The EU AI Act Is Now Enforced. Here Is What It Actually Requires.
Scaling Business

The EU AI Act Is Now Enforced. Here Is What It Actually Requires.

Rosie Nguyen

Rosie Nguyen

31 July 2026

The EU AI Act requires organizations developing or deploying AI systems covered by the Act to classify each system by risk level and comply with obligations tied to that classification. Where high-risk AI is involved, this means quality management systems, full technical documentation, log retention, conformity assessments, and human oversight built into the system before market placement. Prohibited practices have been enforceable since February 2025, General Purpose AI (GPAI) obligations went live in August 2025, and Article 50 transparency obligations apply as of August 2026. Penalties reach €35 million or 7% of global annual turnover, higher than GDPR's 4% ceiling. The question is no longer whether the Act applies to your company. It is whether your current AI deployments are compliant.

EU AI Act Compliance Timeline

The EU AI Act entered into force on 1 August 2024. Its obligations are phased across key enforcement milestones:

  • 2 February 2025 - Prohibited Practices & AI Literacy: Prohibited AI practices became illegal and enforceable. Providers and deployers became responsible for ensuring an appropriate level of AI literacy among personnel and other persons dealing with AI systems on their behalf.
  • 2 August 2025 - General Purpose AI (GPAI): Model governance obligations for General Purpose AI providers went live. Penalty provisions became applicable to the obligations then in force.
  • 2 August 2026 - Transparency & Market Supervision: Transparency duties under Article 50 take effect. Users must be informed when interacting with AI (e.g., chatbots), and AI-generated or manipulated content must be labelled or disclosed where required. National competent authorities begin exercising full enforcement powers for active provisions.
  • 2 December 2027 - Annex III Standalone High-Risk AI: High-risk AI systems under Annex III (HR and recruitment tools, education, credit scoring, critical infrastructure, biometrics, law enforcement, migration, justice) become subject to full compliance obligations. This deadline was extended from August 2026 following the EU's 2026 Omnibus simplification package.
  • 2 August 2028 - Annex I Product-Embedded High-Risk AI: High-risk AI systems embedded as safety components in regulated physical products, including machinery, medical devices, and vehicles, become subject to full compliance requirements (deferred from August 2027 under the 2026 Omnibus amendments).

The Omnibus timeline extensions apply to high-risk deadlines (Annex III and Annex I) to align with technical standards, but prohibited practices, GPAI rules, Article 50 transparency duties, and the penalty regime remain on their active schedules.

The Four Risk Tiers and What They Mean in Practice

Unacceptable risk (Banned since 2 February 2025)

These practices are prohibited outright. For a mid-market company, key prohibitions include:

  • Emotion recognition systems in workplaces and educational institutions.
  • AI that exploits vulnerabilities based on age, disability, or specific socio-economic situations to distort behavior.
  • Real-time remote biometric identification in publicly accessible spaces (with narrow law enforcement exceptions).
  • Untargeted scraping of facial images from the internet or CCTV to build recognition databases.

If your employee monitoring, HR analytics, or customer engagement tools include any of these capabilities, they are not compliant under EU law.

High-risk (Phased in through 2027-2028)

For most mid-market companies, the high-risk category is where compliance effort concentrates. Relevant examples include:

  • AI operating as a safety component in machinery, vehicles, or medical devices (Annex I - in force 2 August 2028).
  • AI-powered CV screening, candidate ranking, or employee performance monitoring (Annex III - in force 2 December 2027).
  • AI used for credit assessment and certain insurance risk assessments (Annex III - in force 2 December 2027).
  • AI used in the operation of critical infrastructure, including safety-critical predictive maintenance. (Annex III - in force 2 December 2027).

Limited risk (In force 2 August 2026)

Chatbots and AI systems that generate synthetic content fall here. The core obligation is Article 50 transparency: users must be informed they are interacting with AI, and AI-generated or manipulated content must be labelled or disclosed where required under Article 50. No formal conformity assessment is required.

Minimal risk

Spam filters, video games, and standard AI-assisted document search tools. These carry no mandatory legal obligations under the Act, though voluntary codes of conduct are encouraged.

What High-Risk AI Compliance Actually Requires

If you deploy or develop a high-risk AI system, the Act specifies mandatory statutory requirements before the system reaches the market or goes into operational use:

  • Quality Management System (Article 17) - Documented policies covering data governance, system design, change management, post-market monitoring, and incident reporting.
  • Technical Documentation (Article 11) - Full documentation of the system's purpose, training data, architecture, performance metrics, and known limitations (governed by Article 11 and retained for 10 years after being placed on the market per Article 18).
  • Log Retention (Articles 12 & 26) - Technical logging capabilities must be enabled by providers (Article 12). Deployers must, where logs are under their control and technically feasible, retain automatically generated logs for an appropriate period, at least six months, unless other EU or national law applies (Article 26).
  • Conformity Assessment (Article 43) - Completed before the system is placed on the market or put into service. Depending on the system type, this is either self-assessment or third-party assessment.
  • EU Declaration of Conformity & CE Marking (Articles 47 & 48) - A formal declaration and CE mark indicating the system meets the Act's requirements before market placement.
  • Registration in the EU AI Database (Article 49) - Mandatory registration of the system in the official EU database before being placed on the market or put into service.
  • Human Oversight (Article 14) - Providers must design effective oversight mechanisms into the system design, enabling operators to understand system limitations, prevent automation bias, and intervene or stop the system.

