The EU AI Act ( Regulation (EU) 2024/1689) is the world’s first legal framework for AI. It took effect on August 1, 2024, and its timeline was revised to the first half of 2026 for high-risk systems. This guide provides an overview of the actual obligations facing companies and is part of our broader overview of AI security in the enterprise, intended for CISOs and CIOs.
What are the four risk levels under the EU AI Act?
The regulation classifies each AI system according to its risk level:
- Unacceptable risk (Prohibited as of February 2, 2025): Public social scoring, behavioral manipulation, real-time biometric recognition. The Digital Omnibus Act adds a ban on non-consensual intimate deepfakes effective December 2, 2026.
- High risk: Systems listed inAnnex III or integrated into regulated products (Annex I). This level involves the most onerous requirements, and its timeline has been modified by the Omnibus Act.
- Limited risk (Chatbots, generative AI): Subject primarily to a transparency requirement (informing the user that they are interacting with AI).
- Minimal risk (spam filters, video games): No specific requirements; voluntary codes of conduct are encouraged.
Appendix III: What are the 8 areas considered high-risk?
An AI system is classified as high-risk if it significantly influences decisions that affect people in any of the following areas:
- Biometrics: Remote identification, categorization, emotion recognition.
- Critical Infrastructure: Energy, Water, Gas, and Transportation Management.
- Education: Access to educational institutions, grading, and fraud detection.
- Employment and HR: Screening resumes, evaluating candidates, and making decisions regarding job assignments or terminations.
- Essential services: Credit scoring, insurance, social benefits.
- Law Enforcement: Law enforcement practices governed by national law.
- Migration, asylum, and border control.
- Justice and Democratic Processes: Support for Judicial Decision-Making, Electoral Influence.
The screening mechanism under Article 6(3) allows for the exclusion of certain systems if they do not pose a significant risk to fundamental rights, requiring a case-by-case analysis.
AI Provider or Deployer: What Are Your Legal Obligations?
The EU AI Act clearly distinguishes between the roles and their associated obligations:
If you are a supplier (designer of a high-risk system)
- Establish a continuous risk management system (Article 9).
- Ensure strict data governance and bias analysis (Article 10).
- Compile a complete set of technical documentation (Article 11).
- Ensure effective human oversight (Article 14) and automatic logging.
- Obtain CE marking and register in the EU database.
If you are a deployer (a company using the system)
The implementer (e.g., a purchaser of HR SaaS or scoring software) must follow the vendor’s instructions, ensure effective human oversight, monitor performance, and maintain logs (Article 26). A fundamental rights impact assessment is required for public bodies (Article 27).
Caution: Substantially modifying a system or adding your own branding to it transfers all supplier obligations to the deployer.
What is the timeline for implementing the EU AI Act?
The Digital Omnibus (adopted on June 29, 2026) revised the deadlines for Annex III. Specifically, for a company:
- August 2, 2026 : The transparency requirements of Article 50 apply to new systems (informing users that they are interacting with AI, Identification of synthetic content generated by AI; informing users about the use of AI and the collection of data related to emotion recognition and biometric classification; labeling of deepfakes and AI-generated public interest content)
- December 2, 2026: Transparency requirements apply to systems already on the market. Requirement to digitally label AI-generated content.
- December 2, 2027 (rather than August 2, 2026): All requirements for high-risk autonomous systems listed in Annex III (recruitment, credit, education, justice, biometrics, critical infrastructure), including a documented risk management system, data governance, technical documentation, human oversight, and CE marking.
- August 2, 2028: High-risk systems incorporated into products that are already regulated (medical devices, machinery, toys) are still subject to a delayed timeline.
This 16-month extension allows companies to plan ahead for the finalization of the technical standards.
Penalties and Fines: What Are the Consequences for Companies in the Event of Noncompliance?
The system offines remains particularly effective as a deterrent:
- Up to 35 million euros or 7% of global revenue for violations of prohibited practices.
- Up to 15 million euros or 3% of global revenue for failure to comply with obligations (e.g., suppliers, importers, transparency, etc.)
- Up to 7.5 million euros or 1% of global revenue for failure to comply with transparency requirements.
The amount of the penalties depends on the severity, duration, and impact of the violation, as well as the size of the company and its level of cooperation.
For small and medium-sized enterprises (SMEs) and startups, penalties are capped at the lowest amount to ensure they remain proportionate to their economic capacity. The Digital Omnibus extends these protections and access to regulatory sandboxes (supervised testing environments) to companies with fewer than 750 employees.
Regulatory Synergies: How Can the AI Act Be Aligned with the GDPR, ISO 42001, and NIS2?
The AI Act applies alongside the GDPR whenever personal data is processed (HR, scoring). The CNIL recommends combining the fundamental rights impact assessment with the Data Protection Impact Assessment (GDPR) to reduce the administrative burden. Furthermore, relying on the ISO 42001 standard (AI management) and the NIS2 Directive (cybersecurity) makes it possible to centralizeaudit evidenceand avoid duplication of governanceprocesses .
Checklist: 5 Priority Actions to Take Right Now
- Map all AI systems, including Shadow AI.
- Describe the company’s role (supplier, implementer, or both).
- Classify each system according to the risk criteria in Annex III.
- Audit SaaS providers based on their documentation and contractual commitments.
- Update the transparency disclosures before the August 2026 deadline.
FAQ on European Regulations Governing Artificial Intelligence
What is the EU AI Act?
TheEU AI Act (the European Regulation on Artificial Intelligence) is the EU’s first comprehensive legal framework governing the placing on the market, deployment, and use of AI systems based on their level of risk, with the aim of protecting fundamental rights, health, and safety, while promoting innovation.
Who is subject to the IA Act?
Any organization that provides, distributes, or deploys AI systems or models within the European Union. This applies to private companies, public bodies, subcontractors, and SaaS providers, whether they are based in the EU or abroad, as long as the system affects European users.
What is the scope of the AI Act?
• Prohibited: Practices posing an unacceptable risk (e.g., social scoring, real-time biometrics).
• High risk: Sensitive uses (HR, healthcare, infrastructure, justice) subject to strict governance and transparency requirements.
• Limited risk: Generative models and chatbots subject to information disclosure requirements.
• Minimal risk: Common uses without specific regulatory restrictions.
Who is responsible for enforcing the regulations?
-
National authorities: Each Member State designates market surveillance authorities and other competent authorities to monitor the compliance of AI systems within its territory.
-
European Commission / AI Office: specifically oversees general-purpose AI (GPAI) models, coordinates their implementation at the European level, and may impose sanctions in this area.
-
European Artificial Intelligence Board: brings together representatives from the member states to ensure consistent implementation of the regulation.
Prepare your AI systems for compliance before regulatory deadlines.
Our experts help you map your usage patterns, assess your risk levels, and secure your deployments.
Would you like to discuss your project or assess your needs? Contact our experts.

