Ask ten business owners about the EU AI Act and you get two answers. Either it is a problem for 2027, or it already applies to everything and the fines are ruinous. Both are wrong, and both cost money.
The Act entered into force on 1 August 2024 and applies in stages. Those stages moved in July 2026. Today some of it is live and enforceable, more lands in December 2026, and the heaviest obligations sit in December 2027 and August 2028. A great deal of guidance still circulating online says the whole regulation became applicable in August 2026. It did not, and a compliance programme built on that reading spends its budget on the wrong controls in the wrong order.
What follows is the practical version, written for people who run businesses rather than people who argue about them in court. What applies now, what is coming, which role your company actually occupies, and what to do about it this quarter. The engineering counterpart to this guide, Engineering for the EU AI Act, covers how we build the same duties into product architecture rather than into a policy document.
1. What the EU AI Act actually is
The EU AI Act is Regulation (EU) 2024/1689, the first horizontal law anywhere that regulates artificial intelligence across every sector at once. It is not a data protection law, a product law or a copyright law. It sits alongside all of them.
Its model is risk based. The European Commission presents four tiers:
- Unacceptable risk. Banned outright.
- High risk. Permitted, with the largest set of obligations attached.
- Transparency risk. Permitted, with duties to tell people what they are dealing with.
- Minimal risk. The overwhelming majority of ordinary business AI, with no specific obligations beyond the general ones.
That last line matters more than anything else in this guide. The Act does not impose the same duties on every AI system. Most tools a normal company uses, the meeting summariser, the marketing copy assistant, the analytics model that forecasts demand, sit in the minimal tier. They need no registration, no conformity assessment and no CE marking. Anyone telling you otherwise is selling something.
2. Does the EU AI Act apply to your business?
Probably, and the answer does not depend on where your office is.
The Act has extraterritorial reach. It can apply to providers outside the EU who place AI systems or general purpose AI models on the EU market, and to providers or deployers outside the EU where the output of the system is used inside the EU. A British agency running an AI assistant for a customer in Dublin is in scope. So is a US software company whose product is resold into Germany.
Does the EU AI Act apply to UK or US companies? Yes, potentially. Where the company is headquartered is only one factor. Where the system is placed on the market, and where its output is used, matter more.
There is a second gate before scope: is the software an AI system at all? The Act defines one as a machine based system that operates with some autonomy, may adapt after deployment, and infers from its inputs how to generate outputs such as predictions, content, recommendations or decisions. Ordinary deterministic software does not automatically qualify. A workflow does not become regulated AI because it automates something. The question is whether the system infers an output or simply executes rules somebody wrote. That is the first decision node in the flow above, and getting it right removes a surprising amount of work from the rest of the exercise.
3. Provider or deployer, and why the difference decides your workload
The Act allocates duties by role, not by company size. The two roles that matter to almost everyone:
- A provider develops an AI system or general purpose AI model, or has one developed, and puts it on the market under its own name or trademark.
- A deployer uses an AI system under its own authority in a professional context.
The Act also recognises importers, distributors, authorised representatives and product manufacturers, which matter mostly in hardware and regulated goods.
| What your company does | Likely role |
|---|---|
| Uses Microsoft Copilot or ChatGPT internally | Deployer |
| Buys an AI customer service product and points it at your inbox | Deployer |
| Builds and sells an AI recruitment platform | Provider |
| Rebrands a bought in AI system and resells it as yours | Provider, by operation of Article 25 |
That last row is the trap. Article 25 can move provider obligations onto you if you put your name or trademark on a high risk system, modify it substantially, or change its intended purpose in a way that makes it high risk. Buying software does not automatically make compliance somebody else's problem, and a reseller who never reads the clause inherits duties it has not budgeted for.
4. What is banned outright
The prohibitions in Article 5 have applied since 2 February 2025. They are the strictest part of the Act, and they are already enforceable. They cover, among other things:
- harmful manipulation or deception that materially distorts behaviour;
- exploiting vulnerabilities tied to age, disability or socioeconomic situation;
- certain forms of social scoring;
- predicting criminality from profiling or personality traits alone;
- untargeted scraping of facial images from the internet or CCTV to build recognition databases;
- emotion recognition in workplaces and schools, with narrow exceptions;
- biometric categorisation that infers highly sensitive characteristics;
- most real time remote biometric identification in public by law enforcement.
