info
This article describes the state of play around the European AI Regulation (EU 2024/1689) as of 10 July 2026, following the final adoption of the Digital Omnibus on AI, and was re-checked against new developments on 20 August 2026. The legislation is always moving. For specific situations, always consult a legal advisor. version 3.0

Free AI Act Readiness Check for SMEs

Know where your organisation stands in fifteen minutes. This free check translates the law into concrete questions and builds your dossier automatically along the way:

  • Know where you stand in fifteen minutes
  • Automatic AI Act dossier: register, transparency statement, action plan, policy outline and calendar reminders
  • Privacy-first: everything stays in your browser, we store nothing
  • Free, and also available in Dutch

Start your check

The European AI Regulation, better known as the EU AI Act, is the first binding AI legislation in the world. The law was published in the Official Journal of the European Union on 12 July 2024, entered into force on 1 August 2024 and has been applying in phases ever since. From 2 August 2026 the bulk of the regulation genuinely starts to bite: the transparency obligations under Article 50, the enforcement powers over general-purpose AI, and the full penalty regime. The heavy high-risk obligations, by contrast, have been pushed back to 2 December 2027 and 2 August 2028.

That distinction is crucial and is frequently misunderstood in practice. A delay of the high-risk deadlines does not make 2 August 2026 a quiet date. For most organisations that use AI through a subscription or an integrated tool, that is precisely the moment their first concrete obligations become enforceable.

In this guide we explain what the regulation covers, which risk categories exist, which deadlines apply after the Omnibus, and how your organisation can become compliant step by step. We close with the most common mistakes and a practical roadmap.


What changed recently?

The most important development since the previous version of this article is that the so-called Digital Omnibus on AI, also referred to as the AI Omnibus or Omnibus VII, has moved from political agreement to completed legislation.

The political agreement of 7 May 2026 is now final. The European Parliament approved the text at first reading on 16 June 2026, after which the Council of the European Union gave its definitive approval on 29 June 2026. This concluded the ordinary legislative procedure. The amending regulation will be published in the Official Journal and enters into force on the third day following publication, well ahead of 2 August 2026.

DateEvent
19 November 2025European Commission presents the Digital Omnibus package.
13 March 2026Council adopts its negotiating position.
28 April 2026Second trilogue ends without agreement.
7 May 2026Provisional political agreement between Parliament, Council and Commission.
13 May 2026Publication of the final compromise text, confirmed by Member States.
19 May 2026Commission publishes draft guidelines on the classification of high-risk AI systems.
10 June 2026Commission publishes the Code of Practice on Transparency of AI-Generated Content.
16 June 2026European Parliament approves the Omnibus at first reading.
29 June 2026Council grants final approval. Legislative procedure concluded.
7 July 2026Commission presents the EU Action Plan on Cybersecurity and Artificial Intelligence.
9 July 2026Commission publishes its opinion on the assessment of the Code of Practice on Transparency of AI-generated content.
22 July 2026Deadline to appear on the first public list of initial signatories to the Code of Practice.
warning
Mind the nuance when communicating with clients. The new deadlines only become legally binding once the amending regulation actually appears in the Official Journal and enters into force. Until that moment the original dates formally remain in effect. The substantive outcome is settled, but the publication date determines when the clock starts running.

The core of the Omnibus in five points:

  1. Deferral of the high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
  2. Two new prohibited practices in Article 5: nudifier applications and AI-generated child sexual abuse material, applying from 2 December 2026.
  3. A grace period until 2 December 2026 for machine-readable marking of synthetic content by systems already on the market before 2 August 2026.
  4. Resolution of the double compliance between the AI Act and sectoral product legislation, in particular the Machinery Regulation.
  5. Extension of the SME simplifications to small mid-caps and a reformulation of the AI literacy obligation.

What has not changed: the risk-based structure, the conformity assessment model, the dedicated track for general-purpose AI, the AI Office and the full penalty regime all remain intact.


What is the EU AI Act?

