Guide AI Compliance

EU AI Act: What Is Now in Force and What the Digital Omnibus Changed

The EU AI Act (Regulation 2024/1689) is now in force. Prohibitions have applied since February 2025. Article 50 transparency obligations covering chatbot disclosure, synthetic content labelling, and deepfake marking took effect on 4 August 2026. Annex III high-risk AI obligations, originally due the same day, were delayed to 2 December 2027 by the Digital Omnibus amendments. This article covers what is now enforceable, what changed, and what deployers of high-risk AI must have in place by December 2027.

Key takeaways
  • Article 50 transparency obligations are now in force: chatbots must identify themselves as AI, synthetic content must be labelled, and deepfakes must be marked
  • Annex III high-risk AI obligations were delayed to 2 December 2027 by the Digital Omnibus; the original August 2026 deadline no longer applies
  • Most businesses using third-party AI tools are deployers, not providers, but deployers of high-risk AI still have real legal obligations
  • Eight Annex III categories define high-risk AI, employment and recruitment AI is in scope for most regulated businesses
  • Several AI practices have been banned since February 2025, including emotion recognition in workplaces and AI-powered social scoring
  • Using ChatGPT, Copilot, or Gemini makes you an AI system deployer under the Act. GPAI obligations (Articles 53–55) fall on the model developers (OpenAI, Microsoft, Google), not on you. You carry responsibility for how you use those systems, including any high-risk applications you build on top of them
  • Fines reach €35 million or 7% of global turnover for the most serious violations

What the EU AI Act is

The EU AI Act (Regulation EU 2024/1689) is the first comprehensive legal framework for artificial intelligence. Published on 12 July 2024 and in force from 1 August 2024, it applies across all sectors and all AI use cases rather than regulating a single industry. A risk-based structure determines which obligations apply to a given system.

The Act distinguishes two main actors. Providers develop AI systems and place them on the EU market: software vendors, SaaS companies, AI tool developers. Deployers use AI systems in a professional context under their own authority. Most businesses, including SMEs using off-the-shelf AI tools for HR, customer service, or operations, are deployers. Providers carry heavier obligations. Deployers of high-risk AI carry lighter but substantive ones.

Scope

The Act covers providers placing AI on the EU market regardless of where they are based, and deployers located in the EU. If your organisation uses AI in the Netherlands, in any EU member state, or in the UK where post-Brexit equivalence is under active review, and the AI output affects people in the EU, this law covers you.

The four risk tiers

The Act assigns AI systems to one of four tiers. The tier determines your obligations, ranging from no requirements for everyday tools to an outright ban for the most dangerous applications.

Unacceptable risk, Banned In force since 2 February 2025
These AI practices are prohibited outright. No business justification can authorise them.
Social scoring by public authorities Subliminal manipulation Emotion recognition in workplaces Real-time biometric ID in public spaces Facial recognition database scraping Criminal behaviour prediction by profiling
High risk Obligations apply from 2 December 2027
AI systems listed in Annex III. Both providers and deployers have obligations. Covers eight categories including employment AI, credit scoring, education systems, and critical infrastructure.
CV screening and recruitment AI Employee performance monitoring Credit and insurance scoring Student assessment AI Biometric identification systems
Limited risk Transparency obligations only
AI systems that interact with people must disclose that they are AI. Chatbots must tell users they are talking to a machine. AI-generated content must be labelled as such.
Customer service chatbots AI-generated text and images Deepfake content
Minimal risk No specific obligations
The vast majority of AI applications, spam filters, recommendation engines, AI in productivity tools, most automation, fall here. Providers can voluntarily adopt codes of conduct.
Spam filters AI-powered search Inventory forecasting Grammar correction

Prohibited AI: what has been banned since February 2025

Chapter II prohibitions became enforceable on 2 February 2025. Any organisation currently using the following systems is in violation.

