EU AI Act Compliance: What Businesses Must Do in 2026

EU AI Act compliance after the Digital Omnibus: what applies now, what was delayed, the fines, and a practical checklist you can work through this month.

Daniel Bouw
Daniel Bouw
Airflows
10 min read
EU AI Act Compliance: What Businesses Must Do in 2026
In this article12
  1. 1.What the EU AI Act actually regulates
  2. 2.What changed with the Digital Omnibus
  3. 3.EU AI Act timeline: what applies when
  4. 4.Prohibited AI practices
  5. 5.Transparency obligations under Article 50
  6. 6.EU AI Act fines
  7. 7.Who enforces it
  8. 8.EU AI Act compliance checklist
  9. 9.What this means when you build AI agents
  10. 10.Frequently asked questions
  11. 11.Next steps
  12. 12.Sources

EU AI Act compliance in 2026 comes down to three live obligations for most businesses: don't use prohibited AI practices, take measures to support AI literacy among your staff, and, since August 2, 2026, be transparent when people interact with AI or see AI-generated content. The heavy high-risk requirements were pushed back by the Digital Omnibus to December 2027 and August 2028. If you operate in the EU or sell AI-powered services into it, these rules apply to you regardless of company size.

The short version:

  • The Digital Omnibus on AI (Regulation (EU) 2026/1744) has applied since July 27, 2026 and delays high-risk rules to December 2, 2027 (Annex III) and August 2, 2028 (Annex I).
  • Prohibited practices and AI literacy have applied since February 2, 2025. Transparency under Article 50 has applied since August 2, 2026.
  • Fines reach EUR 35 million or 7% of global annual turnover for prohibited AI, and EUR 15 million or 3% for transparency and deployer violations.
  • Enforcement at national and EU level started on August 2, 2026, although several member states are still finalizing their supervisory setup.

What the EU AI Act actually regulates

The AI Act is an EU regulation that classifies AI systems by risk. The higher the risk to people's health, safety or fundamental rights, the stricter the rules. A short list of uses is banned outright. A defined set of "high-risk" uses face documentation, oversight and conformity requirements. Chatbots, deepfakes and some other systems carry transparency duties. Everything else, which includes most business automation such as invoice extraction or quote drafting, is minimal risk with few extra obligations.

Two roles matter for compliance:

  • Providers develop an AI system or model and place it on the market under their own name.
  • Deployers use an AI system under their own authority in a professional context.

Most companies are deployers. If you use ChatGPT, Microsoft Copilot, or an AI agent that was built for you and runs inside your own processes, you are typically the deployer. If you build an AI product and sell it to others, you are the provider, with considerably more obligations.

Because the AI Act is a regulation rather than a directive, it applies directly in all EU member states. It also has extraterritorial reach: a non-EU company whose AI system's output is used in the EU can fall within scope. Will the EU AI Act apply to the UK? Not domestically, but UK companies selling AI systems or AI-driven services into the EU still need to comply for that part of their business.

What changed with the Digital Omnibus

The European Commission proposed the Digital Omnibus on AI on November 19, 2025. It was published as Regulation (EU) 2026/1744 and entered into force on July 27, 2026. The key changes for businesses:

  • High-risk rules delayed. Obligations for Annex III high-risk systems (recruitment, credit scoring, education access, critical infrastructure and similar) now apply from December 2, 2027. High-risk AI embedded in regulated products such as machinery, toys and lifts (Annex I) follows on August 2, 2028.
  • AI literacy softened. The duty moved from ensuring "a sufficient level" of AI literacy to taking measures that support its development. We cover the details in our article on the AI literacy requirement.
  • Relief extended to small mid-caps. Simplifications previously reserved for SMEs now also cover small mid-cap companies.
  • New ban on "nudification apps", plus an EU-wide regulatory sandbox.

The Omnibus did not repeal the AI Act. Prohibitions, transparency, and general-purpose AI rules are all in force.

EU AI Act timeline: what applies when

DateWhat appliesRelevant if you
Feb 2, 2025Prohibited practices (Art. 5), AI literacy (Art. 4)Use AI in any form
Aug 2, 2025General-purpose AI model rules; member states designate authoritiesBuild or fine-tune foundation models
Aug 2, 2026Transparency (Art. 50); enforcement starts at national and EU levelRun chatbots, publish AI content, use emotion recognition
Dec 2, 2026New bans on non-consensual sexual deepfakes; Art. 50(2) transition ends for existing systemsProvide generative AI systems
Aug 2, 2027At least one regulatory sandbox per member stateWant to test under supervision
Dec 2, 2027High-risk AI in Annex IIIUse AI for hiring, worker management, credit, education
Aug 2, 2028High-risk AI in products (Annex I)Manufacture machinery, medical devices, toys

Source: the European Commission's AI Act Service Desk timeline, updated September 25, 2026.

Prohibited AI practices

Article 5 bans a limited set of uses deemed an unacceptable risk. Most won't appear in normal business operations, but two can slip into off-the-shelf software unnoticed:

  • Emotion recognition in the workplace and in education, except for medical or safety reasons. A tool that scores employee emotions during sales calls or interviews is a problem.
  • Manipulative or deceptive techniques that materially distort behavior, or that exploit vulnerabilities related to age, disability or social situation.

Also banned: social scoring, untargeted scraping of facial images to build recognition databases, biometric categorization based on sensitive traits, predicting criminal behavior purely from profiling, and real-time remote biometric identification by law enforcement (with narrow exceptions). The Omnibus added nudification apps, and from December 2, 2026 AI for non-consensual sexual deepfakes and child sexual abuse material is prohibited too.

