update page now

New: EU CAPTCHA – GDPR-compliant bot protection. Try it free for 3 months!

Obligations, Risks, and Deadlines

The EU AI Act for Businesses

The EU AI Act, which has been in effect since August 2024, is the world’s first comprehensive legal framework for artificial intelligence. Originally, the obligations for high-risk AI systems were scheduled to take full effect on August 2, 2026. The so-called Digital Omnibus now postpones this deadline to December 2027. The corresponding amending regulation has been officially in force since July 27, 2026.

For businesses, this changes the timeline, but not the need to prepare. This article provides an overview of the current risk classes, obligations, and deadlines under the EU AI Act and outlines what businesses should specifically keep in mind right now.

Key Points at a Glance

  • The EU AI Act, also known as the AI Regulation, classifies AI systems into four risk categories across the EU: prohibited, high, limited, and minimal.

  • Prohibited practices and the AI competence requirement have been in effect since February 2025, while obligations for general-purpose AI have been in effect since August 2025.

  • The Digital Omnibus postpones the obligations for autonomous high-risk AI systems to December 2, 2027, and for product-integrated high-risk AI systems to August 2, 2028.

  • Transparency requirements for chatbots and AI-generated content remain in effect as of August 2, 2026.

  • Violations are subject to fines of up to 35 million euros or 7 percent of global annual revenue.

01

What is the EU AI Act?

The EU AI Act, also known in German as the AI Regulation or AI-VO, is Regulation (EU) 2024/1689 of the European Parliament and of the Council. It constitutes the first comprehensive legal framework for artificial intelligence and entered into force on August 1, 2024.

The regulation takes a risk-based approach: the greater the risk an AI system poses to fundamental rights, safety, or health, the stricter the obligations become. As an EU regulation, the AI Act is directly applicable in all member states. Unlike a directive, member states are not required to transpose it into national law. For supervision and enforcement, however, Germany still requires national authorities and rules on administrative fines, which are regulated in the AI Market Surveillance and Innovation Promotion Act (KI-MIG).

The EU AI Act clearly distinguishes itself from data protection under the GDPR (General Data Protection Regulation): While the GDPR governs the handling of personal data, the AI Act specifically focuses on the development, placing on the market, and use of AI systems. There is also a substantive distinction from regulatory frameworks such as the NIS 2 Directive, which addresses the cybersecurity of operators of critical infrastructure, although the two regulatory frameworks often overlap in practical implementation.

02

Who is subject to the EU AI Act?

The EU AI Act affects far more companies than the name might initially suggest. The regulation distinguishes four key roles along the AI value chain:

  • Providers develop an AI system or have it developed and place it on the market under their own name.

  • Operators use an AI system under their own responsibility—for example, a company that uses an AI tool for candidate selection.

  • Importers bring AI systems into the EU from third countries.

  • Distributors make AI systems available on the market without developing or importing them themselves.

For providers, the “place of marketing” principle applies: Anyone who places an AI system on the market or puts it into service in the EU falls under the regulation, regardless of where the company is headquartered. For operators, the location of their establishment in the EU is what counts. The AI Act even applies to companies with no EU connection of their own if someone in the EU uses the output of their AI system—such as an assessment or score generated abroad.

Companies in regulated and KRITIS-related sectors—such as finance, healthcare, public administration, or energy supply—are particularly affected. It is precisely in these sectors that organizations frequently use AI for high-stakes decisions, such as granting loans, making medical diagnoses, or managing critical processes. For these companies, the obligations under the AI Act carry greater weight because they apply in parallel with existing regulations such as NIS-2 or DORA (Digital Operational Resilience Act).

