EU AI Act: Complete Business Guide 2026
The world's first comprehensive AI law is now in force. Understand your obligations, key deadlines, and how to find compliant AI tools — all in one place.
The information on this page is of a general nature only and is not intended to address the specific circumstances of any particular individual or entity. It is not necessarily comprehensive, complete, accurate, or up to date. It does not constitute legal advice, legal opinion, regulatory guidance, or a legal interpretation of any legislation. No attorney-client relationship is created by accessing or relying on this content. GateOnAI, the AI Decision Platform for Business, is an independent AI tools directory — not a law firm, regulatory body, or compliance consultancy. For advice specific to your organisation's obligations under the EU AI Act or any other regulation, consult a qualified legal professional specialising in EU technology law or contact your national competent authority.
You are solely responsible for how you use this information. It is your responsibility to independently verify anything on this page against the official sources linked below before relying on it, and to seek information from qualified, authoritative sources — especially where safety, legal compliance, or regulatory risk is involved.
On 24 July 2026, the EU published Regulation (EU) 2026/1744 (the "Digital Omnibus on AI"), which entered into force 27 July 2026 and amends the AI Act. The most significant change: the compliance deadline for stand-alone high-risk AI systems (Annex III) is deferred from 2 August 2026 to 2 December 2027. High-risk systems embedded in regulated products (Annex I) move from 2 August 2027 to 2 August 2028. National AI regulatory sandboxes are now due by 2 August 2027. A new prohibition on AI-generated non-consensual intimate imagery ("nudifiers") and CSAM was also added to Article 5.
Article 50 transparency obligations are NOT delayed — chatbot disclosure, deepfake labelling, and AI-generated content marking still apply from 2 August 2026 as originally scheduled.
What is the EU AI Act?
The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive, horizontal legal framework governing artificial intelligence. Adopted by the European Parliament and Council, it entered into force on 1 August 2024 and applies a risk-based approach: the stricter the potential harm of an AI system, the more stringent the obligations.
Unlike sector-specific regulations, the AI Act applies across all industries and use cases — from healthcare and hiring to marketing automation and customer service. Crucially, it has extraterritorial reach: any organisation providing or deploying AI systems that affect people in the EU must comply, regardless of where that organisation is headquartered.
Implementation Timeline
The AI Act follows a phased implementation schedule. Different obligations apply at different dates depending on the type of AI system and your role in the supply chain.
The regulation was published in the Official Journal and became binding EU law. The phased implementation timeline begins.
Article 5 prohibitions took effect. Unacceptable-risk AI systems — including social scoring, subliminal manipulation, and certain biometric surveillance — are now banned. Violations face fines of up to €35M or 7% of global turnover. AI literacy obligations (Article 4) also apply from this date.
General-Purpose AI (GPAI) model providers must comply with transparency requirements, technical documentation standards, and copyright policies. New GPAI models released after this date must comply immediately. Member States designate national competent authorities.
Chatbot and AI-assistant disclosure, deepfake labelling, and marking of AI-generated content took effect from this date as originally scheduled — these obligations were not affected by the 2026 Digital Omnibus delay. See the dedicated section below for what this means in practice.
For generative AI models released before 2 August 2026, the deadline to label outputs as AI-generated (e.g. via watermarking) is extended from 2 August 2026 to 2 December 2026 under Regulation (EU) 2026/1744.
Each EU Member State must have at least one AI regulatory sandbox operational. This obligation was postponed by one year, from 2 August 2026, under Regulation (EU) 2026/1744.
The most significant milestone for most businesses. Stand-alone high-risk AI systems (Annex III — e.g. recruitment, credit scoring, education, critical infrastructure) must complete conformity assessments, establish risk management systems, maintain technical documentation, ensure human oversight, and register in the EU database. This deadline was deferred from 2 August 2026 by Regulation (EU) 2026/1744, published 24 July 2026.
Obligations extend to high-risk AI systems embedded in regulated products already covered by EU product-safety law (medical devices, machinery, toys, automotive systems). Deferred from 2 August 2027 by Regulation (EU) 2026/1744.
Which sections of this guide are worth reading?
Tick anything that applies to your situation. This only highlights which parts of the AI Act text on this page may be relevant — it does not tell you whether you comply. Nothing you select is stored, saved, or sent anywhere — it runs entirely in your own browser and disappears when you close this page.
How do I know that's true?
Risk Categories Explained
The AI Act classifies AI systems into four risk tiers. Your compliance obligations depend entirely on which tier your AI system falls into.
