The EU AI Act: What It Means for Business

What Is the EU AI Act?

The EU AI Act is the world’s first comprehensive legal framework for artificial intelligence. Formally, it is Regulation (EU) 2024/1689. Substantively, it is Europe’s attempt to turn “trustworthy AI” from a policy aspiration into enforceable rules.

The Act is risk-based. It does not treat a spam filter, a chatbot, a hiring algorithm, a medical device, and a foundation model as the same thing. The more consequential the use of AI, the heavier the legal burden. Minimal-risk uses are mostly left alone. High-risk uses face more substantial obligations. Some uses are prohibited outright. The regulation itself frames the law around harmonized rules for AI systems placed on the EU market, put into service, or used in the EU, with the stated goal of protecting health, safety, fundamental rights, democracy, the rule of law, and the environment. (eur-lex.europa.eu)

For businesses, the most important point is scope. The Act is not limited to companies incorporated in Europe. It can apply to organizations outside the EU where they place AI systems on the EU market, put AI systems into service in the EU, or where the output produced by an AI system is used in the EU. A U.S. company with European customers, European employees, or an AI-enabled product available in Europe may therefore be in scope even without a European headquarters.

That means the first question is not simply: Do we use AI? Almost everyone does to some extent.

The better questions are: What AI system are we using, what does it do, who does it affect, where is it used, and what role do we play?

That is why the Act is operationally demanding. It is not enough to have an AI policy. Companies need an AI inventory. They need to know which tools are customer-facing, which tools support internal decisions, which tools generate content, which tools are embedded in products, which tools come from vendors, and which tools have been modified or rebranded internally.

The rest of this piece maps the law’s architecture, timeline, roles, risk tiers, penalties, and the foundation-model layer, and then turns to the part that actually consumes a compliance team’s calendar: what to do before the next deadline lands. The explainer is the easy half. The operational half is where the work is.

What Is the Timeline?

Regulatory status current as of July 5, 2026. The Digital Omnibus discussed below was approved by the Council on June 29, 2026 and is awaiting publication in the Official Journal; confirm its status before relying on the amended dates.

The AI Act applies in phases.

The Act entered into force on August 1, 2024. On February 2, 2025, the general provisions, AI literacy obligations, and prohibitions on unacceptable-risk AI practices began applying. On August 2, 2025, governance rules and obligations for providers of general-purpose AI models began applying. The Act’s general application date is August 2, 2026, subject to specific transition rules and exceptions. (eur-lex.europa.eu)

What happens August 2, 2026.

Starting August 2, several things matter for businesses. The broader AI Act framework becomes generally applicable. Article 50 transparency obligations begin applying. The Commission’s enforcement powers for general-purpose AI model obligations also begin. For companies with AI systems touching the EU market, this is the date when the law becomes a live operational issue rather than a future compliance project. (ai-act-service-desk.ec.europa.eu)

Then comes the AI Omnibus.

Under the Council-approved Omnibus, obligations for stand-alone high-risk AI systems under Annex III move from August 2, 2026 to December 2, 2027. Obligations for high-risk AI systems embedded in regulated products under Annex I move from their original date of August 2, 2027 to August 2, 2028. Note the asymmetry: the stand-alone category gets roughly a sixteen-month push, the embedded category twelve. That difference is deliberate, not a rounding artifact, the two categories were treated differently on purpose. The Omnibus also adds prohibitions on AI practices involving non-consensual sexual or intimate content and child sexual abuse material, set to apply December 2, 2026. (consilium.europa.eu)

The Omnibus also creates a limited transition for one specific transparency obligation: providers of generative AI systems that were already on the market before August 2, 2026 have until December 2, 2026 to implement machine-readable marking of artificially generated content. That grace period applies only to those legacy systems. It does not extend to systems placed on the market after August 2, 2026, and it does not move any of the other Article 50 transparency obligations.

One further Omnibus change worth noting: the AI literacy obligation that began applying in February 2025 has been softened. Rather than a direct obligation on providers and deployers to ensure AI literacy, the Omnibus shifts the framework toward the Commission and Member States supporting and facilitating AI literacy efforts. Training your workforce on AI remains good governance, but the legal posture of that requirement has changed.

At the time of writing, the Omnibus had been approved by the Council, with publication in the Official Journal and entry into force still to be confirmed. That status should be checked again before publication or client use.

The key point is not that “the EU delayed the AI Act.” The better framing is that it split the compliance calendar. Some high-risk obligations moved; one narrow transparency transition was created for legacy systems; but August 2, 2026 still stands.