Deployers, companies that use high-risk AI built by a third party, also carry obligations. These include conducting Fundamental Rights Impact Assessments (FRIAs under Article 27) for public authorities and essential service providers, implementing appropriate human oversight measures, and retaining logs.

Using ChatGPT, Claude, or Gemini in Your Product. What That Means Under the Act.

The General Purpose AI (GPAI) obligations that came into force in August 2025 apply primarily to GPAI model providers, OpenAI, Anthropic, Google, not to companies using their APIs for standard business operations.

If your company uses a third-party AI model via API to power internal workflows or customer features, you are a deployer. Your compliance exposure is limited to ensuring the use case does not fall into a prohibited or high-risk category and complying with Article 50 transparency requirements.

The line changes if you build and deploy a product that substantially modifies a GPAI model, or if you place it on the EU market under your own brand or trademark. In that case, your company assumes provider status under the Act and takes on the corresponding obligations, including technical documentation, transparency, and, where the system reaches the high-risk threshold, full conformity assessment.

Extraterritorial Scope

Article 2 of the Act is explicit: it applies to any company placing AI systems on the EU market, or whose AI outputs affect users located in the EU, regardless of where the company is headquartered or where its engineering team resides.

A company headquartered in the US, UK, or Asia with development teams in Vietnam, India, or the Philippines is subject to the full obligations of an EU company if its product serves users in the European Union. What determines applicability is where the AI system is placed or used, not where it is built.

Penalties

Enforcement powers are split between national market surveillance authorities and the European AI Office:

  • Prohibited practices: Up to €35 million or 7% of global annual turnover (whichever is higher).
  • High-risk AI non-compliance: Up to €15 million or 3% of global annual turnover.
  • Providing incorrect information to authorities: Up to €7.5 million or 1.5% of global annual turnover.

At 7%, the AI Act's maximum fine ceiling exceeds GDPR's 4% cap. Non-EU companies face the exact same penalty scale.

Frequently Asked Questions

What does the EU AI Act require companies to do in 2026?

In 2026, organizations should inventory and assess AI systems they develop or deploy. Companies must ensure compliance with Article 50 transparency obligations (informing users when interacting with chatbots and disclosing AI-generated media), ensure an appropriate level of AI literacy., and map high-risk tools against the 2027 and 2028 compliance deadlines.

Does the EU AI Act apply to companies outside the EU?

Yes. Article 2 applies to any provider or deployer whose AI system is placed on the EU market or whose outputs affect individuals in the EU, regardless of corporate location. A non-EU company selling an AI-powered product to European customers is subject to the same obligations as an EU entity.

What AI practices are now banned under the EU AI Act?

As of February 2025, banned practices include real-time remote biometric identification in public spaces, social scoring, AI that manipulates behavior through subliminal techniques or exploitation of vulnerabilities, emotion recognition in workplaces and schools, and untargeted scraping of facial images to build recognition databases.

What happens if a company uses ChatGPT or Claude in its product?

If accessed via API for general operations or features, primary GPAI model obligations rest with the provider (e.g., OpenAI, Anthropic). If the company substantially modifies the model or markets the solution under its own brand in the EU, it becomes a provider under the Act and assumes documentation, transparency, and high-risk conformity obligations.

When does the EU AI Act apply to HR and recruitment AI?

HR, recruitment, CV screening, candidate ranking, and employee performance monitoring tools are classified as high-risk under Annex III. Following the AI Act implementation amendments adopted in 2026, the enforcement deadline for Annex III standalone high-risk systems is 2 December 2027.

What is the difference between a provider and a deployer under the EU AI Act?

A provider develops an AI system (or has one developed) and places it on the market under its own brand name. A deployer uses a third-party AI system under its authority for operational purposes. Providers carry primary structural obligations (quality management, technical documentation, conformity assessments, CE marking). Deployers carry operational duties (implementing human oversight measures, log retention for at least six months where feasible, and user transparency disclosures).

Take the Next Step

Gradion supports companies across DACH and Southeast Asia in assessing AI compliance exposure, auditing risk classifications, and building AI systems that meet production-grade standards. Contact our team to start the conversation.

Rosie Nguyen

About the author

Rosie Nguyen

Rosie Nguyen works at the intersection of Marketing, Communications, and meaningful Storytelling at Gradion. She covers leadership and scaling, writing for the founders and operators building across Asia.

Is Your AI Deployment Compliant?

We help companies classify AI risk exposure and close compliance gaps before enforcement catches up.