Key Takeaways
- The EU AI Act sorts AI systems into four risk tiers: unacceptable (banned outright), high-risk (full compliance obligations), limited risk (transparency disclosures), and minimal risk (no added obligations). Knowing your tier is what decides how much compliance budget you commit.
- The Article 50 transparency deadline is no longer ahead of you. It applies from 2 August 2026, and national market surveillance authorities’ enforcement powers went live on the same date. If you run a customer-facing AI assistant or agent with no disclosure, you are already exposed.
- There is one piece of relief, and only one. Generative systems already on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking requirement under Article 50(2). The duty to tell people they are talking to an AI was not extended.
- The Digital Omnibus is now law — political agreement on 7 May 2026, Parliament endorsement on 16 June, Council approval on 29 June, in force from July 2026. It moves Annex III high-risk obligations to 2 December 2027 and Annex I to 2 August 2028.
- Sitting inside an Annex III domain does not automatically make you high-risk. Whether you are a provider or a deployer, and whether the Article 6(3) exemption applies, decide the outcome — and if you self-declare as exempt, you still have to register the system.
- Fines are up to 7% of global turnover or €35 million, whichever is higher, for prohibited practices, and up to 3% or €15 million for most other breaches — Article 50 included. That second tier is the one now live.
1. The Deadline Already Landed: What Applies Right Now
For most of the past year, the story in the trade press was that the EU AI Act had been delayed. That was true — but for a narrower slice of the Act than the headlines suggested, and the part that was not delayed has now arrived.
The Digital Omnibus on AI has completed its passage. The Council and Parliament reached political agreement on 7 May 2026, Parliament formally endorsed the text on 16 June, the Council gave final approval on 29 June, and the regulation entered into force in July 2026. It defers high-risk obligations for stand-alone Annex III systems from 2 August 2026 to 2 December 2027, and for AI embedded in regulated products under Annex I to 2 August 2028. For companies that genuinely fall under Annex III, that is real headroom — sixteen extra months on a timeline that was uncomfortably tight.
What the Omnibus did not touch is Article 50. Transparency obligations applied from 2 August 2026 as originally scheduled. Any AI system that interacts directly with a natural person must disclose that it is an AI. Synthetic content must carry a machine-readable marker. Deepfakes and AI-generated text published on matters of public interest must be labelled by the deployer. Emotion recognition and biometric categorisation require notification. From the same date, the Commission and national market surveillance authorities acquired the power to fine breaches of these duties at up to 3% of global turnover or €15 million, whichever is higher.
Two other obligations have been live even longer and are frequently forgotten: the prohibited practices and the Article 4 AI literacy duty have both applied since 2 February 2025, and obligations on general-purpose AI models since 2 August 2025.

Figure: EU AI Act compliance timeline, February 2025 to August 2028
One point before you read on, because it determines whether any of this is yours to worry about. The Act reaches beyond the EU’s borders: if your AI system’s output is used in the EU, or the system affects people located there, the obligations generally apply regardless of where your company is incorporated. For an Asia-headquartered company with European customers, European staff, or a product sold into the EU, the answer is usually yes. If you want the fuller picture on scope and how the Act compares with the rules in your own jurisdiction, start with our companion piece on why the EU AI Act has become the global reference point.
The sequencing is what trips companies up. Boards heard “delayed,” assumed the whole machine had moved, and put classification work on the 2027 calendar. In fact the obligation touching almost every company — disclose your AI, mark your generated content — is the one that arrived first, and it is already enforceable.
One date worth noting if you also sell into the United States: California moved the operative date of its AI Transparency Act (SB 942, as amended by AB 853) from January 2026 to 2 August 2026, — a coincidence several law firms have flagged, though the public legislative record does not document EU alignment as the stated reason for the date change. Large generative AI providers must now offer a free AI detection tool and apply visible and latent provenance disclosures, with further phases in 2027 and 2028. The engineering work overlaps heavily with Article 50(2) marking — scope it once.
If you have not run the inventory, you are not preparing for a deadline any more. You are remediating against a live one. That changes the order of the work, not the work itself.
2. The Four-Tier Risk Pyramid: How the EU AI Act Classifies AI Systems

Figure: EU AI Act four-tier risk pyramid — unacceptable, high-risk, limited, and minimal risk
| Risk Tier | Common Examples | Key Obligations & Timing |
|---|---|---|
| Unacceptable Risk | Social scoring, certain biometric categorisation, real-time remote biometric identification in public spaces (narrow law-enforcement exceptions) | Banned outright. In force since 2 February 2025. A new prohibition on AI-generated non-consensual intimate imagery and CSAM was added by the Omnibus and applies from 2 December 2026. |
| High-Risk | Recruitment screening, credit scoring, education admissions, law-enforcement risk assessment (Annex III’s eight domains); AI embedded in regulated products (Annex I) | Risk management, data governance, technical documentation, logging, human oversight, conformity assessment. Annex III: 2 December 2027. Annex I: 2 August 2028. |
| Limited Risk | AI assistants and customer service agents, autonomous AI agents, generative content tools, deepfake generators, emotion recognition | Article 50 transparency and disclosure. Live since 2 August 2026. Machine-readable marking under Article 50(2) is extended to 2 December 2026 for systems already on the market before 2 August 2026. |
| Minimal Risk | AI-enabled games, spam filters | No additional statutory obligations at present. |
| Cuts across all tiers | Any AI system, any tier | The Article 4 AI literacy duty has applied since 2 February 2025 and was not touched by the Omnibus. GPAI model obligations have applied since 2 August 2025. |
Executives instinctively ask “are we high-risk?” first. In practice the row to check first is limited risk — its obligations are already in force and they reach nearly every company running generative AI or an AI agent.
