EU AI Act: what the AI regulation changes for you
Who is affected, four risk levels, the timeline after the July 2026 omnibus, obligations, penalties, French authorities and first steps.
The EU AI Act is the European regulation on artificial intelligence (Regulation (EU) 2024/1689): it governs how AI systems are placed on the market and used in the European Union according to the level of risk they pose. It bans certain practices, imposes strict requirements on “high-risk” systems and transparency obligations on others, and applies to software vendors as well as organisations that use AI. As of 14 September 2026, part of the text already applies; high-risk obligations were pushed back to late 2027 and 2028 by the Digital Omnibus adopted in July 2026.
What is the EU AI Act?
Adopted on 13 June 2024 and published in the Official Journal on 12 July 2024, the Artificial Intelligence Act is the first general legal framework dedicated to AI. Like the GDPR, it is a regulation: it applies directly in every Member State, without transposition.
It has two aims: protecting people's health, safety and fundamental rights, and creating a single market for AI with the same rules across Europe. It does not regulate a technology as such but uses: the same language model can be harmless in a writing aid and high-risk in software that screens job applications.
What is an “AI system” under the regulation?
Article 3 defines an AI system as a machine-based system, with some degree of autonomy, that “infers” from the input it receives how to generate outputs such as predictions, content, recommendations or decisions. This ability to infer is what distinguishes it from conventional software whose rules were all written by hand. On 6 February 2025 the Commission published guidelines on this definition: a spreadsheet with formulas or a basic statistical calculation is in principle excluded, while machine learning and large language models are included.
What is out of scope
The regulation does not apply to systems used exclusively for military, defence or national security purposes, to pure scientific research, or to personal non-professional use. It does apply to operators established outside the EU when their system is placed on the EU market or its output is used in the EU.
Who is affected by the AI Act?
The AI Act allocates obligations according to the role played in the value chain. The same organisation can hold several roles: a software vendor that builds a third-party model into its product is the provider of its system, and a deployer of the AI tools it uses internally.
| Role | Simplified definition | Example |
|---|---|---|
| Provider | Develops an AI system or model (or has it developed) and places it on the market or puts it into service under its own name | Vendor of candidate screening software |
| Deployer | Uses an AI system under its own authority, in a professional context | Hospital, bank, local authority or SME using that software |
| Importer | Established in the EU, places on the market a system from a provider established outside the EU | Exclusive EU distributor of a US solution |
| Distributor | Makes the system available on the market, without being the provider or importer | Integrator or software reseller |
| Authorised representative | Represents in the EU a provider established outside the EU | Firm appointed in writing by the provider |
Watch out for the change of role under Article 25: a deployer, distributor or importer becomes a provider, with all the obligations that go with it, if it puts its name on a high-risk system, substantially modifies it or changes its intended purpose so that it becomes high-risk. A business unit that “retrains” a tool to assess employees can thus slip into the most demanding regime without realising it.
Most organisations will above all be deployers. Their obligations are covered in a dedicated article: AI Act obligations for organisations that use AI.
The four risk levels of the AI Act
At the heart of the regulation is a graduated approach: the higher the risk to people, the heavier the obligations. It is usually shown as a four-level pyramid, plus a separate regime for general-purpose AI models.
The four risk levels of the AI Act
-
Unacceptable risk Prohibited
Social scoring, manipulation, emotion recognition at work or in schools, facial image scraping… (Article 5).
-
High risk Strict requirements
Recruitment, credit, education, essential services, safety components of regulated products (Article 6, Annexes I and III).
-
Transparency risk Inform
Chatbots, generated content, deepfakes, emotion recognition (Article 50).
-
Minimal risk No specific obligation
Spam filters, video games, internal writing aids: the vast majority of uses.
Separately: general-purpose AI models (Articles 51 to 55), with their own obligations, reinforced above a “systemic risk” threshold.
Unacceptable risk: prohibited practices
Article 5 bans eight practices deemed contrary to EU values: manipulation through subliminal or deceptive techniques, exploitation of vulnerabilities linked to age, disability or social situation, social scoring, predicting crime based solely on profiling, untargeted scraping of facial images to build recognition databases, emotion recognition in the workplace and in education (except for medical or safety reasons), biometric categorisation to infer sensitive data, and real-time remote biometric identification in public spaces for law enforcement, subject to narrow exceptions. The Commission clarified their scope in guidelines of 4 February 2025. The 2026 omnibus adds two bans, applicable from 2 December 2026: systems that generate realistic intimate images of an identifiable person without consent, and systems that produce child sexual abuse material.
High risk: strict requirements
A system is high-risk either because it is a safety component of an already regulated product (medical device, toy, lift…), or because it is used in a sensitive area listed in Annex III: biometrics, critical infrastructure, education, employment, access to essential services such as credit or social benefits, law enforcement, migration, justice and democratic processes. The two classification routes, the exceptions and the requirements are detailed in our article high-risk AI systems: does the AI Act apply to you?