Answer honestly based on the public criteria quoted below — this narrows down which tier card to read first, it does not classify your AI system for you. Nothing here is stored, saved, or sent anywhere — it runs entirely in your browser.
These AI systems are completely banned under Article 5. No compliance pathway exists — they must not be developed, deployed, or used.
- Social scoring systems by public authorities
- Real-time remote biometric identification in public spaces (with narrow exceptions)
- Subliminal manipulation causing harm
- Exploitation of vulnerability of persons (age, disability, social situation)
- Emotion recognition in workplace or education
- Predictive policing based solely on profiling
- AI-generated non-consensual intimate imagery ("nudifiers") and CSAM — added to Article 5 by Regulation (EU) 2026/1744, July 2026
Permitted, but subject to extensive obligations before market placement. Deadline: 2 December 2027 (deferred from 2 August 2026 by Regulation (EU) 2026/1744, in force since 27 July 2026).
- Biometric identification and categorisation systems
- AI in recruitment, CV screening, interview assessment
- Credit scoring and insurance risk assessment
- AI in medical devices and clinical decision support
- Education: student assessment and performance evaluation
- Law enforcement: evidence evaluation, criminal risk profiling
- Migration and border control systems
- Critical infrastructure: water, gas, electricity, road traffic
Permitted with transparency requirements under Article 50. Users must be clearly informed they are interacting with an AI.
- Customer service chatbots and virtual assistants
- AI-generated content (text, images, audio, video)
- Deepfake generation tools
- Emotion recognition systems (limited contexts)
- Spam filters with direct user interaction
The vast majority of AI tools fall here. The European Commission estimates approximately 85% of AI systems in the EU market are minimal risk. No mandatory obligations apply, though voluntary codes of conduct are encouraged.
- AI-enabled video games
- Content recommendation systems
- Writing assistants and productivity tools
- Image generation for creative use
- SEO and marketing analytics tools
AI-Generated Content Labelling: What Changed on 2 August 2026
On 20 July 2026, the European Commission adopted formal guidelines on the Article 50 transparency obligations, which took effect on 2 August 2026 as originally scheduled. These rules require clear disclosure across four areas: direct interaction with an AI system, AI-generated or AI-manipulated content, emotion recognition and biometric categorisation, and deepfakes or AI-generated text on matters of public interest. Non-compliance can attract fines of up to €15 million or 3% of worldwide annual turnover.
Alongside the guidelines, the AI Office published a voluntary Code of Practice on Transparency of AI-Generated Content, setting out concrete technical measures for marking and watermarking AI outputs. Signing the Code is treated by the Commission and the AI Board as an adequate way for organisations to demonstrate Article 50(2), (4) and (5) compliance, though signing it does not by itself guarantee compliance with the Act's other obligations.
The largest AI labs have begun adapting. OpenAI uses Google DeepMind's SynthID to embed an invisible watermark in AI-generated images, since extended to audio. Anthropic announced that all Claude models released from 2 August 2026 onward embed a watermark directly in generated text — imperceptible to readers and preserved when the text is copied elsewhere, since it is part of the text itself rather than a separate marker. Both companies have adopted the C2PA (Coalition for Content Provenance and Authenticity) standard for storing and transmitting content-provenance metadata.
For businesses that use AI tools to generate marketing copy, images, or other public-facing content, this matters directly: as a deployer of a generative AI system, you may have your own disclosure obligations under Article 50(4) when publishing AI-generated or AI-manipulated content, separate from the AI provider's own marking obligations as the tool's provider.
What Every Business Must Do Now
Regardless of your AI risk tier, Article 4 (AI literacy) applies to all organisations using AI as of February 2025. Here is a practical action plan:
Catalogue every AI system your organisation provides, deploys, or uses — including embedded AI in third-party tools (HR software, CRM, marketing platforms). Over 50% of enterprises lack a systematic AI inventory, creating immediate compliance risk.
Apply the four-tier classification to each system. Use the official AI Act Explorer or the EU Commission's compliance checker. Pay particular attention to HR, credit, medical, and education use cases — these are almost always high-risk under Annex III.
Article 5 prohibitions have been in force since February 2025. If any of your AI systems fall under unacceptable risk — emotion recognition in the workplace, social scoring, certain biometric surveillance — discontinue them without delay. Enforcement is active.
Article 4 requires that all staff using or overseeing AI systems have sufficient AI literacy. Document your training programme — without evidence of training, you cannot demonstrate compliance even if your systems are technically sound.
