The EU AI Act is easy to lose track of. Since 2024, businesses have faced several application dates, Commission guidelines, and a final AI Omnibus in 2026.
The good news?
The ordinary business use of AI is often less dramatic than the headlines suggest. Not every AI tool is high-risk, and a ChatGPT draft does not automatically trigger a mountain of paperwork.
In this guide, I explain the regulation from the ground up. You will learn which risk categories exist, which role your business has, which dates matter, and where to start.
- The EU AI Act does not regulate every AI use in the same way. Prohibited practices, high-risk systems, transparency cases, and low-risk applications follow different rules.
- Most small businesses should first rule out prohibited uses, organize suitable AI literacy measures, and check the Article 50 transparency duties.
- The 2026 AI Omnibus changed several dates. Article 50 applies from August 2, 2026, while the revised high-risk dates are December 2, 2027, and August 2, 2028.
What is the EU AI Act?
The EU AI Act is Regulation (EU) 2024/1689. It is directly applicable across EU member states, although national laws and authorities still handle parts of supervision and enforcement.
Its goal is not to ban artificial intelligence. The regulation aims to limit risks to health, safety, and fundamental rights while creating one legal framework for the European market.
That is why the Act takes a risk-based approach. The more an AI system can affect people and consequential decisions, the stricter its requirements become.
Who does the EU AI Act apply to?
The key question is not whether your business does something with AI. You first need to identify your role for each system.
Many freelancers, creators, agencies, and small companies are deployers. They use a finished service such as ChatGPT, Microsoft Copilot, or an AI feature built into existing software.
Roles can change. If you substantially modify a third-party system, change its intended purpose, or sell it under your own name, provider duties may move to your business.
The four risk levels in the EU AI Act
1. Prohibited AI practices
The EU considers certain practices incompatible with fundamental rights. The original prohibitions have applied since February 2, 2025. Two prohibitions added by the AI Omnibus apply from December 2, 2026.
Subject to the Act's precise conditions and exceptions, they include:
- manipulative or deceptive techniques that cause significant harm,
- harmful exploitation of a person's vulnerability,
- social scoring based on behavior or personal characteristics,
- certain crime predictions based only on profiling,
- untargeted scraping of facial images to build recognition databases,
- emotion recognition in workplaces and schools outside limited exceptions, and
- certain biometric categorization based on highly sensitive characteristics.
The details are narrow and technical. Still, screen risky ideas before a pilot begins. Testing a system does not create a legal free zone.
The AI Omnibus adds two further prohibitions to Article 5. From December 2, 2026, subject to their precise statutory conditions, they cover certain AI systems involving realistic non-consensual intimate material depicting identifiable people and child sexual abuse material.
2. High-risk AI
High-risk systems are not prohibited. Providers and deployers must meet much stricter requirements.
The category can cover AI used as a safety component in regulated products. Annex III also lists stand-alone uses in areas such as critical infrastructure, education, employment, essential services, law enforcement, migration, and justice.
Common business examples include:
- a system that filters applications or scores job candidates,
- AI that evaluates workers or assigns tasks based on personal behavior,
- a system that assesses the creditworthiness of natural persons, and
- certain exam, admission, or learning assessment systems.
Provider duties include risk management, data governance, technical documentation, logging, human oversight, accuracy, robustness, and cybersecurity. Deployers have their own duties, including use according to instructions, monitoring, and effective human oversight.
A product name alone does not tell you whether a system is high-risk. Intended purpose, context, and the function used are decisive.
3. Specific transparency risks
Some AI systems are neither prohibited nor high-risk, but can mislead people about their artificial nature. Article 50 addresses those cases.
The transparency rules mainly cover:
- direct interaction with chatbots, AI agents, and synthetic avatars,
- machine-readable marking of generative outputs by providers,
- emotion recognition and biometric categorization, and
- deepfakes and certain AI-generated text about matters of public interest.
There is no universal visible label for every AI-assisted item. My guide to AI content labeling under the EU AI Act explains the boundaries with practical examples.
For the technical layer, read my explanation of C2PA and Content Credentials. The separate Instagram AI label guide covers Meta's platform workflow.
4. Limited or minimal risk
Most everyday AI uses are not high-risk. Spelling assistance, internal ideation, summaries, and many image edits do not require a high-risk conformity assessment merely because AI is involved.
That does not mean anything goes. GDPR, copyright, trade secret protection, personality rights, employment law, and consumer protection still apply.
Rules for general-purpose AI models
The Act also regulates general-purpose AI models, often shortened to GPAI. These are powerful models that can perform many tasks and sit underneath numerous downstream systems.
Providers must supply technical information, maintain a policy for complying with EU copyright law, and publish a sufficiently detailed summary of training content. Models with systemic risk face additional evaluation, risk mitigation, incident reporting, and cybersecurity duties.
Using a finished chatbot does not make you the provider of its underlying model. If you integrate a model into your own product, however, you need to examine how responsibilities are divided.
AI literacy under Article 4
Article 4 has applied since February 2, 2025. Its revised wording was published on July 24, 2026, and takes effect on July 27. Providers and deployers must then take measures supporting the AI literacy of people who deal with AI systems on their behalf.
Existing knowledge, experience, education, the use context, and affected groups all matter. The amended wording does not require a business to guarantee one specific level of competence.
There is no mandatory seminar, certificate, or fixed number of training hours. Doing nothing is not a sensible answer either. My guide to AI literacy under Article 4 shows you how to choose and document proportionate measures.
Which EU AI Act deadlines matter in 2026?
The original Act was published on July 12, 2024, and entered into force on August 1, 2024. Its rules apply in stages.
The December 2026 transition only concerns the provider's technical marking duty for an existing generative system. It is not a general grace period for chatbot notices, deepfakes, or covered public-interest text.
What the final 2026 AI Omnibus changed
The final AI Omnibus was adopted on June 29, 2026, published on July 24, and takes effect on July 27. It adjusts implementation details without removing the Act's underlying risk model.
The main business changes include:
- new prohibitions concerning certain intimate and abuse material,
- fixed new application dates for the high-risk rules in 2027 and 2028,
- revised wording for measures supporting AI literacy,
- a limited technical marking transition for existing systems, and
- further simplifications concerning documentation, oversight, and support.
Older articles may therefore show outdated timelines. Check the original regulation together with its published amendments instead of relying on the original 2024 schedule.
How enforcement works across the EU
The regulation applies directly, but member states appoint national competent authorities and market surveillance authorities. Sector regulators can also remain involved when AI is used in finance, employment, healthcare, or regulated products.
The European AI Office has central responsibilities, particularly for general-purpose AI models. Businesses should not assume that one authority covers every issue. Privacy regulators, labor authorities, consumer bodies, and specialist regulators may all be relevant to the same system.
What are the maximum fines?
Article 99 sets different caps for different violations.
For undertakings, the higher cap generally applies. For small and medium-sized enterprises and small mid-cap enterprises, the lower cap applies. Authorities must still consider the nature, severity, duration, intent, cooperation, and consequences of a violation.
A practical EU AI Act check in 7 steps
- List every AI system your business uses professionally or supplies.
- Identify your role for each system.
- Record its purpose, users, data, affected people, and possible consequences.
- Rule out prohibited practices and screen for high-risk uses.
- Assign transparency duties for interactions and generated content.
- Set proportionate AI literacy, human review, and documentation measures.
- Review the classification after feature, purpose, or legal changes.
A clear AI policy template helps turn those decisions into workable rules for staff and contractors.
Do not start with a hundred-page file for every writing assistant. Start with a complete inventory, then deepen the review where AI genuinely affects people, sensitive data, or consequential decisions.






