Skip to the guide
Regulation (EU) 2024/1689 Updated 3 August 2026
Practical EU AI Act Guide

Know what applies. Know what to do next.

A plain-language route from AI use case to risk level, legal role and audit-ready evidence without reading the entire Regulation first.

Active now Prohibitions, AI literacy, GPAI, transparency and enforcement
2 Dec 2027 Annex III high-risk rules apply under the revised timeline
2 Aug 2028 High-risk rules for AI embedded in regulated products
€35m / 7% Highest maximum fine tier; SME calculation differs
The AI Act is no longer only a future deadline. Core rules and enforcement powers became applicable on 2 August 2026. Several obligations had already applied since 2025.
In force
Start here

Compliance becomes manageable in three decisions.

Do not begin with a 100-page policy. First determine scope, role and risk. Those three decisions control the rest of your workload.

1

Are you in scope?

Check where your organisation operates, where the AI is placed on the market and where its output is used.

Run the scope check
2

What is your role?

A buyer using Copilot is usually a deployer. A company selling an AI tool under its own name may be a provider. Duties differ.

Identify your role
3

What is the risk?

Classify the actual use case not only the product name. The same model can be low-risk in one workflow and high-risk in another.

Screen the use case
Step 1 · Applicability

Could the EU AI Act apply to your organisation?

Answer three preliminary questions. This is a triage tool, not a legal determination.

1. Is your organisation established or located in the EU?
2. Do you provide or place an AI system or general-purpose AI model on the EU market?
3. Is output produced by your AI system used in the EU?

Complete the three questions

If at least one answer is “yes”, the Act may apply. Your next step is to determine your legal role and classify each use case.

  • Scope can reach organisations outside the EU.
  • Specific exclusions and exceptions may apply.
  • Assess each AI use case separately.
Do not use headquarters as your only test. Non-EU providers can be in scope when they place AI on the EU market or when AI output is used in the EU.
Step 2 · Legal role

Your obligations depend on what you do with the AI.

Choose the description that best matches your organisation. You can hold more than one role for different systems.

Most organisations

Deployer

You use an AI system under your authority in a professional context for example Microsoft Copilot, an HR screening tool or an AI-enabled service desk.

Typical priorities

  • Use the system according to its instructions and assign accountable human oversight.
  • Monitor operation, inputs, incidents and changes in the use case.
  • Inform affected people or workers where the Act requires it.
  • Complete a FRIA where Article 27 applies; assess GDPR DPIA requirements separately.
  • Keep evidence of governance decisions, training and controls.
Provider status can be triggered unintentionally. Rebranding a system under your own name, making a substantial modification or changing its intended purpose can shift provider-level duties onto your organisation.
Step 3 · Classification

Classify the use case, not the tool.

“We use ChatGPT” is not a risk classification. Document what the AI does, whose rights it can affect and how humans use its output.

Stop and assess

Prohibited practices

  • Manipulative or exploitative practices causing significant harm
  • Certain social scoring and predictive policing uses
  • Untargeted facial-image scraping
  • Certain biometric categorisation and emotion recognition
Strict controls

Potentially high-risk

  • Recruitment, worker management and access to self-employment
  • Education, essential services and certain credit decisions
  • Biometrics, critical infrastructure and regulated products
  • Law enforcement, migration and administration of justice
Disclosure duties

Transparency risk

  • Chatbots and direct human interaction
  • AI-generated or manipulated content
  • Deepfakes and public-interest text
  • Emotion recognition or biometric categorisation disclosures
Baseline governance

Other / minimal risk

  • Spam filtering and routine optimisation
  • Internal drafting with meaningful review
  • Low-impact workflow assistance
  • Voluntary codes and proportionate controls remain useful
Quick use-case screener

Choose the closest primary use.

Select the use case

You will receive a preliminary direction and the first evidence to collect.

Formal classification depends on the system’s intended purpose, context, exclusions and your role.

General-purpose AI is a separate layer. A foundation-model provider has GPAI duties. An organisation using a product built on that model still needs to classify its own concrete use case.
Official application timeline

What applies now — and what comes next.

The July 2026 AI Omnibus extended the high-risk dates. It did not pause obligations that already apply.

1 Aug 2024

AI Act entered into force

The phased implementation period began.

Completed
2 Feb 2025

Prohibitions and AI literacy

Prohibited practices, relevant definitions and Article 4 AI literacy measures began to apply.

Applies now
2 Aug 2025

Governance and GPAI obligations

Governance rules and obligations for providers of general-purpose AI models began to apply.

Applies now
2 Aug 2026

Core rules, transparency and enforcement

Article 50 transparency requirements and enforcement powers became applicable, alongside other core provisions.

