The EU AI Act is the European Union's risk-based regulatory framework governing the development, market placement, deployment and use of AI systems. It applies to providers and deployers both inside and outside the EU whenever their AI systems reach the EU market or affect people in it. Some obligations β prohibited practices, AI literacy, general-purpose AI model rules, and transparency requirements β already apply. High-risk obligations for most systems are now scheduled for December 2, 2027, following the Digital Omnibus amendment. The question for executives is no longer whether it applies, but which systems, under which obligations, on which date.
What is the EU AI Act?
The EU AI Act, formally Regulation (EU) 2024/1689, is a risk-based regulatory framework governing the development, placing on the market, deployment and use of AI systems in the European Union. It sorts AI systems into risk tiers β unacceptable, high, limited and minimal β and attaches obligations to each tier, rather than regulating AI as a single category.
The EU AI Act has moved from legislation to implementation. For executives, the question is no longer whether the regulation is coming β it is which AI systems inside the organization fall within its scope, what obligations apply to them, and who inside the organization is accountable for compliance.
Does the EU AI Act apply to my company?
Almost certainly, if you use AI in any business process that touches the EU. "We are not an AI company" is not a reason to be exempt β most organizations with obligations under the Act never built a model. They are deployers: organizations using someone else's AI system in a professional context.
A bank using AI for credit decisions is a deployer. An employer using AI in recruitment is a deployer. A company running an AI customer-service agent is a deployer. A hospital using diagnostic AI is a deployer. A company that built an application on top of OpenAI, Anthropic, Gemini or another provider's model is a deployer of that model, and may also take on provider obligations for what it built on top. A business using AI for employee monitoring or biometric applications is a deployer, often of a high-risk or prohibited system.
The Act also reaches beyond the EU's borders. Organizations headquartered outside the EU can fall within scope depending on how their AI systems are placed on the EU market or how their output is used by people inside it β physical presence in the EU is not the test. This overview does not constitute legal advice; scope determinations for a specific system should go through counsel.
Provider vs. deployer: know your role
This distinction gets misunderstood constantly, and it is worth getting right because it determines which obligations actually land on your organization.
| Role | In plain English |
|---|---|
| Provider | Generally, the organization that develops an AI system or model β or has one developed β and places it on the market or puts it into service under its own name or trademark |
| Deployer | An organization using an AI system under its own authority in a professional or business context β most enterprises using third-party AI fall here |
| Importer | An organization in the EU that places an AI system from outside the EU onto the EU market |
| Distributor | An organization in the supply chain that makes an AI system available on the EU market without being its provider or importer |
Your role determines which specific obligations apply, how much documentation you must produce and hold, whether you owe a conformity assessment or "only" operational duties like human oversight and monitoring, and who β you or your vendor β is legally responsible for a given failure. Many organizations are both: a deployer of the underlying model and a provider of what they built with it, if they substantially modified it or put it into service under their own name.
What kind of AI are you using, and what risk category is it in?
The Act sorts every AI system into one of four tiers, and the tier β not the underlying technology β determines what you owe.
| Tier | What it means | Example |
|---|---|---|
| Unacceptable | Prohibited outright β roughly ten application types incompatible with EU fundamental rights | Social scoring, certain manipulative or exploitative systems, most real-time biometric categorization |
| High-risk | Permitted, subject to extensive obligations: risk management, data governance, technical documentation, human oversight, conformity assessment | Recruitment and HR screening, credit and insurance scoring, medical diagnostics, biometric identification |
| Limited risk | Transparency obligations only β people must know they're interacting with or looking at AI | Chatbots, deepfakes, AI-generated content |
| Minimal risk | No mandatory obligations | Spam filters, AI-enabled video games, basic recommendation engines |
High-risk status mostly follows from Annex III, the list of use areas the Act treats as carrying meaningful risk to safety or fundamental rights: biometric identification, critical infrastructure management, education and vocational training, employment and worker management, access to essential private and public services (including credit and insurance), law enforcement, migration and border control, and the administration of justice. Falling inside an Annex III area does not automatically make a system high-risk β Article 6(3) carves out systems that perform only a narrow procedural task or merely improve the result of an already-completed human activity β but the default assumption for most Annex III use cases is that they qualify, and the burden is on the provider to document why one doesn't.
