AI Governance, Security & Compliance

EU AI Act: What Businesses Need to Know and How to Prepare

Pillar guide Updated August 2026 17 min read By Ricardo Mendoza Castro

The 2026 Digital Omnibus reset the EU AI Act's clock, not its rules. Here are the deadlines that now matter, who carries which obligations, and a practical path to readiness.

AT A GLANCE
Status as of August 2026
4
Risk tiers: prohibited, high-risk, transparency, minimal
€35M
Or 7% of worldwide turnover — the top penalty ceiling
2 Dec 2027
New high-risk deadline for Annex III systems
83%
Of assessed organizations have no formal AI inventory
WHERE YOUR SYSTEMS LAND
Prohibited
Social scoring, manipulation, emotion recognition at work
High-risk
Hiring, credit, insurance pricing, education, biometrics
Transparency
Chatbots, deepfakes, synthetic content — live since Aug 2026
Minimal
Spam filters, inventory optimization, internal tools
THE WEEK EVERYTHING CHANGED
27 July 2026
Digital Omnibus delays the high-risk deadlines by more than a year.
2 August 2026
Chatbot and deepfake transparency duties become enforceable anyway.

On 27 July 2026, Regulation (EU) 2026/1744 — the "Digital Omnibus on AI" — entered into force and pushed back the EU AI Act's high-risk deadlines by more than a year. Six days later, on 2 August 2026, most of the Act's remaining rules, including chatbot and deepfake transparency duties, became enforceable anyway. A large share of businesses read the first headline and missed the second: a 2026 vendor analysis of its own client assessments across eight industries found that 78% of organizations assessed had taken no meaningful steps toward AI Act compliance, and 83% had no formal inventory of the AI systems they use (Vision Compliance, April 2026).

The short answer to "does the EU AI Act apply to my business": it may if you build, sell, or use an AI system in the EU, or if the system's output is used there — even when your company is headquartered elsewhere. Article 2 contains specific exemptions, so scope still requires a case-by-case check. The rest of this guide covers what changed in 2026, what didn't, the deadlines that now matter, who carries which obligations, and a practical path to get ready.

What is the EU AI Act, and does it apply to your business?

Regulation (EU) 2024/1689 defines an AI system as software that infers, from the inputs it receives, how to generate outputs — predictions, content, recommendations, or decisions — that can influence physical or virtual environments. Autonomy and inference are the operative words. A conventional rules engine or a deterministic calculator doesn't automatically qualify just because it runs on a computer, and a system doesn't need deep learning or generative capabilities to qualify either.

The Act reaches providers who place AI systems on the EU market, deployers established in the EU, importers, distributors, and — critically — third-country providers and deployers whose system's output is used in the EU. Unlike some other EU laws, this territorial rule does not depend on a separate "targeting" test. Subject to Article 2's exemptions, it can cover a Colombian recruitment platform scoring candidates for an EU-based hiring manager, a Salvadoran fintech's credit model feeding a European partner bank, or a US SaaS tool whose chatbot serves Spanish customers, regardless of where their servers, staff, or incorporation sit.

Spain moved early on enforcement infrastructure. The Agencia Española de Supervisión de la Inteligencia Artificial (AESIA), created by Royal Decree 729/2023 and operational since 2024, became the first dedicated national AI supervisor in the EU. It has since helped publish a set of 16 practical compliance guides developed through the Spanish AI regulatory sandbox — a useful reference for any Barcelona- or Spain-facing business trying to translate the regulation into operational steps.

The 2026 Digital Omnibus: what actually changed (and what didn't)

This is the point most secondary coverage gets wrong, and it matters commercially: the delay is real, but partial.

Regulation (EU) 2026/1744 postponed the two high-risk deadlines that were set to bite hardest — Annex III use cases (employment, credit, education, essential services, and more) now apply from 2 December 2027, and Annex I product-embedded AI (medical devices, machinery, toys) from 2 August 2028. It also extended some SME simplifications to small mid-cap companies, widened access to regulatory sandboxes, simplified the original company-facing AI-literacy regime, and added a new prohibition covering AI systems that generate non-consensual intimate imagery or child sexual abuse material, effective 2 December 2026.

