
On 2 August 2026, the European Commission formally began enforcing the EU AI Act, Regulation (EU) 2024/1689, the first binding legal framework for artificial intelligence anywhere in the world. But this was not the beginning but more an arrival: the regulation entered into force two years earlier, in August 2024, and has been gradually rolling out ever since. Companies that assumed they had time to prepare are now inside the enforcement window. Now the questions I'd like to raise and answer in this guide is what Europe's AI regulation actually requires, of whom, and by when?
The Act sorts AI systems by the harm they could plausibly cause and assigns obligations to both the companies that build them and the companies that deploy them. Those obligations are being phased in across a three-year schedule that is still running. To understand what the Act means for a company, it helps to start with these categories and the obligations attached to each.
The first rules to take effect were the bluntest. Under Chapter II of the regulation, certain uses of AI became illegal across the European Union on 2 February 2025, regardless of how the system was built or who deployed it. Those systems are banned outright, without any path to compliance through additional scrutiny or assessment.
The prohibited list covers AI that manipulates people through subliminal techniques they cannot consciously detect, systems that exploit the vulnerabilities of specific groups such as children or people with disabilities to distort their behaviour, and most uses of real-time remote biometric identification in publicly accessible spaces. Social scoring by public authorities, assigning citizens a generalised rating based on their behaviour, is prohibited, as is AI that infers a person's emotions in workplace or educational contexts. The prohibition on predictive policing tools, which assess a person's likelihood of committing a crime based purely on personal characteristics rather than actual behaviour, sits in the same category.
Baker McKenzie's EU Regulation on AI resource notes that Chapter I general provisions and Chapter II prohibitions have been applicable since 2 February 2025, making these the only parts of the Act that had been live for more than a year before the broader enforcement machinery came into force. Any company that has been running a system in these categories since that date has been operating outside the law.
Below the prohibited category, the Act organises AI into tiers based on potential harm, and those tiers determine what a company must do before placing a system on the market or putting it to work.
High-risk AI covers systems used in consequential contexts: recruiting and employment decisions, credit scoring, essential services, educational assessment, administration of justice, border control, and the operation of critical infrastructure. Systems embedded in products already regulated under existing EU product safety law, medical devices, vehicles, machinery, also fall into the high-risk category.
The obligations for these systems include mandatory conformity assessments, risk management documentation, logging requirements that allow decisions to be traced and reviewed, human oversight mechanisms, and registration in a public EU database before deployment. For companies that build these systems, the documentation burden is substantial; for companies that deploy them under licence from a third party, that deployment does not remove their own obligations. Building the requirement into a system satisfies the provider's obligation. The deployer is responsible for what users actually encounter.
Then there is the middle tier, which covers limited-risk systems, primarily those that interact directly with people. A chatbot, a deepfake generator, a synthetic voice system: each requires disclosure to users, who must be told they are interacting with an AI. Conformity assessment is not required for these systems, but disclosure is mandatory and enforceable.This is where the transparency rules that came into force on 2 August 2026 apply. The European Commission's enforcement announcement states that AI systems must now tell users when they are interacting with AI and when content has been generated or altered by it.
The disclosure is not a suggestion; national market surveillance authorities and the European AI Office can now issue fines of up to €15 million, or 3 percent of global annual turnover, for companies that fail to comply.
Most AI tools used in low-stakes contexts, content recommendation, spam filters, simple automation, fall into a third, minimal-risk category and carry no mandatory obligations beyond whatever existing law already applies.
When the regulation was being finalised, large language models presented a classification problem. A general-purpose AI model is not, by itself, a product with a defined use case: it is infrastructure that other companies build on top of. Treating it as a single high-risk system made no sense; ignoring it made less. The Act resolved this with a dedicated chapter that applies specifically to providers of general-purpose AI models, and those rules came into force on 2 August 2025.
The requirements scale with capability. Providers of all general-purpose AI models must produce technical documentation, comply with EU copyright law, and publish a summary of the data used in training. Providers of models designated as posing systemic risk, currently those trained on compute above a defined threshold, which in practice means the most capable frontier models, carry additional obligations: adversarial testing, incident reporting to the European AI Office, and cybersecurity measures proportionate to the model's reach. OpenAI, Google, and Anthropic, all of which offer models through European-facing APIs, fall into this category. So does Mistral AI, the Paris-based frontier lab whose models are widely used across European enterprise deployments.