The official Commission guidance is emphatic that these are assessed case by case. Two superficially similar systems can land on opposite sides of the line depending on purpose and context. The practical instruction for a business is narrower than it looks: screen for these once, honestly, and document the conclusion. Almost every commercial deployment clears the screen in an afternoon. The ones that do not are the ones you needed to find.
5. New prohibitions arriving in December 2026
The 2026 amendments added prohibited practices covering AI generated or manipulated intimate material involving identifiable people, and child sexual abuse material. These become applicable on 2 December 2026. Older articles on the AI Act will not mention them. If your product generates images or video, this is the one new prohibition to read in full.
6. What counts as high risk AI
There are two routes into the high risk category, and only two.
Route A, regulated products. The AI is itself a product, or a safety component of one, covered by existing EU product safety legislation that requires third party conformity assessment. Think machinery, medical devices, certain vehicles. These obligations apply from 2 August 2028.
Route B, Annex III use cases. A list of sensitive applications: biometrics; safety components in critical infrastructure such as water, gas, electricity and road traffic; education, including admissions, assessment and exam monitoring; employment, including recruitment, screening, promotion, task allocation and worker monitoring; access to essential services such as credit scoring, benefits, life and health insurance pricing and emergency triage; plus law enforcement, migration, justice and democratic processes. These apply from 2 December 2027.
Here is the nuance almost every summary drops. Article 6 lets a system that falls inside an Annex III area escape the high risk classification when it does not pose a significant risk to health, safety or fundamental rights, and performs only a narrow procedural or preparatory task. So the statement "all AI used in HR is high risk" is simply false. A tool that deduplicates applications is not doing the same job as a tool that ranks candidates for rejection. The accurate version:
Some AI used in recruitment, hiring, worker evaluation and employment decisions falls into the high risk category. Whether a specific system does depends on its intended purpose and on the Article 6 criteria.
If a system does land in high risk, the obligations are real. Providers face continuous risk management, data governance, technical documentation, automatic logging, transparency to deployers, human oversight design, accuracy and cybersecurity requirements, a quality management system, conformity assessment, a declaration of conformity, CE marking, registration, corrective action and post market monitoring. Deployers face a lighter but genuine set: follow the instructions for use, assign competent human oversight, keep input data relevant where they control it, retain logs, monitor operation and report serious incidents. Certain deployers must also complete a fundamental rights impact assessment before going live, which sits next to a GDPR data protection impact assessment rather than replacing it.
The honest summary: high risk compliance is not a form. It is a lifecycle governance process covering design, testing, documentation, deployment, monitoring and incident response. Which is precisely why December 2027 is not far away for anyone who has to build it.
7. What changed in 2026
Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026. It amended the AI Act, moved parts of the timetable and simplified several obligations, including proportionate relief for small and medium businesses.
The practical consequence is that any article, tracker or consolidated text written before late July 2026 may state deadlines that are no longer correct. The most common stale claim is that Annex III high risk obligations applied from August 2026. They did not. They apply from December 2027. Check the date on anything you rely on.
8. The transparency rules that landed in August 2026
Article 50 became applicable on 2 August 2026, and enforcement powers switched on for provisions that are already in force. This is the part that touches ordinary businesses today.
People must know they are talking to an AI. Where someone interacts directly with an AI system, it has to be designed so a reasonably informed person knows, unless that is already obvious. Chatbots, AI customer service agents, conversational assistants and voice agents are the obvious surfaces.
If a customer reasonably believes they are speaking to a person when they are actually dealing with an AI assistant, that is exactly the situation these rules exist to address.
Synthetic content has to be markable. Providers of systems that generate synthetic audio, images, video or text must make outputs machine readable and detectable as artificially generated. This duty sits mainly with the provider of the generating system, not with every company that uses it.
Deepfakes have to be disclosed. Deployers publishing AI generated or manipulated images, video or audio that would falsely appear authentic generally have to say so, with modified rules for artistic, creative, satirical and fictional work.
Some public interest text has to be labelled. Article 50 also covers AI generated text published to inform the public on matters of public interest, with an important exception where the content underwent human review and a person or organisation takes editorial responsibility for it. So no, not every AI assisted blog post has to carry a label. That claim is wrong, and it is repeated constantly.
One transition worth knowing: systems already on the market before 2 August 2026 have until 2 December 2026 to meet certain machine readable marking requirements, and content generated before August 2026 does not have to be retroactively labelled.