What it did not touch: the Article 5 prohibited-practices regime and the original definitions, both applying since 2 February 2025; the GPAI-model obligations, applying since 2 August 2025; and the Article 50 transparency duties — telling users they're talking to a chatbot, labelling deepfakes, marking synthetic content — which became enforceable on 2 August 2026 along with the Commission's enforcement powers over GPAI providers. One transition applies: providers of synthetic-content systems placed on the market before 2 August 2026 have until 2 December 2026 to meet Article 50(2). Reading "the AI Act was delayed" as "we can relax on AI" still leaves a live compliance gap in areas that already carry penalties.

The four risk tiers: where your AI systems fall

Every AI system a business builds, buys, or embeds lands in one of four tiers. The labels "limited risk" and "minimal risk" are explanatory shorthand, not exhaustive legal categories — the actual legal tests sit in Articles 5, 6, and Annex III of the regulation itself.

Tier Legal treatment Typical examples What it requires
Prohibited Cannot be placed on the market, put into service, or used, subject to narrow exceptions Social scoring, manipulative techniques causing significant harm, untargeted facial-scraping databases, workplace or educational emotion recognition, non-consensual intimate or CSAM generation Stop, redesign, or document a narrow statutory exception
High-risk Full Chapter III requirements: risk management, data governance, logging, human oversight, conformity assessment, CE marking Biometrics, critical infrastructure, employment decisions, credit scoring, life and health insurance pricing, education, policing, migration Classification memo, technical file, testing, conformity assessment, registration
Specific transparency ("limited risk") Article 50 disclosure and marking duties Chatbots, deepfakes, synthetic-content generators, emotion-recognition interfaces User notices, machine-readable marking, visible disclosure
Minimal risk Generally no mandatory AI Act system controls Spam filters, inventory optimization, internal productivity tools Baseline inventory and governance; watch for scope creep

High-risk classification runs through two routes. Article 6(1) catches AI that's a regulated product or safety component under Annex I where sectoral law already requires third-party conformity assessment. Article 6(2) presumes Annex III use cases high-risk unless the system performs only narrow, procedural, or preparatory tasks and poses no significant risk — an exception that requires a documented analysis, not an assumption. General-purpose AI (GPAI) models sit under a separate model-level regime that can apply even when the downstream system isn't high-risk: providers of models like GPT-4-, Gemini-, or Claude Opus-class systems must maintain technical documentation, share information with downstream providers, publish a training-data summary, and comply with EU copyright rules. Models presumed to carry systemic risk — informally, those trained above roughly 10²⁵ floating-point operations, a threshold the Commission can also apply by other criteria — face additional testing, risk mitigation, and incident-reporting duties.

Every deadline you need to track

Already in force
Upcoming deadline
1 August 2024
Regulation (EU) 2024/1689 enters into force
2 February 2025
Definitions and Article 5 prohibited practices apply
2 August 2025
Governance rules and GPAI-provider obligations apply
27 July 2026
Digital Omnibus (Regulation (EU) 2026/1744) enters into force
2 August 2026
General application of remaining provisions, including Article 50 transparency; the Commission begins enforcing GPAI rules
2 December 2026
New prohibition on non-consensual intimate imagery and CSAM generation applies; the Article 50(2) transition ends for synthetic-content systems placed on the market before 2 August 2026
2 August 2027
Legacy GPAI models (placed on the market before 2 August 2025) must come into compliance
2 December 2027
High-risk rules apply to Annex III systems
2 August 2028
High-risk rules apply to Annex I product-embedded AI

Sources: Regulation (EU) 2024/1689 and Regulation (EU) 2026/1744, Official Journal of the EU (EUR-Lex); European Commission, "Navigating the AI Act".

