Guide · Last reviewed 26 August 2026

The EU AI Act, explained for companies

The EU AI Act is Regulation (EU) 2024/1689, in force since 1 August 2024 and amended by the Digital Omnibus on AI, Regulation (EU) 2026/1744 of 8 July 2026 (in force 27 July 2026). As of August 2026, the prohibited-practices rules (Article 5), the AI literacy obligation (Article 4), the transparency duties (Article 50) and the general-purpose AI rules already apply; high-risk obligations follow from 2 December 2027 (Annex III) and 2 August 2028 (Annex I products).

Last reviewed: 26 August 2026 · Primary source: Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744.

What the EU AI Act is

The EU AI Act — Regulation (EU) 2024/1689 — is the world's first comprehensive law regulating artificial intelligence. It entered into force on 1 August 2024 and applies in stages. In July 2026 it was significantly amended by the Digital Omnibus on AI, Regulation (EU) 2026/1744 (adopted 8 July 2026, published in the Official Journal 24 July 2026, in force 27 July 2026), which pushed back the high-risk deadlines, softened the AI literacy duty, added new prohibitions and introduced fine relief for smaller companies. Everything on this site reflects the Act as amended — a lot of older guidance on the web still describes the pre-Omnibus version.

The Act is a product-safety-style regulation: it does not regulate 'AI' in the abstract, but specific AI systems and general-purpose AI models, and it attaches obligations to defined roles in the value chain — above all providers (who develop or place systems on the market) and deployers (who use them under their own authority). See our guide on the provider vs deployer distinction — it is the single most important classification you will make.

Who the Act covers

The Act applies far beyond AI companies. You are in scope if you:

  • Develop or sell AI systems in the EU market, wherever you are established (providers, Article 2(1)(a));
  • Use AI systems in the course of business in the EU — including ordinary companies using third-party tools such as chatbots, generative AI, scoring or screening software (deployers, Article 2(1)(b));
  • Are established outside the EU but the output of your AI system is used in the EU (Article 2(1)(c));
  • Import or distribute AI systems into the EU.

Purely personal, non-professional use is out of scope, as are systems used solely for military purposes and (with limits) scientific research and development. But for a normal company, the practical rule of thumb is: if your staff use AI tools at work, or your products contain AI, at least some obligations apply to you today.

The risk-based system

The Act sorts obligations by risk rather than by technology:

  • Prohibited practices (Article 5) — a closed list of banned uses (manipulative techniques causing significant harm, social scoring, untargeted facial-image scraping, emotion recognition at work and in education, and others), applicable since 2 February 2025. The Omnibus added prohibitions on AI systems that generate or manipulate child sexual abuse material and non-consensual intimate imagery, applicable from 2 December 2026.
  • High-risk systems (Article 6, Annexes I and III) — systems in sensitive areas (employment, credit, education, essential services, biometrics and more) or embedded as safety components in regulated products. These carry the heaviest duties — risk management, data governance, technical documentation, human oversight, conformity assessment — from 2 December 2027 (Annex III) and 2 August 2028 (Annex I). See high-risk AI systems explained.
  • Transparency duties (Article 50) — disclosure and marking rules for chatbots, synthetic content, emotion recognition and deepfakes, applicable since 2 August 2026. Note: 'limited risk' is convenient shorthand, not a statutory category — Article 50 applies to systems regardless of their risk class.
  • General-purpose AI models (Chapter V) — obligations for model providers such as documentation, copyright policy and training-data summaries, applicable since 2 August 2025 and enforceable with fines of up to €15 million or 3% of worldwide turnover since August 2026.

What applies now vs later (post-Omnibus timeline)

As of August 2026, the following are already binding:

  • Since 2 February 2025: the original Article 5 prohibitions, and Article 4 — the duty to take measures that support the development of sufficient AI literacy among your staff (softened by the Omnibus: no guaranteed competence level per individual is required). See Article 4 AI literacy.
  • Since 2 August 2025: general-purpose AI model rules, governance structures, penalties framework.
  • Since 2 August 2026: Article 50 transparency duties — with a grace period to 2 December 2026 for the Article 50(2) marking duty for generative systems already on the market before 2 August 2026. See Article 50 transparency.

Still to come:

  • 2 December 2026: the new CSAM/NCII prohibitions.
  • 2 December 2027: high-risk obligations for Annex III systems (moved from 2 August 2026 by the Omnibus).
  • 2 August 2028: high-risk obligations for Annex I product-embedded AI.
  • 2 August 2030: longstop for certain pre-existing systems used by public authorities.

Full date-by-date breakdown: EU AI Act deadlines. What the July 2026 amendment changed: the Digital Omnibus explained.

Penalties — and the SME cap

Maximum fines are tiered: up to €35 million or 7% of worldwide annual turnover for prohibited practices, €15 million or 3% for most other violations (including the GPAI rules), and €7.5 million or 1% for supplying incorrect information to authorities. For most undertakings the applicable cap is whichever amount is higher; for SMEs and start-ups it is whichever is lower (Article 99(6)), and the Omnibus extended this proportionate treatment to small mid-caps as defined in Commission Recommendation (EU) 2025/1099. Details: AI Act fines and the AI Act for SMEs.

Where to start

For most companies the practical sequence is short: build an inventory of the AI systems you use or provide, determine your role for each, screen against Article 5, put Article 4 literacy measures in place, implement the Article 50 transparency duties that match your role, and diarise the 2027/2028 high-risk deadlines for anything that may fall under Annex III or Annex I. Our step-by-step compliance checklist walks through exactly this, with the article numbers and dates for each step — and our template kit gives you the documents to implement it.

All guides in this series

Related reading

Frequently asked

Does the EU AI Act apply to companies outside the EU?+

Yes. It applies to providers placing AI systems on the EU market wherever they are established, and to providers and deployers in third countries where the output produced by the system is used in the EU (Article 2(1)).

Is the EU AI Act already in force in 2026?+

Yes. The Act entered into force on 1 August 2024 and applies in stages: prohibitions and AI literacy since 2 February 2025, GPAI rules since 2 August 2025, and transparency duties since 2 August 2026. High-risk obligations follow on 2 December 2027 (Annex III) and 2 August 2028 (Annex I).

What did the Digital Omnibus change in 2026?+

Regulation (EU) 2026/1744 (in force 27 July 2026) postponed the high-risk deadlines to 2 December 2027 and 2 August 2028, softened Article 4 AI literacy, added CSAM/NCII prohibitions from 2 December 2026, inserted Article 4a on bias detection, extended SME fine relief to small mid-caps, and moved machinery to Annex I Section B.

My company only uses ChatGPT and similar tools — are we covered?+

Yes, as a deployer. You must take AI literacy measures for staff (Article 4) and comply with deployer transparency duties where relevant, such as disclosing deepfakes or AI-generated public-interest text (Article 50(4)). The machine-readable marking duty under Article 50(2) stays with the tool's provider, not you.

Is there an official 'limited risk' category in the AI Act?+

No. The Act defines prohibited practices, high-risk systems, transparency duties under Article 50 and GPAI rules. 'Limited risk' and 'minimal risk' are explanatory shorthand — and Article 50 duties apply to systems in scope regardless of risk classification.

Primary sources

See exactly what applies to your company

Six questions, two minutes, no signup.

Run the check