Does the EU AI Act apply to us? A checklist for Australian businesses
The EU AI Act is the first broad AI law in the world, and it does not stop at Europe's border. It reaches a business anywhere if the output of its AI system is used in the EU. For most Australian businesses of 10 to 500 people the honest answer is "no, not today". For a minority with EU customers, exports or platforms, the answer is "yes, and here is what tier". These seven questions sort you into one of those two groups in about ten minutes.
This is a checklist, not legal advice. If question 1 or 2 is a yes, get advice. The Act's own text, on eur-lex.europa.eu, governs.
The seven questions
1. Do we sell, deploy or make available an AI system to anyone in the EU?
"Provider" covers a business that puts an AI system on the EU market under its own name, even if it is built by someone else. "Deployer" covers a business established in the EU that uses one. If you have an EU entity, EU customers using your product, or an EU distributor, you are in scope for that system. Write down which systems.
2. Is the output of any of our AI systems used in the EU?
This is the reach that catches Australian businesses. A scoring, a decision, a recommendation or generated content produced here and used in the EU brings the provider and the deployer in scope, regardless of where the company sits and without any test of intent. A quoting agent whose quotes go to EU buyers, a screening tool used on EU applicants, a chatbot on a site serving EU visitors: each is a candidate.
3. Does any system do a prohibited practice?
A short list, in force since February 2025: manipulative or deceptive techniques that distort behaviour, exploiting vulnerabilities, social scoring, untargeted scraping of facial images, emotion recognition in workplaces and schools, biometric categorisation by protected characteristics, and most real-time remote biometric identification. Almost no business in our client base goes near these. Confirm it and move on.
4. Does any system fall in a high-risk use?
High risk is where the real obligations sit. Annex III lists the uses: biometrics, critical infrastructure management, education and vocational training decisions, employment and worker management (recruitment screening, promotion, task allocation, monitoring), access to essential services including credit scoring and insurance pricing, law enforcement, migration, and justice. A second group covers AI as a safety component of regulated products such as machinery and medical devices. If a system you deploy for EU use sits in one of these, it is high risk.

5. Is any system a general-purpose model, or built on one?
Obligations on general-purpose AI models fall on their providers, the model makers, from August 2025. If you build on a commercial or open model you are not the model's provider, but you should be able to name it, which is what the open supply chain guardrail asks anyway.
6. Does any system talk to people, or generate content people see?
Transparency duties apply to chatbots and to generated audio, image, video and text presented as real. People must be told they are dealing with AI, and synthetic content must be marked as such. This is the tier most Australian businesses with EU-facing sites land in, and it is cheap to satisfy: the plainly disclosed guardrail already does it.
7. When do the obligations bite?
Prohibited practices since 2 February 2025. General-purpose model obligations since 2 August 2025. High-risk obligations were scheduled for 2 August 2026 for Annex III uses and 2 August 2027 for product-embedded systems. A 2025 European Commission "Digital Omnibus" proposal would push the high-risk dates back. Check the current timetable on eur-lex before relying on any date; this is the part of the Act that moves.

Reading your answers
- No to 1 and 2: out of scope today. Note the systems you checked and the date, and re-run the list when you win an EU customer.
- Yes to 1 or 2, no to 3 and 4, yes to 6: limited-risk tier. Disclose that people are dealing with AI and mark generated content. Keep a record of what you did.
- Yes to 1 or 2 and yes to 4: high-risk tier. Get advice. Expect a risk management system, data governance, technical documentation, logging, human oversight, accuracy and robustness requirements, and a conformity assessment. The Guardrails Framework covers the same ground in plain English and gives you a head start on the evidence.
- Yes to 3: stop the practice. There is no compliance path for a prohibited use.
What to do this month if you are in scope
- Name an owner for each in-scope system. One person, with authority to pause it.
- Write the register: system, purpose, EU exposure, tier, models underneath, data in and out.
- Add disclosure wherever a person meets the system.
- Start the record: what was tested, who signed off, what changed.
- If high risk, brief your lawyer with the register in hand. It halves the cost of the advice.
The free AI enablement audit scores governance as one of its six pillars and produces the register above as a by-product. The Guardrails Framework is the plain-English version of the same obligations, built for Australian businesses that do not have a compliance department.