The AI Act is European legislation that regulates artificial intelligence based on the risk a system may pose to people and society. The greater the risk, the heavier the requirements. The regulation uses a tiered approach with four categories, each carrying its own obligations.

The AI Act applies extraterritorially. Organisations established outside the EU must also comply as soon as their AI systems, or the output of those systems, are used within the EU. In legal circles this is known as the Brussels Effect.

Under the final text, an AI system is a machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment, and that infers from the input it receives how to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments.

The seven cumulative elements of the AI definitionexpand_more
ElementExplanation
Machine-basedThe system operates through hardware and software to perform computations.
Levels of autonomyThe system does not function without any human input, but must not rely purely on explicit instructions.
AdaptivenessThe ability to learn autonomously and adjust behaviour after deployment, optional for classification.
InferenceDeriving outputs from inputs via models rather than fixed programming rules.
Internal objectivesGoals that are explicitly embedded or implicitly derived from behaviour.
Intended purposeThe external objective set by the provider.
Influence on environmentThe capacity of the output to steer decisions or actions.

Systems that rely exclusively on simple mathematical optimisation or long-established methods, such as standard linear or logistic regression without adaptive components, fall outside the scope. Once these methods are combined with techniques such as reinforcement learning, they are generally treated as AI systems.


The four risk categories

blockUnacceptable risk
AI applications that pose a clear threat to safety, livelihoods or fundamental rights. Prohibited in the EU since 2 February 2025, with two new prohibitions from 2 December 2026.
warningHigh risk
Systems that affect fundamental rights or safety. Permitted, but with the strictest conformity requirements. Deadline moved to 2 December 2027.
visibilityLimited risk
Chatbots, deepfakes and systems with transparency duties. Users must know they are interacting with a machine. Applies from 2 August 2026.
check_circleMinimal risk
Spam filters, recommendation systems and AI in video games. No additional legal obligations, voluntary codes of conduct are encouraged.

1. Prohibited AI practices

Since 2 February 2025, eight categories of AI applications have been fully banned in the EU. The legislator has drawn a hard line against practices considered unethical or manipulative.

  • check_circleHarmful manipulation through subliminal techniques that alter behaviour unconsciously.
  • check_circleExploitation of vulnerabilities based on age, disability or socio-economic situation.
  • check_circleSocial scoring by public authorities or private entities based on behaviour or personality.
  • check_circlePredictive policing that forecasts the likelihood of a crime based on profiling.
  • check_circleEmotion recognition in the workplace or in educational institutions, except for strict safety purposes.
  • check_circleBiometric categorisation based on race, religion, political opinion or sexual orientation.
  • check_circleReal-time remote biometric identification in public spaces by law enforcement.
  • check_circleUntargeted scraping of biometric data from the internet or CCTV.

Two new prohibitions from 2 December 2026

The Omnibus adds two practices to Article 5. These are not yet in force and only become enforceable on 2 December 2026.

warning
The nudifier ban is broader than most business owners assume. It captures not only systems designed to create non-consensual intimate imagery, but also systems placed on the market without reasonable safety measures that would prevent such use. Deployers using such a system are equally caught.
  1. AI systems that generate or manipulate realistic depictions of an identifiable person's intimate parts, or of an identifiable person engaged in sexually explicit activity, without that person's freely given, specific, informed, unambiguous and explicit consent.
  2. AI systems that generate or manipulate child sexual abuse material within the meaning of Directive 2011/93/EU, subject to a narrow carve-out where national law recognises a without right defence.

The prohibition extends to three acts: placing a system on the market for this purpose, placing a system on the market without reasonable safety measures to prevent such use, and use of the system by a deployer. Whether safety measures are reasonable is assessed against the state of the art and whether they demonstrably reduce risk. Breach falls in the heaviest penalty tier: up to 35 million euro or 7 percent of global annual turnover. The Commission has announced further guidelines on the precise scope.

