The EU AI Act is about to become much more visible for businesses that sell to, operate in or serve customers in the EU. From 2 August 2026, many of its rules will apply, bringing new questions about how AI is used in products, services and everyday business processes. For a company using AI in areas such as pricing, fraud checks, customer support, recruitment, demand planning or order management, the Act makes AI governance not just a technology issue, but a boardroom issue too.

What Is the EU AI Act?

The EU AI Act is the European Union’s legal framework for artificial intelligence systems placed on the EU market, put into service in the EU or used in ways that produce outputs used in the EU. It classifies AI systems by risk level and sets obligations based on how those systems may affect safety, health and fundamental rights. For businesses, this means understanding where AI is already being used across the organisation and which systems may fall into different risk categories.

Officially known as Regulation (EU) 2024/1689, the Act entered into force on 1 August 2024. The next major phase becomes applicable on 2 August 2026, although some requirements started to apply in 2024 and 2025, including rules on prohibited AI practices, AI literacy and general-purpose AI models.

Key Takeaways

  • The EU AI Act is now a business issue, not just a technology issue. From 2 August 2026, many of its rules apply, affecting how businesses use AI in products, services and processes linked to the EU.
  • The Act uses a risk-based approach. AI systems are treated differently depending on their potential effect on safety, health and fundamental rights, with stricter obligations for higher-risk uses.
  • UK businesses can still fall within scope. Companies outside the EU may be affected if they place AI systems on the EU market, put them into service in the EU or use AI outputs in the EU.
  • Transparency and evidence matter. Businesses may need to show where AI is used, how it is governed and what records support AI-assisted decisions, especially for higher-risk systems.

Finance Futures: Tomorrow’s Vision

Discover how tokenised money and real-world assets are rewiring settlement, how confidential computing and Proof of Personhood restore trust, and how AI agents, quantum acceleration and wallet-first experiences are redefining finance.
Download the report (opens in a new tab)
Finance Futures: Tomorrow's Vision report

The EU AI Act Explained

The EU AI Act takes a risk-based approach. In simple terms, the more potential harm an AI system could cause, the more scrutiny it attracts. Some AI practices are banned outright, while high-risk systems face strict rules on risk management, data quality, logging, documentation, transparency, human oversight, accuracy, robustness and cybersecurity.

Lower-risk uses may still come with transparency duties, such as telling people when they are interacting with AI or making some AI-generated content identifiable. For many organisations, the challenge isn’t just understanding these categories, but identifying where AI is already embedded in business processes and making sure the right governance is in place.

The Scope of the EU AI Act

The EU AI Act matters because it can apply to organisations based outside the EU. A UK company may still be in scope if it sells an AI-enabled product or service to EU customers, runs AI in an EU operation or uses AI outputs in the EU.

That makes the Act relevant not only to software developers, but also to any business using AI through third-party applications, ecommerce platforms, HR tools, finance systems or customer service software. This often means involving multiple teams (not just IT or Legal) but also Finance, HR, Operations and Procurement to understand where AI is being used and who is responsible for overseeing it. The practical question for many leaders will be: where do we use AI, what role do we play and what proof do we have that it is being managed responsibly?

Categorisation of AI Systems

The EU AI Act sorts AI systems by risk level, so the rules match the potential harm to people, safety and fundamental rights. The main categories include unacceptable risk, high-risk, limited or transparency risk, and minimal or no risk.

  • Unacceptable risk: Certain AI practices are prohibited because they pose an unacceptable risk to people’s safety, livelihoods or fundamental rights. Examples include certain forms of harmful manipulation, social scoring and biometric categorisation.
  • High risk: High-risk AI systems are permitted but are subject to strict requirements because of their potential impact on people’s safety or fundamental rights. Examples can include certain AI systems used in employment, education, essential services, migration, critical infrastructure and safety-related components of products.
  • Transparency risk: Certain AI systems are subject to specific transparency requirements where people need to know that AI is being used. This can include systems such as chatbots, as well as certain AI-generated or manipulated content. Depending on the use, businesses may need to inform people that they are interacting with AI or ensure that AI-generated content is identifiable.
  • Minimal to no risk: Most AI systems fall into this category and are not subject to additional obligations under the AI Act. Examples can include AI-enabled video games and spam filters.

Requirements for High-Risk AI

High-risk AI systems carry more detailed requirements because their outputs can affect people’s opportunities, rights or safety. The Act focuses on making these systems traceable, transparent and subject to human oversight.

Obligations for AI Providers

Providers of high-risk AI systems must meet requirements before those systems are placed on the market or put into service. These include risk assessment, high-quality data sets, activity logs, technical documentation, clear deployer information, human oversight, accuracy, robustness and cybersecurity.

Standards for Compliance

Harmonised European standards are expected to give providers a practical route for meeting high-risk AI requirements. The Commission says standardisation work is underway, including a quality management system standard for EU AI Act regulatory purposes.

