Complete guide · Pillar page · Updated June 2026

EU AI Act 2026: Complete Compliance Guide for Companies, Funds and Executives

Timeline (Digital Omnibus, 2 December 2027), risk classification, high-risk and GPAI obligations, D7™ scoring and compliance checklist. The reference guide for European AI compliance.

Last updated: 6 June 2026 · Reflects Digital Omnibus political agreement (7 May 2026)

1. What is the EU AI Act?

The EU AI Act (Regulation (EU) 2024/1689) is the world's first binding regulatory framework specifically governing artificial intelligence. Adopted on 13 June 2024 and published in the Official Journal on 12 July 2024, it entered into force on 2 August 2024.

It applies to any provider, deployer, importer or distributor of AI systems operating in the EU market — regardless of where they are established. A US company selling an AI recruitment tool to European companies is fully subject to the Act (Art. 2).

The Digital Omnibus update (7 May 2026): A political agreement between the Council and Parliament extended the application deadline for high-risk Annex III systems from 2 August 2026 to 2 December 2027. Formal adoption is pending. Prohibited practices (Art. 5) and GPAI obligations (Art. 51–55) remain unchanged and fully in force.

2. Application timeline

DateRegimeLegal basis
2 August 2024Entry into forceArt. 113 — 20 days after OJEU publication (12 July 2024)
2 February 2025Prohibited practices (Art. 5) + Chapter IArt. 113§a — 6 months after entry into force
2 August 2025GPAI models (Chapter V) + GovernanceArt. 113§b — 12 months after entry into force
2 December 2027High-risk systems (Annex III)Digital Omnibus political agreement, 7 May 2026
2 August 2028AI systems embedded in regulated products (Annex I)Digital Omnibus — 36 months from EIF

3. The four risk tiers

TierExamplesObligation
Unacceptable riskReal-time biometric surveillance, social scoring, subliminal manipulation, emotion recognition at workProhibited — immediate ban (Art. 5)
High riskCV screening, credit scoring, medical diagnostics, critical infrastructure, law enforcement AIFull compliance regime (Art. 9–15)
Limited riskChatbots, AI-generated content, emotion recognition systemsTransparency obligations only (Art. 50)
Minimal riskSpam filters, recommendation engines, image editing toolsNo specific obligation

4. High-risk systems: Annex III sectors

A system is high-risk under Art. 6§2 if it falls within one of the eight sectors listed in Annex III:

  1. Biometrics: remote identification, categorisation by sensitive attributes, emotion recognition
  2. Critical infrastructure: management of water, gas, electricity, road and rail networks
  3. Education: admission decisions, assessment, monitoring of learners
  4. Employment & HR: CV screening, candidate ranking, performance monitoring, promotion decisions
  5. Essential services: credit scoring, insurance pricing, social benefits, emergency dispatch
  6. Law enforcement: risk profiling, crime analytics, facial recognition in investigations
  7. Migration & borders: asylum risk assessment, lie detection, visa processing
  8. Justice & democracy: AI used to influence elections or assist courts

Key principle: Classification attaches to the use case, not the model. A general-purpose LLM is not high-risk in itself. Deployed for CV screening, it becomes high-risk under Annex III §4.

5. Obligations for high-risk systems (Art. 9–15)

ArticleObligationWhat it means in practice
Art. 9Risk management systemDocumented QMS, continuous, covering the full AI lifecycle
Art. 10Data governanceTraining data documented, biases identified, quality controls in place
Art. 11 + Annex IVTechnical documentationDetailed technical file (architecture, data, performance, testing)
Art. 12Record-keepingAutomatic logs for decisions and operations of the system
Art. 13TransparencyDeployers must receive adequate information on capabilities and limits
Art. 14Human oversightHuman operators must be able to understand, monitor and override outputs
Art. 15Accuracy, robustness, cybersecurityPerformance standards maintained; resilience against adversarial attacks

6. GPAI models (Art. 51–55)

General-Purpose AI models (GPAI) — foundation models used for multiple purposes — have specific obligations regardless of how they are deployed:

Systemic risk threshold: 10²⁵ FLOPs of training compute (or designation by the AI Office). Above this threshold, additional obligations apply: adversarial testing, incident reporting to the AI Office, and enhanced cybersecurity measures (Art. 55).

