EU AI Act: what it means for companies building or using AI

EU AI Act for companies: risk categories, provider and deployer duties, the timeline after the 2026 AI Omnibus, GPAI rules and practical compliance steps.

EU AI Act: what it means for companies building or using AI

EU AI Act for companies: risk categories, provider and deployer duties, the timeline after the 2026 AI Omnibus, GPAI rules and practical compliance steps.

EU AI Act: what it means for companies building or using AI

EU AI Act for companies: risk categories, provider and deployer duties, the timeline after the 2026 AI Omnibus, GPAI rules and practical compliance steps.

IN THIS GUIDE

No headings found on page

SHORT ANSWER

The EU AI Act (Regulation (EU) 2024/1689) sorts AI systems into four risk levels and sets duties for providers and deployers. Bans have applied since February 2025, general-purpose AI rules since August 2025 and transparency rules since August 2026. After the 2026 AI Omnibus, high-risk duties apply from 2 December 2027 for Annex III uses and 2 August 2028 for AI in regulated products.

If you build AI features or buy tools that contain them, the EU AI Act decides what evidence you’ll need and by when. The Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and applies in stages. It regulates AI by risk level: a few practices are banned, high-risk systems face strict requirements, some systems carry transparency duties and most AI is left largely alone. What you must do depends on your role (provider or deployer) and on the use case, not on the technology. This guide is general information, not legal advice.

What are the AI Act risk categories?

Risk level

Examples

What applies

Unacceptable (prohibited)

Social scoring, manipulative techniques that cause harm, emotion recognition at work or school, untargeted facial image scraping, AI that generates non-consensual intimate imagery (added in 2026)

Banned in the EU

High risk

AI in recruitment and HR decisions, creditworthiness scoring, life and health insurance pricing, education and exams, critical infrastructure, safety components of regulated products

Risk management, data governance, documentation, logging, human oversight, conformity assessment, EU database registration

Transparency risk

Chatbots, AI-generated or manipulated images, audio, video and text, deepfakes, emotion recognition

Tell people they are dealing with AI and mark synthetic content in a machine-readable way

Minimal risk

Spam filters, demand forecasting, recommendation engines, most internal analytics

No specific obligations beyond AI literacy, plus voluntary codes

Classification follows the use. One language model is minimal risk when it summarises internal documents and high risk when it ranks job applicants. An Annex III system isn’t high risk if it only performs a narrow procedural task or prepares a human assessment without materially influencing the outcome. You still have to document that assessment.

Provider or deployer: which role do you have?

  • Provider: develops an AI system or GPAI model, or has one developed, and places it on the market or puts it into service under its own name. Carries most of the obligations.

  • Deployer: uses an AI system under its authority in a professional context, for example a bank using a vendor’s credit scoring tool.

  • Importer and distributor: brings third-country AI systems to the EU market and must check that the provider has done its part.

  • Becoming a provider by accident: a deployer or distributor becomes the provider of a high-risk system if it puts its own name on it, makes a substantial modification or changes the intended purpose so the system becomes high risk (Article 25).

For a high-risk system, providers carry most of the work. They run a risk management system, govern training and test data, write technical documentation, build in automatic logging, give deployers instructions for use and design for human oversight. They also meet the Article 15 requirements on accuracy, robustness and cybersecurity, operate a quality management system, complete a conformity assessment, register the system and monitor it after release.

Deployers must use the system according to its instructions, assign competent people to oversee it, monitor how it runs, keep the logs it generates for at least six months and inform workers and affected people. Public bodies, and deployers in certain uses such as credit scoring and insurance pricing, must also carry out a fundamental rights impact assessment.

What is the AI Act timeline after the AI Omnibus?

The Commission proposed the Digital Omnibus on AI in November 2025. The EU adopted it as Regulation (EU) 2026/1744, published on 24 July 2026 and in force since 27 July 2026. It pushes the high-risk deadlines back because harmonised standards and guidance weren’t ready in time.

Date

What applies

2 February 2025

Prohibited practices and AI literacy duties (softened in 2026 to supporting AI literacy of staff)

2 August 2025

General-purpose AI model obligations, governance and penalty rules

2 August 2026

Transparency obligations under Article 50, most remaining provisions and Commission enforcement powers over GPAI providers

2 December 2026

New ban on AI generating non-consensual intimate imagery and child sexual abuse material, and end of the grace period for machine-readable marking in generative systems already on the market before 2 August 2026

2 August 2027

GPAI models placed on the market before 2 August 2025 must comply, and national AI regulatory sandboxes are due

2 December 2027

High-risk obligations for stand-alone Annex III systems (originally 2 August 2026)

2 August 2028

High-risk obligations for AI in products covered by EU harmonisation legislation, Annex I (originally 2 August 2027)

The Omnibus also extends some simplified SME rules to small mid-cap companies, streamlines EU database registration for systems exempt from high-risk status and allows processing of special category data to detect and correct bias, under safeguards. Guidelines and harmonised standards are still coming, so check the AI Office and the AI Act Service Desk before you settle your approach.