2. High-risk AI

High-risk systems are permitted provided the strictest requirements are met. These systems are identified through two routes. The first covers systems acting as a safety component in products already governed by existing EU harmonisation legislation, such as medical devices, lifts and radio equipment. The second covers stand-alone systems explicitly listed in Annex III.

warning
Working with AI in HR, lending, education, healthcare or access to public services? There is a strong chance you fall into this category and must meet heavy compliance requirements. The deadline moved, the obligation did not.

Examples of Annex III applications:

  • Biometrics and remote biometric identification
  • Critical infrastructure such as road traffic, water supply and electricity
  • Education and vocational training, including admission and exam grading
  • Employment and workforce management, including targeted job advertising, filtering applications, performance evaluation, task allocation, promotion and termination
  • Access to essential services such as credit scoring and insurance risk assessment
  • Law enforcement, migration, asylum and border control
  • Administration of justice and democratic processes

For these systems, providers must carry out a conformity assessment, implement a risk management system, draw up technical documentation and ensure effective human oversight.

lightbulb
On 19 May 2026 the Commission published draft guidelines on the classification of high-risk AI systems, with practical examples per sector and use case. This is currently the most usable document for substantiating your own classification.

Transitional regime and the notion of significant change

An important but underexposed part of the transitional regime: the Chapter III high-risk obligations apply to systems already on the market before the date of application only where those systems subsequently undergo significant design changes.

warning
A system placed on the market before 2 December 2027 (Annex III) or before 2 August 2028 (Annex I) therefore benefits from a grandfathering regime, provided its design remains unchanged. However, the threshold for a significant change has not yet been defined. That is a real gap in legal certainty that belongs in your product planning.

3. Limited-risk AI: the deadline that really is 2 August 2026

This tier covers systems subject to transparency requirements but not to heavy compliance duties. Article 50 sets out four duties:

  1. Article 50(1): inform people that they are interacting with an AI system, for example a chatbot.
  2. Article 50(2): mark generative output in a machine-readable format as artificially generated or manipulated.
  3. Article 50(3): inform people exposed to emotion recognition or biometric categorisation.
  4. Article 50(4): label deepfakes, as well as AI-generated or AI-manipulated text published to inform the public on matters of public interest, unless it has undergone human review with editorial responsibility assumed.

Article 50 has not been delayed. The transparency obligations become enforceable on 2 August 2026. Only the machine-readable marking under Article 50(2) benefits from a grace period: generative systems already placed on the market or put into service before 2 August 2026 have until 2 December 2026. Systems entering the market after that date must comply immediately.

The Code of Practice on Transparency of AI-Generated Content

On 10 June 2026 the Commission published the final Code of Practice on marking and labelling AI-generated content. It was developed through a multi-stakeholder process involving more than 180 participants and six independent experts appointed by the AI Office.

AspectExplanation
StatusVoluntary instrument, not a replacement for Article 50 or the Commission guidelines.
StructureTwo separate sections, one for providers and one for deployers, signable independently.
EffectIf assessed positively, signatories may rely on the Code to demonstrate compliance.
AssessmentOn 9 July 2026 the Commission published its opinion on the assessment of the Code, alongside the AI Board.
SigningTo appear on the first public list, the form must be submitted before 18:00 CET on 22 July 2026. Signing later remains possible.
lightbulb
Signing reduces administrative burden but does not guarantee compliance. Market surveillance authorities remain competent to assess Article 50 compliance independently. If you choose your own route, you must demonstrate its adequacy yourself.

In parallel, the Commission is finalising guidelines interpreting the scope of Article 50, to be published ahead of 2 August 2026. The draft text indicates, among other things, that a deepfake must show an appreciable rather than identical resemblance, that the subject must be realistic and capable of existing, and that minor technical edits such as colour correction or noise reduction do not by themselves create a deepfake.

4. Minimal risk

The vast majority of AI applications, such as spam filters, recommendation systems and AI in video games, fall into this category. No additional legal obligations apply under the regulation, although voluntary codes of conduct are encouraged.


