European legislation rarely features on an Iranian manager's list of concerns — until the day a new annex appears in a foreign client's draft contract asking you to document how your data-driven systems align with the EU's AI requirements. That is when a distant legal text becomes a practical condition for keeping a market.
The EU AI Act entered into force in August 2024 and its obligations arrive in stages: from 2 February 2025, the prohibitions on unacceptable-risk practices and the AI-literacy duty; from 2 August 2025, the obligations for general-purpose models and the governance structure; and under the Act's own timetable, most high-risk system requirements from 2 August 2026 onward.
Four risk tiers: the backbone of the law
- Unacceptable risk: prohibited uses, such as social scoring and exploiting the vulnerabilities of specific groups.
- High risk: systems affecting people's rights, such as CV screening, credit assessment and medical applications; the heaviest documentation and oversight duties.
- Limited risk with transparency duties: chat assistants and generated content, where users must know they are dealing with a machine.
- Minimal risk: most ordinary enterprise applications, with few mandatory obligations.
Why it reaches an Iranian company's contracts
There are two routes. First, the Act's extraterritorial reach: when a system's output is used within the Union, the relevant duties can be triggered even if the developer sits elsewhere. Second, and in practice sooner, contractual pass-through: the obliged European company hands those duties to you as contract clauses and supplier questionnaires. For an export-oriented firm, it is the second route that decides who wins the tender.
The documentation a foreign client will ask for
- A clear description of the system's purpose, intended users and risk tier.
- The provenance of training data and the lawful basis for using it.
- Quality and error assessment, together with the system's known limitations.
- Event logging and log retention for audit and traceability.
- The human oversight point and a mechanism for contesting or reviewing a decision.
- Marking of generated content and disclosure when users interact with an automated system.
None of this is exotic; the list is more or less what any well-engineered system should have anyway.
Early compliance as a negotiating advantage
Building this documentation from day one costs a fraction of reconstructing it under deadline pressure. An organisation that knows its risk tiers and has designed its human oversight point answers a supplier questionnaire within days; against a competitor who needs months, that speed is a commercial advantage.
Where to start
- Month one: build a complete inventory of live and in-development AI applications and assign a risk tier to each.
- Month two: for higher-risk applications, document data provenance, error assessment, the human oversight point and log retention policy.
- Month three: prepare a ready response pack for client questionnaires and name an owner for keeping it current.
Common mistakes
- Assuming that operating outside the Union exempts you; the European client passes the obligation on.
- Delegating everything to legal, when most documentation belongs to engineering and the process owner.
- Documenting once and filing it away; every change to the model or training data makes the file stale.
- Freezing innovation in the name of compliance, when most ordinary applications sit in the minimal-risk tier.
Frequently asked questions
- We have no European clients; does this still matter?
If exporting services or software is anywhere in your horizon, yes; producing the documentation now is cheaper than retrofitting it years later. - Are only large systems in scope?
Obligations follow the risk of the use case, not company size; a small CV-screening tool can carry heavier duties than a large content recommender. - What is the cheapest place to start?
The application inventory with a risk tier for each item; that one- or two-page document is the foundation for everything else.
Takeaway
For an Iranian company the EU AI Act is less a legal duty than a market standard: the language in which foreign clients judge whether your system can be trusted. An organisation that writes down its application inventory, risk tiers, data provenance and human oversight points today has ready answers in tomorrow's negotiation; the other builds compliance under deadline pressure at several times the cost.
Glossary
- EU AI Act: the European framework setting obligations for AI systems by level of risk.
- Compliance: documented adherence to mandatory rules, and the ability to demonstrate it.
- Risk tier: the classification of a use case by its potential effect on rights and safety.
- General-purpose model: a foundation model used across varied applications, with its own transparency obligations.
- Extraterritorial reach: a law's effect on companies outside its territory whose output is used inside it.