web analytics
AI Governance

EU AI Act

The World's First Comprehensive AI Law

The one-paragraph answer

The EU AI Act is the world's first comprehensive law regulating artificial intelligence. It passed in 2024 and applies in stages through 2027. It bans a short list of AI practices outright, forces heavy documentation on "high-risk" AI, and imposes transparency rules on generative AI. It reaches any company whose AI touches EU users, even from Texas. Fines run up to 35 million euros or 7 percent of global revenue, whichever is higher.

The pain the EU AI Act is causing our customers

A leadership team in Frisco does not think of themselves as a European company. They serve US customers. Their office is in Texas. Their board is domestic. Then a large enterprise customer in Germany sends over a vendor questionnaire. Question fourteen: "Confirm compliance with EU AI Act Article 26 obligations as a deployer of high-risk AI systems." The room goes quiet.

This is the extraterritorial reach that catches US companies off guard. The EU AI Act does not care where you are headquartered. It cares whether your AI touches people in the European Union. If a French user runs a resume through your AI hiring tool, if your AI credit-scoring product filters a Belgian applicant, if your AI chatbot serves an Irish customer, the EU AI Act applies to you. The pain is that most US executives learn this from a customer contract, an insurance renewal, or a regulatory notice, not from a proactive review. By then the timeline is short and the remediation is expensive.

What the EU AI Act actually is

The EU AI Act is a European Union regulation, formally titled Regulation (EU) 2024/1689. It was adopted in June 2024 and entered into force on August 1, 2024. It is the first horizontal (across all industries) binding AI law in the world. It creates one rulebook for AI providers, deployers, importers, distributors, and product manufacturers whose AI systems are placed on the EU market or whose output is used in the EU.

The regulation uses a risk-based approach. AI systems are sorted into four tiers by the risk they pose to health, safety, and fundamental rights. Each tier gets a different level of obligation. The tiers are: unacceptable risk (banned outright), high risk (heavy compliance), limited risk (transparency), and minimal risk (no obligation).

General-purpose AI models, meaning foundation models and large language models, get their own separate track. Providers of these models have documentation, copyright compliance, and transparency obligations even if they never build an application. Models with "systemic risk" (very large compute or scale) get extra safety-evaluation, incident-reporting, and cybersecurity obligations.

What the EU AI Act requires you to do

Article 5: Prohibited practices

Some AI uses are banned in the EU. This includes AI that manipulates people through subliminal techniques, exploits vulnerabilities of specific groups, does social scoring by public authorities, does predictive policing based solely on profiling, scrapes facial images from the internet, infers emotions in workplaces or schools, and does real-time remote biometric identification in public (with narrow exceptions). These prohibitions took effect February 2, 2025.

Articles 6-15: High-risk classification and obligations

An AI system is high-risk if it is a safety component of a regulated product (like medical devices) or if it falls into one of the categories listed in Annex III (employment, education, credit, insurance, law enforcement, migration, essential services, and certain public services). High-risk AI must have a risk management system, data governance, technical documentation, record-keeping, transparency, human oversight, and accuracy and cybersecurity by design. Providers must complete a conformity assessment and register the system in an EU database.

Article 26: Deployer obligations

Deployers are companies that use high-risk AI in their operations. Deployer obligations include using the system according to the provider's instructions, keeping the human oversight running, monitoring performance, keeping logs, and, in many cases, running a fundamental rights impact assessment before deployment. This is the article that catches most US companies. You do not have to build AI to be a deployer; you just have to use it.

Article 50: Transparency obligations for generative AI

Chatbots must disclose that a user is interacting with an AI. Deepfakes and synthetic content must be labeled as artificially generated. Generative AI outputs must be marked in a machine-readable format. This applies whether or not the underlying model is a foundation model or a fine-tuned application.

Articles 51-56: General-purpose AI models

Providers of general-purpose AI models must publish technical documentation, respect EU copyright law (including opt-outs for text and data mining), and publish a summary of training data. If the model has systemic risk (currently, models trained with more than 10 to the 25th floating point operations), the provider must also run model evaluations, track and report serious incidents, protect against cybersecurity risks, and follow the EU code of practice.

Article 15: Accuracy, robustness, and cybersecurity

Three obligations, not one, and the distinction has real consequences. High-risk AI systems must achieve an appropriate level of accuracy, robustness, and cybersecurity, and perform consistently in all three respects across their lifecycle. Robustness is where adversarial resilience lives. Cybersecurity is where conventional product security lives. They are not the same obligation and they are not discharged by the same evidence.

This matters because of a route that exists in the EU Cyber Resilience Act. CRA Article 12(1) allows a high-risk AI system that is also a product with digital elements to be deemed compliant with Article 15, provided it meets the CRA’s essential requirements and demonstrates the protection level in its EU declaration of conformity. Nearly every summary of that provision stops there, and stopping there is a mistake. The article opens with the words “without prejudice to the requirements relating to accuracy and robustness”. The deeming reaches the cybersecurity limb only. Accuracy and robustness survive intact and must be evidenced independently. A team that stands down its adversarial testing programme on the strength of a CRA declaration has discharged one third of Article 15 and kept the other two thirds without knowing it.

