Regulation rarely arrives all at once, and the European Union’s approach to artificial intelligence has followed a staged timetable. The obligations that take effect first are the least glamorous ones: documentation, disclosure and the duty to tell people when they are interacting with a machine.
Those requirements now apply to a broad set of systems, and companies that assumed the rules were aimed only at frontier developers are discovering that their customer support bots, content recommenders and document tools fall inside the scope. The EU AI Act text and its accompanying guidance set out the detail.
What the transparency duties actually require
At the simplest level, users must be informed when they are dealing with an AI system rather than a person. Synthetic media must be marked in a way that survives normal use. Certain systems must keep logs, and providers must supply documentation that allows a deployer to understand capabilities and limitations.
The difficult parts are the edges. What counts as sufficient disclosure for a chatbot that only answers questions about opening hours? How should a generated image be labelled when it is edited afterwards? Guidance has narrowed some of these questions, but many will be settled only through enforcement.
The risk tiers and where companies get placed
The framework sorts systems by risk. A small number of uses are prohibited outright. A larger set is classified as high risk and attracts obligations around data governance, human oversight, accuracy and conformity assessment. The remainder face mainly transparency duties.
Classification is where legal and engineering teams must work together, because it depends on what the system does rather than what it is called. A tool marketed as a productivity assistant may still fall into a higher tier if it is used to evaluate people, determine access to services or influence voting.

General purpose models and the paperwork burden
Providers of general purpose models face a separate set of duties, including summaries of training data and information for downstream developers. These obligations are designed to make the supply chain legible, so that a company building on top of a model can understand what it is working with.
The practical effect is a new genre of technical documentation. Teams that already maintained model cards and evaluation reports have an advantage. Teams that did not are now writing them under time pressure, and the quality varies considerably.
Enforcement, penalties and the compliance industry
Penalties scale with the seriousness of the breach and the size of the company, with the largest fines reserved for prohibited practices. National authorities carry out enforcement, which means the practical experience of regulation will differ between member states.
A compliance industry has grown quickly around the framework, offering audits, templates and monitoring tools. Buyers should ask what standards an auditor is working to, because the field is young and credentials are uneven. Independent bodies such as NIST in the United States and standardisation organisations in Europe have published frameworks that auditors increasingly reference.

How this affects companies outside Europe
The rules apply to systems used in the European Union, regardless of where the provider is based. That extraterritorial reach has led many non-European firms to adopt the requirements globally, on the reasoning that maintaining two compliance regimes is more expensive than applying the stricter one everywhere.
This pattern mirrors what happened with data protection rules, where a regional law became a de facto international standard. Whether the same happens here depends on how enforcement develops and whether other jurisdictions adopt compatible requirements.
Smaller companies and the cost of compliance
The framework includes accommodations for smaller providers, including simplified documentation and reduced fees in some cases. In practice, the fixed cost of understanding the rules still falls hardest on organisations without dedicated legal staff, and the gap between large and small firms widens at each deadline.
Openly licensed templates and industry guidance reduce the burden, and trade associations have published material aimed at smaller members. The remaining work is judgement about classification, which is difficult to outsource because it depends on how a system is actually used.
Companies that build on top of a general purpose model also inherit duties from their supplier, which means the quality of the documentation they receive shapes their own compliance position. Asking a vendor for model cards and evaluation summaries is now a reasonable procurement question rather than an unusual one.
Practical steps for engineering teams
Start with an inventory. Most organisations do not have a reliable list of every AI system in use, including those embedded in third party software. Classification follows from the inventory, and documentation follows from classification.
Then build the habits that make compliance cheap: versioned prompts, recorded evaluations, clear ownership and logs that can be produced on request. These are the same practices that make systems easier to debug, which is why the teams that do them well tend to regard the regulation as a prompt to fix problems they already had.
Image: jeffowenphotos · CC BY 2.0 · via Wikimedia Commons.