AI Governance, Security & Compliance
EU AI Act: What Businesses Need to Know and How to Prepare
The 2026 Digital Omnibus reset the EU AI Act's clock, not its rules. Here are the deadlines that now matter, who carries which obligations, and a practical path to readiness.
On 27 July 2026, Regulation (EU) 2026/1744 — the "Digital Omnibus on AI" — entered into force and pushed back the EU AI Act's high-risk deadlines by more than a year. Six days later, on 2 August 2026, most of the Act's remaining rules, including chatbot and deepfake transparency duties, became enforceable anyway. A large share of businesses read the first headline and missed the second: a 2026 vendor analysis of its own client assessments across eight industries found that 78% of organizations assessed had taken no meaningful steps toward AI Act compliance, and 83% had no formal inventory of the AI systems they use (Vision Compliance, April 2026).
The short answer to "does the EU AI Act apply to my business": it may if you build, sell, or use an AI system in the EU, or if the system's output is used there — even when your company is headquartered elsewhere. Article 2 contains specific exemptions, so scope still requires a case-by-case check. The rest of this guide covers what changed in 2026, what didn't, the deadlines that now matter, who carries which obligations, and a practical path to get ready.
What is the EU AI Act, and does it apply to your business?
Regulation (EU) 2024/1689 defines an AI system as software that infers, from the inputs it receives, how to generate outputs — predictions, content, recommendations, or decisions — that can influence physical or virtual environments. Autonomy and inference are the operative words. A conventional rules engine or a deterministic calculator doesn't automatically qualify just because it runs on a computer, and a system doesn't need deep learning or generative capabilities to qualify either.
The Act reaches providers who place AI systems on the EU market, deployers established in the EU, importers, distributors, and — critically — third-country providers and deployers whose system's output is used in the EU. Unlike some other EU laws, this territorial rule does not depend on a separate "targeting" test. Subject to Article 2's exemptions, it can cover a Colombian recruitment platform scoring candidates for an EU-based hiring manager, a Salvadoran fintech's credit model feeding a European partner bank, or a US SaaS tool whose chatbot serves Spanish customers, regardless of where their servers, staff, or incorporation sit.
Spain moved early on enforcement infrastructure. The Agencia Española de Supervisión de la Inteligencia Artificial (AESIA), created by Royal Decree 729/2023 and operational since 2024, became the first dedicated national AI supervisor in the EU. It has since helped publish a set of 16 practical compliance guides developed through the Spanish AI regulatory sandbox — a useful reference for any Barcelona- or Spain-facing business trying to translate the regulation into operational steps.
The 2026 Digital Omnibus: what actually changed (and what didn't)
This is the point most secondary coverage gets wrong, and it matters commercially: the delay is real, but partial.
Regulation (EU) 2026/1744 postponed the two high-risk deadlines that were set to bite hardest — Annex III use cases (employment, credit, education, essential services, and more) now apply from 2 December 2027, and Annex I product-embedded AI (medical devices, machinery, toys) from 2 August 2028. It also extended some SME simplifications to small mid-cap companies, widened access to regulatory sandboxes, simplified the original company-facing AI-literacy regime, and added a new prohibition covering AI systems that generate non-consensual intimate imagery or child sexual abuse material, effective 2 December 2026.
What it did not touch: the Article 5 prohibited-practices regime and the original definitions, both applying since 2 February 2025; the GPAI-model obligations, applying since 2 August 2025; and the Article 50 transparency duties — telling users they're talking to a chatbot, labelling deepfakes, marking synthetic content — which became enforceable on 2 August 2026 along with the Commission's enforcement powers over GPAI providers. One transition applies: providers of synthetic-content systems placed on the market before 2 August 2026 have until 2 December 2026 to meet Article 50(2). Reading "the AI Act was delayed" as "we can relax on AI" still leaves a live compliance gap in areas that already carry penalties.