General-Purpose AI: regulating the foundations

The rapid rise of Large Language Models such as GPT, Claude and Gemini led to a separate chapter on General-Purpose AI, or GPAI. These models can be integrated into countless downstream applications, so specific rules apply to their providers. Those obligations have applied since 2 August 2025.

The Commission's enforcement powers over GPAI providers only switch on from 2 August 2026. The first year was therefore compliance on paper without penalty exposure. That now changes.

Providers of GPAI models must:

  1. Maintain technical documentation about the model and its training.
  2. Provide information to downstream users integrating the model.
  3. Operate a policy to comply with EU copyright law.
  4. Publish a public summary of the training data used.
Requirements for the public training data summaryexpand_more
SectionRequired information
Model characteristicsModalities such as text, audio and video, language coverage and intended use.
Source attributionDescription of datasets, individual listing of large datasets, narrative explanation of web-scraped data.
Crawling detailsList of the top ten percent of domain names, five percent for SMEs, and operational details of web crawlers.
Copyright and moderationExplanation of compliance with Text and Data Mining opt-outs and measures against illegal content.
Synthetic dataDisclosure of whether training data was generated by other AI models and identification of those source models.

Models trained with compute exceeding ten to the power of twenty-five floating point operations are automatically classified as models with systemic risk. Providers of such models must conduct additional evaluations, mitigate risks through adversarial testing and report serious incidents directly to the European AI Office.

The GPAI Code of Practice

On 10 July 2025 the AI Office published the voluntary GPAI Code of Practice, covering three chapters: Transparency, Copyright, and Safety and Security. Signing earns a rebuttable presumption of conformity and a lighter administrative load. Roughly twenty-four organisations have signed, including Amazon, Anthropic, Google, IBM, Microsoft, Mistral AI, Aleph Alpha, Cohere and Samsung Electronics. Meta declined to sign, and xAI signed only the Safety and Security chapter.

The Omnibus additionally clarifies the division of competence between the AI Office and national authorities for supervising AI systems built on GPAI models. Until now this was a grey area.


Provider or deployer: your responsibility

This is the part of the law that surprises most business owners. Even if you do not build AI yourself but simply buy it through a subscription, you are legally a deployer and carry your own obligations.

The law draws a fundamental distinction between providers, meaning companies that develop AI systems or place them on the market, and deployers, meaning organisations that use AI in their working processes. Under Article 3 of the AI Act, any organisation applying AI to support or automate business processes is a deployer. The regulation also assigns roles to importers, distributors and authorised representatives.

Your responsibility as a deployer includes:

  • Understanding the purpose for which you use the AI and the associated risks.
  • Ensuring human oversight for decisions that directly affect people.
  • Being transparent towards customers, applicants and other affected persons.
  • Documenting how you use AI and what measures you have taken.
  • Meeting the AI literacy requirement for your staff.
warning
If you substantially modify an existing AI system or adapt it for a specific high-risk purpose, you legally become the provider. Full responsibility for technical documentation and conformity assessment shifts to your organisation, even though you did not build the core model. A startup that buys a model, wraps it in its own interface, prompts and workflows, and then sells it into HR or education can easily end up in the provider role.

Which tools do you actually use?

Many business owners do not know exactly which AI systems are used in their organisation, for what, and by whom. That is usually the first obstacle: you cannot assess compliance without an inventory. Below are common tools and the risk category they typically fall into.

Tool or systemRisk categoryExplanation
ChatGPT, Claude, Gemini for internal tasksLimited or minimalLow risk when used for text, summarisation or analysis. Responsibility shifts once decisions about people are involved.
AI chatbot on your websiteLimited riskArticle 50(1). From 2 August 2026 users must explicitly know they are talking to AI.
Image or video generator in marketingLimited riskArticles 50(2) and 50(4). Machine-readable marking and visible labelling of deepfakes.
AI recruitment tool ranking candidatesHigh riskFalls under Annex III, employment and workforce management. Deadline 2 December 2027.
AI in accounting or invoicing softwareMinimal riskNo legal obligations, provided no decisions about people are made.
AI scoring for credit or payment behaviourHigh riskExplicitly named in Annex III.
AI for automated CV screeningHigh riskFalls under employment and workforce management.
Marketing AI for segmentationLimited or minimalDepends on the impact on individuals.
AI in medical diagnostic supportHigh riskFalls under regulated products. Deadline 2 August 2028.
AI in machinery and industrial controlOutside direct scopeLargely handled under the Machinery Regulation after the Omnibus.

