EU AI Act

The EU AI Act, explained for the people who have to comply with it

21 July 2026 · 8 min

The most useful thing to understand about the EU AI Act in the summer of 2026 is that the deadline everyone circled has quietly moved, and the deadlines nobody circled have not. For two years, boards were told that 2 August 2026 was the day the hard rules on high-risk AI arrived. As of July 2026, that is no longer true. A late amendment to the law, the Digital Omnibus, has pushed the heaviest high-risk obligations out by more than a year. The danger is that firms read the headline, exhale, and switch off. That would be a mistake, because several obligations are already live, already enforceable, and already carrying fines large enough to matter to a mid-sized regulated business.

This is a guide for the people who actually have to answer for compliance: the compliance officer, the CFO, the board member who signs off on the risk register. It assumes you are smart and busy, not that you are a lawyer.

What the Act is, in one paragraph

The EU AI Act is a product-safety law dressed as a technology law. It does not regulate "AI" as a single thing. It sorts uses of AI by how much harm they could do to people, and attaches obligations accordingly. Like the GDPR, it reaches beyond Europe: if your AI system is used in the EU or affects people in the EU, it applies to you regardless of where your firm sits. For a finance, insurance, payments or fintech business, that reach is the whole point, because the uses the Act treats most seriously, credit scoring, insurance pricing, fraud and identity checks, hiring, are exactly the ones you run.

The four risk tiers, with real examples

The Act is usually described as four tiers. That is a helpful mental model as long as you remember it is a simplification. In practice the law runs several independent checks that can stack on top of each other. A single system can be caught by more than one.

Unacceptable risk (prohibited). These uses are banned outright under Article 5. They include social scoring by public authorities, systems that use manipulative or subliminal techniques to distort behaviour, exploitation of the vulnerabilities of specific groups, untargeted scraping of facial images to build recognition databases, and most real-time remote biometric identification in public spaces. Emotion recognition in the workplace and in schools is also prohibited, with narrow exceptions. For most financial firms these are not day-to-day tools, but "we would never do that" is not a compliance position. You need to be able to show you checked.

High risk. This is the tier that carries the real weight for regulated firms. A system is high risk if it is a safety component of a product already covered by EU product-safety law (Annex I), or if it falls into one of the sensitive use areas listed in Annex III. Annex III is where finance lives. It captures AI used to evaluate creditworthiness or credit scores, AI used for risk assessment and pricing in life and health insurance, and AI used in recruitment and worker management. Biometric identification and critical-infrastructure safety also sit here. If you use a model to decide who gets a loan, what premium someone pays, or which job applicants advance, assume high risk until you have documented otherwise.

Limited risk (transparency). "Limited risk" is not a formal category in the text. It is shorthand for systems that trigger the transparency duties in Article 50. If a customer is talking to a chatbot, they must be told it is a machine. If content is AI-generated, including synthetic images, audio or video, it must be disclosed and, in most cases, machine-marked as artificial. A bank running a customer-service assistant or generating marketing imagery is in this territory.

Minimal risk. Everything else: spam filters, inventory forecasting, the AI baked into ordinary software. No specific obligations. Most of what any firm runs sits here, which is worth remembering when the compliance workload starts to feel infinite.

What "high risk" actually demands

When a system is high risk, the Act asks for the kind of discipline a regulated firm already recognises from model risk management, applied with more paperwork and a legal edge. The core duties for providers of high-risk systems include:

  • A risk management system that runs across the whole lifecycle, not a one-off sign-off.
  • Data governance: training and testing data that is relevant, representative and checked for bias, with a documented lineage.
  • Technical documentation detailed enough for a regulator to understand how the system works and why it is compliant, prepared before the system goes to market.
  • Record-keeping and logging so events can be traced after the fact.
  • Human oversight: a real person who can understand the output, override it, and stop the system. Not a rubber stamp.
  • Accuracy, security and resilience appropriate to the system's purpose, tested and evidenced.
  • A conformity assessment before deployment, plus registration in an EU database, and post-market monitoring once the system is live.

Deployers, the firms using a system built by someone else, carry lighter but real duties: use the system as intended, keep humans in the loop, monitor it, and hold on to the logs. If you buy a credit-decisioning model from a vendor, you do not escape the Act. You inherit a defined slice of it, and you should be pushing the vendor for the documentation that lets you meet your part.

