Skip to content
Linkedin
  • en_USEN
    • bg_BGBG
  • en_USEN
    • bg_BGBG
  • Home
  • About us
    • Our Values
    • Our Commitment
    • Our Team
  • Our expertise
  • Careers
  • Events
  • News
  • Home
  • About us
    • Our Values
    • Our Commitment
    • Our Team
  • Our expertise
  • Careers
  • Events
  • News
Contact
  • Home
  • About us
    • Our Values
    • Our Commitment
    • Our team
  • Our expertise
  • Careers
  • News
  • Events
  • Contact
  • en_USEN
    • bg_BGBG
  • Home
  • About us
    • Our Values
    • Our Commitment
    • Our team
  • Our expertise
  • Careers
  • News
  • Events
  • Contact
  • en_USEN
    • bg_BGBG
September 18, 2026

The EU AI Act: Practical Business Guidance

 

Artificial intelligence is becoming part of everyday business operations, from drafting emails and analysing documents to recruiting employees, communicating with customers and assessing financial risk.

The EU Artificial Intelligence Act, Regulation (EU) 2024/1689, establishes a legal framework for the development, provision and professional use of AI systems. It does not prohibit ordinary business use of artificial intelligence. Instead, the requirements depend mainly on how the technology is used and the level of risk involved.

With the main provisions and transparency requirements applicable since 2 August 2026, businesses should identify which AI systems they use, understand how those systems affect people and introduce appropriate safeguards. Further details are available from the European Commission.

Which businesses are affected?

The AI Act may apply to almost any organisation that develops, offers, imports, distributes or professionally uses an AI system. A business using tools such as ChatGPT, Microsoft Copilot or Gemini, including AI functions built into accounting or recruitment software, will generally be considered a “deployer” and remains responsible for how the system is used.

The Act may also affect companies established outside the European Union if they offer AI systems in the EU or if the output produced by their systems is used within the EU.

Risk depends on how AI is used

The risk category of an AI system is determined mainly by its intended purpose and the way it is used, rather than by the technology or product name alone.

Business use Likely classification
Correcting the grammar and style of an email Minimal risk
Summarising an internal report Minimal risk
Operating a customer-service chatbot Transparency obligations
Generating advertising images Possible labelling obligations
Ranking or rejecting job applicants Potentially high risk
Recognising employees’ emotions in the workplace Generally prohibited

The same AI technology can therefore fall into different categories depending on the context in which it is deployed.

Understanding the main risk categories

Prohibited AI practices

Certain uses of AI are prohibited because they create an unacceptable risk to people’s rights and safety. These include specific forms of manipulative AI, social scoring and the exploitation of certain vulnerabilities. AI-based emotion recognition in the workplace is also generally prohibited, except in limited medical or safety situations. These restrictions have applied since 2 February 2025.

High-risk AI systems

AI systems may be classified as high-risk when used in sensitive areas such as recruitment, employee management, education, creditworthiness assessments, essential services and critical infrastructure.

Not every AI-assisted process in these areas is automatically high-risk. For example, an HR tool that extracts names and qualifications from CVs may be treated differently from a system that automatically ranks and rejects candidates.

High-risk systems face more extensive requirements concerning risk management, documentation, traceability, human oversight, accuracy and cybersecurity.

Under the updated implementation timetable, rules for high-risk systems in areas listed in Annex III, including employment, education and credit, will apply from 2 December 2027. Rules for high-risk AI incorporated into certain regulated products will apply from 2 August 2028. The European Commission’s guidance on high-risk AI systems provides further information.

Transparency and minimal-risk systems

Since 2 August 2026, specific transparency requirements have applied to certain AI systems. When customers communicate directly with a chatbot or virtual assistant, they should be informed clearly and promptly that they are interacting with AI, unless this is already obvious.

Deepfakes and certain AI-generated or substantially manipulated content may also need to be disclosed. More information is available in the European Commission’s guidance on AI-generated content.

Common tools for text editing, translation, document summarisation and idea generation are generally considered minimal risk. Businesses must still consider data protection, confidentiality, cybersecurity, copyright and employment legislation.

