If you build or sell software with AI features to customers in the European Union, the AI Act is no longer a future concern. Some obligations have applied since 2025, the transparency rules started on August 2, 2026, and the deadlines for high-risk systems were moved — but not cancelled — by the Digital Omnibus adopted in summer 2026. This guide explains, in plain language, which rules apply to typical software products such as chatbots, AI agents and document automation, what the new timeline looks like and what to do this quarter.
This article is general information, not legal advice. For a specific product, involve counsel familiar with the AI Act.
The AI Act in one paragraph
The AI Act, Regulation (EU) 2024/1689, is the EU's horizontal law for artificial intelligence. It entered into force on August 1, 2024 and regulates AI by risk: a few practices are banned, high-risk systems face strict requirements, systems that interact with people carry transparency duties, and everything else is largely unregulated (European Commission: AI Act). Like the GDPR, it applies to companies outside the EU when their AI systems are placed on the EU market or their output is used in the EU, which matters for Ukrainian and other non-EU vendors serving European clients.
The timeline after the Digital Omnibus
In 2026 the EU adopted the Digital Omnibus on AI, which entered into force on July 27, 2026 and postponed the high-risk deadlines while leaving most other dates intact (Gibson Dunn summary).
| Date | What applies |
|---|---|
| February 2, 2025 | Prohibited practices (Article 5) and the AI literacy duty (Article 4) |
| August 2, 2025 | Obligations for general-purpose AI model providers, governance and penalties |
| August 2, 2026 | Transparency obligations (Article 50) and most remaining provisions |
| December 2, 2026 | End of grace period for marking AI-generated content in systems already on the market |
| December 2, 2027 | High-risk systems listed in Annex III (employment, credit, education, biometrics, critical infrastructure and others) |
| August 2, 2028 | High-risk AI embedded in products covered by EU product safety law (Annex I) |
The practical takeaway: transparency is live now, and high-risk compliance has roughly a year and a half of extra runway, not an exemption.
Which risk category is your product?
Prohibited practices
Article 5 bans, among others, manipulative techniques that cause significant harm, exploiting vulnerabilities of specific groups, social scoring, emotion recognition in workplaces and schools (with narrow exceptions) and untargeted scraping of facial images (Article 5). Typical B2B software is nowhere near these, but check features like "employee sentiment monitoring" carefully.
High-risk systems
Annex III lists use cases that are high-risk regardless of the technology: AI used for recruitment and employee evaluation, creditworthiness scoring, access to education, essential public and private services, critical infrastructure, law enforcement, migration and justice (Annex III). If your product screens CVs, ranks job candidates or scores loan applicants, you are likely building a high-risk system and will need risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness measures, and a conformity assessment.
Limited risk: transparency duties
This is where most chatbots, AI agents and content tools land. Article 50 requires, in summary (Article 50):
- People must be informed that they are interacting with an AI system, unless it is obvious from the context.
- Synthetic audio, image, video and text generated by AI must be marked in a machine-readable way as artificially generated.
- Deployers of deepfakes must disclose that content was artificially generated or manipulated, and AI-generated text published to inform the public on matters of public interest must be disclosed unless it has undergone human editorial review.
Minimal risk
Spam filters, recommendation of internal documents, code completion and most internal automation carry no specific obligations beyond the AI literacy duty — though GDPR, consumer law and sector rules still apply.
Provider or deployer?
The Act assigns duties by role:
- Provider — develops an AI system or has it developed and places it on the market under its own name. A SaaS company shipping an AI assistant is a provider.
- Deployer — uses an AI system under its own authority in a professional context. Your client using that assistant for their customers is a deployer.
Many software companies are both: providers of their own product and deployers of third-party models inside it. Using a general-purpose model through an API does not make you a model provider, but if you build an AI system on top of it, you are the provider of that system.
What to do now: a practical checklist
- Build an AI inventory. List every feature that uses AI, which model it uses, who uses it and for what decisions.
- Classify each feature. Prohibited, high-risk (Annex III), transparency (Article 50) or minimal. Document the reasoning.
- Implement Article 50 disclosures. Tell users when they talk to an AI, and mark generated media. In customer support this is also good practice for trust, as we discuss in AI support agents: where they work and where they don't.
- Run AI literacy training. Staff who build, sell or operate AI features need a working understanding of capabilities, limits and risks. Keep a record.
- Update contracts. Define provider and deployer responsibilities with clients and model vendors, including incident reporting and information sharing.
- Prepare for high-risk early if it applies. Technical documentation, logging and human oversight take months to build properly. December 2027 is closer than it looks.
- Strengthen security and logging. Robustness and cybersecurity requirements overlap heavily with good agent security practice: least privilege, audit logs and protection against prompt injection, covered in AI agent security.
AI inventory entry (example)
Feature: Support assistant on customer portal
Model: Third-party LLM via API
Role: Provider (our product), client is deployer
Users: End customers of our clients (EU)
Decisions: Answers questions, drafts tickets; no automated refunds
Risk category: Limited risk — Article 50 disclosure
Controls: "You're chatting with an AI assistant" banner, human handoff,
logging 180 days, monthly quality review
Owner: Product lead, support platform
Penalties
Fines depend on the infringement: up to €35 million or 7% of worldwide annual turnover for prohibited practices, up to €15 million or 3% for most other obligations, and up to €7.5 million or 1% for supplying incorrect information to authorities, with lower caps for SMEs (Article 99).
How the AI Act fits with other EU rules
The AI Act does not replace the GDPR: personal data in prompts, logs and training sets still needs a lawful basis, minimization and data processing agreements. Products with digital elements also fall under the Cyber Resilience Act, whose vulnerability reporting duties started on September 11, 2026 (European Commission: CRA), and consumer-facing digital services may need to meet the European Accessibility Act, covered in Web accessibility in 2026.
FAQ
Does the AI Act apply to a company outside the EU? Yes, if you place AI systems on the EU market or their output is used in the EU.
Is a customer support chatbot high-risk? Usually not. It is typically limited risk with transparency duties, unless it makes decisions in Annex III areas such as access to essential services or credit.
We only call a third-party model API. Are we affected? Yes, as the provider or deployer of the AI system you build, even though the model provider carries the general-purpose model obligations.
Did the Digital Omnibus delay everything? No. It postponed the high-risk deadlines to December 2027 and August 2028, but prohibitions, AI literacy, general-purpose model rules and Article 50 transparency already apply.
Do we need to register our AI system somewhere? Providers of high-risk systems listed in Annex III must register them in an EU database before placing them on the market. Limited-risk systems such as chatbots have no registration duty, only transparency obligations.
Sources
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), EUR-Lex.
- European Commission. AI Act — regulatory framework for AI.
- AI Act text by article: Article 5, Article 50, Article 99, Annex III.
- Gibson Dunn (2026). EU AI Act Omnibus agreement — postponed high-risk deadlines and other key changes.
- European Commission. Cyber Resilience Act.