AI11 min read8 June 2026

The EU AI Act: Everything You Need to Know (And Why It Matters More Than You Think)

There is a piece of legislation working its way through the European Union that will reshape how every organisation on the planet builds, deploys, and sells...

There is a piece of legislation working its way through the European Union that will reshape how every organisation on the planet builds, deploys, and sells artificial intelligence. It is called the EU AI Act, and if you are reading this from anywhere outside the EU, do not make the mistake of thinking it does not apply to you. It does. Extraterritorially. With teeth.

The AI Act entered into force on 1 August 2024. Since then, it has been rolling out in stages, with different obligations kicking in at different points. Some provisions are already live. Others land in August 2026. And a recent legislative intervention in May 2026, the so-called “Digital Omnibus,” has pushed several critical deadlines further out, giving businesses more breathing room but also more uncertainty about what is coming and when.

This article is a comprehensive walkthrough: what the Act is, how it works, what it bans, what it demands, who it affects, and what you should be doing about it right now.

The Big Idea: Risk-Based Regulation

The fundamental principle behind the EU AI Act is deceptively simple: not all AI systems pose the same level of risk, so they should not all be treated the same way. The Act establishes a four-tier risk classification system, and your obligations depend entirely on which tier your AI system falls into.

This is, at its core, a regulatory application of something behavioural scientists have understood for decades. When people face complex decisions, they use heuristics, mental shortcuts that compress information into manageable categories. The EU has essentially built a regulatory heuristic: instead of assessing every AI system individually (which would be administratively impossible), it sorts them into buckets and applies graduated obligations to each one.

Whether you think this is a sensible approach or an exercise in bureaucratic overreach, the framework is now law. Here is how it works.

The Four Risk Tiers

1. Unacceptable Risk (Banned)

These are AI practices the EU considers fundamentally incompatible with human dignity and fundamental rights. They are prohibited outright, with no exceptions (or only very narrow ones for law enforcement under strict judicial oversight).

The banned list includes:

These prohibitions have been in force since 2 February 2025. If you are building any of these systems, you are already non-compliant.

A new prohibition, added by the May 2026 Digital Omnibus, bans AI systems that generate non-consensual intimate imagery (so-called “nudifiers”) and child sexual abuse material. This takes effect on 2 December 2026.

2. High-Risk AI Systems

This is where the bulk of the regulatory burden falls. High-risk AI is permitted but heavily regulated. These are systems used in contexts where errors or biases could have serious consequences for people’s lives, livelihoods, or fundamental rights.

High-risk systems are identified in two ways:

Annex III (Use-Based): AI systems deployed in specific high-stakes domains:

Annex I (Product-Based): AI systems that are safety components of products already covered by existing EU harmonisation legislation, such as medical devices, machinery, toys, vehicles, and lifts.

The obligations for high-risk AI systems are substantial:

For deployers (the organisations using these systems, not building them), the obligations include ensuring staff AI literacy, maintaining use logs, conducting Fundamental Rights Impact Assessments (FRIAs) where applicable, and monitoring the system’s performance in practice.

3. Limited Risk

These systems face transparency obligations. The key requirement under Article 50 is straightforward: users must know when they are interacting with AI.

This includes:

These transparency obligations take effect on 2 August 2026. For generative AI systems already on the market before that date, the machine-readable watermarking requirement has been extended to 2 December 2026 by the Digital Omnibus. For systems placed on the market after 2 August 2026, compliance is immediate.

4. Minimal or No Risk

The vast majority of AI systems fall here. Spam filters, AI in video games, recommendation engines in most consumer contexts. No specific obligations under the Act.

General-Purpose AI Models (GPAI)

The Act has a separate regime for general-purpose AI models, the foundation models that power tools like ChatGPT, Gemini, Claude, and similar systems.

