Contents
Join our newsletter
Cybersecurity tips, analyses and news delivered to your inbox every month! 
Learn more about our privacy policies.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
All articles
10
min
ISO 42001 and AI Governance

AI Act 2026: Understanding Risk Classification and Your Obligations

The European regulation on artificial intelligence is no longer a distant prospect. The AI Act has been in effect since August 1, 2024, and its implementation timeline has just been definitively clarified.

On July 27, 2026, Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, entered into force. It postpones the most stringent obligations—those concerning high-risk AI systems—from August 2, 2026, to December 2, 2027. This text is no longer a legislative proposal: it is now European law in force, published in the Official Journal of the European Union on July 24, 2026, following a political agreement between the Parliament and the Council reached in late June 2026.

Yet many organizations continue to view this legislation from a distance, convinced that it does not directly affect them. This is a mistake. The AI Act does not merely regulate technologies; it regulates actors, responsibilities, and roles within a value chain. And within this chain, virtually all companies that use, purchase, deploy, or distribute AI are affected.

Let’s break down what this regulation actually means in practice, beyond the simplified explanations.

A historic text, but one that is often misunderstood

The AI Act represents a world first: a comprehensive, structured regulatory framework that applies directly to all AI systems and stakeholders within the European Union. Its ambition goes far beyond technical compliance. The Act seeks to establish the conditions for a more robust, responsible, and sustainable development of AI.

But reducing the AI Act to a checklist of requirements would be a strategic mistake. It challenges us to rethink AI governance within the organization—a governance framework that, when well-designed, becomes a driver of performance and differentiation, not a hindrance.

The level of risk does not depend solely on the technology. It depends above all on how it is used.

Legal Definition: What Article 3 of the AI Act Says

Regulation (EU) 2024/1689 provides a precise definition of an AI system in Article 3:

"AI system": an automated system designed to operate at various levels of autonomy and capable of adapting after deployment, which, for explicit or implicit purposes, uses the inputs it receives to determine how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.

This deliberately broad definition explains why the text applies to a very wide range of tools: from a simple recommendation algorithm to an AI-assisted medical diagnostic system.

The official schedule, confirmed for July 27, 2026

Date Status What Applies
August 1, 2024 ✅ In effect Official Effective Date of the Regulation
February 2, 2025 ✅ In effect Prohibitions on Practices Involving Unacceptable Risk
August 2, 2025 ✅ In effect Obligations of GPAI Models + General Penalty System
August 2, 2026 ✅ In effect Transparency—Article 50 (chatbots, deepfakes, AI-generated content)
December 2, 2026 🔄 Coming Soon End of the transition period for content labeling + 2 new prohibitions (non-consensual nudification, AI-generated child pornography)
December 2, 2027 🔄 Coming Soon High Risk, Annex III: Recruitment, Credit, Education, Justice, Critical Infrastructure
August 2, 2028 🔄 Coming Soon High Risk Annex I: AI integrated into products already subject to regulation (medical devices, machinery, connected toys)

Two extension deadlines are often confused: the extension to December 2027 applies to standalone systems listed in Annex III (HR, credit, education), while the extension to August 2028 applies to AI systems integrated into products that are already regulated under other provisions (Annex I). These are not the same thing, nor do they follow the same timeline.

The 4 risk levels: an impact-based approach

The core of the framework is based on a classification of AI systems according to their potential risk to people’s safety, health, and fundamental rights.

AI Act - Decision Tree

🔴 Unacceptable risk: Total ban

These systems have been outright banned since February 2, 2025. They undermine the fundamental values of the European Union.

Examples include:

  • Social rating of individuals by government authorities
  • Exploitation of people’s vulnerabilities (age, disability, economic situation)
  • Behavioral or cognitive manipulation without the individuals' knowledge
  • Emotion recognition in professional or educational settings

Two additional bans will take effect on December 2, 2026, as introduced by the Digital Omnibus: AI systems that generate non-consensual intimate content and AI-generated child pornography.

🟠 High risk: Strict regulations now set for December 2, 2027

These systems are not inherently dangerous, but their potential impact on individuals places high demands on them. This is where most companies will need to take action, with a little more time than originally anticipated.

Examples include:

  • Recruitment tools or automated candidate assessment tools
  • Credit scoring algorithms or algorithms for access to financial services
  • Medical diagnostic support systems
  • Systems used in the justice system, law enforcement, or critical infrastructure
  • Student Assessment Tools in Education

Regulation (EU) 2026/1744 postpones these obligations from August 2, 2026, to December 2, 2027. This postponement is now final and has been published in the Official Journal: it is no longer a parliamentary proposal but applicable law.

