On 2 August 2026 the bulk of the EU AI Act became enforceable. Not the headline-grabbing bans — those have applied since February 2025 — but the part that touches ordinary companies: high-risk classification, conformity assessments, CE marking, and transparency duties for anything that talks to a customer or generates content. Enforcement powers for the AI Office arrived on the same date.

Surveys published a few months before the deadline suggested that around three quarters of organisations had taken no meaningful preparatory steps. If that describes your company, the useful question is no longer “when do we start?” but “which of our systems are actually in scope, and what is the cheapest path to defensible compliance?”

This guide answers that. It covers what changed, how to classify your systems, what the fines really are (they are not what most summaries claim), and where the rules may still shift.

What changed on 2 August

The AI Act entered into force on 1 August 2024 and has been switching on in stages ever since. The staged approach matters, because obligations that were theoretical last year are enforceable now.

  • 2 February 2025 — prohibited practices under Article 5, plus AI literacy duties for staff.
  • 2 August 2025 — obligations for general-purpose AI models and the governance structures behind them.
  • 2 August 2026 — the main body of the regulation: high-risk systems listed in Annex III, transparency obligations under Article 50, conformity assessment procedures, CE marking, and enforcement powers.
  • 2 August 2027Article 6(1), covering AI embedded as a safety component in products already regulated under EU product legislation.

The full sequence is published on the official implementation timeline, and the Commission maintains its own overview of the regulatory framework.

Whether you are in scope at all

Two questions decide this, and most companies get the second one wrong.

Question one: what role do you play?

The Act assigns duties by role, not by company size. A provider develops an AI system and places it on the market. A deployer uses one under its own authority. Importers and distributors have their own, lighter obligations. Buying a commercial AI tool and pointing it at your HR pipeline makes you a deployer — and deployers of high-risk systems carry real duties, including human oversight and monitoring.

The common mistake is assuming that because you did not build the model, none of this applies. It does. It is also worth noting that the Act reaches beyond the EU: it applies where the output of the system is used inside the Union, regardless of where the provider sits. A firm in Dubai serving European clients is not outside its reach.

Question two: is the system high-risk?

Annex III lists the areas that make a system high-risk by default. Broadly:

  • Biometric identification and categorisation
  • Critical infrastructure management
  • Education and vocational training
  • Employment, worker management and access to self-employment
  • Access to essential private and public services
  • Law enforcement
  • Migration, asylum and border control
  • Administration of justice and democratic processes

Read the employment line carefully, because it catches far more companies than the others. CV screening, candidate ranking, tools that influence promotion or task allocation, systems that monitor performance — these are high-risk under Annex III. A mid-sized company with no AI product whatsoever can be a high-risk deployer purely through its recruitment stack.

Article 50: the obligation almost everyone has

Even if nothing you run is high-risk, Article 50 probably reaches you. It imposes transparency duties in four situations:

  • Systems that interact with people must make clear they are AI, unless it is obvious from context. Your customer-facing chatbot falls here.
  • Synthetic content — audio, image, video or text generated by AI — must be marked in a machine-readable way.
  • Emotion recognition and biometric categorisation require informing the people subjected to them.
  • Deep fakes must be disclosed as artificially generated or manipulated.

The chatbot disclosure duty applies now. The machine-readable marking of AI-generated content received a short deferral, to 2 December 2026 — four months, not four years. If you publish AI-assisted content or run a generative feature, that clock is short.

What non-compliance actually costs

Most summaries quote “€35 million or 7% of turnover” and stop there. That is only the top tier, and for smaller companies the calculation works differently. Article 99 sets three bands:

  • Up to €35 million or 7% of total worldwide annual turnover, whichever is higher — for breaching the Article 5 prohibitions (social scoring, untargeted facial scraping, emotion recognition in workplaces and schools, subliminal manipulation, exploitation of vulnerabilities, and real-time remote biometric identification outside narrow exceptions).
  • Up to €15 million or 3% — for most operator obligations, including the Article 50 transparency duties.
  • Up to €7.5 million or 1% — for supplying incorrect, incomplete or misleading information to authorities.