Provider, deployer, importer, distributor: who's responsible for what

The Act assigns obligations by function, not by contract label. Calling yourself a "customer" or "reseller" doesn't override what you actually do with a system.

  • Providers carry the heaviest load: defining intended purpose, building the technical file, running risk management, designing logging and human-oversight capability, and completing conformity assessment.
  • Deployers — the role most businesses actually occupy — must use systems according to instructions, assign competent human oversight, monitor operation, keep accessible logs, and report risks. Public bodies and deployers of specified credit or life and health-insurance systems must also run a fundamental-rights impact assessment.
  • Importers and distributors verify that the provider has done its part before the system reaches the market, and must halt supply if it hasn't.

The trap worth naming explicitly: Article 25 reclassifies a deployer as a provider — with a provider's full obligations — if it rebrands a system under its own name, substantially modifies it, or changes its intended purpose in a way that makes it high-risk. A bank that takes a vendor's credit-scoring model and retrains it on proprietary data, or a BPO that white-labels a third-party AI tool for its own clients, can cross that line without meaning to. Classification should be reopened whenever data, model, interface, or purpose changes — not filed once and forgotten.

What high-risk compliance actually requires

For systems that land in the high-risk tier, Chapter III sets out a defensible-evidence architecture, not a checkbox exercise: lifecycle risk management, data governance and quality controls, technical documentation (Annex IV), automatic logging retained for at least six months, instructions and transparency for deployers, human-oversight design that gives a real person the authority to override or stop the system, accuracy and cybersecurity testing, a documented quality-management system, conformity assessment, an EU declaration of conformity, CE marking, registration, and post-market monitoring with serious-incident reporting.

For most Annex III use cases, the default conformity route is internal control rather than third-party certification — specified biometric systems are the main exception, where a notified body may be required. For Annex I products, AI requirements fold into the existing sectoral conformity process (for example, the Medical Devices Regulation), rather than running as a parallel track. One caveat worth building into any 2026–2027 project plan: the harmonised standards that would create a presumption of conformity are still incomplete — CEN and CENELEC missed their original August 2025 target, and standardisation work continues into 2026. Absence of a final standard doesn't remove the duty to prepare; it means documenting defensible alternative specifications and test evidence until one exists.

HUMAN OVERSIGHT IN PRACTICE

The Act doesn't just ask for a person somewhere in the loop — it requires that person to understand the system's capabilities and limitations, recognise automation bias, interpret its outputs, and hold real authority to override, ignore, or stop it. A reviewer who signs off on outputs without the time, training, or organisational standing to actually challenge them won't hold up as effective oversight if a regulator asks. Building that role into a job description, not just a workflow diagram, is part of the compliance file.

Sector spotlight: healthcare and medical devices

Healthcare AI reaches high-risk status through either of two doors: an Annex III essential-service use (a system controlling access to or eligibility for care), or Article 6(1), where the AI is a medical device or safety component and existing device law already requires third-party conformity assessment.

In practice, AI embedded in MDR Class IIa/IIb/III and IVDR Class A–D devices — sometimes informally called "Medical Device AI" — now carries AI Act duties on top of existing MDR/IVDR obligations: additional data governance, transparency, human oversight, and post-market monitoring layered onto a compliance process that was already substantial. The Medical Device Coordination Group published MDCG 2025-6 specifically to clarify how the two regimes interact, and the message is consistent: integrate the AI Act's requirements into the existing quality-management system and clinical evaluation process rather than running two parallel programs. The applicable date for this Annex I route is now 2 August 2028, but CE marking under MDR or IVDR doesn't relieve a hospital of validating its own workflows, user competence, and ongoing performance in its actual patient population — that responsibility stays local.

Sector spotlight: financial services and insurance

Two specific uses are presumptively high-risk under Annex III: AI that evaluates creditworthiness or sets a credit score for a natural person, and AI used for risk assessment and pricing in life and health insurance. Fraud-detection AI is explicitly carved out of the credit-scoring high-risk basis, though it can still trigger other AI Act provisions.