  • Subliminal manipulation: AI that influences people through techniques operating below conscious perception to distort their behaviour or decisions in ways that cause harm.
  • Exploiting vulnerabilities: AI that exploits specific groups' vulnerabilities, age, disability, social or economic situation, to distort their behaviour harmfully.
  • Social scoring: AI used by public authorities to evaluate or classify individuals based on their social behaviour or personal characteristics, leading to detrimental or unfavourable treatment.
  • Criminal behaviour prediction by profiling: AI that assesses the risk of a person committing a crime based solely on profiling or personality traits, rather than on objective verifiable facts.
  • Untargeted biometric scraping: AI systems that create or expand facial recognition databases by scraping images from the internet or CCTV footage without a specific purpose.
  • Emotion recognition in workplaces and education: AI that infers the emotions of workers or students. This is a direct and immediate concern for employers using mood or engagement monitoring tools.
  • Biometric categorisation by sensitive attributes: AI that categorises people based on biometric data into groups defined by race, political opinion, religion, sexual orientation, or other sensitive characteristics.
  • Real-time remote biometric identification in public spaces: AI used for live biometric identification of people in publicly accessible spaces, subject to narrow and strictly supervised law enforcement exceptions.
Check now

Employee engagement monitoring platforms, productivity tracking tools that record facial expressions or emotional state, and HR technology that scores or categorises workers by biometric signals may already constitute prohibited AI. Review those tools now.

High-risk AI: the eight Annex III categories

Annex III lists every category of AI system classified as high-risk. The Digital Omnibus amendments, passed in June 2026, pushed the compliance deadline for providers and deployers in these categories to 2 December 2027. The original August 2026 deadline no longer applies. For most organisations, the employment and financial services categories present the greatest exposure.

1
Biometric systems
AI used for remote biometric identification or categorisation of natural persons, and AI used for emotion recognition. Affects security systems, access control, and attendance monitoring using facial or biometric data.
2
Critical infrastructure
AI used as a safety component in management and operation of digital infrastructure, road, rail, water, gas, heating, and electricity. Relevant for utilities, logistics, and managed infrastructure providers.
3
Education and vocational training
AI that determines access to or assigns people to educational institutions, evaluates learning outcomes, assesses students in exams, or monitors for prohibited behaviour. Relevant for training providers, HR learning platforms, and assessment tools.
4
Employment and workers management
AI used for recruitment (CV screening, job ad targeting, interview analysis), promotion decisions, task allocation, performance monitoring, and contract termination. This is the category most relevant to regulated businesses using third-party HR technology.
5
Essential private and public services
AI used in credit scoring, insurance risk assessment, creditworthiness evaluation, and emergency services dispatching. Critical for financial services firms and insurers.
6
Law enforcement
AI used to assess the risk of a person becoming a victim of crime, polygraphs and similar tools, and profiling in the context of criminal offences. Primarily applies to law enforcement agencies.
7
Migration, asylum, and border control
AI used to assess risks for visa applications, asylum claims, and border crossing. Primarily applies to public authorities, but third-party service providers may be affected.
8
Administration of justice and democratic processes
AI that assists in researching and interpreting facts and the law, or influencing elections. Primarily relevant to legal services and public administration.

What deployers of high-risk AI must do

If your organisation uses a high-risk AI system, your obligations as a deployer are separate from the provider's. The provider handles design, documentation, and conformity assessment. You are responsible for how the system is used.

  • Use it as intended: You must use the system in accordance with the provider's instructions for use. Modifications or use cases outside the intended scope shift liability towards you.
  • Implement human oversight: You must designate a person with the necessary competence, authority, and resources to implement human oversight of the system's operation. Fully automated high-risk decisions without meaningful human review are not permitted.
  • Monitor for unexpected behaviour: You must monitor the operation of the system and report serious incidents or malfunctions to the provider and, where required, to the relevant market surveillance authority.
  • Keep logs: Where the AI system generates logs automatically, you must retain those logs for the period required by applicable law.
  • Inform affected workers: Where the AI system affects employees, for example, performance monitoring or task allocation, you must inform the workers and their representatives of the system's use before it is deployed.
  • Conduct a Fundamental Rights Impact Assessment (FRIA): Deployers that are public bodies, or that deploy high-risk AI for credit scoring, insurance, or certain other services, must conduct and document an FRIA before deployment.
2 Aug
2026
high-risk AI obligations apply, Annex III systems
€35M
or 7% global turnover, maximum fine for prohibited AI
€15M
or 3% global turnover, maximum fine for high-risk non-compliance

General Purpose AI models: what deployers need to know

General Purpose AI (GPAI) models, the large foundation models underlying ChatGPT, Microsoft Copilot, Google Gemini, and similar tools, follow a separate compliance track under the Act. GPAI obligations on providers became enforceable from 2 August 2025.