The four risk tiers: where your AI systems fall
Every AI system a business builds, buys, or embeds lands in one of four tiers. The labels "limited risk" and "minimal risk" are explanatory shorthand, not exhaustive legal categories — the actual legal tests sit in Articles 5, 6, and Annex III of the regulation itself.
High-risk classification runs through two routes. Article 6(1) catches AI that's a regulated product or safety component under Annex I where sectoral law already requires third-party conformity assessment. Article 6(2) presumes Annex III use cases high-risk unless the system performs only narrow, procedural, or preparatory tasks and poses no significant risk — an exception that requires a documented analysis, not an assumption. General-purpose AI (GPAI) models sit under a separate model-level regime that can apply even when the downstream system isn't high-risk: providers of models like GPT-4-, Gemini-, or Claude Opus-class systems must maintain technical documentation, share information with downstream providers, publish a training-data summary, and comply with EU copyright rules. Models presumed to carry systemic risk — informally, those trained above roughly 10²⁵ floating-point operations, a threshold the Commission can also apply by other criteria — face additional testing, risk mitigation, and incident-reporting duties.
Every deadline you need to track
Sources: Regulation (EU) 2024/1689 and Regulation (EU) 2026/1744, Official Journal of the EU (EUR-Lex); European Commission, "Navigating the AI Act".
Provider, deployer, importer, distributor: who's responsible for what
The Act assigns obligations by function, not by contract label. Calling yourself a "customer" or "reseller" doesn't override what you actually do with a system.
- Providers carry the heaviest load: defining intended purpose, building the technical file, running risk management, designing logging and human-oversight capability, and completing conformity assessment.
- Deployers — the role most businesses actually occupy — must use systems according to instructions, assign competent human oversight, monitor operation, keep accessible logs, and report risks. Public bodies and deployers of specified credit or life and health-insurance systems must also run a fundamental-rights impact assessment.
- Importers and distributors verify that the provider has done its part before the system reaches the market, and must halt supply if it hasn't.
The trap worth naming explicitly: Article 25 reclassifies a deployer as a provider — with a provider's full obligations — if it rebrands a system under its own name, substantially modifies it, or changes its intended purpose in a way that makes it high-risk. A bank that takes a vendor's credit-scoring model and retrains it on proprietary data, or a BPO that white-labels a third-party AI tool for its own clients, can cross that line without meaning to. Classification should be reopened whenever data, model, interface, or purpose changes — not filed once and forgotten.
What high-risk compliance actually requires
For systems that land in the high-risk tier, Chapter III sets out a defensible-evidence architecture, not a checkbox exercise: lifecycle risk management, data governance and quality controls, technical documentation (Annex IV), automatic logging retained for at least six months, instructions and transparency for deployers, human-oversight design that gives a real person the authority to override or stop the system, accuracy and cybersecurity testing, a documented quality-management system, conformity assessment, an EU declaration of conformity, CE marking, registration, and post-market monitoring with serious-incident reporting.
For most Annex III use cases, the default conformity route is internal control rather than third-party certification — specified biometric systems are the main exception, where a notified body may be required. For Annex I products, AI requirements fold into the existing sectoral conformity process (for example, the Medical Devices Regulation), rather than running as a parallel track. One caveat worth building into any 2026–2027 project plan: the harmonised standards that would create a presumption of conformity are still incomplete — CEN and CENELEC missed their original August 2025 target, and standardisation work continues into 2026. Absence of a final standard doesn't remove the duty to prepare; it means documenting defensible alternative specifications and test evidence until one exists.
The Act doesn't just ask for a person somewhere in the loop — it requires that person to understand the system's capabilities and limitations, recognise automation bias, interpret its outputs, and hold real authority to override, ignore, or stop it. A reviewer who signs off on outputs without the time, training, or organisational standing to actually challenge them won't hold up as effective oversight if a regulator asks. Building that role into a job description, not just a workflow diagram, is part of the compliance file.
