What the EU AI Act is
The EU AI Act—officially Regulation (EU) 2024/1689—is the world's first comprehensive regulatory framework for artificial intelligence. It was published in the Official Journal of the EU on July 12, 2024, and entered into force on August 1, 2024.
As a regulation, it applies directly in all member states without the need for transposition into national law. Member states only need to designate the competent authorities and regulate procedural matters.
Its goal is twofold: to create a uniform legal framework for the European single market and to ensure a high level of protection for health, safety, and fundamental rights. The methodological approach is noteworthy. The regulation does not govern the technology itself, but rather its use. The same speech recognition software is unproblematic in a dictation device but a different matter in a job application process. The legislator deliberately focused on the intended purpose, not the model.
The risk-based approach: four classes
The core of the regulation is a classification into four levels. This determines the entire scope of compliance requirements.
Unacceptable risk – prohibited (Article 5). Certain practices are banned in the EU, including manipulative systems that undermine free will, the exploitation of vulnerabilities, and social scoring. These prohibitions have been in effect since February 2, 2025.
High risk (Article 6 with Annexes I and III). This category carries the most extensive list of obligations. Classification occurs in two ways: AI as a safety component of a product that is already subject to an EU conformity assessment (Annex I), or use in one of eight exhaustively listed fields (Annex III)—biometric identification, critical infrastructure, education, employment, access to essential services, law enforcement, migration, and the judiciary.
The list is exhaustive. AI outside these fields does not fall under the high-risk rules, even if it is powerful and has significant business consequences. Additionally, Article 6(3) provides an exception: if a system performs only a narrowly defined task and does not significantly influence the outcome of a decision, it may be excluded despite being mentioned in Annex III—unless it involves profiling. In that case, it remains high-risk.
Limited risk (Article 50). Certain systems are subject only to transparency obligations, with no further testing requirements.
Minimal risk. All other systems. Here, only the general obligation for AI literacy applies. The majority of corporate AI usage falls into this class.
Who has which obligations: the four roles
Just as important as the risk class is the question of which role a company plays. The regulation defines four.
Provider is anyone who develops an AI system, or has one developed, and places it on the EU market or puts it into service under their own name or trademark. This applies regardless of whether the company is based in the EU or in a third country: providers from outside the EU are also subject to the regulation if their system's output is used within the EU. This role carries the most extensive obligations.
Deployer is anyone who uses an AI system under their own authority. This role is frequently underestimated: anyone using a finished AI tool has their own obligations—without having written a single line of code. However, the requirements are significantly lighter than those for providers.
Importers and distributors are subject to testing and due diligence obligations within the supply chain.
These roles are not rigid. Article 25 governs when a deployer legally becomes a provider: if they place their own name or trademark on a high-risk system that has already been placed on the market, if they make substantial modifications to it, or if they change the intended purpose of a system not classified as high-risk in such a way that it becomes a high-risk system. In these cases, the full provider obligations under Article 16 apply.
Deadlines at a glance
The staggered applicability is governed by Article 113 of the regulation.
- February 2, 2025: Prohibited practices (Art. 5), AI literacy requirements (Art. 4)
- August 2, 2025: Obligations for providers of general-purpose AI models, governance, penalties
- August 2, 2026: General applicability: Transparency obligations (Art. 50), oversight, enforcement
- December 2, 2026: Additional prohibitions
- December 2, 2027: Obligations for standalone high-risk systems under Annex III
- August 2, 2028: Obligations for high-risk systems in regulated products under Annex I
The last two lines require clarification, as they have caused confusion. The Digital Omnibus Regulation of July 8, 2026, was published in the Official Journal on July 24, 2026, and entered into force on July 27, 2026. The Council gave final approval to the simplification package on June 29, 2026, after the European Parliament adopted it on June 16, 2026. It was the high-risk block that was postponed—not the general date of application. The common claim that "the AI Act has been postponed" therefore only applies to a portion of it. Transparency obligations under Article 50 have been in effect since August 2, 2026.
What implementation means in practice
The regulations result in a manageable number of tasks. They build upon one another.
1. AI inventory
The first step is to create a list of all systems with AI functionality. This sounds trivial, but in practice, it is the biggest hurdle because AI is rarely purchased as such today. It arrives as an additional module in existing software, a feature in a cloud service, or an add-on subscribed to independently by a specific department. An inventory that only covers the IT system landscape will remain incomplete.
2. Determine role and risk class
Both must be clarified for each use case, not for each company or system. The same tool may be classified differently in two departments because the regulation is based on the intended purpose. The result of this classification determines everything that follows—which is why it is worth documenting it thoroughly, even if it leads to the conclusion that no special obligations apply.
