AI regulation
Does the EU AI Act apply to our company?
In short
Almost certainly yes, to some degree. The EU AI Act applies to anyone who provides or uses AI systems in the EU, regardless of company size. What is required depends on your role — provider or deployer — and on the system’s risk level. Since 2 August 2026, transparency duties apply to AI that interacts with people or generates content, together with the AI-literacy duty for staff. The heavy high-risk obligations were postponed to December 2027 (Annex III) and August 2028 (Annex I) by the Digital Omnibus regulation.
Last reviewed: September 2026
Step 1: Which role do you have?
The Act distinguishes providers (who develop an AI system or place it on the market under their own name) from deployers (who use an AI system in their operations). A company that builds an AI feature into its product is the provider of that feature. A company using ChatGPT, Copilot or an AI-based recruitment tool is a deployer. Many companies are both.
- You build a model or an AI feature that customers use: provider.
- You use a purchased AI tool in your business: deployer.
- You build on a general-purpose model (GPT, Claude, Mistral) and put your own name on the service: provider of the AI system, even though you did not train the model.
Step 2: Which risk level does the system have?
| Risk level | Examples and what applies |
|---|---|
| Prohibited | Social scoring, manipulative AI, biometric categorisation of sensitive traits. Banned since 2 February 2025. |
| High risk (Annex III) | AI in recruitment, credit scoring, education, critical infrastructure. Risk management, data governance, documentation, human oversight, logging. Applies from 2 December 2027. |
| High risk (Annex I) | AI as a safety component in products under other EU law, e.g. medical devices, machinery. Applies from 2 August 2028. |
| Limited risk | Chatbots, AI-generated content, deepfakes. Article 50 transparency duties since 2 August 2026; marking of AI-generated content from 2 December 2026. |
| Minimal risk | Spam filters, recommendations in internal software. No specific duties beyond AI literacy. |
What already applies to everyone
- AI literacy (Article 4): staff using AI systems must have sufficient knowledge. In force since 2 February 2025, fully applicable since 2 August 2026. Document the training you provided.
- Transparency (Article 50): users must be told when they interact with an AI, and AI-generated content must be marked. Applies since 2 August 2026.
- AI system register: not a formal duty for minimal risk, but the prerequisite for answering every other question. List which systems you use, for what, with which data.
- GDPR applies in parallel: personal data in prompts, training or output needs a legal basis and often an impact assessment.
If you build AI features into your product
- 1Classify the feature against Annex III. Recruitment, credit scoring, education and workforce management are the most common cases for SaaS companies.
- 2If high risk: start the risk-management system, technical documentation and logging now, even though the duties apply from 2027. Public-sector customers already ask.
- 3If limited risk: implement marking and user information, and document how.
- 4Write down which general-purpose model you build on, its terms and which data you send to it. That is the first question in every supplier assessment.
- 5Consider ISO/IEC 42001, the AI management system standard. Not a legal requirement, but the structured way to show you are in control.
How Isodora helps with the AI Act
Isodora reproduces the ISO/IEC 42001 requirement text under licence from SIS and links the AI Act’s articles to controls, owners and evidence — in the same management system as ISO 27001 and GDPR, so AI governance does not become a parallel project.
AI register with role and risk level
List every AI system, your role, its risk level and the data involved. The foundation for every other duty.
Requirements mapped to controls
Article 4, Article 50 and the Chapter III high-risk duties are linked to concrete controls with owners and evidence.
Literacy and transparency as evidence
Training logs and marking procedures are recorded so you can show the duties that apply today are met.
ISO 42001 when customers ask
The same material that satisfies the Act builds the AI management system under ISO/IEC 42001.
Isodora structures and evidences your AI Act work. Whether a system is high risk is your assessment, and in case of doubt should be checked with legal counsel.
Frequently asked questions
- Does the AI Act apply to us if we only use ChatGPT?
- Yes, as a deployer. The duties are then limited: AI literacy for staff, transparency if you let AI communicate with customers or generate content, and the GDPR rules for personal data in prompts. No notification or registration is needed.
- When do the high-risk obligations start to apply?
- Under the Digital Omnibus regulation (EU) 2026/1744, in force since 27 July 2026, the obligations for Annex III high-risk systems apply from 2 December 2027 and for Annex I from 2 August 2028. The AI-literacy and transparency duties already apply.
- Which authority supervises in Sweden?
- The inquiry SOU 2025:101 proposes the Swedish Post and Telecom Authority (PTS) as coordinating market surveillance authority and the Swedish Authority for Privacy Protection (IMY) for prohibited systems. Check the current status with IMY and PTS, since the Swedish supplementary act may have changed after this page was reviewed.
- Do we need ISO 42001 certification?
- No, the Act requires no certification. ISO/IEC 42001 is, however, the structured way to show customers and authorities that you run a working AI management system, and most of its controls overlap the Act’s duties.