Transparency risk: informing people
Article 50 requires informing people that they are interacting with an AI (a chatbot, for example), marking generated content in a machine-readable way, disclosing deepfakes and informing people exposed to an emotion recognition or biometric categorisation system.
Minimal risk: no specific obligation
Spam filters, recommendations in a video game, spell checkers: the vast majority of systems have no specific obligation under the AI Act, apart from AI literacy (see below). The regulation encourages voluntary codes of conduct.
EU AI Act timeline as of 14 September 2026
The AI Act entered into force on 1 August 2024 and applies in stages. This timeline was amended by Regulation (EU) 2026/1744, the “Digital Omnibus on AI”. Proposed by the Commission on 19 November 2025 to simplify digital rules, it reached political agreement in early May 2026, was adopted on 8 July 2026, published in the Official Journal on 24 July and entered into force on 27 July 2026, just ahead of the 2 August deadline. The main change: high-risk requirements are postponed to fixed dates, whereas the Commission had first proposed linking their application to the availability of technical standards.
| Date | What applies | Status on 14 September 2026 |
|---|---|---|
| 2 February 2025 | Prohibited practices (Art. 5), AI literacy (Art. 4) | Applicable |
| 2 August 2025 | General-purpose AI models, governance, notified bodies, penalty regime | Applicable |
| 2 August 2026 | General application: transparency (Art. 50), market surveillance, Commission powers to fine general-purpose AI providers | Applicable |
| 2 December 2026 | New prohibitions (non-consensual intimate imagery, child sexual abuse material); marking of generated content for systems placed on the market before 2 August 2026 | Upcoming |
| 2 August 2027 | Compliance of general-purpose AI models placed on the market before 2 August 2025; at least one national regulatory sandbox per Member State | Upcoming |
| 2 December 2027 | Requirements for Annex III high-risk systems (originally 2 August 2026) | Postponed by the omnibus |
| 2 August 2028 | Requirements for high-risk systems embedded in Annex I products (originally 2 August 2027) | Postponed by the omnibus |
Two remarks. First, the postponement only concerns high-risk systems: other obligations have not moved, and content marking only received a four-month grace period for systems already on the market. Second, several implementing texts are still pending: on 19 May 2026 the Commission put out for consultation draft guidelines on the classification of high-risk systems and plans to adopt the final version by the end of 2026. Harmonised standards, drafted by CEN and CENELEC, are not all available yet, which justified the delay.
Key obligations under the AI regulation
For everyone: AI literacy (Article 4)
Since 2 February 2025, providers and deployers must ensure that their staff, and people using AI on their behalf, sufficiently understand the systems they handle: their capabilities, limits and risks. The omnibus softened the wording: they must now “take measures to support” the development of AI literacy, without requiring a specific level for each person. The obligation remains, as a best-efforts duty to be scaled to the uses.
For providers of high-risk systems
Before placing a high-risk system on the market, the provider must meet the requirements of Articles 9 to 15 (risk management, data quality, technical documentation, record-keeping, transparency towards users, human oversight, accuracy, robustness and cybersecurity), operate a quality management system, undergo conformity assessment, draw up an EU declaration of conformity, affix the CE marking, register the system in the EU database, then carry out post-market monitoring and report serious incidents.
For deployers of high-risk systems
The user organisation must follow the instructions for use, assign human oversight to competent people, ensure the input data it provides is relevant, monitor operation and alert the provider in case of problems, keep logs for at least six months, inform workers before deploying such a system in the workplace and inform people who are subject to a decision. Public bodies, private entities providing public services, and banks and insurers for credit scoring and life and health insurance pricing must also carry out a fundamental rights impact assessment (Article 27).
For uses subject to transparency
Since 2 August 2026, chatbot providers must disclose that people are talking to a machine, generative system providers must mark the content produced, and deployers must disclose deepfakes and generated text published to inform the public, unless it has undergone human review under editorial responsibility. The Commission supported these rules with a Code of Practice on marking and labelling AI-generated content, finalised in June 2026, and guidelines published in July 2026.
General-purpose AI: foundation models and the code of practice
General-purpose AI (GPAI) models are large models able to perform a wide range of tasks and built into many products, such as language models. Since 2 August 2025, their providers must keep technical documentation, inform the providers that integrate them, put in place a copyright policy and publish a summary of training data using a Commission template. Models with “systemic risk”, presumed above 1025 floating-point operations used for training, have additional obligations: evaluations and adversarial testing, risk management, serious incident reporting, cybersecurity.
