Definition
The EU AI Act – formally Regulation (EU) 2024/1689 – is the first comprehensive rulebook for artificial intelligence in the European Union. It follows a risk-based approach: what is regulated is not the technology itself but the intended purpose. The greater the potential harm to health, safety or fundamental rights, the stricter the requirements.
A few applications are prohibited, a clearly defined set counts as high-risk, another group is subject to transparency rules – and for most everyday use, nothing changes legally. The practical question is therefore never “are we affected by the AI Act?”, but “which class does this specific use case fall into, and what is our role in it?”.
Origin and purpose
The regulation was adopted in 2024, entered into force on 1 August 2024 and has been applying in stages since February 2025. It aims to protect fundamental rights and safety while creating a single market for AI, so that providers do not have to serve 27 national rulebooks.
The legislator deliberately modelled it on product safety law: a high-risk AI system is treated much like a machine or a medical device – risk management, documented data quality, technical documentation, logging, human oversight and a conformity assessment before it reaches the market. That explains why the AI Act initially feels foreign: it thinks in products and roles, not in departments.
The risk classes
Prohibited practices (Article 5). These include social scoring and the untargeted scraping of facial images from the internet or from CCTV footage to build facial recognition databases. Also prohibited are inferring emotions in the workplace and in education, except for medical or safety reasons, and manipulative systems that deliberately impair a person's ability to make an informed decision. These bans have applied since 2 February 2025.
High-risk AI systems (Article 6). There are two routes into this class. One runs via Annex I: AI as a safety component in products that already require EU conformity assessment. The other runs via Annex III and is the more relevant one for most organizations: named areas of use such as recruitment and employment, education, critical infrastructure, access to essential services such as credit scoring, law enforcement, migration and justice. An AI-supported CV screening tool falls under it; an AI assistant that drafts meeting minutes generally does not.
Transparency obligations (Article 50). People must be able to recognize that they are talking to a machine. Synthetically generated or manipulated audio, image, video and text content must be machine-readably marked. These obligations have applied since 2 August 2026. A transition period until 2 December 2026 exists only for the marking duty under Article 50(2), and only for providers of generating systems – the chatbot disclosure duty applies to deployers with no transition period.
General-purpose AI models (GPAI) have carried their own obligations since 2 August 2025, covering documentation, copyright and training data; these apply to model providers, not to the organizations using such models. Everything else – the bulk of day-to-day AI use – carries no specific obligations under the AI Act. Data protection, employment and copyright law apply regardless.
Provider or deployer: the decisive question
The AI Act attaches obligations to roles, not to industries. A provider develops an AI system, or has it developed, and places it on the market under its own name; most obligations sit here. A deployer uses an AI system under its own authority in a professional capacity – which applies to most organizations that buy AI rather than build it. Deployer obligations are lighter: use the system as intended, ensure human oversight, control input data, retain logs, inform affected people.
The role is not fixed. Anyone who passes on a purchased high-risk system under their own name, modifies it substantially or changes its purpose becomes a provider under Article 25. This shift is the one most often overlooked in practice.
Deadlines at a glance
2 February 2025 – prohibited practices and the duty to support AI literacy (Article 4)
2 August 2025 – obligations for GPAI models
2 August 2026 – general start of application, transparency obligations under Article 50
2 December 2026 – two additional prohibitions; Article 50(2) marking for legacy systems
2 December 2027 – high-risk obligations for Annex III systems
2 August 2028 – high-risk obligations for Annex I systems
2 August 2030 – legacy high-risk systems intended for use by public authorities
Article 99 provides for fines of up to EUR 35 million or 7 % of worldwide annual turnover for prohibited practices, up to EUR 15 million or 3 % for other infringements and up to EUR 7.5 million or 1 % for supplying incorrect information to authorities – whichever is higher, and the lower figure for SMEs and small mid-caps. In Germany, the Federal Network Agency has been the competent market surveillance authority since 29 July 2026; it also runs an AI service desk and an AI regulatory sandbox.
