EU AI Act compliance step by step: what a company actually has to do

Most companies don't build AI, they use it. Your obligations depend on which role you're in. This walks through the classification and what each role actually owes.

16 min readByBoncz Bálint

Does the EU AI Act apply to my company, and what changed in summer 2026?

If your company uses or offers any AI system in the Union, the regulation reaches you. But most executives are working from the wrong date. The 2 August 2026 deadline for high-risk systems moved to 2 December 2027. What actually started applying on 2 August 2026 was the Article 50 transparency set.

The postponement came through Regulation (EU) 2026/1744, which the press calls the Digital Omnibus on AI. The Commission proposed it in November 2025, the trilogue closed on 7 May 2026, Parliament adopted it on 16 June, the Council on 29 June, publication in the Official Journal followed on 24 July, and it entered into force on 27 July 2026. Six days before the original deadline.

2026-08-02

Article 50 transparency, already applicable

2027-12-02

Annex III high-risk systems, new date

2028-08-02

Annex I product-embedded systems

The delay is breathing room, not a gift. Sixteen months is not much time to build a risk management system, data governance and technical documentation for an Annex III system, especially since most companies had not started the inventory before the original deadline either. Anyone settling into a “we will deal with it in 2027” posture will arrive at exactly the same place, a year and a half later.

When does each obligation actually apply? The timeline before and after the omnibus

The omnibus moved three things: the high-risk compliance package, the deadline for regulatory sandboxes, and Annex I product-embedded systems. It left the prohibitions, the GPAI rules and the penalty regime alone. The table below puts the original and the current date side by side, so you can see what moved and what did not.

Obligation setOriginal dateDate after the omnibusStatus in August 2026
Article 5 prohibited practices2025-02-02unchangedapplicable
Article 4 AI literacy2025-02-02same date, softened wordingapplicable
GPAI models (Art. 53 to 55), governance, Art. 99 penalties2025-08-02unchangedapplicable
Article 50 transparency duties2026-08-02unchangedapplicable
Art. 50(2) marking on systems already on the marketno separate date2026-12-02grace period running
New Article 5 prohibition: generating NCII and CSAMdid not exist2026-12-02transition running
Regulatory sandboxes (Art. 57) set up by member states2026-08-022027-08-02postponed
GPAI models placed on the market before 2025-08-022027-08-02unchangedahead of us
Annex III standalone high-risk systems (Art. 8 to 27)2026-08-022027-12-02postponed by 16 months
Annex I product-embedded high-risk systems2027-08-022028-08-02postponed by 12 months
Sources: Regulation (EU) 2026/1744, FPF timeline analysis (2026-07-28), European Commission.

It pays to be precise about what went into the future and what stayed here. Chapter III Sections 1 to 3 moved to 2 December 2027, and that includes the Article 27 fundamental rights impact assessment, because Articles 26 and 27 sit in Section 3.

Applicable todayPostponed to 2027-12-02
Article 5 prohibitions and the Article 99 penaltiesArt. 8 to 15: risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy
Article 50 transparency: chatbot disclosure, synthetic content marking, deepfake labellingArt. 16 to 25: provider, importer and distributor duties, Art. 17 quality management, Art. 43 conformity assessment, Art. 47 declaration, Art. 48 CE marking, Art. 49 registration
GPAI: Art. 53 to 55, plus the Commission enforcement powers live since 2026-08-02Art. 26 deployer obligations and the Art. 27 FRIA

Are you a provider or a deployer? That question decides everything else

Almost every obligation in the regulation attaches to a role, not to company size. Under Article 3(3) a provider develops an AI system and places it on the market under its own name or trademark. Under Article 3(4) a deployer uses someone else’s system under its own authority. The line runs at the name, not at the code.

What you do in the companyYour roleWhat applies to you now
Your team uses ChatGPT or Claude for email, notes and codingDeployer. The provider is OpenAI or Anthropic.Article 4 support for AI literacy, GDPR separately. No high-risk obligation.
You bought a chatbot from a development agency and it runs on your site under your nameYou are most likely the provider under Article 3(3), the agency is a supplier.Art. 50(1) chatbot disclosure since 2026-08-02. Art. 50(2) machine-readable marking on generative output.
You build your own AI product and sell it under your own trademarkProvider, in every case.Article 50 now. If the intended purpose falls under Annex III, all of Chapter III from 2027-12-02.
As an integrator you embed someone else's model into your client's systemDepends whose name it goes into service under. Usually the client is the provider and you are a supplier.Settle the role and the documentation duty in the contract. Article 25 can flip it.
You run a general purpose model over CV screening or promotion recommendationsDeployer in an Annex III point 4 use case, and Art. 25(1)(c) can make you a provider too.Article 26 duties from 2027-12-02. The classification and the decision, however, are due now.

