The EU AI Act is phasing in. High-risk obligations land in August 2026
The first comprehensive AI law anywhere regulates by risk tier — from outright prohibitions already in force to detailed conformity requirements for high-risk systems. The compliance clock is running whether you build AI or merely deploy it.
- In force
- 1 August 2024, phased to 2027
- Prohibitions apply
- Since 2 February 2025
- High-risk duties
- From 2 August 2026
- Maximum fines
- €35m or 7% of global turnover
The highlights
The Act sorts AI systems into four tiers, and your obligations follow the tier — plus a separate regime for general-purpose AI models.
Prohibited practicesTier 1
Social scoring, exploitative manipulation, untargeted facial-image scraping and most real-time remote biometric identification are banned outright — and these prohibitions have applied since February 2025.
High-risk systemsTier 2
AI in recruitment, credit scoring, education, critical infrastructure, medical devices and law enforcement faces the full regime: risk management, data governance, technical documentation, human oversight, logging and conformity assessment.
Transparency dutiesTier 3
Chatbots must disclose they are AI, synthetic media must be labelled, and deployers of emotion recognition must inform the people exposed to it.
General-purpose AIGPAI
Model providers owe technical documentation, copyright policies and training-data summaries since August 2025 — with systemic-risk models facing evaluations, incident reporting and cyber security duties on top.
Deployers are regulated tooArt. 26
This is the part most organisations miss: using a high-risk AI system brings its own duties — human oversight, input data quality, monitoring, log retention and staff AI literacy. Buying the AI in does not contract the obligation out.
Where to start
- Inventory your AI — you cannot classify what you have not catalogued. Include embedded AI in procured SaaS — it counts.
- Classify against the tiers — determine your role (provider, deployer, importer, distributor) and tier per system. Most obligations hang off that pairing.
- Stand up AI literacy now — Article 4's AI literacy requirement already applies to everyone using AI in a professional context.
- Anchor it in a management system — ISO 42001 gives the Act's risk management and governance requirements an auditable operational home.
Building with AI, buying AI, or being sold it?
Sentinel42 delivers AI system inventories, EU AI Act applicability assessments and ISO 42001-aligned governance frameworks that turn the Act's obligations into an operating rhythm.