The EU AI Act is in force. What must businesses comply with? Risk levels, deadlines, obligations — a practical guide.
On February 2, 2025, the world's first comprehensive AI law took effect: the EU AI Act. Not as a draft, not as a directive — as a binding regulation directly applicable in all 27 EU member states. If your company uses, develops, or distributes AI, this law affects you. The question isn't whether, but how much.
This article explains the key regulations, puts them in practical context, and shows concretely what you need to do now — especially if you use text analysis or other AI-driven data processing.
The Four Risk Levels: From Prohibition to Freedom
The heart of the EU AI Act is a risk-based approach. Not all AI is regulated equally — the stringency of the rules depends on the potential for harm:
Level 1: Unacceptable Risk (Prohibited)
Certain AI applications are simply banned in the EU. These include:
- Social scoring: Rating systems that classify people based on their social behavior (like China's Social Credit System)
- Emotion recognition in the workplace and educational institutions: AI that recognizes employee or student emotions and bases decisions on them
- Mass biometric surveillance: Real-time facial recognition in public spaces by law enforcement (with narrowly defined exceptions for serious crimes)
- Manipulation of vulnerable groups: AI systems that deliberately manipulate children, elderly people, or people with disabilities
These prohibitions have been in effect since February 2, 2025. There are no transition periods.
Level 2: High Risk (Strict Regulation)
AI systems used in sensitive areas are subject to extensive obligations. These include systems in:
- Personnel selection and applicant management
- Creditworthiness and insurance decisions
- Justice and law enforcement
- Migration and border control
- Critical infrastructure (energy, water, transportation)
- Education (access and assessment)
These systems face strict requirements for risk assessment, documentation, transparency, human oversight, and technical robustness.
Level 3: Limited Risk (Transparency Obligations)
AI systems that interact directly with people must make transparent that they are AI. This covers:
- Chatbots: Users must know they're speaking with an AI
- Deepfakes: AI-generated images, videos, and audio must be labeled as such
- AI-generated text: When texts are produced by AI and published on topics of public interest, this must be disclosed
Level 4: Minimal Risk (No Special Obligations)
The vast majority of AI applications — spam filters, AI in video games, AI-powered music recommendations — are minimally regulated. General laws apply (GDPR, consumer protection), but no specific AI Act obligations.
What's Already Banned — Since February 2025
The first wave of the EU AI Act is already in effect. Companies employing the following practices have been acting unlawfully since February 2, 2025:
- Social scoring of any kind — even if internally labeled as an "employee engagement score" or "customer loyalty index," as long as it aggregates behavioral assessments and bases decisions on them
- Emotion recognition in the workplace — AI systems analyzing employees' facial expressions, voice, or body language to detect emotions (exception: safety-relevant applications like fatigue detection for pilots)
- Predictive policing at the individual level — AI predicting whether a specific person will commit a crime
- Untargeted collection of facial images from the internet or surveillance cameras to build facial recognition databases
Violation: Fines up to 35 million euros or 7% of global annual turnover — whichever is higher.
High-Risk AI: The Strictest Rules
If your AI system falls into the high-risk category, you must meet extensive requirements:
- Risk management system: A documented, ongoing process for identifying, analyzing, and mitigating risks
- Data governance: High standards for training data — relevance, representativeness, accuracy, completeness
- Technical documentation: Detailed description of the system, its functionality, limitations, and intended use
- Logging: Automatic recording of inputs, outputs, and relevant decision parameters
- Transparency toward users: Clear, understandable information about the system's capabilities and limitations
- Human oversight: Design that enables human control and intervention — including the ability to stop the system
- Accuracy and robustness: Proof that the system functions reliably and is protected against manipulation
These requirements apply from August 2026. But: preparation takes months. Companies that don't start now will miss the deadline.
Timeline: When Does What Apply?
The EU AI Act is being rolled out in stages:
- February 2025: Prohibited practices in effect (already active!)
- August 2025: Rules for General Purpose AI (GPAI) — affects providers of foundation models like GPT, Claude, Llama. Transparency obligations, copyright compliance, technical documentation
- August 2026: Main body of the law — high-risk AI obligations, market surveillance, conformity assessments
- August 2027: Extended rules for AI systems embedded in other products (medical devices, vehicles, toys)
Important: Deadlines apply to both placing on the market AND use. Even if you don't develop AI but only deploy it, you're obligated as a "deployer."
What Does This Mean for Text Analysis?
This is where it gets practically relevant for many companies. Your text analysis system's classification depends on its intended use:
Minimal risk (few obligations):
- Text analysis for market research and trend analysis
- Sentiment analysis of public product reviews
- Automatic document summarization
- Topic extraction from customer feedback (anonymized)
Limited risk (transparency required):
- AI chatbots in customer contact — must be identified as AI
- AI-generated texts for marketing purposes — labeling required for public distribution
High risk (full regulation):
- Text analysis for automated personnel selection — e.g., evaluating cover letters or resume screening
- AI-powered creditworthiness assessment based on text data
- Text analysis in criminal justice — e.g., automated evaluation of witness statements
- AI analysis of texts for insurance decisions
Rule of thumb: If your text analysis makes automated decisions that significantly affect people (job, credit, insurance, justice), it's probably high-risk under the AI Act.
Five Practical Steps to Compliance
- Inventory: What AI systems do you use? Create a complete inventory — purchased tools and AI embedded in standard software count too
- Risk classification: Assign each system to a risk level. When in doubt, classify conservatively. The burden of proof is on you
- Build documentation: Start technical documentation now. Describe the purpose, functionality, training data, known limitations, and intended use of each system
- Ensure human-in-the-loop: For high-risk systems, you must demonstrate that humans can monitor and intervene in decisions. Implement appropriate processes
- Establish monitoring: Continuous performance monitoring, drift and bias detection, regular risk reassessments
GDPR + AI Act: Double Obligations, Double Protection
For European companies, the AI Act doesn't come from nowhere — it meets an existing GDPR infrastructure. The two laws complement each other but also partially overlap. Companies must comply with both:
- GDPR: Governs the protection of personal data — legal basis, consent, right of access, right to erasure, data minimization
- AI Act: Governs the safe and trustworthy use of AI — risk assessment, transparency, human oversight, technical robustness
The overlap is significant: when an AI system processes personal data (and almost all do), both regulatory frameworks apply simultaneously. Article 22 GDPR (automated individual decisions) and the AI Act's high-risk requirements make similar but not identical demands.
The good news: companies with solid GDPR processes already have a strong foundation. Data minimization, purpose limitation, and transparency are principles central to both laws.
The less good news: the AI Act goes beyond the GDPR in many respects — particularly in technical documentation, risk assessment, and training data requirements. GDPR compliance alone isn't enough.
Conclusion: Regulation as Competitive Advantage
The EU AI Act is often criticized as a bureaucratic monster. And yes, the compliance requirements are substantial. But the alternative — an unregulated AI market where trust erodes and individual scandals damage entire industries — would be worse for European businesses.
Companies that take the AI Act seriously early will discover: compliance isn't a cost center — it's a trust seal. In a world where AI trust is becoming scarce, demonstrable regulatory compliance is a competitive advantage. Customers, partners, and investors will increasingly ask about AI Act compliance — just as they ask about ISO certifications and GDPR compliance today.
Don't wait for August 2026. Preparation takes longer than you think. And the companies that are compliant first will be the first to earn their customers' trust.
Using AI text analysis and want to know how the AI Act affects you? Talk to our team — we'll help you assess your situation.


