off guard and map out whether your AI poses compliance risks.

    Frequently asked questions

    Does the AI Act apply to my company if I deploy AI but do not develop it?

    +

    Yes, in that case you are a 'deployer'. Deployers have direct obligations too. Do not just think about deploying high-risk systems (where usage monitoring and oversight are required), but also Article 50: your implementation is only compliant once your clients or employees clearly understand they are interacting with an AI bot.

    What is AI literacy (Art. 4) and when does it apply?

    +

    This provision has been in effect since 2 February 2025. It mandates that organisations demonstrably do their best to provide their employees, who work with or via AI systems, with sufficient technical theory and context, so algorithms are operated with understanding and risk awareness.

    Can I continue to use ChatGPT or Claude at work?

    +

    Yes, in principle you may continue to deploy enterprise services from GPAI providers, provided you respect your deployer duties. Check vendor compliance, establish clear policy regarding data classifications (especially when API logs are trained on by the vendor), and stay alert regarding automated decision-making on the shop floor.

    What if I fine-tune an open-source model?

    +

    If you make a substantial modification and independently push that fine-tuned system to a high-risk environment or commercialise it, your legal role shifts from deployer to 'provider'. The documentation duty, certification, and risk management requirements will then rest squarely on your shoulders.

    Who oversees enforcement in the Netherlands?

    +

    Nationally, the Data Protection Authority (AP) has been designated as the coordinator. They are supported by specific sectoral regulators such as the Digital Infrastructure Authority (RDI), DNB (for finance), and the ACM. At the overarching level of generic GPAI models and systemic entities, oversight is centralised in Brussels at the EU AI Office.

    How does the AI Act relate to the GDPR?

    +

    Both regimes operate alongside one another, cumulatively and therefore applying simultaneously. Whereas the GDPR safeguards privacy and data processing at the level of individual personal datasets, the AI Act imposes obligations on the intrinsic properties, safety assessments, governance, and transparency surrounding the underlying technical system itself.