EU AI Act: What It Is, Deadlines and How to Prepare in 2026

AI is now a board-level topic, and so is the regulation that comes with it. The EU AI Act is the first comprehensive AI law in the world, and it carries fines that can outpace GDPR. If your company builds, sells, or simply uses AI systems that touch people within the European Union, the EU […]

by Angel Kurtev

August 6, 2026

10 min read

Dreamix EU AI Act, EU AI Act how to prepare, EU AI act timeline

AI is now a board-level topic, and so is the regulation that comes with it. The EU AI Act is the first comprehensive AI law in the world, and it carries fines that can outpace GDPR. If your company builds, sells, or simply uses AI systems that touch people within the European Union, the EU AI Act is applicable to you, no matter where your headquarters sit.

This guide breaks down what the regulation covers, who it concerns, what your obligations are based on risk level, and what a sound compliance plan looks like. We'll also share how Dreamix, with more than two decades in regulated industries like fintech, regtech, aviation and healthcare, helps partners turn compliance into a competitive advantage instead of a bottleneck.

What Is the EU AI Act?

The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) is the European Union's attempt to set common rules for how AI is built, sold, and used across its 27 member states. It entered into force on August 1, 2024, and its obligations are phasing in through 2027 and beyond.

Rather than treating all artificial intelligence systems the same, the Act takes a risk-based approach. That means that the stricter the potential impact on people's safety and rights, the heavier the compliance burden. This mirrors how the EU approached data privacy with GDPR: set a baseline, phase it in, and let it become a global reference point for other regulators. Deloitte notes that the Act is already shaping AI governance conversations well beyond Europe, with several other jurisdictions drafting comparable frameworks of their own.

Who does the AI act concern?

This is the part decision makers most often underestimate: the Act reaches far beyond companies physically based in the EU.

It applies to any organization, EU-based or not, that:

  • Builds and places AI systems on the EU market, or puts them into service there ("providers")
  • Uses AI systems within the EU as part of business operations ("deployers")
  • Imports or distributes AI systems into the EU
  • Has AI outputs that are used by people located in the EU, even if the system itself was developed elsewhere.

In practice, a US or Asian company selling AI-driven software, tools, or services to EU customers, or using AI to make decisions that affect people in the EU (hiring, credit scoring, insurance pricing), falls under scope. The extraterritorial reach is deliberate, and it closely follows the GDPR playbook that many businesses are already familiar with.

Sectors under particular scrutiny include financial services, insurance, healthcare, aviation and transportation, HR and recruitment, law enforcement, and any business relying on biometric or credit-scoring systems.

The four risk tiers and how they affect your business

The Act sorts AI systems into four categories, and your obligations scale with the risk level Deloitte outlines clearly in its governance breakdown:

1. Unacceptable risk: banned outright. Systems that manipulate human behaviour, enable social scoring, or use real-time biometric identification in prohibited ways are simply not allowed on the EU market as also stated in the Official Journal of the European Union.

2. High risk: heavy compliance requirements. This covers AI used in safety-critical contexts such as aviation, medical devices, critical infrastructure, credit scoring, and recruitment. Providers must build a risk management system, maintain rigorous technical documentation, ensure human oversight, and pass conformity assessments before deployment.

3. Limited risk: transparency obligations. Chatbots, AI-generated content, and deepfakes fall here. The core requirement is simple: people must know they're interacting with AI, and synthetic content needs to be identifiable as such.

4. Minimal risk: light touch. The majority of everyday AI applications, from recommendation engines to AI-enabled virtual assistants, face few binding requirements, though voluntary codes of conduct are encouraged.

If your business operates in high-risk territory, expect real engineering and governance work: documented risk management, quality management systems, audit trails, and in many cases, a registered representative in the EU.

Key deadlines to know

The AI Act's timeline shifted meaningfully in 2026 through the EU's "Digital Omnibus" simplification package, which the European Parliament and Council formally adopted in June 2026, with the changes entering into force in July 2026. The dates below reflect the current, legally binding timeline:

2 August 2026: The EU AI Act becomes generally applicable. Article 50's transparency obligations apply from this date: providers and deployers must comply with the disclosure duties it sets out. This date survived the Omnibus largely intact - the high-risk regime moved, transparency and enforcement did not. (European Commission)

2 December 2026: The first near-term deadline

First, the new Article 5 prohibition on AI systems generating child sexual abuse material and non-consensual intimate material - the "nudifier" ban - becomes applicable, roughly four months after the Omnibus entered into force. Second, a narrow grandfathering deadline: generative AI systems placed on the market before 2 August 2026 must meet the machine-readable marking and detection obligation under Article 50(2) only from this date. Content generated before 2 August 2026 needs no retroactive labelling. Systems placed on the market on or after 2 August 2026 mark from the August date, not December. 

