EUAIFit

Resource · FAQ

Frequently asked questions

Answers about the EU AI Act, risk classification, and how EUAIFit works.

The AI Act

Does the AI Act apply to my company?+

If your organisation places an AI system on the EU market, puts it into service in the EU, or uses it within the EU — yes. The Act applies regardless of where your company is headquartered. A US startup with EU customers is just as in scope as a Berlin enterprise.

What counts as an 'AI system' under the Act?+

The Act defines an AI system broadly: any machine-based system that, for explicit or implicit objectives, infers from input how to generate outputs like predictions, recommendations, or decisions. This includes traditional ML models, LLM-based products, rule-based expert systems with inference, and hybrid approaches.

When do I need to be compliant?+

The Act is phased. Prohibited-practice and AI-literacy provisions have applied since February 2025, and obligations for providers of general-purpose AI models began in August 2025. Article 50 transparency duties apply from August 2026. Following the 2026 AI Omnibus, Annex III high-risk rules apply from 2 December 2027 and high-risk rules for AI embedded in regulated products apply from 2 August 2028. Your duties also depend on whether you are a provider, deployer, importer, or distributor.

What are the penalties?+

Fines range up to €35 million or 7% of global annual turnover (whichever is higher) for prohibited practices, up to €15 million or 3% for other violations, and up to €7.5 million or 1% for providing incorrect information. SMEs and startups face proportionate amounts based on turnover.

Risk classification

How do I know if my AI system is high-risk?+

Start with our free exposure check. It highlights obvious high-risk, prohibited-practice, and transparency triggers, but it is not a definitive classification. Pilot customers receive a fuller, source-linked assessment reviewed with a qualified compliance professional.

We just use ChatGPT internally — is that high-risk?+

Probably not, unless you're using it in a way that affects employment decisions, access to essential services, or other Annex III areas. Internal knowledge management, drafting, and brainstorming with a general-purpose AI tool typically fall into the minimal or limited-risk category. Transparency obligations may still apply.

Can a system change risk class over time?+

Yes. The risk classification is based on the intended purpose and use case, not the technology alone. If you expand a recommendation engine into a credit-scoring tool, it may move from minimal to high-risk. You should reclassify whenever the intended purpose changes materially.

EUAIFit product

Is EUAIFit itself an AI system?+

The current public exposure check is a deterministic screening tool, not a machine-learning model. EUAIFit is developing a versioned, source-linked classification workflow for expert-supported pilots.

How long does compliance take?+

A clear system can usually be screened in 10–15 minutes, but a defensible classification may require product, legal, privacy, and technical input. During the pilot we help customers build the inventory, resolve missing facts, and prepare a reviewable evidence pack.

Do you cover GDPR too?+

GDPR is separate from the AI Act but often overlaps, especially around automated decision-making, lawful processing, impact assessment, and transparency. The pilot flags areas for specialist review; it does not replace a GDPR assessment.

What about the UK?+

The UK has its own approach to AI regulation, currently sector-based rather than a single horizontal law. EUAIFit's EU AI Act module is our first release. A UK-specific guidance module is planned for early 2027.

Still have questions?

We're happy to talk through your specific situation — no sales pressure, just practical guidance.

Get in touch