The Direct Answer
European companies should treat the EU AI Act as an operating requirement now, not as a future policy project. As of 24 September 2026, the prohibition rules and AI-literacy duty have applied since 2 February 2025, most governance rules for general-purpose AI have applied since 2 August 2025, and the main body of the Act, including many transparency obligations, applies from 2 August 2026. A company that places an AI system on the EU market, puts it into service, or uses it within the Union may therefore have duties even if its model was developed outside Europe. The right response is to inventory relevant systems, assign roles, test contractual controls, document decisions, and correct deficiencies before an authority, customer, insurer, or litigant discovers them. This is not an argument for buying expensive software or retaining outside counsel for every deployment; it is a case for matching controls to actual legal exposure. A chatbot used only for internal drafting may need less evidence than a biometric system used in employment, but both require a defensible classification record.
Also worth reading: How Should Companies Build an Agentic AI Risk Assessment Framework in 2026? · What are the best enterprise agentic AI governance frameworks in 2026, and how should companies actually implement them? · What is a startup legal broker and how does it differ from traditional law firms for early-stage companies?
The Act applies to providers, deployers, importers, distributors, product manufacturers, and certain authorised representatives. A provider develops an AI system or general-purpose AI model and places it on the market or into service under its own name. A deployer uses such a system under its own authority, but an employee who uses approved workplace tools does not automatically become the provider. This distinction matters because the duties are unevenly distributed. A deployer may have a smaller set of direct obligations while still needing supplier information, monitoring, human oversight, incident escalation, and reliable logs. Companies should begin by producing an accurate role-and-system register rather than by assuming that service from a cloud vendor transfers every legal duty to that vendor.
How the Risk Classification Works
The EU AI Act combines product-safety rules with a list of sensitive use cases. Under Article 6, an AI system is generally high-risk when it is a safety component of a product, or itself a product, covered by listed EU product legislation and must undergo third-party conformity assessment. The second route covers uses in areas such as recruitment, worker management, access to essential private and public services, education, credit or insurance pricing, law enforcement, migration, justice, and democratic processes. There is no universal turnover or user-count threshold that makes a system high-risk. Classification depends on the intended purpose, the applicable sector rules, and what the system actually does. A lower-cost model can be high-risk, while a sophisticated model used for ordinary calendar management may not be.
Article 6(3) permits certain systems listed in Annex III to be treated as lower risk when they present only a narrow risk of harm and do not materially influence decisions. That exclusion is conditional, not automatic. The provider must document why the system is excluded, while the Commission and national authorities retain supervisory powers. A company cannot obtain this treatment merely by marketing a recruitment tool as an assistant rather than a decision tool. If it scores, filters, ranks, or recommends people in ways that influence access to work, the intended function remains the primary fact to examine. Regulators also consider profiling, contextual use, and foreseeable misuse when assessing whether an exclusion should be revoked.
Prohibited practices appear in Article 5, while Article 50 creates transparency duties for matters including human interaction, synthetic content, and deepfakes. Some of these rules overlap without making every affected system high-risk. A customer-facing bot may need an interaction disclosure without satisfying the full high-risk regime. Likewise, synthetic-audio and synthetic-video obligations differ from the disclosure required for an entirely fictional text, and editorial or human-review situations can affect the rule. A useful classification memo should explain both the applicable category and the evidence supporting it. It should also record the intended purpose, users, affected people, decision effects, data categories, geographical reach, and planned changes.
Dates That Matter in September 2026
The staged dates create several overlapping compliance programmes. The Act entered into force on 1 August 2024. Prohibitions and the duty concerning AI literacy began on 2 February 2025, as did the requirement for Member States to prepare penalties. Most general-purpose AI obligations began on 2 August 2025, although legacy models receive more time. The main application date was 2 August 2026, which is relevant to many transparency requirements and the broader governance structure. Certain high-risk systems tied to regulated products have a later deadline of 2 August 2027. National implementation measures and standardisation remain separate from these dates and should not be confused with the date on which a company becomes legally subject to a particular rule.
For general-purpose AI, the transitional treatment requires special attention. A model placed on the market after 2 August 2025 generally falls under the applicable provider duties sooner than a qualifying model that was already available before that date. Providers of older models may have until 2 August 2027, subject to the precise transitional provision. The Commission can designate models with systemic risk using specified criteria, including a presumed compute threshold of 10^25 floating-point operations. That presumption concerns a threshold for further analysis, not a finding that every model above or below it has the same legal consequences. Model providers should also examine downstream provider responsibilities, copyright-policy duties, and the publication of sufficiently detailed summaries of training content.
