What the EU AI Act is
The EU AI Act, Regulation (EU) 2024/1689, is the EU law on artificial intelligence. It entered into force on 1 August 2024 and its obligations apply in stages. What it asks of you depends on how each AI system is used and on your role, usually provider or deployer.
This summary is for operations, IT, compliance and product leads at companies that use AI tools or are having AI systems built, including UK companies selling into the EU. Most are deployers. Some are providers without having noticed, because a custom system went live under their name.
The four risk levels
The Act sorts AI into four levels: prohibited practices, high-risk systems, systems with transparency duties and minimal risk. The level follows the use, so the same model can be minimal risk in one system and high risk in another.
| Level | What it covers | Examples | What it means for you |
|---|---|---|---|
| Prohibited (Article 5) | Practices banned outright | Social scoring; inferring emotions at work or in education; untargeted scraping of facial images | Stop the use. Applies since 2 February 2025 |
| High risk (Article 6, Annexes I and III) | Uses in the areas listed in Annex III, and AI as a safety component of products under the EU laws in Annex I | Filtering job applications; creditworthiness of individuals; pricing life and health insurance; admission to education; AI in medical devices | Duties for providers and deployers, from 2 December 2027 (Annex III) or 2 August 2028 (Annex I) |
| Transparency (Article 50) | AI that interacts with people or generates content | Chatbots saying they are AI; machine-readable marking of generated content; disclosing deep fakes | Tell people when AI is involved. Applies since 2 August 2026 |
| Minimal risk | Everything else | Internal search, drafting help and document extraction usually sit here | No AI Act duties beyond AI literacy. The GDPR still applies |
An Annex III system is not high risk when it poses no significant risk of harm, for example when it performs a narrow procedural task. That exception never covers a system that profiles people, and the provider must document its assessment and register the system.
Timeline: what applies when
Checked on 16 September 2026
The prohibitions and the AI literacy duty have applied since 2 February 2025, the rules for general-purpose AI models since 2 August 2025 and the transparency duties since 2 August 2026. The high-risk rules have moved: they apply from 2 December 2027 for Annex III uses and from 2 August 2028 for AI in Annex I products.
| Date | What starts to apply | Status |
|---|---|---|
| 2 February 2025 | AI literacy (Article 4) and prohibited practices (Article 5) | Already applies |
| 2 August 2025 | Obligations for general-purpose AI model providers, governance and penalty rules | Already applies |
| 27 July 2026 | The Digital Omnibus on AI, including the new wording of Article 4 | Already applies |
| 2 August 2026 | Most remaining provisions, including transparency duties (Article 50) | Already applies |
| 2 December 2026 | Two new prohibitions, and output marking for generative AI systems already on the market | From 2 December 2026 |
| 2 August 2027 | General-purpose AI models placed on the market before 2 August 2025 | From 2 August 2027 |
| 2 December 2027 | High-risk rules for Annex III uses, including Articles 26 and 27 for deployers | From 2 December 2027 |
| 2 August 2028 | High-risk rules for AI in Annex I products | From 2 August 2028 |
The Digital Omnibus on AI
The Commission proposed the Digital Omnibus on AI on 19 November 2025, and Parliament and Council reached a political agreement on 7 May 2026. The final text, Regulation (EU) 2026/1744 (opens in a new tab), was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. Before it, the Annex III rules would have applied from 2 August 2026. For companies using AI, the Omnibus:
- Moved the high-risk dates to 2 December 2027 and 2 August 2028.
- Reworded the AI literacy duty in Article 4, described below.
- Banned AI that generates non-consensual intimate images of identifiable people or child sexual abuse material, from 2 December 2026.
- Extended some SME relief, such as lower fine caps, to small mid-cap companies (SMCs).
Provider or deployer: which are you?
You are a deployer when you use an AI system under your own authority, such as a support team using a chatbot or an AI feature in your CRM. You are a provider when you develop an AI system, or have one developed, and place it on the market or put it into service under your own name or trademark.
When you commission a custom AI system
Putting into service includes supplying a system for your own use, so a system built only for your staff counts. If a development partner builds a system to your specification and you put it into use under your name, you are usually the provider.
Outside the high-risk areas, being the provider adds little beyond AI literacy and the Article 50 duties. For a high-risk use, providers carry the main obligations, such as risk management, technical documentation, logging, human oversight and conformity assessment.
We build AI systems for clients, and when we scope a build we expect to settle these points in the contract:
- Who is the provider, and under whose name the system goes live.
- The intended purpose and the uses it is not meant for, since classification follows the purpose.
- What the developer hands over: architecture, data sources, test results and instructions for use.
- Who tells whom about incidents and changes to the model or purpose.
- For a high-risk system, the information and technical access each supplier gives the provider, which Article 25(4) requires in a written agreement.
When a deployer becomes a provider
Under Article 25, a deployer, importer or distributor becomes the provider of a high-risk system if it puts its name or trademark on one, makes a substantial modification that keeps it high risk, or changes the purpose of another system, including a general-purpose one, so that it becomes high risk. A general chat assistant used to screen job applicants is one example.
What deployers have to do
Every deployer already has to support AI literacy among the people who use AI on its behalf, and some also have transparency duties. Deployers of high-risk systems take on more from 2 December 2027, and some of them must assess the impact on fundamental rights before first use.
AI literacy (Article 4)
Since 27 July 2026, Article 4 requires providers and deployers to take measures to support the AI literacy of their staff and of others who operate or use AI systems on their behalf. It does not require them to guarantee a specific level for any individual. The original wording asked for measures to ensure, to their best extent, a sufficient level.
