Back to News
Compliance
6 min

EU AI Act 2026: What Your Business Needs to Know Now

Article 50 transparency duties apply since August 2, 2026; the high-risk rules moved to December 2027. Here's what that means for your company — explained in plain language.

AI transparency: This article was drafted with the support of AI tools and reviewed and approved by a person before publication. ThinkLocAI UG (haftungsbeschränkt) holds editorial responsibility. More on AI transparency

The European Union has passed the world's first comprehensive AI regulation: the EU AI Act. Since August 2, 2026 its transparency rules, penalties and market surveillance have been live. The Digital Omnibus on AI — Regulation (EU) 2026/1744, in force since July 27, 2026 — moved the high-risk obligations to December 2, 2027. If your company uses AI in any form, from chatbots to automated HR screening, this affects you. Here's what you need to know, without the legal jargon.

What Is the EU AI Act?

Think of it as the GDPR for artificial intelligence. Just as the GDPR regulates how companies handle personal data, the AI Act regulates how companies use AI systems. It applies to any business operating in the EU, regardless of where the AI system was developed. The core idea: the riskier the AI application, the stricter the rules.

What Applies Now, and What Was Postponed

The Digital Omnibus changed the calendar, not the substance. Live since August 2, 2026: the Article 50 transparency duties, the Article 5 prohibitions, the rules for general-purpose AI models, and the penalty and market-surveillance regime. Postponed: the obligations for stand-alone high-risk systems under Annex III, from August 2, 2026 to December 2, 2027, and for AI as a safety component in regulated products, from August 2, 2027 to August 2, 2028. Two new prohibitions — AI-generated non-consensual intimate imagery and child sexual abuse material — take effect on December 2, 2026. The AI literacy duty in Article 4 survived in softened form: you now have to support the development of AI literacy among staff rather than guarantee a level.

The Risk Categories: Where Does Your AI Fit?

The AI Act divides AI applications into four risk levels:

  • Unacceptable risk (banned): Social scoring, manipulative AI, real-time biometric surveillance in public spaces
  • High risk (strict rules, applicable from December 2, 2027): AI in hiring decisions, credit scoring, healthcare diagnostics, legal proceedings, critical infrastructure
  • Limited risk (transparency required since August 2, 2026): Chatbots must disclose they are AI; AI-generated content must be labeled
  • Minimal risk (no special rules): Spam filters, AI in video games, basic internal productivity tools

What This Means for Your Company

If you use AI for HR screening, financial assessments, or any process that significantly affects people's lives, you likely fall into the high-risk category. From December 2, 2027 this means you need to document how your AI system works, monitor its outputs for bias and errors, maintain detailed logs of AI decisions, ensure human oversight for important decisions, and conduct risk assessments before deployment. The extra time is not a reason to wait: logging and oversight are architectural decisions, and retrofitting them into a live system is expensive. And whatever your risk category, you already have to tell people when they're interacting with AI.

Why On-Premise AI Makes Compliance Easier

Here's where your choice of AI infrastructure matters. With cloud AI services, you're trusting an external provider to meet the AI Act's requirements. You often can't access detailed logs, control how the model processes data, or demonstrate full transparency to regulators. With on-premise AI, you have complete control: every query is logged on your servers, you can audit the entire system, and you can demonstrate to regulators exactly how data flows through your AI. You're not dependent on a provider's compliance promises.

How to Prepare: A Simple Checklist

You don't need to panic, but you should start preparing now:

  • Inventory: Make a list of every AI tool your company uses — including ChatGPT, Copilot, and any AI features in your existing software
  • Classify: Determine the risk category for each AI use case using the EU's classification system — do this now, even though the high-risk duties only bite in December 2027
  • Evaluate your providers: Ask your AI vendors how they plan to comply with the AI Act
  • Document: Start documenting how AI decisions are made in your organization
  • Consider infrastructure: For high-risk applications, evaluate whether on-premise deployment gives you better control and auditability
  • Assign responsibility: Designate someone in your organization to oversee AI compliance

The EU AI Act isn't something to fear — it's a framework that builds trust in AI. The Digital Omnibus bought companies sixteen extra months on the high-risk rules, but the transparency duties are already being enforced. Companies that prepare early will be able to demonstrate to customers, partners and regulators that their AI use is responsible and transparent. Start with the checklist above.

How ThinkLocAI is classified under the AI Act

Our compliance page sets out the split of duties between provider and deployer, the Annex III use cases relevant to our customers, the Art. 50 transparency measures and a deployer checklist.

Open the EU AI Act page

Ready to get started?

Experience the power of on-premise AI for your enterprise.

Request Demo