2 August 2027: The compliance rulebook becomes usable

Providers of general-purpose AI models that were on the market before 2 August 2025 must be compliant by this date. That deadline sits in Article 111(3) of the AI Act itself and was not changed by the Omnibus - so if you built your own foundation model, or license one from a vendor whose model predates August 2025, the grandfathering runs out here. 

Expert advice: Procurement teams should be asking potential vendors about this now, not in 2027.

EU AI Act, EU AI act implementation timeline, EU AI Act impact business, how to prepare for E AI Act

Two further things land on this date. Member States must have at least one national AI regulatory sandbox operational by 2 August 2027 - a real option if you're building something novel and would rather test under supervision than guess. And by the same date the Commission must adopt delegated acts specifying where obligations can be limited because sectoral product legislation already provides equivalent protection. 

If you're in a regulated sector, that act could remove duplicate work -  worth tracking rather than assuming the worst case.

2 December 2027: The big one for most companies

From this date, AI used in business operations like e.g. recruitment, credit, education, biometrics and access to essential services must meet the full high-risk requirements: documented classification, risk and quality management, technical documentation, and conformity assessment before deployment. 

The date moved from August 2026 because standards and national authorities weren't yet ready and proceeding would have driven implementation costs sharply higher sixteen extra months, not a lighter obligation. 

2 August 2028: AI inside regulated physical products

The same high-risk requirements reach AI that is, or is a safety component of, a product already covered by EU harmonisation law - medical devices, machinery and similar. 

Two changes narrow the scope and warrant re-running existing classifications: AI used solely for user assistance, performance optimisation, service efficiency, automation, convenience or quality control no longer counts as a safety component unless its failure would endanger health and safety, and embedding a high-risk AI system does not by itself force third-party conformity assessment where the sectoral legislation already allows reliance on harmonised standards.

The takeaway for decision makers: the timeline bought some breathing room, but GPAI obligations and prohibited-practice rules are already enforceable today, and formal adoption of the revised dates is expected before the original August 2026 cutoff. Treating this as a 2027 problem is a mistake. Inventorying your AI systems and classifying their risk level now is what protects you regardless of how the calendar moves.

Potential penalties: A fine structure

Regulators built the AI Act's fine structure to be more severe than GDPR's:

  • Up to €35 million or 7% of global annual turnover, whichever is higher, for deploying prohibited AI practices.
  • Up to €15 million or 3% of turnover for other high-risk compliance failures.
  • Up to €7.5 million or 1% of turnover for submitting incorrect or misleading information to regulators.

Beyond fines, authorities can force a noncompliant AI system off the market entirely, which can mean lost revenue, damaged partner trust, and a scramble to rebuild product roadmaps under regulatory pressure. For companies with EU customers or operations, this is a business continuity issue as much as a legal one.

Also read: eIDAS 2.0 Explained: What it is, Timeline, and Business Impact

Where to start and how to prepare 

Deloitte's guidance for organisations getting ahead of the Act centers on five moves that apply just as well to a 200-person company as a global enterprise:

  1. Take stock: Build a full inventory of the AI systems in use across your company and classify each one against the Act's risk tiers.
  2. Plan and mobilise: Set a coordinated strategy for managing AI risk, track new obligations as they're finalized, and map requirements to your existing risk and controls framework.
  3. Assign clear ownership: Compliance shouldn't sit with one team in isolation. Bring legal, engineering, product, and data governance together, with senior leadership backing the effort.
  4. Adopt a recognised framework: Rather than build controls from scratch, align to established standards so your documentation holds up to audit and scales as new AI systems come online.
  5. Use AI to manage AI: Modern governance tooling can help identify applicable regulations, flag documentation gaps, and monitor systems as they change, cutting the manual burden significantly.

McKinsey's 2026 research on responsible AI maturity found that organizations investing seriously in governance and risk management already see measurably stronger outcomes from their AI programs, including higher realized business value (McKinsey). Compliance and performance aren't competing priorities. They tend to move together.

