EU AI Act compliance for EU companies
The high-risk deadline moved. Reg. (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and shifted Chapter III Sections 1-3 to 2 December 2027. What binds you today is Article 5 and, since 2 August 2026, the Article 50 transparency rules. Maximum fine: EUR 35M or 7% of global turnover, whichever is higher. We map your AI systems to the regulation, then deliver compliance in a fixed-price 4–8 week project: DPIA, FRIA, technical documentation, human oversight, prompt-injection defences.
The essence in 30 seconds
- The EU AI Act (Reg. 2024/1689) is the EU's first comprehensive AI law. It classifies AI systems into four risk tiers (prohibited, high, limited, minimal) and assigns separate obligations to each.
- ~95% of EU SMEs sit in limited- or minimal-risk categories, with three concrete duties by 2 August 2026: AI policy for staff, privacy notice update, and transparency for chatbot / AI-generated content.
- High-risk operators (HR screening, credit scoring, education scoring, medical diagnosis support, biometric identification) need full conformity by 2 August 2026: Annex IV technical file, FRIA, CE marking, EU database registration. Typical mid-market project cost: EUR 15k–50k.
- Article 4 (AI literacy) and Article 5 (prohibited practices) have applied since 2 February 2025.
The four risk tiers: which one is your AI in?
The EU AI Act classifies every AI system by its use, not its underlying technology. The same large language model can be "high-risk" in one corporate use and "minimal" in another.
- Tier 1<1%
Prohibited AI
Typical examples
Social scoring, subliminal manipulation, untargeted biometric mass surveillance in public, emotion recognition at the workplace or in schools.
Obligations
Cannot be operated in the EU in any form. Banned since 2 February 2025. Fines run up to EUR 35M or 7% of global turnover.
- Tier 2~5%
High-risk AI
Typical examples
HR CV-screening and hiring scoring, credit scoring, insurance pricing, education exam scoring, medical diagnostic support, critical-infrastructure control, biometric identification, justice systems.
Obligations
Conformity assessment, detailed technical documentation (Annex IV), FRIA, CE marking, EU database registration, post-market monitoring, human oversight on every decision.
- Tier 3~30%
Limited-risk AI
Typical examples
Customer-service chatbots, deepfake and AI-generated media, emotion detectors in marketing, AI assistants in marketing/sales flows.
Obligations
Transparency duty: users must know they are talking to AI or seeing AI-generated content. Content-level labelling.
- Tier 4~65%
Minimal-risk AI
Typical examples
Spam filtering, AI in video games, recommendation engines in webshops, automatic image editing, code completion (Copilot, Cursor) inside closed internal environments.
Obligations
Voluntary code of conduct recommended. No specific statutory obligation, though GDPR still applies to any AI processing personal data.
~95% of EU SMEs are in tiers 3 and 4. The full enumeration is in Article 6 and Annex III.
Official applicability timeline (Article 113)
Source: artificialintelligenceact.eu/implementation-timeline and EUR-Lex 2024/1689.
| Date | Article | What becomes applicable |
|---|---|---|
| 2024-08-01 | Art. 113 | EU AI Act enters into forceOfficially published in the Official Journal of the European Union. Most articles are not yet applicable, but the 6/12/24/36-month transition clocks all start ticking from this day. |
| 2025-02-02 | Art. 4 + Art. 5 | Prohibited practices ban + AI literacy dutySubliminal manipulation, social scoring, untargeted biometric mass surveillance and workplace/school emotion recognition are banned across the EU. AI literacy training becomes mandatory for staff who use AI. Fines up to EUR 35M or 7% of global turnover. |
| 2025-08-02 | Art. 53–55 | GPAI obligations applyGeneral-purpose AI providers (OpenAI, Anthropic, Google, Meta, Mistral) must publish technical documentation, downstream-integrator info, copyright policy and a sufficiently detailed training-data summary. Systemic-risk GPAI gets adversarial testing and serious-incident reporting. |
| 2026-07-27 | Reg. (EU) 2026/1744 | The Digital Omnibus on AI enters into forceSix days before the old high-risk deadline, the amending regulation rewrote the timeline. Chapter III Sections 1-3, meaning Articles 8 to 27, moved to 2 December 2027, and Annex I product-embedded systems moved to 2 August 2028. It also added an Article 5 ban on AI built to generate CSAM or non-consensual intimate imagery, and created a small mid-cap category with lower fine caps. |
| 2026-08-02 | Art. 50 | Transparency obligations applyThis is the date that actually landed. If a person talks to your chatbot, you have to tell them, unless it is obvious from the context. Generative output needs machine-readable marking, deepfakes and AI-written text on matters of public interest need a label. The Commission's GPAI enforcement powers start on the same day. |
| 2026-12-02 | Art. 50(2) + Art. 5 | Grace period closes for older generative systemsSystems already on the market before 2 August 2026 have until this date to solve machine-readable marking of their output. The same date ends the transition for the new CSAM and NCII prohibition, which means refusal training and output filtering. |
| 2027-12-02 | Ch. III §1-3 (Art. 8-27) | High-risk AI obligations apply (main deadline)Operators of high-risk AI (HR screening, credit scoring, medical diagnosis support, education scoring, biometric identification) must demonstrate full compliance: technical documentation, FRIA, post-market monitoring, human oversight, CE marking, EU database registration. The 16-month shift comes from Reg. (EU) 2026/1744. |
| 2028-08-02 | Art. 6(1) | Annex I product-embedded high-risk AIWhere the AI is a safety component of a product already regulated under Annex I, such as a medical device, a vehicle or machinery, there are 12 extra months. The intermediate 2 August 2027 date still exists but covers different things: regulatory sandboxes and the compliance deadline for GPAI models placed on the market before August 2025. |
Penalties (Article 99)
Three fine bands. SMEs benefit from the lower of the percentage or absolute amount. That is relief, not exemption.
