Skip to content

Published · Updated · 6 min read

What is the EU AI Act Compliance? Checklist, Requirements & Penalties [Guide]

The EU AI Act is here: what to expect

Kimberly NyitrayKimberly NyitraySenior Counsel

The EU AI Act is here, and parts of it are already starting to take effect. But for most companies, the real question is not "what does the law say?" It is "what does this actually mean for me?"

What Does the EU AI Act Mean for Your Business?

The answer depends on what you are doing with AI. Are you building an AI system? Using one internally? Selling AI into the EU? Using a general-purpose AI model? Putting AI in a product that touches hiring, credit, education, law enforcement, healthcare, safety, or other regulated areas? The AI Act does not treat all AI the same. Your obligations depend on your role, your use case, and the level of risk.

The AI Act entered into force on August 1, 2024. The first rules started applying on February 2, 2025, including AI literacy obligations and a comprehensive set of prohibited AI practices, meaning banned AI practices had to stop by that date. General-purpose AI model obligations, governance rules, and penalties began applying on August 2, 2025, subject to certain transition periods. From there, the phasing continues: most remaining obligations apply from August 2, 2026, while certain high-risk AI systems now have extended transition periods under the 2026 Digital Omnibus, including high-risk AI systems embedded in regulated products, such as medical devices and machinery, which have until August 2, 2028. Certain high-risk use cases covered by Annex III have until December 2, 2027. So the work now is less about waiting for “the AI Act deadline” and more about figuring out which parts apply to your business, in what role, and when.

EU AI Act: Practical Starting Point

  1. What AI are we using?
  2. Are we building it, deploying it, or relying on a vendor?
  3. Does it touch customers, employees, or regulated decisions?
  4. Is it prohibited, high-risk, GPAI, transparency-related, or lower-risk?
  5. What evidence do we have that it is being managed?

What Are the EU AI Act Requirements for Your Business?

The Act's obligations aren't one list - they depend on your role and the risk tier of the specific system. Four tiers and what each currently requires:

  • Prohibited practices (in effect since February 2, 2025). Manipulative or subliminal techniques, exploiting vulnerabilities, social scoring, and - since the 2026 Digital Omnibus, from December 2, 2026 - AI that generates non-consensual intimate imagery or CSAM. If your business has any of these in production, the obligation is to stop, not to document.
  • General-purpose AI (GPAI) model obligations (in effect since August 2, 2025). Providers must maintain technical documentation, share information with downstream deployers, publish a training-content summary, and comply with EU copyright law. Providers of models with "systemic risk" carry added duties: evaluation, adversarial testing, incident reporting to the AI Office, and cybersecurity controls.
  • High-risk AI system obligations (phased through 2028). Providers owe a risk management system, data governance, technical documentation, logging, transparency to deployers, human-oversight design, and accuracy/robustness/cybersecurity testing, plus conformity assessment and EU database registration. Deployers owe use per instructions, assigned human oversight, monitoring, serious-incident reporting, and - for certain public-sector and high-impact uses - a fundamental rights impact assessment. Under the 2026 Digital Omnibus, most Annex III high-risk obligations now apply from December 2, 2027, and high-risk systems embedded in regulated products (medical devices, machinery) from August 2, 2028.
  • Transparency obligations for limited-risk systems (in effect from August 2, 2026). Disclose when someone is interacting with an AI system, and label AI-generated or manipulated audio, image, video, or text - including deepfakes - unless a narrow exemption applies.

Who owes what also depends on your role, not just your product:

RoleCore duties
ProviderBuilds or places the system on the EU market - owns conformity assessment, technical documentation, registration
DeployerUses the system under its own authority - owns oversight, monitoring, incident reporting, employee notice
Importer / distributorBrings a non-EU provider's system into the EU market - owns conformity verification, CE marking checks, 10-year record-keeping

How Should Companies Start an EU AI Act Compliance Inventory?

The work starts with an inventory. Not a perfect spreadsheet that gets stale in a month, but a real map of where AI shows up in the business. This includes product features, internal tools, vendor systems, and workflows that affect customers, employees, or regulated decisions. That means understanding where AI is generating, classifying, recommending, summarizing, detecting, scoring, or deciding.

From there, the question becomes ownership. Who knows what the system does? What data does it use? Who is the vendor? Which humans review the output? What logs exist? What happens when the system is wrong?

Why Is AI Governance an Evidence Exercise?

That is the real shift under the EU AI Act. AI governance is no longer just a policy statement or a procurement checklist. It is an evidence exercise. Companies will need to show that they know where AI is being used, how risk is being classified, what controls are in place, and whether those controls are actually working.

The companies that are best prepared will be the ones that can connect their AI policies to real controls, evidence, and accountability.