GPAI obligations, which have been in force since 2 August 2025, include:

For GPAI models that pose systemic risk, defined as models trained using substantial computing power (currently set at more than 10^25 FLOPs), additional obligations apply:

The Digital Omnibus: What Changed in May 2026

On 7 May 2026, EU legislators reached a provisional agreement on a “Digital Omnibus” that makes targeted amendments to the AI Act. The headline change: several critical deadlines have been pushed back.

What moved:

What did not move:

Other changes:

The Omnibus is expected to be formally adopted and published in the Official Journal before 2 August 2026.

Extraterritorial Scope: Yes, This Applies to You

If you are based outside the EU but your AI systems’ outputs are used within the EU, the Act applies to you. This is the same logic the EU applied with GDPR, and it has proven remarkably effective at setting global standards.

For anyone building AI products, serving EU customers, or deploying AI systems that affect people in the EU, the territorial reach is clear. The EU is, once again, exporting its regulatory preferences to the rest of the world.

Penalties

The enforcement mechanism is not subtle:

For small and mid-cap companies, the fines are capped at the lower of the two figures (the absolute amount or the percentage).

These are not theoretical numbers. The EU has demonstrated with GDPR that it is willing to enforce significant penalties, and the AI Act gives regulators even sharper tools.

What You Should Be Doing Now

The staged timeline means different things for different organisations. Here is a practical breakdown:

Already in force (since February 2025):

Already in force (since August 2025):

Due August 2026:

Due December 2027 (postponed from August 2026):

Due August 2028:

Practical steps right now:

  1. Audit your AI inventory. Catalogue every AI system your organisation builds, deploys, or procures. Classify each one against the four risk tiers.

  2. Start with the prohibitions. If any of your systems fall into the banned category, the deadline has already passed. Act immediately.

  3. Build AI literacy. This is already an obligation. Ensure your teams understand the systems they are working with and the regulatory framework that governs them.

  4. Prepare for transparency requirements. August 2026 is close. If you are running chatbots, generating AI content, or using deepfake technology, your disclosure and labelling systems need to be in place.

  5. Begin high-risk compliance work now. Even though the deadline has been pushed to December 2027, the requirements are substantial. Risk management systems, data governance frameworks, technical documentation, conformity assessments, and post-market monitoring all take significant time to build properly. Starting now is not premature. It is prudent.

  6. Assess your supply chain. If you are a deployer of high-risk AI (using it, not building it), you need to understand your providers’ compliance status. Your obligations include verifying that the systems you use have undergone conformity assessments and are registered in the EU database.

  7. Watch for further guidance. The European Commission is expected to publish additional guidelines and a Code of Practice to assist with compliance. The regulatory sandboxes, once established, will also provide controlled environments for testing and validation.

The Bigger Picture

The EU AI Act is the most comprehensive attempt to regulate artificial intelligence in the world. It is not perfect. Critics argue it is too complex, too burdensome for smaller companies, and too slow to keep pace with the technology it purports to govern. Supporters argue it is a necessary framework for protecting fundamental rights in an era of rapidly advancing AI capabilities.

What is not in dispute is its influence. Just as GDPR became the de facto global standard for data privacy, the AI Act is likely to set the template for AI regulation worldwide. Countries and regions that lack their own comprehensive AI legislation will find themselves operating within the EU’s framework simply because their companies serve EU customers.

The question for every organisation is not whether the EU AI Act affects you. It is whether you will be ready when it does.


David Chadderton spent his twenties and thirties teaching people how to make life-or-death decisions at forty thousand feet. He now applies the same principles to consumer psychology, which, depending on the brief, can feel equally high-stakes. He’s the creator of the STAR Framework and the author of The STAR Framework: Rewriting the Rules of Consumer Engagement (NYC Big Book Award 2025), The STAR Operating System: Decode Mindset, Understand Motivation, Transform Human Behaviour, and Dear Algorithm, It’s Not Me, It’s You. By day, a Chief Marketing Officer. By night, a behavioural science obsessive who writes The Unoptimised Human because he can’t stop thinking about why people do what they do.

The STAR Framework

If you enjoyed this essay, you'll find the full argument — and the framework behind it — in the book.