Timeline and deadlines after the Omnibus

The AI Act is being introduced in phases. The Digital Omnibus on AI moved several deadlines, but the overall direction stands. A wait-and-see strategy is risky, because conformity assessments and selecting a Notified Body often take twelve to eighteen months.

ComponentOriginal dateCurrent date
Prohibited practices (Article 5)2 February 2025Already in force
AI literacy (Article 4)2 February 2025Already in force, text revised
GPAI obligations2 August 2025Already in force
Transparency for chatbots and deepfakes (Article 50)2 August 20262 August 2026, unchanged
GPAI enforcement and penalty regime2 August 20262 August 2026, unchanged
Machine-readable marking, legacy systems (Article 50(2))2 August 20262 December 2026
Ban on nudifier apps and AI-generated CSAMDid not exist2 December 2026
National AI regulatory sandboxes2 August 20262 August 2027
Interoperable watermark detection (Code of Practice)Did not exist2 February 2027
High-risk AI, Annex III stand-alone2 August 20262 December 2027
High-risk AI, Annex I regulated products2 August 20272 August 2028
info
The reason for the delay is emphatically not that Brussels takes the law less seriously. European standardisation bodies fell behind in delivering harmonised standards, the designation of national competent authorities stalled, and the conformity assessment infrastructure was not ready. Without those instruments, companies would have to comply without knowing how. Parliament deliberately chose fixed dates rather than the Commission's original proposal to tie the date of application to a Commission decision on the readiness of standards. Those fixed dates now stand, regardless of whether the standards exist by then.
warning
Treat the delay as planning room, not as a breather. Annex III systems require risk assessments, technical documentation, conformity assessments and, in many cases, notified body involvement. None of that gets organised in the final quarter before a deadline.

Sectoral overlap and the machinery carve-out

One of the most persistent criticisms of the original AI Act was double compliance for products already covered by EU product safety legislation. An AI-driven industrial machine had to satisfy both the Machinery Regulation and the AI Act simultaneously, with partly overlapping and sometimes contradictory requirements.

The Omnibus addresses this directly:

  • Machinery falls outside the direct application of the AI Act where overlap exists. Health and safety aspects are handled directly under the Machinery Regulation.
  • For other sectoral legislation, such as that governing medical devices, connected vehicles and toys, the Commission will issue implementing acts.
  • The definition of safety component has been amended.
  • Alongside the AI Act, the AI Omnibus also amends the EASA Basic Regulation (EU) 2018/1139, keeping AI integration in aviation within the existing safety regime.
lightbulb
Building AI into a physical product? Do not work out on your own which regulation prevails. The implementing acts have not been published yet. Document your assumptions and watch the Commission's publications.

Relief for SMEs and small mid-caps

The AI Act already contained a simplified compliance framework for SMEs. The Omnibus extends those facilities to small mid-cap companies, abbreviated in the legal text as SMCs.

AspectDetail
ScopeCompanies up to roughly 750 employees and 150 million euro annual turnover.
Simplified documentationStandardised templates for technical documentation.
Sandbox accessPriority access to national AI regulatory sandboxes.
PenaltiesProportionally lower maximum amounts.
GuidanceSimplified guidance from the Commission and the AI Office.
info
The extension has drawn criticism. The European Parliament noted that treating SMCs and genuine SMEs identically risks creating competitive imbalances, particularly to the detriment of micro-enterprises.

