What are the EU AI Act obligations for companies?

EU AI Act obligations depend on two variables: your role (provider, deployer, importer, distributor) and your system’s classification (unacceptable risk is banned; then high, limited and minimal risk). Most companies are deployers — they use AI systems supplied by third parties.

The EU AI Act (Regulation (EU) 2024/1689) defines four risk levels. Unacceptable risk (Article 5): prohibited practices. High risk (Article 6 and Annex III): reinforced obligations. Limited risk: transparency obligations. Minimal risk: no binding obligations.

For a deployer of a high-risk system, the main obligations are set out in Article 26: use the system in line with the provider’s instructions, ensure human oversight, monitor operation, report serious incidents, keep automatic logs, inform affected persons, and — in certain cases — carry out a Fundamental Rights Impact Assessment (FRIA, Article 27).

For a provider of a high-risk system, the obligations are heavier (Articles 9 to 21): a risk-management system, data governance, technical documentation, automatic record-keeping, transparency towards deployers, ex-ante conformity assessment, CE marking, registration in the EU database, a declaration of conformity, and post-market monitoring.

For limited-risk systems (chatbots, deepfakes, AI-generated content): a transparency obligation (Article 50) — users must know they are interacting with an AI or that content is AI-generated. The preparation priority before 2 August 2026: map your AI systems, classify each against Annex III, identify your role for each, and prioritise bringing high-risk systems into compliance.

Related Information

  • Four risk levels: unacceptable, high, limited, minimal
  • Roles: provider, deployer, importer, distributor
  • High-risk deployer: Article 26 + FRIA (Article 27) in certain cases
  • High-risk provider: Articles 9–21 + ex-ante conformity assessment
  • Transparency (limited risk): Article 50
  • 2026 priority: inventory, classification, compliance plan

Expert Insight

Start from your role, not the technology: most organisations are deployers, and Article 26 is a far shorter list than the provider duties in Articles 9–21 — knowing which hat you wear scopes the whole programme.

Explore related training

Browse all: Cybersecurity

Browse all FAQs →

Full knowledge base

We use cookies to improve your experience

Necessary cookies are always active. You can accept, reject non-essential cookies, or customize your preferences.

What are the EU AI Act obligations for companies? – EU AI Act obligations for companies – ISO 42001 Lead Implementer |…