To help providers, the Commission published on 10 July 2025 a General-Purpose AI Code of Practice in three chapters (transparency, copyright, safety and security). It is voluntary but provides a presumption of conformity. The official list of signatories includes Mistral AI, OpenAI, Anthropic, Google, Microsoft, Amazon and IBM; xAI signed only the safety and security chapter. Since 2 August 2026, the Commission's AI Office can fine model providers, and models placed on the market before 2 August 2025 have until 2 August 2027 to comply.
For a user organisation, these rules have an indirect but useful effect: the documentation that model providers must supply is raw material for your own risk analyses and supplier questionnaires.
EU AI Act penalties
Article 99 sets maximum administrative fines at three levels. For each level, the higher of the fixed amount and the percentage of worldwide annual turnover applies.
| Breach | Maximum |
|---|---|
| Prohibited practice (Article 5) | €35 million or 7% of worldwide annual turnover |
| Other obligations (high risk, transparency, operator roles, notified bodies) | €15 million or 3% |
| Incorrect, incomplete or misleading information supplied to authorities | €7.5 million or 1% |
| General-purpose AI model providers (Article 101, Commission fines) | €15 million or 3% |
For SMEs and start-ups, the lower of the two amounts applies; the omnibus extended this treatment to small mid-caps. Authorities take into account gravity, duration, cooperation and the measures taken to mitigate harm. Each Member State decides whether, and to what extent, fines can be imposed on public authorities and bodies.
Governance and authorities: who enforces the AI Act?
At EU level
The AI Office, part of the Commission, supervises general-purpose AI models. The omnibus also gives it exclusive competence over systems built on a model from the same provider and over those embedded in very large online platforms. The European AI Board brings Member States together for consistent application, supported by a scientific panel of independent experts and an advisory forum.
In France: a decentralised scheme, not yet adopted
Each Member State had to designate its authorities by 2 August 2025. France chose to rely on existing regulators. The scheme presented by the government on 9 September 2025 provides for:
- the DGCCRF (consumer protection authority) to coordinate market surveillance and act as single point of contact, and the DGE for strategic coordination and representation on the European AI Board;
- the CNIL (data protection authority) for several prohibited practices (predictive policing, facial image scraping, emotion recognition at work and in schools, biometric categorisation) and for high-risk systems in biometrics, employment, education, law enforcement and migration;
- the DGCCRF and Arcom (audiovisual and digital regulator) for manipulative practices and transparency of generated content, the ACPR for credit and insurance, and the supreme courts for the justice system;
- existing sector authorities, such as ANSM for medical devices, for AI embedded in regulated products;
- ANSSI and PEReN for technical support on cybersecurity and AI expertise.
This scheme must be enshrined in law. It is part of a bill adapting French law to EU law (known as DDADUE), adopted by the Senate on 18 February 2026. In early September 2026, the bill had not yet been examined by the National Assembly, and we found no final adoption as of the date of this article (14 September 2026). In practice, the CNIL remains fully competent under the GDPR whenever an AI system processes personal data.
How the AI Act fits with the GDPR, NIS 2 and the Cyber Resilience Act
The AI Act adds to existing texts rather than replacing them. For a CISO or DPO, the challenge is to pool efforts rather than stack them.
| Text | Overlap with the AI Act | What can be pooled |
|---|---|---|
| GDPR | Any AI system processing personal data remains subject to the GDPR; the omnibus allows, under strict conditions, processing sensitive data to detect and correct bias | The fundamental rights impact assessment can reuse parts of the DPIA (Article 27(4)) |
| NIS 2 | Essential and important entities must manage the risks to their information systems, including AI-based ones, and to their supply chain | Risk analysis, supplier assessment, incident management |
| Cyber Resilience Act | A high-risk AI system that is also a product with digital elements and meets the CRA's essential requirements is deemed to meet the cybersecurity requirements of Article 15 of the AI Act | Security documentation, vulnerability handling |
To go further: our guide to the DPIA, our article on NIS 2, the one on the Cyber Resilience Act and, for AI-specific security requirements (data poisoning, prompt injection), our article on AI cybersecurity and Article 15. In its Q&A updated in August 2026, the CNIL points out that the AI Act does not replace GDPR requirements.
Where to start: first steps towards compliance
The high-risk postponement buys time, but not enough to wait: a serious inventory, contract reviews and staff training take several months. Here is a six-step approach that also serves the obligations already in force.
- Inventory AI uses. Purchased tools, AI features added to existing software, generative assistants used by staff, in-house developments: for each, record the purpose, the data used, the people affected and the business owner.
- Identify your role for each system: provider, deployer, importer, distributor. Check that no modification or change of purpose turns you into a provider.
- Classify each use: prohibited practice to stop, high risk, transparency, minimal risk. Document your reasoning, especially when you conclude that an Annex III use is not high-risk.
- Organise AI literacy: general awareness, deeper training for people who exercise human oversight or buy AI solutions, rules for using generative tools.
