Quick Answer
The EU AI Act 2026 is now fully enforceable. It classifies AI into four risk tiers from banned to lightly regulated. High-risk AI systems require CE marking, conformity assessment, EU database registration, and ongoing monitoring before they can legally enter the European market. Penalties reach €35 million or 7% of global annual turnover. The law applies to any company serving EU customers, regardless of headquarters.
What Is the EU AI Act 2026?
The EU AI Act is the world’s first comprehensive artificial intelligence law. It treats high-risk AI like medical devices products that must prove safety before reaching the market.
Passed in March 2024 and fully enforceable as of August 2, 2026, the EU AI Act 2026 creates a single rulebook for AI across all 27 EU member states. Unlike GDPR, this law governs the AI systems themselves, how they’re built, tested, and monitored.
“This is product safety law applied to software. If your AI is high-risk and doesn’t have a CE mark after August 2026, you cannot legally sell it in Europe.” — EU AI Act Guide, March 2026

Why It Matters Globally
The EU AI Act has extraterritorial reach. A SaaS company in San Francisco or a startup in Bangalore must comply if their AI affects people in the EU. The law cares where your AI is used, not where you’re headquartered.
The 4 Risk Tiers
| Tier | Status | Examples |
|---|---|---|
| Unacceptable | Banned | Social scoring, manipulative AI, real-time biometric ID in public |
| High | Strict rules | Medical AI, hiring tools, credit scoring, education AI, law enforcement |
| Limited | Transparency | Chatbots, deepfakes, emotion recognition |
| Minimal | Voluntary | Spam filters, inventory forecasting, basic recommendations |
Most companies worry about high-risk. Don’t ignore limited-risk those obligations are enforceable now.
Who Must Comply?
The EU AI Act 2026 applies to four roles in the AI value chain:
| Role | Who They Are | Key Obligations |
|---|---|---|
| Providers | Develop AI and place it on the market | Risk management, technical docs, conformity assessment, CE marking, EU database registration |
| Deployers | Use AI under their authority | Human oversight, monitor operation, report incidents, rights impact assessments |
| Importers | Bring non-EU AI into the EU | Verify provider compliance, ensure documentation is complete |
| Distributors | Distribute AI in the EU supply chain | Check conformity before distribution |
Most enterprises are deployers. If you use AI for hiring, credit decisions, or customer service, you have obligations — not just the developer.
High-Risk AI: 10 Requirements
Before CE marking, high-risk AI must satisfy all 10 requirements:
| # | Requirement |
|---|---|
| 1 | Risk Management System — continuous risk identification and mitigation |
| 2 | Data Governance — training data must be relevant, representative, and error-free |
| 3 | Technical Documentation — comprehensive compliance evidence (Annex IV) |
| 4 | Record-Keeping — automatic logging for post-deployment traceability |
| 5 | Transparency — clear instructions documenting capabilities and limitations |
| 6 | Human Oversight — humans must be able to review and override AI decisions |
| 7 | Accuracy & Robustness — performance metrics met; resilient to manipulation |
| 8 | Cybersecurity — protection against adversarial attacks and data poisoning |
| 9 | Quality Management — organizational system covering full development lifecycle |
| 10 | Conformity Assessment — self-assessment (most) or Notified Body (biometric/safety-critical) |
The hard truth: Most harmonized standards aren’t published yet in 2026. You must interpret the Act’s requirements directly legal and technical advisory input is essential.
CE Marking: The Two Routes
No CE mark = no EU market access. Period.
Route 1: Internal Control (Annex VI) Most Companies
For most Annex III high-risk AI employment tools, educational AI, credit scoring, public service AI you self-certify. No third-party auditor required.
| Step | Timeline |
|---|---|
| Compile Annex IV technical documentation | 3–6 months |
| Implement quality management system | 2–4 months |
| Internal conformity assessment | 4–8 weeks |
| Draw up EU Declaration of Conformity | 1–2 weeks |
| Affix CE mark + EU database registration | 1 week |
| Total | ~4–8 months |
Route 2: Third-Party Assessment (Annex VII) Biometric & Safety-Critical
Mandatory for:
- AI for real-time or post-hoc remote biometric identification
- AI that is a safety component of regulated products (medical devices, machinery, vehicles)
Table
| Step | Timeline |
|---|---|
| Engage Notified Body | 4–8 weeks |
| Prepare Annex IV documentation | 3–6 months |
| Notified Body assessment | 2–4 months |
| Respond to queries and revisions | 4–8 weeks |
| Total | ~9–14 months |
Critical warning: Notified Bodies have limited capacity and long lead times in 2026. If you need Route 2 and haven’t started, you’re behind schedule.