For a borderline system, the safer and cheaper posture is to treat it as high-risk and document your reasoning, rather than assume it is exempt and defend that position later under regulatory review.
What obligations already apply
What's coming next
The Digital Omnibus on AI β Regulation (EU) 2026/1744, in force since July 27, 2026 β pushed the main high-risk deadlines back. Use the dates below, not older sources that still say high-risk obligations began in August 2026 or August 2027.
The formal adoption process for the Digital Omnibus was ongoing as of this update; treat December 2, 2027 as the planning anchor and confirm final adoption before locking a compliance timeline to it.
What non-compliance actually costs
Article 99 sets a three-tier penalty structure, designed to exceed GDPR's maximum fines, with the higher of a fixed amount or a percentage of global annual turnover applying in each case.
| Infringement | Maximum fine |
|---|---|
| Prohibited AI practices | β¬35 million or 7% of global annual turnover, whichever is higher |
| High-risk or GPAI non-compliance | β¬15 million or 3% of global annual turnover |
| Supplying incorrect information (Art. 99) | β¬7.5 million or 1.5% of global annual turnover |
A company with β¬2 billion in annual revenue using a prohibited practice, such as workplace emotion recognition, could face a fine as high as β¬140 million β 7 percent of its turnover. Caps that favor the lower amount can apply for SMEs and startups in certain cases.
Who inside the organization should own this?
EU AI Act compliance gets misfiled the same way ISO 42001 does: it reads like a legal document, so it lands entirely with legal, and legal alone rarely has visibility into which systems the business actually runs, how autonomous they are, or how they're integrated. Classification, the highest-leverage step in this whole framework, requires someone who understands both the AI portfolio and the regulatory exposure β the Chief AI Officer's mandate, working alongside legal and compliance rather than instead of them. Legal determines binding obligations and signs off on classification calls; the CAIO maintains the inventory, flags likely triggers, and keeps the portfolio current as systems change. Neither should own this alone.
What management should do now
- Inventory every AI system touching the EU market or EU persons β including tools embedded in HR, marketing and operations software that nobody thinks of as "an AI system."
- Determine your role for each one β provider, deployer, importer or distributor β since obligations attach to the role, not the technology.
- Classify each system's risk tier, defaulting to high-risk on genuinely borderline Annex III cases and documenting the reasoning either way.
- Confirm Article 50 transparency obligations are met now β this deadline has already passed as of this update.
- Build the Annex III compliance path early for anything likely to be high-risk β technical documentation, data governance, human oversight and conformity assessment take months, and December 2027 is a deferral, not a reprieve.
- Name an owner β a CAIO or cross-functional AI governance lead working with legal, not legal working alone.
"We don't build AI" was never the exemption. Almost every obligation in this Act was written with the deployer, not the model builder, in mind.
Building the AI inventory, classification and governance structure this requires is the same discipline covered in WAIU's AI Governance Model β Use-Case Classification and Decision Rights are exactly where EU AI Act obligations get operationalized rather than left as a legal memo no one acts on.
A 6-week accelerator. You bring one real business challenge; you leave with a governed AI initiative.
Explore the Chief AI Officer ProgramConsultants advising clients on EU AI Act readiness should see the Certified AI Consultant Program.
Frequently asked questions
Is the EU AI Act already in force?
Parts of it, yes. Prohibited practices and AI literacy requirements have applied since February 2, 2025; governance provisions and GPAI rules since August 2, 2025; and Article 50 transparency obligations since August 2, 2026. Most high-risk obligations are now scheduled for December 2, 2027.
Does using ChatGPT, Claude or Gemini in our product make us subject to the Act?
It can. You are a deployer of the underlying model at minimum, and if you substantially modify it or put it into service under your own name, you may also take on provider obligations for what you built.
Why did the high-risk deadline move from 2026 to 2027?
The Digital Omnibus on AI, in force since July 27, 2026, deferred Chapter III high-risk obligations for Annex III systems to December 2, 2027, and for Annex I embedded products to August 2, 2028 β giving organizations more lead time to comply.
Does a US or non-EU company need to worry about this?
Yes, if its AI system reaches the EU market or affects people located in the EU. Physical presence in the EU is not the test β where the system's output is placed or used is.
