AI Leadership & Perspective

The EU AI Act, Explained: What It Actually Means for Your Business

The EU AI Act has stopped being a “someday” compliance topic. It’s in force, it’s phasing in, and in 2026 it went through its first major amendment. But most coverage misses the one distinction that actually decides how much any of this affects your organization: are you building and selling AI, or just using tools like ChatGPT or Claude to get work done? The obligations and the costs are very different depending on which side of that line you’re on. 

This article is part of a bigger guide. Read the full story on IPXO’s blog. 

Why it exists 

The Act didn’t start as a rulebook. It started as a philosophy: trustworthy AI. An EU expert group laid out ethics guidelines in 2019, the European Commission followed with a formal proposal in 2021, and the law entered into force in August 2024. 

The design choices trace back to four goals. Hiring algorithms, credit scoring models, and other high-stakes automated decisions can be opaque or quietly biased, and the Act exists partly to keep that in check.  

It’s also a market-fragmentation fix: without one EU-wide rulebook, all 27 member states could end up writing their own AI laws, splintering the single market the EU has spent decades building. There’s an economic bet built in too – that businesses adopt new technology faster when there are guardrails around it, not despite them.  

And then there’s the GDPR precedent: once Europe set the global bar for data privacy, other regions largely fell in line, and Brussels is clearly hoping the AI Act plays out the same way. That’s part of why the law reaches well beyond EU borders. Any company whose AI systems or their outputs touch the EU market falls under it, no matter where that company is actually based. 

The 2026 timeline reset 

The Act phases in over several years, and 2026 brought a significant reshuffle. Through the “Digital Omnibus on AI,” the European Parliament and Council pushed back the toughest deadlines. The European Parliament adopted the changes on 16 June 2026, with the Council’s final approval following on 29 June. 

Two things are worth getting straight.  

What moved: the heavy, full-compliance obligations for high-risk AI systems, now due December 2027 for stand-alone systems and August 2028 for AI embedded in regulated products.  

What didn’t move: almost everything else. Banned practices have applied since February 2025, general-purpose-AI model rules since August 2025, and 2 August 2026 remains live for governance structures and most transparency duties. The Omnibus even added a new obligation – a ban on AI systems generating non-consensual intimate imagery, landing December 2026. 

The practical takeaway: the extra runway isn’t a reprieve. Building a proper compliance program takes 12–18 months, and other laws – GDPR, product liability, anti-discrimination rules – already apply to AI-driven harm today, regardless of the Act’s own calendar. 

Four risk tiers, one central question 

The Act sorts AI by risk.  

Unacceptable-risk practices – social scoring, subliminal manipulation, certain biometric surveillance, and now AI-generated non-consensual intimate imagery – are banned outright.  

High-risk systems, covering hiring, credit scoring, education assessment, critical infrastructure, and AI safety components in regulated products, carry the full obligation set.  

Limited-risk uses, like chatbots and generative content, need disclosure and labeling.  

Minimal-risk – the majority of everyday AI use – carries no new obligations at all; regulatory impact assessments estimate only 5–15% of AI systems ever qualify as high-risk. 

Classification isn’t optional guesswork. It requires a documented rationale, and it isn’t permanent. A tool’s risk tier can shift if its purpose or capability changes, so building in periodic review matters. 

Are you a producer, or a user? 

This is the question most businesses actually have, and where most explainers stop short. 

A provider builds an AI system, or has one built, and places it on the market under its own name. Anthropic, OpenAI, and Google are providers of their models, and so is any company that builds a product on top of one of those models. A deployer uses an AI system under its own authority in a professional context, running ChatGPT or Claude internally, for instance. 

If you’re only using subscription AI tools, you’re almost certainly a deployer, doing minimal or limited-risk work: drafting, summarizing, research, coding support. The heavy model-level compliance – technical documentation, training-data summaries, systemic-risk testing – sits with the model provider, not you.  

Your own duties are lighter: basic AI literacy for staff (already in force since February 2025), transparency when you deploy AI toward the public, and, only if you repurpose a tool for a high-risk use like screening job candidates or scoring creditworthiness, the fuller deployer obligations, now pushed to December 2027. 

There’s one trap worth flagging: putting your own brand on a high-risk system, materially modifying it, or repurposing a general-purpose tool into a high-risk use can legally turn you into a provider, with the full obligation set attached, even if you never set out to build anything. 

If you build and sell AI-powered products, your burden scales with risk tier.  

High-risk products trigger the full stack – risk management, data governance, technical documentation, conformity assessment, CE marking, registration, post-market monitoring.  

Non-high-risk conversational or generative products carry lighter transparency and watermarking duties. And if you train your own general-purpose model, you’re on the GPAI track: technical documentation, a copyright policy, a training-content summary, plus added testing and incident-reporting duties for the largest “systemic-risk” models – all already in force since August 2025. 

Market response and financial stakes 

Around 26 major AI providers – Microsoft, Google, Amazon, OpenAI, and Anthropic among them – signed the voluntary GPAI Code of Practice in 2025; Meta declined. Industry pushback was real and consequential: roughly 45 major European companies, including Airbus, ASML, and Siemens, publicly lobbied to “stop the clock” on the heaviest rules, and the 2026 Digital Omnibus delays are largely the result. 

The penalties, though, are not symbolic. The top tier reaches €35 million or 7% of global annual turnover for prohibited practices, with other major infringements capped at €15 million or 3%. For large groups, the turnover-based calculation, not the flat euro figure, is usually what matters, and AI Act fines can stack with GDPR and product-liability claims arising from the same incident. 

What to do now 

Whichever side of the provider/deployer line you sit on, the starting moves are the same: inventory every place AI is used or built in your organization, classify each instance by role and risk with a written rationale, assign clear ownership, document decisions as you make them rather than after the fact, train staff on real AI literacy, and build oversight and audit logging into anything high-risk from day one. 

The companies that navigate this comfortably won’t be the ones using the most AI – they’ll be the ones that can prove, on demand, that they’re using it responsibly. 

This article is for general information and does not constitute legal advice. Specific obligations depend on your systems, your role, and your jurisdiction consult qualified counsel for your situation. 

Author

Related Articles

Back to top button