Short answer: as of September 2026, EU AI Act compliance means four things are already live: the banned-practice rules (since February 2025), the rules for general-purpose AI models (since August 2025), and, from 2 August 2026, the Article 50 transparency duties for chatbots and AI-generated content plus the Commission's power to fine model providers. The big one that did not arrive in August 2026 is the high-risk regime. The Digital Omnibus on AI, published in the Official Journal in July 2026, moved it to 2 December 2027 for Annex III systems (hiring, credit scoring, education and similar) and 2 August 2028 for AI built into regulated products.
This guide is written for companies that build or deploy AI systems, including companies outside the EU with EU customers. It covers the risk tiers, the corrected timeline, what typical business automations fall under, and a checklist you can start on this week.
Does the EU AI Act apply to your company, even outside the EU?
Very likely, if EU users touch your AI. Article 2(1) of Regulation (EU) 2024/1689 applies the Act to providers placing AI systems on the EU market "irrespective of whether those providers are established or located within the Union or in a third country," and to providers and deployers in third countries "where the output produced by the AI system is used in the Union."
In practice that means a US or Pakistani SaaS company running a support bot for German customers is in scope, and so is a UK firm whose AI screens CVs for a role in Ireland. Two roles matter most:
- Provider: whoever develops an AI system (or has one developed) and puts it on the market or into service under its own name. If you ship an AI feature inside your product, you are usually its provider.
- Deployer: whoever uses an AI system under its authority in a professional context. A company that buys a hiring tool and uses it on applicants is a deployer.
You can be both. If you build a custom agent for your own operations, you are typically the provider and the deployer of that system. If an agency builds it for you, the contract should be clear about who is the provider, because that role carries most of the documentation duties.
The four risk tiers, in plain terms
The European Commission's AI Act overview describes a risk-based structure. Most business AI sits in the bottom two tiers.
| Tier | What it covers | What you must do |
|---|---|---|
| Unacceptable (banned) | Practices in Article 5, such as social scoring, harmful manipulation, untargeted scraping of facial images, and emotion recognition in workplaces and schools. The Omnibus adds AI-generated non-consensual intimate imagery and child sexual abuse material. | Don't build or use them. Fines here are the highest in the Act. |
| High-risk | Safety components of regulated products (Annex I) and the use cases in Annex III: biometrics, critical infrastructure, education, employment, access to essential services such as credit scoring, law enforcement, migration and justice. | Risk management, data governance, technical documentation, logging, human oversight, accuracy and cybersecurity, conformity assessment, registration. Now due 2 December 2027 (Annex III) or 2 August 2028 (Annex I). |
| Transparency risk | Chatbots and other AI that interacts with people, generative AI that produces synthetic content, deepfakes, emotion recognition and biometric categorisation. | Article 50 disclosure and marking duties. In force since 2 August 2026. |
| Minimal or no risk | The majority of AI systems, per the Commission, including spam filters and video games. | No specific AI Act obligations beyond the general AI literacy duty. Other laws, like GDPR, still apply. |
The EU AI Act timeline as of September 2026
The original Act set most obligations to apply on 2 August 2026. That changed. The Digital Omnibus on AI, Regulation (EU) 2026/1744, was signed on 8 July 2026, published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. Its recitals say the delayed availability of standards and the slow setup of national authorities made the original high-risk date unworkable. Here is the current schedule, taken from Article 113 as amended:
| Date | What applies | Status |
|---|---|---|
| 2 February 2025 | General provisions (including AI literacy) and the original Article 5 prohibitions | In force |
| 2 August 2025 | Obligations for providers of general-purpose AI (GPAI) models, governance, and most penalty rules | In force |
| 27 July 2026 | Articles 102 to 110 (amendments to sector laws), per the Omnibus | In force |
| 2 August 2026 | The rest of the Act by default, including Article 50 transparency and the Commission's power to fine GPAI model providers (Article 101) | In force |
| 2 December 2026 | New Omnibus prohibitions on non-consensual intimate imagery and CSAM; Article 50(2) marking deadline for generative systems already on the market before 2 August 2026 | Upcoming |
| 2 August 2027 | Deadline for GPAI models placed on the market before 2 August 2025; national AI regulatory sandboxes must be operational | Upcoming |
| 2 December 2027 | High-risk rules (Chapter III, Sections 1 to 3) for Annex III systems | Delayed from 2 August 2026 |
| 2 August 2028 | High-risk rules for AI in products covered by Annex I | Delayed from 2 August 2027 |
| 2 August 2030 | Deadline for high-risk systems used by public authorities | Unchanged |
Two notes on reading that table. First, the Commission's own AI Act page (last updated 3 August 2026) shows the same revised dates, so this is settled law, not a proposal. Second, a delay is not a repeal. As the law firm Cooley's summary puts it, Article 50 transparency, AI Office enforcement and governance obligations stayed on their original August 2026 schedule. The high-risk requirements themselves are unchanged in substance; you just have until late 2027 to meet them.
