Most guidance on Regulation (EU) 2024/1689 — the AI Act — is written either for lawyers or for companies that build AI systems. Neither is much help to a mid-sized manufacturer that bought a vision-inspection system from a supplier, uses an off-the-shelf tool to screen job applicants, and has a maintenance model somebody built in-house two years ago.
This guide is for that organisation. It sets out the two questions that determine almost everything, the small number of obligations that genuinely reach an ordinary industrial user, and what is worth documenting now.
Why this matters now
The Act entered into force on 1 August 2024 and applies in stages rather than all at once. The stage that matters most to industrial users has now arrived: the general application date of 2 August 2026, which brings the high-risk regime under Annex III into effect, along with the transparency obligations. Two earlier stages have already passed — the prohibitions and the AI-literacy duty in February 2025, and the general-purpose AI and governance provisions in August 2025. One remains: high-risk AI embedded as a safety component in products already covered by EU product legislation, which follows in August 2027.
The practical consequence is that the question is no longer hypothetical. If your organisation uses AI in recruitment, worker management, or the operation of critical infrastructure, obligations may already apply to you as a user, not merely to your supplier.
1. Which role are you in?
This is the question that changes the answer most, and the one most often skipped. The Act assigns duties by role, not by industry. The same piece of software creates completely different obligations depending on how you came by it.
| Role | You are this if… | Weight of obligation |
|---|---|---|
| Provider | You develop an AI system, or have one developed, and place it on the market or put it into service under your own name or trademark. | Heaviest. Conformity assessment, technical documentation, risk and quality management, registration, post-market monitoring. |
| Deployer | You use an AI system under your own authority, in a professional capacity. Most manufacturers are here. | Moderate, and specific. Use it per instructions, assign competent human oversight, monitor operation, keep logs, inform affected workers. |
| Importer / distributor | You bring a third-country system into the EU market, or make one available in the chain. | Verification duties — chiefly checking the provider did what it should. |
There is a trap here worth stating plainly. A deployer can become a provider. Under Article 25, if you put your own name or trademark on a high-risk system, substantially modify it, or change its intended purpose so that it becomes high-risk, the provider's obligations transfer to you. Retraining a supplier's model on your own data, or repurposing a quality-inspection system to also rank operator performance, can move you across that line without anyone deciding to.
2. Which risk tier applies?
The Act sorts systems into four tiers. For an industrial organisation, the realistic answer is almost always the third or fourth.
- Prohibited. Applicable since February 2025. Includes emotion inference in the workplace, except for medical or safety reasons — worth knowing, because “engagement” or “attentiveness” analytics marketed for workforce use can fall here. Also social scoring, and untargeted facial-image scraping.
- High-risk. Annex I covers AI as a safety component of regulated products. Annex III lists standalone use cases — see below.
- Limited risk / transparency. Systems that interact with people or generate synthetic content must disclose that fact.
- Minimal risk. Everything else. Most predictive-maintenance, forecasting, scheduling and defect-detection systems sit here, and carry no specific obligations beyond AI literacy.
Assumptions behind this guide
- The organisation is established in the EU, or places systems on the EU market. Extraterritorial reach exists but is out of scope here.
- Staged application dates are those in the Regulation as adopted. Implementation detail, harmonised standards and guidance continue to develop — check current status before relying on a date.
- “Ordinary manufacturer” means an organisation that buys AI systems rather than developing and placing them on the market.
- Sector-specific law — machinery, medical devices, automotive — interacts with the Act and is not covered here.
3. What actually reaches a manufacturer
Strip away what applies to AI developers and a short list remains.
AI literacy (Article 4)
Article 4 has applied since 2 February 2025 and reaches both providers and deployers. You must take measures to ensure a sufficient level of AI literacy among staff who operate and use AI systems on your behalf, taking account of their technical knowledge, training and context of use. There is no certification requirement and no prescribed curriculum. There is also no exemption for small organisations, and it applies regardless of risk tier.
This is the single most commonly missed obligation, precisely because it is undramatic. It is also the cheapest to satisfy and the easiest to evidence.
Employment and worker management (Annex III(4))
AI used for recruitment, selection, screening or filtering applications, for decisions on promotion or termination, for task allocation based on behaviour or personal traits, or for monitoring and evaluating performance, is high-risk. This is the provision most likely to catch an industrial employer by surprise, because CV-screening and workforce-analytics tools are bought routinely by HR without an AI Act assessment.
As a deployer of such a system your duties include using it in line with the provider's instructions, assigning human oversight to people with the competence, training and authority to exercise it, monitoring operation, retaining logs, and informing affected workers and their representatives before putting it into use.
Critical infrastructure (Annex III(2))
AI intended as a safety component in the management and operation of critical digital infrastructure, road traffic, or the supply of water, gas, heating or electricity is high-risk. For most factories this does not apply: optimising your own consumption behind the meter is not operating the supply. For a utility, a district-heating operator or a grid-connected generator, it may well.
The distinction that matters is safety component. A model that advises a human dispatcher is treated differently from one wired into protection or control. If you are unsure which side you are on, that uncertainty is itself the finding — document it and get it resolved.
Transparency (Article 50)
If you run a chatbot or voice agent, people must be told they are interacting with an AI system unless it is obvious. Synthetic image, audio, video or text content must be marked machine-readably as artificially generated. Straightforward, and easy to overlook on a customer-service widget nobody thinks of as “an AI system”.
4. What to document now
Whatever your risk tier, the same four artefacts are worth having, and none requires legal advice to start.
- An inventory of AI systems in use. What it is, who supplied it, what it decides or recommends, who acts on the output, and whether it touches recruitment, worker evaluation or infrastructure operation. Most organisations discover on doing this that they use more AI than they thought, usually inside procured software.
- A role determination per system. Provider or deployer, with the reasoning in one or two sentences — and a note of anything that could move you across the Article 25 line.
- A record of AI-literacy measures. Who was trained, on what, when. A dated register and the training material is enough.
- Supplier documentation. Ask each supplier, in writing, for their AI Act classification of the system and their instructions for use. Their answer — or their inability to give one — is useful either way, and asking is free.
That inventory is also the thing most likely to be requested first in any dispute, audit or procurement questionnaire. It is worth having whether or not you are high-risk.
Penalties
| Breach | Maximum fine | or % of worldwide annual turnover |
|---|---|---|
| Prohibited AI practices | €35 million | 7% |
| Most other obligations, including deployer duties | €15 million | 3% |
| Supplying incorrect or misleading information to authorities | €7.5 million | 1% |
Whichever is higher applies, except for SMEs and start-ups, where the lower of the two figures applies instead. Enforcement is by national market surveillance authorities.
Limits of this guide
We have simplified deliberately. Annex III lists eight high-risk areas and this covers two. The high-risk regime carries requirements we have not set out. Sector-specific law on machinery, medical devices and vehicles interacts with the Act and can change the answer completely. Nothing here is legal advice or a compliance assessment.
Used as intended, it should leave you with a defensible starting position and a short list of things to write down. That makes the conversation with a specialist shorter, and cheaper.
Sources
- Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) — official text on EUR-Lex. Articles 4, 6, 25, 26, 50, 99; Annexes I and III.
- European Commission, AI Act overview and implementation timeline — digital-strategy.ec.europa.eu.
Found an error? Tell us and show your working — we correct in place and record what changed. Contact us.