Skip to main content

EU AI Act Guide

The EU AI Act is law. Does your business know what it requires?

The Act entered into force in August 2024 and applies in stages. The next compliance date is 2 December 2026. High-risk obligations follow on 2 December 2027 and 2 August 2028, with penalties reaching €35 million or 7% of global annual turnover.

Most organisations operating AI tools have not yet mapped their compliance obligations. Article 4, the AI literacy obligation, has applied since 2 February 2025.

Take the ACTS Assessment

Free risk tier classification; no email required for your first result

€35M or 7%
of global revenue
Maximum fine: high-risk violations
€15M or 3%
of global revenue
Fine for other violations
4
risk tiers
Defined by the Act
2 Dec 2026
next compliance date
New prohibitions and synthetic-content transparency

What the EU AI Act actually is

The EU AI Act is a regulatory framework adopted by the European Union that governs how AI systems are developed, deployed, and used across the EU. It classifies AI systems into 4 risk tiers and assigns compliance obligations based on where a system falls. It applies to any organisation that deploys, operates, procures, or places AI systems on the EU market, not only to companies that build AI.

The Act was adopted by the European Parliament and Council and published on June 12, 2024. It entered into force on August 1, 2024. It is the first comprehensive AI regulatory framework of its kind, built to ensure AI systems operating in the EU are safe, transparent, and subject to meaningful human oversight.

The Act is not a future requirement in the way many organisations assume. Parts of it are already in force. The Article 4 AI literacy obligation has applied since 2 February 2025. High-risk obligations were rescheduled by the June 2026 digital omnibus agreement and now apply from 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for systems embedded in regulated products. The exact entry into force of that change depends on publication in the Official Journal, so verify the final dates at EUR-Lex.

The 4 risk tiers, explained plainly

Prohibited

Unacceptable Risk

Who falls here
Systems that manipulate users through subliminal techniques, exploit the vulnerabilities of specific groups, conduct real-time remote biometric surveillance of individuals in public spaces (with narrow law-enforcement exceptions), or enable social scoring by government authorities.
What the Act requires
Complete prohibition. These systems cannot be deployed in the EU under any circumstances. The list is not fixed: further prohibitions, covering non-consensual intimate imagery and CSAM generation, apply from 2 December 2026.
Consequence
Deployment is a violation regardless of intent or claimed benefit.

Strictly Regulated

High Risk

Who falls here
AI systems used in critical infrastructure, employment and workforce management (hiring, performance evaluation, task allocation), education, access to essential services (credit, insurance, public benefits), biometric categorisation, border control, administration of justice, and AI safety components in regulated products such as machinery, medical devices, and vehicles.
What the Act requires
Conformity assessment before deployment, registration in the EU AI database, technical documentation, human oversight mechanisms, data governance, ongoing monitoring, and transparency to deployers and users. Stand-alone systems listed in Annex III apply from 2 December 2027; systems embedded as safety components in regulated products (Annex I) apply from 2 August 2028.
Consequence
Non-compliance can result in penalties of up to €35 million or 7% of global annual turnover. Deploying a non-compliant high-risk system is itself a violation.

Transparency Obligations

Limited Risk

Who falls here
Chatbots, AI-generated synthetic content (images, audio, video), deep-fake generation tools.
What the Act requires
Disclosure. Users must be told they are interacting with an AI system. AI-generated content must be labelled as such. Providers of generative AI systems placed on the market before 2 August 2026 have until 2 December 2026 to meet the Article 50(2) machine-readable marking duty.
Consequence
Penalties reach €15 million or 3% of global annual turnover for transparency violations.

No Mandatory Obligations

Minimal Risk

Who falls here
The large majority of AI tools currently in use: spam filters, AI-powered recommendation engines, productivity and drafting assistants, basic analytics tools.
What the Act requires
No specific mandatory compliance requirements under the current framework. Good-practice codes of conduct exist and may become more relevant as the regulatory landscape develops.
Consequence
Minimal regulatory exposure, provided the system is correctly classified. Misclassification is the risk: assuming Minimal when a system's function or context of use places it in a higher tier.

This requirement is not a future deadline. It is already in force.

Article 4 of the EU AI Act requires any organisation deploying or operating AI systems to “take measures to support the development of AI literacy” among the staff working with those systems. This obligation applies to providers and deployers alike, and it has applied since 2 February 2025. The wording was softened by the June 2026 digital omnibus agreement, from ensuring a sufficient level to supporting development, but the obligation is still live.

AI literacy is not defined as a fixed exam or certification. It means employees understand the capabilities and limitations of the AI systems they use, the risks of misuse, and how to apply sound judgment when AI informs a decision. For a quality technician using an AI inspection tool, it means knowing what the tool can get wrong and when to override it. For a manager, it includes understanding the risks of AI-assisted decisions in their team.

According to ERT and McKinsey, 42% of Europeans currently lack sufficient digital skills. The baseline for documented AI literacy in a regulated operating context is considerably higher than general digital skills, and closing that gap is already your organisation's legal obligation.

The Act does not prescribe how literacy must be documented. The expectation is that organisations can demonstrate, if audited, that relevant personnel have received appropriate instruction and understand their responsibilities.

What is in force and when

  1. Act enters into force

    The Act becomes law across the EU. Its obligations then phase in on the dates that follow.