| Violation Type | Penalty Cap (whichever is higher) | Note |
|---|---|---|
| Prohibited practices | 7% of global turnover or €35 million | Unacceptable-risk tier |
| Provider and deployer obligations | 3% of global turnover or €15 million | Article 50 duties fall here — already in force |
| Supplying false or misleading information to regulators | 1% of global turnover or €7.5 million |
3. Are We High-Risk? Three Questions — and the Two Filters Most Companies Skip
Run every AI application your company uses or plans to use against Annex III’s eight domains: biometric identification, critical infrastructure, education and vocational training, employment and worker management (recruitment screening, performance evaluation, task allocation), essential public and private services (credit scoring, insurance pricing, benefits eligibility), law enforcement, migration and border control, and administration of justice and democratic processes.
For companies deploying generative AI or AI agents as internal efficiency tools, the trap is rarely the obviously regulated areas like law enforcement or border control. It is employment management and credit or insurance scoring — systems that IT or HR typically roll out before legal ever sees them.
The classification exercise runs on three questions:
- Does it fall on the prohibited list? Social scoring, manipulative techniques, real-time remote biometric identification in public spaces, and — from 2 December 2026 — AI-generated non-consensual intimate imagery. If yes, it is banned outright and no further analysis is needed.
- Does it fall into one of Annex III’s eight domains, or serve as a safety component in an Annex I product? If yes, it is a candidate for high-risk — but read the two filters below before you conclude that it is.
- Even if it is not high-risk, does it interact with people, generate content, or act as an agent on someone’s behalf? If yes, it is limited-risk, and the Article 50 obligations already apply. This is the step most companies skipped, because they spent all their attention on question two.

Figure: three-question classification flow, with the provider/deployer and Article 6(3) filters
Filter one: are you the provider or the deployer? The Act assigns sharply different duties to the company that develops and places an AI system on the market and the company that uses it under its own authority. A bank that buys a credit-scoring model is a deployer; the vendor is the provider. Most of the heavy high-risk engineering obligations — risk management systems, technical documentation, conformity assessment — sit with the provider. Deployers carry human oversight, input-data relevance, log retention, and monitoring duties. Two warnings: putting your own name on a third-party system, or substantially modifying it, can make you the provider of it. And under Article 50, some duties are explicitly the deployer’s — labelling deepfakes and AI-generated text on matters of public interest is your obligation even if you did not build the model.
Filter two: does the Article 6(3) exemption apply? A system can sit squarely inside an Annex III domain and still fall outside the high-risk tier if it does not pose a significant risk of harm to health, safety, or fundamental rights — because it performs a narrow procedural task, improves the result of a previously completed human activity, detects decision patterns without replacing human assessment, or performs preparatory work. A CV-parsing tool that extracts structured fields for a recruiter to review is a different object from a tool that ranks and screens out candidates. This filter is where a great many HR and finance deployments actually get decided.
The exemption is not a free pass. If you rely on Article 6(3), you must document the assessment before placing the system on the market or putting it into service — and the Omnibus reinstated the obligation to register the system in the EU database even when you have self-declared it exempt. An undocumented exemption is indistinguishable from an unclassified system when a regulator asks.
4. What the Commission’s Final Article 50 Guidelines Changed
On 20 July 2026, less than two weeks before the obligations took effect, the Commission adopted the final version of its Guidelines on implementing Article 50 — a 51-page document replacing the May draft. Separately, on 8 and 9 July, the Commission and the AI Board assessed the Code of Practice on Transparency of AI-Generated Content as adequate to demonstrate compliance. Neither instrument is binding — only the CJEU can authoritatively interpret the Act — but national market surveillance authorities and the AI Office can be expected to work from them, which makes them the practical yardstick.
Five points from the final text are worth acting on:
- Burying the disclosure in your terms and conditions is not enough. The duty is to inform the person interacting with the system, and a link nobody opens does not inform them. Technical marking alone does not satisfy the Article 50(1) disclosure duty either.
- AI agents get specific treatment. Where a provider cannot determine in advance whether an agent will interact with a natural person, the agent must be designed and instructed to disclose itself wherever such interaction is reasonably likely — including when the person is acting for a legal entity. Agents must also disclose themselves at key steps such as authorisation, reporting, and validation, and at every new interaction. Multi-agent architectures are in scope.
- The business-to-business carve-out was tightened. Three cumulative conditions now apply, including that the output must not be intended for sharing outside the organisation and must be protected by safeguards against foreseeable misuse, such as cloud isolation and role-based access control. Public and consumer-facing systems are excluded from the carve-out entirely.