The European Banking Authority published a factsheet in November 2025 mapping the AI Act against CRD, CRR, and DORA, and found no significant contradictions between the two regimes — financial institutions can satisfy much of the provider quality-management obligation through their existing governance arrangements, while still owning the AI-specific duties around risk management and incident reporting. EIOPA reached a similar conclusion for insurance in its August 2025 opinion, which confirms that governance obligations already in Solvency II and the Insurance Distribution Directive extend naturally to AI systems outside the prohibited and high-risk categories. Neither authority is proposing new rules; both are telling regulated firms to map what they already do against the Act rather than build a second compliance stack.

The practical risk sits in procurement. A bank or insurer using a third-party high-risk model is usually a deployer, but a vendor contract that simply states "we comply with the AI Act" isn't evidence — the regulated entity keeps its own deployment, oversight, and consumer-protection duties regardless of what the vendor promises. Model documentation, bias and performance evidence, version-change notification, audit rights, and incident commitments belong in the contract, not taken on faith.

Penalties: what non-compliance actually costs

MAXIMUM FINE, € MILLIONS
Prohibited practices / data governance€35M
7% of worldwide turnover — above GDPR's 4% ceiling
Other AI Act obligations€15M
3% of worldwide turnover
GPAI-provider breaches (Commission-enforced)€15M
3% of worldwide turnover
Misleading information to authorities€7.5M
1% of worldwide turnover

Source: Regulation (EU) 2024/1689, Article 99, EUR-Lex.

For SMEs and startups, the lower of the fixed sum or the percentage applies; for larger enterprises, the higher one does. A startup with €2 million in turnover facing a Tier-1 infringement is looking at roughly €140,000, not €35 million — a meaningful distinction that gets lost in headline coverage. For context, the 7% ceiling for prohibited practices exceeds GDPR's 4% cap, making it the second-highest percentage-based penalty in EU digital regulation after the Digital Markets Act's 10%.

How to prepare: an 8-step compliance roadmap

The postponement bought time, not an excuse to wait — high-risk readiness routinely takes 12–24 months once data remediation, logging architecture, and testing are factored in. This is the order that gets a business from zero to defensible.

1
Build an AI system inventory
Cover purchased tools, embedded vendor functions, internally built models, employee "shadow AI," and any GPAI dependencies. You cannot classify what you haven't mapped — and 83% of assessed organizations had no formal inventory to start from.
2
Run a risk-classification exercise
Test every system against Articles 5 and 6 and the Annex III list. Document any Article 6(3) exception in a short memo, not a spreadsheet label — it needs to survive scrutiny later.
3
Assign legal roles
Decide provider, deployer, importer, or distributor for each system, and flag anything close to the Article 25 "accidental provider" line.
4
Stand up a governance body and a named owner
A committee with no owner produces documentation nobody maintains.
5
Build documentation and logging processes
Annex IV technical files and system logs need a home before an auditor — or a regulator — asks for them.
6
Put vendor risk management in your contracts
Require model documentation, incident commitments, audit rights, and change notification from every AI vendor, not just the ones you suspect are high-risk.
7
Prepare for conformity assessment where you act as a provider
Internal control covers most Annex III cases; specified biometric systems and Annex I products may need a notified body.
8
Treat Articles 9–15 as your working checklist through the delay
The high-risk deadline moved to December 2027, but the engineering, data, and governance work needed to meet it doesn't get faster by starting later.

What EU AI Act compliance can cost

There is no credible universal price for AI Act compliance. Cost depends on whether the company is a provider or deployer, whether the system is high-risk, and which controls already exist. A business using ordinary productivity tools should not budget as if it manufactures a regulated medical device.

An estimated benchmark for big companies
€23,850–€40,400

In April 2026, the European Commission estimated this incremental AI Act compliance cost for an Annex I high-risk product provider that already had a quality-management system and sectoral conformity assessment in place. Read the Commission's answer to the European Parliament.

