Guide · Regulation

EU AI Act: what businesses must do, and when

The Digital Omnibus changed the timeline in July 2026. Here is what already applies, what arrives on 2 December 2027, the obligations for a business that uses AI, and a six-step action plan.

Zakaria El Asri14 min

The date that moved

High-risk deadline: moved from 2 August 2026 to 2 December 2027.

In short

The key points in one paragraph

The EU AI Act (Regulation (EU) 2024/1689) applies in stages. Already in force: the prohibited practices and the AI literacy obligation since 2 February 2025, and the transparency obligations since 2 August 2026. The obligations for high-risk systems under Annex III, such as screening job applications or credit scoring, will apply from 2 December 2027, the date set by the Digital Omnibus (Regulation (EU) 2026/1744), which entered into force on 27 July 2026.

For most SMEs, the AI Act currently comes down to three tasks: train the teams that use AI, label agents and chatbots as AI, and check that no use falls into a high-risk category. Everything else depends on what your systems do.

Timeline

The AI Act timeline after the Digital Omnibus

DateWhat appliesReference
1 August 2024Regulation enters into forceArt. 113
2 February 2025Prohibited practices and AI literacyArt. 5 and 4
2 August 2025General-purpose AI models, penalty regime, national authoritiesChap. V, Art. 70 and 99
2 August 2026Transparency obligations (chatbots, generated content)Art. 50
2 December 2026Content marking for systems already on the market; two new bansArt. 50(2) and 5
2 August 2027National regulatory sandboxes; general-purpose models placed on the market before 2 August 2025Art. 57 and 111
2 December 2027High-risk systems under Annex IIIArt. 6(2)
2 August 2028High-risk systems built into products (Annex I)Art. 6(1)
Consolidated timeline based on the European Commission's AI Act Service Desk, checked on 13 September 2026.
EU AI Act timeline from 2024 to 2028, with Annex III high-risk rules on 2 December 2027 and Annex I on 2 August 2028
AI Act deadlines after the Digital Omnibus.

What changed

The Digital Omnibus: adopted, published, in force

The Commission proposed the Digital Omnibus on AI on 19 November 2025. The European Parliament voted for it on 16 June 2026 and the Council gave final approval on 29 June. It was published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744 and entered into force on 27 July 2026. It is now binding law.

What it means for a business:

  • High-risk rules postponed. Annex III moves from 2 August 2026 to 2 December 2027, and Annex I from 2 August 2027 to 2 August 2028.
  • AI literacy softened. Article 4 used to require a sufficient level of AI literacy; it now requires measures to support it.
  • Wider relief. Simplifications that used to be reserved for SMEs now also cover small mid-cap companies.
  • Two new bans from 2 December 2026, covering sexual content generated without consent and child sexual abuse material.
  • Simpler impact assessment. The fundamental rights impact assessment can build on the GDPR data protection impact assessment.

The postponement leaves the rules already in force untouched. It gives sixteen more months to prepare high-risk uses, including recruitment: our comparison of AI agencies for HR explains what this means for tools that screen job applications.

Today

What already applies to your business

Prohibited practices (Article 5), since 2 February 2025. These include social scoring, manipulation that exploits vulnerabilities, and emotion recognition in the workplace or in education, except for medical or safety reasons. An HR tool that analyses candidates' emotions during video interviews falls under this ban.

AI literacy (Article 4), since 2 February 2025. Businesses that use AI systems must take measures so that their staff, and the people who use these systems on their behalf, understand the tools. In its FAQ, the Commission states that no certification is required, that there is no one-size-fits-all approach, and that keeping an internal record of training is useful. It suggests four steps: a general understanding of AI, the role of the business, the risks of the systems in use, and then training suited to each person's level.

Transparency (Article 50), since 2 August 2026. People must be told they are dealing with an AI, at the latest during the first interaction, unless it is obvious. Deepfakes must be labelled. Our guide to the transparency obligation for AI agents explains who must do what between the tool vendor and the business that deploys it.

Classification

When is an AI system high-risk?

A system is classified by its purpose, and its sector alone settles nothing. Under Article 6(2), a system is high-risk when it is used for one of the purposes listed in Annex III.

LevelExamplesRegime
UnacceptableSocial scoring, emotion recognition at workBanned since 2 February 2025
High-riskScreening job applications, credit scoring, life and health insurance pricingObligations from 2 December 2027
TransparencyChatbots, conversational agents, generated contentPeople must be informed since 2 August 2026
MinimalInternal automation, spam filters, writing assistanceNo specific obligation beyond Article 4
AI Act risk levels with the consolidated dates. Lumyniq, 2026.

Article 6(3) sets out an exception. A system listed in Annex III does not count as high-risk if it only performs a narrow procedural task, improves the result of a human activity already completed, detects patterns without replacing human assessment, or performs a preparatory task. This exception never applies to a system that profiles natural persons. A provider relying on it must document its assessment.