What just changed, and what did not

Here is the part that requires care, because it is fresh and the sources are still settling.

In the first half of 2026 the EU agreed the Digital Omnibus, the first significant amendment to the AI Act since it passed. Negotiators reached a provisional deal in early May, the European Parliament adopted the text on 16 June 2026, and the Council gave final approval on 29 June. Reporting indicates the act was signed on 8 July 2026 and is completing publication in the Official Journal, after which it enters into force. Treat the exact procedural status as "all but final" rather than settled, and confirm against EUR-Lex before you rely on it in a board paper.

What the Omnibus does is defer, not dismantle. The heavy obligations for standalone high-risk systems under Annex III, the ones covering credit and insurance, move from 2 August 2026 to 2 December 2027. High-risk AI embedded in regulated products under Annex I moves to 2 August 2028. The architecture of the law is unchanged. You have more time, not a reprieve.

What did not move is as important as what did:

  • Prohibited practices have applied since 2 February 2025.
  • AI literacy under Article 4 has also applied since 2 February 2025. Providers and deployers must ensure staff and contractors who work with AI have a sufficient understanding of it. This is the broadest duty in the Act, it is live now, and the Omnibus left it in place after a proposal to soften it was rejected.
  • General-purpose AI model rules and the governance and penalty machinery have applied since 2 August 2025.
  • Transparency obligations under Article 50 arrive on schedule around 2 August 2026, with a short grace period into December 2026 for marking existing synthetic content.
  • Enforcement by national market-surveillance authorities begins in August 2026.

So the fines are real now, and the supervisors are switching on now, even as the high-risk paperwork deadline sits in late 2027.

The penalties, precisely

The numbers are set in Article 99, and they are tiered to the seriousness of the breach:

  • Using a prohibited system: up to €35 million or 7% of total worldwide annual turnover, whichever is higher.
  • Breaching other obligations, including the high-risk requirements and the transparency duties: up to €15 million or 3% of worldwide annual turnover.
  • Supplying incorrect or misleading information to authorities: up to €7.5 million or 1%.

For SMEs and start-ups, the fine is the lower of the fixed sum and the percentage, not the higher. These are ceilings, not tariffs, and regulators must be proportionate. But 7% of global turnover is the kind of figure that ends up in an annual report.

Key dates

  • 2 February 2025 · Prohibited practices and AI literacy (Article 4) in force. Live.
  • 2 August 2025 · GPAI model rules, governance structures and the penalty regime in force. Live.
  • 2 August 2026 · Transparency duties (Article 50) apply; national enforcement begins.
  • 2 December 2027 · High-risk obligations for Annex III standalone systems (credit, insurance, employment). Deferred from 2026 by the Omnibus.
  • 2 August 2028 · High-risk obligations for AI embedded in regulated products (Annex I).

What to do in the next ninety days

The extra time is a gift only if you use it. A sensible sequence:

  1. Inventory every AI system. Bought, built, and buried inside vendor tools. You cannot classify what you cannot see, and the shadow AI in a marketing team or a broker desk is usually where the surprise lives.
  2. Classify each one by risk. Prohibited, high, transparency, minimal. Write down the reasoning, especially for anything you decide is not high risk, because that judgement is exactly what a supervisor will ask you to defend.
  3. Run a gap analysis on the high-risk items. Compare what the Act asks for against what you actually have: documentation, data lineage, human oversight, logging, testing.
  4. Stand up governance. Name an owner. Put AI on the risk committee's agenda. Decide who signs off before a new system goes live.
  5. Deliver AI literacy now. It is already required, it is cheap, and it is the easiest thing to evidence. Train the people who touch these systems and keep a record that you did.

None of this needs to wait for the final text in the Official Journal, because the parts that bind you today were never in doubt.

If you want a faster read on where you stand, a short readiness diagnostic can map your systems against the tiers and flag the handful that carry real exposure. But the honest first step costs nothing: open a spreadsheet, list your AI, and start asking which column each system belongs in. Most firms discover the answer is less frightening, and more specific, than the headlines suggested.

This article is general information, current as of July 2026, and not legal advice. The Digital Omnibus was completing its final procedural steps as this was written; verify dates against EUR-Lex and the European Commission before relying on them.

← All insights

Where do you stand?

A short diagnostic tells you exactly where you are on the EU AI Act, and what to do next. No pressure.

Book an intro call →