Registration in the public EU database

The AI Act provides for a central, publicly searchable EU database in which high-risk AI systems are registered. The registration duty has been extended to providers of so-called exempted AI systems, meaning systems that fall outside the high-risk category based on a risk assessment despite operating in an Annex III domain.

A lighter information duty applies to these exempted systems. In Annex VIII, Section B, points 7 and 9 have been deleted for systems self-assessed as non-high-risk. The underlying registration requirement, however, stands in full.

lightbulb
Bear in mind that even if your system is classified as exempt, you must substantiate and register that classification yourself. Retain the risk assessment, the justification for the exemption and the supporting documentation for at least the lifecycle of the system plus ten years.

What this means in practice:

  • Providers of Annex III systems who consider their system to pose no significant risk must be able to demonstrate this through a structured self-assessment.
  • Registration in the EU database is publicly searchable, so customers and regulators can see that your system exists and what the exemption claim is.
  • In case of doubt, or where shortcomings are identified, the regulator can withdraw the exemption and impose high-risk obligations retroactively.

AI literacy: Article 4 after the Omnibus

Since 2 February 2025, organisations must take measures to ensure the AI literacy of their staff. This applies to everyone working with AI output, from HR managers to customer service staff.

The Commission originally proposed shifting this duty entirely from the organisation to the EU and national authorities. That proposal did not survive. In the final text the duty has, however, been reformulated.

Providers and deployers must take measures to support the development of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf. The law explicitly states that this obligation does not require them to guarantee any specific level of AI literacy for any individual. The Commission and Member States are obliged to support and facilitate organisations in fulfilling it.

That is a best-efforts obligation rather than an obligation of result. It lowers the evidentiary burden, but it does not remove the duty.

lightbulb
Start an AI literacy training programme now. It is an obligation that already applies, and it immediately reduces risk on the work floor. A good training combines AI fundamentals with practical examples from your own organisation. Record attendance, that is your evidence.

In the Dutch implementing act for the AI Regulation, this duty is expected to be enforced through remedial sanctions such as an order subject to a penalty payment. Critics argue this discourages proactive implementation, because companies only need to act once a shortcoming has been identified. There are calls for a stronger role for the works council in pressuring employers.


Human oversight: Article 14

High-risk AI systems must be designed so that natural persons can exercise effective oversight during the period of use. This oversight must prevent people from blindly trusting a machine's suggestions, a phenomenon known in the literature as automation bias.

The overseer must:

  • Understand the system's operation well enough to judge it critically.
  • Be able to disregard outputs or halt the system entirely.
  • Be aware of the system's limitations and possible errors.
  • Be able to request a second opinion or arrange an independent assessment in case of doubt.

Dutch enforcement: the hybrid supervisory model

In the Netherlands, supervision of the AI Regulation is laid down in the national implementing act. The government has opted for a hybrid model combining sectoral expertise with central coordination.

gavelDutch Data Protection Authority
Coordinating supervisor for algorithms and AI since 2023. Supervises high-risk applications without an existing sectoral regulator, such as education, recruitment and selection.
hubDutch Authority for Digital Infrastructure
Focuses on AI in critical infrastructure and, together with the DPA, streamlines coordination between regulators.

Existing sectoral regulators retain their role for AI in their domain:

  • NVWA for consumer products
  • IGJ for medical devices
  • AFM and DNB for the financial sector
  • ILT for transport

Interaction with the GDPR: synergy or conflict?

For systems processing personal data, the GDPR and the AI Act apply simultaneously. Under the GDPR, a Data Protection Impact Assessment is mandatory for high-risk processing. Under the AI Act, certain deployers, notably public authorities and providers of essential services, must carry out a Fundamental Rights Impact Assessment.

AspectDPIA (GDPR)FRIA (AI Act)
FocusProtection of personal dataBroad fundamental rights
Mandatory forHigh-risk processingCertain deployers of high-risk AI
ScopePrivacy and data breachesHuman dignity, non-discrimination, freedom of expression, children's rights
lightbulb
Combine FRIA and DPIA into a joint process. This reduces administrative burden and gives a holistic view of the impact on the rights of data subjects.