What the Digital Omnibus changed
Regulation (EU) 2026/1744 of 8 July 2026 adjusted the original rules. High-risk obligations were postponed – Annex III to 2 December 2027, Annex I to 2 August 2028. This buys time but does not change the direction of travel.
Article 4 on AI literacy was softened. The obligation has existed since February 2025 and remains, but is now worded differently: providers and deployers “shall take measures to support the development of AI literacy of their staff”. The text explicitly adds that this does not require them to guarantee any particular level of AI literacy for any individual. What has gone is the target of a “sufficient level” of AI literacy, not the obligation. Article 99(1) now also expressly names administrative fines as a possible penalty; warnings and non-monetary measures were already there.
Common misconceptions
- - “The AI Act bans AI.” Only a few clearly named practices are prohibited under Article 5. Most day-to-day use in organizations falls into the minimal-risk class and carries no specific obligations under the regulation.
- - “This does not concern us, we do not develop AI.” Most obligations fall on deployers – everyone who buys AI and uses it professionally. You additionally become a provider if you pass a system on under your own name, modify it substantially or change its purpose.
- - “This only applies from December 2027.” Only the high-risk obligations were postponed. The prohibitions and the duty to support AI literacy have applied since February 2025, the transparency obligations since August 2026.
- - “The Digital Omnibus abolished the AI literacy duty.” It remains in force, only worded more weakly: the target of a “sufficient level” of AI literacy has gone. Nobody has to guarantee a particular level of competence – but measures are still required.
- - “High-risk means dangerous technology.” Classification depends on the intended purpose, not on the model. The same language model can be high-risk in CV pre-screening and carry no specific obligations when drafting meeting minutes.
Example from practice
An organization introduces an AI-supported tool that pre-sorts incoming job applications. The class: employment and recruitment are listed in Annex III, so the tool is a high-risk system. The role: the organization buys and configures the tool – it is a deployer, as long as it does not pass the tool on under its own name or change its purpose. The deadline: the full high-risk obligations apply from 2 December 2027.
That is no reason to wait: the duty to support AI literacy, data protection law, works council codetermination and the duty to inform applicants all apply today. An organization that postpones preparation will face requirements in late 2027 that cannot be retrofitted in a few weeks.
Criticism and limitations
The AI Act is criticized from two directions. Industry associations consider the compliance burden too high, particularly for smaller companies – the Digital Omnibus is the answer to that. Civil rights organizations see the same amendment as a weakening of rules before they have had any effect.
The practical difficulty is classification: whether a piece of software is an “AI system” within the meaning of the regulation, whether a use case falls under Annex III, and whether a change already counts as a substantial modification can rarely be answered from the text alone. This article provides a professional overview and does not constitute legal advice.
The CALADE perspective
We frequently see organizations treat the AI Act as a legal project: an opinion is commissioned, filed – and nothing changes in daily work. That falls short. At the decisive points, the regulation calls for organizational answers: who decides which AI application is introduced? Who carries human oversight – with what competence, authority and time? How does an application even become visible before it goes live?
Our approach is the same as in any transformation: first create transparency about actual usage, then clarify roles and decision paths, then build competence – and let documentation emerge as a by-product of clean processes rather than as a separate project. We work through this in our training SAFe AI: Compliance, Governance and Security.
Related terms
AI literacy – Article 4 of the AI Act
Human oversight – Article 14
Shadow AI
Tokens – processing units in AI language models
Sources: Regulation (EU) 2024/1689 (AI Act) and Regulation (EU) 2026/1744 (Digital Omnibus Regulation on AI), EUR-Lex; Bundesnetzagentur on national supervision under the KI-MIG act. As of September 2026.
Summary
The EU AI Act regulates AI by risk, not by technology. What matters is not whether an organization is affected but which class a specific use case falls into and whether it acts as provider or deployer. Prohibitions and the duty to support AI literacy have applied since February 2025 and transparency obligations since August 2026; following the Digital Omnibus, high-risk obligations apply from December 2027 and August 2028 respectively.