EU AI Act compliance: what a company that uses AI must actually do
By the E-Solutions Web editorial team. Published , updated . How we write
The short answer
Most companies are deployers under the EU AI Act: they use AI systems built by others. Since February 2025, they must build AI literacy and avoid prohibited practices. Since August 2026, they must be transparent about deepfakes and certain AI-generated texts. Duties for high-risk uses, such as hiring or credit scoring, apply from December 2, 2027, after the 2026 digital omnibus moved the date.
This guide is not legal advice. It summarizes the official texts as we read them on September 30, 2026, for a company that uses or deploys AI. Your situation depends on your use cases, your sector and your contracts; a lawyer or your data protection officer should confirm any decision. Where the rules are still moving, we say so.
Under the EU AI Act, your role comes first: provider or deployer
Your obligations under the EU AI Act depend first on your role, and most companies that buy or subscribe to AI tools are deployers. The regulation defines a deployer as any person or organization “using an AI system under its authority,” except for personal, non-professional use. The provider is the one who develops the system, or has it developed, and places it on the market under its own name.
The line can move. Article 25 turns a deployer into a provider of a high-risk system in three situations: when it puts its own name or trademark on a high-risk system, when it makes a substantial modification to one, or when it changes the intended purpose of a system so that it becomes high-risk. A company that takes a general chatbot and turns it into a tool that screens job applications has, in the regulation’s eyes, built a new high-risk system.
The scope is also wide geographically. Article 2 covers providers placing systems on the EU market “irrespective of whether those providers are established or located within the Union or in a third country,” deployers located in the EU, and providers and deployers elsewhere “where the output produced by the AI system is used in the Union.”
The four risk levels, and where your uses fall
The regulation sorts AI uses into four levels, and obligations grow with the risk to people’s health, safety and fundamental rights. The European Commission notes that “the vast majority of AI systems currently used in the EU” fall into the lowest level, which carries no specific rules.
| Level | What it covers | What it means for a deployer | Applies from |
|---|---|---|---|
| Prohibited | Practices listed in Article 5: harmful manipulation, social scoring, emotion recognition at work or in education (outside medical or safety reasons), untargeted scraping of facial images, and others | Do not use them | February 2, 2025; new bans on non-consensual intimate content from December 2, 2026 |
| High risk | Uses listed in Annex III, such as recruitment and candidate evaluation, decisions on promotion or termination, creditworthiness assessment, life and health insurance pricing; and AI in products covered by EU safety law (Annex I) | The duties of Article 26, and in some cases a fundamental rights impact assessment | December 2, 2027 (Annex III); August 2, 2028 (Annex I) |
| Transparency | Chatbots and other systems that interact with people, generated or manipulated content, emotion recognition and biometric categorization | Disclose deepfakes and certain AI-generated texts; inform people exposed to emotion recognition | August 2, 2026 |
| Minimal | Everything else | No specific obligation under the AI Act; AI literacy still applies | Not applicable |
Being listed in Annex III is not always final. Article 6(3) excludes a system that does not pose a significant risk of harm, for instance because it performs a narrow procedural task or a preparatory task, but never one that profiles people. The Commission published draft guidelines on classification with practical examples on May 19, 2026; at the time of writing they are still a draft.
The calendar in force on September 30, 2026
The regulation entered into force on August 1, 2024 and applies in stages; the digital omnibus on AI, in force since July 27, 2026, postponed the high-risk rules. The omnibus is Regulation (EU) 2026/1744 of July 8, 2026, published in the Official Journal on July 24, 2026. The Commission had proposed it on November 19, 2025, and the Council and Parliament negotiators reached a provisional agreement on May 7, 2026.
| Date | What applies |
|---|---|
| February 2, 2025 | Prohibited practices and AI literacy obligations |
| August 2, 2025 | Rules for general-purpose AI models, governance, penalties |
| August 2, 2026 | General application, including the Article 50 transparency duties |
| December 2, 2026 | New bans on AI generating non-consensual intimate content or child sexual abuse material; deadline for generative systems already on the market before August 2, 2026 to mark their outputs |
| December 2, 2027 | High-risk systems listed in Annex III (employment, credit, education, essential services and others) |
| August 2, 2028 | High-risk AI embedded in products covered by EU safety legislation (Annex I) |
| August 2, 2030 | Public authorities’ high-risk systems already in service before the application date |
One nuance matters for systems already in place. Under Article 111 as amended, a high-risk system placed on the market or put into service before the date its rules apply is covered only if its design changes significantly afterward. Public authorities are the exception: they must bring such systems into line by August 2, 2030.