9. ChatGPT, Claude and general purpose AI models
General purpose AI models get their own regime, with provider obligations that have applied since 2 August 2025: technical documentation, information for downstream providers, a copyright policy, respect for rights reservations, and a sufficiently detailed public summary of training content. Models above a compute threshold of 10^25 FLOP are presumed to carry systemic risk and pick up evaluation, adversarial testing, incident reporting and cybersecurity duties on top.
The distinction businesses keep getting wrong:
Using ChatGPT does not make your company the provider of GPT.
Calling a third party model through an API makes you a deployer of a system, not the provider of the model. Your obligations attach to what you build on top and how you use it. Two further corrections while we are here. Open source AI is not automatically outside the Act; some exemptions exist for freely licensed general purpose models, but they are conditional and do not reach systemic risk models. And the Code of Practice on transparency of AI generated content is voluntary, with roughly 190 organisations signed by the end of July 2026. The statutory duty underneath it is not voluntary at all.
10. EU AI Act timeline, 2024 to 2028
| Date | What happens |
|---|---|
| 1 Aug 2024 | The AI Act enters into force |
| 2 Feb 2025 | Definitions, AI literacy and the original prohibited practices apply |
| 2 Aug 2025 | General purpose AI obligations and governance provisions apply |
| 27 Jul 2026 | Digital Omnibus amendments enter into force |
| 2 Aug 2026 | Article 50 transparency applies; enforcement begins for applicable provisions |
| 2 Dec 2026 | New intimate content and CSAM prohibitions apply; marking transition deadline closes |
| 2 Aug 2027 | Member States should have a regulatory sandbox operating |
| 2 Dec 2027 | Annex III high risk obligations apply |
| 2 Aug 2028 | High risk AI embedded in regulated products applies |
11. Fines and penalties
Worth stating plainly, because this is where the scaremongering lives. The maximum depends on which obligation was breached.
| Type of infringement | Maximum |
|---|---|
| Prohibited AI practices | €35m or 7% of worldwide annual turnover |
| Most other provider, deployer and transparency breaches | €15m or 3% of worldwide annual turnover |
| Supplying incorrect or misleading information | €7.5m or 1% of worldwide annual turnover |
| General purpose AI provider breaches, set by the Commission | €15m or 3% of worldwide annual turnover |
Article 99 provides for small and medium businesses, including startups, to face the lower of the fixed and percentage figures in defined cases. Enforcement is shared: national market surveillance authorities handle AI systems, the European AI Office handles general purpose models, and the European Data Protection Supervisor covers EU institutions.
Nobody is going to fine a company €35m for using ChatGPT clumsily. The headline number attaches to the banned practices, which almost no commercial deployment goes anywhere near.
12. What businesses should do now
Ten steps, in the order we actually run them with clients. The first three are cheap and unlock everything after.
- Build an AI inventory. Every tool in use: ChatGPT, Copilot, Claude, the CRM assistant, recruitment software, support chatbots, voice agents, marketing generation, fraud scoring, analytics, internal agents. You cannot classify what you have not listed, and the list is always longer than the leadership team expects.
- Fix your role per system. Provider, deployer, importer, distributor, product manufacturer. Write it down against each entry.
- Record the intended purpose. Classification turns on what the system is actually asked to do, so a vague description makes every later step guesswork.
- Screen for prohibited practices. Already enforceable. Do this once, properly.
- Review Article 50 exposure. Chatbots, customer service agents, voice systems, synthetic images, video and audio, deepfakes, published public interest text. These duties are live now, not in 2027.
- Put AI literacy measures in place. Also already required, and covered below.
- Flag potential high risk use cases early. HR, recruitment, worker monitoring, credit, insurance, education, biometrics, critical infrastructure, public services.
- Keep a vendor register. Provider, model, version, intended use, contract terms, data handling, documentation, risk classification, human oversight, applicable duties.
- Establish governance. Who approves an AI deployment, who owns compliance, who assesses high risk candidates, who monitors systems in production, who handles incidents, who trains staff. Named people, not a committee in the abstract. This is the same discipline we describe in Governed autonomy, where approval lanes and audit trails are what make agent systems safe to run at all.
- Design for the 2027 requirements now. Documentation, logging, monitoring, quality systems, data governance and human oversight are cheap to build into new software and expensive to retrofit. December 2027 is roughly one product cycle away.
