The EU AI Act is the world's first comprehensive AI law. To many organisations that first sounds like effort and uncertainty. In reality the regulation is more predictable than its reputation suggests: it orders AI by risk and phases in its obligations in clear tiers over several years. Whoever understands this logic can plan calmly instead of reacting in a rush.
- The AI Act regulates AI by risk, not by technology
- Four risk tiers plus a separate regime for general-purpose AI
- The obligations phase in from 2024 to 2030
- The timeline has shifted: high-risk obligations only from December 2027, transparency obligations still from August 2026
- Developers, providers and users have distinct, clearly tailored obligations
The AI Act doesn't ask first: is this AI? It asks: how much harm can this system cause? From that single question almost everything else follows.
What is the EU AI Act?
The AI Act (officially Regulation (EU) 2024/1689) is a single rulebook for artificial intelligence across the entire European Union. Its core idea is simple: the greater the risk of an AI system to people, fundamental rights and safety, the stricter the requirements. A spam filter is treated differently from a system that decides on creditworthiness or job applications.
With this, Europe takes a different path from pure self-commitments. The AI Act creates binding, graduated rules that apply to everyone who provides or uses AI in the EU, regardless of where the company is based.
The four risk tiers
The heart of the regulation is a classification into risk tiers. Every AI system can be assigned to one of these tiers, and the tier decides which obligations apply.
Unacceptable risk
prohibitedSystems considered a clear threat to safety and fundamental rights, such as social scoring by authorities, manipulative system design or the untargeted scraping of facial images. These applications are banned in the EU.
High risk
strictly regulatedAI in sensitive areas such as recruitment, credit scoring, critical infrastructure, education or justice. Permitted, but only with risk management, documentation, human oversight and a conformity assessment.
Limited risk
transparency obligationSystems that interact with people or generate content, such as chatbots or AI-generated text and images. They must be clearly recognisable as AI to people.
Minimal risk
no specific obligationsThe vast majority of AI applications, such as spam filters, search functions or recommendations. No specific obligations apply here; voluntary standards are possible.
General-purpose AI
separate regimeVersatile foundation models such as large language models follow their own rules: documentation, transparency about training data and copyright. Particularly capable models with systemic risk face additional obligations.
Most AI applications in typical organisations fall into the lower tiers. That is an important reassurance: not every use of AI triggers extensive obligations. What matters is the honest assessment of which tier a system actually belongs to.
The roadmap: phased introduction until 2030
The AI Act does not apply all at once. Its obligations take effect in stages, so organisations have time to prepare. The interactive overview below shows the key dates. Pick a milestone and then a perspective to see what it means for developers, providers and users.
The AI Act over time
The obligations of the AI Act don't all arrive at once. They phase in over several years. Pick a milestone and then a perspective to see what concretely applies to you.
Transparency obligations (Article 50)
From now on, the transparency obligations under Article 50 apply: chatbots, deepfakes and AI-generated content must be recognisable as such. The high-risk obligations originally planned for this date were deferred by the Digital Omnibus to December 2027.
Implement transparency technically: label chatbots as AI and machine-readably mark generated audio, image, video and text content (watermarks).
Click a milestone, then switch between developer, provider and user. This overview is for orientation and does not replace legal advice.
Update, July 2026: the Digital Omnibus postpones the high-risk deadlines
Since this article first appeared, the timeline has changed. With the Digital Omnibus on AI, the first amendment package to the AI Act since 2024, the EU has pushed its most demanding obligations back significantly. The reason is sober: the harmonised standards and assessment tools that companies need for conformity were not ready in time.
Concretely: the obligations for standalone high-risk systems under Annex III, for example AI in hiring, credit or education, no longer apply on 2 August 2026 but only from 2 December 2027. That is sixteen additional months. For high-risk AI built into regulated products as a safety component (Annex I), the date moves from August 2027 to August 2028.
What was postponed are the high-risk obligations, not the entire AI Act. The transparency obligations under Article 50, the labelling of chatbots and AI-generated content, still apply from 2 August 2026. The prohibitions and the rules for large AI models also remain unchanged.