Article 25 pushes a deployer into provider status in three cases. When it puts its own name or trademark on a high-risk system already on the market. When it makes a substantial modification and the system stays high risk. And when it changes the intended purpose of a system that was not classified as high risk, including a general purpose AI system, so that it becomes high risk. The original provider is then released, but has to cooperate and grant reasonable technical access.

In practice this clause is missing from most development contracts. In German and Austrian projects the contract argument usually runs along the Werkvertrag and Dienstvertrag split under sections 631 and 611 BGB, which allocates delivery risk and acceptance but says nothing about who is the provider under Article 3(3). Those are two separate questions and both belong in the document. One paragraph now is cheaper than a dispute in the middle of a market surveillance procedure.

Step 1: how do you build an AI system inventory?

The inventory is the one work product every company should produce regardless of role or risk category. A single table listing every tool that contains AI, including the assistants embedded in software you already pay for. Without it, classification is guesswork and there is nothing to hand an authority that asks.

Start the search at finance, not at IT. Card statements and SaaS invoices reveal more shadow tooling than any internal survey: translation plugins, meeting note takers, CV ranking modules inside the ATS, lead scoring built into the CRM, sentiment analysis in the support desk. All of these are AI systems in the sense of the regulation.

SystemWhere we use itRoleModel and vendorData categoriesDecision without human sign-off?Classification
Customer service chatbot on the websiteMarketing, customer serviceProviderGPT API, OpenAIName, email, order numberNo, escalates to a human agentArticle 50(1) transparency duty
CV pre-screening in the ATSHR, recruitmentDeployer, possibly providerVendor's built-in modelApplicant CV, contact detailsYes, it ranks and filters outAnnex III point 4, high risk
Invoice data extraction in accountingFinanceDeployerDocument processing cloud serviceInvoice data, partner dataNo, the accountant approves every itemMinimal risk
These seven columns are the minimum. Add two more: accountable owner, date of last review.

Step 2: which risk category does your system fall into?

Four categories exist. Prohibited under Article 5, high risk under Article 6(1) with Annex I or Article 6(2) with Annex III, transparency risk under Article 50, and minimal risk, which carries no specific duty. Classification happens per system and per intended purpose, never at company level.

Annex III lists eight areas: biometrics, critical infrastructure, education, employment and worker management, access to essential services (this covers creditworthiness assessment and life or health insurance risk pricing), law enforcement, migration and border control, and administration of justice and democratic processes. Most mid-sized European companies only ever meet the fourth and the fifth.

Article 6(3) is the escape hatch. A system that falls under Annex III is nevertheless not high risk if it does not pose a significant risk and one of four conditions holds. It performs a narrow procedural task. It improves the result of previously completed human activity. It detects decision patterns or deviations without replacing human assessment. Or it performs a preparatory task. Where the system profiles natural persons, it is always high risk and no exception applies. The provider has to document the assessment before going to market and still register under Article 49(2). The omnibus made that registration lighter, it did not delete it.

We walked the classification through question by question in a separate piece: the decision tree for high-risk AI systems. If the outcome is high risk, the Annex III compliance checklist shows which work products come with it.

Step 3: what is already mandatory in August 2026?

Three things. The Article 5 prohibitions since 2 February 2025, Article 4 AI literacy from the same day, and the Article 50 transparency duties since 2 August 2026. All three apply to every company regardless of size or risk classification, and the penalty regime has been live since 2 August 2025.

Article 5: what is off limits entirely

Of the eight prohibited practices, two are the ones an ordinary company runs into by accident. The first is emotion recognition in the workplace and in education under 5(1)(f), outside medical and safety purposes. Sentiment analysis on call centre recordings counts, if it is aimed at the employee. The second is biometric categorisation under 5(1)(g) where it infers a protected attribute. The remaining prohibitions cover manipulative techniques, exploitation of vulnerability, social scoring, crime prediction based solely on profiling, and untargeted scraping of facial images.

The omnibus added one prohibition: AI intended to generate or manipulate non-consensual intimate imagery and child sexual abuse material. Anyone running a generative system has until 2 December 2026 to put the filtering in place.

Article 50: what has to be written on the screen

This is the set that went live twelve days ago and that most European websites currently fail. Its four paragraphs cover four different situations.