When you use a GPAI model through an API, a subscription product, or a platform like Microsoft 365 Copilot, you are a deployer. OpenAI, Microsoft, and Google carry the primary GPAI compliance obligations: maintaining technical documentation, publishing summaries of training data, and complying with EU copyright law. You inherit their compliance through their terms and transparency documentation.

That position changes if you build on top of a GPAI model. Fine-tuning a foundation model, adding it to a product you place on the market, or using a GPAI model to power an Annex III application such as a CV screening tool makes you a provider of that downstream application. The underlying GPAI provider's compliance does not extend to what you have built on top.

Using ChatGPT or Copilot responsibly is not the same as being compliant. Obligations follow the use case, and a high-risk use case built on a GPAI tool is your compliance problem to solve.

GPAI models with systemic risk

GPAI models trained using more than 10²⁵ floating point operations, broadly the most capable frontier models available today, carry a systemic risk designation. Their providers face additional requirements: adversarial testing, incident reporting to the European AI Office, cybersecurity measures, and energy efficiency reporting. Your obligations as a deployer are unchanged, but you should confirm that your GPAI provider has registered with the EU AI Office and published the required transparency documentation.

The implementation timeline

1 Aug 2024
Act enters into force
Regulation (EU) 2024/1689 published and in force. Transition periods begin.
2 Feb 2025
Prohibited AI applies
Chapter I (definitions) and Chapter II (prohibited practices) become enforceable. The eight categories of banned AI are now illegal.
2 Aug 2025
GPAI model obligations apply
Providers of General Purpose AI models must comply with documentation, transparency, and copyright requirements. Systemic-risk GPAI providers face additional adversarial testing and incident reporting obligations.
2 Aug 2026
Article 50 transparency obligations now in force
Chatbots must disclose they are AI. Synthetic content must carry machine-readable labelling. Deepfakes must be marked. European AI Office gains full penalty enforcement powers over GPAI providers.
2 Dec 2027
Annex III high-risk AI deadline
Delayed from August 2026 by the Digital Omnibus. All high-risk standalone AI systems (employment, credit, biometrics, education, critical infrastructure) must comply with full provider and deployer obligations.

What most businesses need to do now

The Annex III deadline moving to December 2027 gives organisations time for a structured compliance process. Start with a full inventory. You cannot assess your obligations without knowing what AI you are running and in what context.

Step 1: Inventory your AI use

List every AI system in use across your organisation, not just tools IT has procured but tools individual teams and employees have adopted. Include productivity AI (Copilot, ChatGPT), HR platforms with AI features, customer-facing chatbots, fraud detection tools, and any analytics platforms that make or inform decisions about people. Most organisations find through this process that employees are running AI tools the IT function has never reviewed. For AI that can take autonomous actions on behalf of users, the security considerations are distinct; our guide to agentic AI security risks covers those specific controls.

Step 2: Classify each system by risk tier

For each system identified, determine which tier applies. The key question for most SMEs: does the AI system make or materially assist decisions about people in employment, education, credit, or essential services? If yes, it is likely high-risk. A chatbot the user knows is AI is limited risk. A recommendation engine or internal productivity tool is likely minimal risk.

Step 3: Check your HR and recruitment AI

Employment and workers management is the Annex III category relevant to the widest range of organisations. If you use a tool that automates or assists in screening CVs, ranking candidates, scheduling interviews, monitoring employee productivity, or allocating tasks, ask your HR technology vendor directly: is this system classified as high-risk under the EU AI Act, and what is your compliance roadmap?

Step 4: Review your prohibited AI exposure

Check each prohibited AI category against your current tools. Emotion recognition and workplace monitoring present the most common exposure for private sector organisations. Any platform that analyses facial expressions, voice tone, or physical behaviour to infer employee engagement or emotional state requires immediate review.

