Insights  ·  Corporate & Commercial

The EU AI Act: What a Business Has to Do

In short

The Artificial Intelligence Act regulates the use to which a system is put, not the technology behind it. The obligations that attach to your business depend on your position in the supply chain and on what the system decides. This is how to work out both, and what to have on file.

Most businesses asking about the Artificial Intelligence Act ask the wrong question first. The question is not whether the business uses artificial intelligence. It is what the systems it uses are permitted to decide, and what position the business occupies in the chain that supplies them. Those two answers determine everything else, and both can be established from documents the business already holds.

What is in force, and from when

The Act is Regulation (EU) 2024/1689 of 13 June 2024. It entered into force on 1 August 2024 and applies in stages.

The prohibited practices and the AI literacy obligations have applied since 2 February 2025. The rules on general purpose AI models, the governance provisions and the penalty provisions have applied since 2 August 2025. The Regulation applies generally from 2 August 2026.

The high risk provisions were then deferred. Regulation (EU) 2026/1744 of 8 July 2026, the Digital Omnibus on AI, which entered into force on 27 July 2026, moved the application of Sections 1, 2 and 3 of Chapter III to 2 December 2027 for systems classified as high risk under Article 6(2) and Annex III, and to 2 August 2028 for systems classified as high risk under Article 6(1) and Annex I, that is those embedded in products already regulated under EU product legislation.

The deferral is of the compliance deadline, not of the analysis. A business that will be a provider or deployer of a high risk system in December 2027 needs to know that now, because the documentation the Act requires is generated during development and procurement, not retrieved afterwards.

The Act regulates the use, not the technology

The Act takes a horizontal approach. It does not create a separate rulebook for each industry, and it does not attach obligations to a technology by name. It defines what counts as an AI system, distinguishing it from ordinary software, and then it grades the obligations by the risk that the particular use presents.

The consequence is that the same model can carry heavy obligations in one deployment and almost none in another. A language model that drafts marketing copy and the same model used to filter job applicants are not in the same regulatory position. Any assessment that starts from the vendor's product name rather than from the use case will produce the wrong answer.

Establish your position in the chain

The Act distinguishes between the roles played in the development, supply and use of a system, and the obligations differ sharply between them. A business that buys a system and applies it to its own operations is in a different position from one that develops a system, and from one that puts its own name on a system built by another.

That last case is the trap, and the Act spells it out. Under Article 25(1), a distributor, importer, deployer or other third party is considered to be the provider of a high risk system, and takes on the provider's obligations under Article 16, where it puts its name or trademark on a high risk system already on the market, where it makes a substantial modification to such a system so that it remains high risk, or where it modifies the intended purpose of a system, including a general purpose AI system, so that the system becomes high risk. The original provider is relieved of those obligations but must co-operate and supply the technical information needed.

Before any assessment is done, establish in writing which role the business occupies for each system, because the answer is not always the one the commercial team assumes.

If you are at this point

The inventory is the step that makes every later obligation manageable. Ask us where to start or write to office@kleanthousplatis.com.

Start with an inventory

Nothing useful can be done without a list. The inventory should record, for each system: what it is, who supplies it, what business decision it informs or takes, whether a person reviews the output before it has an effect, what data goes into it, and who inside the business owns it.

This exercise routinely surfaces systems nobody has approved. Recruitment screening tools, credit and fraud scoring, customer service automation and staff monitoring software are all commonly bought by a department without going anywhere near legal or compliance. The inventory is the deliverable that makes the rest of the analysis possible, and it is also the document a regulator will ask for first.

The four positions a system can be in

Prohibited. A small number of practices are banned outright. Where a proposed use falls into this group, no amount of consent, documentation or contractual protection saves it. The use has to stop.

High risk. The Act reserves its substantive obligations for systems capable of causing significant harm to health, safety or fundamental rights. Where a system is in this category, it has to operate under conditions of governance, record keeping and human oversight that can be evidenced afterwards. A fundamental rights impact assessment under Article 27 is not required of every deployer: the duty falls on deployers that are bodies governed by public law or private entities providing public services, and on deployers of the creditworthiness and insurance pricing systems in points 5(b) and 5(c) of Annex III, and it has to be done before the system is put into use. Other deployers should still document the assessment they did, because the obligation to show human oversight and to keep records applies to them.

