Syntax Station

Insights / AI & Agents

The EU AI Act for Product Teams: What It Means If You Sell in Europe

A practical overview of the EU AI Act for companies building or using AI, including risk categories, transparency duties, timelines and what US, UK and Australian teams selling into Europe should do now.

By Syntax Station Engineering · · 4 min read

Key takeaways

  • The AI Act applies to companies outside the EU if their AI systems are used in the EU.
  • Obligations depend on risk: most business AI is limited or minimal risk, with transparency duties such as telling users they are talking to an AI.
  • High-risk uses, such as hiring, credit scoring and some medical and safety systems, carry heavy requirements for documentation, testing and human oversight.
  • Keep an inventory of your AI features now. It is the foundation for every other step.

The EU AI Act is the first comprehensive AI law from a major economy, and like GDPR, its reach extends well beyond Europe. If your product uses AI and has users in the EU, you need a working understanding of it.

This article is a practical overview, not legal advice. For specific decisions, involve a lawyer who specializes in EU technology regulation.

Who the Act applies to

The Act defines several roles. The two most relevant for software companies are:

  • Providers: companies that develop an AI system and put it on the market under their name. If you build an AI feature into your SaaS product, you are likely a provider.
  • Deployers: organizations that use an AI system in their work. If you use a third-party AI tool to screen job applicants, you are a deployer.

Location does not exempt you. A company in Texas, London or Sydney is in scope if its AI system is used in the EU.

The risk-based structure

Prohibited practices

A short list of uses is banned, including manipulative techniques that cause significant harm, social scoring, and certain uses of biometric identification and emotion recognition in workplaces and schools. Very few legitimate products come close to these.

High-risk systems

These carry the heaviest obligations. They include AI used in hiring and worker management, credit scoring, access to education, essential public services, some critical infrastructure, and AI that is a safety component of regulated products such as medical devices and machinery.

Providers of high-risk systems must implement risk management, data governance, technical documentation, logging, human oversight, accuracy and cybersecurity measures, and a conformity assessment.

Limited risk: transparency duties

Many everyday AI features fall here. The main requirements:

  • Tell people when they are interacting with an AI system, such as a chatbot or voice agent, unless it is obvious.
  • Mark AI-generated synthetic content (images, audio, video) in a machine-readable way.
  • Disclose deepfakes.

Minimal risk

Spam filters, recommendation features, AI in games and most internal productivity tools face no specific new obligations, although general rules such as GDPR still apply.

General-purpose AI models

Companies that train large foundation models have their own obligations around documentation, copyright policies and, for the most capable models, systemic risk. If you build on top of these models through an API, these duties fall mainly on the model provider, but you should know which provider you use and keep their documentation.

Timeline

The Act entered into force in August 2024 and applies in phases: prohibitions and AI literacy from February 2025, general-purpose AI model rules from August 2025, and most other provisions from August 2026, with some product-related high-risk rules later. The European Commission has proposed adjusting some high-risk deadlines, so confirm the current dates before planning.

What to do now

  1. Build an AI inventory. List every AI feature in your products and every AI tool your teams use, what it does and who it affects.
  2. Classify each item by risk level and your role (provider or deployer).
  3. Add transparency where needed. Label chatbots and AI-generated media.
  4. Check for high-risk uses. If any feature touches hiring, credit, education, health or safety, start the documentation and oversight work early. It takes months.
  5. Train your team. The Act expects staff working with AI to have appropriate AI literacy.
  6. Align with GDPR. Many obligations overlap with data protection work you may already be doing.

What about the UK, US and Australia?

The UK has favored a sector-led approach through existing regulators rather than a single AI law. In the US, rules come from a mix of federal guidance, sector regulators and state laws, which continue to change. Australia has published voluntary AI safety standards and updated its privacy law. For companies selling internationally, designing to the EU standard often covers most of what other markets expect.

Building compliant AI from the start

Good engineering practice and compliance point the same way: know what your AI does, test it properly, log its decisions, keep humans in control of important outcomes and be honest with users. Teams that already evaluate their AI features and design for security are most of the way there.

Frequently asked questions

Does the EU AI Act apply to US or UK companies?

Yes, if you place an AI system on the EU market or its output is used in the EU. A US SaaS product with European customers can be in scope even with no EU office.

Is a customer service chatbot high-risk under the AI Act?

Generally no. A typical support chatbot is limited risk. The main duty is transparency: users must be told they are interacting with an AI system unless it is obvious.

When do the AI Act rules apply?

The Act entered into force in August 2024 and applies in stages. Prohibited practices and AI literacy duties applied from February 2025, general-purpose AI model rules from August 2025, and most remaining obligations from 2026 onward. Some high-risk deadlines have been subject to proposed delays, so check the current official timeline.

Related reading