The EU AI Act: What companies need to know
The EU AI Act in a nutshell
The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive regulatory framework for artificial intelligence.
It applies to all AI systems and general-purpose AI models (GPAI) placed on the EU market or used in the EU — including companies based outside the EU, if their AI ends up reaching the EU market.
The regulation is built around four risk categories.
The AI Act entered into force on 1.8.2024, but its obligations apply in phases until 2028.
The AI Omnibus package, which entered into force in July 2026, pushed back the timeline for high-risk systems.
What is the EU AI Act, and why was it created?
The purpose of the EU AI Act is to ensure that AI systems placed on the market and put into use in the EU do not endanger people's health, safety, or fundamental rights. It is not about banning AI, but rather about creating a common set of rules for developing and using AI. The goal is for AI to be developed and used fairly, transparently, and safely.
The AI Act assesses and regulates AI systems based on the risks they pose: the most harmful uses are banned, and requirements are placed on high-risk systems. AI systems that pose minimal or no risk fall outside the scope of the regulation.
The AI Act's risk classification
The AI Act divides AI systems into four tiers based on their potential risk:
Unacceptable risk
The AI Act bans AI systems considered to pose an unacceptable risk. This includes AI systems that threaten people's safety and rights, such as harmful manipulation or social scoring.
High risk
The AI Act places strict obligations and requirements on high-risk AI systems. High-risk use cases include AI systems that could cause serious safety or health risks or undermine fundamental rights, such as AI-based safety components in critical infrastructure and AI solutions used in educational institutions (such as AI-assisted exam grading).
Limited risk (transparency risk)
Limited risk, or transparency risk, refers to AI use cases where transparency is required. The AI Act requires disclosure of AI use where it matters for trust. Certain AI-generated content must also be clearly and visibly labelled, particularly deepfakes and text published to inform the public on matters of public interest. The AI Act's transparency rules entered into application in August 2026.
Minimal or no risk
The AI Act sets no rules for AI systems considered to pose minimal or no risk. Most AI systems currently in use in the EU fall into this category (e.g. spam filters).
When did the AI Act enter into force, and what did the AI Omnibus change?
The AI Act entered into force on 1.8.2024 and became applicable, with certain exceptions, on 2.8.2026. However, the Digital Omnibus package, which entered into force in July 2026, pushed back the deadlines for high-risk AI systems. At the same time, the AI Omnibus introduced a new prohibition: producing non-consensual sexual or intimate content using AI is banned.
Timeline for the AI Act
02/2025 — prohibited practices and AI literacy obligations took effect
08/2025 — governance structure and obligations for general-purpose AI models (GPAI) took effect
08/2026 — transparency rules took effect
2.12.2027 — obligations for high-risk systems in certain sensitive areas (e.g. recruitment, education, biometrics) take effect
2.8.2028 — obligations for high-risk AI systems embedded in products (e.g. lifts) take effect
Which companies does the AI Act apply to?
The AI Act introduces risk-based rules and obligations for companies in key AI-related roles, such as providers, distributors, importers, and deployers of AI systems. Obligations vary depending on the AI system's risk level. The AI Act applies whenever an AI system or general-purpose AI model is placed on the EU market or put into use in the EU, regardless of where the company is registered. It applies to both public and private organizations.
If you're building AI features into your product, it's worth identifying which role you play and which risk category your product falls into.
What does the AI Act require of companies?
The EU AI Act requires companies that provide or deploy AI systems, for example, to ensure their staff has sufficient AI literacy and to comply with the AI Act's transparency requirements. The obligations under the AI Act depend on the company's role (e.g. developer or deployer) and the risk category of the AI system.
If, for example, you act as a provider of an AI system — meaning your company develops or places an AI system or model on the market under its own name or trademark — and your product is classified as high-risk, requirements placed on you include, among others:
building a risk management and quality management system
ensuring data quality and technical documentation
CE marking and an EU declaration of conformity
traceability, human oversight, and ensuring cybersecurity and accuracy
For lower-risk products, such as chatbots, a clear notice to users that they are interacting with AI is usually sufficient.
How should a company prepare for the AI Act?
Map the AI features in your products and identify your role: are you a provider of an AI system, a deployer, or something else?
Identify the risk classification of your AI feature or product. You can read more about risk classification on the European Commission's website here.
Make sure you're compliant now. If your AI system is high-risk, prepare well in advance for the new requirements as they take effect.
Follow new guidance. If you're unsure, you can use the AI Act Single Information Platform or the FAQ page on the European Commission's website.
Unsure about your AI situation? We can help!
You don't have to face uncertainty and problems alone. External help, such as consulting, is worth using whenever your own situation raises questions — for example around data security or compliance. We can quickly get you the help you need, whether that's an AI-native full-stack developer or a cybersecurity expert who understands the importance of cybersecurity in AI systems. Send us a message and find the AI expert you need!