Two new prohibitions were added, effective 2 December 2026. They target particularly harmful forms of AI misuse that concern the personal rights of real people and the protection of children. The AI literacy obligation stays with companies.
In practice, the delay changes less than the headline suggests. It buys time, it does not remove the task. Anyone who relaxes now and postpones their own AI inventory loses exactly the sixteen months meant for preparation. Experts agree: do not bet on a second delay. My advice is the same as before. Do not panic, do not ignore it, but calmly work out which AI runs in your own house and which risk class it belongs to.
What the AI Act means for developers, providers and users
The regulation carefully distinguishes between roles. The same AI can be a product to build for one party and a tool to deploy for another. Three perspectives help with the classification.
For developers
Those who build AI carry the most design responsibility. The AI Act rewards an approach known as compliance by design: requirements are considered from the start, not bolted on afterwards. Concretely, that means logging decisions traceably, managing data cleanly, versioning models and prompts, and building in human intervention options. For high-risk applications, risk management, testing and cybersecurity come on top. Much of this is good engineering practice anyway.
For providers
Providers are those who place an AI system on the market under their own name. They carry the formal responsibility for conformity. For high-risk systems that means a conformity assessment, complete technical documentation, CE marking and registration in the EU database. On top of that comes the duty to monitor the system after market launch and respond to problems. Anyone integrating third-party components should secure their compliance contractually.
For users
Users, called deployers in the law, use AI within their own processes. They too have duties, especially for high-risk systems: they must use the systems as intended, ensure human oversight, keep logs and inform affected people. Across all tiers, the AI literacy obligation has applied since February 2025: whoever uses AI must understand what it does. That is less bureaucracy than common sense in binding form.
Large, versatile models such as language models follow their own regime. All providers of such models owe documentation, information about training data and a copyright policy. Models with systemic risk, that is particularly capable systems, face additional testing and reporting obligations.
What organisations should do now
- Create an inventory of all AI systems in use, including the unnoticed ones inside existing software
- Assign each system to a risk tier and clarify the relevant role, provider or user
- Build AI literacy in the team; this has been mandatory since February 2025
- For high-risk systems, start early with documentation and human oversight
- Implement transparency and clearly label chatbots and AI content
- Review contracts with AI providers for compliance and liability
„The AI Act is not an obstacle to innovation, it is a frame. Organisations that classify their AI early gain something more valuable than legal certainty: they gain clarity about what they are actually doing."Stefan Junge
What does this mean concretely for organisations?
The AI Act forces organisations to answer a question that is worth answering anyway: which AI do we use for what, and with what responsibility? Whoever can answer that has already done most of the compliance work. The pragmatic path runs not through panic, but through a structured inventory and an honest risk assessment. Much of what the AI Act requires overlaps with what good AI practice involves anyway: documentation, traceability and human oversight.
In conversations I see two reactions to the AI Act: paralysis or ignoring it. Both are expensive. My impression from many transformation projects is that regulation is rarely the actual problem. The problem is a lack of clarity about what AI is even running in your own house. Whoever creates that clarity finds that the AI Act is more of a map than a hurdle.
Frequently asked questions
What is the EU AI Act and when does it apply?
The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive AI law. It entered into force on 1 August 2024 and applies in stages: prohibitions and AI literacy since February 2025, obligations for general-purpose AI since August 2025, the transparency obligations from August 2026. The main obligations for high-risk systems were deferred by the Digital Omnibus from August 2026 to December 2027 (Annex I accordingly to August 2028).
Which risk tiers does the AI Act distinguish?
Four tiers: unacceptable risk (prohibited), high risk (strictly regulated), limited risk (transparency obligations, for example for chatbots) and minimal risk (no specific obligations). On top of that there is a separate regime for general-purpose AI models such as large language models.
What do AI providers and users have to do now?
First, an inventory of all AI systems in use and their classification by risk tier. Providers of high-risk systems need documentation, a conformity assessment and CE marking. Users must ensure human oversight, keep logs and train their staff in AI literacy.
Does the EU AI Act also apply to small and medium-sized companies?
Yes. The AI Act applies regardless of company size. There are, however, reliefs for SMEs, such as simplified documentation and proportionally capped fines. What matters is not size, but the risk tier of the AI in use.