Reports in 2026 discussed possible changes to some implementation arrangements, but organisations should distinguish enacted law from proposals and commentary. The Regulation (EU) 2024/1689 and any officially published amending act must be checked against the consolidated text. A proposed delay, guidance document, code of practice, or negotiating position does not by itself replace the legal deadline. Management should record which source it relied on, its publication date, and whether the statement reflected binding law. Given the date of this answer, a short legal status check is sensible before a board document states that a deadline has moved. The safer operational approach is to continue readiness work while confirming any amendment through official EU publications.
A Practical Compliance Programme
Start with an inventory covering internal tools, acquired tools, embedded AI, model APIs, and tools developed by subsidiaries or contractors. Record the business owner, supplier, purpose, user group, affected persons, countries of use, hosting arrangements, and whether the tool influences safety, employment, credit, education, public services, or justice. This inventory does not need to contain trade secrets or personal data. It needs enough information to assign legal roles and identify missing documentation. Procurement should then require suppliers to provide instructions for use, intended-purpose statements, technical documentation, conformity information where applicable, and incident-notification routes. A clause saying the vendor is responsible for compliance is not a substitute for reviewing what the vendor actually supplies.
Next, prioritise systems by legal category, deadline, severity of possible harm, and the difficulty of remediation. Companies should not begin by polishing a public-facing chatbot notice while a recruitment model remains unidentified, uncontrolled, and capable of affecting employment decisions. For high-risk systems, the work commonly includes a risk-management process, data governance, technical documentation, automatic logging, human oversight, accuracy and robustness controls, cybersecurity, quality management, conformity assessment, registration, post-market monitoring, and serious-incident reporting. Deployers should follow instructions for use, ensure competent human oversight, monitor operation, retain relevant logs, and inform providers and authorities when a serious incident or breach occurs. The Act generally requires deployers to keep logs for at least six months where that duty applies, but another legal rule or operational need may justify a different period.
Providers should also examine data quality and whether special-category information is used lawfully. The AI Act does not create a general right to process personal data, so GDPR or other data-protection duties continue alongside it. Bias testing should be tied to the system’s purpose rather than represented by a single accuracy percentage. Accuracy must be assessed across relevant groups and operating conditions, with human review tested under realistic workloads. Documentation should identify who can stop the system, who investigates alerts, how model changes are approved, and how customers are told that behaviour has changed. A named committee is less valuable than assigned duties, escalation times, and evidence that control owners can act.
Transparency, General-Purpose AI, and Technical Evidence
Article 50 duties now need attention because their principal application date has passed. An AI system intended to interact directly with a person generally must inform that person that they are interacting with AI, unless the situation makes this obvious from the circumstances and context. Providers of systems generating synthetic audio, image, video, or text must support detection through appropriate machine-readable markings where technically feasible, subject to the specific rule. Deployers publishing deepfakes must disclose their artificial nature, while certain text published to inform the public on matters of public interest carries a related disclosure obligation. These provisions contain distinctions for artistic, satirical, editorial, and human-review contexts. Legal review is often more useful than assuming that one footer or watermark satisfies every case.
General-purpose AI is a different subject from any one downstream application. A model provider may need information about its capabilities and limitations, a copyright policy, a sufficiently detailed public summary of training content, and measures designed to respect European Union copyright law. If the model has systemic risk, additional evaluation, adversarial testing, incident reporting, cybersecurity, and energy-efficiency work may apply. Commission codes of practice and standards can help organisations interpret good practice, but their status must be checked carefully. Under Article 34, an AI system is presumed to meet a requirement covered by a harmonised standard where relevant standards are cited or referenced in the Official Journal. A technical tool can generate evidence, but it cannot decide whether a legal classification is correct or replace accountable human judgement.
Evidence should be proportionate. For a low-risk summarisation tool, a concise record of provider, purpose, data handling, user disclosure, and periodic review may be sufficient. For a high-risk credit or employment system, the evidence should be much deeper and should permit an independent assessor to understand data selection, performance, human intervention, and residual risks. Companies should test whether an external reviewer could reconstruct important decisions six months later. Screenshots, expired dashboards, undocumented model versions, and training material without revision history are weak evidence. An audit trail connected to actual system releases and operational incidents is stronger. The objective is not maximal paperwork; it is a defensible link between the system that was assessed and the system that customers actually use.