Article 50: chatbots, AI-generated content and deepfakes
For most businesses, Article 50 is the part of the EU AI Act that applies right now. It has four main duties, set out in the official text:
- 1Tell people they are talking to AI (providers, Art. 50(1)). A system that interacts directly with people must be designed so they are informed it is an AI, unless that is obvious to a reasonably well-informed person from the context. A support bot, a sales chat widget, or an AI voice agent answering calls all need this.
- 2Mark synthetic output (providers, Art. 50(2)). Providers of systems that generate synthetic audio, image, video or text must mark outputs in a machine-readable format so they are detectable as AI-generated. There is an exception for assistive editing that doesn't substantially alter the input. Systems already on the market before 2 August 2026 have until 2 December 2026.
- 3Inform people about emotion recognition or biometric categorisation (deployers, Art. 50(3)).
- 4Disclose deepfakes and AI-written public-interest text (deployers, Art. 50(4)). If you publish AI-generated or manipulated image, audio or video that looks real, you must disclose it. AI-generated text published to inform the public on matters of public interest must be disclosed too, unless it went through human review or editorial control and someone holds editorial responsibility.
The Commission published a final Code of Practice on marking and labelling AI-generated content on 10 June 2026, alongside guidelines on the scope of Article 50. Signing the code is voluntary, but the page says the Commission and the AI Board consider it an adequate tool for demonstrating compliance. If you ship a generative feature, read it before you pick a watermarking or metadata approach.
GPAI obligations: who they apply to (and who they don't)
General-purpose AI model obligations have applied since 2 August 2025. Under Article 53, GPAI model providers must keep technical documentation, give downstream developers the information they need to understand the model's capabilities and limits, maintain a copyright policy, and publish a summary of training content using the AI Office's template. Models with systemic risk carry extra duties around evaluation, risk mitigation, incident reporting and cybersecurity. The Commission's voluntary GPAI Code of Practice gives a practical route to meeting these.
If your business calls a model through an API and builds an agent or workflow on top, you are generally not the GPAI model provider. The model vendor is. Your obligations attach to the AI system you build: its risk tier, its Article 50 duties and its use case. What you should do is collect the documentation your model vendor publishes, because you will need it if your system ever lands in the high-risk tier.
Penalties: what non-compliance can cost
Fines are set by Article 99, and member states enforce them for AI systems. The ceilings are whichever is higher of a fixed amount or a share of total worldwide annual turnover:
| Violation | Maximum fine |
|---|---|
| Prohibited practices (Article 5) | EUR 35 million or 7% of worldwide annual turnover |
| Most operator obligations, including provider and deployer duties and Article 50 transparency | EUR 15 million or 3% |
| Supplying incorrect, incomplete or misleading information to authorities | EUR 7.5 million or 1% |
| GPAI model providers (Article 101, fined by the Commission from 2 August 2026) | EUR 15 million or 3% |
For SMEs and start-ups, Article 99(6) flips the rule: the fine is capped at whichever of the two amounts is lower. That is meaningful relief, but a 3% of turnover exposure for a missing chatbot disclosure is still not a risk worth carrying when the fix is a single line of UI copy.
Where typical business automations land
Here is how the automations we see most often usually map. The classification always depends on the actual use, so treat this as a starting point for your own assessment.
| Automation | Likely tier | What that means in practice |
|---|---|---|
| Customer support bot or voice agent | Transparency risk | Disclose that the customer is talking to AI (Art. 50(1)). Keep an easy route to a human. See our AI customer support automation approach. |
| Invoice, receipt and contract extraction | Usually minimal risk | No specific AI Act duties for back-office extraction. Accuracy still matters for your own books, so keep human review for low-confidence fields. Related: intelligent document processing. |
| B2B lead scoring and inquiry replies | Usually minimal risk, plus Art. 50(1) if it chats | Scoring companies for sales priority is not an Annex III use case. Credit scoring of individuals is. If the agent emails or chats with prospects as AI, disclosure rules can apply. Related: AI lead qualification. |
| CV screening, candidate ranking, performance monitoring | High-risk (Annex III, point 4) | Full high-risk regime from 2 December 2027. Emotion recognition at work is already banned. Start documentation and human oversight design now. |
| Creditworthiness assessment of individuals | High-risk (Annex III, point 5(b)) | Fraud detection is excluded, but credit scoring is in. Same 2 December 2027 date. |
| Marketing images, video or voice generated with AI | Transparency risk | Deepfake-style content must be disclosed by the deployer (Art. 50(4)). Your tool provider handles machine-readable marking. |
One nuance that trips people up: Article 6(3) lets an Annex III system escape the high-risk tier if it only performs a narrow procedural task, improves a previously completed human activity, detects patterns without replacing human assessment, or does preparatory work. But any Annex III system that performs profiling of natural persons is always high-risk, and a provider relying on the exception must document the assessment before launch and still register the system. A CV parser that only extracts fields into your ATS is a very different system from one that ranks candidates.
Other Digital Omnibus changes worth knowing
- AI literacy was softened. The amended Article 4 now requires providers and deployers to "take measures to support the development of AI literacy" of staff, and states it does not require them to guarantee any specific level of literacy for any individual. You still need a reasonable training effort, just not a certification program.
