The EU AI Act — what it requires, and when
The AI Act is a regulation, not a directive. It applies directly in every member state, without a national law in between. Parts of it have been binding since February 2025; in July 2026 the high-risk deadlines were moved.
Last updated: 5 August 2026
The dates
What is the EU AI Act?
The AI Act is the EU regulation on artificial intelligence — Regulation (EU) 2024/1689 — and it applies directly in all member states. That is the single most important structural difference from NIS2: there is no national transposition law to wait for, no twenty-seven versions of the text, and no separate national deadline. The obligations are the same in Amsterdam, Brussels, Vienna and Dublin. What differs from country to country is only who supervises and enforces them, and several member states have not finished appointing those authorities.
The regulation does not regulate technology as such. It regulates use: the same model can be unregulated in one application and high-risk in another. The question is never “is this AI”, it is “what is this AI system used for, and what is my role in it”.
What already applies today
Three tranches are already in force: the prohibitions and the AI literacy duty since 2 February 2025, the rules for general-purpose AI models since 2 August 2025, and the transparency obligations, governance and penalties since 2 August 2026.
- 2 February 2025 — general provisions and definitions, the AI literacy obligation in Article 4, and the prohibited practices in Article 5.
- 2 August 2025 — obligations for providers of general-purpose AI models (Articles 51 to 55), plus the governance structure.
- 2 August 2026 — the majority of the regulation, including the transparency obligations in Article 50, and the start of enforcement.
What changed in July 2026
Regulation (EU) 2026/1744 of 8 July 2026 — the digital omnibus on AI — moved the high-risk obligations back: to 2 December 2027 for systems classified as high-risk under Article 6(2) and Annex III, and to 2 August 2028 for systems classified under Article 6(1) and Annex I. It entered into force on 27 July 2026.
The reason given in the recitals is that the harmonised standards, common specifications and guidance were not ready, and that national competent authorities were not in place in time. Two points are worth holding on to. First, only Chapter III Sections 1 to 3 moved — the transparency, prohibition, literacy and general-purpose-model obligations did not. Second, a postponed deadline is not a cancelled one: the documentation a high-risk system needs takes longer to produce than the notice period now left.
There is also a short transitional window for generative systems that were already on the market before 2 August 2026. Their transparency obligations bite four months later, on 2 December 2026 (date not yet confirmed). We mark this one because our sources disagree on it, and a wrong date in a compliance timetable is worse than a missing one — the AI Manager flags it the same way.
The risk classes
The regulation sorts systems into four tiers, and the tier decides what you have to do.
- Prohibited (Article 5) — a short list of practices that may not be placed on the market or used at all, among them social scoring, untargeted scraping of facial images, and emotion recognition in the workplace and in education.
- High risk (Article 6, Annexes I and III) — the heavy tier: risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness, and a conformity assessment. Annex III covers stand-alone systems in areas such as employment, credit, education, critical infrastructure and law enforcement; Annex I covers AI embedded in products that already carry CE marking.
- Transparency (Article 50) — people must be told when they are dealing with an AI system, synthetic content must be marked in a machine-readable way, and deep fakes must be disclosed.
- General-purpose AI models (Articles 51 to 55) — obligations for the model providers themselves, with a stricter set for models with systemic risk.
Everything outside these tiers is unregulated by the AI Act. That is a large share of ordinary business use — and it is the reason a proper classification is worth doing before anything else: it usually shrinks the problem.
Provider or deployer — which are you?
A provider develops an AI system or has one developed and puts it on the market under its own name; a deployer uses one under its own authority. Most small and mid-sized companies are deployers, and deployer obligations are considerably lighter than provider obligations.
The catch is that the roles can swap. If you take a general-purpose system, put your own name on it and place it on the market, or if you substantially modify a high-risk system or change its intended purpose, you become the provider — with the full provider duty set. Fine-tuning a model and shipping it as your own product is the case that catches people out most often.
AI literacy: the duty that applies to everyone
Article 4 requires providers and deployers to take measures that support a sufficient level of AI literacy among the staff and other people who operate their AI systems on their behalf. As reworded by Regulation (EU) 2026/1744 it no longer asks you to guarantee a particular level of competence per person. There is no exemption for small companies and no threshold. It has applied since 2 February 2025.
What “sufficient” means is deliberately not spelled out — it depends on the systems in use, the roles of the people using them, and the context. In practice the obligation is met by knowing which AI systems are in use, briefing the people who work with them, and being able to show that both happened. The last part is the one that gets forgotten.
Transparency obligations since August 2026
Article 50 has four strands, and they hit ordinary businesses more often than the high-risk rules do:
- People interacting directly with an AI system must be informed, unless it is obvious.
- Synthetic audio, image, video or text must be marked in a machine-readable format.
- People exposed to emotion recognition or biometric categorisation must be informed.
- Deep fakes and AI-generated text published to inform the public on matters of public interest must be disclosed as such.
A company that runs a chatbot on its website, or publishes AI-generated images, is in scope of this article today.
What are the fines?
Breaching the prohibitions in Article 5 carries fines of up to 35 million euros or 7% of total worldwide annual turnover, whichever is higher; most other breaches up to 15 million euros or 3%; supplying incorrect or misleading information to authorities up to 7.5 million euros or 1%.
There is one relief that matters for smaller organisations: for SMEs, including start-ups, each of these fines is capped at the lower of the two figures, not the higher. A small company therefore faces the percentage, not the flat amount — which is still enough to hurt, and still requires being able to demonstrate what you did.