3. Establish and document AI competence
This obligation under Article 4 has been applicable since February 2025 and applies regardless of the risk class. Anyone using AI must ensure that the employees involved understand the system: What can it do, where does it make mistakes, and when must a human intervene?
Article 14 on human oversight for high-risk systems shows that this understanding is not secondary: the individuals providing oversight must, among other things, be aware of a potential tendency to automatically trust a system's results—known as automation bias.
This does not mean a certificate, but rather a documented briefing: usage guidelines, training content, and recorded participation.
4. Implement transparency
Article 50 is intended to ensure that people recognize when they are interacting with an AI system and when they are viewing AI-generated content. This results in specific disclosure obligations:
- Anyone interacting with a chatbot or voice assistant must be able to recognize that they are speaking to a machine.
- Outputs from generative systems must be machine-readably labeled as artificially generated.
- Deepfakes and published texts on topics of public interest that lack human review or editorial control must be labeled as such.
- Systems for emotion recognition and biometric categorization must be disclosed to the affected individuals.
Guidance from the Commission itself is now available for practical implementation. On July 20, 2026, it published its final guidelines on transparency obligations; these clarify the scope, exceptions, and use cases. Additionally, there is the Code of Practice on Transparency of AI-generated Content with two sections—one for providers regarding labeling and detection, and one for operators regarding the marking of deepfakes and AI-generated texts. The EU also provides a set of symbols that operators can use to mark AI-generated content—free of charge and without attribution. However, their use alone does not establish legal compliance; the responsibility for sufficient disclosure remains with the operator.
The Commission and the AI Board have confirmed the code as a suitable voluntary instrument for demonstrating compliance. Signatories gain legal certainty and predictability. Those who do not join must demonstrate compliance in another appropriate way and should expect more requests for information, as there is less transparency regarding how obligations are being met. The code is voluntary, but the underlying obligation is not.
5. For high-risk: the full catalog
If a use case actually falls under Annex I or III, it becomes significantly more complex. For providers, Articles 8 through 15 require, among other things, a risk management system throughout the entire lifecycle, requirements for data and data governance, technical documentation, automatic logging, effective human oversight, and specifications regarding accuracy, robustness, and cybersecurity. In addition, there is a conformity assessment. Operators of high-risk systems have their own reduced obligations under Article 26; certain operators must also conduct a fundamental rights impact assessment under Article 27.
6. Establish governance
The point that isn't explicitly stated in the regulations but underpins everything else: clarify responsibilities. Who decides whether a new AI tool can be introduced? Who reviews the classification? What can departments set up independently, and what requires a preliminary check? Without these definitions, the AI inventory will become obsolete within a few months.
Sanctions and Oversight
Article 99 provides for fines of up to 35 million euros or 7 percent of total worldwide annual turnover for prohibited practices under Article 5, and up to 15 million euros or 3 percent for violations of other provisions, including transparency obligations.
Enforcement is carried out via national authorities: each member state designates at least one notifying authority and at least one market surveillance authority, which must act independently and impartially. For general-purpose AI models, the AI Office established within the Commission is responsible.
What this means for manufacturing companies
For industrial and manufacturing companies, the impact is manageable. Typical AI functions in enterprise software—such as demand and sales forecasting, production scheduling suggestions, document entry, predictive maintenance, and analysis of internal master data—do not fall into any of the eight Annex III categories and are therefore not considered high-risk. They are subject to the AI literacy requirement, but nothing else from the extensive catalog. Two areas still deserve close scrutiny: the path via Annex I, if AI is integrated as a safety component in machinery that the company places on the market itself—the Digital Omnibus Regulation has also amended the Machinery Regulation here—and the area of employment, as soon as applicant management systems automatically pre-sort or rank candidates. And the literacy requirement doesn't end in the office: when a planner accepts forecast suggestions or a worker acknowledges the result of an AI-supported inspection station, these are exactly the people the regulation is targeting.
Further information
All information in this article is based on publications by EU institutions. For those who wish to delve deeper, the official sources can be found here:
→ AI Act: Legal framework for artificial intelligence, European Commission
→ Code of practice for the transparency of AI-generated content
→ EU icons for labeling AI-generated content, including download
→ Regulation (EU) 2024/1689 in full text, EUR-Lex
This article provides a general overview and does not constitute legal advice. For the binding classification of specific AI applications, legal counsel should be sought. All information is current as of August 3, 2026.
.png)

