The EU AI Act for companies building AI systems: a 2026 guide.
What applies today, what the Digital Omnibus delayed, and who counts as the provider when you commission a custom system. For companies in the EU, and anyone selling AI into it.
The short version: the EU AI Act has applied generally since 2 August 2026. The bans on prohibited practices have applied since February 2025, and the transparency rules for chatbots and generated content apply now. The obligations for high-risk systems, the part most people worry about, were pushed back by the Digital Omnibus to December 2027 and August 2028. And if you commission a custom AI system and put it into service under your own name, the Act will usually treat you as its provider, not the company that built it.
This guide covers what that means in practice for a company building an AI assistant, an agent, a retrieval system or an automated workflow. It reflects the amended text of the Act. It’s a practical summary from the team that builds these systems, not legal advice, so take advice on your specific case.
What applies now, and what was delayed
Regulation (EU) 2026/1744, the “Digital Omnibus on AI”, entered into force on 27 July 2026 and amended the Act’s timeline. Many articles still quote the old dates. These are the current ones:
| From | What applies |
|---|---|
| 2 Feb 2025 | Prohibited practices (Article 5) and AI literacy (Article 4) |
| 2 Aug 2025 | Governance rules and obligations for general-purpose AI (GPAI) model providers |
| 2 Aug 2026 | The Act applies generally, including Article 50 transparency for chatbots and generated content. The Commission can now enforce against GPAI providers. |
| 2 Dec 2026 | Machine-readable marking (Article 50(2)) for generative systems already on the market before 2 Aug 2026. New systems must comply already. New bans on non-consensual intimate imagery and child sexual abuse material also start. |
| 2 Aug 2027 | GPAI models placed on the market before 2 Aug 2025 must comply |
| 2 Dec 2027 | High-risk obligations for Annex III systems (employment, credit, education, essential services and others) |
| 2 Aug 2028 | High-risk obligations for AI built into regulated products (Annex I, such as medical devices and machinery) |
Source: the amended text, Regulation (EU) 2026/1744, and the Commission’s AI Act overview.
Does it apply to you if you’re outside the EU?
Yes, in most cases that matter commercially. The Act covers providers who place AI systems on the EU market or put them into service there, wherever the provider is established. It covers deployers located in the EU. And it covers providers and deployers outside the EU when the system’s output is used in the EU. A US or UK company whose assistant answers EU customers is in scope.
Provider or deployer: who carries the obligations?
The Act puts most obligations on the provider. The definition in Article 3(3) includes anyone who “has an AI system … developed and places it on the market or puts the AI system into service under its own name or trademark”. A deployer is anyone using an AI system under its authority in a professional capacity.
That wording matters when you hire a development company. If an agency builds a support assistant for you, and you run it under your brand for your customers, you are normally the provider. The agency is a supplier to you. Article 25 adds a second route: a deployer becomes the provider of a high-risk system if it puts its own name on it, makes a substantial modification, or changes its purpose so that it becomes high-risk.
In practice, your contract with your development partner should give you what a provider needs: documentation of how the system works, what it was tested on, its known limits and its logs. If a partner can’t produce those, you’ll have trouble meeting your own obligations.
Chatbots and generated content: Article 50
Article 50 is the part of the Act that applies to most business AI right now, because it isn’t limited to high-risk systems.
- Tell people they’re talking to AI. Interactive systems must be designed so that people “are informed that they are interacting with an AI system”, unless that’s obvious to a reasonably well-informed person. For a support or sales assistant, a clear line at the start of the conversation does the job.
- Mark generated content. Providers of systems that generate synthetic audio, images, video or text must mark the output in a machine-readable way. Systems already on the market before 2 August 2026 have until 2 December 2026.
- Disclose deepfakes and public-interest text. Deployers must disclose deepfakes, and AI-generated text published to inform the public on matters of public interest, unless a person has reviewed and taken editorial responsibility for it.
The Commission adopted its final guidelines on the transparency obligations in July 2026. A voluntary code of practice on marking and labelling generated content is also available.
Is your system high-risk?
Most business AI isn’t. A customer-support assistant, an internal knowledge search, a sales agent or a document-processing workflow usually falls outside the high-risk categories. Annex III lists the areas that are in scope:
- biometrics;
- critical infrastructure;
- education and vocational training;
- employment and the management of workers, such as screening CVs or deciding promotions;
- access to essential private and public services, such as credit scoring and life and health insurance pricing;
- law enforcement, migration and border control;
- the administration of justice and democratic processes.