The Commission is preparing guidelines on this classification; the final version is expected by the end of 2026.

By sector

Real estate, legal, healthcare, HR: where high-risk applies

SectorHigh-risk (Annex III or I)Usually outside high-risk
Human resourcesTargeted job ads, sorting and filtering applications, evaluating candidates, promotion or termination decisions, performance monitoring (4a, 4b)Writing job ads, scheduling interviews, answering candidate questions
Real estateCreditworthiness assessment for a mortgage (5b). Tenant scoring is a grey areaLead qualification, writing listings, booking viewings
LegalSystems used by a judicial authority or in alternative dispute resolution (8a)Legal research and case pre-qualification in a law firm
HealthcareEmergency patient triage (5d); AI built into a medical device subject to third-party conformity assessment (Annex I, 2 August 2028)Appointment booking, administrative document sorting
Lumyniq's reading of Annex III and Article 6. Borderline cases need a case-by-case assessment.

For concrete use cases by profession, see our guides on human resources, real estate, legal and healthcare.

Your role

Deployer or provider: who has to do what

The AI Act separates the provider, who develops an AI system or has it developed and places it on the market under its own name, from the deployer, who uses a system under its authority in a professional context. An SME using an AI tool it has bought is a deployer. It can become a provider if it sells a system under its own brand, substantially modifies it, or changes its purpose to the point of making it high-risk.

For a high-risk system, Article 26 requires the deployer, from 2 December 2027, to:

  1. use the system in line with the provider's instructions for use;
  2. assign human oversight to people with the necessary competence, training and authority;
  3. make sure the input data it controls is relevant;
  4. monitor how the system works and report risks and serious incidents to the provider and the authority;
  5. keep automatically generated logs for at least six months;
  6. inform workers' representatives and affected employees before using the system in the workplace;
  7. tell people when a high-risk system is involved in a decision about them.

Article 27 adds a fundamental rights impact assessment for some deployers: public bodies, private entities providing public services, and businesses that use AI to assess people's creditworthiness or price life or health insurance.

When you commission a custom agent, the split of roles should be written into the contract. Our design principles are set out in our guide to AI agent security.

Financial risk

Penalties

BreachMaximum fine
Prohibited practice (Article 5)€35M or 7% of worldwide annual turnover
Other obligations, including deployer and transparency obligations€15M or 3%
Incorrect or misleading information supplied to authorities€7.5M or 1%
Article 99 of the regulation. The higher amount applies, except for SMEs and start-ups.

For SMEs and start-ups, Article 99(6) uses the lower of the two amounts. These figures are caps: the national authority sets the fine based on the seriousness and duration of the breach and the size of the business.

France

Who enforces the AI Act in France

As of 13 September 2026, France has not yet passed the law designating its competent authorities. The provisions sit in a bill adapting French law to EU law, approved by the Senate on 18 February 2026 and still under discussion at the Assemblée nationale.

The bill gives coordination and the single point of contact role to the DGCCRF (French consumer protection authority), and a central role to the CNIL (French data protection authority) for high-risk systems, in particular those related to employment and biometrics. The ACPR would oversee credit and insurance, the ANSM medical devices, and Arcom synthetic content. These roles still need to be confirmed by the final vote.

In its Q&A page updated on 17 August 2026, the CNIL points out that it remains fully competent to apply the GDPR, and that the AI Act adds to the GDPR without replacing it.

Taking action

A six-step action plan

  1. List your AI uses, including tools you have bought, AI features built into your software and individual use by your teams.
  2. Classify each use: prohibited, high-risk under Annex III, transparency, or minimal. Record your role, deployer or provider.
  3. Stop anything prohibited, starting with any emotion analysis at work.
  4. Put transparency in place for public-facing chatbots, agents and generated content.
  5. Train and document: an AI literacy action suited to each role, with a written record.
  6. Prepare for high-risk rules before December 2027: ask providers for their documentation, name the people responsible for human oversight, organise log retention and plan how employees will be informed.

This work is part of our AI consulting and of every project we deliver in a regulated sector. If your use relies on an AI API, data hosting is also a question: see our guide to Claude API pricing and hosting.

FAQ

Frequently asked questions about the EU AI Act

The EU AI Act is Regulation (EU) 2024/1689 on artificial intelligence, which entered into force on 1 August 2024. It classifies AI systems by the risk they pose to health, safety and fundamental rights, and sets obligations in proportion to that risk. It was amended by Regulation (EU) 2026/1744, known as the Digital Omnibus, which entered into force on 27 July 2026.

Related guides

Read next

Sources

Links verified at publication. Regulatory texts change — always defer to the official source.

Let's talk about your project

A question, a project, an idea? We respond within 24h. Free audit, no commitment.

Contact details