Blog/What This Means

EU AI Act Takes Effect: What Mid-Market Companies Need to Know About Compliance

The EU AI Act officially launches this month with specific requirements for HR, lending, and customer service AI systems.

Nick Simmons, Lomo AI··5 min read
EU AI Act Takes Effect: What Mid-Market Companies Need to Know About ComplianceLomo AI

EU AI Act Takes Effect: What Mid-Market Companies Need to Know About Compliance

The European Union's Artificial Intelligence Act officially took effect on August 1, 2024, but its compliance deadlines are hitting now. Starting February 2025, companies using high-risk AI systems face mandatory conformity assessments, and by August 2025, all high-risk AI applications must meet the Act's full requirements.

For mid-market companies ($10M-$500M revenue) operating in or serving European markets, this isn't a distant regulatory concern. It's an immediate business reality that requires concrete action.

What Qualifies as High-Risk AI Under the Act

The EU AI Act categorizes AI systems into four risk levels: minimal, limited, high, and unacceptable. High-risk systems are those used in sectors and applications that pose significant risks to health, safety, or fundamental rights.

Three areas hit mid-market companies hardest:

HR and Employment Systems: AI used for job candidate screening, employee evaluation, promotion decisions, or task allocation qualifies as high-risk. This includes resume parsing tools, video interview analysis, performance prediction models, and automated scheduling systems that impact worker conditions.

Credit and Lending: Any AI system used to evaluate creditworthiness, determine loan terms, or assess financial risk falls under high-risk classification. This covers automated underwriting, fraud detection systems that affect credit decisions, and AI-powered insurance pricing models.

Customer Service and Sales: AI systems that significantly influence customer access to essential services are high-risk. This includes chatbots handling insurance claims, automated customer onboarding for financial services, and AI systems that determine service eligibility or pricing.

Specific Compliance Requirements

Companies deploying high-risk AI systems must meet eight core requirements:

Risk Management Systems: Organizations must establish ongoing processes to identify, analyze, and mitigate risks throughout the AI system's lifecycle. This means documented risk assessments before deployment and continuous monitoring afterward.

Data Governance: Training datasets must be relevant, representative, and free from errors. Companies need documented data quality processes and bias testing protocols. For a lending AI, this means proving your training data represents your actual customer base across protected characteristics.

Technical Documentation: The Act requires comprehensive technical files covering system design, development process, testing procedures, and performance metrics. This documentation must be maintained for 10 years after the system stops being used.

Record Keeping: All high-risk systems must maintain detailed logs of operations sufficient to ensure transparency and enable post-market monitoring. These logs must capture inputs, outputs, and system decisions.

Transparency Requirements: Users must be clearly informed they're interacting with an AI system. For HR applications, this means job candidates must know when AI tools evaluate their applications and understand the system's role in decision-making.

Human Oversight: Qualified personnel must monitor high-risk AI systems with the ability to intervene or interrupt operations. The system must be designed so humans can effectively understand outputs and maintain control.

Accuracy and Robustness: Systems must maintain consistent performance levels and handle errors gracefully. This requires ongoing testing and validation processes.

Cybersecurity Measures: AI systems must be resilient against cyberattacks and maintain security throughout their operational lifecycle.

Real Compliance Costs and Timeline

Compliance isn't just about checking boxes. A mid-market financial services company implementing AI credit scoring faces tangible costs: legal review of existing systems, technical audits to ensure data governance, staff training on oversight procedures, and ongoing monitoring infrastructure.

European companies reported spending between €50,000 and €200,000 on initial AI Act compliance assessments, with ongoing annual costs of €25,000 to €75,000 for maintaining documentation and monitoring systems.

The timeline is aggressive. Companies have until August 2025 to bring existing high-risk AI systems into full compliance. New systems deployed after February 2025 must comply from day one.

Beyond Europe: Why This Matters Globally

Mid-market companies might assume EU regulations don't apply to them, but the Act's reach extends globally. If your company processes data from EU residents, serves European customers, or partners with European businesses, compliance may be required.

Moreover, the Brussels Effect is already visible. California's proposed AI safety legislation mirrors EU Act provisions. Corporate procurement departments are beginning to require AI Act compliance in vendor contracts, regardless of geography.

Companies that achieve EU AI Act compliance position themselves advantageously for future regulations and customer requirements worldwide.

Practical Steps for Mid-Market Companies

Start with an AI system inventory. Document every AI tool or system your company uses, from HR screening software to customer service chatbots. Classify each system's risk level based on EU Act criteria.

For high-risk systems, begin technical documentation immediately. This includes system design documents, training data descriptions, testing procedures, and performance metrics. The 10-year documentation requirement means starting now saves significant retroactive work.

Implement human oversight procedures. Ensure staff understand their monitoring responsibilities and have clear protocols for system intervention. This often requires both training and technical system modifications.

Establish ongoing compliance processes. EU AI Act compliance isn't a one-time project but a continuous operational requirement. Build monitoring, documentation, and review processes into standard operating procedures.

The Lomo Approach to AI Act Compliance

Many mid-market companies lack the internal expertise to navigate AI Act compliance while maintaining business momentum. This is exactly the challenge our embedded fractional Chief AI Officer model addresses.

Our Lomo Sprint process begins with a comprehensive AI system audit and risk classification. We then develop compliant implementation strategies that align with business objectives rather than treating compliance as a separate burden.

The regulatory landscape will only intensify. Companies that build strong AI governance foundations now position themselves for sustainable growth and competitive advantage.

Ready to turn AI Act compliance into a strategic advantage? Our Lomo Sprint can help you navigate these requirements while accelerating your AI initiatives.

Have questions about what this means for your business?

The Lomo Sprint is designed to answer exactly that. We're always happy to talk.

Let's Talk