In short
The AI Act (Regulation (EU) 2024/1689) sorts uses of AI by risk. A few practices are banned. Uses that affect people's lives, such as hiring or credit, are high-risk and carry real duties. Systems that talk to people or make realistic content must be transparent about it. Everything else carries almost nothing specific.
For a typical company of 10 to 250 people the work is: know which AI tools you use, sort each one, meet the few duties that apply, and be able to show it.
Does it apply to you?
Yes, if your company uses AI in the EU, or its AI output is used in the EU. The Act names two main roles:
- Deployer: you use an AI system under your own authority, for your work. Almost every company is a deployer of something.
- Provider: you develop an AI system, or have one developed, and place it on the market under your name. If you put your name on someone else's high-risk system, or change it substantially, you can become its provider (Article 25).
Personal, non-professional use is outside the Act. UK companies are covered when they place AI on the EU market or their AI output is used in the EU.
The four tiers
Banned practices, such as social scoring, reading the emotions of staff, or manipulating people in harmful ways.
Uses listed in Annex III, such as hiring, managing workers, credit scoring of people, insurance pricing, education and biometrics.
Systems that talk to people, and realistic AI images, audio or video (deepfakes). People must be told.
Everything else: writing help, coding help, transcription, spam filters. No specific duties beyond AI literacy.
The tier belongs to the use, not the product. ChatGPT used to draft emails is minimal. The same model used to rank job applicants is high-risk.
Key dates
| Date | What applies | Status |
|---|---|---|
| 2 February 2025 | Bans and literacy. Prohibited practices banned. AI literacy duty (softened by the Omnibus). | In force |
| 2 August 2025 | Model makers. Rules for providers of general purpose AI models. | In force |
| 2 August 2026 | Tell people it is AI. Article 50: people told they are dealing with AI; deepfakes and some text labelled. | In force |
| 2 December 2026 | Mark AI content. Grace period ends for machine-readable marking of AI content. New ban on AI nudification. | 65 days |
| 2 December 2027 | High-risk duties. Annex III systems: hiring, workers, credit, insurance, education, biometrics. | 430 days |
| 2 August 2028 | AI in products. High-risk AI inside regulated products (Annex I). | 674 days |
What deployers must do
For every AI tool
Help the people who use it understand what it does and where it goes wrong (AI literacy, Article 4). An approved AI use policy that staff sign is the practical way to show this.
Transparency uses (from 2 August 2026)
- People must be told when they interact with an AI system, unless it is obvious (Article 50(1)). The design duty sits with the provider, so check your chatbot vendor does it, or show a line yourself.
- Realistic AI images, audio or video of people, places or events must be disclosed as AI generated when you publish them (Article 50(4)).
- AI text published to inform the public on matters of public interest must be disclosed, unless a person reviews it and takes editorial responsibility (Article 50(4)).
High-risk uses (from 2 December 2027)
- Use the system as the provider's instructions describe (Article 26(1)).
- Assign human oversight to a trained person with the authority to overrule it (Article 26(2)).
- Where you control the input data, make sure it is relevant and representative (Article 26(4)).
- Monitor it, and report serious incidents to the provider and the authority (Article 26(5)).
- Keep the logs it generates for at least six months (Article 26(6)).
- Tell workers and their representatives before using it at work (Article 26(7)).
- Tell people that a high-risk system helps make decisions about them (Article 26(11)), and be ready to explain individual decisions (Article 86).
- For credit and insurance uses, carry out a fundamental rights impact assessment before first use (Article 27).
A GDPR data protection impact assessment is often needed for the same tools. That is a separate duty under GDPR Article 35.
The 2026 Digital Omnibus
On 29 June 2026 the Council gave final approval to the Digital Omnibus, which changed the AI Act's timetable:
- High-risk duties for stand-alone systems (Annex III) moved from 2 August 2026 to 2 December 2027.
- High-risk duties for AI inside regulated products (Annex I) moved to 2 August 2028.
- The transparency rules in Article 50 still applied from 2 August 2026. Machine-readable marking of AI content has a grace period to 2 December 2026 for systems already on the market.
- A new ban covers AI that generates non-consensual intimate images or child sexual abuse material.
- The AI literacy duty was softened. Check the final text in the Official Journal for the exact wording.
Penalties
Using a banned practice can cost up to €35 million or 7% of worldwide annual turnover. Breaching most other duties, including deployer duties, up to €15 million or 3%. For small and medium companies the lower of the two amounts applies (Article 99). In practice, the first pressure most companies feel is commercial: customers and tender panels asking how they govern AI.
A checklist for a company of 10 to 250 people
- List every AI tool in use, including free accounts and AI features inside other software.
- Sort each use into its tier and note whether you are deployer or provider.
- Check nothing in use is a banned practice.
- Make sure your chatbot tells people it is AI, and label realistic AI content you publish.
- Approve an AI use policy and ask staff to sign it.
- For each high-risk use, get the provider's instructions, name an overseer, keep logs and tell staff.
- Keep a dated record of all of it, so you can answer a customer or a regulator in minutes.
Check one tool now, free Or keep the whole list in The Monitor