How Dreamix helps you get ahead of the AI act

Compliance work goes faster when your technology partner already understands regulated environments instead of learning them on your dime.

For nearly two decades, we've built software for partners in fintech, regtech, aviation, and transportation, sectors where regulatory scrutiny, data governance, and audit-readiness are part of daily operations, not an afterthought. Regtech in particular has been core to our work for years: we've built the systems companies use to meet reporting obligations, evidence their controls, and satisfy supervisors, which means regulatory requirements arrive to us as engineering problems we've solved before rather than as unfamiliar legal text. That background matters directly here, because high-risk AI classifications under the Act concentrate in exactly these industries.

Here's what that experience translates into for your AI compliance work:

  • Reliable, explainable, and audit-ready AI systems: We build AI that holds up under scrutiny, with decisions your teams can trace and explain, behaviour that stays consistent in production, and the evidence trail a regulator or auditor will ask for. These qualities are designed in from the first sprint rather than reverse-engineered once a deadline lands.
  • AI system inventory and risk classification: We help you map every AI system in use, from internal tools to customer-facing products, against the Act's four risk tiers, so you know precisely where your exposure sits.
  • Technical documentation and audit trails: Our engineering teams build the automatic logging, quality management processes, and documentation structures that high-risk systems require, integrated into your development pipeline rather than bolted on afterward.
  • Human oversight and governance design: We help design the review checkpoints and escalation paths regulators expect for high-risk systems, without slowing down your product teams more than necessary.
  • Domain-specific expertise: Our work in aviation and fintech means we already speak the language of conformity assessments, data governance, and sector-specific safety rules, so your compliance program is built around how your industry actually operates.
  • Long-term partnership, not a one-off audit: The AI Act's timeline keeps shifting, and enforcement will keep evolving with it. We work with partners for years, not project sprints, which means your compliance posture stays current as the regulatory picture changes.
How Dreamix can help you with EU AI Act, EU AI Act business impact, how to prepare and secure business operations

Done well, reducing risk under the AI Act builds the kind of trust that becomes a genuine differentiator with EU customers, regulators, and partners alike, well beyond simply avoiding fines.

If you're assessing where your AI systems stand today, or need a technology partner who understands both the engineering and the regulatory side of the equation, we're glad to help you map the path forward.

FAQ: EU AI Act Compliance

The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive law regulating artificial intelligence. It sorts AI systems into four risk tiers and sets compliance obligations that scale with each tier, applying across all 27 EU member states.

Any organization that builds, sells, deploys, or distributes AI systems affecting people in the EU, regardless of where the company is headquartered. This includes providers, deployers, importers, and distributors of AI systems.

Unacceptable risk (banned outright), high risk (heavy compliance requirements, mainly in safety-critical sectors), limited risk (transparency obligations, such as chatbot disclosure), and minimal risk (light touch, mostly voluntary).

Deadlines are staggered. Bans and AI literacy obligations began February 2025. GPAI provider obligations began August 2025. Transparency and watermarking rules for legacy systems, plus new content-related prohibitions, apply from December 2026. The main high-risk compliance deadline is December 2, 2027, and high-risk AI embedded in regulated products has until August 2, 2028.

Yes. Through the EU's Digital Omnibus simplification package, formally adopted in June 2026, the high-risk compliance deadline for standalone Annex III systems moved from August 2026 to December 2, 2027, roughly a 16-month extension.

The fines can reach up to to €35 million or equal 7% of global annual turnover for prohibited AI practices, up to €15 million or 3% for other high-risk violations, and up to €7.5 million or 1% for misleading information

The AI Act's maximum fine, €35 million or 7% of turnover, exceeds GDPR's ceiling of €20 million or 4% of turnover. Both regulations share an extraterritorial reach, applying to companies outside the EU whose products or services affect people within it.

Yes. If your AI system is placed on the EU market, used within the EU, or produces outputs used by people in the EU, the Act applies regardless of where your company is based.

We’d love to hear about compliance needs regarding the EU AI Act and help you meet your business goals as soon as possible.

Categories

Angel brings 10+ years of experience in building enterprise software products in the industries of telecommunications and Fin Tech. Skilled in bringing projects from idea to reality - product management, business analysis, agile practices and technical awareness.