Home
RiskOnyx

Resources for AI Governance

Practical Considerations for the EU AI Act

Who should move first, which sectors are most exposed, and what the financial risk really looks like

Official EU reference

“providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union”

EU AI Act practical compliance considerations graphic

The short version

The practical compliance question is not “Who should care about the EU AI Act one day?” It is “Who should already be mapping exposure now?” The answer is broader than many executives assume. If your organisation develops, buys, deploys, integrates, resells, imports, distributes, or relies on AI outputs used in the Union, the Act can become relevant. The scope is not limited to EU-headquartered tech companies. The AI Act also reaches providers and deployers in third countries when the output of the AI system is used in the Union.

That means companies should stop waiting for a perfect legal trigger before doing anything. The earlier move is to identify whether you are a provider, deployer, importer, distributor, product manufacturer, or another operator in the chain, and then focus on use cases that are likely to attract the most scrutiny.

Who should start preparing first

The first priority group is clear. Providers and deployers of systems that may fall into high-risk categories should already be working on inventory, role allocation, documentation, oversight, and evidence. The Commission’s high-risk classification guidance is aimed at helping providers and deployers assess whether a system is high-risk. Public authorities and businesses using AI in sensitive decision contexts should be especially careful. So should companies embedding AI into regulated products.

The second priority group is businesses that may not think of themselves as “AI companies” at all. If you use third-party AI systems in recruiting, admissions, scoring, eligibility, or critical workflows, you can still sit inside a high-attention zone. The law does not only look at who built the model. It also looks at how systems are placed on the market, put into service, and used.

Which sectors and use cases are most exposed

Recruitment is one of the clearest examples. Annex III lists AI systems intended to be used for recruitment or selection of natural persons, including analysing, filtering, and evaluating job applications, as a high-risk area. That makes headhunters, recruitment platforms, large employers, and staffing intermediaries obvious candidates for early review. It is not enough to say that a human stays in the loop if rankings or scores still materially influence decisions.

Education is another high-attention area. Annex III lists AI systems intended to determine access or admission to educational and vocational training institutions, as well as systems used to evaluate learning outcomes. That puts schools, universities, edtech providers, and testing organisations into the front row.

Banks and other lenders should pay attention because access to essential private services is a named category in Annex III. The law explicitly includes AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score, subject to certain exceptions. In practice, that means retail credit scoring and similar personal-finance decision tools are not peripheral use cases. They sit near the heart of the risk-based regime.

Life and health insurers should also pay attention because Annex III includes AI systems intended for risk assessment and pricing in relation to natural persons in life and health insurance. The wider point is simple: if an AI system influences access, ranking, eligibility, admission, employment, pricing, or important life chances, you should assume the compliance conversation starts earlier, not later.


Practical takeaway. The most affected sectors are often not “AI companies” in the narrow sense. They are organisations using AI to make or shape high-impact decisions about people.

What the financial exposure looks like

Article 99 of the AI Act sets out three main administrative fine levels. Non-compliance with the prohibited practices in Article 5 can trigger fines of up to EUR 35 million or 7 percent of worldwide annual turnover, whichever is higher. Other major operator and notified-body breaches can trigger fines of up to EUR 15 million or 3 percent. Supplying incorrect, incomplete, or misleading information can trigger fines of up to EUR 7.5 million or 1 percent.

Those are not abstract numbers. They matter because they change how boards, procurement teams, and internal control functions will treat AI governance. The real shift is not only regulatory. It is managerial. Once the financial exposure is visible, AI governance stops looking like an innovation side topic and starts looking like operational risk.

What to do next

If you are in recruitment, education, consumer finance, life or health insurance, public services, or any use case that shapes access, ranking, pricing, or eligibility, you should not wait for the final compliance clock to force action. Start by classifying your systems, assigning ownership, and centralising evidence. The organisations that move early will not just be safer. They will also be easier to trust.

In brief
  • Do not start from geography alone. Start from role and use case.
  • Recruitment, education, and consumer credit are among the clearest early pressure points.
  • Article 99 fine levels are high enough to change boardroom behaviour.
Why companies should care

Because the sectors most exposed are often the ones using AI to shape real decisions about people, not just the ones building frontier models.