03

An Overview of the Risk Categories Under the EU AI Act

The EU AI Act classifies each AI system into one of four risk categories. This classification determines the specific obligations a company must fulfill:

Risk Class
Examples
Key Obligations

Prohibited Risks

Social scoring, manipulative AI, untargeted real-time biometric monitoring in public spaces

Prohibited since February 2025

High Risk

AI for hiring, credit checks, critical infrastructure, medical devices

Risk management, technical documentation, logging, human oversight, conformity assessment

Limited Risk

Chatbots, deepfakes, AI-generated content

Labeling and information requirements under Art. 50

Minimal risk

Spam filters, AI in video games, simple recommendation systems (e.g., “You might also like” features)

No specific obligations; voluntary codes of conduct recommended

Prohibited Risks

Social scoring, manipulative AI, untargeted real-time biometric monitoring in public spaces

High Risk

AI for hiring, credit checks, critical infrastructure, medical devices

Limited Risk

Chatbots, deepfakes, AI-generated content

Minimal risk

Spam filters, AI in video games, simple recommendation systems (e.g., “You might also like” features)

Since the Digital Omnibus, another new practice has been added to the list of prohibited uses: Effective December 2, 2026, the AI Act will also prohibit AI systems that are specifically used to create non-consensual intimate depictions or abusive images of minors.

In addition to these four classes, there is a separate category: general-purpose AI (GPAI) models, such as the large language models that power many chat applications. Their providers must, regardless of the specific application, provide technical documentation, publish a summary of the training data, and adhere to a copyright compliance policy. For models posing systemic risk—such as particularly powerful foundation models—risk assessments, security tests, and incident reporting are also mandatory.

04

What obligations do companies have under the EU AI Act?

The applicable obligations depend on the risk class and the role within the AI value chain. The following sections therefore organize the most important obligations primarily by provider and operator. These are the two roles in which most companies find themselves.

Providers of High-Risk AI Systems

Providers bear the most extensive obligations. These include, among other things:

  • a risk management system covering the entire lifecycle of the AI system (Art. 9)

  • data governance and control of training, validation, and test data (Art. 10)

  • technical documentation that makes the system’s structure and operation understandable (Art. 11)

  • automatic logging of all relevant events (Art. 12)

  • Transparency information and user instructions for operators (Art. 13)

  • The technical capability for human oversight (Art. 14)

  • An appropriate level of accuracy, robustness, and cybersecurity (Art. 15)

  • A conformity assessment and registration in the EU database prior to placing the system on the market

Operators of High-Risk AI Systems

Operators are subject to streamlined but equally binding obligations under Article 26: They must use the system in accordance with the instructions for use and entrust qualified individuals with human oversight.

This includes monitoring ongoing operations and informing affected individuals—as well as the works council, if applicable—before the system is deployed in the workplace. Companies that do not develop their own AI models but instead use, for example, an external AI tool for applicant screening or credit checks should pay particular attention to these operator obligations.

Importers and distributors are primarily subject to verification obligations: They must verify whether the supplier has fulfilled its obligations—such as providing the CE marking, a declaration of conformity, and instructions for use—before importing a system into the EU or making it available on the market (Articles 23, 24).

The Requirement for All Companies: AI Competence

Regardless of risk class, the AI competence requirement under Article 4 has been in effect since February 2025: Companies must ensure that their employees have sufficient knowledge to work with AI systems. The Digital Omnibus slightly softens the wording of this requirement: Instead of ensuring a specific level of competence, companies must actively promote AI competence in the future. The requirement itself remains unaffected.

05

Deadlines: The Digital Omnibus and the New Timeline

Hardly any other EU regulation has been so fundamentally revised so soon after its entry into force as the AI Act. On July 27, 2026—just a few days before the originally critical deadline—Amending Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, entered into force. It postpones key deadlines and provides relief to smaller companies in particular, without eliminating the fundamental obligations.

Here is the new timeline:

  • August 1, 2024: The EU AI Act enters into force.

  • February 2, 2025: Prohibited practices under Article 5 and the AI competence requirement under Article 4 become applicable.

  • August 2, 2025: Obligations for general-purpose AI models, as well as the requirements regarding governance, designated authorities, and fines, take effect.

  • August 2, 2026: The core obligations under Article 50 regarding transparency for chatbots and AI-generated content become applicable.