AI literacy is already a business obligation

Since 2 February 2025, providers and deployers have been required to promote an appropriate level of AI literacy among people using AI on their behalf.

Employees do not need to become technical experts. Training should reflect their responsibilities, experience, the system being used and its possible impact on affected individuals.

Employees should understand that AI output can be inaccurate, important results require human review and confidential information must not be entered into unauthorised systems. They should also know when AI content needs to be disclosed and how to report an incident.

Businesses should retain appropriate evidence of completed training.

Six practical steps for businesses

1. Prepare an inventory of AI systems.

Identify approved systems and public tools employees may use independently. Record their purpose, provider, data processed and influence on decisions concerning individuals.

2. Determine the organisation’s role

For each system, establish whether the business acts as a provider, deployer, importer, distributor or manufacturer of a product incorporating AI. The applicable responsibilities will depend on this role.

3. Classify each use

Consider whether the system supports employment decisions, credit assessments, biometric analysis, customer communication or public content. These uses may require a more detailed assessment.

4. Introduce an internal AI policy

The policy should identify approved tools and permitted uses, information that may be entered, situations requiring human review and the process for approving new systems. It should also cover content labelling, incident reporting and responsibility for final decisions.

5. Provide role-specific training

Training should reflect the risks encountered by different departments. Marketing teams may need guidance on content labelling and copyright. HR teams should understand discrimination risks and human oversight. Accounting and finance employees should focus on confidentiality, professional secrecy and the handling of client information.

6. Review contracts with AI providers

Businesses should request clear information about a system’s intended purpose, risk classification, limitations, data practices, security measures and compliance documentation. A general statement that a product is “AI Act compliant” should not replace proper due diligence.

Particular considerations for accounting and professional services

Professional-services firms regularly process financial records, contracts, personal information and commercially sensitive documents. Uploading such information to a public or unauthorised AI tool may create risks under data-protection rules, confidentiality obligations and professional standards.

Businesses should use approved corporate systems, restrict access according to employee responsibilities and anonymise information where appropriate. Original client documents should not be uploaded to public AI tools without a valid basis, appropriate safeguards and internal approval.

Human oversight also remains essential. AI may support research, drafting and analysis, but the responsible professional should verify the accuracy, relevance and completeness of the final result.

Preparing for responsible AI use

For most businesses, the AI Act does not mean giving up tools such as ChatGPT or Copilot. The greater practical risk is using AI without knowing which systems are in use, what information employees enter or whether automated results influence important decisions about people.

A sensible starting point is to create an inventory of AI systems, assess how they are used, establish clear internal rules and provide practical employee training. These measures can help businesses benefit from AI while protecting confidential information, maintaining human oversight and preparing for the remaining stages of the EU AI Act.

TGS Bulgaria can support businesses in reviewing their internal processes and assessing the financial, organisational and compliance implications associated with the professional use of artificial intelligence.

Other News

November 21, 2025

Key Questions and Answers on the Euro Adoption in Bulgaria

Essential points businesses need to know about Bulgaria’s switch to the euro in 2026.
READ MORE
July 22, 2025

Bulgaria’s Euro Adoption: 2026 Business Checklist

What the switch to the euro means for your business—key steps, deadlines, and how to prepare.
READ MORE

TGS Bulgaria
Sofia, Otets Paisiy 44 str.,
ent. 2, office 3

Information

  • Careers
  • About us
  • News
  • Contact
  • Careers
  • About us
  • News
  • Contact

Expertise

  • Tax Services
  • Advisory services
  • Accounting services
  • Audit
  • Tax Services
  • Advisory services
  • Accounting services
  • Audit

Contact

info@tgs-bulgaria.com

+ 359 2 952 57 14
+ 359 2 400 14 14

Legal

  • Privacy Policy
  • Cookie Plocy
  • Privacy Policy
  • Cookie Plocy
Linkedin

TGS Bulgaria is an independant member of TGS, an international network of professional business advisors and signatory of the United Nations Global Compact.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
X