However, the postponement does not exempt entities from all obligations: three obligations remain fully enforceable immediately, regardless of the risk level of the system in question:

  • Clearly inform the user that they are interacting with an AI (Article 50)
  • To comply with the sanctioning and supervisory powers of the competent authorities
  • Train staff in the critical use of AI (Article 4, AI literacy), under a more flexible version that took effect on July 27, 2026

The postponement to 2027 should not be interpreted as a pause. Four actions remain a priority as of now:

  • AI Literacy for Teams: Training employees who use or oversee AI systems—a requirement in effect since February 2025 and confirmed in a more flexible form in July 2026
  • Transparency Regarding Chatbots and Generated Content: Informing Users—A Requirement Fully Effective as of August 2, 2026
  • Mapping at-risk systems: Identify now which tools will be reclassified under Annex III (recruitment, scoring, education) before the December 2027 deadline
  • Documentation and Risk Register: Laying the Groundwork for Structured AI Governance Rather Than Waiting Until the Deadline

🟡 Specific risk related to transparency: Article 50, in effect since August 2, 2026

These systems are free to use, but must clearly inform users that they are interacting with an AI. This requirement has been fully in effect since August 2, 2026, with no extension.

Examples include:

  • Chatbots and virtual assistants
  • Deepfakes and synthetic content
  • Any AI-generated content intended for the public

Only technical content marking (watermarking, Article 50(2)) is subject to a transition period, which was reduced from six to three months by the Digital Omnibus: systems already on the market before August 2, 2026, must comply by December 2, 2026. The other transparency requirements under Article 50 (informing users that they are interacting with an AI) have been in effect since August 2, 2026.

🟢 Minimal risk: Safe to use

These systems are not subject to any specific requirements, but the voluntary adoption of best practices is strongly recommended.

Examples: spam filters, content recommendation systems, internal optimization AI that has no direct impact on individuals.

Would you like to develop your roadmap with expert guidance?

Get support with AI compliance →

The key distinction: AI systems vs. general-purpose AI (GPAI)

This is one of the most commonly misunderstood points, yet it is essential for determining your actual obligations.

An AI system is an operational application designed for a specific purpose: an automated recruitment tool, a scoring algorithm, or a diagnostic system. It is at the heart of the regulatory framework.

A general-purpose AI (GPAI) model, such as GPT or image-generation models, is a core technology that can be reused in multiple contexts. It is not limited to a single use. The requirements that have applied to such models since August 2025 primarily concern transparency, documentation, and compliance with copyright laws regarding training data.

What this means for you: If your company uses a GPAI model to build an internal or commercial AI system, you are subject to both the obligations related to the model AND those related to the system. The two sets of requirements apply cumulatively.

Your position in the value chain determines your obligations

The AI Act does not treat all stakeholders the same. It identifies five roles, each carrying a different level of responsibility.

Role Definition Level of obligation
Supplier Develops an AI system or brings it to market The highest
Deployer Uses an AI system in its operations High (high risk)
Distributor Makes a system available without being a developer Moderate
Agent Represents a non-European supplier in the EU Moderate
Importer Introduces a third-party AI system to the European market Moderate

One point that is often overlooked: a single company can fulfill multiple roles simultaneously, depending on the systems it uses or sells. A B2B SaaS company that integrates AI into its product acts both as a provider to its customers and as a deployer for its internal use. This dual role creates cumulative obligations.

It is precisely at this stage that a structured governance framework, based on standards such as ISO 42001, helps clarify who is responsible for what under each system used.

The Penalty Schedule: Three Levels You Need to Know

The penalties for noncompliance are graded according to the severity of the violation:

Type of violation Maximum penalty
Prohibited Practices (Unacceptable Risk) 35 million euros, or 7% of annual global revenue
High-Risk Breaches of Obligations (Transparency, Documentation, Governance) 15 million euros, or 3% of annual global revenue
Incorrect or incomplete information provided to the authorities 7.5 million euros, or 1.5% of annual global revenue

This schedule has been in effect since August 2, 2025, regardless of the postponement of high-risk bonds to 2027.

Why AI governance is an advantage, not a constraint

It would be simplistic to view the AI Act solely as a regulatory burden. Organizations that prepare for this transformation reap tangible benefits:

  • Defining Responsibilities: Who Decides, Who Approves, and Who Is Accountable for the Use ofAI‍
  • Risk Prioritization: Not all AI systems are created equal; governance allows us to focus our efforts where the impact isgreatest‍
  • Stakeholder trust: Customers, partners, investors, and regulators are placing increasing trust in organizations that demonstrate mastery of theirAI‍
  • Access to new markets: Public tenders and demanding B2B contracts are increasingly incorporatingAI compliance criteria‍
  • Sustainable regulatory alignment: robust governance enables organizations to adapt to future regulatory changes without having to start from scratch

ISO 42001, the first international standard for AI management, serves as a key enabler in this regard. It enables the implementation of this governance framework within a proven structure inspired by best practices in risk management. Our support for ISO 42001 certification helps you implement it effectively.

Key takeaways

The AI Act is neither a theoretical document nor a distant concern. It is in effect, its timeline has just been definitively clarified by the Digital Omnibus, and the window of opportunity—though extended through 2027—continues to narrow for companies that have not yet begun to prepare.

The right question is no longer “Are we affected?” Virtually all companies that use AI are affected. The right question is: “What is the actual purpose of our AI systems, and what impacts might they have?”

It all starts with this answer.

👉 Watch the recording of our webinar: How to Secure Your AI Applications from A to Z

Official sources

Your regulatory obligations are changing. Let’s work together to identify your compliance priorities.

Let's discuss your compliance →
More content

Our latest Blog posts