Article 43: Conformity assessment, and the assumption that is usually wrong

Ask most executives what "high-risk" means under the EU AI Act and they will tell you it means an external audit. For the categories most businesses actually fall into, that is false, and the error runs in both directions: some organisations are budgeting for an assessment they do not need, while others assume a notified body will catch what they missed and no notified body is coming.

Article 43(2) is unambiguous:

“For high-risk AI systems referred to in points 2 to 8 of Annex III, providers shall follow the conformity assessment procedure based on internal control as referred to in Annex VI, which does not provide for the involvement of a notified body.”

Annex III points 2 through 8 are critical infrastructure, education, employment, essential services including credit scoring, law enforcement, migration, and the administration of justice. That is nearly every high-risk AI system a normal company operates, and the route for all of it is self-assessment.

When a notified body actually is required

Two cases, and only two.

Annex III point 1, biometrics. Even here the provider gets a choice: where the harmonised standards have been applied, Annex VI internal control is available; where they have not been applied, or applied only in part, Annex VII with a notified body becomes mandatory.

AI embedded in an Annex I Section A product (machinery, medical devices, lifts, toys, and the rest). Here the AI Act’s requirements are folded into the sectoral conformity assessment that an existing notified body performs on the product anyway. The AI does not get its own separate audit; it gets absorbed into one that was already happening.

One further wrinkle worth knowing: where a high-risk system is intended for use by law enforcement, immigration, or asylum authorities, the market surveillance authority acts as the notified body.

Self-assessment is not a rubber stamp

The relief is procedural, not substantive. Annex VI still requires the provider to verify that the quality management system meets Article 17, to examine the technical documentation against every requirement in Chapter III Section 2, and to confirm that the design, development, and post-market monitoring processes are consistent with that documentation. Articles 9 through 15, the risk management system, data governance, technical documentation, record-keeping, transparency, human oversight, and accuracy, robustness and cybersecurity, all still bind in full.

What changes is who checks. Nobody external is coming to catch the gap. The evidence still has to exist, and it has to survive a market surveillance authority arriving after something has already gone wrong, which is a considerably worse moment to discover it is thin.

Article 43(6): the clause that could reverse all of this

The self-assessment route is not permanent, and the trigger for changing it is unusually candid. Article 43(6) empowers the Commission to move Annex III points 2 to 8 onto the Annex VII notified-body route by delegated act, taking into account, in the Act’s own words, the effectiveness of internal control and “the availability of adequate capacities and resources among notified bodies.”

Read that twice. Assessor capacity is written into the statute as a condition for tightening the regime. The obligation to self-assess for employment and credit AI today exists partly because the third-party capacity to assess it does not. If that capacity is built, the Commission has a standing power to require its use, and the organisations that treated self-assessment as a reason to build thin evidence will be the ones caught when it is exercised.

Build the evidence base as though a notified body will read it. Whether one ever does is the Commission’s decision, not yours.

Article 73: Serious incident reporting

Providers of high-risk AI must report serious incidents to the market surveillance authority within 15 days (immediately for widespread infringements). Serious means death, serious harm to health, serious infrastructure disruption, or serious infringement of fundamental rights.

The EU AI Act timeline you need to plan around

The law came into force August 1, 2024, but obligations phase in through 2028. February 2, 2025 was the deadline for prohibited practices and AI literacy obligations. August 2, 2025 was the deadline for general-purpose AI model obligations and governance provisions. August 2, 2026 is the enforcement date for Article 50 transparency obligations: chatbot disclosure, machine-readable marking of AI-generated content, and clear labeling of deepfakes. AI systems placed on the EU market before August 2, 2026 have until December 2, 2026 to comply with Article 50(2) watermarking.

The Digital Omnibus is now final. The European Parliament endorsed it on June 16, 2026 and the Council gave final approval on June 29, 2026. Stand-alone Annex III high-risk obligations are deferred from August 2, 2026 to December 2, 2027, a sixteen-month reprieve. High-risk AI embedded in regulated Annex I products moves from August 2, 2027 to August 2, 2028. These are no longer proposals; they are the compliance dates.

Two things did not move. Article 50 transparency still applies from August 2, 2026, with only the narrow Article 50(2) watermarking requirement for already-deployed systems getting a grace period to December 2, 2026. And the Act's architecture is untouched: the four risk tiers, the conformity assessment regime, the GPAI track, and the AI Office's oversight role all stand. This is a deferral, not a dismantling.

The Omnibus also adds a prohibited practice. AI-generated non-consensual intimate imagery (so-called nudifiers) and child sexual abuse material are now banned under Article 5, from December 2, 2026, at the maximum penalty tier. Any organisation whose models can synthesise images or audio needs technical and contractual safeguards in place before that date. Member State regulatory sandboxes are pushed to August 2027.

