What changes?
AI is classified according to how it is used and the harm it could cause—not simply according to which model powers it. Most everyday AI remains lightly regulated, while high-impact uses require substantial controls.
The EU’s AI Act is not a general ban on artificial intelligence. It is a risk-based regulation that treats AI as a governed business process when it can affect people’s rights, safety, livelihood, or access to services.
AI is classified according to how it is used and the harm it could cause—not simply according to which model powers it. Most everyday AI remains lightly regulated, while high-impact uses require substantial controls.
The rules can apply to providers, deployers, importers, distributors, product manufacturers, and certain organizations outside the EU. A non-EU company may still be in scope if its AI system is placed on the EU market or its output is used in the EU.
This general explainer now has a companion briefing for KBD’s work as a brand-experience agency building websites, digital experiences, synthetic media, and client-facing AI features.
The Act regulates uses proportionally. It does not treat a spam filter and an AI hiring system as equivalent.
These uses are banned because they threaten fundamental rights or safety. Examples include harmful manipulation, certain social-scoring systems, certain sensitive biometric categorization, emotion inference in workplaces or schools, and some profiling-based predictive policing.
New prohibitions covering AI-generated non-consensual sexual material and child sexual-abuse material apply from 2 December 2026.
Recruitment, education, essential services, critical infrastructure, law enforcement, migration, courts, democratic processes, and certain biometric uses can fall into this category.
These systems require risk management, data governance, documentation, logging, human oversight, accuracy, robustness, cybersecurity, and quality controls.
Chatbots and other covered interactive systems generally must disclose that users are interacting with AI. Deepfakes and certain synthetic audio, images, video, and text must be disclosed or marked in machine-readable form, subject to exceptions.
Many spam filters, recommendation tools, video-game features, and ordinary productivity uses remain outside the Act’s heavy obligations. Privacy, copyright, consumer, employment, cybersecurity, and sector-specific laws still apply.
The Digital Omnibus changed the high-risk deadlines. The main rollout now extends through August 2028.
The Act becomes EU law, with its obligations phased in over time.
Definitions, AI-literacy provisions, and the initial prohibited-practice rules become applicable.
General-purpose AI model obligations begin, and Member States must establish key governance arrangements.
Article 50 transparency rules start to apply, along with enforcement for applicable prohibitions, GPAI rules, transparency requirements, and AI literacy.
New sexual-content prohibitions apply. Certain providers of pre-existing systems generating synthetic content receive a transition deadline for Article 50(2).
High-risk systems in areas such as employment, education, essential services, law enforcement, migration, and justice enter the main compliance regime.
High-risk AI embedded in products covered by EU product-safety legislation enters the delayed regime.
The largest impact is organizational: AI use must become inventoried, classified, governed, and evidenced.
Identify models, vendors, internal tools, customer-facing features, automated decisions, and systems embedded in products.
The same model can be low-risk for drafting an email but high-risk when used to rank job applicants. Classify the application, not only the model.
Determine whether the organization is a provider, deployer, importer, distributor, product manufacturer, or downstream provider.
Contracts may need documentation, security, incident-notification, audit, data-use, and transparency provisions.
Maintain risk assessments, test results, logs, human-oversight procedures, model documentation, and monitoring records.
Staff need appropriate AI literacy and competency measures, coordinated with privacy, security, procurement, legal, and compliance teams.
Foundation-model providers and businesses embedding them into products face obligations beyond ordinary application transparency.
The Act increases transparency and accountability, but it is not a universal right to refuse every AI-assisted decision.
Users should increasingly know when they are dealing with a chatbot or viewing AI-generated or manipulated content.
AI used in hiring, education, benefits, credit, law enforcement, and similar decisions faces stronger safeguards.
The EU provides complaint and whistleblower channels for alleged violations supervised by the AI Office, alongside rights that may arise under GDPR and other law.
Different authorities handle different systems, but the potential penalties are large enough to make AI governance a board-level issue for many companies.
For prohibited AI practices, the maximum is up to €35 million or 7% of worldwide annual turnover, whichever is higher.
Other major violations, including GPAI obligations, can reach up to €15 million or 3% of worldwide annual turnover.
For certain incorrect, incomplete, or misleading information provided to authorities, the maximum can reach €7.5 million or 1% of worldwide annual turnover.
These are maximums, not automatic fines. Actual penalties depend on factors including seriousness, duration, intent, cooperation, and organizational size.
Classification depends on the use, the role of the organization, and the surrounding facts.
Probably not a high-risk use, but confidentiality, privacy, copyright, and internal-use policies still matter.
Likely a high-risk employment use, requiring substantial governance and human oversight under the updated timetable.
Generally needs to disclose that users are interacting with AI from August 2026, subject to the detailed rules and exceptions.
Machine-readable marking and deepfake disclosure may apply, depending on the content and how it is published.
May need GPAI documentation, copyright compliance, training-data summaries, and systemic-risk controls.
The Act can still apply when a non-EU provider’s output is used in the EU.
The independent guide linked above is useful for orientation, but some of its older summary pages predate the Digital Omnibus. For current dates and amended provisions, use the European Commission timeline and the final legal text.
This is a practical briefing, not legal advice. Whether a particular system is in scope depends on its exact use, provider/deployer role, market placement, and applicable national and sector-specific law.