A notable provision in the AI Act allows providers of high-risk systems to temporarily process special categories of personal data, such as race, religion or health, in order to detect and correct bias in models. The Omnibus broadens this: using special category personal data for bias detection and mitigation becomes easier, provided it is strictly necessary. It remains a direct exception to the general processing prohibition under the GDPR. Strict security and pseudonymisation measures remain mandatory and the data must be deleted after correction.

info
Note: the broader Digital Omnibus, which amends the GDPR, NIS2 and the Data Act, is a separate legislative track and is not yet concluded. The Council was due to vote on it on 29 June 2026, but this was postponed due to disagreement over its content. Only the AI part is final.

Penalty structure

The sanctions are designed to deter even large tech companies. Proportionally lower amounts apply to SMEs, startups and small mid-caps. The Omnibus leaves the penalty regime unchanged.

Type of infringementMaximum fineTurnover-based alternative
Use of prohibited AI practices35 million euro7 percent of global annual turnover
Non-compliance with high-risk requirements15 million euro3 percent of global annual turnover
Breach of transparency rules15 million euro3 percent of global annual turnover
Incorrect information to authorities7.5 million euro1 percent of global annual turnover
warning
With the nudifier ban, a second exposure sits alongside the fine: potential civil and mass claims under EU product liability rules.

Roadmap: how to become compliant

A structured approach is essential to be ready in time for the 2026, 2027 and 2028 deadlines. Below is the practical roadmap Cloud Captains uses in compliance projects for clients.

1
Step 1: AI inventory
Map every AI system used within the organisation, including tools staff adopt ad hoc. This so-called Shadow AI is often the biggest blind spot. Document the purpose, the provider, the department and the stakeholders involved for each system.
2
Step 2: Classification
Determine the risk level per system and check the Annex III categories thoroughly. Use the draft guidelines of 19 May 2026 as a reference. Distinguish between the provider and deployer role. Document why a given classification applies.
3
Step 3: Get Article 50 ready for 2 August 2026
This is your next hard deadline. Label your chatbot, mark generative output in a machine-readable format, label deepfakes visibly. Assess whether signing the Code of Practice is worthwhile and whether you want to make the 22 July 2026 deadline.
4
Step 4: AI literacy
Implement a training programme for all staff working with AI output. Start with management and HR, then expand across the organisation. Record attendance.
5
Step 5: Risk management system
For high-risk systems you must establish a formal risk management system covering the full lifecycle, from design to post-market monitoring. Start no later than early 2027.
6
Step 6: Documentation and transparency
Draw up technical documentation, carry out a Fundamental Rights Impact Assessment where required, and ensure transparency towards end users. Lock down contractual guarantees with your suppliers.
7
Step 7: Governance
Appoint an AI Officer or a multidisciplinary working group that oversees the lifecycle of systems. Ensure clear responsibilities and escalation procedures.
8
Step 8: Ongoing monitoring
Implement post-market surveillance, incident reporting and periodic reassessments. The law requires you to actively follow up on changes in risk.

Common misconceptions and pitfalls

1. Assuming 2 August 2026 has been called off

The most common misconception right now. The delay applies exclusively to the high-risk obligations in Chapter III. Article 50, the GPAI enforcement powers and the penalty regime all take effect on 2 August 2026.

2. Provider status through modification

An organisation that substantially modifies an existing AI system or adapts it for a specific high-risk purpose becomes the provider in legal terms. Full responsibility for technical documentation and conformity assessment shifts to that organisation.

3. The incident reporting paradox

Following an AI-related incident, an organisation often has to report within three different timeframes to three different authorities: 24 hours for NIS2, 72 hours for the GDPR and fifteen days for the AI Act. The risk is that statements made in the first 24 hours can later be used against the organisation in a GDPR or AI investigation.

