In this article12
- 1.What the EU AI Act actually regulates
- 2.What changed with the Digital Omnibus
- 3.EU AI Act timeline: what applies when
- 4.Prohibited AI practices
- 5.Transparency obligations under Article 50
- 6.EU AI Act fines
- 7.Who enforces it
- 8.EU AI Act compliance checklist
- 9.What this means when you build AI agents
- 10.Frequently asked questions
- 11.Next steps
- 12.Sources
EU AI Act compliance in 2026 comes down to three live obligations for most businesses: don't use prohibited AI practices, take measures to support AI literacy among your staff, and, since August 2, 2026, be transparent when people interact with AI or see AI-generated content. The heavy high-risk requirements were pushed back by the Digital Omnibus to December 2027 and August 2028. If you operate in the EU or sell AI-powered services into it, these rules apply to you regardless of company size.
The short version:
- The Digital Omnibus on AI (Regulation (EU) 2026/1744) has applied since July 27, 2026 and delays high-risk rules to December 2, 2027 (Annex III) and August 2, 2028 (Annex I).
- Prohibited practices and AI literacy have applied since February 2, 2025. Transparency under Article 50 has applied since August 2, 2026.
- Fines reach EUR 35 million or 7% of global annual turnover for prohibited AI, and EUR 15 million or 3% for transparency and deployer violations.
- Enforcement at national and EU level started on August 2, 2026, although several member states are still finalizing their supervisory setup.
What the EU AI Act actually regulates
The AI Act is an EU regulation that classifies AI systems by risk. The higher the risk to people's health, safety or fundamental rights, the stricter the rules. A short list of uses is banned outright. A defined set of "high-risk" uses face documentation, oversight and conformity requirements. Chatbots, deepfakes and some other systems carry transparency duties. Everything else, which includes most business automation such as invoice extraction or quote drafting, is minimal risk with few extra obligations.
Two roles matter for compliance:
- Providers develop an AI system or model and place it on the market under their own name.
- Deployers use an AI system under their own authority in a professional context.
Most companies are deployers. If you use ChatGPT, Microsoft Copilot, or an AI agent that was built for you and runs inside your own processes, you are typically the deployer. If you build an AI product and sell it to others, you are the provider, with considerably more obligations.
Because the AI Act is a regulation rather than a directive, it applies directly in all EU member states. It also has extraterritorial reach: a non-EU company whose AI system's output is used in the EU can fall within scope. Will the EU AI Act apply to the UK? Not domestically, but UK companies selling AI systems or AI-driven services into the EU still need to comply for that part of their business.
What changed with the Digital Omnibus
The European Commission proposed the Digital Omnibus on AI on November 19, 2025. It was published as Regulation (EU) 2026/1744 and entered into force on July 27, 2026. The key changes for businesses:
- High-risk rules delayed. Obligations for Annex III high-risk systems (recruitment, credit scoring, education access, critical infrastructure and similar) now apply from December 2, 2027. High-risk AI embedded in regulated products such as machinery, toys and lifts (Annex I) follows on August 2, 2028.
- AI literacy softened. The duty moved from ensuring "a sufficient level" of AI literacy to taking measures that support its development. We cover the details in our article on the AI literacy requirement.
- Relief extended to small mid-caps. Simplifications previously reserved for SMEs now also cover small mid-cap companies.
- New ban on "nudification apps", plus an EU-wide regulatory sandbox.
The Omnibus did not repeal the AI Act. Prohibitions, transparency, and general-purpose AI rules are all in force.
EU AI Act timeline: what applies when
| Date | What applies | Relevant if you |
|---|---|---|
| Feb 2, 2025 | Prohibited practices (Art. 5), AI literacy (Art. 4) | Use AI in any form |
| Aug 2, 2025 | General-purpose AI model rules; member states designate authorities | Build or fine-tune foundation models |
| Aug 2, 2026 | Transparency (Art. 50); enforcement starts at national and EU level | Run chatbots, publish AI content, use emotion recognition |
| Dec 2, 2026 | New bans on non-consensual sexual deepfakes; Art. 50(2) transition ends for existing systems | Provide generative AI systems |
| Aug 2, 2027 | At least one regulatory sandbox per member state | Want to test under supervision |
| Dec 2, 2027 | High-risk AI in Annex III | Use AI for hiring, worker management, credit, education |
| Aug 2, 2028 | High-risk AI in products (Annex I) | Manufacture machinery, medical devices, toys |
Source: the European Commission's AI Act Service Desk timeline, updated September 25, 2026.
Prohibited AI practices
Article 5 bans a limited set of uses deemed an unacceptable risk. Most won't appear in normal business operations, but two can slip into off-the-shelf software unnoticed:
- Emotion recognition in the workplace and in education, except for medical or safety reasons. A tool that scores employee emotions during sales calls or interviews is a problem.
- Manipulative or deceptive techniques that materially distort behavior, or that exploit vulnerabilities related to age, disability or social situation.
Also banned: social scoring, untargeted scraping of facial images to build recognition databases, biometric categorization based on sensitive traits, predicting criminal behavior purely from profiling, and real-time remote biometric identification by law enforcement (with narrow exceptions). The Omnibus added nudification apps, and from December 2, 2026 AI for non-consensual sexual deepfakes and child sexual abuse material is prohibited too.
Transparency obligations under Article 50
This is the obligation that touches the most businesses right now. What are the transparency obligations under the EU AI Act? In practice:
- Chatbots and AI agents must be recognizable as AI. People must know they are dealing with AI at the latest at the first interaction. A clear line such as "You're chatting with our AI assistant" in the first message usually does the job.
