The EU AI Act: Everything You Need to Know (And Why It Matters More Than You Think)
There is a piece of legislation working its way through the European Union that will reshape how every organisation on the planet builds, deploys, and sells...
There is a piece of legislation working its way through the European Union that will reshape how every organisation on the planet builds, deploys, and sells artificial intelligence. It is called the EU AI Act, and if you are reading this from anywhere outside the EU, do not make the mistake of thinking it does not apply to you. It does. Extraterritorially. With teeth.
The AI Act entered into force on 1 August 2024. Since then, it has been rolling out in stages, with different obligations kicking in at different points. Some provisions are already live. Others land in August 2026. And a recent legislative intervention in May 2026, the so-called “Digital Omnibus,” has pushed several critical deadlines further out, giving businesses more breathing room but also more uncertainty about what is coming and when.
This article is a comprehensive walkthrough: what the Act is, how it works, what it bans, what it demands, who it affects, and what you should be doing about it right now.
The Big Idea: Risk-Based Regulation
The fundamental principle behind the EU AI Act is deceptively simple: not all AI systems pose the same level of risk, so they should not all be treated the same way. The Act establishes a four-tier risk classification system, and your obligations depend entirely on which tier your AI system falls into.
This is, at its core, a regulatory application of something behavioural scientists have understood for decades. When people face complex decisions, they use heuristics, mental shortcuts that compress information into manageable categories. The EU has essentially built a regulatory heuristic: instead of assessing every AI system individually (which would be administratively impossible), it sorts them into buckets and applies graduated obligations to each one.
Whether you think this is a sensible approach or an exercise in bureaucratic overreach, the framework is now law. Here is how it works.
The Four Risk Tiers
1. Unacceptable Risk (Banned)
These are AI practices the EU considers fundamentally incompatible with human dignity and fundamental rights. They are prohibited outright, with no exceptions (or only very narrow ones for law enforcement under strict judicial oversight).
The banned list includes:
-
Social scoring systems. AI that evaluates or classifies people based on their social behaviour, personal traits, or predicted characteristics, leading to unfavourable treatment in unrelated contexts. Think of it as a regulatory line in the sand against algorithmic caste systems.
-
Manipulative and deceptive AI. Systems that deploy subliminal techniques or purposefully manipulative methods to distort a person’s behaviour in ways they are not aware of, causing or likely to cause significant harm. This is the EU’s answer to the dark patterns debate, extended into AI.
-
Exploitation of vulnerabilities. AI that targets people’s vulnerabilities due to age, disability, or specific social or economic situations to distort their behaviour and cause harm.
-
Predictive policing based solely on profiling. AI systems that assess the risk of someone committing a crime based solely on their personality traits, past behaviour, or profiling data. There are narrow exceptions, but the baseline is prohibition.
-
Untargeted facial recognition scraping. Building or expanding facial recognition databases by scraping images from the internet or CCTV footage without any targeting criteria.
-
Emotion recognition in workplaces and schools. AI that infers emotions in educational or employment settings, with limited exceptions for medical or safety purposes.
-
Biometric categorisation to infer sensitive characteristics. Systems that use biometric data to classify people by race, political opinions, religious beliefs, sexual orientation, or other sensitive characteristics.
-
Real-time remote biometric identification in public spaces. Generally banned for law enforcement, with narrow exceptions requiring prior judicial authorisation for specific serious crimes, missing persons, or imminent threats.
These prohibitions have been in force since 2 February 2025. If you are building any of these systems, you are already non-compliant.
A new prohibition, added by the May 2026 Digital Omnibus, bans AI systems that generate non-consensual intimate imagery (so-called “nudifiers”) and child sexual abuse material. This takes effect on 2 December 2026.
2. High-Risk AI Systems
This is where the bulk of the regulatory burden falls. High-risk AI is permitted but heavily regulated. These are systems used in contexts where errors or biases could have serious consequences for people’s lives, livelihoods, or fundamental rights.
High-risk systems are identified in two ways:
Annex III (Use-Based): AI systems deployed in specific high-stakes domains:
- Biometric identification and categorisation
- Management and operation of critical infrastructure
- Education and vocational training
- Employment, worker management, and access to self-employment
- Access to and enjoyment of essential private and public services (including credit scoring, insurance pricing, and social security)
- Law enforcement
- Migration, asylum, and border control management
- Administration of justice and democratic processes
Annex I (Product-Based): AI systems that are safety components of products already covered by existing EU harmonisation legislation, such as medical devices, machinery, toys, vehicles, and lifts.