For the companies building products on top of these models rather than developing the models themselves, the obligations shift: they are deployers or downstream providers, depending on how much they modify what they received. The line between the two determines which conformity requirements apply. A company that takes a general-purpose model and fine-tunes it for a specific high-risk use case, a recruitment screening tool, say, becomes a provider of a high-risk AI system and carries the full weight of that classification.
The Act did not survive its own implementation period unmodified. In November 2025, the European Commission proposed targeted amendments under what became known as the AI Omnibus, part of a broader digital simplification package. The Council of the European Union confirmed in May 2026 that the Council and Parliament had agreed on changes designed to reduce recurring administrative costs, including extending by up to 16 months the timeline for applying rules on high-risk AI systems. Those amendments entered into force on 27 July 2026, the week before full enforcement began.
The practical effect is that some of the most detailed conformity and documentation requirements for high-risk systems will not apply until later in the decade than the original text suggested. The prohibitions and transparency obligations remain on their original schedule. The enforcement architecture is now active.
Enforcement is distributed. National market surveillance authorities in each member state handle most AI systems. The European AI Office, established within the Commission, supervises general-purpose AI models directly and coordinates across member states. The European Data Protection Supervisor enforces the rules when EU institutions themselves are providers or deployers, as the Commission's August 2026 announcement sets out.
Fines are tiered by violation type. Prohibited practice violations carry the highest penalties: up to €35 million or 7 percent of global turnover. Failures on high-risk system obligations sit at up to €15 million or 3 percent of global turnover. Providing false or misleading information to national authorities or the AI Office carries a lower ceiling of €7.5 million or 1 percent of global turnover. For small and medium-sized enterprises, the Act caps fines at the lower of the percentage figure or the absolute amount. European startups deploying AI systems without dedicated compliance functions are directly in scope of that cap, and the enforcement machinery is now running.
The AI Office published its first set of rules of procedure for investigating general-purpose AI models in March 2026, and those procedures allow it to initiate investigations on its own motion rather than waiting for a complaint. That means a frontier model provider does not need a customer to trigger scrutiny: the Office can open a case because it has reason to believe a systemic-risk obligation is being met inadequately. The AI Office's published rules of procedure grant it powers to request technical documentation, commission independent evaluations, and require providers to take corrective action within a fixed window before a fine is imposed.
National authorities coordinate through a newly established scientific panel of independent experts that advises the AI Office on whether a model meets the systemic-risk threshold and on whether the adversarial testing a provider has submitted is credible. A negative panel opinion carries no formal binding force over the Office, but in practice it is the likely precursor to a formal investigation. For companies in the systemic-risk category, the scientific panel is the audience their technical documentation actually has to satisfy.
The obligations are not uniform across every company that uses AI. The Act assigns them based on role, and getting the role wrong is the first compliance mistake companies make.
A company that develops an AI model from training and places it on the European market is a provider. A company that deploys a third-party model in its own product without modifying the underlying model is a deployer. A company that takes a foundation model, fine-tunes it on proprietary data, and puts it to work in a specific application is a provider of a new AI system, regardless of whether it built the underlying model. The European Commission's official summary of the AI Act draws this distinction explicitly, and it carries financial consequences: providers bear the conformity assessment burden, while deployers bear responsibility for ensuring the system is used within the purpose for which it was assessed.
In practice, a company deploying a general-purpose model API to power a customer-service assistant, internal knowledge tool, or marketing workflow is usually not itself the provider of the underlying model. Its obligations depend instead on what it does with the model, how the resulting system is used, and whether that use places the system into one of the regulated categories.
That distinction matters because the AI Act does not regulate companies simply for using AI. It regulates specific systems, uses, and roles. The first task for any company is therefore to establish what AI systems it actually has in operation, who provides them, what they are being used for, and which obligations attach to each one.
For most companies, that exercise produces a mixed picture. A handful of systems may carry no specific obligations. Others may trigger transparency requirements. A smaller number may fall into a high-risk category or support a use case that requires additional governance. The same company can therefore be operating across several tiers at once.
The practical challenge is that companies rarely have a complete picture when they begin. AI may have entered through procurement, software subscriptions, individual employees, customer-facing tools, or features quietly added to systems they already use. An organisation may have dozens of AI-enabled tools without having a single record of where they sit, who owns them, or what obligations they create.
That is why compliance starts with an inventory rather than a policy. Before a company can decide what it must document, disclose, monitor, or change, it needs to know what it is actually using.