Key Takeaways
- The EU AI Act establishes four risk levels: Prohibited, High-Risk, Limited Risk, and Minimal Risk. Your obligations depend entirely on which category your AI systems fall into.
- August 2, 2026 is the critical deadline: high-risk Annex III systems (HR, credit scoring, biometrics, education) must be fully compliant from this date.
- General-Purpose AI (GPAI) obligations have been in force since August 2, 2025. Any company building products on models like GPT or Claude is both a deployer of that model and a provider of their own product.
- Penalties exceed GDPR: up to €35M or 7% of global turnover for prohibited AI practices, €15M or 3% for other non-compliance.
- Every EU member state must have an operational AI regulatory sandbox by August 2, 2026 - a resource for startups and companies testing compliance approaches.
Is Your HealthTech Product Built for Success in Digital Health?
.avif)
The EU AI Act is no longer a future concern. It entered into force on August 1, 2024, and its obligations have been rolling out in phases ever since. If your company builds, deploys, or uses AI systems, the most critical deadline yet lands on August 2, 2026.
This article breaks down what the regulation actually requires, who it applies to, and what your company needs to do right now.
What Is the EU AI Act?
The EU AI Act (Regulation (EU) 2024/1689) is the world’s first comprehensive legal framework for artificial intelligence. It applies to any company that places AI systems on the EU market or uses them to affect people in the EU, regardless of where the company is based.
That means US-based SaaS companies, Asian AI vendors, and any global business with EU customers or operations falls within its scope.
The Four Risk Categories
The Act classifies AI systems into four risk levels. Your obligations depend entirely on which category your system falls into.
Prohibited AI
Certain AI applications are banned outright under Article 5. These include:
- AI using subliminal, manipulative, or deceptive techniques that distort behavior
- AI exploiting vulnerabilities of people based on age, disability, or socioeconomic situation
- Social scoring systems evaluating people based on behavior with negative consequences
- Predictive crime risk assessment based purely on profiling (with no objective evidence)
- Scraping facial images from the internet or CCTV to build biometric databases
- Emotion recognition systems in workplaces and educational institutions
- Biometric categorization inferring race, political views, sexual orientation, or religious beliefs
- Real-time remote biometric identification in public spaces by law enforcement (with narrow exceptions: searching for missing persons, preventing imminent threats, identifying suspects of serious crimes)
Violations of these prohibitions carry the highest penalties: up to €35 million or 7% of global annual turnover, whichever is higher. These rules have been enforceable since February 2, 2025.
High-Risk AI
High-risk systems are not banned, but they require substantial compliance work before and after deployment. The Act defines two types:
Article 6(1) - AI embedded in safety-regulated products: Systems that are a safety component of, or themselves constitute, a product covered by EU harmonisation legislation listed in Annex I (medical devices, machinery, vehicles, aviation equipment). These must comply by August 2, 2027, this is the one provision deliberately deferred to give manufacturers of physical products more time.
Article 6(2) - Annex III standalone AI systems: AI used in specific high-stakes domains, regardless of whether it is embedded in a physical product. These must comply by August 2, 2026. Categories include:
- Recruitment, employee evaluation, and workforce monitoring
- Educational access and assessment
- Credit scoring and insurance risk evaluation
- Law enforcement profiling and risk assessment
- Migration and asylum processing
- Administration of critical infrastructure
- Biometric identification and categorization
Providers of high-risk AI must implement:
- A risk management system (ongoing, not a one-time assessment)
- Data governance practices covering training, validation, and testing data
- Technical documentation kept up to date
- Automatic logging of system activity
- Transparency measures enabling human oversight
- Accuracy, robustness, and cybersecurity standards
Provider vs. deployer: the Act distinguishes between providers (companies that develop and place an AI system on the market under their own name) and deployers (companies that use an AI system in their own operations). A company building a product on top of a third-party model such as GPT or Claude is the deployer of that model but the provider of their own product - and carries provider obligations for it. If a deployer substantially modifies a high-risk system or changes its intended purpose, they become the provider of the modified system and must meet all provider obligations.
Deployers of high-risk systems must conduct fundamental rights impact assessments and ensure appropriate human oversight is in place.
Non-compliance with obligations applying to providers, importers, distributors, and deployers: up to €15 million or 3% of global annual turnover.
Limited Risk
This category covers AI systems with moderate interaction potential, primarily interactive systems and those generating synthetic content.
Key obligation under Article 50: providers of any AI system designed for direct interaction with natural persons, chatbots, virtual assistants, AI voice systems, must ensure users are informed they are interacting with an AI, unless this is obvious from context. Deployers of emotion recognition systems must additionally notify the people being subject to them. Systems generating synthetic audio, images, video, or text must label that content as machine-generated. An exception applies for legitimate artistic, editorial, or journalistic purposes.