Art. 99(3)
Prohibited AI practices
EUR 35M or 7% of global annual turnover
Whichever is higher. Applies to operating any AI system listed in Article 5.
Art. 99(4)
High-risk non-compliance
EUR 15M or 3% of global annual turnover
Applies to obligations under Articles 16, 22-24, 26, 31, 33-34, 50.
Art. 99(5)
Inaccurate / misleading info
EUR 7.5M or 1% of global annual turnover
Information given to authorities or notified bodies. SMEs benefit from the lower of % vs absolute amount.
30-day action plan to start compliance
The minimum viable compliance program for a mid-market company with one or two high-risk AI systems.
- 1
Week 1: AI inventory & risk classification
Catalogue every AI system in production, in pilot or under contract (vendor, in-house, embedded SaaS Copilots). Classify each as prohibited / high / limited / minimal under Articles 5 and 6 + Annex III.
- 2
Week 2: Gap analysis vs Annex IV
For every high-risk system, score the gap against the Annex IV technical documentation set: data governance, accuracy/robustness, transparency, human oversight, post-market plan.
- 3
Weeks 3–5: Documentation pack + FRIA
Produce: Annex IV technical file, instructions for use (Article 13), Fundamental Rights Impact Assessment (Article 27), data governance policy, AI literacy training plan (Article 4).
- 4
Weeks 6–8: Conformity, CE, post-market
Conformity assessment (self-assessment for most Annex III, third-party for biometric / Annex I product-embedded). CE marking + EU database registration. Wire up post-market monitoring telemetry.
For high-risk systems we map every step to a specific Article in the 24-step Annex III compliance checklist.
EU AI Act: frequently asked questions
The timeline changed in the summer of 2026. Reg. (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and moved the high-risk package from 2 August 2026 to 2 December 2027. Annex I product-embedded AI now has until 2 August 2028 (Art. 6(1)). What did not move: prohibited practices (Art. 5) since 2 February 2025, GPAI obligations (Art. 53-55) and the penalty regime (Art. 99) since 2 August 2025, and Article 50 transparency since 2 August 2026.
Related content and services
EU AI Act is rarely a standalone topic. These are worth thinking about together.
EU AI Act 24-step high-risk checklist
Annex III high-risk AI checklist for the 2027-12-02 deadline, with exact Article references and fine thresholds.
MegnézemAI ROI calculator
Estimate process-automation savings and 3-year ROI with a transparent methodology.
MegnézemNIS2 compliance
If you are a critical-sector operator, NIS2 applies in parallel with the AI Act. SIEM, MFA, IR playbook.
MegnézemNIS2 checklist for IT leaders
10 + 7 step compliance program for essential and important entities under NIS2 Annex I/II.
MegnézemAI development & integration
Custom AI systems built EU AI Act-compliant from day one. RAG, agents, MCP, AppForge stack.
MegnézemProcess automation
Python + LangChain process automation with audit trail and human-in-the-loop safety.
Megnézem
Request an EU AI Act gap analysis + roadmap
4–8 weeks, fixed-price project. Output: risk classification of every AI system, FRIA draft, gap list, and a prioritised plan that starts with the Article 50 items you already owe and runs to the 2 December 2027 high-risk deadline. You will be ready for supervisory questions.