Back to other guides and reports

Preparing for the EU AI Act: A practical guide

October 8, 2025

TLDR; The EU AI Act has officially come into force, making it the world’s first rulebook for safe, responsible AI. But with many details still unclear, businesses are left asking what to do next. This guide unpacks what the Act really means, the actions to take now, and how you can make compliance work in your favour. We'll cover: 

  • How the EU AI Act categorises risk levels and what obligations apply to each
  • Key deadlines and enforcement timelines every organisation should know
  • What compliance will cost, and how to prepare budgets and governance structures
  • How to build trust with customers through transparent, responsible AI

Missed our webinar on the EU AI Act? Watch it here.

AI adoption is in full swing


Within just a handful of years, around half of the world's businesses have adopted AI. The pace of uptake has beenextraordinary; a 2025 AWS report even predicts that Europe could reach near-universal AI adoption by 2030, faster than the adoption of mobile phones or the dawn of the internet.

Until now, much of this growth has happened without clear rules. It's a familiar story: when GDPR arrived in 2018, it followed years of near-total freedom online, where personal data was gathered with little oversight. The EU AI Act is designed to avoid that same lag, putting guardrails in place while the technology is still in its rapid ascent.

Breaking down the EU AI Act


The EU AI Act has been finalised and published, but many of the practical details, such as how it will be enforced and the guidance businesses will need to follow, are still being ironed out. Its purpose is to ensure that AI used in or affecting Europe is safe, transparent, and respects people's rights, without hindering innovation.

The rules follow a risk-based approach: the higher the potential harm, the stricter the obligations. They don't just apply to tech companies building AI, but also to those selling, importing, or deploying it.

Geography doesn't offer an escape clause either: if an AI system impacts people in the EU, the rules apply, regardless of the provider's location. The Act builds on the EU's broader data protection framework, so companies need to consider how AI compliance and data compliance work together.


Understanding the EU AI Act penalties

  1. 1.5% of global annual turnover, or up to €7.5 million, whichever is higher, for disclosing inaccurate information.
  2. 3% of global annual turnover, or up to €15 million, whichever is higher, for violations relating to high-risk systems.
  3. 7% of global annual turnover, or up to €35 million, whichever is higher, for violations of unacceptable risk.

Europe now faces a global race for leadership in AI, with the United States pushing a more hands-off approach and China rapidly scaling government-backed innovation. At the same time, geopolitical tensions are putting pressure on the assumptions that shaped the AI Act: that Europe can set global standards as it did with GDPR, that strong regulation can build trust without stifling innovation, and that digital independence is possible in a market dominated by U.S. and Chinese players.

Not everyone is convinced. In an open letter, the leaders of 44 major European firms, including Airbus and BNP Paribas, urged Commission President Ursula von der Leyen to introduce a two-year pause to the Act, warning that unclear and overlapping regulations risk undermining the bloc's competitiveness in the global AI race.

The costs of compliance requirements will weigh most heavily on smaller firms, though they vary depending on the risk level of the AI system. Lower-risk tools face lighter obligations such as transparency requirements, while high-risk systems must meet stricter rules around human oversight, auditing and documentation.

For SMEs, those obligations can escalate sharply: estimates suggest the costs to stay compliant can range from tens of thousands annually for high-risk models to several hundred thousand when a full QMS (quality management system) is required. Larger players can absorb these demands with established legal teams and deeper pockets, but for startups and medium-sized businesses the burden could divert resources away from innovation.

Investors, meanwhile, remain uncertain: with many details of enforcement still unsettled, European AI ventures can appear riskier, making capital more likely to flow toward regions where the regulatory path is clearer.

Tracking the EU's legislative journey

April 2021

The European Commission unveils a proposal for a new Artificial Intelligence Act.

December 2022

The Council has adopted its common position ('general approach') on the AI Act.

June 2023

The Parliament adopts their negotiation position for the draft AI Act.

June 2023 - December 2023

Final AI Act negotiations occur between the Council, Commission, and Parliament. A provisional agreement to finalize the proposed rules in reached in December 2023.

August 2024

The Artificial Intelligence Act officially came into force on 1 August 2024.

February 2025

Prohibition on 'unacceptable risk' AI systems will apple.

August 2025

Several obligations to general-purpose AI will apply.

August 2026

The final AI Act takes effect in its entirety.

There's also a strong case for why the Act could strengthen, rather than weaken, Europe's hand. Consumer expectations around AI are nuanced.

Intrum's latest European Consumer Payment Report shows that nearly half of customers (48%) say it makes no difference whether AI is involved in a payment process as long as it is smooth and hassle-free, and almost a third (29%) even feel less judged when agreeing payment plans with an AI bot than with a human being.

At the same time, more than half of European consumers (52%) remain concerned about how their personal data is handled by AI systems. This trust gap is exactly what the AI Act is designed to address, by setting clear standards on transparency, accountability and explainability.

For businesses that have already prioritised privacy, fairness and customer care, these rules are unlikely to be disruptive; rather, they validate existing practices. In this way, the Act can serve less as a brake on innovation, and more as a filter that rewards responsible players while exposing those who cut corners.

When customers are considered from the start, building AI that is safe, fair and transparent becomes a natural part of the process, not an afterthought. Compliance isn't only about avoiding fines. It's a chance to strengthen trust, enhance reputation and deliver better outcomes for the people who use your products. Ultimately, the AI Act is part of a wider movement towards ethical AI—an opportunity to lead responsibly, build trust and shape the future of technology on the global stage.

AI Act readiness checklist


Key questions to prepare for the act:

Risk level:

  • Have we identified whether our AI systems fall into minimal, limited, high, or prohibited risk categories?
  • Do we know which systems are in scope for stricter obligations?

Governance:

  • Do we have clear internal ownership of AI governance (legal, compliance, product)?
  • Is there a process for documenting AI system design, data, and decision-making?

Transparency & oversight:

  • Are we able to explain how our AI systems work to regulators, customers, and partners?
  • Do we have appropriate human oversight in place for higher-risk use cases?

Data protection:

  • How does our AI compliance align with GDPR and other data rules?
  • Are we monitoring for bias, fairness, and data quality?

Vendor and partner management:

  • Do we understand how third-party AI tools we use comply with the Act?
  • Are compliance requirements built into contracts and procurement processes?

Costs & resources:

  • Have we budgeted for potential compliance costs (audits, documentation, quality systems)?
  • Do we know what support is available (industry guidance, EU initiatives for SMEs)

Customer trust:

  • Are we communicating clearly to customers about when and how AI is used?
  • Do we have processes to act on customer concerns about fairness or privacy?

Download the whitepaper in full: