The EU AI Act Explained Simply

There’s hardly any other law that’s mentioned so often yet so rarely truly understood. What the AI Act regulates, why the key deadlines have just been postponed, and what that actually means for your business.

Date

/

Category

AI & Automation

AI & Automation

/

Author

Dustin Tatarowicz

Dustin Tatarowicz

Featured image for the post

Hardly any other law is mentioned as often and yet so rarely truly understood as the EU AI Act. Many companies know it exists but aren’t sure whether or how it affects them, and often rely on snippets from news headlines rather than a clear, objective assessment. Here are the basics, explained in plain language, along with the latest updates on the timeline, which has shifted significantly once again this year.

A note up front, since it applies to the entire post: This text is not a substitute for legal advice. The AI Act is complex, and the specific classification of your AI application depends heavily on the individual circumstances. If you’re unsure whether and how you’re affected, it’s worth seeking advice from an attorney specializing in IT and data protection law. What follows here is a general overview intended to provide a better basic understanding—it is not an assessment of your specific case.

Four risk levels, one law

The AI Act is the EU’s first comprehensive AI law. Rather than regulating AI across the board, it differentiates based on risk. The greater the risk an AI application poses to people, the stricter the requirements. This is the fundamental principle that runs throughout the entire law and also explains why the obligations for most small and medium-sized enterprises are significantly more manageable than the headlines sometimes suggest.

Very broadly speaking, without getting into any legal details, four levels can be distinguished. Prohibited practices—such as AI that manipulates people or establishes a social credit system like those found in authoritarian surveillance states—are completely banned. High-risk systems—such as AI used in hiring, lending, or medical applications—are subject to strict requirements regarding documentation, transparency, and human oversight. Systems with limited risk, such as chatbots or applications that generate images or text, must above all make it clear that AI is involved. And applications with minimal risk—most everyday AI tools—are subject to virtually no additional obligations.

To assess where your own company stands, it’s therefore worth first asking which of these four levels your AI usage actually falls into before looking at specific deadlines. Most applications that smaller companies use on a daily basis—such as text assistants, image editing, and simple automation—fall into the lowest or second-lowest level.

This classification is not merely an academic exercise, even if it may sound like one at first glance. It directly determines the actual level of effort a company will have to expend. A company that uses an AI chatbot exclusively for customer inquiries has a manageable transparency obligation to fulfill. A company that uses AI for the automated pre-screening of job applications, on the other hand, is potentially operating in a high-risk area, with significantly more extensive requirements for documentation and human oversight. There is a major difference between these two scenarios, one that many companies do not fully appreciate at the outset.

These provisions are already in effect

Part of the law has long been in effect, regardless of any subsequent delays in the timeline. The prohibited practices have been in effect since the beginning of 2025. Obligations for providers of particularly powerful, general-purpose AI models have been in effect since mid-2025. In practice, these two areas primarily affect large AI providers themselves—that is, the companies that develop models such as ChatGPT or Claude—not the companies that simply use these tools in their day-to-day operations.

It is therefore important to distinguish between two roles: the provider, who develops and brings an AI system to market, and the operator, who deploys an existing system. Most small and medium-sized enterprises are operators, not providers, which significantly reduces the number of obligations that actually apply to them.

A simple example of this difference: A company that uses ChatGPT or a similar tool for internal texts is an operator of a third-party system. The obligations regarding the technical development and testing of the model rest with the provider behind it, not with the company using it. Only when a company develops an AI system itself or adapts an existing system in such a way that it effectively becomes a new product does it assume the role of provider—and thus a significantly broader set of obligations. For most companies reading this article, the role of operator is likely to be the more realistic starting point.

The schedule has changed, and that is now final.

The original timeline called for the requirements for high-risk systems to take effect starting in August 2026. The EU revised this timeline as part of the so-called Digital Omnibus, with the aim of giving companies more time to prepare. Unlike just a few months ago, this is no longer merely an announcement but a done deal: The Digital Omnibus officially entered into force at the end of July 2026, just a few days before the original August deadline.

According to the current, final status, several important deadlines have been postponed. The requirements for high-risk systems in the area that would affect most companies—such as those used in personnel selection or credit decisions—are being pushed back from August 2026 to December 2027. For high-risk systems that are directly embedded in products, such as certain machines or devices, the deadline is being pushed back from August 2027 to August 2028.

When it comes to labeling AI-generated content, it’s worth taking a closer look, because many online summaries get this point mixed up. Specifically, the technical watermarking requirement for providers of AI systems that generate content—that is, the machine-readable labeling in the background—has been postponed to December 2026. The more general transparency requirement—that people must be able to recognize when they are speaking with a chatbot or viewing content that is obviously AI-generated—will, however, still take effect in August 2026 and was not postponed by the Digital Omnibus. So anyone who uses a chatbot on their own website cannot avoid this labeling requirement, regardless of the postponed watermark deadline, which primarily affects technical providers, not the companies using the chatbots themselves.

As of today, these deadlines have been finalized and published. Nevertheless, given that this issue has been postponed several times in recent months, anyone making concrete preparations should check the current status directly with official sources before making any major decisions, rather than relying solely on individual articles online—including this one.

To put into context why these deadlines have been the subject of such lengthy and contentious debate: The original timeline for the AI Act was ambitious, especially compared to other major EU regulations, which often had several years of lead time. For months, feedback from the business community and the member states themselves indicated that the technical foundations for a smooth implementation were simply not yet mature enough. At its core, the Digital Omnibus is the EU’s response to precisely this feedback—not a fundamental departure from the regulation itself.

For most companies, there won't be any dramatic changes

For most small and medium-sized businesses that use AI chatbots, text tools, or similar everyday tools in their day-to-day operations, the AI Act won’t bring about any dramatic changes. The most important obligation in this area remains—and has always been—transparency. People must be able to recognize when they are interacting with AI—for example, when using a chatbot on your website or encountering AI-generated content that, at first glance, might appear to have been written by a human.

The situation is different if your company uses AI in more sensitive areas, such as the automated pre-screening of job applications, credit decisions, or medical applications. In these cases, it’s worth taking a closer look to determine whether a high-risk classification applies, even if the specific obligations now take effect later than originally planned. The extended deadline is not a reason to put off addressing the issue entirely; rather, it provides additional time to tackle it thoroughly rather than hastily.

Especially in these more sensitive areas, it’s worth seeking an external expert assessment early on, because an incorrect self-assessment can prove more costly here than in almost any other area of digitalization. A company that mistakenly classifies an application as non-critical may, in the worst-case scenario, not realize this until an audit or a complaint arises—rather than earlier, when a correction would still have been simple and inexpensive.

One area that is often overlooked in many companies: AI that wasn’t intentionally introduced as an AI project, but simply runs alongside existing software. An applicant tracking system with built-in automatic pre-screening, accounting software with automatic risk assessment, a CRM system that automatically prioritizes customer data. Anyone looking only for their own, deliberately implemented AI projects can easily overlook precisely these cases, because they slip unnoticed into tools that have long been part of everyday life.

A simple first step to uncovering these hidden instances: Go through the software your company uses on a daily basis, and for each major program, specifically ask whether and where AI features are built in. Vendors now usually list this information in their product descriptions or release notes because they themselves know that this question is being asked more and more often.

Three things that are still worth doing right now

Even if deadlines are pushed back, it’s worth preparing now for one simple reason: What you do now with plenty of time to spare won’t have to be caught up on later under time pressure.

  • Be aware of where AI is actually being used in your company. Many companies don’t fully realize this themselves because AI has long been integrated into many tools without anyone recognizing it as a separate project.

  • Label AI-generated content transparently, even before any specific requirement takes effect. It builds trust with your customers, and you'll be prepared when a deadline actually arrives, rather than having to react at the last minute.

  • Document where and how AI plays a role in important decisions, such as HR matters or customer reviews. This will make any future audits much easier and, if in doubt, demonstrate that your company took the issue seriously long before it became a legal requirement.

None of these three points requires a major compliance project. They can be addressed with just a few hours of effort and still lay a solid foundation for everything that comes later.

Those who want to take a more systematic approach can use a simple internal checklist as a guide: Which tools with AI capabilities does the team use? Who is responsible for them internally? And where do the results of AI usage influence decisions that directly affect customers or employees? Such a checklist often fits on a single page and can be created together with the team in an hour or two, without any external consulting—at least for an initial overview.

Why the deadlines were pushed back in the first place

The reasoning behind the postponement is also interesting because it says something about the practical feasibility of the law. A key criticism of the original deadlines was that the technical standards and testing procedures that companies would actually have needed to comply with the high-risk requirements were not yet fully in place by the scheduled start date. A requirement without the necessary practical tools would have put many companies in a position where they would have been formally required to comply without having the means to do so.

This delay is therefore less a sign that the issue is losing importance than an acknowledgment that effective regulation takes time to be implemented in practice. For companies, this means that the additional time should actually be put to good use and not be interpreted as a signal that the issue has been resolved.

Another, often overlooked side effect of the postponement: It also gives the specific testing and certification bodies—which companies will eventually need for certain high-risk systems—more time to get established. Companies that are already prepared by the time these structures are in place will be able to complete the actual testing process more quickly than companies that only begin to address the issue at that point.

Conclusion: No reason to panic, but a reason to take a closer look

For most small and medium-sized businesses, the AI Act will have less of a dramatic impact than the headlines suggest, mainly because the strictest requirements have now been pushed back even further. Nevertheless, it’s worth taking an honest look at where AI already plays a role in your business before the new deadlines draw nearer—even if December 2027 still seems a long way off today.

And once again, because it’s important enough to repeat at the end: This post provides general guidance but is not a substitute for individual legal advice. If you have specific questions about your own situation, a lawyer specializing in IT and data protection law can help—not a blog post, not even this one.

Related: What the New AI Disclosure Requirement Means for Your Website and How Small Businesses Can Make Effective Use of AI Without a Large Budget · Services: AI Consulting and Implementation

Do you want to know where your company stands when it comes to AI and compliance?

Together, we’ll take a look at where AI is already being used in your company and where it’s worth taking a closer look—without replacing a legal assessment. Send us a quick message using the contact form. We’ll respond within 24 hours, personally and without any sales pitch.