The EU AI Act in Practice: What It Means for Companies (2026)
The EU AI Act entered into force on 1 August 2024 with a risk-based approach (prohibited / high-risk / limited / minimal risk). The Digital Omnibus proposal defers high-risk obligations to 2 December 2027, but prohibited practices and GPAI rules apply earlier. Most companies are affected as…
On this page
TL;DR: The EU AI Act entered into force on 1 August 2024 with a risk-based approach (prohibited / high-risk / limited / minimal risk). The Digital Omnibus proposal defers high-risk obligations to 2 December 2027, but prohibited practices and GPAI rules apply earlier. Most companies are affected as deployers (users) — preparation should start now.
Why this matters to you
The AI Act does not only apply to AI developers. If your company uses AI — for example a customer-service chatbot, a CV screener, a credit-scoring or document-analysis tool — obligations may arise. Supplier contracts increasingly include AI Act expectations. The good news: the deferred high-risk deadline gives time for structured preparation.
What is the EU AI Act?
🔴 Legal requirement. The AI Act (Regulation (EU) 2024/1689) is the EU's first comprehensive artificial-intelligence regulation. It entered into force on 1 August 2024 and introduces a risk-based approach:
| Risk level | Example | Main expectation |
|---|---|---|
| Prohibited | manipulative techniques, certain mass surveillance | ban |
| High-risk (Annex III) | HR/recruitment, lending, critical infrastructure | strict compliance (risk management, data, human oversight, documentation) |
| Limited | chatbot, synthetic content | transparency (labelling obligation) |
| Minimal | spam filter, game AI | no specific obligation |
Separate rules apply to general-purpose AI models (GPAI).
The deadlines and the Digital Omnibus
🔴 Legal requirement / moving. The Digital Omnibus on AI was published by the Commission on 19 November 2025. As a result:
- High-risk (Annex III) obligations are deferred to 2 December 2027.
- Product-embedded (Annex I) systems to 2 August 2028.
- Prohibited practices and GPAI-model obligations apply earlier.
⚪ Important caveat. If the Omnibus is not formally adopted before 2 August 2026, the original AI Act deadlines apply. A provisional political agreement was reached on 6 May 2026. The topic therefore needs continuous monitoring (see news monitoring).
Flagged review item: final application dates to be fixed in the article after the Omnibus is officially published.
Provider or deployer? — the role decides
🔴 Obligations depend on your company's role:
- Provider (developer/distributor): responsible for the system's conformity.
- Deployer (user): responsible for appropriate, intended use, human oversight, and transparency.
Most SMEs are deployers — so an inventory, classification, and a correct usage policy are the most important first steps.
What this means in practice — AI inventory and classification in 6 steps
- Inventory of AI systems — what we use, for what, on what data.
- Clarify the role — provider or deployer for each system.
- Risk classification — prohibited / high-risk / limited / minimal.
- Map obligations by classification (transparency, human oversight, documentation).
- AI usage policy and human-oversight process.
- Governance framework — see An AI Governance Framework.
Risk and opportunity
Risk: significant fines, restricted market access, reputational damage, and loss of regulated customers. Opportunity: early, orderly AI governance builds trust, accelerates sales to enterprise and public-sector customers, and reduces later transition costs.
How Regcytech helps
Regcytech supports the AI-system inventory, risk classification, mapping of deployer obligations, and the design of an AI-governance framework and documentation — preparing for the AI Act and ISO/IEC 42001. (Not legal advice.)
FAQ
When do we have to comply with the AI Act? Prohibited practices and GPAI rules already apply; high-risk obligations are deferred — via the Digital Omnibus — to 2 December 2027 (if the Omnibus is adopted in time).
What is high-risk AI? Uses listed in Annex III, such as HR/recruitment, credit scoring, critical infrastructure — subject to strict compliance requirements.
Does it apply if we only use AI? Yes — as a user (deployer) you also have obligations, mainly around correct use, human oversight, and transparency.
Related content
Trust signals
- Expert reviewed — Regcytech
- Last reviewed:
- Next review:
- Regulatory / standard status: Current within the stated review window.
- Related service: AI governance
- Related analysis: An AI Governance Framework for Leaders: Governing Responsible AI
- Related knowledge article: ESG and VSME for Hungarian SMEs: What Is Mandatory, What Is Recommended (2026)
- Author
- Regcytech
- Editorial status
- Published
- Update cycle
- monthly
- Last reviewed
- Next review
Sources
- Regulation (EU) 2024/1689 (AI Act) – EUR-Lex
- Digital Omnibus on AI – European Commission / EP Legislative Train
- European Commission, digital-strategy
This content is general information and does not constitute legal advice. Regcytech Kft. is not a law firm, accredited auditor, or certification body. Seek professional advice for specific matters.
Related services
Related knowledge
Related analysis
NEXT STEP
AI Governance consultation
A short call clarifies AI Act exposure, documentation gaps and responsible AI governance.
Request AI consultation