The obligations for high-risk AI systems are substantial:
- Risk management systems. Providers must establish, implement, and maintain a continuous risk management process throughout the AI system’s lifecycle.
- Data governance. Training, validation, and testing datasets must be relevant, representative, free of errors, and complete. This is where many organisations will struggle, because the quality of AI depends entirely on the quality of the data it learns from.
- Technical documentation. Detailed documentation must be prepared before the system is placed on the market and kept up to date.
- Record-keeping. Systems must automatically log events throughout their operation to enable traceability.
- Transparency. Users must be able to understand the system’s outputs and use them appropriately.
- Human oversight. Systems must be designed to allow effective human oversight, including the ability to override or intervene in the system’s operation.
- Robustness, accuracy, and cybersecurity. Systems must perform consistently and be resilient against errors, faults, and attacks.
- Conformity assessment. Before placing a high-risk system on the market, providers must conduct a conformity assessment, either self-assessment or through a third-party notified body, depending on the system.
- Post-market monitoring. Ongoing monitoring and reporting of serious incidents.
- EU database registration. High-risk systems must be registered in a public EU database.
For deployers (the organisations using these systems, not building them), the obligations include ensuring staff AI literacy, maintaining use logs, conducting Fundamental Rights Impact Assessments (FRIAs) where applicable, and monitoring the system’s performance in practice.
3. Limited Risk
These systems face transparency obligations. The key requirement under Article 50 is straightforward: users must know when they are interacting with AI.
This includes:
- Chatbots must disclose that they are AI systems.
- AI-generated content (text, images, audio, video) must be clearly labelled as AI-generated.
- Deepfakes must be marked as such.
These transparency obligations take effect on 2 August 2026. For generative AI systems already on the market before that date, the machine-readable watermarking requirement has been extended to 2 December 2026 by the Digital Omnibus. For systems placed on the market after 2 August 2026, compliance is immediate.
4. Minimal or No Risk
The vast majority of AI systems fall here. Spam filters, AI in video games, recommendation engines in most consumer contexts. No specific obligations under the Act.
General-Purpose AI Models (GPAI)
The Act has a separate regime for general-purpose AI models, the foundation models that power tools like ChatGPT, Gemini, Claude, and similar systems.
GPAI obligations, which have been in force since 2 August 2025, include:
- Maintaining and making available technical documentation
- Providing information and documentation to downstream providers (the businesses building products on top of these models)
- Establishing a copyright compliance policy
- Publishing a sufficiently detailed summary of the training data
For GPAI models that pose systemic risk, defined as models trained using substantial computing power (currently set at more than 10^25 FLOPs), additional obligations apply:
- Performing model evaluations, including adversarial testing
- Assessing and mitigating systemic risks
- Tracking, documenting, and reporting serious incidents
- Ensuring adequate cybersecurity protections
The Digital Omnibus: What Changed in May 2026
On 7 May 2026, EU legislators reached a provisional agreement on a “Digital Omnibus” that makes targeted amendments to the AI Act. The headline change: several critical deadlines have been pushed back.
What moved:
- High-risk AI obligations (Annex III): Postponed from 2 August 2026 to 2 December 2027. This is a 16-month delay for standalone high-risk systems like those used in recruitment, credit scoring, or law enforcement.
- High-risk AI obligations (Annex I): Moved from 2 August 2027 to 2 August 2028. AI embedded in regulated products like medical devices or machinery gets an extra year.
- Watermarking for existing systems: The machine-readable marking requirement for generative AI systems already on the market before August 2026 is extended to 2 December 2026.
- National AI regulatory sandboxes: Member States now have until 2 August 2027 to establish these, a one-year extension.
What did not move:
- The prohibitions on unacceptable risk (already in force since February 2025)
- AI literacy obligations (already in force since February 2025)
- GPAI model obligations (already in force since August 2025)
- General transparency obligations under Article 50 (still due 2 August 2026)
Other changes:
- Simplification measures to reduce overlaps between the AI Act and existing sectoral regulation (particularly for medical devices and machinery)
- Extended simplified requirements to small mid-cap companies
- Clarified the supervisory role of the EU AI Office, granting it exclusive competence over GPAI-based systems and AI integrated into Very Large Online Platforms and Very Large Online Search Engines
The Omnibus is expected to be formally adopted and published in the Official Journal before 2 August 2026.
