CURRENT TREND INSIGHT
EU AI Act compliance requirements for mid-sized corporations Illustration

EU AI Act compliance requirements for mid-sized corporations

Direct Summary:

The EU AI Act (Regulation (EU) 2024/1689) applies in phases, not all at once: prohibited practices and AI-literacy obligations started February 2, 2025; obligations for general-purpose AI model providers started August 2, 2025; and the bulk of rules — including most high-risk AI system obligations under Annex III (which covers common mid-sized-corporation use cases like automated recruitment and credit-scoring tools) — apply from August 2, 2026. A mid-sized company's actual compliance work is mostly about classifying which of its AI systems fall into the "high-risk" category and, if so, meeting that category's specific obligations (risk management, logging, human oversight, technical documentation).

"Data is the new oil."

— Clive Humby

Key Insights

  • Risk classification comes first: the Act's obligations depend entirely on which risk tier a given AI system falls into (unacceptable/banned, high-risk, limited-risk with transparency duties, or minimal-risk) — you can't plan compliance work before this classification is done for each system you use.
  • Recruitment and credit-scoring tools are common high-risk triggers for mid-sized firms: Annex III explicitly names employment/worker-management AI and creditworthiness assessment as high-risk categories — exactly the kind of automation many mid-sized companies have already adopted.
  • The timeline has already shifted once via the "Digital Omnibus": a 2026 simplification package moved some high-risk deadlines (e.g., employment-related systems) later — check the current official timeline rather than assuming a date from an older source is still accurate.

"EU AI Act compliance" isn't one deadline — it's a staggered rollout where different obligations activate on different dates, and where the obligations that actually apply to your company depend on classifying each AI system you use against the Act's risk tiers. For a mid-sized corporation, the practical starting point isn't a generic compliance checklist; it's an inventory of every AI system in active use, checked against Annex III's list of high-risk use cases.

Building a compliance approach that actually maps to the law

1. Inventory every AI system in use and classify its risk tier. Check each system against Annex III's high-risk categories (employment/HR tools, credit scoring, and others) — most general-purpose chat assistants used for drafting or research won't qualify as high-risk, but purpose-built decision-automation tools often will.

2. Track the applicable dates for your specific systems. A high-risk recruitment tool and a general-purpose AI assistant are on different compliance timelines — don't apply the same deadline to every system in your inventory.

3. For anything classified high-risk, build the required documentation and oversight. High-risk obligations include a risk management system, technical documentation, logging capability, and human oversight measures — these need to exist before the applicable deadline, not be retrofitted after.

ai_system_inventory.md
# A starting template for an AI system risk-classification inventory
# -- fill one row per AI system your company actually uses

| System            | Purpose                  | Annex III Match? | Risk Tier   |
|--------------------|---------------------------|-------------------|-------------|
| Resume screening AI| Candidate ranking          | Yes (employment)  | High-risk   |
| Support chatbot    | Customer Q&A                | No                 | Limited-risk (transparency) |
| Internal drafting assistant | Document drafting | No                 | Minimal-risk |
Applicable Date What Activates
February 2, 2025 Prohibited AI practices banned; AI-literacy obligations begin
August 2, 2025 Governance rules and general-purpose AI model provider obligations
August 2, 2026 Most high-risk system obligations (Annex III) and transparency rules (Article 50)

Because the timeline has already been revised once (the 2026 "Digital Omnibus" simplification package pushed some high-risk deadlines later), treat any specific date you read — including the ones above — as something to verify against the European Commission's official AI Act Service Desk before finalizing a compliance calendar, rather than something to hardcode into a policy document indefinitely.

Practical Challenge

Build an inventory like the template above for 3-5 AI tools your organization actually uses, and for each one, check it against Annex III's high-risk categories on the official AI Act text.

Concept Check

What is the first practical step a mid-sized company should take to approach EU AI Act compliance?
Correct! Every other compliance activity — timelines, documentation, oversight — depends on first knowing which risk tier each of your AI systems actually falls into.
Incorrect. Try again! The Act's obligations are tier-dependent, so classification has to come first — and several obligations (prohibited practices, AI literacy) already applied well before August 2026.

Sources & Further Reading

Previous Guide Dashboard Next Guide