12.1 AI literacy is already an obligation
This is the requirement most businesses miss entirely. Since 2 February 2025, under Article 4, both providers and deployers have had to take measures ensuring a sufficient level of AI literacy among the people who operate and use AI on their behalf. The 2026 amendments simplified the drafting; the obligation stands.
The Commission suggests covering what AI is, which systems the organisation uses, whether it is provider or deployer, the risks attached to those systems, and the existing technical knowledge of the staff involved. In practice this is a short internal programme, not a certification scheme. A company running nothing more exotic than a generative assistant still has an active duty here, which makes it the single most overlooked item on the list.
13. A compliance checklist you can run this quarter
- Inventory complete and owned by a named person.
- Role recorded for every system.
- Intended purpose documented for every system.
- Prohibited practices screen completed and signed off.
- Article 50 surfaces identified and disclosures shipped.
- AI literacy measures delivered and evidenced.
- High risk candidates flagged with a 2027 plan.
- Vendor register live and maintained.
- Approval gate defined, with the authority to say no.
- Logging and monitoring in place for anything customer facing.
If all ten are true, you are in better shape than most organisations we assess, and you have not stopped using AI anywhere it was creating value.
14. Frequently asked questions
Is the EU AI Act already enforceable? Yes, in part. AI literacy and most prohibited practices since February 2025, general purpose AI obligations since August 2025, transparency rules since August 2026. The major high risk obligations arrive in December 2027 and August 2028.
Does it apply to small businesses? Yes, though the Omnibus extended proportionate relief on documentation, quality management and penalties to small and medium businesses, including startups.
Does it apply to UK or US companies? It can. Placing a system on the EU market, or having its output used in the EU, is enough.
Does it apply to ChatGPT? The model provider carries the general purpose AI duties. A business using ChatGPT is normally a deployer with its own, different obligations.
Does all AI generated content have to be labelled? No. Providers must make synthetic output detectable, deployers must disclose deepfakes, and certain published public interest text must be labelled unless a person took editorial responsibility for it. Ordinary AI assisted work does not require a label.
Do chatbots have to say they are AI? In substance, yes, where a person is interacting directly with the system and it would not already be obvious.
Is AI recruitment high risk? Some of it. Annex III covers recruitment and employment decisions, but the Article 6 filter can exclude narrow procedural tools. Classification depends on intended purpose.
Does the AI Act replace GDPR? No. It sits alongside GDPR, employment law, consumer law, cybersecurity rules, copyright and product safety legislation.
Does it apply to open source AI? Sometimes. Exemptions exist for certain freely licensed general purpose models, but they are conditional and do not cover systemic risk models.
15. How we think about it
The central point of this guide is not a legal one.
The EU AI Act is not primarily a reason to stop using AI. It is a reason to know what AI your business is running, what it has been asked to do, and where human accountability still sits.
Commercially, the sequence is: understand the process, classify the risk, put the right controls around it, and keep using AI everywhere it creates measurable value. That is the same order we work in when we build systems for businesses, and it is why our own products are designed with disclosure, provenance and human oversight as architecture rather than configuration. Nure runs governed agents that correspond with people on a business's behalf, which puts it squarely inside Article 50, and the transparency controls are built into the pipeline rather than bolted onto the settings page.
If you are working out where your AI systems sit, or you need the classification and controls built rather than described, talk to us.
16. Sources and disclaimer
- Regulation (EU) 2024/1689, the AI Act, on EUR-Lex.
- Regulation (EU) 2026/1744, the Digital Omnibus on AI.
- European Commission, regulatory framework for AI.
- Official AI Act Service Desk and its implementation timeline.
- Article 5, prohibited practices and Annex III.
- Article 50, transparency and the Commission's transparency FAQ.
- Article 53 and Article 55 on general purpose AI, plus the Commission's AI literacy questions and answers.
- Article 99, Article 101 and the enforcement framework.
This article provides general information about the EU AI Act and is not legal advice. The position depends on the specific system, its intended purpose, the sector and the role your organisation occupies. Anyone dealing with high risk or otherwise sensitive deployments should take qualified legal and compliance advice, and confirm dates against the Official Journal text.
This guide sits in our Operations research. The technical companion is in Engineering, and related work runs through the governance, operations, generative and research note threads. The full library is at Research.