EU AI Act News 2026: Key Updates, Compliance Deadlines, and What Businesses Must Do Now

By Legiseye Team


EU AI Act News 2026: Key Updates, Compliance Deadlines, and What Businesses Must Do Now

EU AI Act News 2026: Key Updates, Compliance Deadlines, and What Businesses Must Do Now

What Is the EU AI Act?

The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive horizontal legislation governing artificial intelligence. Adopted by the European Parliament in March 2024 and published in the Official Journal of the EU on 12 July 2024, it applies to any organization that develops, deploys, or uses AI systems affecting people located in the EU β€” regardless of where the developer is based.

The Act classifies AI systems into four risk categories: unacceptable risk (banned outright), high risk (strict compliance obligations), limited risk (transparency requirements), and minimal risk (voluntary codes of conduct).

What Does the EU AI Act Regulate?

The EU AI Act regulates AI systems across their entire lifecycle β€” from design and development through deployment and monitoring. Key areas covered:

  • Prohibited AI practices β€” social scoring by governments, real-time remote biometric identification in public spaces (with narrow exceptions), AI that exploits psychological vulnerabilities, and systems that infer political opinions, religious beliefs, or sexual orientation
  • High-risk AI systems β€” AI used in critical infrastructure, education, employment, essential public services, law enforcement, migration, and administration of justice
  • General-Purpose AI (GPAI) models β€” Large language models and foundation models (like GPT-4, Claude, or Gemini) face specific transparency and safety evaluation requirements
  • Transparency obligations β€” Users must be informed when they are interacting with AI or AI-generated content
  • Conformity assessments β€” High-risk AI systems require third-party audits or self-assessments before market placement

EU AI Act Timeline: When Does It Apply?

The regulation follows a phased rollout:

Date Requirement
2 February 2025 Prohibited AI practices ban enters force. All unacceptable-risk AI must be shut down.
2 August 2025 GPAI model rules apply. Providers of large AI models (>10^25 FLOPs training threshold) must register and submit safety reports.
2 August 2026 Core high-risk AI obligations apply. Conformity assessments, technical documentation, human oversight, and EU database registration required.
2 August 2027 High-risk AI embedded in existing regulated products (medical devices, machinery) must comply.

Companies operating in the EU should already be in compliance preparation mode for August 2026.

Key Changes and Updates in 2026

GPAI Codes of Practice Finalized

The AI Office (the EU body enforcing the Act) published final Codes of Practice for General-Purpose AI models in early 2026. These codes define how GPAI providers must:

  • Conduct systematic risk evaluations
  • Document training data provenance
  • Implement copyright compliance measures
  • Report serious incidents within 72 hours

Providers of GPAI models with "systemic risk" designation (the most powerful models) face additional requirements including adversarial testing (red-teaming) before release.

High-Risk AI Registration Database Live

The EU has launched its public database for high-risk AI systems. Operators deploying high-risk AI must register their systems with the relevant national market surveillance authority. Registration requires:

  • A description of the AI system and its intended purpose
  • Details of the conformity assessment performed
  • Contact information for the responsible operator
  • Declaration of conformity

SME Exemptions and Support

Small and medium enterprises (annual turnover below €50M, fewer than 250 employees) benefit from:

  • Simplified conformity assessment procedures for some high-risk AI categories
  • Access to regulatory sandboxes run by national authorities
  • Reduced documentation requirements for low-volume deployments
  • Priority access to the AI Office's helpdesk

Does the EU AI Act Apply to SMBs?

Yes, but with proportionality measures. The EU AI Act applies to any organization placing AI systems on the EU market or deploying AI to users in the EU. SMBs are not exempt. However, the obligations scale with risk:

  • Minimal-risk AI (spam filters, AI in video games, recommendation systems not in high-risk categories): No mandatory requirements. Voluntary adherence to codes of conduct is encouraged.
  • Limited-risk AI (chatbots, deepfake generators): Must notify users they are interacting with AI. Minimal compliance burden.
  • High-risk AI: Full compliance required regardless of company size β€” though SMBs get simplified assessment procedures and regulatory sandbox access.

A small HR software company using AI to screen CVs for EU-based employers falls into the high-risk category under the employment provisions. It must run a conformity assessment, maintain documentation, implement human oversight, and register its system. There is no SMB carve-out for high-risk AI.

Compliance Requirements: What High-Risk AI Systems Must Have

Organizations deploying or developing high-risk AI systems must implement all of the following before August 2026:

1. Risk Management System A continuous process identifying, evaluating, and mitigating risks throughout the AI system's lifecycle. Must be documented and updated at each significant change.

2. Data Governance Training, validation, and testing datasets must meet quality criteria: relevance, representativeness, and freedom from errors. Practices for data collection, preparation, and processing must be documented.

3. Technical Documentation A comprehensive technical file covering: system architecture, training methodology, performance metrics, risk assessment results, and known limitations. Must be available to national authorities on request.

