This article is part of the AI in the Real World series — practical guides for AI adoption, governance, and implementation in business.

Introduction

The EU AI Act entered into force in August 2024, with obligations phasing in through 2027. For Greek businesses, this is not Brussels bureaucracy — it is the legal framework that will govern every AI system you deploy. Understanding it now is not optional.

The Risk-Based Approach

The AI Act classifies AI systems into four risk categories, each with different obligations:

Unacceptable Risk (Prohibited)

These AI applications are banned entirely:

  • Social scoring by governments
  • Real-time biometric identification in public spaces (with narrow exceptions)
  • Emotion recognition in workplaces and schools
  • AI that exploits vulnerabilities of specific groups
  • Predictive policing based solely on profiling

High Risk

Heavily regulated, requires conformity assessment:

  • Biometric identification and categorisation
  • Critical infrastructure management
  • Education and vocational training access
  • Employment, worker management, self-employment access
  • Essential services access (credit, insurance)
  • Law enforcement applications
  • Migration, asylum, border control
  • Justice and democratic processes

Limited Risk

Transparency obligations only:

  • Chatbots must disclose they are AI
  • Emotion recognition systems must inform users
  • Deep fakes must be labelled
  • AI-generated content must be marked

Minimal Risk

No specific obligations, but voluntary codes of conduct encouraged. This includes most business AI applications: spam filters, inventory management, recommendation engines.

Timeline for Greek Businesses

DateMilestone
August 2024AI Act enters into force
February 2025Prohibited AI practices banned
August 2025GPAI model rules apply, governance structures required
August 2026Most obligations for high-risk AI apply
August 2027Full application to all AI systems

What Greek SMEs Need to Do

Immediate Actions (2025)

  1. AI inventory — Document every AI system in use, including third-party tools
  2. Risk classification — Categorise each system using EU criteria
  3. Prohibited use check — Ensure no banned applications are deployed
  4. Transparency review — Verify chatbots and AI content are properly disclosed

Medium-term Actions (2025-2026)

  1. High-risk assessment — If you deploy high-risk AI, begin conformity process
  2. Documentation — Create technical documentation and risk assessments
  3. Human oversight — Establish procedures for human review of AI decisions
  4. Supplier contracts — Update agreements with AI vendors for compliance clauses

Penalties

The AI Act has significant penalties:

  • Prohibited practices: Up to €35 million or 7% of global turnover
  • High-risk non-compliance: Up to €15 million or 3% of global turnover
  • Incorrect information: Up to €7.5 million or 1.5% of global turnover

For SMEs, penalties are capped at the lower of the fixed amount or percentage.

Greek National Implementation

Greece must designate:

  • A national supervisory authority
  • Market surveillance structures
  • A regulatory sandbox for AI innovation

The Ministry of Digital Governance is expected to coordinate, but specific structures are still being defined. Monitor announcements from the Hellenic Data Protection Authority and the Ministry.

Practical Compliance Steps

For Most Greek Businesses

If you only use minimal-risk AI (the majority of cases):

  1. Document your AI inventory
  2. Ensure transparency for chatbots and AI content
  3. Monitor for updates as you may add higher-risk applications

For High-Risk AI Users

If you deploy HR screening, credit scoring, or other high-risk systems:

  1. Conduct conformity assessment
  2. Implement quality management system
  3. Establish human oversight procedures
  4. Create incident reporting mechanisms
  5. Register in the EU database (when available)

Conclusion

The EU AI Act is the most comprehensive AI regulation in the world. Greek businesses have until 2027 for full compliance, but the smart ones are starting now. Begin with an inventory, classify your risks, and build compliance into your AI strategy from day one.