Penalties for Non-Compliance

Penalties vary by infringement and can reach €35 million or 7% of worldwide annual turnover for the most serious breaches. Other breaches may carry fines of up to €15 million or 3%, or €7.5 million or 1% for supplying incorrect, incomplete or misleading information.

6 Reasons the EU AI Act is Important

The EU AI Act is the first-ever legal framework on AI, which addresses the risks of AI and positions Europe to play a leading role globally. At the centre, the EU AI Act aims to facilitate the safety and fundamental rights of organisations and individuals, while also fostering AI adoption and innovation within the EU. The EU AI Act’s regulations are important for the following reasons:

  1. Better visibility into AI use. Many businesses already use AI in more places than they realise. A review can reveal AI-assisted features in finance, HR, sales, service, fulfilment, supply chain and reporting tools.
  2. Clearer accountability. The Act distinguishes between providers, deployers, importers, distributors and other roles. Knowing which role applies helps teams understand what they may need to do.
  3. More useful supplier conversations. Businesses can ask vendors what AI features their products include, how those features are updated and what documentation is available.
  4. Stronger records. High-risk AI systems may require logs, documentation and review processes. Good record-keeping can make audits, customer questions and regulatory checks easier to handle.
  5. Greater customer confidence. Businesses that can explain how AI is used and reviewed are better placed to build trust with EU customers and partners.
  6. Lower operational risk. Classifying AI by risk level can help teams avoid prohibited uses, spot sensitive applications and decide where more oversight is needed.

Stay Current with EU AI Act Expectations

For businesses selling to the EU, the EU AI Act should not sit in a legal folder that no one opens. AI can appear in the tools used by finance, commerce, HR, sales, operations and service teams, sometimes without being labelled as a separate AI product. Understanding the Act means connecting legal duties with data, process ownership, supplier management and reporting.

  1. Check the EU connection. Work out whether AI systems are sold into the EU, used in the EU or produce outputs used in the EU. This is a key question for any company with EU based employees, EU based suppliers, EU based investors and EU based customers.
  2. Map AI across the business. Identify AI tools and AI-assisted features across the business. Identify where AI tools or AI-assisted features are being used and what it is being used to do.
  3. Classify AI use by risk. Determine whether AI systems and practices fall into the unacceptable-risk, high-risk, transparency-risk or minimal-to-no-risk categories, and identify which requirements apply to each use case.
  4. Understand your role. A business may have different duties depending on whether it develops an AI system, uses a third-party tool, distributes a product or sells something with AI included.
  5. Review transparency duties. Any company interacting with AI, making AI-generated content or using AI on any level needs to disclose usage and scale.
  6. Keep evidence accessible. Policies, approvals, vendor materials, logs, data records and review notes should be easy for the right teams to find when customers, auditors or regulators ask questions.

Implement AI Governance with NetSuite ERP

NetSuite ERP can support AI governance by helping businesses manage financial, operational and transactional data in one cloud business management solution. NetSuite ERP covers areas such as accounting, inventory, production, supply chain and warehouse operations, giving teams a central place to manage business information and processes.

That matters because AI governance depends on reliable records. NetSuite helps organisations establish the visibility, governance and auditability needed to support AI oversight. By centralising financial and operational data, maintaining audit trails and providing reporting across core business processes, it gives teams a stronger foundation for demonstrating responsible AI governance. For companies with EU based employees, EU based suppliers, EU based investors and EU based customers, those capabilities can help connect AI oversight with the finance, operations and reporting processes teams already use every day.

The EU AI Act changes the way businesses need to think about AI in products, services and internal workflows that touch the EU. As more rules apply from 2 August 2026, leaders should know where AI is used, which risk category it falls into and what evidence supports its use. NetSuite ERP can help by giving teams a stronger operational and financial foundation for AI governance.

EU AI Act FAQs

What is the EU AI Act 2026?

The “EU AI Act 2026” usually refers to 2 August 2026, when many of the Act’s rules become applicable. Some requirements began earlier, including rules on prohibited AI practices from 2 February 2025 and general-purpose AI obligations from 2 August 2025.

Is the EU AI Act mandatory?

Yes. The EU AI Act is a regulation, so its rules apply directly across EU member states once the relevant provisions are in application.

Will the EU AI Act apply to the UK?

The UK is not an EU member state, but UK companies may still fall within the Act if they place AI systems on the EU market, put them into service in the EU or use AI outputs in the EU, even if the AI is used outside the EU.

What are the penalties for EU AI Act non-compliance?

Penalties depend on the type of infringement, the role of the business and the facts of the case. Businesses should seek legal advice to understand their exposure under the relevant provisions.

Who should own EU AI Act compliance inside a business?

Ownership usually needs a cross-functional group involving legal, compliance, IT, finance and business process owners. That structure helps connect AI policy with systems, data, supplier reviews and everyday decisions.