Where ISO/IEC 42001 fits
The AI Act says what must be achieved, not how to organise it. ISO/IEC 42001 is the management-system standard for artificial intelligence and provides that organisational frame: context and scope, policy, roles, risk assessment and treatment, a statement of applicability, operation, monitoring, internal audit and management review.
The two are not the same thing and a certificate does not create a presumption of conformity with the regulation. But the overlap is substantial, and building the management system once — rather than once for the standard and once for the regulation — is what keeps the effort proportionate. Both are instruments inside the broader practice of AI governance — which system is allowed, who is accountable for it, and what evidence you can produce.
How do you prepare?
- List the AI systems you actually use — including the ones embedded in tools you already licence. Most inventories are shorter than feared and longer than expected.
- Classify each use, not each tool — prohibited, high risk, transparency, or none of these.
- Establish your role per system — provider or deployer, and check whether anything you do turns you into a provider.
- Cover Article 4 now — it already applies, and it is the cheapest obligation to meet and the easiest to be caught out on.
- Document as you go — the deadlines that moved to 2027 and 2028 look distant until you count the evidence a high-risk file needs.
Frequently asked questions
Is the EU AI Act already in force?
Yes, in stages. The prohibitions and the AI literacy obligation have applied since 2 February 2025, the rules for general-purpose AI models since 2 August 2025, and the transparency obligations, governance and penalties since 2 August 2026.
Were the high-risk deadlines postponed?
Yes. Regulation (EU) 2026/1744 of 8 July 2026 moved the obligations in Chapter III Sections 1 to 3 to 2 December 2027 for high-risk systems under Article 6(2) and Annex III, and to 2 August 2028 for those under Article 6(1) and Annex I. The transparency, prohibition and AI literacy obligations were not postponed.
Does the AI Act apply to small companies?
Yes. There is no general size threshold. The AI literacy obligation in Article 4 and the transparency obligations in Article 50 apply regardless of headcount; only the fines are capped differently, at the lower of the two figures for SMEs including start-ups.
Am I a provider or a deployer?
A provider develops an AI system or has one developed and places it on the market under its own name; a deployer uses one under its own authority. Most companies are deployers, but placing a system on the market under your own name, substantially modifying a high-risk system or changing its intended purpose makes you a provider.
What are the fines under the EU AI Act?
Up to 35 million euros or 7% of total worldwide annual turnover for breaching the prohibitions in Article 5, up to 15 million euros or 3% for most other breaches, and up to 7.5 million euros or 1% for supplying incorrect or misleading information to authorities. For SMEs including start-ups, the lower of the two figures applies.
Do I need a national law to be affected?
No. The AI Act is a regulation and applies directly in every member state without national transposition. National law only determines which authority supervises and enforces it, and several member states are still completing that step.
Does ISO/IEC 42001 make me compliant with the AI Act?
No. ISO/IEC 42001 is a management-system standard for artificial intelligence and gives the organisational structure — scope, policy, risk assessment, statement of applicability, monitoring, internal audit. It does not create a presumption of conformity with the regulation, but the two overlap substantially and are best built once rather than twice.
What the documented version of this looks like
Everything above is the obligation. These four views are the TSMONDO AI Manager working through it — classification, obligations, the Article 4 record and the report you hand over. The screenshots show sample data for a fictitious credit-scoring use case.
The classification, answered rather than guessed
The prohibitions come first, because a single yes there ends the discussion. Every question carries the article it comes from, so the answer is traceable months later when someone asks why you decided what you decided.
Only the duties that actually apply to you
The class and your role decide the list, and the reason for the class is stated next to it. Each duty is set to met, partial, open or not applicable — that status is what the compliance report is built from.
Article 4, covered and on file
The literacy duty has applied since February 2025 and has no size threshold. Eight short modules cover the ground; the form underneath turns the session into a dated record with the participants named individually, a person responsible, and a refresher proposed a year on.
The finished document, not the raw data
Per system a compliance report, a dossier and a statement of applicability; for the organisation a management report, the training record and the evidence overview. Exported as PDF, ready to hand to an auditor.
Built by one specialist, not resold as a platform
One point of contact with the papers to match
- ISO 27001 Lead Auditor and Lead Implementer
- ISACA CISM (Certified Information Security Manager)
- Certified data protection officer and IT security officer (TÜV)
- Member of the Alliance for Cyber Security (BSI, Germany)
Organisations already working with it
- Industry, media, healthcare, the public sector and digital platforms
- On security, NIS2 and data protection
- Named only with permission — full list at tsmondo.de/referenzen
Try it first, decide afterwards
- 21 days, no registration and no cloud account
- Runs locally on Windows; nothing is sent anywhere
- Your inventory, classifications and evidence stay on your own machine
- If it does not fit, delete the folder — nothing is left behind
Priced by company size, not per seat
- From EUR 499 per year or EUR 49 per month, both net
- One licence per company, unlimited users at every site — the price band follows the number of employees
- Monthly subscription cancellable from the end of the current month, annual with one month's notice
- Reverse charge applies for businesses in other EU member states with a valid VAT identification number
Local · no cloud · no data passed to third parties · built by an ISO 27001 Lead Auditor and ISACA CISM. This offer is addressed exclusively to businesses; there is no right of withdrawal. Our terms and conditions apply.
From reading about it to having it documented
The TSMONDO AI Manager takes you through classification, roles, obligations and the documents — locally, on your own machine, with no cloud account.