The EU AI Act ( Regulation (EU) 2024/1689) is the world’s first legal framework for AI. It entered into force on August 1, 2024, and its timeline was revised to the first half of 2026 for high-risk systems. This guide provides an up-to-date overview of companies’ actual obligations, filtering out outdated information.
The Four Risk Levels Under the EU AI Act
The regulation classifies each AI system according to its risk level:
- Unacceptable risk (Prohibited as of February 2, 2025): Public social scoring, behavioral manipulation, real-time biometric recognition. The Digital Omnibus Act adds a ban on non-consensual intimate deepfakes effective December 2, 2026.
- High risk: Systems listed inAnnex III or integrated into regulated products (Annex I). This level involves the most onerous requirements, and its timeline has been modified by the Omnibus Act.
- Limited risk (Chatbots, generative AI): Subject primarily to a transparency requirement (informing the user that they are interacting with AI).
- Minimal risk (spam filters, video games): No specific requirements; voluntary codes of conduct are encouraged.
The 8 high-risk areas listed in Annex III
An AI system is classified as high-risk if it significantly influences decisions that affect people in any of the following areas:
- Biometrics: Remote identification, categorization, emotion recognition.
- Critical Infrastructure: Energy, Water, Gas, and Transportation Management.
- Education: Access to educational institutions, grading, and fraud detection.
- Employment and HR: Screening resumes, evaluating candidates, and making decisions regarding job assignments or terminations.
- Essential services: Credit scoring, insurance, social benefits.
- Law Enforcement: Law enforcement practices governed by national law.
- Migration, asylum, and border control.
- Justice and Democratic Processes: Support for Judicial Decision-Making, Electoral Influence.
The screening mechanism under Article 6(3) allows for the exclusion of certain systems if they do not pose a significant risk to fundamental rights, requiring a case-by-case analysis.
Obligations: Supplier and Deployer
The EU AI Act clearly distinguishes between the roles and their associated obligations:
If you are a supplier (designer of a high-risk system)
- Establish a continuous risk management system (Article 9).
- Ensure strict data governance and bias analysis (Article 10).
- Compile a complete set of technical documentation (Article 11).
- Ensure effective human oversight (Article 14) and automatic logging.
- Obtain CE marking and register in the EU database.
If you are a deployer (a company using the system)
The implementer (e.g., a purchaser of HR SaaS or scoring software) must follow the vendor’s instructions, ensure effective human oversight, monitor performance, and maintain logs (Article 26). A fundamental rights impact assessment is required for public bodies (Article 27).
Caution: Substantially modifying a system or adding your own branding to it transfers all supplier obligations to the deployer.
2025–2028 Timeline Revised by the Digital Omnibus
The Digital Omnibus (adopted on June 29, 2026) revised the deadlines for Annex III. Specifically, for a company:
- August 2, 2026 : The transparency requirements of Article 50 apply to new systems (informing users that they are interacting with AI, Identification of synthetic content generated by AI; informing users about the use of AI and the collection of data related to emotion recognition and biometric classification; labeling of deepfakes and AI-generated public interest content)
- December 2, 2026: Transparency requirements apply to systems already on the market. Requirement to digitally label AI-generated content.
- December 2, 2027 (rather than August 2, 2026): All requirements for high-risk autonomous systems listed in Annex III (recruitment, credit, education, justice, biometrics, critical infrastructure), including a documented risk management system, data governance, technical documentation, human oversight, and CE marking.
- August 2, 2028: High-risk systems incorporated into products that are already regulated (medical devices, machinery, toys) are still subject to a delayed timeline.
This 16-month extension allows companies to plan ahead for the finalization of the technical standards.
Sanctions and Measures
The system offines remains particularly effective as a deterrent:
- Up to 35 million euros or 7% of global revenue for violations of prohibited practices.
- Up to 15 million euros or 3% of global revenue for failure to comply with obligations (e.g., suppliers, importers, transparency, etc.)
- Up to 7.5 million euros or 1% of global revenue for failure to comply with transparency requirements.
The amount of the penalties depends on the severity, duration, and impact of the violation, as well as the size of the company and its level of cooperation.
For small and medium-sized enterprises (SMEs) and startups, penalties are capped at the lowest amount to ensure they remain proportionate to their economic capacity. The Digital Omnibus extends these protections and access to regulatory sandboxes (supervised testing environments) to companies with fewer than 750 employees.
Alignment with the GDPR, ISO 42001, and NIS2
The AI Act applies alongside the GDPR whenever personal data is processed (HR, scoring). The CNIL recommends combining the fundamental rights impact assessment with the Data Protection Impact Assessment (GDPR) to reduce the administrative burden. Furthermore, relying on the ISO 42001 standard (AI management) and the NIS2 Directive (cybersecurity) makes it possible to centralize audit evidence.
Checklist: The First 5 Steps to Take
- Map all AI systems, including Shadow AI.
- Describe the company’s role (supplier, implementer, or both).
- Classify each system according to the risk criteria in Annex III.
- Audit SaaS providers based on their documentation and contractual commitments.
- Update the transparency disclosures before the August 2026 deadline.
Frequently Asked Questions
Who is subject to the IA Act?
Any organization that provides, distributes, or deploys AI systems or models in the EU, including companies
What is the scope of the AI Act?
All AI systems, categorized by risk level: prohibited, high risk, limited risk, minimal risk.
What is the deadline for complying with the AI Act ?
Phased implementation: February 2, 2025; August 2, 2025; August 2, 2026, for full general applicability; and August 2, 2027, for certain high-risk AI-integrated products.

