Practical briefing
Current as of 4 August 2026

The EU AI Act: what it means in practice

The EU’s AI Act is not a general ban on artificial intelligence. It is a risk-based regulation that treats AI as a governed business process when it can affect people’s rights, safety, livelihood, or access to services.

What changes?

AI is classified according to how it is used and the harm it could cause—not simply according to which model powers it. Most everyday AI remains lightly regulated, while high-impact uses require substantial controls.

Who can be caught?

The rules can apply to providers, deployers, importers, distributors, product manufacturers, and certain organizations outside the EU. A non-EU company may still be in scope if its AI system is placed on the EU market or its output is used in the EU.

KBD-specific implications

This general explainer now has a companion briefing for KBD’s work as a brand-experience agency building websites, digital experiences, synthetic media, and client-facing AI features.

Read the KBD implications briefing →

Four practical risk levels

The Act regulates uses proportionally. It does not treat a spam filter and an AI hiring system as equivalent.

Prohibited

Unacceptable-risk AI

These uses are banned because they threaten fundamental rights or safety. Examples include harmful manipulation, certain social-scoring systems, certain sensitive biometric categorization, emotion inference in workplaces or schools, and some profiling-based predictive policing.

New prohibitions covering AI-generated non-consensual sexual material and child sexual-abuse material apply from 2 December 2026.

High risk

High-impact AI

Recruitment, education, essential services, critical infrastructure, law enforcement, migration, courts, democratic processes, and certain biometric uses can fall into this category.

These systems require risk management, data governance, documentation, logging, human oversight, accuracy, robustness, cybersecurity, and quality controls.

Transparency

Limited-risk AI

Chatbots and other covered interactive systems generally must disclose that users are interacting with AI. Deepfakes and certain synthetic audio, images, video, and text must be disclosed or marked in machine-readable form, subject to exceptions.

Minimal risk

Mostly unregulated by the AI Act

Many spam filters, recommendation tools, video-game features, and ordinary productivity uses remain outside the Act’s heavy obligations. Privacy, copyright, consumer, employment, cybersecurity, and sector-specific laws still apply.

The current implementation timeline

The Digital Omnibus changed the high-risk deadlines. The main rollout now extends through August 2028.

1 Aug 2024
Regulation enters into force

The Act becomes EU law, with its obligations phased in over time.

2 Feb 2025
General provisions and prohibitions apply

Definitions, AI-literacy provisions, and the initial prohibited-practice rules become applicable.

2 Aug 2025
GPAI rules and governance apply

General-purpose AI model obligations begin, and Member States must establish key governance arrangements.

2 Aug 2026
Transparency and active enforcement begin

Article 50 transparency rules start to apply, along with enforcement for applicable prohibitions, GPAI rules, transparency requirements, and AI literacy.

2 Dec 2026
New prohibitions and a transition deadline

New sexual-content prohibitions apply. Certain providers of pre-existing systems generating synthetic content receive a transition deadline for Article 50(2).

2 Dec 2027
Standalone Annex III high-risk rules apply

High-risk systems in areas such as employment, education, essential services, law enforcement, migration, and justice enter the main compliance regime.

2 Aug 2028
High-risk AI embedded in regulated products

High-risk AI embedded in products covered by EU product-safety legislation enters the delayed regime.

What businesses will need to do

The largest impact is organizational: AI use must become inventoried, classified, governed, and evidenced.

Inventory AI use

Identify models, vendors, internal tools, customer-facing features, automated decisions, and systems embedded in products.

Classify the use

The same model can be low-risk for drafting an email but high-risk when used to rank job applicants. Classify the application, not only the model.

Assign legal roles

Determine whether the organization is a provider, deployer, importer, distributor, product manufacturer, or downstream provider.

Control vendors

Contracts may need documentation, security, incident-notification, audit, data-use, and transparency provisions.

Create evidence

Maintain risk assessments, test results, logs, human-oversight procedures, model documentation, and monitoring records.

Train the people involved

Staff need appropriate AI literacy and competency measures, coordinated with privacy, security, procurement, legal, and compliance teams.

General-purpose AI gets its own regime

Foundation-model providers and businesses embedding them into products face obligations beyond ordinary application transparency.

Model providers

Baseline GPAI obligations

  • Technical documentation
  • Instructions and information for downstream providers
  • Compliance with EU copyright law
  • A public summary of training-content sources
Systemic risk

Additional controls for the most capable models

  • Model evaluation and adversarial testing
  • Serious-incident reporting
  • Risk assessment and mitigation
  • Cybersecurity protections

What individuals will notice

The Act increases transparency and accountability, but it is not a universal right to refuse every AI-assisted decision.

More disclosure

Users should increasingly know when they are dealing with a chatbot or viewing AI-generated or manipulated content.

More scrutiny

AI used in hiring, education, benefits, credit, law enforcement, and similar decisions faces stronger safeguards.

More recourse

The EU provides complaint and whistleblower channels for alleged violations supervised by the AI Office, alongside rights that may arise under GDPR and other law.

Enforcement is meaningful

Different authorities handle different systems, but the potential penalties are large enough to make AI governance a board-level issue for many companies.

Prohibited practices

Up to €35m or 7%

For prohibited AI practices, the maximum is up to €35 million or 7% of worldwide annual turnover, whichever is higher.

Other major breaches

Up to €15m or 3%

Other major violations, including GPAI obligations, can reach up to €15 million or 3% of worldwide annual turnover.

Incorrect information

Up to €7.5m or 1%

For certain incorrect, incomplete, or misleading information provided to authorities, the maximum can reach €7.5 million or 1% of worldwide annual turnover.

These are maximums, not automatic fines. Actual penalties depend on factors including seriousness, duration, intent, cooperation, and organizational size.

Concrete examples

Classification depends on the use, the role of the organization, and the surrounding facts.

Internal memo drafting

Probably not a high-risk use, but confidentiality, privacy, copyright, and internal-use policies still matter.

AI candidate ranking

Likely a high-risk employment use, requiring substantial governance and human oversight under the updated timetable.

Customer-service chatbot

Generally needs to disclose that users are interacting with AI from August 2026, subject to the detailed rules and exceptions.

Synthetic marketing video

Machine-readable marking and deepfake disclosure may apply, depending on the content and how it is published.

Foundation-model provider

May need GPAI documentation, copyright compliance, training-data summaries, and systemic-risk controls.

U.S.-hosted service used in Europe

The Act can still apply when a non-EU provider’s output is used in the EU.

A note on currency

The independent guide linked above is useful for orientation, but some of its older summary pages predate the Digital Omnibus. For current dates and amended provisions, use the European Commission timeline and the final legal text.

This is a practical briefing, not legal advice. Whether a particular system is in scope depends on its exact use, provider/deployer role, market placement, and applicable national and sector-specific law.