EU AI Act: What Companies Really Need to Know
Blog / Enterprise AI / AI Regulation

ENTERPRISE AI · AI REGULATION

The EU AI Act: What Companies Need to Know

Author: Julia Rose / Published: July 2026

Artificial intelligence has long been part of everyday business, whether as a chatbot in customer service, in automated applicant screening, or in intelligent analytics tools. With the EU AI Act, the European Union has created the first comprehensive legal framework regulating the use of AI systems. What complicates matters is that the timeline has recently shifted, which can easily create the false impression that there is no need to act for now. The opposite is true: some obligations already apply today, others take effect unchanged in August 2026.

What Is the EU AI Act?

The EU AI Act is the world’s first comprehensive law regulating artificial intelligence. It follows a risk-based approach: the greater the potential impact of an AI system on people, safety, or fundamental rights, the more extensive the legal requirements.

Unlike the GDPR, the AI Act does not focus primarily on personal data. Instead, the central question is which risks an AI system poses and which safeguards are required. The regulation applies directly in all member states of the European Union, creating uniform rules for the European market.

Who Does the AI Act Apply To?

The regulation affects considerably more companies than many initially assume. It applies to:

  • Companies based in the EU that develop or deploy AI systems
  • Providers of AI solutions outside the EU, provided their systems are used on the European market
  • Companies that use AI outputs within the EU
  • Manufacturers of products with integrated AI components

What matters, therefore, is not only the company’s location but also the effect of the AI system within the European Union. A German company using a US-based AI service can be just as affected by the requirements as an American provider whose solution is available to European customers.

The Most Important Deadlines at a Glance

The EU AI Act does not enter into force in full on a single date. The requirements take effect in stages, and the recent adjustments through the so-called Digital Omnibus make it even more important to keep the individual dates clearly apart.

Since August 2024: The regulation officially entered into force.

Since February 2025: Two sets of rules already apply: the ban on certain AI practices with unacceptable risk, and the obligation to ensure adequate AI literacy among employees who work with AI systems (Article 4). Companies must therefore already ensure today that their staff have the necessary knowledge to use AI responsibly.

Since August 2025: The requirements for so-called General-Purpose AI models (GPAI) apply. These include in particular the powerful foundation models on which many modern AI applications are built.

As of 2 August 2026: This is the deadline that the recent postponement tends to push into the background, but which is the most relevant in practice for many companies. On this day, most transparency obligations under Article 50 take effect. Unlike the high-risk obligations, they are expressly unaffected by the postponement and apply as originally planned. In concrete terms, this means that users must be able to recognise when they are interacting with an AI, for example with chatbots, virtual assistants, or generative AI applications. One single exception concerns the labelling of AI-generated content under Article 50(2): for systems placed on the market before 2 August 2026, this specific obligation is postponed to 2 December 2026.

The High-Risk Deadlines, and Why the Postponement Is No All-Clear

The situation has shifted considerably here. With the Digital Omnibus, which the Council and Parliament agreed on in May 2026, the strictest deadlines are being postponed:

  • 2 December 2027 for standalone high-risk systems under Annex III, such as AI in recruiting, lending, education or critical infrastructure. Originally, August 2026 was envisaged here.
  • 2 August 2028 for high-risk AI embedded in regulated products, such as medical devices or machinery.

Two things are decisive here. First, the Council and Parliament have approved the Digital Omnibus (Parliament on 16 June, Council on 29 June 2026). The new deadlines become legally binding only upon publication in the Official Journal, expected in July 2026. Until then, the original timeline formally applies. Companies should therefore treat the new dates as a very reliable planning assumption whose legal force is imminent.

Second, and this is the actual point: only the date on which the obligations are enforced has been postponed. The substantive requirements, namely conformity assessment, technical documentation, risk management, data governance, and human oversight, remain unchanged. Those who treat the additional time as a pause will build the relevant systems later under time pressure. Those who use it will lay the foundations now in peace. A conformity assessment and the associated documentation are produced most cleanly when they are part of development from the outset, rather than being built around a finished system afterwards.

The Four Risk Classes of the AI Act

The heart of the regulation is the classification of AI systems into different risk categories.

Prohibited AI Practices:

Certain applications are deemed incompatible with European fundamental rights and are prohibited in principle. These include, for example:

  • Manipulating people through subliminal techniques
  • Exploiting the vulnerability or need for protection of specific groups
  • Social scoring modelled on social rating systems
  • the untargeted scraping of facial images from the internet or from video surveillance to build facial recognition databases

For companies, this category is comparatively rarely relevant, but it marks the clear boundary of what is permissible within the EU.