SituationWhat it requiresLegal basisFrom when
The user interacts directly with an AI systemTell them they are talking to an AI, unless that is obviousArt. 50(1)2026-08-02
The system generates synthetic text, image, audio or videoMark the output in machine-readable form as artificially generatedArt. 50(2)2026-08-02, and 2026-12-02 for systems already on the market
You operate an emotion recognition or biometric categorisation systemInform the exposed persons that the system is operatingArt. 50(3)2026-08-02
Deepfakes, or AI-generated text published on matters of public interestDisclose visibly that the content is artificially generated or manipulatedArt. 50(4)2026-08-02, no grace period

For the technical side of this, the Commission finalised the Code of Practice on Transparency of AI-Generated Content on 10 June 2026. Signing it is voluntary, but it carries a presumption of conformity and it names concrete marking techniques.

Article 4: AI literacy, now softer

The original text said providers and deployers shall ensure a sufficient level of AI literacy among their staff. The omnibus rewrote it: they shall support the development of AI literacy. An obligation of result became an obligation of effort. In practice a documented internal training session and a usage policy are enough, and you do not have to examine your colleagues.

I would not treat that as a solved item. Article 4 is the one clause that touches every company and the cheapest thing for an authority to check. A three-page AI usage policy plus a dated attendance sheet from one training session is a few hours of work.

Step 4: what do you need ready by 2 December 2027?

If classification came out high risk, the full Chapter III package applies from 2 December 2027, or from 2 August 2028 for Annex I product-embedded systems. The package is not a set of declarations. It is working processes plus documented evidence, and the provider list differs from the deployer list.

ArticleWhat you have to buildThe work product that proves it
Art. 9Continuous risk management system across the whole lifecycleRisk register, mitigation measures, test records
Art. 10Data governance for training, validation and test datasetsData provenance description, representativeness and bias examination
Art. 11 and Annex IVTechnical documentation, ready before market entry and kept currentChapter structure per Annex IV, versioned
Art. 12Automatic event logging over the lifetime of the systemLogging design, retention rule, technical implementation
Art. 13Transparency towards the deployerInstructions for use that let the deployer meet its own duties
Art. 14Human oversight at design levelDescription of oversight points, intervention and stop capability
Art. 15Accuracy, resilience and cybersecurityMetrics, fault tolerance tests, adversarial and data poisoning defences
Art. 17Quality management systemDocumented policies, procedures, responsibility matrix
Art. 43Conformity assessmentInternal control for most Annex III cases, notified body for Annex I
Art. 47, 48, 49EU declaration of conformity, CE marking, EU database registrationSigned declaration, marking on the product, registration entry
Art. 73Serious incident reportingReporting procedure, 15 days, 2 days for widespread infringement
Provider obligations, applicable from 2027-12-02.

As a deployer, Article 26 gives you a shorter list, though not a trivial one. Human oversight has to be assigned to a competent, trained and authorised person. Input data under your control has to be relevant. You have to monitor operation and inform the provider without delay when a risk or serious incident appears. Logs have to be kept for at least six months. Before deploying at a workplace, worker representatives and the affected workers have to be informed. And affected natural persons have to be notified when the system makes or supports a decision about them.

The Article 27 fundamental rights impact assessment binds public bodies, private entities providing public services, and deployers of the systems in Annex III points 5(b) and 5(c), meaning creditworthiness assessment and life or health insurance risk pricing. The completed template has to be submitted to the market surveillance authority. This duty also runs from 2 December 2027, even though several sources still print 2 August 2026.

We broke the work products down article by article, with owners and a refresh cadence, in a separate piece: AI Act compliance documentation. Where data sovereignty is also a constraint, the local AI deployment route keeps training and log data inside the company entirely.

How large can the fines get?

Article 99 sets three tiers, and in each the ceiling is the higher of a fixed amount and a revenue percentage. Prohibited practices reach 35 million euro or 7 percent. Most other breaches reach 15 million or 3 percent. Misleading the authority reaches 7.5 million or 1 percent. For SMEs the logic inverts. The omnibus did not change the amounts.

InfringementGeneral ceilingSME and startupSmall mid-cap
Art. 5 prohibited practiceEUR 35M or 7% of worldwide annual turnover, whichever is higherwhichever of the two is lowerno separate relief
Breach of Art. 16, 22 to 26 and Art. 50EUR 15M or 3%, whichever is higherwhichever of the two is lowerlower ceiling
Incomplete or misleading information to the authorityEUR 7.5M or 1%, whichever is higherwhichever of the two is lowerlower ceiling
Provider of a GPAI model (Art. 101)EUR 15M or 3%, imposed by the Commissionnot relevantnot relevant
Article 99, applicable since 2025-08-02. Article 99(6) makes the lower value the ceiling for SMEs.