Sector spotlight: healthcare and medical devices
Healthcare AI reaches high-risk status through either of two doors: an Annex III essential-service use (a system controlling access to or eligibility for care), or Article 6(1), where the AI is a medical device or safety component and existing device law already requires third-party conformity assessment.
In practice, AI embedded in MDR Class IIa/IIb/III and IVDR Class A–D devices — sometimes informally called "Medical Device AI" — now carries AI Act duties on top of existing MDR/IVDR obligations: additional data governance, transparency, human oversight, and post-market monitoring layered onto a compliance process that was already substantial. The Medical Device Coordination Group published MDCG 2025-6 specifically to clarify how the two regimes interact, and the message is consistent: integrate the AI Act's requirements into the existing quality-management system and clinical evaluation process rather than running two parallel programs. The applicable date for this Annex I route is now 2 August 2028, but CE marking under MDR or IVDR doesn't relieve a hospital of validating its own workflows, user competence, and ongoing performance in its actual patient population — that responsibility stays local.
Sector spotlight: financial services and insurance
Two specific uses are presumptively high-risk under Annex III: AI that evaluates creditworthiness or sets a credit score for a natural person, and AI used for risk assessment and pricing in life and health insurance. Fraud-detection AI is explicitly carved out of the credit-scoring high-risk basis, though it can still trigger other AI Act provisions.
The European Banking Authority published a factsheet in November 2025 mapping the AI Act against CRD, CRR, and DORA, and found no significant contradictions between the two regimes — financial institutions can satisfy much of the provider quality-management obligation through their existing governance arrangements, while still owning the AI-specific duties around risk management and incident reporting. EIOPA reached a similar conclusion for insurance in its August 2025 opinion, which confirms that governance obligations already in Solvency II and the Insurance Distribution Directive extend naturally to AI systems outside the prohibited and high-risk categories. Neither authority is proposing new rules; both are telling regulated firms to map what they already do against the Act rather than build a second compliance stack.
The practical risk sits in procurement. A bank or insurer using a third-party high-risk model is usually a deployer, but a vendor contract that simply states "we comply with the AI Act" isn't evidence — the regulated entity keeps its own deployment, oversight, and consumer-protection duties regardless of what the vendor promises. Model documentation, bias and performance evidence, version-change notification, audit rights, and incident commitments belong in the contract, not taken on faith.
Penalties: what non-compliance actually costs
Source: Regulation (EU) 2024/1689, Article 99, EUR-Lex.
For SMEs and startups, the lower of the fixed sum or the percentage applies; for larger enterprises, the higher one does. A startup with €2 million in turnover facing a Tier-1 infringement is looking at roughly €140,000, not €35 million — a meaningful distinction that gets lost in headline coverage. For context, the 7% ceiling for prohibited practices exceeds GDPR's 4% cap, making it the second-highest percentage-based penalty in EU digital regulation after the Digital Markets Act's 10%.
How to prepare: an 8-step compliance roadmap
The postponement bought time, not an excuse to wait — high-risk readiness routinely takes 12–24 months once data remediation, logging architecture, and testing are factored in. This is the order that gets a business from zero to defensible.
What EU AI Act compliance can cost
There is no credible universal price for AI Act compliance. Cost depends on whether the company is a provider or deployer, whether the system is high-risk, and which controls already exist. A business using ordinary productivity tools should not budget as if it manufactures a regulated medical device.
In April 2026, the European Commission estimated this incremental AI Act compliance cost for an Annex I high-risk product provider that already had a quality-management system and sectoral conformity assessment in place. Read the Commission's answer to the European Parliament.
For SMEs, a lower official estimate starts at €5,000. The Commission's 2021 proposal modelled annual human-oversight costs for users of high-risk AI at approximately €5,000–€8,000 per year. This is a narrowly scoped regulatory estimate, not a market quote or an all-in compliance budget. See the official EUR-Lex proposal.
The timing estimates below are planning ranges, not statutory deadlines. Several workstreams can run in parallel.