Transparency obligations under Article 50

This is the obligation that touches the most businesses right now. What are the transparency obligations under the EU AI Act? In practice:

  1. Chatbots and AI agents must be recognizable as AI. People must know they are dealing with AI at the latest at the first interaction. A clear line such as "You're chatting with our AI assistant" in the first message usually does the job.
  2. Deepfakes must be disclosed. Image, audio or video content that resembles real people, places or events and was generated or manipulated by AI must be labeled.
  3. Emotion recognition and biometric categorization must be disclosed in advance to the people exposed to them.
  4. AI-generated text published to inform the public on matters of public interest must be disclosed as such, unless it went through human editorial review with editorial responsibility.

Providers of generative AI must also make output detectable as AI-generated in a machine-readable way (Art. 50(2)). Systems already on the market before August 2, 2026 have until December 2, 2026 for that part.

A practical note beyond the AI Act itself: consumer and data protection regulators increasingly expect a route to a human. The Dutch data protection authority and consumer authority stated jointly in October 2025 that a chatbot may not fully replace people in customer service. If you are building an AI chatbot for customer service, design in a human handoff from day one.

EU AI Act fines

Penalties are set out in Article 99. The higher of the two amounts applies:

ViolationMaximum fine
Prohibited practices (Art. 5)EUR 35 million or 7% of worldwide annual turnover
Deployer obligations (Art. 26) and transparency (Art. 50)EUR 15 million or 3% of worldwide annual turnover
Incorrect or misleading information to authoritiesEUR 7.5 million or 1%

For SMEs, the lower of the two amounts applies, and member states must consider economic viability when setting penalties. That keeps fines proportionate, not trivial.

Who enforces it

Each member state designates market surveillance authorities, coordinated at EU level through the AI Office for general-purpose AI. Enforcement of prohibitions, transparency, AI literacy and GPAI rules started on August 2, 2026. Not every member state has its national law finalized. The Netherlands, for example, put its implementation act out for consultation in April 2026 with a hybrid model of ten market regulators, and its data protection authority currently describes itself as the "intended supervisor". That uncertainty does not pause your obligations: the regulation applies directly.

EU AI Act compliance checklist

A lean compliance program for a small or mid-sized business looks like this:

  1. Build an AI inventory. List every AI tool and AI feature in use, including AI embedded in existing software such as Microsoft 365 Copilot, your CRM or your helpdesk.
  2. Determine your role per system. Provider or deployer? A custom agent you commissioned and use internally usually makes you the deployer.
  3. Screen for prohibited practices. Walk through Article 5, with extra attention to emotion recognition on staff.
  4. Screen for high-risk use. AI in hiring, performance evaluation or credit decisions means additional obligations from December 2027. Start documenting data sources, human oversight and decision logic now.
  5. Implement transparency. Add an AI disclosure and a human escalation path to every customer-facing chatbot or agent. Label AI-generated images and video.
  6. Support AI literacy. Map who uses which AI, what they need to know, and plan training proportionate to the risk.
  7. Connect it to GDPR. For most businesses the day-to-day AI risk is a data protection risk. See our guide on ChatGPT and GDPR.
  8. Write it down. A two-page AI policy with your inventory, rules and owners is a solid starting point and helps you demonstrate compliance.

What this means when you build AI agents

If you commission an AI agent that takes actions in your ERP, accounting software or CRM, it will usually be minimal risk. The legal requirements are light, but good engineering practice overlaps with the spirit of the Act: full action logs, human approval for consequential steps, scoped permissions, and clear AI disclosure whenever the agent talks to customers. At Airflows we build those in by default, because they also keep agents from going off the rails in production.

The moment an agent makes decisions about people, such as screening job applicants, you move toward high-risk territory. That is a design decision to make up front, not a retrofit.

Frequently asked questions

Is the EU AI Act legally binding?

Yes. The AI Act is an EU regulation, which means it applies directly in all member states without national transposition. Its obligations phase in over time: prohibitions and AI literacy since February 2025, transparency since August 2026, and high-risk rules from December 2027.

What are the key changes in the EU AI regulations for 2026?

Two things happened in 2026. The Digital Omnibus entered into force on July 27, delaying high-risk rules to December 2027 and August 2028 and softening the AI literacy duty. Then on August 2, the Article 50 transparency obligations started applying and enforcement began at national and EU level.

Does the EU AI Act apply to small businesses?

Yes. There is no size threshold. Any company using AI must avoid prohibited practices, meet transparency duties and support AI literacy. SMEs and small mid-caps do benefit from simplifications and lower fine ceilings.

Will the EU AI Act apply to the UK?

The AI Act is not UK law. However, UK businesses that place AI systems on the EU market, or whose AI output is used in the EU, fall within its scope for that activity and need to comply.

What is the fine for violating the EU AI Act?

Up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices, and up to EUR 15 million or 3% for breaches of transparency and deployer obligations. For SMEs the lower of the two amounts applies.

Next steps

Start with the inventory and the transparency check, since that is where most of the work and most of the insight sits. If you want to see which AI use cases make sense for your business and how to set them up compliantly from day one, take our free AI scan. When we build for you, logging, human oversight and AI disclosure are part of the standard setup; see our services for how a project runs.

Sources

Daniel Bouw
Written by
Daniel Bouw

Builds AI agents, automations and custom software for businesses at Airflows.

What can AI do for your business?

Book a no-obligation call. In 30 minutes you will know where AI saves time and what it costs.