Who Does It Apply To?

The AI Act applies by role and by market impact.

A company may be in scope because it builds an AI product. It may be in scope because it uses a third-party AI system in European operations. It may be in scope because AI-generated outputs are used in the EU. Many companies will occupy more than one role at the same time.

Providers

A provider is the party that develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark.

If a company builds an AI-enabled product and offers it to customers in the EU, it may be a provider for that system. Depending on the type of system, that can bring obligations relating to documentation, risk management, instructions for use, post-market monitoring, conformity assessment, and other requirements.

The provider role matters because it generally carries the heaviest obligations.

It also matters because companies can move into provider status through their own conduct. If a company substantially modifies a third-party AI system or presents that system as its own, it may take on provider obligations even if it originally viewed itself as a user or customer.

Deployers

A deployer is the party using an AI system in a professional context.

Most companies will be deployers before they are providers. If an HR team uses an AI tool to screen candidates in Europe, the company may be a deployer. If customer support uses an AI assistant for EU users, the company may be a deployer. If marketing, legal, finance, or operations teams use AI systems in workflows touching Europe, those uses may need to be inventoried and classified.

Deployers generally have fewer obligations than providers, but fewer does not mean none. Deployers may still need to use systems consistently with provider instructions, satisfy applicable transparency obligations, maintain appropriate human oversight where required, and manage internal governance.

Importers and Distributors

Importers and distributors matter when AI systems move into the EU market through parties other than the original provider.

This is especially relevant for companies reselling, integrating, bundling, or distributing AI-enabled products into Europe. A company may think of itself as a reseller, implementation partner, or systems integrator, but the Act may assign it a more formal compliance role.

The Practical Reality

The clean labels are useful, but the operational map matters more.

A company might be a deployer of workplace AI tools, a provider of its own AI-enabled SaaS product, a distributor of a third-party AI integration, and a customer of a foundation model provider all at the same time.

That means the first serious compliance task is not writing an AI policy. It is figuring out what AI the organization actually uses, where it is used, who it affects, and which role the organization plays for each system.

The Four Risk Zones

The AI Act sorts AI systems by risk. That is the primary framework of the law.

Zone 1: Prohibited AI

Some AI practices are banned outright.

The prohibited category includes practices such as harmful AI-based manipulation, harmful exploitation of vulnerabilities, social scoring, certain biometric categorization practices, certain emotion recognition systems in workplaces and educational institutions, and certain uses of real-time remote biometric identification in publicly accessible spaces.

This is the highest-risk category because it is not a compliance checklist. It is a stop sign. If a system may fall into a prohibited category, the organization should stop, reassess, redesign, or obtain specific legal advice before continuing.

The Omnibus also adds new prohibitions involving AI-generated non-consensual sexual or intimate content and child sexual abuse material, set to apply December 2, 2026, the same date the legacy-system watermarking transition lands, subject to the Omnibus entering into force. (consilium.europa.eu)

Zone 2: High-Risk AI

High-risk systems are not banned, but they are heavily regulated.

This category includes systems used in areas where the consequences of error, bias, opacity, or misuse can be serious. Examples include employment, worker management, education, access to essential services, critical infrastructure, biometric identification, migration, border control, law enforcement, and administration of justice.

For these systems, the compliance burden can be substantial: risk management, data governance, documentation, logging, transparency to deployers, human oversight, accuracy, robustness, cybersecurity, conformity assessment, post-market monitoring, and registration.

This is where the Omnibus provides the most significant timing relief. Under the Council-approved Omnibus, stand-alone high-risk AI systems under Annex III move to December 2, 2027, and high-risk AI systems embedded in regulated products under Annex I move from August 2, 2027 to August 2, 2028. (consilium.europa.eu)

The mistake would be treating the delay as a pause. It is a runway.

A company that waits until late 2027 to inventory its AI systems, determine which are high-risk, collect documentation, review vendor contracts, and design oversight controls may find itself late before the deadline arrives.

Zone 3: Transparency AI

This is the zone that matters most for August 2.

Article 50 applies to transparency obligations for certain AI systems. It is broader than many organizations assume because it is not limited to high-risk AI. It applies to systems that interact directly with people, generate synthetic content, use emotion recognition or biometric categorization, or create deepfakes or AI-generated text published to inform the public on matters of public interest, for example, AI-written news or public-affairs content. It is worth keeping the Article 50 transparency regime conceptually separate from the high-risk compliance regime, they are different obligations on different timelines. (eur-lex.europa.eu)

Article 50 includes four basic transparency obligations.

