AI & GovernancePractical guide

The EU AI Act in Practice: What It Means for Companies (2026)

The EU AI Act entered into force on 1 August 2024 with a risk-based approach (prohibited / high-risk / limited / minimal risk). The Digital Omnibus proposal defers high-risk obligations to 2 December 2027, but prohibited practices and GPAI rules apply earlier. Most companies are affected as…

3 min readReviewed: 24 July 2026
On this page

TL;DR: The EU AI Act entered into force on 1 August 2024 with a risk-based approach (prohibited / high-risk / limited / minimal risk). The Digital Omnibus proposal defers high-risk obligations to 2 December 2027, but prohibited practices and GPAI rules apply earlier. Most companies are affected as deployers (users) — preparation should start now.

Why this matters to you

The AI Act does not only apply to AI developers. If your company uses AI — for example a customer-service chatbot, a CV screener, a credit-scoring or document-analysis tool — obligations may arise. Supplier contracts increasingly include AI Act expectations. The good news: the deferred high-risk deadline gives time for structured preparation.

What is the EU AI Act?

🔴 Legal requirement. The AI Act (Regulation (EU) 2024/1689) is the EU's first comprehensive artificial-intelligence regulation. It entered into force on 1 August 2024 and introduces a risk-based approach:

Risk levelExampleMain expectation
Prohibitedmanipulative techniques, certain mass surveillanceban
High-risk (Annex III)HR/recruitment, lending, critical infrastructurestrict compliance (risk management, data, human oversight, documentation)
Limitedchatbot, synthetic contenttransparency (labelling obligation)
Minimalspam filter, game AIno specific obligation

Separate rules apply to general-purpose AI models (GPAI).

The deadlines and the Digital Omnibus

🔴 Legal requirement / moving. The Digital Omnibus on AI was published by the Commission on 19 November 2025. As a result:

  • High-risk (Annex III) obligations are deferred to 2 December 2027.
  • Product-embedded (Annex I) systems to 2 August 2028.
  • Prohibited practices and GPAI-model obligations apply earlier.

Important caveat. If the Omnibus is not formally adopted before 2 August 2026, the original AI Act deadlines apply. A provisional political agreement was reached on 6 May 2026. The topic therefore needs continuous monitoring (see news monitoring).

Flagged review item: final application dates to be fixed in the article after the Omnibus is officially published.

Provider or deployer? — the role decides

🔴 Obligations depend on your company's role:

  • Provider (developer/distributor): responsible for the system's conformity.
  • Deployer (user): responsible for appropriate, intended use, human oversight, and transparency.

Most SMEs are deployers — so an inventory, classification, and a correct usage policy are the most important first steps.

What this means in practice — AI inventory and classification in 6 steps

  1. Inventory of AI systems — what we use, for what, on what data.
  2. Clarify the role — provider or deployer for each system.
  3. Risk classification — prohibited / high-risk / limited / minimal.
  4. Map obligations by classification (transparency, human oversight, documentation).
  5. AI usage policy and human-oversight process.
  6. Governance framework — see An AI Governance Framework.

Risk and opportunity

Risk: significant fines, restricted market access, reputational damage, and loss of regulated customers. Opportunity: early, orderly AI governance builds trust, accelerates sales to enterprise and public-sector customers, and reduces later transition costs.

How Regcytech helps

Regcytech supports the AI-system inventory, risk classification, mapping of deployer obligations, and the design of an AI-governance framework and documentation — preparing for the AI Act and ISO/IEC 42001. (Not legal advice.)

FAQ

When do we have to comply with the AI Act? Prohibited practices and GPAI rules already apply; high-risk obligations are deferred — via the Digital Omnibus — to 2 December 2027 (if the Omnibus is adopted in time).

What is high-risk AI? Uses listed in Annex III, such as HR/recruitment, credit scoring, critical infrastructure — subject to strict compliance requirements.

Does it apply if we only use AI? Yes — as a user (deployer) you also have obligations, mainly around correct use, human oversight, and transparency.

Trust signals

Author
Regcytech
Editorial status
Published
Update cycle
monthly
Last reviewed
Next review

Sources

  • Regulation (EU) 2024/1689 (AI Act) – EUR-Lex
  • Digital Omnibus on AI – European Commission / EP Legislative Train
  • European Commission, digital-strategy

This content is general information and does not constitute legal advice. Regcytech Kft. is not a law firm, accredited auditor, or certification body. Seek professional advice for specific matters.

ShareLinkedInE-mail

NEXT STEP

AI Governance consultation

A short call clarifies AI Act exposure, documentation gaps and responsible AI governance.

Request AI consultation