Penalties
| Violation Type | Fine |
|---|---|
| Prohibited AI practices | Up to €35M or 7% of global turnover |
| High-risk non-compliance | Up to €15M or 3% of global turnover |
| Incorrect info to authorities | Up to €7.5M or 1% of global turnover |
| Transparency failures | Up to €15M or 3% of global turnover |
National authorities enforce the law, can force product withdrawal, issue fines, and in some states hold directors personally liable.
Compliance Timeline
| Deadline | What Became Enforceable |
|---|---|
| February 2, 2025 | Prohibited AI practices banned |
| August 2, 2025 | GPAI model obligations active |
| August 2, 2026 | High-risk AI full enforcement + limited-risk transparency |
| August 2, 2027 | High-risk systems already on market must comply |
Where we are now: If your high-risk AI isn’t CE marked, you have days, not months until August 2, 2026.
What Deployers Must Do
If you use high-risk AI, you have obligations too:
- Use AI according to provider instructions
- Ensure human oversight is in place
- Monitor the system during operation
- Report serious incidents to authorities
- Conduct fundamental rights impact assessments (certain public-facing uses)
- Maintain records of AI decisions, especially adverse ones
“If you customize prompts, connect proprietary data, or change default behavior, regulators will look at your governance, not only the upstream model card.” — AgentWorks AI Compliance
FAQs
What is the EU AI Act 2026?
The world’s first major AI law, fully enforceable in the EU from August 2, 2026. It regulates AI based on risk levels and applies to any company serving the EU.
Who does the EU AI Act apply to?
It applies to:
Distributors
Providers (developers placing AI on the market)
Deployers (organizations using AI)
Importers
What is high-risk AI under the EU AI Act?
High-risk AI includes systems used in healthcare, hiring, credit scoring, education, law enforcement, critical infrastructure, and biometric identification.
These require CE marking, risk management, human oversight, and technical documentation.
What is CE marking for AI?
CE marking is mandatory for high-risk AI under the EU AI Act. Most systems can self-certify, but biometric AI and certain safety components require third-party assessment by a Notified Body. It must be affixed before placing the AI on the EU market.
What are the penalties?
€35 million or 7% of global annual turnover for prohibited AI
€15 million or 3% for high-risk non-compliance
€7.5 million or 1% for supplying incorrect information
National authorities can also force product withdrawal.
Does the EU AI Act apply to non-EU companies?
Yes. The EU AI Act has extraterritorial reach. Any company worldwide must comply if it places AI on the EU market or if its AI outputs are used in the EU.
What is the difference between a provider and a deployer?
Providers (developers): Bear the heaviest obligations risk management, conformity assessment, CE marking, documentation, and database registration.
Deployers (users): Must ensure human oversight, monitoring, incident reporting, and impact assessments.
Most companies using AI are deployers.
When is the EU AI Act fully enforceable?
Prohibited AI: Banned since February 2025
General-purpose AI (GPAI): Obligations since August 2025
High-risk AI: Full enforcement from August 2, 2026
Existing high-risk systems: Must comply by August 2027
Do I need a Notified Body?
Most high-risk AI can self-assess. Only two categories require a Notified Body:
- Remote biometric identification systems
- AI as a safety component of regulated products (medical devices, machinery, vehicles)
Assessments typically cost €15,000–€50,000 and take 2–4 months.
What should companies do right now?
Start with an AI inventory and risk classification. Then:
- Stop any prohibited AI uses
- Implement risk management, data governance, human oversight, and documentation for high-risk systems
- Prepare for CE marking and EU database registration
High-risk compliance usually takes 12–18 months start immediately.
Related Resources
AI Regulation 2026: Complete Guide to Global Laws, Compliance & Policy
Illinois AI Accountability Act (SB 315): What Companies Must Do
