The EU AI Act is the first horizontal European framework that regulates artificial intelligence with a risk-based approach. It does not impose the same obligations on everyone: what a business must do depends on its role (provider or deployer), the use case and the risk tier of the system. It matters because, from August 2026, user-facing transparency obligations begin to apply, and because the penalties reach very high figures.
Many companies already use artificial intelligence without having formalized it: text assistants, classifiers, support chatbots, image generation tools or models embedded in third-party products. The EU AI Act sets rules for that usage, but not as a single identical checklist for everyone. This article explains what the regulation is, how its risk-tier classification works, the real application timeline (including the 2026 nuance) and the concrete steps an organization can take to get ready.
Key takeaways
- It is Regulation (EU) 2024/1689, the first horizontal EU framework for artificial intelligence.
- It classifies systems into four tiers: unacceptable risk (prohibited), high, limited and minimal, with a separate regime for general-purpose AI (GPAI) models.
- Prohibitions apply from February 2025 and GPAI provider obligations from August 2025.
- On 2 August 2026, the Article 50 transparency obligations and the Commission's oversight powers over GPAI begin to apply.
- Penalties reach up to 35 million euros or 7% of total worldwide annual turnover for prohibited practices.
- What each business must do depends on its role, the use case and the risk tier; it is not a single identical obligation for everyone.
What the EU AI Act is
The EU AI Act is Regulation (EU) 2024/1689, the European Union's first horizontal framework dedicated to artificial intelligence. Horizontal means it does not regulate a specific sector (such as healthcare or banking) but covers AI transversally, with rules that apply according to what the system does and the risk it creates, not according to the industry it is used in.
Its central logic is a risk-based approach. Rather than treating all artificial intelligence the same, the regulation grades obligations: the greater the risk a system poses to health, safety or fundamental rights, the stricter the requirements. That gradation is organized into four tiers, plus a specific regime for general-purpose models.
Why a horizontal, risk-based framework
The advantage of the risk-based approach is that it avoids drowning trivial AI uses in bureaucracy (a spam filter, a product recommender) while concentrating controls on the cases where an error can have serious consequences for people. For a business, this has a very clear practical implication: before "complying with the AI Act," you need to know which tier each system falls into, because everything else depends on that.
The four risk tiers
The regulation distinguishes four risk categories, and each carries a different set of obligations.
Unacceptable risk: prohibited practices
At the highest level are the AI practices considered to be of unacceptable risk, which are directly prohibited. These are uses deemed incompatible with fundamental rights or with the Union's values. For businesses, the rule here is simple: these uses are not permitted, there are no obligations to meet because the system simply cannot be deployed.
High risk: strict obligations
High-risk systems are those that can significantly affect people's safety or rights. They are not prohibited, but they are subject to a broad set of obligations: risk management throughout the lifecycle, governance of the data used to train and evaluate the model, technical documentation, effective human oversight and system robustness. This is the tier where compliance costs are highest and where it pays to plan ahead.
Limited risk: transparency obligations
At the limited-risk tier, the main requirement is transparency (Article 50). It is worth understanding it properly: Article 50 does not impose a single identical visible notice for all AI-generated content. Its obligations depend on the role (provider or deployer) and on the specific situation covered, and each situation has its own way of being met. For example, informing a person when they interact with a chatbot (an obligation of the system provider), marking synthetic content in a machine-readable way when a system generates it (also on the provider side), or disclosing when a deployer publishes a deepfake or an AI-generated or AI-manipulated text of public interest. Not every AI use falls under Article 50, and not all of them require exactly the same notice: the concrete requirement depends on who you are in the chain and on which situation you are in.
Minimal risk: no additional obligations
The vast majority of everyday AI uses fall into the minimal-risk tier, which carries no additional obligations under the regulation. Filters, recommenders or internal utilities usually sit here. This does not mean they are exempt from other rules (data protection, security, intellectual property), only that the AI Act adds no specific requirements on top.
General-purpose AI models (GPAI)
In addition to the four tiers, the regulation creates a separate regime for general-purpose AI (GPAI) models, that is, models not designed for a single task but that serve as a base for many different applications (for example, large language models). These models carry specific obligations for their providers, distinct from the high-risk systems regime.
For a business that does not train its own models but does integrate them, this point is relevant: although the regulatory weight of GPAI falls on the model provider, whoever embeds it in a product or service must understand what guarantees they receive and how that component fits into their own risk classification. If you work with conversational assistants, it is also worth reviewing the security risks of ChatGPT in businesses and the threat patterns captured in the OWASP Top 10 for LLMs.
Application timeline
The EU AI Act does not take effect all at once. Its obligations are staggered over time, and that timeline is one of the things that causes the most confusion. It is worth attributing each milestone to its date precisely.
Milestones already in force
The prohibitions (unacceptable-risk practices) apply from 2 February 2025. The obligations of general-purpose model providers apply from 2 August 2025. In other words, by the time August 2026 arrives, two layers of the regulation are already operating.
August 2026: transparency and GPAI oversight
On 2 August 2026, the Article 50 transparency obligations begin to apply. They are not a single universal notice, but a set of duties that depend on the role and the situation: warning about interaction with a chatbot, marking the synthetic content a system generates, or flagging deepfakes and certain AI-generated or AI-manipulated texts of public interest. Each situation falls on the provider or on the deployer depending on the case. On that same date, the European Commission acquires oversight and enforcement powers over general-purpose models. These user-facing obligations are the ones many businesses will notice first, because they directly affect products and communications already in the market.
Earlier GPAI models and the 2026 nuance
Providers of GPAI models launched before 2 August 2025 have until 2 August 2027 to comply. And there is an important current nuance: on 16 June 2026, the European Parliament approved the "Digital Omnibus" package, which postponed the high-risk obligations by 12 to 16 months. This postponement does not eliminate those obligations nor affect the other layers: it only delays the application of the high-risk tier. The user-facing transparency obligations do arrive in August 2026 as planned.