What must general-purpose AI model providers do?

GPAI providers must keep technical documentation, give downstream providers the information they need to build the model into their own systems, have a copyright compliance policy and publish a summary of training content using the Commission template. Models with systemic risk (presumed above 10^25 floating-point operations of training compute) must also run model evaluations and adversarial testing, track and report serious incidents and maintain strong cybersecurity. The GPAI Code of Practice published in July 2025 is the main route to show compliance.

Most enterprises aren’t GPAI providers. They build AI systems on top of such models, so the system-level rules matter more to them.

What does traceable AI look like in practice?

On an enterprise GraphRAG chatbot we built, leadership wouldn’t trust answers they couldn’t check. So every answer cites its sources, and a transparency mode shows the context, the generated graph query and the raw data behind each response. Our first pilot used an automated LLM graph builder, which invented roles and duplicated people. A manually verified layer of known people, roles and projects fixed that, with zero entity duplication. That tool is minimal risk, but the same design gives you the traceability the Act demands of high-risk systems.

What should companies do to prepare?

  1. Build an AI inventory. List every AI system you develop, buy or embed, including features inside SaaS tools, with owner, purpose, users, data and vendor.

  2. Classify each system. Check it against the prohibited list, the Annex III use cases and the Annex I product rules, then record your role and reasoning.

  3. Stop or redesign anything prohibited. These rules have applied since February 2025.

  4. Meet transparency duties now. Label chatbots, mark AI-generated content and disclose deepfakes, as Article 50 applies from 2 August 2026.

  5. Start documentation for high-risk systems. Begin the technical file, data sheets, risk register and instructions for use early. Fourteen months to December 2027 is short for a conformity assessment.

  6. Design human oversight. Decide who can review, override or stop the system, what they see and how you train them.

  7. Log and monitor. Record inputs, outputs, model versions and user actions so you can trace decisions, and set up post-market monitoring and incident reporting.

  8. Update vendor contracts. Require providers to supply documentation, logs, instructions and notice of substantial changes.

This overlaps with good engineering practice. The work in our LLM evaluation guide and in taking an AI proof of concept to production produces much of the evidence the Act asks for. Our AI readiness assessment checklist helps you map your AI use first.

How RUBICON helps with AI Act readiness

We help teams build an AI inventory, classify use cases and add the logging, evaluation and human oversight the Act expects. We’re about 55 people, 40+ engineers, ISO 27001:2022 and ISO 9001:2015 certified and a Microsoft Solutions Partner for Cloud & AI Platforms. Our AI and machine learning services cover the build work.

If you’re unsure where your systems fall, our architects can work through the classification with you.

Frequently asked questions

When does the EU AI Act apply to high-risk AI systems?

After the AI Omnibus (Regulation (EU) 2026/1744), in force since 27 July 2026, high-risk duties for stand-alone Annex III systems, such as AI used in recruitment, credit scoring or education, apply from 2 December 2027. High-risk AI embedded in products covered by EU product legislation, such as machinery or medical devices, follows from 2 August 2028. Prohibitions and GPAI rules already apply.

Does the EU AI Act apply to companies outside the EU?

Yes. It covers providers that place AI systems or general-purpose AI models on the EU market, wherever they are based, and providers and deployers outside the EU when the output of the AI system is used in the EU. Non-EU providers of high-risk systems and GPAI models must appoint an authorised representative in the EU.

Is a company that uses ChatGPT or Copilot a provider or a deployer?

Usually a deployer: you use an AI system under your authority in a professional context. Deployers have lighter duties, such as AI literacy measures, transparency towards the people affected and, for high-risk uses, human oversight and log retention. You become a provider if you build your own system on a model and place it on the market under your name, or substantially modify a high-risk system.

What are the fines under the EU AI Act?

Fines reach up to €35 million or 7% of worldwide annual turnover for prohibited practices, up to €15 million or 3% for most other breaches, and up to €7.5 million or 1% for supplying incorrect information to authorities, whichever is higher. For SMEs and start-ups the lower amount applies. National market surveillance authorities enforce most rules, and the AI Office supervises GPAI models.

Related case study

Case study image showcase

Enterprise GraphRAG Chatbot with Neo4j | Case Study

How RUBICON's Two Layer Fixed Entity Architecture eliminated data bottlenecks for a multi team enterprise, delivering a conversational AI system that gives leadership instant project clarity, without hallucinations.

More resources

If you need to classify your AI systems or add logging and human oversight to a product already in use, our architects can run an AI Act readiness review with you.
If you need to classify your AI systems or add logging and human oversight to a product already in use, our architects can run an AI Act readiness review with you.
If you need to classify your AI systems or add logging and human oversight to a product already in use, our architects can run an AI Act readiness review with you.