EU AI Act – visual: weathered balance scale with an AI chip symbol on one pan, resting in damp moss
AI Law · EU AI Act

EU AI Act: What the New AI Regulation Means for Your Business

Sennefer Consulting e.U. – Ing. Karl Mustafa

A Risk-Based Law With Staggered Deadlines

Since 1 August 2024, Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence has been in force – the "AI Act". However, it doesn't apply all at once; instead, it follows a staggered timeline. Since 2 August 2026, the bulk of the regulation therefore applies, most notably the transparency obligations for AI systems. At the same time, the recently adopted "Digital Omnibus on AI" has shifted a number of deadlines.

The AI Act doesn't regulate AI as such, though. Instead, it follows a risk-based approach: the higher the risk an application poses to health, safety or fundamental rights, the stricter the requirements become. Unacceptable practices such as social scoring or manipulative techniques are therefore banned outright. High-risk applications – for example in recruitment, credit scoring or critical infrastructure – are subject to strict obligations instead. Most everyday AI applications, by contrast, remain largely unregulated or face only transparency duties.

Concretely, chatbots must be identifiable as AI systems since 2 August 2026. Likewise, AI-generated or manipulated images, video and audio content – including deepfakes – must carry a label. AI-generated text on matters of public interest must also be disclosed, unless subject to editorial control. Prohibited practices and the obligation to support staff AI literacy have already applied since February 2025. Obligations for providers of general-purpose AI (GPAI) models and the penalty provisions, meanwhile, have applied since August 2025.

Who Is Covered – And What the Digital Omnibus Changed

Its scope is deliberately broad. It covers providers, who develop and place an AI system on the market. It also covers deployers, who use an AI system professionally – the most common role – as well as importers, distributors, authorised representatives and product manufacturers. Where a company is established makes no difference here. Providers and deployers outside the EU are covered as well, if the output of their AI system is used in the Union. Exempted, however, are purely personal use, military and defence purposes, research prior to market placement, and, with conditions, open-source AI systems.

Regulation (EU) 2026/1744, which entered into force on 27 July 2026, significantly postponed the deadlines for high-risk AI systems. Applications under Annex III – including education, HR and creditworthiness assessment – now only need to be compliant from 2 December 2027. Originally, the deadline was 2 August 2026, so this amounts to a 16-month deferral. For AI embedded in already-regulated products under Annex I, the new date is 2 August 2028. The Digital Omnibus doesn't remove any already-applicable obligations, though. It does, however, make targeted substantive changes. The AI literacy duty was softened from a duty of result to a duty of best efforts. And from 2 December 2026, a new prohibition also applies to AI systems that generate non-consensual intimate content or child sexual abuse material.

For organisations already running a certified management system – under ISO 14001 or ISO/IEC 27001, say – structured risk and document management is nothing new. Our posts on the EmpCo Directive, the PPWR, the new ISO 19011:2026, the Microplastics Regulation (REACH) and the PFAS ban in firefighting foam likewise show just how many regulatory changes 2026 has brought.

Five EU AI Act Takeaways From Our Advisory Practice

Binding Obligations – Legal Compliance

Staggered Deadlines Since 2024

The AI Act doesn't apply all at once, but in stages. Prohibited practices and AI literacy apply since February 2025, GPAI obligations and penalties since August 2025. The bulk of the regulation, including transparency duties, has applied since 2 August 2026. These dates now belong in your legal register.

Role Clarification – Risk Management

Provider, Deployer & Co.

Whether your company qualifies as a provider, deployer, importer, distributor or authorised representative determines its concrete obligations. A company can hold several roles at once.

Transparency Duties – Document Management

Art. 50 AI Act

Since 2 August 2026, chatbots must identify themselves as AI. AI-generated images, videos and deepfakes must be labelled, and AI-generated text on matters of public interest must be disclosed. How that labelling is evidenced belongs in a structured management system.

Prohibited Practices & High-Risk Deadlines – Risk Management

Art. 5, Annex III

Social scoring and manipulative practices have been banned since February 2025. For high-risk applications under Annex III – recruitment or credit scoring, for instance – the Digital Omnibus pushed the deadline back 16 months to 2 December 2027. Reason enough to prepare your risk classification now, rather than deferring it again.

Competence Management

Art. 4 – Now a Best-Efforts Duty

The obligation to support your staff's AI literacy has applied since February 2025. The Digital Omnibus softened it from a duty of result to a duty of best efforts. That changes little for training records, though: they still belong in competence management.

Deadline 2 August 2026 – but deadlines keep moving: Since that date, the bulk of the AI Act applies, most notably the transparency obligations. The Digital Omnibus (Regulation (EU) 2026/1744, in force since 27 July 2026) also postponed the deadlines for high-risk systems. The new dates: December 2027 and August 2028, respectively. Prohibited practices, transparency and GPAI obligations remain unaffected regardless, even though individual provisions were changed on purpose.

Enforcement in Austria and Why a Management System Pays Off

Austria has not yet designated the national market surveillance authority required under the AI Act, according to the RTR AI Service Centre. The EU deadline of 2 August 2025 has therefore been significantly missed. Germany is further ahead: its AI Implementation Act (KI-MIG) has designated the Bundesnetzagentur as the central authority since June 2026. Regardless of national enforcement status, though, the GDPR remains fully applicable (Art. 2(7) AI Act). This matters in particular for the data protection impact assessment under Art. 35 GDPR. It merely supplements any required fundamental rights impact assessment under Art. 27 AI Act, rather than duplicating it.

The AI Act's extensive evidence, documentation and monitoring obligations are best captured through a structured management system. ISO/IEC 42001, created specifically for AI, provides a ready-made framework for this. Existing quality (ISO 9001) or information security management systems (ISO/IEC 27001) can likewise be extended to cover AI-specific risks, rather than starting from scratch.

Want to know which role your company holds under the AI Act and which obligations specifically apply? Get in touch – we'll help you classify your systems and embed the requirements in your management system.

This article was created with AI assistance.

Leave a Reply

Your email address will not be published. Required fields are marked *