AI Act — What Does the European Union’s First Comprehensive AI Regulation Require?

AI Act — What Does the European Union's First Comprehensive AI Regulation Require? - ai act

The AI Act is coming — the European Union’s first comprehensive regulation on artificial intelligence. Its purpose is to help companies and organizations reduce the risks associated with AI. 

It does not necessarily mean a restriction for every company. While high-risk systems are subject to strict requirements, limited-risk systems carry a transparency obligation. Minimal-risk systems — which make up most of the AI in use today — can operate freely.

This article focuses on the technical side: who the regulation applies to, what the deadlines are, and what IT conditions must be met for compliance.

Who does it apply to?

The scope of the regulation is broader than it may first appear. Beyond AI developers, it also reaches the companies that use AI.

The AI Act distinguishes between two primary roles. A provider is an organization that develops an AI system or places it on the market under its own name. A deployer is an organization that uses a finished AI system in its own operations. Most large enterprises fall into this second category.

Three questions help determine whether an organization is affected:

  • Does the company use an AI system that makes or supports decisions about people? This includes credit scoring, HR screening, and insurance risk assessment. These typically fall into the high-risk category.
  • Does the company develop or customize its own AI solution? In that case, provider obligations may apply, beyond simple use.
  • Does the company interact directly with its customers through AI? A customer service chatbot or a generative content tool triggers a transparency obligation. Affected individuals must know they are talking to a machine.

The same large language model can be minimal-risk in an internal summarization tool and high-risk in a CV-screening process. Classification is always determined by the specific use case.

What are the deadlines?

The AI Act is being phased in, and reaches an important milestone in the summer of 2026. Recent amendments have pushed back some deadlines while leaving others unchanged. It’s worth knowing which applies when.

Already in force:

  • Prohibited practices — such as social scoring — since February 2, 2025.
  • Rules governing general-purpose (GPAI) models and the supervisory structure, since August 2, 2025.

Taking effect in 2026:

  • August 2, 2026 — transparency rules. Users must be informed when they are interacting with an AI system. On this date, national market surveillance authorities also receive full inspection and enforcement powers.
  • December 2, 2026 — two new prohibited practices: producing non-consensual intimate content and child sexual abuse material using AI. From the same date, machine-readable labeling of synthetic content becomes mandatory for generative systems placed on the market before August 2026.

Later:

  • December 2, 2027 — standalone high-risk (Annex III) systems: credit scoring, HR screening, biometric identification, critical infrastructure.
  • August 2, 2028 — high-risk systems embedded in regulated products (Annex I).

The deferral provides real breathing room for the most complex obligations. Compliance for high-risk systems, however, still requires risk assessment, technical documentation, and conformity assessment. This is work measured in months. The 2027 date is the deadline for completion, not the starting point.

Worth noting: the AI Act’s deadlines have already been amended once. The obligations for high-risk systems were pushed back by the Digital Omnibus package, adopted by the Council on June 29, 2026. The dates above reflect this current status. Further amendments cannot be ruled out, so it is worth verifying final deadlines against an official EU source. This overview does not constitute legal advice.

Where does your own system fall?

The AI Act classifies the risk of the use case, not the technology itself. The same system can fall into a different category depending on how it is used. There are four tiers, and classification determines the obligations. It’s worth reviewing where your own systems fit.

Unacceptable risk. No company may use this category: the associated practices are entirely excluded from the EU market because they are incompatible with fundamental rights. This includes social scoring, subliminal manipulation, and real-time biometric identification in public spaces. The ban has applied since February 2, 2025, with no exemptions.

High risk. Many large enterprises fall into this category — often more easily than expected. A company is affected if it uses AI in credit scoring, HR screening, insurance risk assessment, biometric identification, or the management of critical infrastructure. These systems may remain on the market, but only under strict conditions — risk management, logging, human oversight, and detailed documentation. The vast majority of obligations are built around this category.

Limited risk. This applies to a company operating a customer service chatbot or using a generative tool to produce content. The requirement is transparency: users must know they are communicating with a machine, and AI-generated content must be labeled. Compliance is considerably lighter here, without a full conformity assessment.

Minimal risk. Most everyday AI use by companies falls here — from spam filters to recommendation engines to inventory optimization. The regulation imposes no separate obligations on these. Voluntary adherence to a code of conduct is recommended, but not required.

What needs to be done?

Most obligations fall on the high-risk category. At first glance the list is long, but a recurring pattern runs through it: most requirements come down to monitoring, documenting, and overseeing the system’s operation continuously, in production. This is exactly where observability becomes increasingly indispensable.

Automatic logging. The regulation requires a high-risk system to automatically record its operation throughout its entire lifecycle. This logging provides the evidence of compliance: without it, what happened and why cannot be reconstructed afterward. On the IT side, this means continuous, reliable event logging that covers the AI system’s entire path.

Human oversight. High-risk systems must be designed so that a person can meaningfully oversee them and intervene when necessary. This requires the system’s behavior to be transparent: real-time visibility, alerting, and anomaly detection are needed so the responsible person notices in time when something goes wrong.

Accuracy, robustness, cybersecurity. Three requirements that must all be met simultaneously in production. The system must operate reliably and predictably, and must not be manipulable. In production, this means continuously monitoring accuracy, response time, error rate, and model drift. Performance degradation can only be managed once it becomes visible in time.

Post-market monitoring. After the system reaches the market, the provider must continue to actively monitor it and report serious incidents to the authority. This presupposes continuous production-level observation and a functioning incident-management process.

These four obligations share a common technical foundation: you need to see what the AI system is doing, continuously, in a live environment. 

This is where AI Observability comes in. It turns the black box into transparent, documentable operation, and compliance becomes the natural outcome of well-managed operations — without a separate investment of effort.

Consequences of non-compliance

The regulation sets out expectations, and attaches significant penalties to non-compliance. Fines are tiered, scaled to the severity of the violation. For each tier, the regulation specifies both a fixed amount and a percentage of revenue — whichever is higher applies.

The most severe tier: prohibited practices. Using prohibited AI practices can result in fines of up to €35 million or 7% of global annual revenue.

Violations of high-risk and transparency obligations. Failing to meet the requirements for high-risk systems or the transparency rules can result in fines of up to €15 million or 3% of revenue.

Incomplete or misleading information. If an organization provides inaccurate, incomplete, or misleading data to the authorities, the fine can reach €7.5 million or 1% of revenue.

Beyond financial penalties, authorities may order a system’s withdrawal from the market or restrict its operation. Full inspection and enforcement powers pass to national market surveillance authorities as of August 2, 2026 — the date the grace period ends.

For SMEs and startups, the lower of the two values applies, keeping the penalty proportionate to the organization’s size.

Observability is the key to compliance

The AI Act’s long list of requirements ultimately converges on a single point: you need to know what your AI system is doing, continuously, in a live environment. Logging, human oversight, accuracy monitoring, and incident management are all built on this same foundation.

Compliance with the EU AI Act is, in large part, an operational matter. An organization with clear visibility into its systems has already laid the technical foundation for compliance.

AI systems present a particular challenge because their behavior is non-deterministic — something traditional monitoring struggles to capture. AI Observability provides end-to-end visibility into AI-based applications, tracking performance, response time, token usage, and quality signals, and flagging deviations. This turns the black box into transparent, documentable operation.

At Telvice, we help put this technical foundation in place before the deadlines arrive. Get in touch for an expert consultation.

Sources

Official EU sources:

The Digital Omnibus and the amended deadlines:

Fine tiers: