Resource · FAQ
Frequently asked questions
Answers about the EU AI Act, risk classification, and how EUAIFit works.
The AI Act
Does the AI Act apply to my company?+
If your organisation places an AI system on the EU market, puts it into service in the EU, or uses it within the EU — yes. The Act applies regardless of where your company is headquartered. A US startup with EU customers is just as in scope as a Berlin enterprise.
What counts as an 'AI system' under the Act?+
The Act defines an AI system broadly: any machine-based system that, for explicit or implicit objectives, infers from input how to generate outputs like predictions, recommendations, or decisions. This includes traditional ML models, LLM-based products, rule-based expert systems with inference, and hybrid approaches.
When do I need to be compliant?+
The Act is phased. Prohibited-practice and AI-literacy provisions have applied since February 2025, and obligations for providers of general-purpose AI models began in August 2025. Article 50 transparency duties apply from August 2026. Following the 2026 AI Omnibus, Annex III high-risk rules apply from 2 December 2027 and high-risk rules for AI embedded in regulated products apply from 2 August 2028. Your duties also depend on whether you are a provider, deployer, importer, or distributor.
What are the penalties?+
Fines range up to €35 million or 7% of global annual turnover (whichever is higher) for prohibited practices, up to €15 million or 3% for other violations, and up to €7.5 million or 1% for providing incorrect information. SMEs and startups face proportionate amounts based on turnover.
Risk classification
How do I know if my AI system is high-risk?+
Start with our free exposure check. It highlights obvious high-risk, prohibited-practice, and transparency triggers, but it is not a definitive classification. Pilot customers receive a fuller, source-linked assessment reviewed with a qualified compliance professional.
We just use ChatGPT internally — is that high-risk?+
Probably not, unless you're using it in a way that affects employment decisions, access to essential services, or other Annex III areas. Internal knowledge management, drafting, and brainstorming with a general-purpose AI tool typically fall into the minimal or limited-risk category. Transparency obligations may still apply.
Can a system change risk class over time?+
Yes. The risk classification is based on the intended purpose and use case, not the technology alone. If you expand a recommendation engine into a credit-scoring tool, it may move from minimal to high-risk. You should reclassify whenever the intended purpose changes materially.
EUAIFit product
Is EUAIFit itself an AI system?+
The current public exposure check is a deterministic screening tool, not a machine-learning model. EUAIFit is developing a versioned, source-linked classification workflow for expert-supported pilots.
How long does compliance take?+
A clear system can usually be screened in 10–15 minutes, but a defensible classification may require product, legal, privacy, and technical input. During the pilot we help customers build the inventory, resolve missing facts, and prepare a reviewable evidence pack.
Do you cover GDPR too?+
GDPR is separate from the AI Act but often overlaps, especially around automated decision-making, lawful processing, impact assessment, and transparency. The pilot flags areas for specialist review; it does not replace a GDPR assessment.
What about the UK?+
The UK has its own approach to AI regulation, currently sector-based rather than a single horizontal law. EUAIFit's EU AI Act module is our first release. A UK-specific guidance module is planned for early 2027.
Still have questions?
We're happy to talk through your specific situation — no sales pressure, just practical guidance.
Get in touch