Reference · EU AI Act
What the regulation asks, of whom, and from when — as amended by the Digital Omnibus (Regulation (EU) 2026/1744).
Written for people who build or deploy AI systems and need the structure before the detail. It follows the logic of the text, cites the articles, and says what changed in July 2026.
Last reviewed: 30 September 2026
01 · Logic
The AI Act is closer to CE marking than to the GDPR. The provider shows conformity before placing a system on the market, then monitors it in use.
Obligations depend on two questions, always in this order:
A separate chapter regulates general-purpose AI models (GPAI) as models, not as systems.
02 · Dates
The Digital Omnibus (Regulation (EU) 2026/1744, OJ L of 24 July 2026) moved the high-risk dates. Prohibitions, AI literacy, GPAI and transparency were not postponed.
Postponed does not mean optional: a quality system, risk file and technical documentation take a year or more to build.
03 · Scope and roles
The regulation follows the market and the output, not the address. A company outside the EU is covered when its system, or its system's output, is used in the EU.
For Swiss companies: selling into the EU, or producing outputs used there, brings them into scope.
04 · Risk levels
Classification comes from the intended purpose. Transparency obligations stack on top of the others: a chatbot that screens candidates is high-risk and subject to Art. 50.
| Level | What it covers | Consequence | Basis |
|---|---|---|---|
| Prohibited | Practices with unacceptable risk | May not be placed on the market or used | Art. 5 |
| High-risk | Safety components of regulated products (Annex I) or uses in the areas of Annex III | Requirements of Arts. 8–15, conformity assessment, CE marking, registration, monitoring | Art. 6 |
| Transparency | Chatbots, synthetic content, deep fakes, emotion recognition | Inform people, mark outputs | Art. 50 |
| Minimal | Everything else: spam filters, recommendations, writing aids… | Art. 4 only, voluntary codes | Art. 95 |
05 · Prohibited practices
Applicable since 2 February 2025, with the highest fines. The Commission published guidelines on these practices and on the definition of an AI system in February 2025.
Added by the Omnibus, from 2 December 2026: systems generating child sexual abuse material (bb) or non-consensual intimate content of identifiable people (ba).
06 · High-risk
A system is high-risk either because of the product it belongs to, or because of the area it is used in. A documented derogation can take an Annex III system out.
The system is a product, or a safety component of a product, covered by EU harmonisation legislation that requires third-party assessment: medical devices and IVDs, toys, lifts, radio equipment, personal protective equipment…
Omnibus: machinery moves from Section A to Section B of Annex I, out of the direct application of the requirements; the Commission may add AI-specific requirements by delegated act.
An Annex III system is not high-risk if it poses no significant risk because it performs a narrow procedural task, improves the result of a completed human activity, detects decision patterns without replacing human assessment, or performs a preparatory task.
07 · Obligations
The provider builds conformity into the system. The deployer uses it as instructed, keeps a human in charge, and informs the people affected.
People affected by decisions based on Annex III systems have a right to an explanation Art. 86.
08 · Transparency
Applicable since 2 August 2026. The duties are split between the provider, who builds the notice or the marking, and the deployer, who discloses in context.
09 · General-purpose AI
Chapter V regulates the companies that train large models. Most organisations sit downstream: they use a model through a product and are deployers — or providers, if they build a high-risk system on it.
Open-source models are exempt from the first two, unless they carry systemic risk.
The General-Purpose AI Code of Practice (July 2025) is the usual way to show compliance.
10 · Digital Omnibus
Signed on 8 July 2026, published on 24 July, in force since 27 July 2026. It postpones and simplifies; it does not remove the high-risk regime.
11 · GDPR and ISO/IEC 42001
Much of what the AI Act asks overlaps with the GDPR and with an AI management system under ISO/IEC 42001. Mapping them avoids documenting the same thing three times.
| AI Act | GDPR | ISO/IEC 42001 |
|---|---|---|
| Fundamental rights impact assessment Art. 27 | Data protection impact assessment Art. 35 — complemented, not replaced Art. 27(4) | AI system impact assessment A.5, ISO/IEC 42005 |
| Human oversight Arts. 14, 26 | Automated decisions Art. 22 | Responsible use, roles A.9, A.3 |
| Data and bias Art. 10, Art. 4a | Special categories Art. 9, minimisation Art. 5 | Data for AI systems A.7 |
| Quality and risk management Arts. 9, 17 | Accountability, privacy by design Arts. 24, 25 | Clauses 6 and 8, life cycle A.6 |
| Information to people Arts. 26(11), 50, 86 | Information and access Arts. 13–15 | Information for interested parties A.8 |
| Authorised representative Art. 22 | EU representative Art. 27 | — |
ISO/IEC 42001 is not a harmonised standard under the AI Act and does not give a presumption of conformity. The harmonised standards from CEN-CENELEC JTC 21 are late, one of the reasons for the postponement.
12 · Penalties and authorities
Fines are set as a fixed amount or a share of worldwide annual turnover, whichever is higher; for SMEs and start-ups, whichever is lower Art. 99(6).
| Infringement | Maximum | Basis |
|---|---|---|
| Prohibited practices | €35 million or 7% | Art. 99(3) |
| Other obligations (providers, deployers, transparency…) | €15 million or 3% | Art. 99(4) |
| Incorrect information to authorities | €7.5 million or 1% | Art. 99(5) |
| GPAI providers, imposed by the Commission | €15 million or 3% | Art. 101 |
13 · Test yourself
Short cases that come up in practice. Open each one to see the answer.
Deployer: it uses the system under its authority, and the output is used in the EU Art. 2(1)(c). High-risk, Annex III point 4. Art. 26 obligations from 2 December 2027; Art. 4 already today.
It becomes a provider Art. 25: requirements of Arts. 9–15, quality system, conformity assessment, CE marking, registration, and an authorised representative in the EU Art. 22.
Transparency: the provider makes sure users know they are talking to an AI Art. 50(1), applicable since 2 August 2026. The deployer checks the notice is active. Plus Art. 4.
Deployers of high-risk systems that are public bodies or private entities providing public services, and deployers of systems for creditworthiness or for pricing life and health insurance Art. 27. Not for critical infrastructure.
Yes, through the derogation of Art. 6(3), provided it does not profile people. The assessment is documented Art. 6(4) and the system is still registered, in simplified form since the Omnibus.
€35 million or 7% of worldwide annual turnover, whichever is higher. For an SME, whichever is lower Art. 99(6).
Art. 4 now asks for measures that support the development of staff AI literacy, rather than ensuring a sufficient level. It has applied since 2 February 2025.
Questions
Classification and role are where most of the work starts. If you want to talk it through, write to me.
This page is a study reference, not legal advice. Dates and content of the Omnibus checked against the text of Regulation (EU) 2026/1744. Official texts: Regulation (EU) 2024/1689 · Regulation (EU) 2026/1744.