LinkedInInstagramXTikTok

Does the EU AI Act Apply to Your Company? A 2026 Readiness Checklist

The EU Artificial Intelligence Act is the world’s first comprehensive law on AI — and it reaches far beyond Europe’s borders. If your company builds, sells, or simply uses AI in connection with the EU market, it almost certainly applies to you. The good news: in May 2026 the EU agreed to postpone the toughest deadlines, giving companies more time to prepare. The risk: many businesses read “delay” as “ignore” — and that is exactly the wrong conclusion.

Here is what you actually need to know, in plain language.

What is the EU AI Act?

The AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024. Instead of regulating the technology itself, it regulates risk: the higher the potential harm of an AI system, the stricter the rules. It applies across every sector — finance, healthcare, HR, marketing, manufacturing — wherever AI is involved.

Does it apply to you? (Almost certainly, yes)

The Act applies to several roles, not just developers:

  • Providers — you develop an AI system or general-purpose AI model and place it on the EU market under your own name or brand.
  • Deployers — you use an AI system under your own authority in a professional context. Most companies fall here — for example, using an AI tool to screen job applicants.
  • Importers and distributors — you bring AI systems into, or make them available on, the EU market.

Crucially, the Act is extraterritorial. A company based outside the EU is still covered if the output of its AI system is used in the EU. A US or UK firm whose AI is used by European customers cannot assume it is exempt.

The four risk levels

  1. Unacceptable risk — prohibited. A small set of practices is banned outright, such as social scoring, manipulative or exploitative AI, untargeted scraping of facial images, and emotion recognition in the workplace or education (with narrow exceptions). These prohibitions have applied since 2 February 2025.
  2. High risk — heavily regulated. AI used in areas like recruitment and HR, credit scoring, education, critical infrastructure, biometrics, and law enforcement. These systems face the most obligations: risk management, data governance, technical documentation, human oversight, transparency, and conformity assessment.
  3. Limited risk — transparency only. Chatbots must tell users they are talking to a machine; AI-generated or manipulated content (deepfakes) must be labelled.
  4. Minimal risk — no specific obligations. The vast majority of everyday AI (spam filters, recommendation engines, AI in games) falls here.

The updated timeline (this changed in 2026)

This is where many companies are working from outdated information. Under the Digital Omnibus on AI, provisionally agreed on 7 May 2026 and expected to be formally adopted during 2026, several key deadlines were pushed back:

  • 2 February 2025 — Prohibited practices apply. (In force.)
  • 2 August 2025 — Obligations for general-purpose AI (GPAI) models apply. (In force.)
  • 2 December 2026 — Two new prohibitions take effect (AI used to generate child sexual abuse material and non-consensual intimate imagery).
  • 2 December 2027 — High-risk obligations for stand-alone Annex III systems (recruitment, credit scoring, education, law enforcement and similar) — postponed from the original August 2026.
  • 2 August 2028 — High-risk obligations for AI embedded in regulated products under Annex I (medical devices, machinery, vehicles) — postponed from August 2027.

The extra time is real, but it exists for a reason: high-risk compliance (testing, documentation, third-party assessment) takes many months to build. Companies that start in 2027 will already be late.

The penalties

The AI Act has GDPR-level fines:

  • Up to EUR 35 million or 7% of total worldwide annual turnover for breaching the prohibited-practice rules.
  • Up to EUR 15 million or 3% for breaching most other obligations (including high-risk requirements).
  • Up to EUR 7.5 million or 1.5% for supplying incorrect or misleading information to authorities.

Whichever figure is higher applies (with lower caps for SMEs and start-ups).

Your readiness checklist

  1. Inventory your AI. List every AI system you build or use — including tools embedded in software you already license.
  2. Classify each system into one of the four risk levels.
  3. Identify your role (provider, deployer, importer, distributor) for each system — your obligations depend on it.
  4. Flag prohibited uses and stop them now; these rules are already in force.
  5. Map high-risk systems to the December 2027 / August 2028 deadlines and plan the documentation, human oversight and assessment work backwards from there.
  6. Meet transparency duties today: label AI chatbots and AI-generated content.
  7. Assign ownership — appoint someone accountable for AI governance and keep a written record of your assessment.

What to do now

“Delayed” is not “cancelled.” The prohibitions and transparency rules already apply, and high-risk preparation is a multi-month project. The companies that come out ahead will treat the postponement as breathing room to build properly — not an excuse to wait.

Not sure where your AI tools land? Get in touch and book your free first hour — we will map your obligations with you, in plain language.

This article is general information, not legal advice. For an assessment of your specific situation, talk to a qualified lawyer.

Related reading

EU AI Act · GDPR · Business lawyer in Stockholm

Leave a Reply

Your email address will not be published. Required fields are marked *


0Cart0,00 

No products in the cart.

Return to shop