A separate consultation on the European Commission's draft guidelines for Article 6 high-risk classification closes July 23, 2026. The draft interprets "intended purpose" broadly (provider instructions, promotional materials, and technical documentation all count) and treats conformity assessments involving only internal controls as within scope, which is broader than many businesses anticipated. Clients with EU exposure should review the draft and consider submitting comments.

In practice, if your organization touches EU users with AI, you should be operating as if the full EU AI Act is in force today, with Article 50 as the immediate compliance surface.

Why the EU AI Act matters to you

The EU AI Act matters even if you never plan to sell in Europe, for four reasons.

First, extraterritorial reach. If a European user interacts with your AI, you are in scope. This is the same "long-arm" pattern as GDPR: your web analytics, your hiring tool, your chatbot, your credit product, or your generative-AI feature can all trigger EU jurisdiction without you meaning to.

Second, fines are severe. Prohibited practices carry fines up to 35 million euros or 7 percent of worldwide annual turnover, whichever is higher. High-risk obligations carry up to 15 million euros or 3 percent. Even a small US company can face material exposure if a violation is proven.

Third, the EU AI Act is becoming the global template. Brazil, Canada, the UK, and multiple US states are drafting laws that mirror its risk-based structure. Building an AI program that aligns to the EU AI Act today is the closest thing to a hedge against the next five years of AI regulation.

Fourth, procurement is already flowing through it. Large European buyers are asking US vendors for EU AI Act compliance statements. If you do not have one, you lose the deal. This is happening in software, professional services, financial services, healthcare, and manufacturing right now.

What the research says about EU AI Act

The academic literature on EU AI Act is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.

“concerns about their impact on individual and societal wellbeing, particularly due to the lack of transparency and accountability”

That is the gap between having AI and governing it. The second finding is the one that tends to change the room.

“all those who are involved in the research, development and maintenance of AI systems have social and ethical responsibilities”

Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about EU AI Act arrives from the board, the buyer, or the regulator.

How to prepare for the EU AI Act: a 5-step path

This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.

  1. Establish whether the Act reaches you. It does if your AI is placed on the EU market, or if its output is used by people in the EU. Your headquarters is irrelevant. A single French user of your hiring tool is enough.
  2. Classify each system by risk tier. Prohibited, high-risk, limited-risk, or minimal. Annex III is the list that catches most businesses: employment, credit, insurance, education, essential services. Document the classification and the reasoning.
  3. Work out whether you are a provider or a deployer. Buying an off-the-shelf model makes you a deployer, and Article 26 deployer obligations still bind you. You cannot pass the whole duty upstream to OpenAI or Microsoft.
  4. Meet Article 50 now. Transparency obligations are enforceable from 2 August 2026: chatbot disclosure, machine-readable marking of AI-generated content, deepfake labelling. This is the nearest deadline and the one most companies have not touched.
  5. Build the high-risk file against the deferred dates. Stand-alone Annex III high-risk obligations were deferred to 2 December 2027 and embedded-product high-risk to 2 August 2028. The extra runway is not a reprieve; the documentation burden is heavy and starting late is how firms end up non-compliant on the date.

Done in this order, EU AI Act becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.

Frequently asked questions about the EU AI Act

Does the EU AI Act apply to my US company?

Yes, if you either place an AI system on the EU market, use AI whose output affects people in the EU, or are a deployer of AI in the EU. Location of your company does not matter; location of your users does.

What if we only use AI tools from vendors like OpenAI or Microsoft?

You are a deployer. Deployer obligations still apply. You cannot pass the entire compliance responsibility upstream to the model provider. You are responsible for how you use the model.

Are we exempt because our AI is not "high-risk"?

If your AI is truly minimal risk (a spam filter, a game NPC), most obligations do not apply. But even minimal-risk AI must comply with prohibited practices and, if it is generative, with Article 50 transparency. Very few businesses have zero EU AI Act obligations.

How does the EU AI Act interact with ISO/IEC 42001 and NIST AI RMF?

Alignment to ISO/IEC 42001 is treated as evidence of compliance with many EU AI Act obligations. NIST AI RMF alignment is also useful documentation. Neither substitutes for full EU AI Act compliance, but both dramatically reduce the lift.

Where does the EU AI Act show up in The AI Risk & Governance Review™?

In Chapter 8 and in Appendix L (the AI Governance Framework Crosswalk™) of Volume III of The Operating Discipline for AI Library™. Every operating artifact in the Library (the AI Usage Policy, the Accountability Matrix, the risk register, the dossier structure) maps to specific EU AI Act articles. Reaching defensible EU AI Act readiness is the six-step 6-Step Review Process™ that the book codifies.

Primary sources on EU AI Act

The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning EU AI Act that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.

Ready to see where you stand?

The AI Business Enablement Audit™ measures your organization against every framework in this library, including EU AI Act, and delivers a defensible governance dossier. Start or finish your audit below.

Start or finish your AI Audit →
Schedule a Free AI Consultation