Step 5: Update your AI policies and inform your workforce

The Act requires deployers of high-risk AI to inform workers when AI systems are used in employment decisions. Beyond that legal requirement, staff who understand which AI tools are in use and how they operate are a governance asset. Update your acceptable use policy to cover generative AI, document which tools are approved and for what purposes, and confirm that the person responsible for AI oversight has the authority and time to exercise it.

Our audits and compliance team works with organisations to structure AI Act readiness assessments, from inventory to gap analysis to remediation. Our AI advisory practice supports businesses deploying AI across regulated sectors including financial services, healthcare, and hospitality.


The fine structure

The Act sets a three-tier penalty structure. National market surveillance authorities enforce it within each member state; the European AI Office oversees GPAI providers directly.

  • Prohibited AI violations: Up to €35 million or 7% of total worldwide annual turnover, whichever is higher.
  • Non-compliance with high-risk AI obligations: Up to €15 million or 3% of total worldwide annual turnover, whichever is higher.
  • Providing incorrect, incomplete, or misleading information to authorities: Up to €7.5 million or 1% of total worldwide annual turnover, whichever is higher.

For SMEs and start-ups, fines are capped at whichever figure is lower, the absolute cap or the percentage of turnover. The absolute figures remain significant at any scale. The European AI Office has indicated that enforcement will focus first on serious violations and on repeat or negligent non-compliance, rather than first-time technical breaches by organisations working towards compliance.

Frequently asked questions

Does the EU AI Act apply to businesses outside the EU?

Yes. The Act covers any provider that places an AI system on the EU market or puts it into service in the EU, regardless of where that provider is established. It also covers deployers located in the EU. If your AI system's output is used in the EU, the Act covers you.

What is the difference between a provider and a deployer under the EU AI Act?

A provider develops an AI system and places it on the market or puts it into service. A deployer uses an AI system in a professional context under their own authority. Most businesses using tools like ChatGPT, Microsoft Copilot, or third-party recruitment AI are deployers. Providers carry heavier obligations: technical documentation, conformity assessments, registration. Deployers of high-risk AI carry real obligations too.

Is using ChatGPT or Microsoft Copilot regulated under the AI Act?

These tools are General Purpose AI (GPAI) models. Their providers, OpenAI, Microsoft, Google, must comply with GPAI obligations including technical documentation and copyright compliance. As a deployer, you inherit their compliance through their terms and model cards. If you use a GPAI model to build a high-risk application, for example an AI-powered CV screening tool, you take on responsibility for the high-risk obligations.

Which AI uses are already banned since February 2025?

Prohibited practices enforceable from 2 February 2025 include: AI that manipulates people through subliminal techniques or by exploiting their vulnerabilities; social scoring by public authorities; real-time remote biometric identification in public spaces (with narrow law enforcement exceptions); biometric categorisation inferring sensitive attributes such as race, religion, or political opinion; scraping facial images from the internet or CCTV to build recognition databases; emotion recognition in workplaces or educational institutions; and AI that predicts criminal behaviour based on profiling.

What are the fines under the EU AI Act?

Violations involving prohibited AI systems can result in fines of up to €35 million or 7% of global annual turnover, whichever is higher. Non-compliance with obligations for high-risk AI systems carries fines of up to €15 million or 3% of global annual turnover. Providing incorrect or misleading information to authorities can result in fines of up to €7.5 million or 1% of global annual turnover. For SMEs and start-ups, the fine is capped at whichever figure is lower.

Ryland Deakin
About the author
Ryland Deakin
Lead Consultant, Cyvra · CISM · CompTIA Security+ · MCP

Ryland has delivered cybersecurity, compliance, and IT management programmes for regulated organisations across the UK and the Netherlands for over 20 years, including senior roles at Microsoft, ING, IPsoft, PPHE and more. View full profile

EU AI Act Readiness

Not sure where your AI use lands?

We help organisations map their AI inventory, identify high-risk exposure, and build a compliance plan ahead of the December 2027 Annex III deadline.