Most companies react to the EU AI Act the same way — “this doesn’t concern us, we don’t build AI" — and they are usually wrong. Regulation (EU) 2024/1689 does not regulate only AI developers; it also regulates companies that use AI, in their capacity as deployers: from the chatbot on your website to the CV screening tool, all the way to ChatGPT used internally by your marketing team. This guide summarises what already applies, what is coming, and what to do about it.
In short: if your company uses any AI tool, you already have two active obligations dating from February 2025 — not to use prohibited practices, and to ensure AI literacy among staff working with those systems. Everything else depends on what kind of AI you use.
The full timeline, after the Digital Omnibus
The regulation entered into force on 1 August 2024, with staggered application. In June 2026, the “Digital Omnibus on AI" regulation — adopted by the European Parliament on 16 June and by the Council on 29 June — moved the deadlines for high-risk systems. It was published as Regulation (EU) 2026/1744 in the Official Journal of 24 July 2026 and entered into force on 27 July. The resulting timeline:
| Deadline | What applies |
|---|---|
| 2 February 2025 in force | Prohibitions on unacceptable-risk practices (Art. 5) and the AI literacy obligation for staff (Art. 4) — for any organisation using AI systems |
| 2 August 2025 in force | Rules for general-purpose AI models (GPAI) — transparency and documentation obligations borne by model providers |
| 2 August 2026 | Transparency obligations (Art. 50): users must be informed when interacting with a chatbot, and AI-generated content must be marked |
| 2 December 2026 | Machine-readable marking of generated content, for systems already on the market before 2 August 2026 (Art. 50(2)); the new prohibition inserted by the Omnibus into Art. 5 — AI systems creating non-consensual intimate images |
| 2 December 2027 postponed | Full obligations for high-risk systems under Annex III — recruitment, credit scoring, education, critical infrastructure, law enforcement |
| August 2028 postponed | AI embedded in products already covered by their own safety legislation (Annex I): medical devices, machinery, toys |
The correct reading of the postponement: the heaviest block moved, and only for companies that actually have high-risk systems. What was already mandatory did not shift by a single day. We covered the consequences of that confusion, in the context of public institutions, in “Who checks the AI the state buys?".
The four risk levels
The AI Act does not treat all systems alike. Risk classification determines your obligations — and it is the first thing to establish for every tool in the company.
| Risk level | Examples | What is required |
|---|---|---|
| Unacceptable | Social scoring, subliminal manipulation, exploiting vulnerabilities, certain biometric uses | Prohibited. To be removed immediately if present |
| High | CV screening, credit scoring, admission and examination in education, critical infrastructure | Risk management, data governance, technical documentation, human oversight, logging, registration in the EU database |
| Limited | Chatbots, image and text generators, emotion recognition systems | Transparency: informing the user and marking generated content |
| Minimal | Spam filters, product recommendations, AI in games | No specific obligations beyond AI literacy |
In ordinary companies, recruitment is by far the most common high-risk case. If you use a tool that automatically filters, scores or ranks candidates, you are in Annex III — even if a human makes the final decision.
What this means in practice: five compliance steps
For a company that uses AI without developing it, the minimum compliance programme looks like this:
- An inventory of AI systems — which tools the company uses, who uses them, for which decisions and with what data. Include tools adopted informally by teams without IT approval: in practice these are the largest source of unknown risk.
- Risk classification — assign a level to every system in the inventory. Anything falling under prohibited practices goes now; anything high-risk enters the plan for December 2027.
- An internal usage policy — written rules for employees: what data may and may not be entered into AI tools, who checks outputs before they are used, which decisions are never automated.
- Team training — this covers the AI literacy obligation in Art. 4, already in force. It must be documented: who attended, when, and what was covered.
- Transparency towards users — by August 2026, chatbots and AI-generated content must be marked appropriately across all of the company’s public channels.
For companies wanting something more solid than a set of ad-hoc policies, ISO/IEC 42001 provides the management framework that AI Act obligations largely rest on — particularly useful if you already hold ISO 27001 and can extend the existing system.
Penalties
Fines reach up to EUR 35 million or 7% of total worldwide annual turnover for prohibited practices, and up to EUR 15 million or 3% for breaching other obligations — whichever is higher. For SMEs and start-ups the rule is inverted: the lower cap applies, precisely so the penalty stays proportionate.
In Romania, the authorities were proposed by a government memorandum in March 2026 — the verb used in the document is "we propose", not "we designate": ANCOM as market surveillance authority and single point of contact, ASF and BNR for the financial sector, ANSPDCP for sensitive domains, and ADR as notifying authority. The memorandum acknowledges, in its own words, that Romania did not notify the Commission by the 2 August 2025 deadline.
The consequence is stated by the proposed authority itself. In its statement of 24 July 2026, ANCOM notes that the competent authorities "will be able to verify and sanction non-compliance with the Regulation only after the entry into force of the national act currently being drafted".
That does not mean the obligations can be ignored: the regulation applies directly, the deadlines run, and the national law, once in force, will not retroactively excuse the preceding period.
Why it pays to start now
Because the expensive part is not documentation — it is replacing tools. A company that discovers in 2027 that its recruitment platform cannot supply the technical documentation Annex III requires must choose between a crisis migration and knowing non-compliance. The same company, asking the question at procurement time, solves it with a contract clause.
The inventory and classification — steps 1 and 2 — are done once and answer almost every question that follows. They are also the only ones that cannot be fully outsourced: no one outside your organisation knows which tools your teams actually use.
How we can help
Speed Flow provides AI governance consulting: system inventory and classification, usage policies, team training and preparation for the AI Act deadlines. If you want to start with a clear picture of where you stand, the AI diagnostic is the natural entry point.