- Bring AI into your existing processes: risk analyses, DPIAs, supplier assessment (documentation, contract clauses, instructions for use), incident management.
- Set up governance: a lead, a validation circuit for new uses, an up-to-date register and indicators for management, in line with your GRC approach.
For the use of AI within compliance work itself, see also our article AI and GRC: what automation changes, and its limits.
How Phinasoft helps
Phinasoft is governance, risk and compliance software. It does not replace the legal analysis of your uses, but it supports the steps above:
- the compliance campaigns module assesses scopes (subsidiaries, departments, teams) against a list of requirements you choose from your frameworks: you can set out the AI Act obligations that concern you, collect justifications and evidence, then track action plans;
- the risk analysis module follows the EBIOS Risk Manager method or your own, to include the risks specific to an AI system and track measures over time;
- the vendor risk management module sends your suppliers, including AI solution providers, questionnaires built from your requirements through a dedicated portal;
- the GDPR module manages the record of processing activities and DPIAs, essential as soon as an AI system processes personal data.
To see how these modules fit together on a real case, book a demo.
Summary
A risk-based regulation
The AI Act bans a few practices, tightly regulates high-risk systems, requires transparency for certain uses and leaves the rest alone. It covers providers as well as organisations that use AI.
A timeline pushed back, not suspended
Prohibitions, AI literacy, general-purpose AI rules and transparency already apply. The July 2026 omnibus moved high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
Start with an inventory
List your AI uses, classify them, identify your role for each, train your teams and bring AI into risk analyses, DPIAs and supplier assessments: this work pays off now.
Frequently asked questions
What is the EU AI Act?
The AI Act is Regulation (EU) 2024/1689 of 13 June 2024. It sets common rules for placing on the market and using AI systems in the EU, following a risk-based approach: prohibited practices, high-risk systems subject to strict requirements, transparency obligations and a specific regime for general-purpose AI models.
When does the AI Act apply?
It entered into force on 1 August 2024 and applies in stages. Prohibitions and the AI literacy obligation have applied since 2 February 2025, general-purpose AI rules since 2 August 2025, and transparency and enforcement since 2 August 2026. Since the Digital Omnibus (Regulation (EU) 2026/1744, in force on 27 July 2026), high-risk requirements will apply on 2 December 2027 for Annex III uses and 2 August 2028 for Annex I products.
Does the AI Act apply to my company if it does not develop AI?
Yes, as soon as it uses an AI system in a professional context: it is then a “deployer”. It must in particular support the AI literacy of its staff, meet the transparency obligations that apply to it and, if it uses a high-risk system, follow the provider's instructions, ensure human oversight and keep the logs.
What are the penalties under the AI Act?
Up to €35 million or 7% of worldwide annual turnover for a prohibited practice, up to €15 million or 3% for most other breaches, and up to €7.5 million or 1% for supplying incorrect information to authorities. The higher amount applies, except for SMEs and, since the omnibus, small mid-caps, for which the lower amount applies.
Who enforces the AI Act in France?
As of 14 September 2026, the designation of authorities is not complete. The scheme presented by the French government in September 2025 gives coordination to the DGCCRF (consumer protection authority) and the DGE, a central role to the CNIL (biometrics, employment, education, several prohibited practices) and sector-specific powers to the ACPR, Arcom, ANSM and the supreme courts. It is part of a bill adopted by the Senate on 18 February 2026, which was still awaiting examination by the National Assembly in early September 2026.
Does the AI Act replace the GDPR?
No. The GDPR still applies to any processing of personal data, including by an AI system. The two texts complement each other: the fundamental rights impact assessment required by the AI Act can, for example, reuse parts of the data protection impact assessment (DPIA).
Sources (14)
- EUR-Lex — Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (AI Act)
- EUR-Lex — Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI)
- European Commission — AI regulatory framework (application timeline)
- European Commission — Guidelines on the AI system definition (6 February 2025)
- European Commission — Guidelines on prohibited AI practices (4 February 2025)
- European Commission — General-Purpose AI Code of Practice (10 July 2025)
- European Commission — Targeted consultation on draft guidelines for the classification of high-risk AI systems (19 May 2026)
- European Commission — Code of Practice on marking and labelling of AI-generated content
- DGE — Competent authorities for implementing the EU AI Act in France (9 September 2025, in French)
- Banque des Territoires (Localtis) — The Senate approves AI regulation designations (18 February 2026, in French)
- CNIL — Entry into force of the EU AI Act: first Q&A (updated 17 August 2026, in French)
- Cuatrecasas — Digital Omnibus on AI: Key Changes to the AI Act (28 July 2026)
- Gibson Dunn — EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes (27 May 2026)
- EUR-Lex — General Data Protection Regulation (GDPR)
A platform and service that adapt to you
Our platform is designed for fine-tuned configuration and broad adaptability to your needs.