Definition
The EU AI Act is the European Union's regulation governing artificial intelligence, the first comprehensive AI law in the world. It takes a risk-based approach: a few AI practices are banned outright, high-risk systems in areas such as hiring, credit, education and critical infrastructure face strict obligations, general-purpose models have transparency and documentation duties, and most everyday uses have light or no requirements. The EU AI Act applies to any company placing AI on the EU market or using it in the EU.
For a company, the EU AI Act means classifying each AI use case by risk. Using AI to screen job applicants or assess creditworthiness is high-risk and requires risk management, data governance, human oversight, logging and documentation. Using a chatbot requires telling users they are talking to AI. Generating synthetic images or video requires labelling. Most internal productivity uses carry no specific obligation beyond existing law such as GDPR.
The EU AI Act entered into force on 1 August 2024. Bans applied from February 2025 and general-purpose AI obligations from 2 August 2025. In 2026 the Digital Omnibus on AI, published as Regulation (EU) 2026/1744 in July 2026, postponed most high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I), while transparency duties still applied from 2 August 2026. The misconception is that the delay means the Act is dead. Bans, GPAI and transparency rules are in force now.
In practice
A recruiting software company mapped its AI features against the EU AI Act, found its CV ranking tool falls under high-risk, and started building the required documentation, human review step and logging well before the deadline, turning compliance into a sales argument with enterprise buyers.
Why it matters
If you sell to or operate in Europe, the EU AI Act defines what you must document and control when using AI. Enterprise customers already ask about it in procurement, so readiness is commercial as well as legal.
Frequently asked questions
- Does the EU AI Act apply to my company?
- It applies if you develop, sell or use AI systems in the EU, regardless of where your company is based. Most obligations fall on providers of high-risk systems and general-purpose models, but users of high-risk AI and anyone deploying chatbots or synthetic media also have duties, mainly around oversight and transparency.
- When do the EU AI Act high-risk rules apply?
- After the 2026 Digital Omnibus on AI, obligations for standalone high-risk systems listed in Annex III apply from 2 December 2027, and for AI embedded in regulated products from 2 August 2028. Bans, general-purpose AI obligations and transparency rules are already in force, so the delay only affects part of the Act.