Comparing Compliance Support Options
| Feature | Internal compliance programme | Specialist legal and technical assessment | AI legal services broker | Software compliance platform |
|---|---|---|---|---|
| Best role | Day-to-day governance and evidence ownership | One-off classification, legal analysis, and technical testing | Independent scoping and comparison of providers | Continuous inventory, policy, and monitoring workflows |
| Typical depth | Strong inside knowledge, but risks of confirmation bias | Deep work on priority systems and contested questions | Broad market view across legal, security, and assurance providers | Faster screening and repeatable documentation |
| Indicative planning cost | Approximately €50,000–€250,000+ for a multi-system programme | Roughly €15,000–€100,000+ per priority initiative | Often no fixed fee; project pricing may be €5,000–€25,000+ | Approximately €5,000–€50,000+ annually, depending on users and modules |
| Main limitation | May lack independent challenge or specialist capacity | Can be expensive if scope is not controlled | Requires careful provider diligence and a defined outcome | Does not determine legal classification or replace professional judgement |
| Suitable first use | Maintaining the register, training, approvals, and controls | High-risk systems, Article 50 questions, or regulator response | Selecting a firm, testing market prices, or separating workstreams | Building an inventory and tracking evidence across vendors |
A comparison should examine relevant regulated-sector experience, methodology, deliverables, independence, subcontracting, data handling, and liability allocation. Ask whether the quotation includes a written system classification, a documented gap analysis, remediation priorities, or merely training sessions and a general policy template. Clarify who performs testing, what standards or internal benchmarks are used, and whether the adviser can support a notified authority or notified body without assuming that every assessor has authority. A low quotation may become expensive if it excludes data-governance review, supply-chain work, conformity assessment, or post-release monitoring. The best offer is usually the one that resolves defined risks and produces usable evidence, not the one with the largest list of service names.
Common Mistakes and Warning Signs
A frequent error is treating the AI Act as a GDPR add-on. The two regimes have different purposes, definitions, actors, and procedures, although both can affect the same system. Data-protection impact assessments, transfer mechanisms, and lawful-basis analysis remain necessary, but a DPIA does not establish whether a use is prohibited or high-risk. Another error is relying exclusively on vendor marketing. Terms such as responsible AI, human in the loop, or EU hosted do not establish conformity with the Act. Hosting data in the EU also does not remove a global model provider from the relevant extraterritorial rules. Contracts, technical documentation, and actual system behaviour must support the compliance claim.
Companies also confuse risk labels with legal categories. A system described as moderate risk by a consultant may still be prohibited or high-risk under the legislation. Conversely, not every use appearing on a secondary list is automatically an Annex III high-risk use once the Article 6(3) conditions are examined. The answer should be documented, but the classification should remain revisable. A system can change through model replacement, prompt updates, new data sources, expanded user groups, or acquisition. The regulatory history and product roadmap should therefore include periodic recertification rather than a single decision made in 2025.
The final common mistake is waiting for perfect certainty. The Act does not offer a general grace period for companies that have not finished an inventory. Nor does buying a policy, attending a webinar, or registering a trademark demonstrate compliance. Regulators, customers, employees, and affected individuals may approach problems through different routes, and the reputational cost of a poor response can exceed the cost of early assessment. Documentation should be honest about uncertainty and preserve the reasoning behind decisions. A company that records an unresolved question, assigns an owner, and sets a review date is usually better placed than one that makes an unsupported assurance.
Timing, Penalties, and the Decision to Seek Help
Immediate action is appropriate where a prohibited practice may be operating, people are affected by an unclassified high-risk decision, or a general-purpose model is being placed on the market without the required organisational work. The first priority is containment: stop or limit the affected use, preserve evidence, and obtain advice on notification and remediation. Next come systems already interacting with the public, general-purpose AI services being integrated, and models that influence employment, credit, insurance, education, or essential services. A board that needs a defensible answer should receive a short register, a ranked action plan, accountable owners, dates, and estimated spend. It should not receive only a percentage such as the share of tools carrying a compliance label, because that figure can hide the most serious exposure.
The penalty structure makes delay economically material. For prohibited practices, the maximum can reach €35 million or 7% of worldwide annual turnover from the preceding financial year, whichever is higher for an undertaking. Other breaches can attract up to €15 million or 3%, and supplying incorrect, incomplete, or misleading information to authorities can lead to a maximum of €7.5 million or 1%. Specific rules apply to general-purpose AI, deployers, SMEs, and other actors, so the exact calculation requires legal analysis. The figures are not automatic invoices and do not mean every technical defect creates the maximum fine. They provide a ceiling, not a forecast, and proportionality, intent, mitigation, cooperation, and organisational size can affect enforcement.
An independent legal broker can be especially helpful when management wants a clear brief before selecting specialist firms, but help is not required in every case. A company with strong in-house capability may coordinate the programme itself and use targeted external advice. A smaller business may benefit from a fixed-scope classification and contract review before considering a broad transformation programme. The decision should be driven by exposure and evidence gaps, not fear of a headline penalty. By 24 September 2026, the priority is to verify current statutory text, complete the inventory, address live transparency and general-purpose AI duties, and invest first in systems whose failure could harm people or breach a regulated product obligation. A measured, documented programme is more credible than an expensive claim that every tool is compliant.