Extraterritorial Scope: Yes, This Applies to You
If you are based outside the EU but your AI systems’ outputs are used within the EU, the Act applies to you. This is the same logic the EU applied with GDPR, and it has proven remarkably effective at setting global standards.
For anyone building AI products, serving EU customers, or deploying AI systems that affect people in the EU, the territorial reach is clear. The EU is, once again, exporting its regulatory preferences to the rest of the world.
Penalties
The enforcement mechanism is not subtle:
- Prohibited AI practices: Up to €35 million or 7% of total worldwide annual turnover, whichever is higher.
- High-risk AI non-compliance: Up to €15 million or 3% of turnover.
- Providing incorrect or misleading information: Up to €7.5 million or 1% of turnover.
For small and mid-cap companies, the fines are capped at the lower of the two figures (the absolute amount or the percentage).
These are not theoretical numbers. The EU has demonstrated with GDPR that it is willing to enforce significant penalties, and the AI Act gives regulators even sharper tools.
What You Should Be Doing Now
The staged timeline means different things for different organisations. Here is a practical breakdown:
Already in force (since February 2025):
- Prohibited AI practices are banned. If you are building any of them, stop.
- AI literacy obligations apply. Your staff need to understand the AI systems they are using.
Already in force (since August 2025):
- GPAI model providers must comply with transparency, documentation, and copyright obligations.
- Systemic risk GPAI models face additional evaluation and reporting requirements.
Due August 2026:
- Transparency obligations for limited-risk AI systems. Chatbots must disclose. AI content must be labelled. Deepfakes must be marked.
- Machine-readable watermarking for new generative AI systems.
Due December 2027 (postponed from August 2026):
- Full obligations for high-risk AI systems listed in Annex III.
Due August 2028:
- Obligations for high-risk AI systems embedded in regulated products (Annex I).
Practical steps right now:
-
Audit your AI inventory. Catalogue every AI system your organisation builds, deploys, or procures. Classify each one against the four risk tiers.
-
Start with the prohibitions. If any of your systems fall into the banned category, the deadline has already passed. Act immediately.
-
Build AI literacy. This is already an obligation. Ensure your teams understand the systems they are working with and the regulatory framework that governs them.
-
Prepare for transparency requirements. August 2026 is close. If you are running chatbots, generating AI content, or using deepfake technology, your disclosure and labelling systems need to be in place.
-
Begin high-risk compliance work now. Even though the deadline has been pushed to December 2027, the requirements are substantial. Risk management systems, data governance frameworks, technical documentation, conformity assessments, and post-market monitoring all take significant time to build properly. Starting now is not premature. It is prudent.
-
Assess your supply chain. If you are a deployer of high-risk AI (using it, not building it), you need to understand your providers’ compliance status. Your obligations include verifying that the systems you use have undergone conformity assessments and are registered in the EU database.
-
Watch for further guidance. The European Commission is expected to publish additional guidelines and a Code of Practice to assist with compliance. The regulatory sandboxes, once established, will also provide controlled environments for testing and validation.
The Bigger Picture
The EU AI Act is the most comprehensive attempt to regulate artificial intelligence in the world. It is not perfect. Critics argue it is too complex, too burdensome for smaller companies, and too slow to keep pace with the technology it purports to govern. Supporters argue it is a necessary framework for protecting fundamental rights in an era of rapidly advancing AI capabilities.
What is not in dispute is its influence. Just as GDPR became the de facto global standard for data privacy, the AI Act is likely to set the template for AI regulation worldwide. Countries and regions that lack their own comprehensive AI legislation will find themselves operating within the EU’s framework simply because their companies serve EU customers.
The question for every organisation is not whether the EU AI Act affects you. It is whether you will be ready when it does.
David Chadderton spent his twenties and thirties teaching people how to make life-or-death decisions at forty thousand feet. He now applies the same principles to consumer psychology, which, depending on the brief, can feel equally high-stakes. He’s the creator of the STAR Framework and the author of The STAR Framework: Rewriting the Rules of Consumer Engagement (NYC Big Book Award 2025), The STAR Operating System: Decode Mindset, Understand Motivation, Transform Human Behaviour, and Dear Algorithm, It’s Not Me, It’s You. By day, a Chief Marketing Officer. By night, a behavioural science obsessive who writes The Unoptimised Human because he can’t stop thinking about why people do what they do.
The STAR Framework
If you enjoyed this essay, you'll find the full argument — and the framework behind it — in the book.