These transparency obligations apply from August 2, 2026.
Minimal Risk
The vast majority of AI applications fall here: spam filters, recommendation engines, data analysis tools, AI in video games. No specific requirements apply, though voluntary codes of conduct are encouraged.
General-Purpose AI Models (GPAI)
This is the category most relevant to companies building products on top of foundation models like GPT, Claude, or Gemini, and to the providers of those models themselves.
GPAI obligations have been in force since August 2, 2025. Providers of GPAI models must:
- Maintain detailed technical documentation
- Comply with EU copyright law and publish summaries of training data content
- Make publicly available a sufficiently detailed summary of training data
Providers of models that pose systemic risk (those trained with compute exceeding 10²⁵ FLOPs) face additional requirements:
- Adversarial testing and red-teaming
- Incident reporting to the AI Office
- Cybersecurity protections
- Model evaluation against standardized benchmarks
Providers of GPAI models placed on the market before August 2, 2025 have until August 2, 2027 to achieve full compliance.
The Full Implementation Timeline
- August 1, 2024: AI Act enters into force
- February 2, 2025: Prohibited AI practices banned; AI literacy requirements apply
- August 2, 2025: GPAI obligations, governance framework, and penalties framework active
- August 2, 2026: High-risk Annex III obligations; Article 50 transparency rules; regulatory sandboxes operational in all member states
- August 2, 2027: Article 6(1) obligations for AI embedded in safety-regulated products (Annex I); GPAI models placed on market before August 2, 2025 must comply
- August 2, 2030: AI systems used by public authorities must comply
Regulatory Sandboxes: A Path for Innovators
By August 2, 2026, every EU member state must have at least one AI regulatory sandbox operational. These are controlled environments where companies can develop and test AI systems with reduced regulatory friction, under supervision of national authorities.
For startups and scale-ups building innovative AI products, sandboxes offer a legitimate route to test compliance approaches before full market deployment. Participation can also serve as evidence of good-faith compliance effort.
How the AI Act Compares to GDPR
Many companies already have GDPR processes in place. The AI Act layers on top of these, and the two frameworks overlap significantly for AI systems that process personal data.
Key differences to keep in mind:
- Higher maximum penalties: GDPR caps fines at 4% of global turnover. The AI Act goes up to 7% for the most serious violations.
- Proactive obligations: GDPR is largely triggered by data processing activities. The AI Act requires conformity assessments and documentation before a system goes to market. The AI Implementation Playbook covers how to embed responsible AI practice into your development process.
- Supply chain accountability: Both deployers and providers carry obligations under the AI Act. Buying an AI tool from a third party does not transfer compliance responsibility entirely to the vendor.
Organizations subject to both must maintain valid GDPR legal bases, conduct Data Protection Impact Assessments where required, and align AI Act documentation with existing data governance practices. For teams building healthcare products, the HIPAA compliance decision tree is a useful starting point for understanding how HIPAA scope maps to your product.
What Your Company Should Do Now
Regardless of where your AI systems fall in the risk hierarchy, three steps apply immediately:
1. Map your AI systems
Catalogue every AI system your company builds, deploys, or uses in a professional context. Identify whether each system falls under Article 6(1), Annex III, GPAI, or lower risk categories.
2. Assess your obligations
For each system, determine what the Act requires: documentation, risk management, transparency disclosures, or simply awareness. The EU AI Act’s official Compliance Checker at artificialintelligenceact.eu can help structure this assessment.
3. Build compliance into your product process
Compliance under the AI Act is not a one-time audit. Risk management systems must be ongoing, logging must be continuous, and documentation must stay current. The earlier you embed these into your development workflow, the lower the long-term cost. Momentum's Infrastructure and Security service helps teams build compliant AI systems from the ground up.
The Cost of Non-Compliance
- Prohibited AI practices (Article 5): up to €35M or 7% of global annual turnover
- Non-compliance by providers, importers, distributors, deployers: up to €15M or 3% of global annual turnover
- Incorrect information to authorities: up to €7.5M or 1% of global annual turnover
Final Thought
The EU AI Act is the most significant AI regulation to date, and August 2, 2026 marks the point at which most companies will feel its practical impact. The good news is that the framework is risk-based: if your AI applications are low-risk, compliance is minimal. If they are high-risk, you now have a clear roadmap.
The companies that will struggle most are those that have not yet mapped their AI exposure. That mapping is the essential first step.
At Momentum, we help technology companies build and scale AI products. If you want to think through how the AI Act affects your product or roadmap, get in touch.





.avif)
.avif)
.avif)