First, providers of AI systems intended to interact directly with people generally must ensure users are informed that they are interacting with an AI system, unless that is obvious from context.

Second, providers of AI systems that generate synthetic audio, image, video, or text content must ensure the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated, subject to exceptions and transition rules.

Third, deployers of emotion recognition or biometric categorization systems must inform the natural persons exposed to those systems.

Fourth, deployers must disclose deepfakes and certain AI-generated or manipulated text published to inform the public on matters of public interest, subject to exceptions including human review or editorial control. Article 50 itself sets out these transparency obligations.

The Omnibus does not push the Article 50 transparency framework into 2027. It creates one narrow transition: providers of generative AI systems already on the market before August 2, 2026 have until December 2, 2026 to implement the machine-readable marking required by Article 50(2). Systems placed on the market on or after August 2, 2026 must comply from day one. All other Article 50 obligations, including every deployer-side obligation, apply from August 2, 2026. (consilium.europa.eu)

For businesses, the practical translation is simple: customer-facing AI, content-generating AI, biometric categorization, emotion recognition, deepfakes, and AI-generated public-interest text should all be reviewed before August 2.

Zone 4: Minimal-Risk AI

Most AI systems will not be high-risk. Spam filters, basic recommendation tools, AI-assisted search, and similar low-impact systems generally do not carry the Act’s heavier obligations.

But minimal risk does not mean invisible.

You still need the inventory. You cannot defend the conclusion that a system is low-risk if you never classified it in the first place.

The Foundation Model Layer

The AI Act treats general-purpose AI models separately because they sit upstream of many applications.

Foundation models and large language models can be used across sectors, integrated into downstream systems, and adapted for many different use cases. The law recognizes that a single upstream model can shape risk across many downstream products.

GPAI obligations began applying on August 2, 2025. Providers of GPAI models placed on the market after that date must comply. Providers of GPAI models already on the market before that date have until August 2, 2027 to comply. The Commission’s enforcement powers for GPAI obligations begin on August 2, 2026. The Commission has also identified the 10²⁵ FLOP threshold as a key threshold for presuming systemic risk. (ai-act-service-desk.ec.europa.eu)

For GPAI providers, the obligations include transparency and copyright-related requirements. The AI Office’s General-Purpose AI Code of Practice, published July 10, 2025, is the practical compliance pathway most major model providers have adopted, and adherence is treated as a mitigating factor in enforcement. For the most advanced models, the obligations become more demanding, including notification, systemic-risk assessment, risk mitigation, serious incident reporting, and safety and security measures.

For companies that build on top of foundation model providers, the direct GPAI obligations may sit upstream. But the business risk is still downstream.

If your product depends on a model provider, your contracts, diligence files, customer terms, and internal risk analysis should reflect that dependency. “We use a third-party model” is not the end of the compliance conversation. It is the beginning of the vendor-risk conversation.

What Are the Penalties?

The AI Act has real teeth.

Violations of prohibited practices can trigger fines of up to 35 million euros or seven percent of worldwide annual turnover, whichever is higher. Violations of many other obligations can trigger fines of up to 15 million euros or three percent of worldwide annual turnover. Providing incorrect, incomplete, or misleading information to notified bodies or national competent authorities can trigger fines of up to 7.5 million euros or one percent of worldwide annual turnover. Article 99 sets out these penalty tiers. (eur-lex.europa.eu)

The GDPR comparison is unavoidable. The AI Act’s top fine level is higher than the GDPR’s four percent maximum. The message is clear: the EU is treating AI governance as a core regulatory priority, not as a soft ethics framework.

One important nuance: do not assume GDPR and AI Act penalties either automatically stack or are automatically barred. Article 99 requires authorities to consider whether fines have already been applied by market surveillance authorities or other authorities for the same infringement or related conduct. But an AI system can still create obligations under both the AI Act and data protection law. If an AI incident involves personal data and AI transparency or risk-management failures, it should be assessed under both frameworks.

What Companies Should Do Now

Inventory First

This is the first move because every other move depends on it.

List every AI system the organization uses, sells, licenses, embeds, distributes, or relies on. Include internal tools, vendor tools, APIs, customer-facing systems, HR systems, marketing tools, analytics tools, product features, and foundation model dependencies.

For each system, identify what it does, where it is used, whether EU users or EU employees are affected, whether outputs are used in the EU, who provides the system, who deploys it, whether it has been modified, and whether it may fall into a prohibited, high-risk, transparency, GPAI, or minimal-risk category.

