We value your privacy

We use necessary cookies to run the site and, with your consent, analytics and marketing cookies to improve it. You can change your choice anytime. Privacy Policy

  • Security
  • Pricing
Book a scoping call
Back to guides
Guides4 min read

What Does the EU AI Act Actually Require of Companies?

Which duties actually apply when a company uses AI — and from when. An honest overview of GDPR, AI-literacy, transparency and high-risk obligations.

July 20, 2026·Qadar AI
What Does the EU AI Act Actually Require of Companies?
The EU AI Act bans no company from using ChatGPT, Copilot & co., and simple, everyday AI use carries few mandatory product obligations. So it is tempting to conclude there is nothing to do. That conclusion is wrong. Three duties apply across every company that uses AI — and the GDPR applies anyway, from the very first record an employee copies into a tool. This guide sets out, honestly, which obligations really apply, to whom, and from when — so you can tell the parts that touch you from the parts that don't.

What actually applies

Most companies that use AI (ChatGPT, Copilot, Gemini, Claude and the like) build nothing — they are deployers, not providers. Even so, the following obligations are in scope. Only one of them is the high-risk regime everyone worries about; the rest apply regardless of risk tier.

ObligationWho it applies toWhenWhat it means
GDPR (data protection)Every company processing personal dataAlways — no transition periodEmployees who put customer or personal data into an unapproved AI tool process it with no legal basis, no data-processing agreement and no record.
AI Act Art. 4 — AI literacyEveryone who uses AI — no exceptionSince 02 Feb 2025Staff must have sufficient AI literacy: a basic grasp of the opportunities and risks of the tools they use.
AI Act Art. 5 — prohibitionsEveryoneSince 02 Feb 2025Certain practices are banned outright — e.g. emotion recognition in the workplace, or social scoring.
AI Act Art. 50 — transparencyAnyone running chatbots or publishing AI contentFrom 02 Aug 2026Label chatbots as AI; visibly mark AI-generated or AI-edited content.
AI Act high-risk (Annex III)Only for a high-risk use caseFrom 02 Dec 2027Human oversight, logging, informing affected people — triggered e.g. by AI in recruiting (see below).
Confidentiality (professional & contract law)Firms under client or contractual confidentialityAlwaysPutting client or customer data into an AI tool can breach confidentiality and trade-secret obligations — independent of the GDPR.

The point many miss

The AI Act has transition periods. The GDPR does not.

The GDPR applies to every processing of personal data — from the moment someone copies a customer name, an email address or a contract into an AI tool. This is the duty that hits every company immediately, regardless of size, industry or AI-Act risk tier. And in practice the trigger is rarely the regulator: it is the first customer or auditor who asks you to show what your team is sending where. "The high-risk rules are deferred to 2027" is true for the high-risk rules only — it says nothing about the obligations that are already live today.

High-risk — for whom, really

The high-risk regime is narrower than the headlines suggest, and Annex III is an exhaustive list. Three groups are worth knowing:

  • Broadly affected — HR & worker management. This is the widest hit. Not just recruiting and CV screening, but also decisions on promotion, task allocation, and monitoring or evaluating employee performance. Almost any company runs at least one of these.
  • Industry-specific. Creditworthiness / credit scoring (anyone who assesses credit or grants lending) and risk assessment or pricing in life and health insurance. Narrow, sector-bound.
  • Not high-risk. Customer support chatbots and lead qualification are generally limited-risk — here only the Art. 50 transparency duty applies, not the high-risk regime. Framing them as high-risk overstates the case (though the GDPR point still applies to any personal data they touch).

If AI does slip into your HR decisions, the heaviest work — the conformity assessment — sits with the tool's provider. A company using AI there becomes a high-risk deployer and must, operationally: ensure human oversight, run the system per the provider's instructions, monitor operation and suspend it on anomalies, keep the automatically generated logs for at least six months, and inform affected people (and, before workplace deployment, employees and the works council). For the classification mechanics — the two Article 6 routes, every Annex III area, and the exemption filter — see our companion guide on which AI systems are high-risk.

What this means in practice

For most companies the real question isn't "Are we regulated?" but: Do we know which AI tools our team uses — and with what data? And could we prove it if someone asked? Usually the honest answer is no.

That gap — real-time visibility, policy enforcement, and an audit log over AI usage — is what Qadar AI Shield is built to close: discover which AI tools are in use and with what data, govern or block them company-wide, and keep the usage records an auditor would ask for. And where Art. 50 requires you to label AI-generated content or chatbots, Disclose handles that transparency layer. Not because a law forces the purchase — but because you cannot control what you cannot see. If you'd like to talk through your specific situation, get in touch.

Download the one-page overview

Want a printable summary to share internally or with counsel? Download / print the one-page overview — the same obligations, timeline and high-risk breakdown on a single page.


This is not legal advice. This guide is for general guidance only. Regulatory statements reflect the EU AI Act as amended by the Digital Omnibus, which is adopted, with publication in the EU Official Journal still pending at the time of writing — deadlines may change. Seek qualified legal counsel for a binding assessment of your specific case.

Last verified: 20 July 2026.

On this page

  • What actually applies
  • The point many miss
  • High-risk — for whom, really
  • What this means in practice
  • Download the one-page overview

Share

Product and governance updates — see our privacy policy.

Related guides

The EU AI Act: A Practical Compliance GuideGuide

The EU AI Act: A Practical Compliance Guide

A practical guide to the EU AI Act for operators: the risk tiers, the compliance timeline, who it applies to, the AI literacy duty, and how it meets GDPR.

Read more
Which AI Systems Are High-Risk Under the EU AI Act?Guide

Which AI Systems Are High-Risk Under the EU AI Act?

Which AI counts as high-risk under the EU AI Act? The Article 6 rules, all Annex III use cases, the 6(3) filter, and what deployers must do — with sources.

Read more
Deployer (EU AI Act)Glossary

Deployer (EU AI Act)

A deployer under the EU AI Act is any organization using an AI system under its own authority. Learn the deployer's duties, how it differs from a provider, and more.

Read more

Put this guide into practice with Qadar AI

A product specialist will reply within one business day

Book a demo

Subscribe to our newsletter

Product and governance updates — see our privacy policy.

AI security and control for every model your team uses.

Built in Dubai. Designed for teams operating across regions, models, and regulatory environments.

  • Product

    • Shield Web
    • Shield Control
    • Shield Desktop
    • Shield Mobile
    • Pricing
    • Download
  • Solutions

    • For CISOs
    • For Operations
    • For AI Teams
  • Use Cases

    • AI Governance
    • AI Agent Security
    • LLM Access Control
    • Secure AI Deployment
    • Enterprise Operations
    • Financial Services
    • HR & Recruiting
  • Resources

    • Help Center
    • Blog
    • Guides
    • Glossary
    • Changelog
    • Compare
    • FAQ
  • Company

    • About
    • Careers
    • Security & Trust
    • Contact
  • Tools

    • Disclose
    • AI Risk Calculator
    • EU AI Act Checker

© 2026 Qadar AI. All rights reserved.

  • ·Legal
  • ·Privacy
  • ·Terms
  • ·Partner Terms
  • ·GDPR / DPA
  • ·