The EU Artificial Intelligence Act is the first comprehensive AI framework in the European Union, and its reach extends well beyond the technology sector. This guide sets out who it applies to, what non-compliance costs, the contract clauses that matter most, and the questions a board should be asking.
Why the EU AI Act matters for all companies
The EU Artificial Intelligence Act is the first major regulatory framework for artificial intelligence, and its impact will extend far beyond the technology sector.
The obligations follow the AI system, not the company's self-description. The Act applies to organisations that develop, use or procure AI systems in the EU, regardless of size or industry. A manufacturer running an AI-assisted quality check, a retailer using automated CV screening and a logistics operator relying on a route-optimisation tool are all in scope, whether or not they consider themselves technology businesses.
This is the point most often missed: a company that has built nothing itself, and only licenses AI tools from third parties, still carries compliance obligations. Buying the technology does not transfer the responsibility for how it is used.
Business risks of non-compliance with the EU AI Act
Under the EU AI Act, companies face serious consequences if they fail to meet compliance obligations:
- Fines of up to 35 million euros or 7% of global annual turnover
- Suspension of AI systems
- Legal claims from customers or employees
- Reputational damage
- Loss of trust among partners, suppliers and investors
The financial penalty is rarely the whole exposure. Suspension of a system that sits inside a live operational process, and the contractual consequences that follow, can cost more than the fine itself.
Practical compliance strategies for businesses
To reduce risk and ensure readiness, companies should:
- Map current AI use across operations, including tools adopted by individual teams without central approval
- Review all third-party AI systems and the documentation each vendor can actually produce
- Update contracts with AI compliance clauses
- Train legal, procurement and IT teams on documentation requirements
- Establish internal AI policies setting out who approves new tools and on what basis
AI compliance clauses: a must-have in contracts
AI compliance warranties
- Vendor confirms EU AI Act compliance
- Risk assessments conducted
- Prohibited practices excluded
Audit and transparency rights
- Documentation access
- Regular audits
- Explanation of AI decisions
Liability provisions
- Vendor assumes liability for non-compliance
- Indemnification clauses
- Immediate termination rights
What boards should discuss about AI risk and governance
Boards must take an active role in AI oversight, and the discussion works best when it is anchored to specific questions rather than general principles:
- Where is AI used in our operations, and who maintains that inventory? An oversight discussion is not possible without a current list.
- Which systems, ours or our vendors', carry the highest risk? Obligations scale with the risk classification, so the classification has to be made deliberately.
- What do our contracts actually say? Whether vendors have warranted compliance, whether we hold audit rights, and who bears liability if a system turns out to be non-compliant.
- Who is accountable internally, and is it documented? Supervisors will ask, and a decision that was never minuted is difficult to evidence afterwards.
- What happens if a system has to be switched off tomorrow? If a core process depends on a single AI tool, suspension is an operational risk as much as a legal one.
Frequently asked questions
Who does the EU AI Act apply to?
The EU AI Act applies to companies that develop, use or procure AI systems within the EU, regardless of their size or industry. Even a company that only uses third-party AI tools has compliance obligations.
What are the penalties for non-compliance with the EU AI Act?
Penalties can reach up to 35 million euros or 7% of global annual turnover. Companies may also face suspension of AI systems, legal claims from customers or employees, and significant reputational damage.
What should companies do to prepare for the EU AI Act?
Map AI use cases across operations, review all third-party AI systems, update contracts with AI compliance clauses, implement internal AI governance policies, and train legal, procurement and IT teams on documentation requirements.
What AI compliance clauses should companies include in contracts?
Contracts should include AI compliance warranties confirming the vendor meets EU AI Act requirements and has conducted risk assessments; audit and transparency rights covering documentation access and explanation of AI decisions; and liability provisions covering vendor responsibility for non-compliance, indemnification and immediate termination rights.
Conclusion: turning compliance into competitive advantage
AI can transform your business, but only if it is used responsibly and compliantly. The work described above is not only defensive: an organisation that can show where AI is used, how it was assessed and what its vendors have warranted is in a stronger position in procurement, in due diligence and in front of a supervisor than one that cannot.
Companies that treat AI governance as a documentation exercise to be done once will repeat it every time the technology changes. Those that build it into how tools are approved and contracted will not.
Need support drafting AI-compliant contracts and safeguarding your business?
Our team at LKOS Law Office helps companies navigate the EU AI Act and embed compliance into every agreement, from vendor due diligence to board-level documentation.
Contact us to make sure your contracts protect your business rather than expose it, or read more about our
ESG and compliance services and
contract law practice.