EU AI Act Explained
- The EU AI Act is a product safety law for artificial intelligence. It sorts AI systems into four risk tiers and attaches different duties to each.
- It applies to organisations outside the EU whose AI systems are placed on the EU market or whose outputs are used in the EU.
- The Digital Omnibus on AI, adopted in June 2026, moved the high-risk deadlines. Stand-alone high-risk systems now apply from 2 December 2027.
- Transparency duties under Article 50 took effect on 2 August 2026 and were not delayed.
- Penalties reach €35m or 7% of worldwide turnover for prohibited practices.
What the Act is
The EU AI Act is a regulation that treats artificial intelligence the way European law treats physical products: by risk. It sorts AI systems into tiers, bans a small number outright, imposes detailed duties on those it calls high risk, requires disclosure for systems that interact with people or generate content, and leaves everything else largely alone.
It came into force in August 2024 and applies in stages. In June 2026 the Digital Omnibus on AI amended those stages, moving the largest set of obligations later while leaving others where they were. The current dates are set out below.
Who does it apply to?
The Act reaches beyond the EU. It applies to providers placing an AI system on the EU market regardless of where they are established, to deployers established in the EU, and to providers and deployers outside the EU where the output produced by the system is used in the EU.
In practice that means a company in London, New York or Singapore is in scope if its product is sold to EU customers or if its output reaches people in the EU. Location of the company is not the test. Location of the market and the output is.
Two roles carry most of the duties. A provider develops an AI system and places it on the market under its own name. A deployer uses an AI system under its own authority. The same company is often both, and the duties differ, so establishing which role you hold for each system is the first practical step.
The four risk tiers
| Tier | What it covers | What it requires |
|---|---|---|
| Prohibited | Practices considered unacceptable, including social scoring, certain biometric categorisation, and manipulative techniques exploiting vulnerability | Banned outright |
| High risk | Systems listed in Annex III, such as employment, creditworthiness, education and essential services, plus AI embedded in regulated products under Annex I | Risk management, data governance, technical documentation, record keeping, transparency to deployers, human oversight, accuracy and robustness, conformity assessment, registration |
| Limited risk, transparency | Systems that interact with people, generate or manipulate content, or use emotion recognition | Disclosure duties under Article 50 |
| Minimal risk | Everything else | No specific obligations under the Act |
General purpose AI models sit alongside this structure with their own obligations, which have applied since August 2025 and cover technical documentation, information for downstream providers, copyright policy and a summary of training content, with additional duties for models presenting systemic risk.
The dates that now apply
The Digital Omnibus on AI was published by the European Commission in November 2025, agreed politically in May 2026, endorsed by the European Parliament in June 2026, approved by the Council on 29 June 2026 and entered into force in July 2026.
| Date | What applies |
|---|---|
| 2 February 2025 | Prohibited practices, and the AI literacy duty |
| 2 August 2025 | General purpose AI model obligations, governance structures, penalties framework |
| 2 August 2026 | Article 50 transparency obligations, except that Article 50(2) does not apply to systems already on the market at that date |
| 2 December 2026 | Article 50(2) applies to those legacy systems, and the new prohibitions on AI generating non-consensual intimate imagery and child sexual abuse material |
| 2 August 2027 | Member States to have at least one national AI regulatory sandbox in operation |
| 2 December 2027 | High-risk obligations for stand-alone Annex III systems |
| 2 August 2028 | High-risk obligations for AI embedded in Annex I regulated products |
The most common current error is to read "high risk delayed" as "the AI Act paused". It did not pause. The transparency duties took effect on 2 August 2026 on the original schedule, and the prohibited practices list was expanded rather than relaxed.
What Article 50 actually requires
Article 50 is the duty that is live now, and it is short.
If a system interacts with people, those people must be told they are dealing with AI, unless it is obvious.
If a system generates or manipulates synthetic audio, image, video or text, the output must be marked in a machine-readable way as artificially generated.
If content is a deep fake, that must be disclosed. If AI-generated text is published to inform the public on matters of public interest, that must be disclosed unless the content underwent human review with editorial responsibility.
If emotion recognition or biometric categorisation is used, the people exposed to it must be informed.
The obligation applies to systems in general, not only to high-risk ones, which is why it catches a much wider set of companies than the high-risk regime does.
Penalties
Up to €35m or 7% of total worldwide annual turnover, whichever is higher, for engaging in prohibited practices.
Up to €15m or 3% for breaches of other obligations, including high-risk requirements and the transparency duties.
Up to €7.5m or 1% for supplying incorrect, incomplete or misleading information to authorities. Lower caps apply to small and medium-sized enterprises.
What to do now
The deferral is time to do the foundational work properly, not permission to stop. Two tasks matter most, and both are prerequisites for everything later.
Build an inventory of every AI system your organisation provides or uses, with a named owner for each.
Classify each one: are you provider or deployer, does it fall in Annex III, does it trigger Article 50, is it embedded in a regulated product.
That classification decides which of the dates above apply to you, and getting it wrong is expensive in both directions. Our EU AI Act service page sets out how we run that work, and our free AI impact assessment gives you a starting view.
References
FAQ
Does the EU AI Act apply to companies outside the EU?
Yes, where the system is placed on the EU market or where its output is used in the EU. Location of the company is not the test.
Has the EU AI Act been delayed?
Parts of it. The Digital Omnibus, adopted in June 2026, moved high-risk obligations to 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for AI embedded in regulated products. The transparency obligations were not delayed.
What applied on 2 August 2026?
The Article 50 transparency obligations, with a carve-out: Article 50(2) does not apply to systems already on the market at that date, and reaches them on 2 December 2026 instead.
What are the fines?
Up to €35m or 7% of worldwide turnover for prohibited practices, up to €15m or 3% for other breaches, with lower caps for smaller companies.
Is ISO/IEC 42001 required by the AI Act?
No. It is a voluntary standard, but it builds the management system the Act's high-risk duties assume, which is why buyers and regulators increasingly look for it.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance. We take companies through the EU AI Act, ISO/IEC 42001, SOC 2 and ISO 27001, from first assessment through to evidence a regulator or a buyer will accept, and maintain the position afterwards. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.
This guide is general information and is not legal advice on your particular circumstances.