4. Ambiguity in GPAI metrics

The obligation for GPAI providers to disclose the volume of scraped content leaves open whether this should be expressed in file size, token count or number of documents. This ambiguity can lead to inconsistent reporting.

5. The supply chain

Organisations deploying AI systems must obtain contractual guarantees from their suppliers. GPAI model providers are required to share information with downstream users, but the depth of that information is frequently a source of commercial dispute. Nail this down in your procurement contracts. Larger clients now routinely demand AI inventories, role mapping and vendor documentation, including from freelancers and small agencies.

6. Open source is not a free pass

Models released under open-source licences are not automatically exempt. Certain transparency exemptions apply to non-systemic open-source models, but the baseline obligations remain.

7. The undefined notion of significant change

The grandfathering regime hinges entirely on what counts as a significant design change. That threshold has not been defined. Anyone counting on an existing system staying out of scope is taking a risk that only becomes visible in hindsight.


The environmental dimension

The AI Act introduces, for the first time, obligations around the ecological footprint of technology. Providers of GPAI models must document known or estimated energy consumption. The European Commission is working on delegated acts to establish standardised measurement and calculation methods. In future, the ecological impact of an AI system may even factor into admission in specific sectors.


AI and cybersecurity

On 7 July 2026 the European Commission presented the EU Action Plan on Cybersecurity and Artificial Intelligence. The plan sets out a coordinated approach to help Member States, businesses and public authorities address the cybersecurity and resilience challenges posed by the most advanced AI models.

  • The Commission will launch a call to increase EU capacity for evaluating AI models, expected to be operational by 2027.
  • The Commission and ENISA will develop a blueprint for secure access to advanced AI systems for cybersecurity purposes.
  • A secure testing platform will be established so organisations in critical sectors such as energy, transport, health, finance and public administration can safely test and deploy AI solutions.

Operational costs for SMEs

According to European Commission impact assessments, compliance costs for an SME can run to around four hundred thousand euro per high-risk product. That sounds steep, but it is spread across several components.

Cost itemExplanationEstimated SME range
Quality management systemWorkflows for data governance and monitoring71,400 to 330,000 euro
Technical documentationDescription of architecture and trainingPart of the QMS
Conformity assessmentExternal review by a Notified BodyUp to 1 million euro, one-off
AI literacy and trainingTraining staff in line with Article 46,000 to 7,000 euro
Ongoing monitoringPost-market surveillance and incident reportingAnnual overhead of 17 percent
info
For many SMEs that only deploy AI rather than develop it, costs stay limited to training, documentation and governance. The heavy figures apply mainly to providers of high-risk systems. With the SME facilities extended to small mid-caps, more organisations now fall under the lighter regime.

Conclusion

The AI Act is far more than a legal checkbox. It is a redefinition of the innovation process. To implement it successfully, organisations must abandon the idea that AI compliance is a task for the IT department alone, or the legal department alone. It touches strategy, governance, HR and operations.

The Omnibus has turned the clock back sixteen months on the heaviest part of the law, but the architecture has remained entirely intact. The risk categories, the conformity assessments, the GPAI track and the AI Office are all still standing. And the date that genuinely matters for most organisations, 2 August 2026, has not moved.

The costs and regulatory burden are significant, but the Brussels Effect will likely make the European norm the global standard for trustworthy, human-centric artificial intelligence. Those who start now build trust with customers and citizens, and avoid compliance becoming a late-stage problem.

The organisations that embrace the AI Act as an opportunity to get their governance in order will, in the long run, score better on trust, quality and customer loyalty than those who wait until the regulator is at the door.

- Cloud Captains

Free AI Act Readiness Check for SMEs

Know where your organisation stands in fifteen minutes. This free check translates the law into concrete questions and builds your dossier automatically along the way:

  • Know where you stand in fifteen minutes
  • Automatic AI Act dossier: register, transparency statement, action plan, policy outline and calendar reminders
  • Privacy-first: everything stays in your browser, we store nothing
  • Free, and also available in Dutch

Start your check