What a deployer of a high-risk system must do
For a high-risk use, the deployer’s job is to use the system as instructed, keep a competent person in control, watch it, keep its logs and inform the people concerned. Article 26 lists the duties. In plain terms:
- Follow the instructions for use and take the technical and organizational measures to do so.
- Assign human oversight to people who have the competence, training and authority to exercise it.
- Check the input data you control is relevant and sufficiently representative for the purpose.
- Monitor the system, and if it presents a risk, inform the provider and the market surveillance authority and suspend its use; report serious incidents.
- Keep the logs the system generates, where they are under your control, for at least six months unless other law says otherwise.
- Inform workers and their representatives before using a high-risk system at the workplace.
- Inform the people about whom the system makes or helps make decisions.
Some deployers must also carry out a fundamental rights impact assessment before first use (Article 27): bodies governed by public law, private entities providing public services, and any deployer using AI to assess creditworthiness or to price life and health insurance. The omnibus lets them reuse the relevant parts of their GDPR data protection impact assessment rather than start from zero; our guide to GDPR and AI explains when that assessment is required.
If you are building such a system with a supplier, these duties should be in the specification from the start: logging, an interface for human review, the ability to suspend. They are much cheaper to design in than to add later, which is how we approach AI agents that act in business processes.
Transparency: chatbots, deepfakes and AI-written texts
Since August 2, 2026, people must know when they are talking to an AI and when certain content was generated by one. The obligations of Article 50 are split between providers and deployers.
Providers must design systems that interact directly with people so that those people “are informed that they are interacting with an AI system,” unless that is obvious to a reasonably well-informed person. Providers of generative systems must also mark outputs in a machine-readable format; for systems already on the market before August 2, 2026, the omnibus sets that deadline at December 2, 2026.
Deployers have three duties. Those who use AI to create deepfakes must disclose that the content was artificially generated or manipulated, with a lighter regime for evidently artistic, satirical or fictional works. Those who publish AI-generated or manipulated text “with the purpose of informing the public on matters of public interest” must disclose it, unless the text has undergone human review or editorial control and someone holds editorial responsibility. Those who use emotion recognition or biometric categorization must inform the people exposed.
The Commission published a voluntary Code of Practice on marking and labelling AI-generated content on June 10, 2026, with one section for providers and one for deployers. For a customer-facing AI chatbot, the practical rule is simple: say it is an AI at the start of the conversation, and offer a way to reach a person. Our knowledge assistant demo shows another good habit, useful well beyond compliance: every answer cites the passage it comes from.
AI literacy: the duty that already applies to everyone
Every provider and deployer, whatever the risk level, has had to work on AI literacy since February 2, 2025. Article 4 was rewritten by the omnibus. It now requires providers and deployers to “take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf,” taking into account their knowledge, experience and the context of use. It adds that this “does not require providers or deployers to guarantee any specific level of AI literacy of any individual,” and asks the Commission and member states to support companies, SMEs in particular.
In practice, a proportionate response is documented and specific: who uses which AI tools, for what, what they have been taught about limits and errors, and how that is refreshed when tools change. Generic awareness sessions rarely answer those questions. Training built around the tools your teams actually use, such as our AI training for teams, does.
What is still moving, and what the penalties are
Several pieces of the framework are still being written, so a compliance plan made today should be reviewed at each new publication. On September 30, 2026, we read the following on official sources:
- Classification guidelines for high-risk systems exist only as a draft, published on May 19, 2026.
- Harmonized standards are not yet published. The Commission’s standardization page, updated on August 3, 2026, reports that the first one, on quality management systems, entered public enquiry on October 30, 2025.
- A second digital omnibus, covering the GDPR, the Data Act and other data rules (procedure 2025/0360(COD), proposed on November 19, 2025), was still at committee stage in the European Parliament, with a draft report published on June 22, 2026. It remains a proposal.
- National enforcement depends on each member state designating its market surveillance authorities; check your country’s authority for local guidance.
Penalties are set in Article 99. Breaching the bans can cost up to 35 million euros or 7% of total worldwide annual turnover, whichever is higher. Breaching deployer duties or transparency obligations can cost up to 15 million euros or 3%. For SMEs and start-ups, each fine is capped at whichever of the two amounts is lower, and the omnibus extends a similar rule to small mid-caps for the 15 million and 7.5 million tiers.