High-Risk AI:

This is where the focus of the regulation lies. High-risk systems are AI applications whose decisions can have significant effects on people or societal processes. Typical examples are:

  • Applicant management and recruiting systems
  • Systems for employee evaluation
  • Creditworthiness assessments
  • Applications in healthcare
  • Systems in the education sector
  • AI solutions for critical infrastructure

These systems are subject to extensive requirements, including:

  • Risk management
  • Technical documentation
  • Data governance
  • Quality management
  • Human oversight
  • Logging and traceability
  • Conformity assessment

The practical consequence: companies must be able to demonstrate that their system is operated in a controlled, traceable, and safe manner.

AI Systems With Limited Risk:

This category covers many applications already in use in companies today. These include, for example:

  • Chatbots
  • Virtual assistants
  • AI-based communication tools

Here, transparency obligations are paramount. Users must be able to recognise that they are communicating with an AI and not with a human. The regulatory effort is considerably lower than for high-risk systems, yet companies should take the relevant disclosure obligations into account early on.

Systems With Minimal Risk:

Most AI applications fall into this category. Examples are:

  • Spam filters
  • AI-assisted spell checkers
  • Recommendation systems with low risk potential

For these systems, the regulation generally provides for no additional obligations. Nevertheless, responsible governance is advisable here too, particularly if areas of application or risks change in the future.

Provider or Deployer? The Role Determines the Obligations

A central point of the regulation is often overlooked: not every company bears the same obligations. What matters is the role in the respective AI project.

Provider:

A provider is anyone who develops an AI system or places it on the market under their own name. Providers bear the most extensive regulatory obligations. These include, among others:

  • Risk assessments
  • Technical documentation
  • Conformity procedures
  • Ongoing monitoring of the system
  • Evidence of compliance with the regulation

Deployer:

Deployers use an existing AI system within their company. Typical examples:

  • Using a recruiting tool
  • Using an AI chatbot in customer service
  • Using generative AI for internal processes

Deployers also have obligations, but these are generally less extensive than those of providers. In particular, they must ensure that:

  • the system is used as intended
  • employees are adequately trained
  • internal processes meet the regulatory requirements
  • necessary transparency obligations are met

For many companies, the deployer role is considerably more relevant than the provider role. What matters here is the threshold at which a deployer becomes a provider: anyone who substantially modifies a purchased high-risk system or deploys it under their own name thereby takes on the considerably more extensive provider obligations.

A 90-Second Self-Check: Which Obligations Apply to You?

Before working through the full preparation process, three questions tell most companies where they stand.

1. Do you build the AI system, or do you use one?

If you develop an AI system or place it on the market under your own name, you are a provider and carry the most extensive obligations. If you use an existing tool largely as delivered, you are a deployer. One caveat: if you substantially modify a purchased high-risk system or run it under your own name, you cross the threshold into provider obligations.

2. What does your system actually decide?

If it decides about people or societal processes, recruiting, creditworthiness, healthcare, education, critical infrastructure, it is likely high-risk. If it only interacts, a chatbot or assistant, it typically falls under limited risk with transparency obligations. If it merely filters or suggests, a spam filter or spell checker, it is usually minimal risk.

3. When does this become urgent for you?

If you run a chatbot or generative AI, most transparency obligations under Article 50 apply from 2 August 2026, and the postponement does not touch them. If you operate a high-risk system, your enforcement deadline is 2 December 2027 (standalone) or 2 August 2028 (embedded in regulated products), but the substantive work starts now.

The most common case in practice: a company that uses a purchased tool (deployer), runs a chatbot (limited risk), and therefore has a real 2 August 2026 deadline. That is the situation the next section walks through in full.

A Worked Example: Support Chatbot

Take a common case. A mid-sized manufacturer has added a purchased AI chatbot to its customer support, straight from the vendor, unmodified. What does the AI Act mean for this company specifically?

Role: The company uses the tool as delivered and does not place it on the market under its own name. It is a deployer, not a provider. This alone removes the heaviest obligations, conformity assessment, technical documentation, ongoing system monitoring, which sit with the vendor.

Risk class: The chatbot interacts with people but does not decide about creditworthiness, hiring, or access to essential services. It falls under limited risk, not high-risk. That distinction is the difference between a handful of transparency duties and a full compliance programme.

Deadline: Because this is a transparency obligation under Article 50, the relevant date is 2 August 2026, and the postponement does not apply. There is no extra time here.

The three concrete to-dos

1
ACTION
Make the AI recognisable
Users must be able to tell they are talking to an AI and not a human. A clear notice at the start of the chat is usually enough.
2
ACTION
Document AI literacy
The staff who manage the chatbot need demonstrable basic knowledge of its risks and limits. A short internal guideline plus a recorded training session satisfies the Article 4 obligation in its adjusted, best-efforts form.
3
ACTION
Check the vendor’s paperwork
As a deployer, you should confirm the provider has met its obligations and that you use the system as intended. Keep that confirmation on file.