What Are the Potential EU AI Act Penalties?

The financial exposure can be significant. For certain infringements involving prohibited AI practices or specific data requirements, fines can reach €35 million or 7% of a company's total worldwide annual turnover for the preceding financial year, whichever is higher. Other breaches can attract fines of up to €15 million or 3% of worldwide annual turnover, while supplying incorrect, incomplete, or misleading information can result in fines of up to €7.5 million or 1%.

For companies, this makes classification, documentation, oversight, and evidence more than administrative exercises. They are part of the practical compliance framework.

What Should Be on Your EU AI Act Compliance Checklist?

Turn the requirements above into work. A practical sequence:

  • Inventory every AI system touching the business - product features, internal tools, and vendor or embedded AI, not just tools with "AI" in the name
  • Classify each system's risk tier - prohibited, high-risk (check against Annex III), GPAI, limited-risk/transparency, or minimal-risk
  • Confirm your role per system - provider, deployer, importer, or distributor; a company can hold more than one role across its stack
  • Assign an owner per system - someone who can answer what data it uses, what the vendor guarantees, and what humans review before a decision goes out
  • Shut down anything prohibited immediately - including the December 2026 additions (non-consensual intimate imagery, CSAM-generating tools)
  • Build the technical file for high-risk and GPAI systems now - documentation, data governance records, testing results, logging, even with the 2027/2028 deadlines still ahead; this takes longer to build than to deploy
  • Put transparency notices in place - chatbot disclosures and AI-content labeling have applied since August 2, 2026
  • Set up incident-reporting paths - to the AI Office for GPAI systemic-risk providers, to the relevant market surveillance authority for high-risk deployers
  • Run AI literacy training for staff who use or oversee these systems - still required under Article 4, though the Digital Omnibus dropped the per-individual guarantee
  • Check whether the business qualifies for small mid-cap relief - under 750 employees and ≤ €150M turnover unlocks simplified templates and sandbox priority
  • Put a review cadence on the calendar - vendor changes, new features, and further Digital Omnibus guidance will keep shifting this list; quarterly is a reasonable default
Key takeaways
  • The EU AI Act does not treat every AI system the same. Obligations depend on the organization's role, the AI system, and its intended use.
  • The AI Act entered into force on August 1, 2024, while its requirements are being introduced progressively.
  • Prohibited AI practices began applying on February 2, 2025, while governance and general-purpose AI model obligations began applying on August 2, 2025.
  • The Act is broadly applicable from August 2, 2026, but certain high-risk AI rules now have extended transition periods under the 2026 Digital Omnibus.
  • Penalties can reach €35 million or 7% of worldwide annual turnover, depending on the infringement.
  • The practical starting point is an AI inventory that identifies systems, vendors, use cases, owners, data, human oversight, and evidence of controls.
TL;DR
Not one-size-fits-allObligations depend on an organization's role, the specific AI system, and its intended use, not a uniform rule applied to every company.
Phased timelineThe Act entered into force in August 2024; prohibited practices and AI literacy started February 2025; GPAI and governance rules started August 2025; broader applicability begins August 2026.
Extended deadlines for high-risk systemsUnder the 2026 Digital Omnibus, certain high-risk use cases now have until December 2027, and high-risk systems in regulated products until August 2028.
PenaltiesFines can reach 35 million euros or 7% of worldwide turnover for the most serious violations, with lower tiers for other breaches.
Where to startBuild a real inventory of where AI is used across products, internal tools, and vendors, covering ownership, data inputs, human oversight, and evidence of controls.
Governance is now an evidence exerciseCompanies increasingly need to show, not just state, that AI risk is being classified and managed, since policy statements alone are no longer sufficient.
FAQs

Does every company using AI have the same EU AI Act obligations?

No, obligations depend on the organization's role, the specific AI system, and its intended purpose and risk classification, since the Act uses a risk-based framework.

Has the EU AI Act's timeline changed?

Yes. While core obligations began applying through 2025-2026, the 2026 Digital Omnibus extended transition periods for certain high-risk AI systems to December 2027 and August 2028.

Is AI literacy still required under the Act?

Yes, Article 4 still requires providers and deployers to support AI literacy among relevant staff, though the 2026 Digital Omnibus removed the requirement to guarantee a specific literacy level for each individual.

What should a company document for AI governance?

At minimum, where AI is used, what each system does, who owns it, what data it uses, which vendors are involved, what human oversight exists, and what evidence supports the compliance position.

Where should a company start with EU AI Act compliance?

Start with an inventory of AI systems and use cases across products, internal processes, and vendors, then determine the organization's role, assess applicable risk classifications, and document controls and evidence.