- Marking sits with the system provider, not the upstream model provider. If you build a product on someone else’s foundation model, the Article 50(2) obligation for the content your system generates is yours.
- There is no retroactive labelling duty. Content created before 2 August 2026 does not need to be labelled. For text on matters of public interest, the relevant date is publication — so content generated before the deadline but published after it is in scope.
5. Infrastructure That Carries the Weight, Whichever Tier You Land In
Work through the three questions and the two filters and most companies land in limited risk, with a meaningful minority in high-risk. Only a small set lands in minimal risk with nothing to do — and even those still carry the Article 4 AI literacy duty.
For everyone else, the underlying problem is the same, and it is an evidence problem rather than a policy one. You need to show that disclosure happened, that oversight happened, that data was governed — and produce a complete, reconstructable record when an auditor, a customer’s procurement team, or a market surveillance authority asks. Policy documents do not produce that record. Infrastructure does.
That is why companies evaluating an AI governance platform tend to look for architecture already aligned to high-risk standards, so that moving up a tier later does not mean rebuilding. AnyInsight's architecture is currently being built toward high-risk-level compliance standards with the aim of carrying a share of that burden for its customers rather than leaving it entirely with them. Concretely:
- Complete interaction logging — recording the full interaction history between users, AI systems and agents, and external systems, including uploads and downloads, exportable for audit. This is the evidence layer behind the record-keeping and technical documentation requirements for high-risk systems, and behind demonstrating that Article 50 disclosure actually reached the user — which the Commission’s Guidelines now scrutinise directly.
- Sensitive-data oversight — monitoring for personal data such as national ID numbers and bank account details, or customer-defined categories, with blocking, alerting, or masking on inbound and outbound flows. This addresses the data governance requirements for high-risk systems while reducing everyday leak exposure.
- AI firewall with allow-list access control — blocking unauthorised access and malicious content, and enforcing which systems and agents may act. This maps to the access-control layer of human oversight, and to the isolation and role-based safeguards the final Guidelines now require for the B2B carve-out.
- Dual-model comparison — running the same query through two models to surface disagreement and reduce hallucination or misjudgement. This is an output-quality control that gives human reviewers something concrete to act on; it supports human oversight and accuracy in practice, and feeds the monitoring evidence a formal risk management system draws on.
Worth being explicit: not every company deploying AI lands in the high-risk tier, and this article is not a substitute for a classification your own legal counsel signs off on. AnyInsight’s position is simply that wherever your classification lands, the groundwork should already be under you rather than ahead of you.
6. FAQ
Q1: We are not headquartered in the EU — does this still apply to us?
Usually yes. The Act has extraterritorial reach, and Section 1 sets out the test. Our companion article on the global regulatory picture works through scope in more detail. Confirm the specifics for your situation with legal counsel.
Q2: We missed 2 August 2026. What do we do now?
Triage rather than panic. First, inventory every system that interacts with a person or generates content. Second, fix the disclosure gaps — they are the fastest to close and the most visible to a regulator or a complainant. Third, check whether your generative systems were on the market before 2 August 2026; if so, the machine-readable marking obligation under Article 50(2) runs to 2 December 2026, which gives you a defined window rather than an open exposure. Document the remediation as you go, because a demonstrable, dated programme reads very differently from silence.
Q3: The high-risk deadline moved to December 2027 — can we revisit this next year?
The deferral buys time on the full compliance obligations. It does not exempt you from classifying now, and it did not touch Article 50, the AI literacy duty, or the prohibitions. High-risk programmes — risk management systems, data governance, technical documentation, conformity assessment — typically take months to a year to stand up. Sixteen months is a schedule, not a reprieve.
Q4: We only buy AI tools, we do not build them. Does that make us exempt?
No. It usually makes you a deployer rather than a provider, which changes which obligations you carry, not whether you carry any. Deployers hold human oversight, input-data, log-retention and monitoring duties for high-risk systems, and under Article 50 they hold the labelling duty for deepfakes and AI-generated text on matters of public interest. Note also that rebranding a third-party system as your own, or substantially modifying it, can make you its provider.
Q5: We only use AI internally, not customer-facing. Does this still matter?
Internal use does not automatically exempt you. What matters is whether the use case falls into an Annex III domain — internal performance reviews and recruitment screening are the common examples — not whether it is internal or external. The final Article 50 Guidelines also tightened the business-to-business carve-out, so internal deployment on its own is a weaker shield than it was in the draft. Have legal or compliance inventory every AI application, internal and external alike.
Conclusion
Classification is not a one-time exercise. It is worth revisiting every time you roll out a new AI application, and especially now, while the Commission’s interpretive guidance is still settling and the high-risk regime is being built out ahead of December 2027.
The framing has changed, though. Until this month, the honest advice was to use the runway. The runway is gone. The right posture now is triage: inventory what you are running, close the disclosure gaps first because they are live and cheap to fix, use the window to 2 December 2026 for marking on legacy generative systems, and build the classification record for Annex III while you still have sixteen months to do it properly.
The Series, Start to Finish
This was Part 2 of The EU AI Act Playbook.