If that sounds basic, that is the point. Most companies cannot comply with an AI law until they know where the AI is.

Fix the August 2 Disclosures

Every customer-facing AI system that interacts directly with EU users should be reviewed for Article 50 disclosure. Chatbots, virtual assistants, automated support tools, and similar systems may need clear notice unless the AI interaction is obvious from context.

This should not wait for a broad AI governance program. It is a near-term product and UX task.

Prepare for Synthetic Content Labeling

If the organization provides systems that generate synthetic audio, image, video, or text, assess whether Article 50(2) applies and what technical marking or detectability measures are required.

Be precise about the dates here, because this is where organizations are most likely to misread the Omnibus. If your generative AI system is already on the market before August 2, 2026, you have until December 2, 2026 to implement machine-readable marking. If you place a new generative AI system on the market on or after August 2, 2026, the marking obligation applies immediately, there is no grace period. And deployer-side transparency obligations are not deferred at all. Machine-readable marking can require product, engineering, policy, and vendor coordination, so neither date should be treated as far away.

Review High-Risk Use Cases

The high-risk deadlines moved, but the classification work should start now.

Focus first on employment, HR, education, essential services, critical infrastructure, biometric systems, migration and border control, law enforcement, and administration of justice. If the company uses or provides AI systems in these areas, the compliance burden may be materially higher.

The question is not only whether a system is high-risk. The question is whether the company can explain how it reached that conclusion.

Update Contracts

Vendor agreements and customer terms need to catch up.

For deployers, provider contracts should address documentation access, use restrictions, system instructions, compliance representations, incident cooperation, audit rights, and allocation of responsibility.

For providers, customer terms should address permitted use, prohibited modifications, rebranding, integration into high-risk workflows, downstream disclosure obligations, cooperation duties, and responsibility for misuse.

Most existing AI contracts were not drafted for this law. That is the problem.

Build Governance That Actually Operates

The AI Act is not satisfied by a paper policy.

Someone needs to own AI intake. Someone needs to classify systems. Someone needs to approve high-impact uses. Someone needs to monitor vendors. Someone needs to maintain records. Someone needs to update disclosures when the product changes.

That means AI governance has to be cross-functional. Legal alone cannot do it. Product alone cannot do it. Engineering alone cannot do it. Procurement alone cannot do it. The operating model has to connect all of them.

One related note on training: the AI literacy obligation that began applying in February 2025 has been softened by the Omnibus, shifting from a direct obligation on providers and deployers toward a framework where the Commission and Member States support and facilitate AI literacy efforts. That changes the legal posture, not the business logic. An organization whose people cannot recognize a high-risk use case or a required disclosure will still fail at every other step of this list.

Do Not Waste the High-Risk Extension

The Omnibus gives companies more time for high-risk AI. That time is valuable only if it is used.

The right use of the runway is not to wait. It is to build the inventory, classify use cases, map vendor dependencies, collect documentation, identify product changes, and design oversight before the hard obligations arrive.

The companies that start now will treat December 2027 as a manageable implementation deadline. The companies that wait will treat it as another emergency.

The Takeaway

This was not a delay so much as a re-sequencing. High-risk obligations moved; one narrow marking transition was created for generative AI systems already on the market; but August 2, 2026 remains a real deadline for transparency, GPAI oversight, and general operational readiness. And for any generative AI system launched on or after that date, the content-marking obligation applies from day one, with no grace period.

For companies using AI in ways that touch the EU, the question is no longer whether the AI Act is coming. It is already here in pieces, and the next piece arrives on August 2, 2026.

The organizations that handle this well will not necessarily be the biggest companies or the companies with the most elaborate AI principles. They will be the companies that can answer basic operational questions clearly:

  • What AI do we use?
  • Where does it touch the EU?
  • Who is affected?
  • Are we the provider, deployer, importer/distributor, or some combination?
  • What risk category applies?
  • What disclosures are required?
  • What contracts govern it?
  • Who owns it internally?

For high-risk AI, the Omnibus bought time.

For transparency, governance, and operational readiness, the clock is still running.

This article is for general informational purposes only and reflects publicly available sources reviewed as of July 5, 2026. It is not legal advice and does not address any company’s specific facts. Organizations should consult qualified counsel regarding their particular AI systems, contracts, and compliance obligations under the EU AI Act, the Omnibus amendments once published in the Official Journal, and applicable national implementing measures. The Digital Omnibus was approved by the Council on June 29, 2026 and is awaiting publication in the Official Journal; it will enter into force on the third day after publication. The status should be verified.

Subscribe to Orthogonal

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe