The AI Act (EU Regulation 2024/1689) applies to every company using or distributing AI systems in the EU, tech or not, and sorts systems into four risk tiers. Prohibited systems have been banned since 2 February 2025; Annex III high-risk systems face full obligations from 2 December 2027 and Annex I ones from 2 August 2028, after the deferral introduced by Regulation (EU) 2026/1744 (the Digital Omnibus on AI, in force since 27 July 2026).
The Regulation (EU) 2024/1689 on Artificial Intelligence, known as the AI Act, is the world's first comprehensive AI legislation and applies directly in all EU member states without national transposition. It is not a directive that each country adapts; it is a regulation of direct and mandatory application. If your business uses, develops, imports or distributes AI systems in the European market, it already has active obligations. What remains to be activated, according to the deadlines in force as of 30 July 2026, are the most demanding rules for high-risk systems. But that does not mean waiting: the time to prepare is now.
This guide explains, in concrete and jargon-free terms, what the AI Act requires of a business in 2026, what the real deadlines are following the latest reform (the Digital Omnibus on AI, Regulation (EU) 2026/1744), what penalties you risk if you fail to act, and how to structure compliance from a compliance department or from the board level.
What is the AI Act and why does it affect you even if you are not a technology company?
The AI Act does not only regulate companies that develop artificial intelligence software. It regulates any organisation that deploys or uses an AI system in the European Union, regardless of whether that system was purchased from an external supplier or built internally. A law firm that uses an automated system to review contracts, a manufacturing company that applies computer vision on its production line, an HR department that uses candidate scoring software: all of them fall within the scope of the regulation.
The regulation classifies AI systems into four categories based on the level of risk they pose to fundamental rights and people's safety. This classification determines which specific obligations apply to each operator.
The four risk categories of the AI Act
| Category | Description | Examples | Applicable regime |
|---|---|---|---|
| Unacceptable risk (prohibited) | Systems that undermine fundamental rights or manipulate people without their knowledge | Social scoring by public authorities; subliminal manipulation; real-time remote biometrics in public spaces (with exceptions); systems exploiting vulnerabilities of protected groups; and, as a new prohibition, the generation or manipulation of realistic intimate or sexually explicit material depicting an identifiable person without that person's consent | Absolute prohibition since 2 February 2025; the two prohibitions added by Regulation (EU) 2026/1744 apply from 2 December 2026 |
| High risk (Annex III) | Systems with significant impact on rights, safety or access to essential services | Automated HR candidate scoring software; credit scoring; biometric categorisation systems; educational assessment tools; critical infrastructure management; decision-making systems in migration and asylum | Full obligations from 2 December 2027 (deadline deferred by Regulation (EU) 2026/1744) |
| High risk (Annex I) | AI embedded in products regulated by sectoral legislation (machinery, medical devices, vehicles, toys…) | AI-assisted medical diagnosis; industrial machinery control systems; AI in autonomous vehicles | Full obligations from 2 August 2028 |
| Limited risk | Systems with transparency risks that can be managed by informing the user | Chatbots; image or text generators; recommendation systems | Transparency obligations under Article 50 (inform the user they are interacting with AI). They are not a tier below high risk: they are triggered by the type of system and can also apply to a high-risk one |
| Minimal risk | Systems with no significant impact on people | Anti-spam filters; internal search assistants; basic productivity tools | No obligations attached to this risk level, but the horizontal AI literacy duty of Article 4 still applies, as does the rest of the law (GDPR, employment, consumer). Article 95 provides for voluntary codes of conduct |
Real deadlines as of July 2026: what is already in force and what is coming
One of the most confusing aspects of the AI Act is its phased timeline. Below we detail the milestones already in force and those ahead, incorporating the changes introduced by Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026, the Digital Omnibus on AI, published in OJ L, 2026/1744, 24.7.2026 and in force since 27 July 2026 under its own Article 4. It is not a political agreement pending adoption: it is Union law in force, which defers the deadlines for high-risk systems and adds new prohibited practices.
February 2025 — Absolute prohibitions in force
Since 2 February 2025, AI practices deemed to present unacceptable risk (Article 5 of the Regulation) have been prohibited: subliminal manipulation, social scoring by public bodies, real-time remote biometrics in public spaces (except strictly defined national security exceptions), systems that exploit vulnerabilities of specially protected groups, and systems inferring emotions in workplaces or educational centres, except where the system is intended to be put in place or into the market for medical or safety reasons. If your business was using any of these systems, it should have retired or adapted them before that date.
2025 — AI literacy, GPAI models and governance
Two blocks of obligations relevant to virtually any business are already in force, on two different dates:
- Article 4 — AI literacy, since 2 February 2025: the duty falls within Chapters I and II, applicable since 2 February 2025 (Article 113, third paragraph, point (a)). Its wording changed on 27 July 2026: Article 4 was replaced in full by Article 1, point 5, of Regulation (EU) 2026/1744, and providers and deployers must now take measures «to support the promotion of» AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf. The article adds expressly that «this obligation does not require providers or deployers to guarantee a specific level of AI literacy of any particular person». It has therefore moved from an obligation of result to an obligation of means — but it still exists and is still enforceable. The Regulation prescribes no number of training hours, and the Commission is to publish practical examples of compliance on the single information platform referred to in Article 62(3)(b).
- Articles 51-55 — General-purpose AI models (GPAI), since 2 August 2025: together with the governance chapter and the penalty regime, also applicable since that date, companies that develop or adapt large-scale language models (such as GPT, Claude, Llama) for distribution in the EU have documentation, systemic risk assessment and registration obligations. This primarily affects technology providers, but also companies that fine-tune models for large-scale internal use.
August 2026 — General date of application
2 August 2026 is the date on which the AI Act reaches full application for the bulk of its general obligations, and Regulation (EU) 2026/1744 has not moved it: recital 40 of the Omnibus itself refers to 2 August 2026 as the general date of application. Although the deadlines for high-risk systems have been deferred, the rest of the Regulation — including governance, transparency and literacy obligations — is enforceable and subject to penalties. One caveat on enforcement in Spain: Spain has not yet adopted the law designating the national market surveillance authorities or setting out the national penalty procedure; a Draft Organic Law (parliamentary file 121/000096) is still at the amendment stage, with the deadline for amendments extended to 2 September 2026. AESIA is expected to take on market surveillance duties once the Spanish law is adopted.
December 2027 — Full obligations for high-risk systems (Annex III)
Following Regulation (EU) 2026/1744, systems classified as high risk under Article 6(2) and Annex III (biometrics, HR, credit, critical infrastructures, education, migration, justice) must comply with the full AI Act regime from 2 December 2027. Two points of precision that are usually lost: what has been deferred is the date of application of Chapter III, Sections 1, 2 and 3, with the express exception of Article 6(5) — not the AI Act as a whole; and the deferral has two dates, the second of which is in the next section. This sixteen-month move from the original date (2 August 2026) gives companies and public administrations more time. However, preparation must begin now: the requirements are substantial (see the following section).
August 2028 — High-risk systems embedded in products (Annex I)
AI systems integrated into products subject to sectoral safety legislation (Machinery Directive, Medical Devices Regulation, etc.) — that is, high-risk systems under Article 6(1) and Annex I — have until 2 August 2028 to comply.
December 2026 — Two separate deadlines that fall on the same date
Regulation (EU) 2026/1744 adds two obligations that land on 2 December 2026 and should not be confused with each other. First, the new Article 111(4) of the AI Act gives providers of AI systems that generate synthetic audio, image, video or text content and that were placed on the market before 2 August 2026 until that date to comply with Article 50(2) — the machine-readable marking of outputs. Second, the two new prohibited practices inserted in Article 5(1), first paragraph, together with the two new paragraphs that delimit when they are triggered, become applicable on that same date.
What specific obligations does your business have if it uses high-risk systems?
If your business operates systems classified as high risk (a candidate scoring module in HR, a scoring system for internal credit approval, a video surveillance platform with facial recognition…), the AI Act obligations are the most demanding in the Regulation. Here is the core of what you will need to have documented and operational before 2 December 2027:
1. AI-specific risk management system
You must establish, document, apply and maintain a risk management system throughout the entire lifecycle of the AI system. A clause in the supplier contract is not sufficient: you must identify the reasonably foreseeable risks of the system, estimate them, assess them and adopt proportionate management measures. This process must be reviewed periodically and whenever there is a material change to the system.
2. Data governance and training data quality
If you develop or adapt the model, you must document your data governance practices: data origin, cleansing procedures, identified biases and corrective measures. Even as a deployer (a company that purchases and uses the system without developing it), you are obliged to monitor that the system operates in accordance with its intended purpose and to document incidents.
3. Technical documentation and activity logs
The AI Act requires detailed technical documentation for each high-risk system: system description, intended purpose, data used, performance metrics, known limitations and human oversight measures. In addition, high-risk systems must generate automatic logs that allow tracing of their operation for a minimum period of six months from use.
4. Transparency and information to users
People affected by a high-risk system (evaluated candidates, credit applicants, people in video surveillance zones) must receive clear information about the existence of the system, its purpose and the rights available to them. This integrates with GDPR rights (Articles 13 and 14) when the system processes personal data.
5. Human oversight
High-risk systems must be designed so that natural persons can oversee, interrupt or override their operation. In practice, this means that no high-impact decision — selecting a candidate, denying credit, restricting access to an essential service — can be made in a fully automated manner without the possibility of human review.
6. Conformity assessment and registration
Before putting a high-risk system into service, a conformity assessment must be carried out. For most Annex III systems, this assessment can be performed by the provider itself through self-assessment, provided the required documentation is in place. The system must be registered in the European AI database (managed by the European Commission) before it is put into service.
Obligations applicable to all businesses (not only high-risk)
Even if your business does not use high-risk systems, the AI Act imposes horizontal obligations that are already in force or will enter into force in August 2026:
- AI literacy (Art. 4): applicable since 2 February 2025, and reworded on 27 July 2026 by Regulation (EU) 2026/1744. You must take measures to support the promotion of AI literacy among the people who operate or use AI on your behalf; you are not required to guarantee a specific level for any particular person. Training on capabilities, limitations and risks remains the practical way to show you have taken those measures.
- Transparency in conversational and generative systems (Art. 50): if you use a customer-service chatbot, you must inform users that they are interacting with an AI system, unless this is obvious from the context.
- Labelling of AI-generated content: video, image or audio content that is generated or significantly manipulated by AI (including deepfakes) must be labelled in a machine-readable format. This affects marketing campaigns using synthetic images or videos.
- Review of your AI tools inventory: while not an express formal requirement of the Regulation, it is standard compliance practice for every business to carry out an inventory of the AI systems it uses or markets, with an initial risk classification. AESIA published 16 guidelines to support AI Act compliance for high-risk systems, announced on 16 December 2025, which are a useful reference for that exercise.
Penalties: how much can you lose by failing to comply with the AI Act?
The AI Act's penalty regime is the highest in all European digital regulation, surpassing even the GDPR in the most serious cases:
| Type of infringement | Maximum penalty |
|---|---|
| Use of prohibited AI practices (Art. 5) | 35 million euros or 7% of total worldwide annual turnover (whichever is higher) |
| Non-compliance with obligations for providers or deployers of high-risk AI | 15 million euros or 3% of total worldwide annual turnover |
| Supply of incorrect or misleading information to supervisory authorities | 7.5 million euros or 1% of total worldwide annual turnover |
For SMEs, including start-ups, Article 99(6) provides that each fine shall be up to the percentages or amount referred to above, whichever thereof is lower, and Article 99(1) — as replaced by Regulation (EU) 2026/1744 — requires Member States, when imposing penalties, to take into account the interests of SMEs, start-ups and small mid-cap companies and their economic viability. That mitigates the figures; it does not exempt anyone from liability.
One point that many pages get wrong: the penalty regime of Chapter XII has applied since 2 August 2025, but it is for each Member State to lay down the rules on penalties and designate the authorities, and Spain has not yet adopted the law designating the national market surveillance authorities or setting out the national penalty procedure. A Draft Organic Law on the good use and governance of artificial intelligence (parliamentary file 121/000096, XV Legislature) is still at the amendment stage and has not been published in the BOE, so its wording may change. As drafted, it does not designate AESIA as the single authority: it shares market surveillance between AESIA and other supervisors depending on the type of system.
How to structure AI Act compliance in your business: a five-step roadmap
In our AI Act consulting service we work with a structured approach that allows a business to move from zero to an auditable compliance file within a reasonable timeframe. These are the five essential steps:
Step 1 — Inventory and classification of AI systems
The starting point is knowing which AI systems your business uses: SaaS tools with AI components, internal developments, automations using language models, computer vision systems, conversational assistants… For each system, its risk category is determined according to the criteria of the Regulation. This inventory is the foundation of any compliance programme and allows efforts to be prioritised.
Step 2 — Gap analysis
With the inventory in hand, the gap between the current situation and the AI Act requirements for each system is analysed. For low- or minimal-risk systems, the gap is usually small (updating legal texts, adding user information). For high-risk systems, the gap may be significant: lack of technical documentation, absence of logs, need to redesign human oversight processes.
Step 3 — Action plan and roadmap
Based on the gap analysis, an action plan is defined with responsible parties, deadlines and resources. The plan must distinguish between immediate actions (complying with obligations already active, such as AI literacy) and medium-term actions (preparing technical documentation for high-risk systems before the December 2027 deadline).
Step 4 — Implementation: documentation, processes and training
This phase includes drafting the required technical documentation, implementing logging and monitoring systems, updating transparency notices to affected users (integrating with GDPR privacy policies), and running AI literacy training programmes for relevant staff.
Step 5 — Ongoing review and maintenance
The AI Act is a lifecycle regulation: obligations are not met once and filed away. The inventory must be reviewed whenever a new AI system is adopted, documentation must be updated when there are material changes to existing systems, and activity logs must be kept active. Additionally, the Regulation itself and the harmonised technical standards that will be published periodically may require regular adjustments.
The AI Act and its relationship with GDPR, NIS2 and ISO 42001
The AI Act does not operate in a vacuum: it interacts with other regulations that your business may already be complying with or that also affect you. Understanding these intersections avoids duplicated work and ensures coherent digital governance.
- GDPR: AI systems that process personal data — that is, virtually all those with an impact on people — must simultaneously comply with the AI Act and the GDPR. The GDPR impact assessments (DPIA) and the AI Act risk assessments can and should be coordinated to avoid duplicating effort. The legal basis for automated data processing remains the GDPR; the AI Act adds the system governance framework.
- NIS2: if your business operates critical infrastructures or essential services and uses AI systems in those environments, the cybersecurity obligations of the NIS2 Directive (pending transposition in Spain as of June 2026) overlap with the security and robustness requirements of the AI Act for high-risk systems.
- ISO 42001: this international standard for AI management systems can act as an implementation framework for AI Act obligations. Having a system certified under ISO 42001 makes it easier to demonstrate conformity with the Regulation, although ISO certification does not by itself constitute legal compliance with the AI Act.
If your business is already working on NIS2 compliance, we recommend coordinating both initiatives. You can learn more about our NIS2 and DORA consulting for businesses with regulatory exposure in cybersecurity.
Frequently asked questions
Does the AI Act affect me if I only use third-party SaaS tools with AI, such as ChatGPT or Copilot?
Yes, although with fewer obligations than if you were the system's developer. As a deployer (a business that uses an AI system developed by a third party), you have specific obligations: ensuring the system is used for its intended purpose, monitoring its operation, informing users when required and, if the system is high-risk, documenting its use and maintaining the required logs. The provider (Microsoft, OpenAI, etc.) assumes the obligations specific to providers, but that does not exempt you from your own obligations as a deployer.
What exactly is the «AI literacy» required by Article 4 and how do I demonstrate it?
Article 4 of the AI Act was replaced in full by Article 1, point 5, of Regulation (EU) 2026/1744, in force since 27 July 2026. Providers and deployers of AI systems must now take measures «to support the promotion of» AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context in which the systems are to be used. The article now states expressly that «this obligation does not require providers or deployers to guarantee a specific level of AI literacy of any particular person». In other words, the duty has moved from an obligation of result to an obligation of means — it still exists and is still enforceable, and it has been applicable since 2 February 2025. The Regulation sets no number of training hours or prescribed content, and the Commission is to publish practical examples of compliance on the single information platform referred to in Article 62(3)(b). A training plan proportionate to your use of AI, with a record of who was trained on what, remains the practical way to evidence the measures taken.
What did the Digital Omnibus on AI change and is it already binding?
It is binding, and it is not an agreement but a regulation. The Digital Omnibus on AI is Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026, published in OJ L, 2026/1744, 24.7.2026 and in force since 27 July 2026. Its most relevant changes for businesses are: (1) the date of application of Chapter III, Sections 1, 2 and 3 is deferred, with the express exception of Article 6(5), to 2 December 2027 for high-risk systems under Article 6(2) and Annex III and to 2 August 2028 for those under Article 6(1) and Annex I; (2) Article 4 on AI literacy is replaced in full; (3) a new Article 4a allows special categories of personal data to be processed, under strict conditions, to detect and correct bias; (4) two new prohibited practices are added to Article 5(1), first paragraph, applicable from 2 December 2026. The general date of application of the AI Act remains 2 August 2026, and the obligations already applicable keep their dates.
Who supervises the AI Act in Spain and what can it do?
The penalty regime of Chapter XII of the AI Act has applied since 2 August 2025, but the Regulation leaves it to each Member State to lay down the rules on penalties and designate the national authorities — and Spain has not yet adopted the law designating the national market surveillance authorities or setting out the national penalty procedure. What exists is a Draft Organic Law on the good use and governance of artificial intelligence (parliamentary file 121/000096, XV Legislature, published in the BOCG Congreso, Series A, No 97-1, of 12 June 2026), still at the amendment stage in the Committee on Economy, Trade and Digital Transformation, with the deadline for amendments extended to 2 September 2026. It has not been published in the BOE, it has no force of law and its wording may change; as drafted, it does not designate AESIA as the single authority but shares market surveillance between AESIA and other supervisors depending on the type of system. What is settled about the Spanish Agency for the Supervision of Artificial Intelligence (AESIA) is that its creation was authorised by Law 22/2021 and Law 28/2022, that Royal Decree 729/2023 of 22 August approved its Statute, that its seat is in A Coruña (Article 2 of the Statute) and that it published 16 guidelines to support AI Act compliance for high-risk systems, announced on 16 December 2025. AESIA is expected to take on market surveillance duties once the Spanish law is adopted.