Small mid-cap is a new category introduced by the omnibus: under 750 employees and at most 150 million euro turnover. It brings simplified documentation, quality management exemptions, sandbox priority and a lower fine ceiling on the second and third tiers. A lot of mid-sized European companies land in this band, so it is worth checking against your own headcount and revenue.

National procedure adds a layer on top. In Hungary, Government Decree 344/2025 (X. 31.) requires the fine to be set in forint, up to the ceiling in Articles 99 and 100 of the EU regulation, payable within 30 days. Summary proceedings are excluded, and the market surveillance authority may conclude an administrative contract with the party instead of issuing a decision on the merits. Grant Thornton Hungary estimated in February 2026 that the maximum for prohibited practices works out around HUF 13.3 billion, which is an exchange-rate dependent estimate rather than a statutory figure.

Which national authority enforces this, and what is still missing?

Each member state designates its own market surveillance authority under Article 70, so the answer depends on where you operate. In Hungary the AI Authority (Mesterseges Intelligencia Hivatal) holds both the market surveillance mandate and the single point of contact role, under Act LXXV of 2025 and Government Decree 344/2025 (X. 31.).

Role under the AI ActHungarian bodyWhere it stands
Market surveillance and point of contact (Art. 70)Mesterseges Intelligencia Hivatal (AI Authority)Operating, though not an independent agency: it is an organisational unit inside a ministry. Website: mihivatal.gov.hu
Notifying authority (Art. 28)National Accreditation AuthorityDesignates conformity assessment bodies on the basis of accredited status
Sectoral market surveillance in financeMagyar Nemzeti Bank (central bank)The relevant authority for credit scoring and insurance AI
Data protectionNAIHNot an AI market surveillance authority. Acts in parallel under its GDPR mandate, since both regulations apply at once.
Coordination and guidanceHungarian Artificial Intelligence CouncilMay issue guidance and position papers on implementation

The honest part: on several points there is no settled national practice yet, and no consultancy can paper over that. We found no published Hungarian fine imposed under the AI Act. We found no data protection authority position paper dealing specifically with the regulation. And we found no public source showing that the Hungarian legislator adjusted Act LXXV of 2025 or Decree 344/2025 to the slipped EU deadlines after the omnibus entered into force on 27 July 2026. The national rules currently assume the 2 August 2026 application logic while the EU regulation no longer does.

That contradiction most likely resolves in favour of the EU regulation, which is directly applicable, so 2 December 2027 governs. That is an inference, not an authority position. If it carries real exposure in your case, ask the competent authority in your own member state directly and get the answer in writing. We deliberately are not naming the designated authority for Germany or Austria here, because we could not verify the current designation from a primary source, and a wrong authority name in a compliance document is worse than a blank field.

What should you do in the next 30 days?

A month will not produce compliance, but it closes the three duties that are already enforceable and gets the high-risk track moving. Order matters: inventory first, because without it you do not know what to write policy about. Budget two to three person-days at a 50 to 500 employee company, plus legal review.

  1. Week one. Ask finance for the SaaS invoices and card statements, and assemble the first version of the system inventory with the seven columns above. Ask HR and marketing which tools they actually use.
  2. Week one. Walk through the Article 5 prohibitions, especially workplace emotion recognition. If any system does this, stop it now. This is not a deadline obligation.
  3. Week two. Put the Article 50(1) disclosure on every customer-facing AI interface. One sentence at the top of the chat window, visible before the first message.
  4. Week two. Map where you produce generative content and how the Article 50(2) machine-readable marking can be implemented. Systems already on the market have until 2 December 2026.
  5. Week three. Write a three-page AI usage policy and hold a one-hour internal briefing. That is documented performance of Article 4. Keep the attendance sheet.
  6. Week three. Classify every row of the inventory into one of the four categories. Flag the Annex III hits and check whether the Article 6(3) exception is available.
  7. Week four. Assign an owner and a schedule to each system flagged high risk, counting backwards from 2 December 2027. Annex IV technical documentation is not a two-week job.
  8. Week four. Review your development and vendor contracts for who is the provider and who is the deployer. Where it is not stated, add a paragraph.