The detail that changes the risk picture for smaller firms: for SMEs and start-ups the calculation inverts. The fine is the lower of the fixed amount or the percentage, not the higher. For a company with €4 million in turnover, top-tier exposure is 7% of turnover rather than €35 million. Still serious, but it is proportionality, not extinction.

A practical sequence

Compliance work tends to stall because teams try to solve everything at once. This order front-loads the cheap steps.

1. Inventory before anything else

List every AI system in use, including the ones nobody calls AI: the CV screener, the fraud scoring in your payments provider, the chatbot on the site, the feature in your CRM, the transcription tool in HR. Shadow AI is the norm, not the exception. For each, record what it does, who supplied it, what data it consumes, and which decisions it influences.

2. Classify by role and risk

For each system, decide whether you are provider or deployer, and whether it is prohibited, high-risk, subject only to transparency duties, or out of scope. Most inventories collapse quickly at this stage: a large share of tools turn out to carry transparency obligations only.

3. Close the transparency gaps first

They are cheap and they are enforceable now. Label the chatbot. Document how AI-generated content is marked. This is a week of work, not a quarter.

4. Build the file for anything high-risk

High-risk systems need a risk management system, data governance, technical documentation, logging, human oversight, and accuracy and robustness measures — then conformity assessment and CE marking. If you are a deployer rather than a provider, your duties are narrower but real: use the system per instructions, assign competent human oversight, monitor operation, keep logs.

5. Reuse a framework instead of inventing one

Do not write governance from scratch. The NIST AI Risk Management Framework maps closely to what the Act expects and is free. The OECD AI Policy Observatory is useful for tracking how obligations are landing across jurisdictions, which matters if you operate outside the EU as well.

The part that may still move

Being straight about this is more useful than pretending the picture is settled. There is active political pressure to delay parts of the Act. The European Parliament has voted in favour of pushing high-risk requirements back, and the Digital Omnibus package could move the Annex III deadline to December 2027, with sector-specific obligations later still. Trilogue negotiations were unresolved as this was written.

What that means in practice: the 2 August 2026 date remains legally binding until something formally replaces it. Betting your compliance posture on a delay that has not happened is a poor trade — the inventory and classification work is worth doing regardless, and it is the part that takes longest.

Frequently asked questions

Q: We are not in the EU. Does this apply to us?

A: Quite possibly. The Act applies where the output of an AI system is used within the Union, irrespective of where the provider or deployer is established. Serving European customers is enough to bring you into scope.

Q: We only buy AI tools, we do not build them. Are we exempt?

A: No. You are a deployer, and deployers of high-risk systems have their own obligations: operating the system according to instructions, assigning human oversight to competent staff, monitoring its behaviour, and retaining logs.

Q: Does using ChatGPT internally make us a provider of a general-purpose AI model?

A: No. Provider obligations for general-purpose models fall on whoever places the model on the market. Using one commercially makes you a deployer, and your duties then depend on what you use it for.

Q: Is our recruitment screening tool really high-risk?

A: If it filters, ranks or scores candidates, Annex III points that way. This is the single most common way a company with no AI product ends up with high-risk obligations.

Q: What is the realistic exposure for a small company?

A: For SMEs and start-ups the fine is the lower of the fixed ceiling or the turnover percentage, not the higher. The percentage bands still apply, so the exposure scales with size rather than jumping straight to headline figures.

Q: Where do we start if we have done nothing?

A: The inventory. You cannot classify what you have not listed, and every later step depends on it. It is also the step that consistently surprises people, because the list is longer than expected.

The bottom line

  • The substantive obligations are live as of 2 August 2026, and the AI Office now has enforcement powers.
  • Transparency duties under Article 50 reach almost every company running a chatbot or generating content. Machine-readable marking of AI content follows on 2 December 2026.
  • Employment and HR tooling is the most common route into high-risk classification for companies that do not consider themselves AI businesses.
  • Fines are tiered, and for SMEs the calculation is the lower of the two figures rather than the higher.
  • Deadlines may shift through the Digital Omnibus, but the current dates remain binding, and the inventory work is worth doing either way.

Start with the inventory this week. Everything else depends on knowing what you are actually running.

Sources

This article is general information, not legal advice. Classification under the AI Act depends on the specific system and how it is used; confirm your position with qualified counsel before relying on it.

Related Articles