In other words: if your concern is a high-risk system, you gain some room; if your concern is disclosing that content is AI-generated or that the user is talking to a bot, the deadline has not moved.
Penalties
The regulation's penalty regime is tiered, in line with the risk logic. For prohibited practices, fines reach up to 35 million euros or 7% of total worldwide annual turnover, whichever is higher. For non-compliance with other obligations, up to 15 million euros or 3%. And for supplying incorrect information to authorities, up to 7.5 million euros or 1%.
These amounts, comparable to those of other major European frameworks, explain why the AI Act has quickly moved onto the board's agenda and not just onto that of the technical teams. The cost of a misclassification or a breach is not marginal.
What businesses must do
The practical question is not "do we comply with the AI Act?" in the abstract, but "what applies to us and what do we have to do?". The first step is always to take inventory.
Inventory your AI systems and uses
Many organizations do not know how much artificial intelligence they actually use. Models embedded in SaaS tools, extensions, personal team assistants or internal prototypes often stay off the radar. That ungoverned usage, so-called shadow AI, is the first obstacle to any serious compliance: you cannot classify what you do not know about. An honest inventory of systems and use cases is the starting point.
Determine role and risk tier
For each system you have to answer two questions. First: what is our role? The regulation distinguishes, among others, the provider (whoever develops or places the system on the market) from the deployer (whoever uses it under their own authority), and obligations differ by role. Second: which risk tier does it fall into? The concrete list of obligations follows from the combination of role and risk tier. This is where businesses most often go wrong by assuming that "everyone does the same thing."
Meet transparency, data governance and human oversight
Where it applies, you must execute the corresponding obligations: user-facing transparency (AI disclosures, marking of generated content, chatbot identification), governance of the data that feeds the models, documentation and effective human oversight. Data governance connects directly with the discipline of knowing and protecting where sensitive information lives, something we cover in the DSPM (Data Security Posture Management) guide.
Lean on voluntary frameworks
There are frameworks that help structure AI governance, such as the ISO/IEC 42001 standard (AI management system) or the NIST AI RMF (AI risk management framework). They are voluntary and useful for organizing processes, but one nuance should be clear: adopting them does not by itself demonstrate compliance with the AI Act. They serve as scaffolding, not as a certificate of conformity.
How the AI Act fits with other rules
The EU AI Act does not exist in isolation. It coexists with other European frameworks that a business is probably already facing, and understanding them together avoids duplicating effort. The NIS2 Directive imposes cybersecurity obligations on essential and important sectors; the Cyber Resilience Act (CRA) sets security requirements for products with digital elements; and DORA governs digital operational resilience in the financial sector. A high-risk AI system embedded in a connected product can touch several of these frameworks at once, so AI governance gains a lot when it is coordinated with the cybersecurity and data governance already in place.
Frequently asked questions
Who does the EU AI Act apply to?
It applies to those who develop, place on the market or use artificial intelligence systems that affect the Union's market, with obligations that vary according to role (provider or deployer), use case and risk tier. It is not a single identical obligation for everyone: it depends on that combination.
What changes on 2 August 2026?
The Article 50 transparency obligations begin to apply, along with the Commission's oversight and enforcement powers over general-purpose models. Article 50 is not a single identical notice for all AI content: it groups several situations (warning about interaction with a chatbot, marking synthetic content, flagging deepfakes and certain texts of public interest), and each one falls on the provider or on the deployer depending on the case. These are the user-facing obligations that many businesses will notice first.
Have all the regulation's obligations been postponed?
No. On 16 June 2026, the European Parliament approved the "Digital Omnibus" package, which postponed the high-risk obligations by 12 to 16 months. That postponement affects only the high-risk layer and does not eliminate it. The user-facing transparency obligations do arrive in August 2026.
What are the maximum penalties?
Up to 35 million euros or 7% of total worldwide annual turnover for prohibited practices; up to 15 million or 3% for non-compliance with other obligations; and up to 7.5 million or 1% for supplying incorrect information to authorities.
Is being certified in ISO/IEC 42001 or adopting the NIST AI RMF enough?
No. Frameworks such as ISO/IEC 42001 or the NIST AI RMF are voluntary and very useful for structuring AI governance, but adopting them does not by itself demonstrate compliance with the AI Act. They help organize the work; they do not replace the role and risk analysis the regulation requires.
Where do I start if I have done nothing yet?
Start by inventorying your AI systems and uses (including shadow AI), determine your role and risk tier for each one, and build the concrete list of obligations from there. Without that inventory and classification, any compliance plan rests on thin air.
Related resources
- Shadow AI: risks and governance for enterprises
- ChatGPT security in businesses: 2026 risks
- OWASP Top 10 for LLMs explained
- What is DSPM (Data Security Posture Management)
- Cyber Resilience Act (CRA) explained
- NIS2 Directive: enforcement and fines
- DORA: compliance guide for businesses 2026
Prepare your AI governance with Secra
At Secra we are an offensive cybersecurity company with our own vulnerability research program, with CVEs published in NVD and INCIBE-CERT (CVE-2025-40652 in CoverManager and CVE-2023-3512 in Setelsa ConacWin CB). That attacker's mindset lets us help you inventory your AI systems, understand your real exposure and structure governance before the obligations tighten. If you want a review tailored to your use case and risk tier, get in contact with us.
About the author
Secra Solutions team
Ethical hackers with OSCP, OSEP, OSWE, CRTO, CRTL and CARTE certifications, 7+ years of experience in offensive cybersecurity, and authors of CVE-2025-40652 and CVE-2023-3512.