Even inside those areas, Article 6(3) excludes systems that don’t pose a significant risk. Examples are systems that perform a narrow procedural task, improve the result of work a person has already done, or prepare an assessment that a person then makes. A system that profiles people is always high-risk. If yours is high-risk, you now have until 2 December 2027 to put in place risk management, data governance, technical documentation, logging, human oversight and accuracy testing. That’s easier to design in from the start than to retrofit.
Most of what the Act asks for in a high-risk system is what a well-engineered system has anyway: tests, logs, documentation and a person who can step in.
GDPR still does most of the work
For most projects, data protection law creates more day-to-day obligations than the AI Act:
- Data protection impact assessments. Article 35 GDPR requires one where processing is likely to be high-risk, which covers many AI uses of personal data.
- Legal basis. The European Data Protection Board’s Opinion 28/2024 says legitimate interest can’t be assumed as the basis for developing or using AI models. It has to pass the three-step test case by case.
- Transfers to US model providers. The EU–US Data Privacy Framework remains valid. The EU General Court dismissed a challenge in September 2025, and an appeal (case C-703/25 P) is pending at the Court of Justice. Using EU-region hosting where your providers offer it, and keeping the model replaceable, protects you if that changes.
The Commission’s proposed GDPR changes for AI, part of the wider digital omnibus, are still being negotiated and aren’t law. Don’t design around them yet.
What the fines look like
| Breach | Maximum fine |
|---|---|
| Prohibited practices | €35m or 7% of worldwide annual turnover |
| Operator obligations, including Article 50 transparency | €15m or 3% |
| Supplying incorrect information to authorities | €7.5m or 1% |
For most companies the higher of the two figures applies. For SMEs, and now for the new “small mid-cap” category the Omnibus created, the lower one does (Article 99).
Italy adds its own rules
Italy is the first member state with a national AI law alongside the Act. Law 132/2025 has been in force since 10 October 2025, and it adds duties the Act doesn’t have:
- Minors. Children under 14 need parental consent to use AI and for the related data processing (Article 4).
- Healthcare. Patients have the right to be told AI is being used, and the decision always stays with the medical professional (Article 7).
- Work. Employers must tell workers when AI is used (Article 11).
- Professions. Lawyers, accountants and other professionals may use AI only in support of their own intellectual work, and must tell clients which AI they use, in clear language (Article 13).
- Public administration. AI supports officials, and a person stays solely responsible for each decision (Article 14).
- Deepfakes. Spreading harmful AI-falsified images, video or voices without consent is now a criminal offence, punishable by one to five years in prison (Article 26).
AgID and the national cybersecurity agency (ACN) are the AI authorities. The Bank of Italy, CONSOB and IVASS keep their roles in finance and insurance. The government’s implementing decrees are due around October 2026.
Italy’s data protection authority, the Garante, is also among Europe’s most active on AI. It fined OpenAI €15m in 2024, but a Rome court annulled that fine in March 2026 on jurisdiction grounds, without ruling on the merits. It restricted DeepSeek’s processing of Italian users’ data in January 2025, and fined the company behind the Replika chatbot €5m in May 2025. For a system aimed at Italian users, privacy notices, age checks and a documented legal basis aren’t optional extras.
What to ask your development partner
| Ask | Why it matters |
|---|---|
| Will we get documentation of how the system works, what it was tested on and its known limits? | As the provider, you need it for your own obligations |
| How do users learn they’re talking to AI, and how is generated content marked? | Article 50 applies now |
| Where is data processed, and by which subprocessors? | GDPR transfers and your records of processing |
| Can the model provider be swapped without a rebuild? | Protection if a transfer mechanism or a vendor’s terms change |
| What is logged, for how long, and who can see it? | Traceability, incident response and data minimisation |
| How is accuracy measured before each release? | Evidence that the system does what you say it does |
| Where does a person take over? | Human oversight, and the escape route when the model is wrong |
Most of these come down to engineering habits rather than legal ones. A partner who builds evaluation sets before features, logs every action and designs fallbacks to a person will have answers ready.
Questions companies ask
Is a customer-service chatbot built on a general-purpose model high-risk?
Usually not. It still has to tell people they’re talking to AI under Article 50, and GDPR applies to the conversations it handles.
We use a model from OpenAI, Anthropic or Google. Doesn’t the model provider carry the obligations?
For the model, yes: GPAI providers have their own obligations. For the system you build on it and run under your name, you’re the provider. Your obligations depend on what the system does, not on whose model sits inside it.
When should we start?
Now, if you’re building something that could fall under Annex III. December 2027 is close for a system that has to be designed, built, tested and documented. For everything else, Article 50 and GDPR apply today.
Modulus Labs AI builds AI systems for companies in the EU, the UK and the US, with the documentation, logging and human oversight described here built in from the start. Tell us what you’re building and we’ll tell you how we’d approach it.