The Law Has Arrived — Are You Ready?
The EU AI Act is the world's first comprehensive legal framework for artificial intelligence. It entered into force in August 2024 and has been applying in stages ever since: prohibited practices since February 2025, transparency obligations for chatbots and synthetic content since August 2026, obligations for general-purpose AI model providers since August 2025, and the Annex III high-risk regime from 2 December 2027, after the EU's Digital Omnibus deferred it in July 2026. If your organisation operates in the EU, sells to EU customers, or processes data about EU residents, this law applies to you.
The EU AI Act is not a future concern. Prohibitions have been enforceable since February 2025, GPAI model obligations since August 2025, and transparency obligations (chatbot disclosure, AI-content labelling) since 2 August 2026. The heaviest layer — the Annex III high-risk requirements — was deferred by the Digital Omnibus and now becomes enforceable on 2 December 2027. That deferral bought time, not an exemption: the classification and documentation work still needs to happen, and "we have until 2027" is exactly the assumption that leaves organisations unready again.
What the EU AI Act Actually Regulates
The Act regulates "AI systems" — a deliberately broad definition that covers most software with a machine learning component. It applies to anyone who:
- ◆Develops an AI system for placing on the EU market
- ◆Deploys an AI system in the EU (even if built elsewhere)
- ◆Imports or distributes AI systems in the EU
- ◆Uses certain high-risk AI systems within the EU
This extraterritorial reach is significant. A US-based SaaS company selling an AI-powered hiring tool to a German company is subject to the Act. A UK fintech using an AI credit scoring model on EU customers is subject to the Act.
The Enforcement Reality
Fines under the EU AI Act are substantial — up to €35 million or 7% of global annual turnover (whichever is higher) for the most serious violations. This is higher than GDPR. National competent authorities in each EU member state are responsible for enforcement, with a European AI Office providing oversight and coordination.
Most organisations in scope still haven't formally assessed which of their AI systems the Act covers — IBM's 2026 Cost of a Data Breach Report found that 63% of breached organisations had no policy governing AI use or shadow AI at all. You cannot comply with a law you haven't mapped yourself against.
The first step in EU AI Act compliance is always the same: inventory and classify your AI systems. Before you can know what you need to do, you need to know what you have. This section will give you the tools to do exactly that.
