The 2026 position

The EU AI Act uses a risk-based framework for AI placed on the EU market or used in the EU. The Act entered into force on 1 August 2024 and became broadly applicable on 2 August 2026, while some provisions started earlier and certain high-risk rules follow later timelines.

In practice, teams need to identify what they are building or using, which role they occupy in the value chain, and what risk category applies. This guide is general information, not legal advice; organizations should obtain qualified advice for their products and markets.

Four practical risk levels

  • Unacceptable-risk practices are prohibited, including specific manipulative, exploitative, social-scoring, and biometric uses described by the Act.
  • High-risk systems face the strongest requirements, including risk management, documentation, logging, human oversight, accuracy, robustness, and cybersecurity obligations.
  • Limited-risk systems may have transparency duties. For example, making clear when people interact with AI or encounter certain synthetic content.
  • Minimal-risk uses generally have no additional mandatory obligations under the Act, though voluntary codes and sound governance remain useful.

Provider or deployer?

A company that develops an AI system and places it on the market under its name may be a provider. A company that uses a system under its authority may be a deployer. Importers and distributors have separate responsibilities. The same organization can occupy different roles across different products.

Do not classify the company once and assume the answer covers everything. Map each system, each use case, the people affected, the market, and the organization’s role.

What product and operations teams should do now

  • Create a living inventory of AI systems, models, vendors, owners, purposes, users, and affected groups.
  • Record intended use, foreseeable misuse, data sources, evaluation results, and known limitations.
  • Define meaningful human oversight and escalation for decisions that affect rights, access, safety, or livelihoods.
  • Review vendor contracts for documentation, incident support, data use, model changes, and audit rights.
  • Add user-facing transparency where people interact with AI or receive AI-generated content.
  • Build post-deployment monitoring and incident reporting into the operating process.

Treat compliance as a product system

A spreadsheet assembled just before a launch will not produce reliable governance. Assign owners, connect documentation to the development lifecycle, make evaluation evidence repeatable, and review systems when the model, data, purpose, or affected population changes.

The strongest approach links legal interpretation with product management, engineering, security, data governance, procurement, and customer support. That turns compliance from a one-time exercise into an operating capability.

Primary sources

We used the following official materials to verify this guide:

  1. European Commission: AI Act regulatory framework
  2. European Commission: Navigating the AI Act
  3. European Commission: AI Omnibus enters into force

Note: This article provides general information and is not legal advice.