7. Sanctions (Art. 99)

ViolationMaximum fine
Prohibited practice (Art. 5)€35M or 7% of global annual turnover
Non-compliant high-risk system€15M or 3% of global annual turnover
Non-compliant GPAI model€15M or 3% of global annual turnover
Inaccurate information to authorities€7.5M or 1.5% of global annual turnover

8. AI Act in M&A: the hidden risk

Regulatory risk under the AI Act attaches to the asset, not the transaction. It persists after closing. An acquirer who purchases a company with a non-compliant high-risk AI system inherits the compliance obligation — and potential enforcement exposure.

On a €50M acquisition, a regulatory haircut of 10–15% represents €5–7.5M of lost value. A D7™ pre-signing score costs less than 0.03% of that exposure.

W&I insurance implication: W&I insurers (AXA XL, Howden, Tokio Marine) are increasingly requiring AI Act compliance documentation for transactions involving AI-significant targets. The D7™ W&I Insurability Mapping™ is designed as the first-pass document for underwriters.

9. Practical compliance checklist

Map all AI systems deployed or developed against Annex III (classification decision)
For each high-risk system: establish a documented QMS (Art. 9)
Document training data origin, quality checks, and bias analysis (Art. 10)
Produce technical documentation per Annex IV (Art. 11)
Implement and test human oversight mechanisms per Art. 14
Set up post-market surveillance and incident reporting (Art. 72–73)
Register high-risk systems in the EU database (Art. 71)
If GPAI: produce technical summary, copyright policy, energy disclosure
Get a D7™ score to benchmark where you stand and prioritise remediation

10. FAQ

Does the EU AI Act apply to companies outside the EU?

Yes. Art. 2 provides for extraterritorial application: any provider or deployer that markets an AI system to users in the EU is subject to the regulation, regardless of where they are established. A US startup selling an AI hiring tool to European companies is fully subject to the Act.

Does the EU AI Act apply to SMEs and startups?

Yes, with some accommodations. SMEs benefit from regulatory sandboxes (Art. 57) and lighter documentation obligations. But if their system is high-risk or prohibited, the obligations apply in full. A startup developing an AI recruitment tool is subject to Annex III §4 from launch.

What is the difference between provider and deployer obligations?

Providers (those who develop and place AI systems on the market) carry the primary compliance obligations under Art. 16: they must produce the technical file, register the system, affix the CE marking. Deployers (those who use a provider's system in their operations) have obligations under Art. 26: ensuring the system is used as intended, reporting serious incidents, and maintaining human oversight. Both are subject to enforcement.

What is the competent authority in France?

The CNIL (Commission Nationale de l'Informatique et des Libertés) is designated as the national competent authority for AI Act enforcement in France. The AI Office (European Commission, DG CNECT) has authority over GPAI model providers at EU level.

What is the D7™ score and how does it help?

The D7™ is a proprietary compliance and value score (0–100) produced by MB AI Value Intelligence. It assesses an AI asset across 7 dimensions: regulatory exposure, technical maturity, data governance, AI governance, commercial defensibility, financial value adjustability, and operational risk. Produced in 48 hours from public data (or 5–10 days with client dataroom). Used for M&A due diligence, W&I underwriting, and PE/VC portfolio monitoring. Pricing on request.

Get your D7™ compliance score in 48 hours

Classification · Regulatory exposure · Remediation plan · W&I insurability mapping
Pricing on request. Audit-grade. Defensible before a regulator or an investor.

Request a D7™ score View all products