Hael
Book a meeting
EU AI Act · Introduction

EU AI Act Explained

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 8 min read
Key takeaways
  • The EU AI Act is a product safety law for artificial intelligence. It sorts AI systems into four risk tiers and attaches different duties to each.
  • It applies to organisations outside the EU whose AI systems are placed on the EU market or whose outputs are used in the EU.
  • The Digital Omnibus on AI, adopted in June 2026, moved the high-risk deadlines. Stand-alone high-risk systems now apply from 2 December 2027.
  • Transparency duties under Article 50 took effect on 2 August 2026 and were not delayed.
  • Penalties reach €35m or 7% of worldwide turnover for prohibited practices.

What the Act is

The EU AI Act is a regulation that treats artificial intelligence the way European law treats physical products: by risk. It sorts AI systems into tiers, bans a small number outright, imposes detailed duties on those it calls high risk, requires disclosure for systems that interact with people or generate content, and leaves everything else largely alone.

It came into force in August 2024 and applies in stages. In June 2026 the Digital Omnibus on AI amended those stages, moving the largest set of obligations later while leaving others where they were. The current dates are set out below.

Who does it apply to?

The Act reaches beyond the EU. It applies to providers placing an AI system on the EU market regardless of where they are established, to deployers established in the EU, and to providers and deployers outside the EU where the output produced by the system is used in the EU.

In practice that means a company in London, New York or Singapore is in scope if its product is sold to EU customers or if its output reaches people in the EU. Location of the company is not the test. Location of the market and the output is.

Two roles carry most of the duties. A provider develops an AI system and places it on the market under its own name. A deployer uses an AI system under its own authority. The same company is often both, and the duties differ, so establishing which role you hold for each system is the first practical step.

The four risk tiers

TierWhat it coversWhat it requires
ProhibitedPractices considered unacceptable, including social scoring, certain biometric categorisation, and manipulative techniques exploiting vulnerabilityBanned outright
High riskSystems listed in Annex III, such as employment, creditworthiness, education and essential services, plus AI embedded in regulated products under Annex IRisk management, data governance, technical documentation, record keeping, transparency to deployers, human oversight, accuracy and robustness, conformity assessment, registration
Limited risk, transparencySystems that interact with people, generate or manipulate content, or use emotion recognitionDisclosure duties under Article 50
Minimal riskEverything elseNo specific obligations under the Act

General purpose AI models sit alongside this structure with their own obligations, which have applied since August 2025 and cover technical documentation, information for downstream providers, copyright policy and a summary of training content, with additional duties for models presenting systemic risk.

The dates that now apply

The Digital Omnibus on AI was published by the European Commission in November 2025, agreed politically in May 2026, endorsed by the European Parliament in June 2026, approved by the Council on 29 June 2026 and entered into force in July 2026.

DateWhat applies
2 February 2025Prohibited practices, and the AI literacy duty
2 August 2025General purpose AI model obligations, governance structures, penalties framework
2 August 2026Article 50 transparency obligations, except that Article 50(2) does not apply to systems already on the market at that date
2 December 2026Article 50(2) applies to those legacy systems, and the new prohibitions on AI generating non-consensual intimate imagery and child sexual abuse material
2 August 2027Member States to have at least one national AI regulatory sandbox in operation
2 December 2027High-risk obligations for stand-alone Annex III systems
2 August 2028High-risk obligations for AI embedded in Annex I regulated products

The most common current error is to read "high risk delayed" as "the AI Act paused". It did not pause. The transparency duties took effect on 2 August 2026 on the original schedule, and the prohibited practices list was expanded rather than relaxed.

What Article 50 actually requires

Article 50 is the duty that is live now, and it is short.

If a system interacts with people, those people must be told they are dealing with AI, unless it is obvious.

If a system generates or manipulates synthetic audio, image, video or text, the output must be marked in a machine-readable way as artificially generated.

If content is a deep fake, that must be disclosed. If AI-generated text is published to inform the public on matters of public interest, that must be disclosed unless the content underwent human review with editorial responsibility.

If emotion recognition or biometric categorisation is used, the people exposed to it must be informed.

The obligation applies to systems in general, not only to high-risk ones, which is why it catches a much wider set of companies than the high-risk regime does.

Penalties

Up to €35m or 7% of total worldwide annual turnover, whichever is higher, for engaging in prohibited practices.

Up to €15m or 3% for breaches of other obligations, including high-risk requirements and the transparency duties.

Up to €7.5m or 1% for supplying incorrect, incomplete or misleading information to authorities. Lower caps apply to small and medium-sized enterprises.

What to do now

The deferral is time to do the foundational work properly, not permission to stop. Two tasks matter most, and both are prerequisites for everything later.

Build an inventory of every AI system your organisation provides or uses, with a named owner for each.

Classify each one: are you provider or deployer, does it fall in Annex III, does it trigger Article 50, is it embedded in a regulated product.

That classification decides which of the dates above apply to you, and getting it wrong is expensive in both directions. Our EU AI Act service page sets out how we run that work, and our free AI impact assessment gives you a starting view.

References

FAQ

Does the EU AI Act apply to companies outside the EU?

Yes, where the system is placed on the EU market or where its output is used in the EU. Location of the company is not the test.

Has the EU AI Act been delayed?

Parts of it. The Digital Omnibus, adopted in June 2026, moved high-risk obligations to 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for AI embedded in regulated products. The transparency obligations were not delayed.

What applied on 2 August 2026?

The Article 50 transparency obligations, with a carve-out: Article 50(2) does not apply to systems already on the market at that date, and reaches them on 2 December 2026 instead.

What are the fines?

Up to €35m or 7% of worldwide turnover for prohibited practices, up to €15m or 3% for other breaches, with lower caps for smaller companies.

Is ISO/IEC 42001 required by the AI Act?

No. It is a voluntary standard, but it builds the management system the Act's high-risk duties assume, which is why buyers and regulators increasingly look for it.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. We take companies through the EU AI Act, ISO/IEC 42001, SOC 2 and ISO 27001, from first assessment through to evidence a regulator or a buyer will accept, and maintain the position afterwards. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not legal advice on your particular circumstances.

Free check

See where you stand on EU AI Act, free.

Answer a short set of questions and see what EU AI Act expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether EU AI Act applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to EU AI Act.

Or speak to us about your deadline. Book a meeting.