Applies now
2 Dec 2027

Annex III high-risk rules

High-risk obligations for listed use cases such as employment, education and essential services begin to apply under the revised timeline.

Prepare now
2 Aug 2028

AI embedded in regulated products

High-risk obligations apply to AI systems that are safety components of products covered by specified EU product legislation.

Future date
Leverage point: build one controlled AI inventory and evidence repository now. The same foundation supports classification, GDPR reviews, vendor governance, board oversight and future audits.
Execution plan

Turn the law into a 90-day operating system.

Prioritise traceable evidence over policy volume. An auditor needs to see what exists, who owns it, how it was assessed and what controls operate.

90-day roadmap
1

Days 1–7 · Find and contain

Name an executive owner, create an AI inventory, identify unsanctioned tools and pause any suspected prohibited practice.

2

Days 8–30 · Classify and assign

Document intended purpose, legal role, risk class, data use, vendor and accountable system owner for every use case.

3

Days 31–60 · Close priority gaps

Implement human oversight, transparency notices, approved-use rules, vendor controls and role-based AI literacy measures.

4

Days 61–90 · Prove operation

Centralise approvals, training records, FRIAs/DPIAs, incident logs, testing and board reporting in a controlled evidence repository.

5

Quarterly · Keep it alive

Review new systems, vendor changes, incidents, risk classifications, controls and upcoming regulatory guidance.

Minimum evidence checklist 0 of 10 complete

Your selections are stored only in this browser. No checklist data is submitted.

Enforcement

The fine is the ceiling. Loss of trust is the multiplier.

Authorities consider the infringement’s nature, gravity and duration. Commercial consequences can include delayed procurement, failed due diligence and suspended deployments.

Highest tier €35m or 7%

Prohibited practices

Up to €35 million or 7% of total worldwide annual turnover for the preceding financial year, subject to the statutory calculation.

Other obligations €15m or 3%

Other covered breaches

Up to €15 million or 3% for non-compliance with specified operator, notified-body and transparency obligations.

Information failures €7.5m or 1%

Incorrect information

Up to €7.5 million or 1% for incorrect, incomplete or misleading information supplied in response to certain official requests.

SME safeguard: for each infringement category, the lower of the fixed amount and turnover percentage is the threshold for SMEs; for other undertakings, the higher threshold applies. Actual penalties must remain effective, proportionate and dissuasive.
Plain-language answers

Questions decision-makers ask first.

Does Microsoft Copilot fall under the EU AI Act?

AI-enabled Microsoft services can fall within the AI Act, but the duties depend on the product, feature, intended use and your role. Most customer organisations will be deployers. Inventory the exact feature and workflow — for example drafting, HR screening or customer interaction — and classify that concrete use.

Is every AI system high-risk?

No. High-risk classification is tied to defined product categories and listed use cases, subject to conditions and exceptions. Many routine systems are not high-risk, although AI literacy, transparency, GDPR, security and internal governance may still apply.

Do we always need a Fundamental Rights Impact Assessment?

No. A FRIA is not universal for every AI system or every deployer. Article 27 applies to specified deployers and high-risk uses. Separately, a GDPR Data Protection Impact Assessment may be required where personal-data processing is likely to create high risk. Record the decision even when an assessment is not required.

Do we need an AIGP-certified person to comply?

No. The AI Act does not make AIGP certification a mandatory corporate role or statutory condition for compliance. Certification can demonstrate knowledge, but evidence of appropriate governance, competent people and operating controls matters more than a badge alone.

Can we wait until the high-risk deadlines in 2027 or 2028?

No. Prohibitions, AI literacy, GPAI-related rules, Article 50 transparency requirements and enforcement are already active. The extension creates preparation time for high-risk duties; it does not remove current obligations or your exposure under GDPR, consumer, employment and sector law.

Does the Act apply if our company is outside the EU?

Potentially yes. The Act can apply to non-EU providers placing AI systems or GPAI models on the EU market and to providers or deployers where system output is used in the EU. Confirm the exact territorial connection and any applicable exclusion.

What is the single best first deliverable?

A controlled AI inventory with an owner, intended purpose, legal role, risk class, vendor, data categories and status for every system. It becomes the index for approvals, FRIAs, DPIAs, contracts, training, incidents and board reporting.

From guidance to evidence

Find your largest governance gaps before an auditor or buyer does.

Start with the Boardroom Diagnostic, or book a focused readiness call to map your fastest route to audit-ready AI governance inside Microsoft 365.

Official sources

Reviewed against official EU sources available on 3 August 2026. This guide provides general information and a preliminary triage only. It does not replace a system-specific legal, technical or conformity assessment.