- New prohibitions on AI systems that generate non-consensual intimate imagery or child sexual abuse material apply from 2 December 2026.
- SME relief expanded. The Omnibus adds a definition of small mid-cap enterprises and extends simplified quality management compliance to all SMEs, including start-ups.
- The AI Office gained supervisory powers over AI systems built on a GPAI model by the same provider, according to Cooley's summary of the final text.
EU AI Act compliance checklist for 2026
If you run AI systems today, this is the order we would work in:
- 1Inventory every AI system. Include vendor tools, internal agents, and AI features inside your product. Note who built it, which model it calls, and whether EU users or EU data subjects are affected.
- 2Assign your role per system: provider, deployer, or both. Put it in writing, including in agency and vendor contracts.
- 3Classify each system by tier. Check it against Article 5 and Annex III. Where you rely on the Article 6(3) exception, document the reasoning now.
- 4Fix Article 50 gaps first, because they are already enforceable. Add AI disclosure to chat widgets, voice agents and AI-sent emails. Label AI-generated media you publish.
- 5If you provide generative features, plan machine-readable marking of outputs before 2 December 2026, using the Commission's code of practice as your reference.
- 6Gather model vendor documentation for each GPAI model you rely on.
- 7For anything in Annex III, start the high-risk work now: risk management, data governance, logging, human oversight design and technical documentation. December 2027 is closer than it looks when conformity work runs through procurement and legal review.
- 8Keep an AI literacy record: short, role-specific training for the people who operate or oversee each system.
- 9Log and monitor. Automatic logs, approval records and performance tracking are high-risk requirements, and they are good engineering anyway. Our guide to AI agent evaluation and observability covers how.
- 10Review quarterly. Guidelines, standards and codes of practice are still arriving.
How Flowrest Labs approaches EU AI Act compliance in the systems we build
We are an engineering team, not a law firm, so we don't sign off on your legal position. What we do is build systems that make compliance easier to demonstrate. Every custom AI agent we deliver has human approval gates before consequential actions, activity audit logging, and plain documentation of what the system does and which model it calls. Customer-facing agents are designed to say they are AI. And because you own 100% of the code, prompts and documentation, you can hand them straight to your counsel or an auditor without asking a vendor for permission.
If you're not sure which tier your current automations fall into, our AI consulting and workflow audits start with exactly that inventory. You can also read how we think about preventing AI hallucinations in production, which overlaps heavily with the accuracy and oversight expectations in the Act.
Want a second pair of eyes on your AI inventory? Book a free 30-minute workflow audit.
Frequently Asked Questions
Was the EU AI Act delayed in 2026?
+
Partly. The Digital Omnibus on AI (Regulation (EU) 2026/1744), in force since 27 July 2026, moved the high-risk rules to 2 December 2027 for Annex III systems and 2 August 2028 for AI in regulated products. Transparency duties under Article 50, the prohibitions and the GPAI model rules were not delayed.
What applies from 2 August 2026 under the EU AI Act?
+
Article 50 transparency obligations (disclosing chatbots, marking synthetic content, labelling deepfakes), the Commission's power to fine GPAI model providers, and the remaining general provisions of the Act. Generative systems already on the market before that date have until 2 December 2026 to add machine-readable marking.
Does the EU AI Act apply to US and other non-EU companies?
+
Yes, if you place AI systems on the EU market or the output of your AI system is used in the EU. Article 2 applies regardless of where the provider is established.
Is a customer service chatbot high-risk under the EU AI Act?
+
Usually not. A typical support chatbot falls under the transparency tier: you must tell users they are interacting with AI unless it is obvious. It could become high-risk if it made decisions in an Annex III area, such as assessing creditworthiness.
Is AI resume screening high-risk under the EU AI Act?
+
Yes. AI used to filter applications or evaluate candidates is listed in Annex III, point 4. The high-risk requirements for these systems apply from 2 December 2027.
What are the fines for violating the EU AI Act?
+
Up to EUR 35 million or 7% of worldwide turnover for prohibited practices, up to EUR 15 million or 3% for most other obligations including transparency, and up to EUR 7.5 million or 1% for misleading information. SMEs are capped at the lower of the two amounts.
Sources & Further Reading
- 01Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex, Official Journal of the European Union, 2024-07-12
- 02Regulation (EU) 2026/1744 (Digital Omnibus on AI) — EUR-Lex, Official Journal of the European Union, 2026-07-24
- 03Consolidated text of Regulation (EU) 2024/1689 as of 27 July 2026 — EUR-Lex, 2026-07-27
- 04AI Act: Regulatory framework on AI — European Commission, Shaping Europe's digital future, 2026-08-03
- 05Code of Practice on Transparency of AI-generated Content — European Commission, Shaping Europe's digital future, 2026-07-31
- 06Digital AI Omnibus Delays Key Deadlines, Introduces New Rules — Cooley, 2026-08-03
- 07EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes — Gibson Dunn, 2026-05-27
