The EU AI Act: Action Plan for Swedish Companies

By Weapp · Updated

The EU AI Act applies in full from August 2, 2026 – the AI literacy requirements and prohibitions have applied since February 2025. Swedish companies should inventory their AI use, classify it against Annex III, document human oversight and logs, and train staff. Sanctions have two caps per violation: a fixed amount or a share of global turnover.

The EU AI Act has been discussed for so long that many have stopped listening. That’s the wrong moment to tune out: the pilot phase is over. Parts of the regulation have applied since 2025, and on August 2, 2026, full applicability kicks in. Here’s the timeline, the requirements that can’t be delegated, and a priority order for companies without their own compliance department.

The timeline: most of it already applies

DateWhat applies
February 2025AI literacy requirements and bans on certain AI practices
August 2025Obligations for general-purpose AI models (GPAI)
August 2, 2026Full applicability – including the main requirements for high-risk systems

Reading the table matters more than the table itself: the literacy requirement and the bans aren’t something that’s “coming” – they’ve applied since February 2025. A company starting the work now isn’t building a buffer, it’s catching up.

The items you can’t delegate

No matter how much is bought in from vendors and consultants, a core set of obligations stays with you:

  • A competency plan – staff using AI must have sufficient knowledge, documented.
  • Human oversight – high-risk use requires designated, trained, and authorized human control.
  • Logs – automatically generated logs from high-risk systems must be retained, as a rule for at least six months.
  • Information to employees – affected staff must be informed when high-risk systems are used in the workplace.
  • Transparency to those affected – people must understand when they’re interacting with AI or affected by its decisions.
  • A FRIA – a fundamental rights impact assessment, where Annex III use applies to your operations.

The vendor’s documentation is supporting material for these items – never a substitute. What the list has in common is that it demands organization rather than technology: every item needs an owner, and the ownership needs to survive staff turnover.

The sanctions framework: two caps, the higher one applies

The sanction fees are built with two caps per violation – a fixed amount or a share of global turnover, whichever is higher. The level depends on the nature of the violation: prohibited practices sit at the top, failure to comply with other requirements in the middle, and providing incorrect information to authorities at the bottom.

A worked example from a decision brief: for a company with SEK 800 million in turnover, the cap per violation could land at SEK 8 million, SEK 24 million, or SEK 141 million depending on which level the violation falls under. The exact figure matters less than the insight: this isn’t a fee that disappears into a financial statement, and the board needs to see the risk picture before the regulator does. Sanctions aren’t the only risk either – customer contracts and procurements are already starting to raise AI Act questions, making compliance a business precondition rather than a legal footnote.

Priority order for an SME without a compliance department

For a Swedish company without its own in-house lawyer, the order matters more than the ambition. Four steps, in sequence:

  1. Inventory all AI use – including shadow AI in SaaS tools where AI features arrived bundled with the purchase.
  2. Classify each use against Annex III: if it touches recruitment, credit scoring, education, or other listed areas, it’s high-risk.
  3. Document – oversight, logging, information to those affected, and your assessments, dated.
  4. Train – the literacy requirement already applies, and completed training is the cheapest compliance point there is.

An example of what this looks like in practice: a manufacturing company with 120 employees runs an inventory and finds eleven AI uses. Nine are low risk – text assistance, translation, meeting notes. Two are candidates for high-risk: a CV-screening tool in recruitment and an AI feature in quality control. The company documents the classification, introduces human review of all recruitment outcomes, and trains the affected teams. That work – maybe a few weeks of effort – is the difference between a managed risk and an undetected one. Also expect the inventory itself to change the picture: most companies find more AI uses than they thought, and different ones than they were worried about.

Start at the right end

The EU AI Act rewards the same thing as good architecture: knowing what you have, why you have it, and who’s responsible. The inventory is therefore not just a compliance step but a map of where AI actually creates value for you. At Weapp we build AI solutions where the regulation’s requirements are part of the design from the start – get in touch if you want help going from timeline to action plan.

Frequently asked questions

Does the EU AI Act apply to small and mid-sized companies too?

Yes, there's no size threshold. The obligations depend on your role – provider or deployer of the AI system – and on the system's risk level, not on headcount. Some relief exists for smaller companies, but the baseline requirements apply to everyone.

What counts as high-risk under Annex III?

Annex III lists use cases, including AI in recruitment and personnel decisions, credit scoring, education, critical infrastructure, and law enforcement. It's the use that gets classified, not the technology – the same model can be high-risk in one workflow and minimal-risk in another.

We're not building our own AI – are we still affected?

Yes. Anyone who deploys AI systems in their operations has their own obligations, including AI literacy, human oversight, and logging for high-risk use. The fact that the tool was purchased doesn't shift responsibility for how it's used away from you.

What is a FRIA?

An assessment of the impact on fundamental rights, which certain deployers of high-risk systems under Annex III must carry out before deployment. It complements GDPR's impact assessment and documents the effect on the people concerned along with the safeguards in place.

What does the AI literacy requirement mean in practice?

That people using AI systems on your behalf have sufficient knowledge to understand the systems' capabilities, limitations, and risks. The requirement has applied since February 2025, and a documented competency plan with completed training is the natural evidence of compliance.