The essentials in 5 points
- The EU AI Act generally applies from 2 August 2026, but the AI Omnibus moved the main high-risk deadlines to 2027 and 2028.
- Deployers are covered, not only model providers: using an AI system in a business creates obligations.
- The heart of the framework: classify systems by risk level, then document, govern, and ensure transparency.
- AI literacy remains operationally important, but the July 2026 Omnibus replaced the company-level duty with non-binding encouragement.
- Penalties reach up to 35 M€ or 7 % of worldwide turnover for prohibited practices, with lower tiers for other breaches.
The short answer
2 August 2026 is not the AI Act’s entry into force. It is the date of general application and the start date for Article 50 transparency duties. The AI Omnibus entered into force on 27 July 2026 and extended the main high-risk timetable: Annex III use cases move to 2 December 2027, while AI embedded in regulated products moves to 2 August 2028.
The right question is not “am I an AI provider?” but “where and how does my organization use AI?”. Because the regulation also weighs on deployers, meaning professional users. Compliance comes in four stages: map the systems in use, classify them by risk level, document and govern the ones that require it, and train the teams. The rest of this article walks through each stage.
Deployers, not only providers
The most common mistake is to assume the AI Act only concerns companies that build models. The regulation distinguishes several roles, two of which touch almost every organization: the provider, who develops or places an AI system on the market, and the deployer, who uses it in a professional setting.
A firm automating contract analysis, an HR team screening applications with a scoring tool, a company embedding a conversational agent in its support: all are deployers. As such, they carry obligations of their own, particularly when they use a system classified as high-risk. The level of requirement does not depend on the size of the organization but on the use and the classification of the system.
The heart of the framework: classify by risk
The AI Act does not treat all AI the same way. It organizes obligations across four risk levels.
Unacceptable uses have been prohibited since February 2025: general-purpose social scoring, subliminal manipulation, certain forms of biometric recognition. A system that falls into this category is not brought into compliance, it is withdrawn.
High-risk systems concentrate the heaviest obligations: AI used in recruitment, access to credit, education or certain public services, plus AI embedded in regulated products. Under the revised timetable, the main Annex III rules apply from 2 December 2027 and product-embedded rules from 2 August 2028. Organizations should use the transition to prepare documentation, risk management, human oversight, logging and data controls.
Limited-risk systems are mostly about transparency: informing people that they are interacting with an AI, flagging generated or manipulated content. Minimal-risk systems, finally, carry no specific obligation.
Without a prior map, it is impossible to know which category each system falls into. That is why the inventory is the very first step.
Documentation, governance, transparency
For the systems that require it, three families of obligations shape compliance.
Documentation means describing what the system does, which data it relies on, what its limits are, and how its performance is measured. It must be kept up to date and available to supervisory authorities.
Governance distributes responsibilities internally: who signs off on putting a system into production, who supervises its operation, who traces the decisions. Human oversight of high-risk systems is not an abstract principle, it requires identified people who are able to understand and interrupt the system.
Transparency applies toward the people concerned: they must know when they are interacting with an AI and when content has been artificially generated.
AI literacy after the Omnibus
The original Article 4 duty required providers and deployers to take measures to ensure a sufficient level of AI literacy. The July 2026 AI Omnibus replaced this company-level duty with non-binding encouragement and gave the Commission and Member States a stronger role in promoting AI literacy.
Training remains a strong governance control: staff still need to understand the risks, limits and correct use of the systems they supervise. It should be justified by the use case and documented as evidence of competent oversight, without presenting it as a standalone binding company obligation after the Omnibus change.
In France, a structured training program can fall within a skills development plan and may be eligible for OPCO funding, subject to the employer’s situation and the relevant OPCO’s approval criteria.
Penalties, with care
The regulation sets out tiered penalties, with caps that vary by the nature of the breach. Prohibited practices carry the highest amounts, up to 35 million euros or 7 percent of total worldwide annual turnover, whichever is higher. Other breaches of obligations fall under lower tiers, and transmitting incorrect information to authorities under a lower tier still. Actual amounts take into account the severity, the duration, and the size of the company. The stake is therefore not the theoretical maximum penalty but being able to demonstrate, in the event of a check, a documented compliance effort.
A four-step compliance plan
- Map. List every AI system in use or planned, including SaaS tools with AI built in. Without an inventory, no obligation can be correctly identified.
- Classify. Assign each system its risk level within the meaning of the regulation. This classification determines the intensity of the obligations.
- Document and govern. For high-risk systems, produce the documentation, define human oversight, organize logging and the roles that sign off.
- Build competence. Train the people who select, operate and oversee AI in proportion to their role, and retain evidence of that competency work.
For the broader compliance journey tailored to smaller organizations, see the EU AI Act SME guide.
Where to start
The first step is to take stock: which AI systems are used, by whom, for what, and which risk category they fall into. It is a few days’ exercise that produces a map and a prioritized action plan, without blocking ongoing use.
Colombani.ai supports this work through AI Act compliance consulting (system mapping, risk classification, documentation, and governance) and develops practical AI competency through the AI Compliance course. The training is Qualiopi-certified; OPCO funding depends on the applicable funding rules and approval. The expertise is certified by Anthropic (Claude Certified Architect).
Sources
Have a project in mind?
Describe your situation. Straight answer within 48 hours.