  2. Prohibitions and Article 4 apply

    Unacceptable-risk AI systems may not be deployed in the EU. Systems that manipulate users through subliminal techniques, enable social scoring, or conduct real-time biometric surveillance are banned. Article 4 also applies from this date: providers and deployers take measures to support the development of AI literacy among staff working with their AI systems.

  3. GPAI model obligations apply

    General-Purpose AI model obligations apply. National governance authorities are required to be operational in each member state.

  4. New prohibitions and transparency retrofit

    New Article 5 prohibitions apply, covering non-consensual intimate imagery and CSAM generation. Providers of generative AI systems placed on the market before 2 August 2026 must also meet the Article 50(2) transparency duty, marking synthetic content in a machine-readable way.

  5. Stand-alone high-risk systems

    High-risk AI systems listed in Annex III, such as employment, credit, and essential-services use cases, become subject to the Chapter III obligations. This is the deadline most operating businesses work back from.

  6. High-risk embedded in products

    High-risk AI systems embedded as safety components in regulated products (Annex I) become subject to their obligations. Most relevant for manufacturers in automotive, machinery, and medical device sectors.

If you operate an industrial facility, the Act is likely already relevant.

Manufacturing organisations that use AI in quality management, supplier evaluation, production planning, workforce scheduling, or safety-relevant processes are operating in territory that requires classification. The risk tier is not determined by what the tool is called. It is determined by what it does and where its output is used.

AI in safety-relevant or regulated processes

Quality inspection systems, predictive maintenance tools, and AI used in production scheduling may qualify as safety components under existing EU product legislation, placing them in scope for Annex I obligations from 2 August 2028. Classification must happen well before that. If you are not yet certain what tier your systems fall into, that uncertainty is itself a compliance gap.

Deployers, not just developers

If your organisation uses AI tools built by a third party, you are still a deployer under the Act. Compliance obligations rest with the deployer based on how the system is used, not only with the vendor who built it. Off-the-shelf tools are not exempt from classification requirements.

TISAX and EU AI Act overlap

Tier-1 and Tier-2 automotive suppliers operating under TISAX face obligations under 2 separate frameworks. TISAX covers information security. The EU AI Act covers AI system governance, risk classification, and transparency requirements. They do not satisfy each other, but they can be addressed efficiently through a single coordinated compliance engagement.

Productivity AI tools deployed across the office

Many manufacturers have rolled out or are evaluating Microsoft Copilot, company-licensed ChatGPT, or similar tools across management and office teams. Drafting and summarization use cases typically fall in the Minimal Risk tier, but that does not eliminate the Article 4 literacy obligation, which applies to every employee using these tools in their role and has applied since 2 February 2025. More importantly, risk tier is set by the use case, not the tool name. Copilot used in a hiring process, a performance review, or a safety-relevant operational decision sits in a different compliance category than Copilot used to draft a supplier email. Review use cases, not just tools.

Employees using personal AI tools without approval

Shadow AI, employees using personal ChatGPT accounts or other unapproved tools with company data, is a compliance gap most organisations have not yet documented a response to. The Act's deployer obligations apply to how AI is used in an employee's work, not only to officially sanctioned tools. An organisation without a written AI usage policy has no documented governance structure around how its workforce is using AI and no audit defense. The minimum required position: a policy defining which tools are approved, what data boundaries apply, what the Article 4 literacy standard is for relevant roles, and what falls outside permitted use.

Article 4 on the factory floor

The AI literacy obligation applies to any employee operating an AI system in a relevant role, not only to managers or compliance teams. Production operators using AI-assisted scheduling tools, quality technicians using AI inspection systems, and supervisors relying on AI-generated shift reports are all in scope.

Find out your compliance exposure in under 5 minutes.

ACTS, AI Compliance Tier Score, is a free interactive assessment. Answer 3 to 4 questions about the AI systems you operate and your current compliance posture. Get an instant risk tier classification and the beginning of a compliance gap picture. No email required for the initial result.

The full ACTS report, which maps your responses to specific EU AI Act requirement areas and identifies your highest-priority gaps, is available after a single email field.

The ACTS result is a starting point for understanding your exposure. It is not a formal compliance assessment or legal opinion. A full gap analysis requires your actual AI system inventory and operating context.

Three steps. In this order.

  1. Classify your AI systems by risk tier.

    Inventory every AI system your organisation deploys or uses, including tools procured from third-party vendors. For each system, determine which risk tier applies based on what it does and where its output is used. High-Risk classification carries the most demanding obligations and the longest lead time to close.

  2. Run a compliance gap analysis.

    Once you know each system's tier, map your current policies, documentation, oversight mechanisms, and training practices against what the Act requires for that tier. The ACTS assessment gives a starting point for this mapping. A thorough gap analysis requires your actual system inventory and full operating context.

  3. Remediate: with a plan, with help, or both.

    Compliance is not a single document. It is a set of written policies, technical records, trained personnel, and governance processes that can be demonstrated on request. Build a roadmap from your current state to what the Act requires. If the gap is significant, starting now is not cautious; it is the minimum required.

    30 minutes. You describe your AI systems and current documentation state. We tell you which programme fits your timeline and what reaching each compliance date looks like from where you are.

Frequently asked questions

Ready to understand your compliance exposure?

30 minutes. No prep needed. Bring what you know about your AI systems.