For SMEs, a lower official estimate starts at €5,000. The Commission's 2021 proposal modelled annual human-oversight costs for users of high-risk AI at approximately €5,000–€8,000 per year. This is a narrowly scoped regulatory estimate, not a market quote or an all-in compliance budget. See the official EUR-Lex proposal.

The timing estimates below are planning ranges, not statutory deadlines. Several workstreams can run in parallel.

Workstream Estimated effort
Governance mandate and named owner3–8 weeks
Enterprise AI inventory4–12 weeks
Classification review per system1–5 days simple; 2–6 weeks complex
Article 50 transparency work2–12 weeks
Vendor due diligence and contract updates4–16 weeks
High-risk deployer controls3–9 months
High-risk provider QMS and technical file6–18 months
Monitoring and incident handlingContinuous

That figure is a bounded example, not a starting price for every company. It does not cover an organisation with no quality-management system, multiple systems, major data remediation, medical-device clinical work, or the ongoing internal cost of monitoring and incident response. The practical first step is to inventory and classify the systems before setting a budget.

Frequently asked questions

Can you explain the EU AI Act in simple terms?

It's an EU regulation that sorts AI systems into four risk tiers — prohibited, high-risk, limited (transparency-only), and minimal — and attaches different legal obligations to each. It can apply to businesses outside the EU when they place AI on the EU market or when a system's output is used in the Union, subject to the exemptions in Article 2.

Does the 2026 Digital Omnibus mean businesses can wait to comply?

No. It postponed the high-risk deadlines to 2 December 2027 (Annex III) and 2 August 2028 (Annex I), but prohibited practices, GPAI obligations, and Article 50 transparency duties are already enforceable. Businesses that read the delay as blanket relief have a live compliance gap in the areas already carrying penalties.

What's the difference between a provider and a deployer under the AI Act?

A provider builds or places an AI system on the market and carries the full technical-file, testing, and conformity-assessment burden. A deployer uses a system someone else built and must follow its instructions, assign human oversight, and monitor its operation. A deployer can become a provider under Article 25 by rebranding, substantially modifying, or repurposing a system.

Is my company's chatbot covered by the EU AI Act?

Almost certainly, under Article 50's transparency rules, which have applied since 2 August 2026. Users need to know they're interacting with an AI system. Chatbots don't typically require the full high-risk compliance architecture unless they perform a separately listed high-risk function.

What are the maximum fines under the EU AI Act?

Up to €35 million or 7% of worldwide annual turnover for prohibited practices and specified data-governance breaches, €15 million or 3% for other obligations, and €7.5 million or 1% for misleading information to authorities. SMEs and startups pay the lower of the fixed amount or the percentage; larger enterprises pay the higher.

Does the EU AI Act apply to businesses outside the EU, like companies in the United States, Colombia or El Salvador?

It can. The Act covers non-EU providers that place AI systems or GPAI models on the EU market and non-EU providers or deployers whose system output is used in the Union, subject to Article 2's exemptions. A non-EU provider of a high-risk system must also appoint an EU authorised representative under Article 22.

Official sources

Every claim above traces to one of these primary sources. Check them directly, and recheck close to your own decision dates — several (the Digital Omnibus, the standardisation timeline, national designations) were still moving at the time of writing.

AI GOVERNANCE

Get an EU AI Act assessment built around your actual systems

A generic checklist tells you what the regulation says. It doesn't tell you where your business sits inside it. Liorant runs EU AI Act readiness as a governance workstream, not a slide deck: system inventory, role and risk classification, and a documentation build-out that maps directly to Articles 9–15 — designed to work alongside teams already running on Copilot Studio, Google Gemini, or Claude. It sits inside Liorant's wider AI strategy work.

Start with a free 30-minute AI discovery session. We identify your highest-value automation opportunity and explain exactly how Liorant can help — no slides, no pitch.

Book your AI discovery session