For each high-risk AI system, complete: risk management documentation, data governance assessment, technical documentation, conformity assessment, and EU database registration. Implementation typically takes 12–18 months for complex organisations. Start now.
For limited-risk systems (chatbots, AI-generated content), ensure users are clearly informed they are interacting with AI. Label all AI-generated content. This applies immediately.
If Step 3 means retiring a prohibited-practice tool, or you're simply choosing new AI tools with EU compliance in mind, GateOnAI's EU-hosted & GDPR-flagged AI tools directory lets you filter specifically for that — a practical starting point, not a substitute for your own due diligence on each tool's actual compliance posture.
Official Resources & Further Reading
GateOnAI Ecosystem
One platform. Every AI tool, workflow, and comparison you need — EU-hosted, independent, always free.
Frequently Asked Questions
What is the EU AI Act?
The EU AI Act (Regulation EU 2024/1689) is the world's first comprehensive legal framework for artificial intelligence. It entered into force on 1 August 2024 and establishes binding rules for AI systems placed on the EU market or used within the EU, regardless of where the provider is headquartered.
Who does the EU AI Act apply to?
The Act applies to any organisation — EU-based or not — that provides, deploys, or uses AI systems affecting people within the European Union. This includes software vendors, businesses using third-party AI tools, importers, and distributors. If your AI system touches EU users, you are in scope.
What are the key deadlines?
2 February 2025: Prohibited AI practices banned. 2 August 2025: GPAI model obligations and national authority designation. 2 August 2026: Article 50 transparency obligations (chatbot disclosure, deepfake labelling) - unaffected by the 2026 delay. 2 December 2026: Extended deadline for labelling generative AI content from models released before August 2026. 2 August 2027: National AI regulatory sandboxes. 2 December 2027: High-risk AI system obligations (Annex III) - deferred from the original 2 August 2026 date by Regulation (EU) 2026/1744, in force since 27 July 2026. 2 August 2028: Full compliance for high-risk AI embedded in regulated products (Annex I).
What are the penalties for non-compliance?
Fines reach up to EUR 35 million or 7% of global annual turnover for prohibited practices — exceeding GDPR levels. High-risk non-compliance: up to EUR 15 million or 3% of turnover. Providing incorrect information to authorities: up to EUR 7.5 million or 1% of turnover. SMEs and startups benefit from proportionate caps.
What is a high-risk AI system?
High-risk AI systems include those used in biometrics, recruitment and HR decisions, credit scoring, medical devices, education assessment, law enforcement, migration, and critical infrastructure. These systems must meet strict requirements including risk management, data governance, transparency, human oversight, and conformity assessment. Following Regulation (EU) 2026/1744 (July 2026), the deadline for stand-alone (Annex III) high-risk systems is 2 December 2027, and for high-risk systems embedded in regulated products (Annex I) it is 2 August 2028.
Does the EU AI Act apply to AI tools I use (not build)?
Yes. Businesses that deploy third-party AI tools — such as HR screening tools, customer service chatbots, or credit assessment software — are considered deployers and have obligations under the Act. This includes maintaining an inventory of AI systems, ensuring AI literacy among staff, and verifying that high-risk tools meet compliance requirements.
What should my business do right now?
Start with an AI inventory: catalogue every AI system you use or provide. Classify each by risk tier. For prohibited practices (already banned since February 2025), discontinue immediately. For high-risk systems, begin conformity assessment and documentation. Ensure AI literacy training for staff — Article 4 is already in force.
This page is provided for general informational and educational purposes only. GateOnAI makes no representations or warranties of any kind, express or implied, regarding the completeness, accuracy, reliability, or suitability of the information contained herein. GateOnAI accepts no responsibility or liability whatsoever with regard to any decisions made or actions taken in reliance on the information on this page. The binding interpretation of EU legislation is the exclusive competence of the Court of Justice of the European Union. Laws and regulations change frequently — always verify with official EU sources before making compliance decisions. External links are provided for convenience only; GateOnAI has no control over and assumes no responsibility for the content of external sites.
By using this page, you acknowledge and accept that you are responsible for what you read here and for where you go to verify it. Always cross-check against the official sources linked on this page, and for compliance, safety, or legal decisions, consult a qualified professional or your national competent authority rather than relying on this page alone.
Sources: Regulation (EU) 2024/1689 (Official Journal, 13 June 2024) • Regulation (EU) 2026/1744 (Official Journal, 24 July 2026) • artificialintelligenceact.eu • European AI Office • EUR-Lex