Transparency obligations. Some uses attract a duty to tell people what they are dealing with, including where a person is interacting with an AI system or is being shown AI generated content. These duties are inexpensive to comply with and embarrassing to be caught breaching.

Everything else. Most business use falls here, and carries no specific obligation under the Act. That is not the same as carrying no obligation at all: data protection law, employment law, consumer law and the ordinary law of contract and negligence continue to apply, and in practice they are the source of most of the risk.

Most businesses asking about the Artificial Intelligence Act ask the wrong question first.

Human oversight is the control that matters

Where a system informs a decision about a person, the practical protection is a human being with the authority, the information and the time to overrule it. Oversight that exists only in the policy document, where the reviewer approves every output because there are four hundred a day, is not oversight, and it will not be treated as such.

Record how oversight actually works: who reviews, on what information, how often they depart from the recommendation, and what happens when they do.

Push the obligations onto the supplier

Much of what a deployer needs, it cannot generate itself. The technical documentation, the description of the training data, the accuracy and limitation statements and the instructions for use all sit with whoever built the system.

The procurement contract is therefore the place where compliance is either secured or lost. Ask for the documentation before signing, not after. Require notice of material changes to the model, because a system that is updated silently is a system whose assessment is out of date. Allocate liability for regulatory breach and for third party claims arising from the output. And obtain a right to terminate if the supplier cannot support the obligations you are subject to.

What is outside the Act

Article 2 sets out the exclusions. By Article 2(3) the Regulation does not apply to AI systems placed on the market, put into service or used exclusively for military, defence or national security purposes. By Article 2(6) it does not apply to AI systems or models, including their output, specifically developed and put into service for the sole purpose of scientific research and development. By Article 2(10) it does not apply to the obligations of deployers who are natural persons using AI systems in the course of a purely personal non-professional activity. The Act also provides for regulatory sandboxes allowing supervised testing, which are of interest to developers rather than to ordinary business users.

What it costs to get it wrong

Article 99 sets the ceilings that Member States must provide for, and each is expressed as the higher of a fixed sum and a percentage of turnover.

Infringement of the prohibited practices in Article 5 attracts fines of up to EUR 35 000 000 or, if the offender is an undertaking, up to 7 per cent of its total worldwide annual turnover for the preceding financial year, whichever is higher. Non-compliance with the operator obligations listed in Article 99(4), which include the provider obligations in Article 16, the deployer obligations in Article 26 and the transparency obligations in Article 50, attracts up to EUR 15 000 000 or 3 per cent, whichever is higher. Supplying incorrect, incomplete or misleading information to a notified body or a national competent authority attracts up to EUR 7 500 000 or 1 per cent, whichever is higher. Lower ceilings apply to small and medium enterprises and start-ups.

Who supervises this in Cyprus

Cyprus has designated the Commissioner of Communications as its notifying authority and market surveillance authority under the Act, and as the national single point of contact. That is the office to which notification and registration questions are addressed, and the one that will conduct market surveillance. Where the deployment involves personal data, the Commissioner for Personal Data Protection remains the supervisory authority for the data protection analysis, and the two exercises should be run together rather than in sequence.

What to send us

The list of AI tools in use or under procurement, the supplier contracts and terms of service, any data protection impact assessment already carried out, and a short description of what each system is used to decide. Where a system touches employees or job applicants, send the process it sits inside as well.

Technology, data and regulatory work sits within our corporate and commercial practice. For the employment side of the same problem, see what an employer must put in place before staff use AI. For liability and contracting where an AI system causes loss, see AI Systems and Liability.

Discuss your own situation with us

Questions we are asked

When does a business that only bought the system become its provider?

Under Article 25(1), a distributor, importer, deployer or other third party is considered the provider of a high risk system, and takes on the provider obligations in Article 16, where it puts its name or trademark on a high risk system already on the market, where it makes a substantial modification so that the system remains high risk, or where it modifies the intended purpose of a system, including a general purpose AI system, so that the system becomes high risk. The original provider is relieved of those obligations but must co-operate and supply the technical information needed.

Does every deployer need a fundamental rights impact assessment?