- Deepfakes must be disclosed. Image, audio or video content that resembles real people, places or events and was generated or manipulated by AI must be labeled.
- Emotion recognition and biometric categorization must be disclosed in advance to the people exposed to them.
- AI-generated text published to inform the public on matters of public interest must be disclosed as such, unless it went through human editorial review with editorial responsibility.
Providers of generative AI must also make output detectable as AI-generated in a machine-readable way (Art. 50(2)). Systems already on the market before August 2, 2026 have until December 2, 2026 for that part.
A practical note beyond the AI Act itself: consumer and data protection regulators increasingly expect a route to a human. The Dutch data protection authority and consumer authority stated jointly in October 2025 that a chatbot may not fully replace people in customer service. If you are building an AI chatbot for customer service, design in a human handoff from day one.
EU AI Act fines
Penalties are set out in Article 99. The higher of the two amounts applies:
| Violation | Maximum fine |
|---|---|
| Prohibited practices (Art. 5) | EUR 35 million or 7% of worldwide annual turnover |
| Deployer obligations (Art. 26) and transparency (Art. 50) | EUR 15 million or 3% of worldwide annual turnover |
| Incorrect or misleading information to authorities | EUR 7.5 million or 1% |
For SMEs, the lower of the two amounts applies, and member states must consider economic viability when setting penalties. That keeps fines proportionate, not trivial.
Who enforces it
Each member state designates market surveillance authorities, coordinated at EU level through the AI Office for general-purpose AI. Enforcement of prohibitions, transparency, AI literacy and GPAI rules started on August 2, 2026. Not every member state has its national law finalized. The Netherlands, for example, put its implementation act out for consultation in April 2026 with a hybrid model of ten market regulators, and its data protection authority currently describes itself as the "intended supervisor". That uncertainty does not pause your obligations: the regulation applies directly.
EU AI Act compliance checklist
A lean compliance program for a small or mid-sized business looks like this:
- Build an AI inventory. List every AI tool and AI feature in use, including AI embedded in existing software such as Microsoft 365 Copilot, your CRM or your helpdesk.
- Determine your role per system. Provider or deployer? A custom agent you commissioned and use internally usually makes you the deployer.
- Screen for prohibited practices. Walk through Article 5, with extra attention to emotion recognition on staff.
- Screen for high-risk use. AI in hiring, performance evaluation or credit decisions means additional obligations from December 2027. Start documenting data sources, human oversight and decision logic now.
- Implement transparency. Add an AI disclosure and a human escalation path to every customer-facing chatbot or agent. Label AI-generated images and video.
- Support AI literacy. Map who uses which AI, what they need to know, and plan training proportionate to the risk.
- Connect it to GDPR. For most businesses the day-to-day AI risk is a data protection risk. See our guide on ChatGPT and GDPR.
- Write it down. A two-page AI policy with your inventory, rules and owners is a solid starting point and helps you demonstrate compliance.
What this means when you build AI agents
If you commission an AI agent that takes actions in your ERP, accounting software or CRM, it will usually be minimal risk. The legal requirements are light, but good engineering practice overlaps with the spirit of the Act: full action logs, human approval for consequential steps, scoped permissions, and clear AI disclosure whenever the agent talks to customers. At Airflows we build those in by default, because they also keep agents from going off the rails in production.
The moment an agent makes decisions about people, such as screening job applicants, you move toward high-risk territory. That is a design decision to make up front, not a retrofit.
Frequently asked questions
Is the EU AI Act legally binding?
Yes. The AI Act is an EU regulation, which means it applies directly in all member states without national transposition. Its obligations phase in over time: prohibitions and AI literacy since February 2025, transparency since August 2026, and high-risk rules from December 2027.
What are the key changes in the EU AI regulations for 2026?
Two things happened in 2026. The Digital Omnibus entered into force on July 27, delaying high-risk rules to December 2027 and August 2028 and softening the AI literacy duty. Then on August 2, the Article 50 transparency obligations started applying and enforcement began at national and EU level.
Does the EU AI Act apply to small businesses?
Yes. There is no size threshold. Any company using AI must avoid prohibited practices, meet transparency duties and support AI literacy. SMEs and small mid-caps do benefit from simplifications and lower fine ceilings.
Will the EU AI Act apply to the UK?
The AI Act is not UK law. However, UK businesses that place AI systems on the EU market, or whose AI output is used in the EU, fall within its scope for that activity and need to comply.
What is the fine for violating the EU AI Act?
Up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices, and up to EUR 15 million or 3% for breaches of transparency and deployer obligations. For SMEs the lower of the two amounts applies.
Next steps
Start with the inventory and the transparency check, since that is where most of the work and most of the insight sits. If you want to see which AI use cases make sense for your business and how to set them up compliantly from day one, take our free AI scan. When we build for you, logging, human oversight and AI disclosure are part of the standard setup; see our services for how a project runs.
Sources
- AI Omnibus enters into force (European Commission, July 27, 2026)
- Timeline for the Implementation of the EU AI Act (AI Act Service Desk, September 25, 2026)
- Regulation (EU) 2024/1689, AI Act (EUR-Lex, June 13, 2024)
- Regulation (EU) 2026/1744, Digital Omnibus on AI (EUR-Lex, July 24, 2026)
- AI supervision becomes concrete: key role for the AP and RDI (Dutch Data Protection Authority, April 20, 2026)
- From August 2 it becomes clearer whether it's AI or real (Dutch Data Protection Authority, July 31, 2026)
- AP and ACM: chatbot may not fully replace humans in customer service (October 2, 2025)

Builds AI agents, automations and custom software for businesses at Airflows.



