How to adapt your company to the EU AI Act: a practical guide
Equipo Tecnea
Tecnea

If you're searching for "how to adapt my company to the AI law" you probably already know the AI Act exists, but not where to start. That's a fair question: Regulation (EU) 2024/1689 isn't a law you comply with by signing one document — it's a classification and documentation process that depends on which AI systems your company actually uses, and only you know that.
This guide deliberately doesn't depend on any specific date. The exact dates for each obligation — what kicks in when — shift with regulatory developments (the EU has already postponed most of the timeline once, with the "Digital Omnibus" of July 2026), and we keep those updated in two other articles: The AI Act shifts: what changes on 2 August and what's been postponed and AI Act: what European companies need to do. Here we stick to what doesn't change: the order of the steps any company has to take, whenever you happen to be reading this.
Step 1: understand what the AI Act regulates (and what it doesn't)
The AI Act doesn't regulate "AI" as a technology. It regulates specific uses, classified by the risk they pose to people. The higher the risk of a given use, the more obligations it carries — from outright prohibited practices to "high-risk" systems with strong documentation requirements, with transparency duties for everything else. Most SMEs won't have any prohibited or high-risk system at all. But you won't know that without going through step 2.
Step 2: inventory the AI your company actually uses
This is the step most companies skip, and it's the only one that can't be outsourced to a consultant without your input: nobody outside the company knows which AI tools each department actually uses. Before classifying anything, you need to answer:
- Which AI tools does each department use — not just what the company bought, but also what individuals install on their own (so-called "Shadow AI")?
- Does any of them decide or score automatically about people: job candidates, employees, customers, or credit or insurance applicants?
- Does any of them process biometric data, minors' data, or judicial or administrative decisions?
- Who is responsible for keeping this inventory current whenever a new tool gets added?
Step 3: classify each system by risk level
With the inventory done, each system fits into one of these categories:
- Prohibited (Art. 5): subliminal manipulation, exploiting vulnerabilities, mass social scoring. Very rare in an SME.
- High-risk (Annex III): mainly systems that decide or score on employment and HR (automated candidate screening, performance evaluation) or on credit and insurance (creditworthiness scoring, life and health policy pricing). Also biometrics, education, critical infrastructure, and the administration of justice — categories less common outside their own sectors.
- General-purpose AI model (GPAI): not your system, but the model behind the tool you use — GPT, Claude, Gemini. The obligations belong to the model provider, not you, unless you build your own product on top of it.
- Limited or minimal risk: most everyday uses in an SME — writing assistants, customer-service chatbots, productivity tools. These carry transparency duties (making clear that people are interacting with AI), not the heavy obligations of high-risk systems.
One nuance worth having clear from the start: in 2026 the European Commission clarified that AI agents are not a separate legal category. If an agent carries out a function that falls under Annex III — say, screening job applications on its own — the same obligations apply as to any other high-risk system, whether or not it's labelled an "agent".
Step 4: if you have a high-risk system, document it before deploying it
High-risk systems require, in essence, four things done before going live, not after: a continuous risk-management process (not a one-off analysis), technical documentation of what the system does and what data it was trained on, automatic event logging that lets you reconstruct its decisions, and a real human oversight mechanism — with the actual ability to intervene, not a symbolic button. The full detail of the ten technical obligations is in our high-risk checklist guide.
Step 5: the risk that doesn't wait for any AI Act date
One obligation has already been in force since February 2025 and doesn't depend on any future postponement: AI literacy (Art. 4). Your team needs a basic level of competence in what these tools can and can't do. In practice, this usually matters less than a parallel, more urgent problem: GDPR. Feeding customer data, contracts, or case files into a free account of a general-purpose AI assistant can mean handing them to a third party with no data-processing agreement, with no way to know if they're used to train the model. That's the real problem, today, regardless of what stage the AI Act is at.
Step 6: name someone responsible, even part-time
You don't need a new department. You do need one specific person — not "the IT department" in the abstract — responsible for keeping the step-2 inventory current, deciding whether a new tool needs review before approval, and being the point of contact if Spain's AI Supervision Agency (AESIA) or an equivalent national authority ever makes an enquiry.
When it makes sense to bring in outside help
If the step-2 inventory turns up zero high-risk systems (the most common case for services SMEs), you can probably manage the rest with internal judgement and the free guides national authorities publish. If one or more high-risk systems show up, or if the AI you use handles special-category data (health, judicial, biometric), the technical documentation and risk-management system usually do need specialised support — it's months of work, not an afternoon.
Frequently asked questions
My company doesn't develop AI, it only uses it. Does the AI Act still apply to me? Yes, though with fewer obligations than for whoever develops the system. As a "deployer" (the Regulation's term), you have duties of human oversight, using the tool as the provider instructs and, if the system is high-risk, ongoing monitoring — even though you didn't build the model yourself.
What happens if I do nothing? The Regulation's fines go up to €35 million or 7% of global turnover (whichever is higher) for prohibited uses, and up to €15 million or 3% for failing high-risk obligations. But the most immediate risk, ahead of any fine, is usually GDPR exposure from uncontrolled AI use with customer data.
How much does it cost to classify my AI systems? The inventory and initial classification can be done by your own team using free guides from national authorities and the time of whoever knows the tools each department uses — it doesn't require a budget. The cost shows up later, if you need to document a high-risk system or review supplier contracts.
Is this legal advice? No. It's a practical work-order guide, not a legal opinion on your specific case. A binding interpretation of whether a system falls under Annex III requires specific legal advice.
If your inventory turns up a high-risk system, or you'd like a second opinion on whether the AI your company uses today is compliant, you can talk to us about your specific case.
Sources
- Regulation (EU) 2024/1689 of the European Parliament and of the Council, of 13 June 2024, laying down harmonised rules on artificial intelligence: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R1689
- Regulation (EU) 2026/1744 ("Digital Omnibus"), Official Journal of the European Union, 24 July 2026: https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force
- European Commission, AI Act Compliance Checker: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- Tecnea, The AI Act shifts: what changes on 2 August and what's been postponed
- Tecnea, AI Act: what European companies need to do
This article is informational and does not constitute legal advice. Tecnea helps companies deploy private, compliant AI and therefore has a commercial interest in this content — the steps it describes apply equally whether the classification is done by your own team, an outside consultant, or Tecnea.
¿Te ha resultado útil este artículo?
Publicamos análisis sobre IA y tecnología empresarial. Sin spam — solo cuando escribamos algo que valga la pena leer.
Did you like this article?
Tell us what you'd like to automate in your company and we'll tell you, with no strings attached, where to start.