No. Under Article 27 the duty falls on deployers that are bodies governed by public law or private entities providing public services, and on deployers of the creditworthiness and insurance pricing systems in points 5(b) and 5(c) of Annex III, and it must be done before the system is put into use. Other deployers should still document the assessment they carried out, because the obligation to show human oversight and to keep records applies to them.

What counts as real human oversight?

A person with the authority, the information and the time to overrule the output. Oversight that exists only in the policy document, where the reviewer approves every output because there are four hundred a day, is not oversight and will not be treated as such. Record who reviews, on what information, how often they depart from the recommendation, and what happens when they do.

What is outside the Act?

Article 2 sets the exclusions. Article 2(3) excludes systems placed on the market, put into service or used exclusively for military, defence or national security purposes. Article 2(6) excludes systems or models, including their output, specifically developed and put into service for the sole purpose of scientific research and development. Article 2(10) excludes the obligations of deployers who are natural persons using AI systems in a purely personal, non-professional activity.

How high do the fines go?

Article 99 sets three ceilings, each expressed as the higher of a fixed sum and a percentage of turnover. Infringement of the prohibited practices in Article 5: up to EUR 35,000,000 or 7 per cent of total worldwide annual turnover. Non-compliance with the obligations listed in Article 99(4), which include Article 16 for providers, Article 26 for deployers and Article 50 on transparency: up to EUR 15,000,000 or 3 per cent. Supplying incorrect, incomplete or misleading information to a notified body or national competent authority: up to EUR 7,500,000 or 1 per cent. Lower ceilings apply to SMEs and start-ups.

Who supervises this in Cyprus?

Cyprus has designated the Commissioner of Communications as its notifying authority and market surveillance authority under the Act, and as the national single point of contact. Where the deployment involves personal data, the Commissioner for Personal Data Protection remains the supervisory authority for the data protection analysis, and the two exercises should run together rather than in sequence.

When does the AI Act actually apply to us?

In stages. Regulation (EU) 2024/1689 of 13 June 2024 entered into force on 1 August 2024. The prohibited practices and the AI literacy obligations have applied since 2 February 2025; the rules on general purpose AI models, the governance provisions and the penalties since 2 August 2025; and the Regulation applies generally from 2 August 2026. The high risk provisions were then deferred by Regulation (EU) 2026/1744, the Digital Omnibus on AI, which entered into force on 27 July 2026 and moved Sections 1, 2 and 3 of Chapter III to 2 December 2027 for systems high risk under Article 6(2) and Annex III, and to 2 August 2028 for those high risk under Article 6(1) and Annex I.

The high risk rules are deferred. Can we wait?

The deferral is of the compliance deadline, not of the analysis. A business that will be a provider or deployer of a high risk system in December 2027 needs to know that now, because the documentation the Act requires is generated during development and procurement rather than retrieved afterwards.

Does the Act regulate the technology or the use?

The use. It takes a horizontal approach, defines what counts as an AI system as distinct from ordinary software, and grades the obligations by the risk the particular use presents. The same model can therefore carry heavy obligations in one deployment and almost none in another: a language model drafting marketing copy and the same model filtering job applicants are not in the same position.

What is the first question to ask about our own exposure?

Not whether the business uses artificial intelligence, but what the systems it uses are permitted to decide, and what position the business occupies in the chain that supplies them. Both answers can be established from documents the business already holds.

This article is for general information only and does not constitute legal advice. Laws and their application can change, and individual circumstances differ. For advice on your own matter, contact Klitos Platis at klitos@kleanthousplatis.com or telephone +357 22 680 330.

Klitos Platis

Klitos Platis

Advocate, Partner

Kleanthous & Platis LLC, Nicosia · Revised 4 August 2026

Need advice on your own matter?

Briefly describe your situation, the people involved and any deadline.

We reply within one business day. We will ask for documents once we confirm we can act.

Discuss your matter
Email+357 22 680 330WhatsApp
Receive legal updates by email

When Cyprus law changes, hear it from us

One short email when something changes that matters: new legislation, a decision worth knowing, a deadline. Written by the partners, no marketing, unsubscribe with one click.

You are on the list. The next update on Cyprus law will reach your inbox.

That did not go through. Please write to office@kleanthousplatis.com and we will add you.

Your address is used for these updates and nothing else. Privacy notice.