  • December 2, 2026: The requirement to label AI-generated content with a watermark applies to existing systems. As of the same date, the new prohibitions—supplemented by the Digital Omnibus—against non-consensual intimate AI depictions and AI-generated images of child abuse also take effect.

  • December 2, 2027: The obligations for standalone high-risk AI systems under Annex III take effect, 16 months later than originally planned.

  • August 2, 2028: The obligations for high-risk AI systems integrated as safety components into already regulated products (Annex I) become applicable.

For small and medium-sized enterprises, the Digital Omnibus provides an additional relief measure: They are permitted to reduce the technical documentation required for high-risk AI systems. The fundamental obligation to provide evidence remains unaffected.

Companies should make use of this additional time. Those who are already planning or deploying AI systems in the high-risk sector today will gain a clear advantage by preparing early, once the postponed obligations take effect.

06

Fines for Violations

The AI Act provides for a three-tiered system of fines, which the Digital Omnibus Act leaves unchanged. Violations are subject to the following penalties:

  • up to 35 million euros or 7 percent of global annual revenue for violations involving prohibited practices (Art. 5)

  • up to 15 million euros or 3 percent of global annual turnover for violations of other obligations, such as the operator obligations under Art. 26

  • up to 7.5 million euros or 1 percent of global annual turnover for providing false or misleading information to authorities

For each category, the higher of the two amounts applies. The Digital Omnibus merely adjusts the scope of the relief measures for small and medium-sized enterprises, for which the lower of the specified percentages or amounts applies in each case, and leaves the fine ranges themselves unchanged. At the same time, the European AI Office is granted its own supervisory and sanctioning powers. This will enable the authority to take more direct action to ensure that companies comply with the requirements.

Skyscrapers in a banking district
07

The EU AI Act in Germany: AI-MIG and the Federal Network Agency

Even though the AI Act, as an EU regulation, is directly applicable, Germany needs its own implementing law to define jurisdictions and establish procedures for imposing fines. The Bundestag passed this law—the AI Market Surveillance and Innovation Promotion Act (KI-MIG)—on June 11, 2026. The Bundesrat approved it on July 10, 2026, and the law entered into force on July 29, 2026.

Under the KI-MIG, Germany centralizes AI oversight at the Federal Network Agency (BNetzA). The agency serves as the central coordinating body, market surveillance authority, and notifying authority for AI in Germany and operates an AI Service Desk as the first point of contact for companies. For particularly sensitive use cases, such as law enforcement or migration, the Federal Network Agency has established an independent AI Market Surveillance Chamber (UKIM). Existing sector-specific supervisory authorities remain responsible in parallel: Those who have previously worked with BaFin (Federal Financial Supervisory Authority) or other sector-specific authorities will continue to work with that authority under the AI Act.

08

Summary: What Matters Now

Despite the Digital Omnibus, the EU AI Act remains a regulatory framework that no company in the EU that develops, deploys, or uses AI systems can ignore. Prohibited practices, the AI competence requirement, and the GPAI obligations are already in effect. Although the obligations for high-risk AI systems will not take effect until 2027 and 2028 due to the Digital Omnibus, companies should actively use this additional time. Clarify your own role as a provider or operator, classify AI systems into the appropriate risk categories, and establish governance structures that will withstand future audits.

Network connections

Frequently Asked Questions About the EU AI Act

The EU AI Act, also known as the AI Regulation, is the first comprehensive EU-wide regulation governing artificial intelligence. It classifies AI systems into four categories based on their risk level, ranging from prohibited to minimal. These categories are associated with obligations of varying stringency for companies.

About the author

Björn Greif

Senior Editor

About the author

Björn started his career as an editor at the IT news portal ZDNet in 2006. 10 years and exactly 12,693 articles later, he joined the German start-up Cliqz to campaign for more privacy and data protection on the web. It was then only a small step from data protection to IT security: Björn has been writing about the latest trends and developments in the world of cybersecurity at Myra since 2020.