What the world's first comprehensive AI law actually requires of you, in plain language. Updated July 2026, following the adoption of the Digital Omnibus.
The Act in one paragraph
The EU AI Act is the first comprehensive law regulating artificial intelligence. It entered into force in August 2024 and applies in phases through 2028. It takes a risk-based approach: the riskier the use of AI, the stricter the rules. Crucially, it regulates the use of AI, not just its creation. If your business uses AI tools such as ChatGPT, Copilot, AI agents or SaaS automations, parts of this law apply to you, whether you are based in the EU or simply serve EU customers.
Does it apply to you?
The Act distinguishes between providers, who build AI systems, and deployers, who use them. Most businesses are deployers. Two tests decide whether you are in scope:
- You use AI. Any AI tool used in your operations counts: chatbots, copilots, agents, automated screening, content generation, analytics with AI features.
- You touch the EU. You are established in the EU, or the output of your AI is used in the EU. A company outside Europe serving EU customers with AI-assisted services can be in scope. This mirrors how GDPR reached beyond Europe.
The four risk levels
| Level | What it means | Examples |
|---|---|---|
| Prohibited | Banned outright since February 2025. | Social scoring, manipulative or exploitative AI, emotion recognition at work, and, added in 2026, AI generating non-consensual intimate imagery. |
| High risk | Permitted with strict duties: risk management, oversight, records, human control. | AI used in hiring and HR decisions, credit scoring, education, critical infrastructure, biometrics. |
| Limited risk | Transparency duties. | Chatbots must reveal they are AI. AI-generated content and deepfakes must be disclosed and machine-readable. |
| Minimal risk | No specific obligations. Most everyday AI sits here. | Spam filters, spellcheck, recommendation features. |
The most common misconception: using AI tools from compliant vendors does not make your business compliant. Deployer duties — AI literacy, transparency towards your customers, and oversight of high-risk uses — belong to you and cannot be outsourced to Microsoft, Google or OpenAI.
What applies to almost every business
AI literacy (in force)
Article 4, since February 2025. Staff who use AI must have sufficient AI literacy for their role. In practice: training, tracked and evidenced.
Transparency (August 2026)
Article 50, from 2 August 2026. Tell people when they are interacting with AI, label AI-generated content, disclose deepfakes. Systems already on the market before August 2026 have until 2 December 2026 to meet the machine-readable marking rules.
High-risk duties (December 2027)
Article 26 and related, from 2 December 2027. If you deploy AI for hiring, credit, education or other Annex III uses: human oversight, monitoring, record keeping, and input controls. AI embedded in regulated products follows from August 2028.
Key dates at a glance
| Date | What happens |
|---|---|
| Aug 2024 | Act enters into force. |
| Feb 2025 | Prohibitions apply. AI literacy duty begins. |
| Aug 2025 | Rules for general-purpose AI models (the providers' problem, not yours). |
| Aug 2026 | General application. Transparency duties live. Penalty regime live. National enforcement in place. |
| Dec 2026 | Grace period ends for marking AI content from pre-existing systems. |
| Dec 2027 | High-risk obligations apply to standalone (Annex III) systems, deferred from 2026 by the Digital Omnibus, adopted June 2026. |
| Aug 2028 | High-risk obligations for AI embedded in regulated products. |
Penalties, stated precisely
Fines scale with the violation: up to €35M or 7% of global turnover for prohibited practices, and up to €15M or 3% for most other breaches, including transparency and high-risk duties. SMEs pay the lower of the fixed sum or the percentage. The AI literacy duty carries no direct fine, but evidence of literacy is exactly what regulators, customers and insurers ask to see first.
The commercial reality: for most businesses the first enforcement will not come from a regulator. It will come from a customer's procurement questionnaire, an insurance renewal, or a lost deal. “How do you govern your use of AI?” is already a buying question. The Act simply made the answer mandatory.
Five practical steps to take now
- Inventory your AI. List every tool, copilot, agent and automation in use, including the ones IT never approved.
- Build AI literacy. Train the people using AI, and keep evidence of who was trained, on what, and when.
- Adopt an AI policy. Define acceptable use, data boundaries and disclosure rules, and have staff sign it.
- Name an owner. One accountable person for AI governance, however small the business.
- Oversee your suppliers. Know which vendors put AI in your workflows, and check what they do with your data.
Do these five things, keep the evidence current, and you can answer the question every buyer is starting to ask, with proof rather than promises.
About EUQA: EUQA is the trust layer for businesses using AI. Five controls, one continuously verified trust profile that customers, procurement teams and insurers can check at any time. Learn more at euqa.ai.
This guide is general information, not legal advice. The EU AI Act applies differently depending on your systems and their use; obtain professional advice for your specific situation. Content reflects the Act as amended by the Digital Omnibus on AI, July 2026.