A reasonable start is to know which AI tools each team uses, explain what each is for and where it goes wrong, and keep a record of that guidance.
Transparency duties
Under Article 50, deployers must inform people exposed to emotion recognition or biometric categorisation, and disclose deep fakes they create with AI. AI-generated text published to inform the public on matters of public interest must be disclosed, unless a person reviewed it and someone holds editorial responsibility. Telling people they are talking to AI is a provider duty, so for a custom chatbot under your name it is probably yours.
Extra duties for high-risk uses (Article 26)
- Use the system according to the provider's instructions, with human oversight assigned to people who have the competence and authority for it.
- Monitor the system, suspend it if it presents a risk, and report serious incidents to the provider and the authority.
- Keep the logs under your control for at least six months, unless other law says otherwise.
- Inform workers' representatives and affected workers before using it at work, and tell people when it makes or helps make decisions about them.
Fundamental rights impact assessment (Article 27)
Before first using an Annex III high-risk system, public bodies and private companies providing public services must carry one out, as must any deployer using AI to assess the creditworthiness of individuals or to price life and health insurance. Critical infrastructure uses are excluded. The results go to the market surveillance authority.
The agents and automation we build log what the AI did and route high-impact actions to a named person for approval, which produces the kind of records these duties ask for. Our article on human-in-the-loop AI agents shows how those approval steps work.
General-purpose AI models and the tools you already use
Obligations for general-purpose AI models, the large models behind chat assistants and AI APIs, fall on the companies that provide those models. If you call a model through an API or use a chat assistant, your duties come from the system you build or use around the model and what that system is used for.
Since 2 August 2025, model providers must keep technical documentation, give companies building on their models the information they need, have a copyright policy and publish a summary of their training content. Models with systemic risk carry further duties. The Commission published a voluntary General-Purpose AI Code of Practice on 10 July 2025, with chapters on transparency, copyright, and safety and security.
When you choose a model vendor, ask whether it signed the Code and for the documentation it must give companies building on its model. You will need that documentation if a system you build turns out to be high risk.
Does the EU AI Act apply to UK companies?
Yes, when their AI reaches the EU. Article 2 covers providers placing AI systems or general-purpose AI models on the EU market or putting them into service there, wherever they are based. It also covers providers and deployers outside the EU whose AI system's output is used in the EU.
A UK software company selling an AI feature to customers in Germany is a provider on the EU market. A UK lender scoring applicants in Ireland uses AI whose output is used in the EU, in an Annex III area. Providers outside the EU must also appoint an authorised representative in the EU before offering a high-risk system or a general-purpose AI model there.
A UK company using AI only for UK staff and customers, with no output used in the EU, is generally outside its scope.
Penalties
Article 99 sets three tiers of maximum fines, each a fixed amount or a share of worldwide annual turnover, whichever is higher. For SMEs the lower of the two applies, and since the Digital Omnibus the same goes for small mid-caps in the second and third tiers.
| Infringement | Maximum fine | SMEs and small mid-caps |
|---|---|---|
| Prohibited practices (Article 5) | EUR 35 million or 7% of turnover | SMEs: whichever is lower |
| Most provider and deployer obligations, including transparency (Article 50) | EUR 15 million or 3% of turnover | SMEs and SMCs: whichever is lower |
| Incorrect or misleading information to authorities or notified bodies | EUR 7.5 million or 1% of turnover | SMEs and SMCs: whichever is lower |
| General-purpose AI model providers (Article 101) | EUR 15 million or 3% of turnover | No separate rule |
These are ceilings. Authorities weigh the gravity and duration of the infringement, the harm, the company's size and its cooperation.
Where to start
Start with a list of the AI you use and build and your role for each system, then check each use against the prohibited practices and the high-risk areas. For AI used in drafting, search and support, what follows is mostly AI literacy and transparency. Uses in recruitment, credit, insurance or education need a legal review before December 2027.
- 01List the AI systems and features you use or are building, with an owner for each. Our AI governance framework covers the inventory and risk rating.
- 02Record your role per system: deployer for tools you use, provider for systems built for you under your name.
- 03Check each use against Article 5 and Annex III. Anything touching recruitment, credit, insurance or education goes to your legal adviser.
- 04Put AI literacy measures in place and record them.
- 05Check the transparency duties for chatbots and generated content.
- 06For custom builds, agree roles, handover documentation and incident reporting in the contract.
If you only use AI tools for internal drafting and search, steps one, two and four may be all you need. Our AI strategy work starts with an inventory of your AI systems and their risk level.
Questions about the AI Act
Has the EU AI Act been delayed?
Partly. The Digital Omnibus on AI moved the high-risk rules to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). The other dates stayed as they were, and those obligations already apply.
Is a chatbot high risk under the EU AI Act?
Usually not. A customer service chatbot has a transparency duty: people must know they are talking to AI unless it is obvious. It becomes high risk when used for an Annex III purpose, such as evaluating job candidates.
Who enforces the EU AI Act?
National market surveillance authorities enforce most of the Act. The Commission, through the AI Office, supervises general-purpose AI model providers and, since the Digital Omnibus, AI systems that a model provider builds on its own general-purpose model, with some exceptions.
How does the EU AI Act relate to the GDPR?
They are separate laws that apply side by side. The AI Act regulates AI systems and models, and the GDPR applies whenever personal data is processed.
Read the full text of Regulation (EU) 2024/1689 on EUR-Lex (opens in a new tab), and the Commission's AI Act page (opens in a new tab) for guidance. This article is general information and is not legal advice. Guidance and rules can change, so check your situation with your legal adviser.