4. Logging and Record-Keeping Automatic logging of system operations with sufficient granularity to enable post-market surveillance and incident investigation. Logs must be retained for a minimum period (varies by system type, minimum 6 months).

5. Transparency and User Information Operators must provide users with clear information about the system's capabilities and limitations, the role of human oversight, and how to interpret outputs.

6. Human Oversight High-risk AI systems must be designed to allow effective human oversight. Humans must be able to understand, monitor, and intervene in system operations. Fully autonomous high-risk AI decisions are generally not permitted.

7. Accuracy, Robustness, and Cybersecurity Systems must meet minimum accuracy thresholds declared in technical documentation, be resilient to adversarial manipulation, and implement cybersecurity measures appropriate to the risk level.

EU AI Act Fines and Enforcement

Non-compliance carries severe financial penalties:

Violation Type Maximum Fine
Prohibited AI practices €35 million or 7% of global annual turnover (whichever is higher)
High-risk AI non-compliance €15 million or 3% of global annual turnover
Providing false information to authorities €7.5 million or 1.5% of global annual turnover

For SMBs, fines are capped at the lower percentage tier. National market surveillance authorities handle enforcement, with the AI Office coordinating cross-border cases involving GPAI models.

First enforcement actions are expected in late 2025 and 2026 for prohibited AI practices violations (the earliest provisions to enter force).

Action Items: EU AI Act Compliance Checklist

  • Inventory all AI systems used or deployed to EU users. Classify each by risk tier.
  • Identify high-risk AI according to Annex III of the Regulation (employment, education, essential services, law enforcement, etc.)
  • Appoint an AI compliance lead β€” either internal or external counsel with EU AI Act expertise
  • Conduct a gap analysis against the technical requirements for each high-risk system
  • Build technical documentation for all high-risk AI systems before August 2026
  • Implement a risk management system with documented review cycles
  • Register high-risk AI systems in the EU database when it opens to your category
  • Review vendor contracts β€” if you use third-party AI, your vendor's non-compliance creates your liability
  • Monitor GPAI Codes of Practice β€” if you use frontier AI models, understand your operator obligations
  • Establish an incident reporting procedure β€” serious incidents must be reported to national authorities

Frequently Asked Questions

Q: When did the EU AI Act come into force? The EU AI Act entered into force on 1 August 2024. The prohibition on unacceptable-risk AI applied from 2 February 2025. High-risk AI system obligations apply from 2 August 2026.

Q: Does the EU AI Act apply to US and UK companies? Yes. The EU AI Act has extraterritorial reach. Any company whose AI systems are used by people in the EU, or whose AI outputs are used in the EU, must comply β€” regardless of where the company is headquartered.

Q: What AI systems are completely banned under the EU AI Act? Banned systems include: AI social scoring by public authorities, real-time remote biometric identification in public spaces for law enforcement (with narrow security exceptions), AI that exploits vulnerabilities of children or elderly, systems that manipulate behavior through subliminal techniques, and AI inferring political opinions or sexual orientation from biometric data.

Q: How does the EU AI Act differ from GDPR? GDPR governs the processing of personal data. The EU AI Act governs AI systems regardless of whether they process personal data. The two regulations overlap β€” many high-risk AI systems also trigger GDPR obligations β€” but they operate independently. Non-compliance with one does not imply non-compliance with the other.

Q: Are AI tools like ChatGPT or Copilot regulated? OpenAI, Microsoft, Google, and Anthropic are subject to the GPAI model provisions as "providers." Businesses using these tools as "operators" have their own obligations depending on how they deploy them (e.g., integrating into high-risk workflows triggers high-risk requirements for the operator).

Q: What is the EU AI Act compliance deadline for 2026? 2 August 2026 is the primary compliance deadline for most high-risk AI system obligations. Organizations should complete gap assessments by Q1 2026 and have full technical documentation and risk management systems in place by Q2 2026, leaving buffer time for any remediation.

Q: Where can I access the full text of the EU AI Act? The full text is available on EUR-Lex: Regulation (EU) 2024/1689. The AI Office's guidance documents are published at digital-strategy.ec.europa.eu.

Related Legislation on Legiseye

Legiseye tracks EU AI Act developments in real time alongside related regulations:

  • EU Data Act β€” governs data access and sharing, overlaps with AI training data requirements
  • EU Digital Services Act β€” algorithmic transparency obligations for large platforms
  • EU Digital Markets Act β€” gatekeeper AI system obligations
  • GDPR β€” data protection requirements for AI processing personal data

Monitor all related EU legislation at legiseye.com.


Sources:

Last Updated: 2026-04-06 Author: Legiseye Legal Intelligence Team

Know What to Do, Not Just What Changed

Every regulation, the moment it drops. AI extracts your obligations so your team knows what to do β€” not just what changed.

Try Legiseye Free