Your first compliance step, and who can help
The first useful move is an inventory: every AI system in use, its provider, its purpose and the people it affects, each placed in the risk table above. Our free AI readiness check, ten questions in about two minutes, shows where your company stands before you list anything. The inventory then becomes the base of your AI governance: who approves a new tool, who watches it, who answers when it fails.
If some of those systems process sensitive data, the AI Act is only half of the question. Where the model runs, and under which law, is covered in our guide to sovereign AI; when the answer is to keep the data at home, a private LLM can run in Europe or on your own servers.
You do not have to sort this out alone. In a free 30-minute assessment, we go through your AI uses with you, point out the ones the AI Act is likely to touch and the first thing to do about them. An AI readiness assessment can then map every system, usually in two to three weeks, with the scope and price fixed in writing before we start. Book your free 30-minute assessment: we reply within one business day.
Frequently asked questions
Who has to comply with the EU AI Act?
Every organization that develops, sells or uses AI systems in a professional capacity in the EU, with different duties by role. Providers, who build or put their name on a system, carry most obligations. Deployers, who use a system under their authority, have lighter but real duties. Importers, distributors and product manufacturers are covered too. Purely personal use is excluded.
Does the EU AI Act apply to companies outside the EU, such as in the United States?
Yes, in two cases set out in Article 2. It applies to providers that place AI systems on the EU market, wherever they are established. It also applies to providers and deployers located outside the EU when the output produced by their AI system is used in the EU. A US company selling or running AI for European users is therefore in scope.
Is the EU AI Act being enforced?
Yes, in stages. The bans have applied since February 2, 2025, and the penalty rules since August 2, 2025. Each member state designates market surveillance authorities to enforce the regulation, while the Commission’s AI Office supervises general-purpose AI models. Fines for prohibited practices can reach 35 million euros or 7% of worldwide annual turnover, whichever is higher.
What is banned under the EU AI Act?
Article 5 bans, among others, manipulative techniques that distort behavior and cause significant harm, exploiting people’s vulnerabilities, social scoring, predicting crimes from profiling alone, untargeted scraping of facial images, and emotion recognition at work or in schools except for medical or safety reasons. From December 2, 2026, systems generating non-consensual intimate images of real people are banned too.
Where can I read the full text of the EU AI Act?
The official text is Regulation (EU) 2024/1689 on EUR-Lex, the EU’s law portal, in every official language. The amendments of the digital omnibus on AI are in Regulation (EU) 2026/1744, also on EUR-Lex. The Commission’s AI Act Service Desk offers a browsable version, a compliance checker and a form to ask questions.
What does Article 50 of the EU AI Act require?
It sets transparency duties that apply since August 2, 2026. Providers must tell people they are interacting with an AI system unless it is obvious, and mark synthetic content in a machine-readable way. Deployers must disclose deepfakes, disclose AI-generated text published to inform the public unless a person has editorially reviewed it, and inform people exposed to emotion recognition.
Sources
- Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), EUR-Lex, Official Journal of the European Union, published 2024-07-12, accessed 2026-09-30.
- Regulation (EU) 2026/1744 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI), EUR-Lex, Official Journal of the European Union, published 2026-07-24, accessed 2026-09-30.
- AI Act, European Commission, Shaping Europe’s digital future, updated 2026-08-03, accessed 2026-09-30.
- Transparency obligations under Article 50 of the AI Act, European Commission, updated 2026-07-24, accessed 2026-09-30.
- Commission publishes Code of Practice on marking and labelling AI-generated content, European Commission, published 2026-06-10, accessed 2026-09-30.
- Draft Commission guidelines on the classification of high-risk AI systems, European Commission, published 2026-05-19, accessed 2026-09-30.
- Standardisation of the AI Act, European Commission, updated 2026-08-03, accessed 2026-09-30.
- Simplification of the digital legislative framework, Digital Omnibus (Omnibus VII), procedure 2025/0360(COD), European Parliament, Legislative Observatory, accessed 2026-09-30.
- Artificial intelligence: Council and Parliament agree to simplify and streamline rules, Council of the European Union, press release, published 2026-05-07, accessed 2026-10-01.
- Simplification of the implementation of harmonised rules on artificial intelligence, Digital Omnibus on AI (Omnibus VII), procedure 2025/0359(COD), European Parliament, Legislative Observatory, accessed 2026-10-01.
- AI Act Service Desk, European Commission, accessed 2026-09-30.