If NIS2 also applies to you, run the two programmes together, because risk management, logging and incident handling are largely reusable across both. This matters most in Germany, where the NIS2 implementation act (NIS2UmsuCG, the new BSIG) was published in the Federal Law Gazette on 5 December 2025 and entered into force the next day, covering roughly 30,000 companies with registration through the BSI portal, incident reporting at 24 hours, 72 hours and one month, and management liability under section 38. A German customer in scope will push those requirements down to its suppliers, including development partners abroad. For the basics start with scope, deadlines and fines under NIS2, and for the overlap with data protection see the EU AI Act, GDPR and AI security piece.

What do people ask most about the AI Act?

The questions below come from the ones we field most often from operating companies rather than from law firms. Every answer names the article and the date it runs from, so you can check it against the regulation instead of taking our word for it.

Was the 2 August 2026 AI Act deadline really postponed?

Yes. Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, entered into force on 27 July 2026, six days before the original date. Chapter III Sections 1 to 3, meaning Articles 8 to 27 including the fundamental rights impact assessment in Article 27, moved to 2 December 2027. Annex I product-embedded systems moved to 2 August 2028.

So there is nothing to do until 2027?

There is. The Article 5 prohibitions have applied since 2 February 2025, and the GPAI rules in Articles 53 to 55 plus the penalty regime in Article 99 since 2 August 2025. The Article 50 transparency duties started on 2 August 2026 and the omnibus did not touch them. What was postponed is only the high-risk compliance package.

How do I know whether I am a provider or a deployer?

The line runs at whose name the system goes to market under, not at who wrote the code. If the AI system is placed on the market or put into service under your name or trademark, you are a provider under Article 3(3). If you use someone else's system under your own authority, you are a deployer under Article 3(4). Article 25 flips a deployer into provider status in three cases.

If we only use ChatGPT for internal work, does anything apply to us?

Very little. You are a deployer and OpenAI is the provider. No high-risk obligation arises, but the Article 4 duty to support AI literacy does, and the GDPR applies in parallel. If you publish the output on a matter of public interest, the Article 50(4) labelling duty covers it. The real exposure starts when someone routes HR or credit decisions through it.

What has to appear next to the chatbot on our website?

Under Article 50(1), since 2 August 2026 the user has to be told they are interacting with an AI system unless that is obvious from the context. One line at the top of the chat window is enough, provided the user sees it before the first message. If the bot produces generative content, Article 50(2) also requires machine-readable marking on the output.

How large can the fine be for a mid-sized company?

The two relevant tiers in Article 99 are 15 million euro or 3 percent of worldwide annual turnover, and 7.5 million euro or 1 percent, in each case whichever is higher. For SMEs and startups Article 99(6) inverts this and makes the lower of the two the ceiling. The omnibus added a small mid-cap category with a lower ceiling on the second and third tiers.

Which authority enforces the AI Act?

Each member state designates its own under Article 70, so it depends where you operate. In Hungary the AI Authority (Mesterseges Intelligencia Hivatal) is the market surveillance authority and single point of contact under Act LXXV of 2025 and Government Decree 344/2025 (X. 31.), the National Accreditation Authority is the notifying authority, and the central bank handles financial sector systems.

Is GDPR compliance enough for the AI Act?

No, but it helps. The two regulations apply in parallel, and your Article 35 GDPR data protection impact assessments, processing records and lawful basis analysis can be reused. The AI Act asks for work products that do not exist under the GDPR: a risk management system, Annex IV technical documentation, a human oversight plan, conformity assessment and CE marking.

This article is information, not legal advice, and it does not replace an individual legal opinion. Classification and role allocation depend on the specific intended purpose and contractual setup at each company. If you want to run compliance as a project, our EU AI Act compliance service works on a fixed price with a four to eight week turnaround.

Primary sources: Regulation (EU) 2026/1744, European Commission, regulatory framework for AI, AI Act Service Desk, Article 99, Hungarian Act LXXV of 2025, Government Decree 344/2025 (X. 31.), Mesterseges Intelligencia Hivatal, BSI on NIS2-regulated companies. Analyses: FPF timeline (2026-07-28), Freshfields (2026-07-10), Gibson Dunn (2026-05-27), Grant Thornton Hungary (2026-02-12), openKRITIS on the German NIS2 act. Article-level references: Art. 5, Art. 25, Art. 26, Art. 27, Art. 50, Annex III. Those pages carry consolidated text, but their timeline is out of date.

Ready to start?

Let's scope your project - 30 free minutes.

Within 24 hours we send back a concrete price range, a realistic timeline and the clear next step. No sales pitch.

Start a project