That is the full extent of it for this company. No conformity assessment, no high-risk documentation, one real deadline, three manageable tasks. The point of the exercise is not the specific answer but the method: role first, then risk class, then deadline, then the short list of duties that actually results.

What Companies Should Do Now

The example shows the method in one case. For your own run-through, it always follows the same order:

Start by recording every AI system you use or plan to introduce, including purchased SaaS solutions. Assign each system to a risk class and clarify your role, deployer or provider. From that combination follow the concrete obligations and the relevant deadline, exactly as in the example above.

Two things are worth settling early: clear responsibilities across compliance, IT security, data protection and the business units, and a simple governance process for documentation, approvals and ongoing monitoring. Neither needs to be elaborate, but both should be named and documented.

One point deserves particular attention, because it has applied since February 2025 and is often overlooked: the AI literacy of your staff. Article 4 requires companies to ensure that people working with AI can responsibly assess its opportunities, risks and limits. The Digital Omnibus adjusts this obligation but expressly does not remove it for companies. An earlier proposal to shift responsibility away from providers and deployers toward the Commission and member states was dropped in the final text. The duty stays with companies and is only reworded to be more practical: the strict obligation to guarantee a certain level of competence becomes an obligation to take appropriate measures to promote AI literacy, a duty of effort, not of result. The point is not to turn every employee into a data scientist, but to enable staff to use AI safely and in a compliant way. Precisely because the requirements vary by industry and use case, practical training formats are an important building block.

Take Action Now and Build Competence

The EU AI Act is not intended to prevent the use of artificial intelligence, but to steer it into reliable and trustworthy channels. For companies, this creates no barrier to innovation, but a clear framework for the safe and responsible use of AI.

Those who already use AI today or are planning corresponding projects should not regard the requirements as a later formality. The decisive course is often already set during the selection, introduction, and use of AI systems. Alongside technical and organisational measures, the AI literacy of employees is becoming particularly important. Companies that build knowledge early and establish clear responsibilities reduce regulatory risks while laying the foundation for a successful AI strategy.

This is exactly where theBlue.ai comes in. We develop custom AI solutions tailored to a company’s specific use case. Data sovereignty, traceability, and human oversight are not an afterthought for us, but have long been an integral part of our development work. Even before the regulation formulated these requirements, we built AI systems so that they deliver traceable results, run entirely in the company’s own data centre where needed, and keep humans in control.

Beyond development, we also pass on the knowledge needed to build AI literacy within the company. In our practical AI Workshops, we train your employees for the safe and compliant use of AI, combining regulatory requirements, concrete use cases, and organisational best practices. If you are planning a specific AI project, talk to us about your use case.

Disclaimer: This article provides a general overview of the EU AI Act as of July 2026 and does not constitute legal advice. The regulatory framework is moving quickly at present: the Digital Omnibus was endorsed by the European Parliament on 16 June 2026 and formally adopted by the Council of the EU on 29 June 2026, but at the time of writing it has not yet been published in the Official Journal of the EU. Only upon that publication, expected in July 2026, do the new deadlines become legally binding; until then, the AI Act in its 2024 form remains the applicable law. Specific points, in particular the high-risk deadlines and the exact shape of the Article 4 AI literacy obligation, may still change with the final text. Check the current status and the binding text of the regulation before making concrete compliance decisions.

About the Author

Julia Rose, Marketing Lead at theBlue.ai

Julia Rose, Marketing Lead, theBlue.ai

Julia has been part of theBlue.ai since 2019 and has accompanied the development of AI applications in the enterprise environment since the company’s early days. In her role as Marketing Lead, she works closely with the engineering and consulting teams and makes complex technical topics understandable and accessible for decision-makers.

In her articles, she writes about practical experiences from enterprise AI projects as well as the challenges and opportunities of using AI in companies.

Tell us about the process you want to automate

Describe your process and we will get back to you within one business day with an initial assessment and a proposal for a 30-minute scoping call.






    Data Controller Information: The controller of your personal data is theBlue.ai GmbH, headquartered in Hamburg, Germany. By submitting this form, you consent to the processing of your personal data for the purpose of responding to your inquiry. You may withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal. Based on our legitimate interest, we may also send you information about our services and solutions, but only if it relates to the topic of your message. If you prefer not to receive such communications, you have the right to object at any time. For more details on how we handle your personal data and your rights, please refer to our Information Clause and Privacy Policy.

    * Required fields.