That figure is a bounded example, not a starting price for every company. It does not cover an organisation with no quality-management system, multiple systems, major data remediation, medical-device clinical work, or the ongoing internal cost of monitoring and incident response. The practical first step is to inventory and classify the systems before setting a budget.
Frequently asked questions
Can you explain the EU AI Act in simple terms?
It's an EU regulation that sorts AI systems into four risk tiers — prohibited, high-risk, limited (transparency-only), and minimal — and attaches different legal obligations to each. It can apply to businesses outside the EU when they place AI on the EU market or when a system's output is used in the Union, subject to the exemptions in Article 2.
Does the 2026 Digital Omnibus mean businesses can wait to comply?
No. It postponed the high-risk deadlines to 2 December 2027 (Annex III) and 2 August 2028 (Annex I), but prohibited practices, GPAI obligations, and Article 50 transparency duties are already enforceable. Businesses that read the delay as blanket relief have a live compliance gap in the areas already carrying penalties.
What's the difference between a provider and a deployer under the AI Act?
A provider builds or places an AI system on the market and carries the full technical-file, testing, and conformity-assessment burden. A deployer uses a system someone else built and must follow its instructions, assign human oversight, and monitor its operation. A deployer can become a provider under Article 25 by rebranding, substantially modifying, or repurposing a system.
Is my company's chatbot covered by the EU AI Act?
Almost certainly, under Article 50's transparency rules, which have applied since 2 August 2026. Users need to know they're interacting with an AI system. Chatbots don't typically require the full high-risk compliance architecture unless they perform a separately listed high-risk function.
What are the maximum fines under the EU AI Act?
Up to €35 million or 7% of worldwide annual turnover for prohibited practices and specified data-governance breaches, €15 million or 3% for other obligations, and €7.5 million or 1% for misleading information to authorities. SMEs and startups pay the lower of the fixed amount or the percentage; larger enterprises pay the higher.
Does the EU AI Act apply to businesses outside the EU, like companies in the United States, Colombia or El Salvador?
It can. The Act covers non-EU providers that place AI systems or GPAI models on the EU market and non-EU providers or deployers whose system output is used in the Union, subject to Article 2's exemptions. A non-EU provider of a high-risk system must also appoint an EU authorised representative under Article 22.
Official sources
Every claim above traces to one of these primary sources. Check them directly, and recheck close to your own decision dates — several (the Digital Omnibus, the standardisation timeline, national designations) were still moving at the time of writing.
- Regulation (EU) 2024/1689 — the EU AI Act (full text, EUR-Lex)
- Regulation (EU) 2026/1744 — the Digital Omnibus on AI (full text, EUR-Lex)
- European Commission — "Navigating the AI Act" (official FAQ)
- European Commission — AI Act regulatory framework overview
- European AI Office — mandate and enforcement powers
- European Commission — AI Act standardisation status (CEN/CENELEC)
- AESIA — Agencia Española de Supervisión de la Inteligencia Artificial (official site)
- European Banking Authority — "AI Act: implications for the EU banking and payments sector" (November 2025)
- EIOPA — Opinion on AI governance and risk management (August 2025)
- MDCG 2025-6 — FAQ on the interplay between MDR/IVDR and the AI Act (European Commission)
- Directive (EU) 2024/2853 — Product Liability Directive (full text, EUR-Lex) — background on the liability regime that sits alongside the AI Act
Get an EU AI Act assessment built around your actual systems
A generic checklist tells you what the regulation says. It doesn't tell you where your business sits inside it. Liorant runs EU AI Act readiness as a governance workstream, not a slide deck: system inventory, role and risk classification, and a documentation build-out that maps directly to Articles 9–15 — designed to work alongside teams already running on Copilot Studio, Google Gemini, or Claude. It sits inside Liorant's wider AI strategy work.
Start with a free 30-minute AI discovery session. We identify your highest-value automation opportunity and explain exactly how Liorant can help — no slides, no pitch.
Book your AI discovery session