MICKAI®ArticlesThe EU AI Act Explained for CEOs …
Article · 22 July 2026

The EU AI Act Explained for CEOs (2026)

A binding regulation applying in stages, not on one date, with high risk obligations now due in 2027 and 2028.

Author
Micky Irons
Published
22 July 2026
Follow Micky Irons
LinkedInX
eu ai acteu ai act deadlineai act compliancehigh-risk aidigital omnibus ai

The EU AI Act is a binding regulation, not guidance, and it now applies in stages rather than on a single date. Prohibited practices and AI literacy duties have been enforceable since February 2025, and general-purpose AI model obligations since August 2025. The much-discussed 2 August 2026 date for high-risk systems has been superseded: the Digital Omnibus on AI has pushed stand-alone high-risk obligations to 2 December 2027 and product-embedded high-risk obligations to 2 August 2028. The deferral is a longer build window, not a lighter workload, because the underlying proof requirements have not changed.

What is the EU AI Act, in one paragraph?

The EU AI Act, formally Regulation (EU) 2024/1689, is the European Union's horizontal law governing the development and use of artificial intelligence. It entered into force on 1 August 2024, twenty days after publication in the Official Journal on 12 July 2024. Rather than regulating "AI" as a single category, it sorts AI systems into risk tiers and attaches obligations proportionate to the tier: some practices are banned outright, some systems carry heavy compliance duties, some carry light disclosure duties, and most everyday AI carries none at all. It applies to providers who build AI and to deployers who use it in a professional context, inside the EU and, in many cases, outside it too.

Is the EU AI Act deadline still 2 August 2026?

No. That date was the original deadline for stand-alone high-risk systems, and it has moved. The European Commission published the Digital Omnibus on AI on 19 November 2025 to defer it. The European Parliament endorsed the change on 16 June 2026, the Council of the EU gave final green light on 29 June 2026, and the deferral took legal effect on publication in the Official Journal shortly afterwards. Two dates now replace the single 2026 deadline, and one obligation is not deferred at all.

ObligationStatus
Article 5 prohibited practicesEnforceable since 2 February 2025. Untouched by the deferral.
Article 4 AI literacy dutyLive since 2 February 2025.
GPAI model obligations (Articles 51 to 56)In force since 2 August 2025. Models already on the market before that date get a compliance grace period to 2 August 2027 (Article 111(3)).
Article 50 transparency duties (chatbots, deepfakes)Largely stay on the original schedule, around 2 August 2026.
Annex III high-risk systems (use-case based)Deferred from 2 August 2026 to 2 December 2027.
Annex I high-risk systems (embedded in regulated products)Deferred to 2 August 2028.

Treat the deferral as extra runway, not a reason to stop planning. The technical documentation, risk management, human oversight and logging duties that were due in 2026 are the same duties now due in 2027 and 2028. A board that starts the governance work now arrives already compliant. A board that waits compresses two years of work into a scramble.

What are the EU AI Act's four risk tiers?

The Act sorts AI into a pyramid of four tiers, plus a separate track for general-purpose AI models. Most of a company's exposure sits at the top and bottom: a short list of banned practices, and a much larger pool of everyday AI that carries no obligation at all.

Unacceptable risk: banned outright

Article 5 prohibits eight practices, enforceable since 2 February 2025:

  • Subliminal or manipulative techniques that materially distort behaviour and cause harm
  • Exploiting vulnerabilities of children, disabled people, or people in vulnerable economic or social situations
  • Social scoring by public authorities based on behaviour or personal characteristics
  • Predictive policing based solely on profiling a person, without additional objective evidence
  • Untargeted scraping of facial images from the internet or CCTV to build facial recognition databases
  • Emotion recognition in the workplace or in educational institutions, with narrow medical or safety exceptions
  • Biometric categorisation used to infer sensitive attributes such as race, political opinion, religion or sexual orientation
  • Real-time remote biometric identification in publicly accessible spaces for law enforcement, subject to three narrow statutory exceptions

High-risk: two routes, two new dates

A system is high-risk if it falls into one of two routes. The Annex I route covers AI that is a safety component of a product already regulated under EU product-safety law, such as medical devices, machinery, toys or lifts, and is now due 2 August 2028. The Annex III route covers AI used in specific high-stakes domains: biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential public or private services including credit scoring and insurance risk, law enforcement, migration and border control, and the administration of justice or democratic processes. This route is now due 2 December 2027. Both routes carry the same substantive duties: a risk management system, data governance, technical documentation, logging, transparency to deployers, human oversight, accuracy and robustness testing, cybersecurity, conformity assessment, registration in the EU database, and CE marking.

Limited risk: transparency, not prohibition

Article 50 covers chatbots, emotion-recognition systems, biometric categorisation systems, and deepfake or synthetic-content generators. The duty here is lighter: tell people they are dealing with AI, or label the content as AI-generated. This is the one part of the pyramid that largely stayed on its original near-term schedule and was not pushed back by the Digital Omnibus.

Minimal risk: most commercial AI

Spam filters, AI-enabled video games and most recommender systems fall here. The bulk of AI in commercial use carries no obligation under the AI Act at all, though ordinary product-safety, consumer-protection and data-protection law still applies to it.

General-purpose AI models: a separate track

GPAI models sit outside the four-tier system because they are defined by capability, not by use case. Every GPAI provider owes technical documentation, a copyright policy and a training-content summary. Models that carry systemic risk, triggered either by a compute threshold currently set at 10^25 FLOPs or by Commission designation, face additional model evaluation, adversarial testing, incident reporting and cybersecurity duties. This tier captures the frontier model builders, not most enterprises buying and deploying AI tools.

Does the EU AI Act apply to my company if we're not in the EU?

Yes, in many cases. The Act reaches non-EU providers and deployers whose AI system's output is used in the EU, even where the company has no EU office or entity. The logic mirrors the GDPR: what matters is where the effect lands, not where the company is registered. A US or UK company with no EU presence can still be in scope if its AI product is used by, or on, people in the EU. This is the single most under-appreciated fact for non-EU boards, and it is worth a direct scoping test.

Three questions settle it for most companies:

  • Do we build or fine-tune AI systems or models (a provider), or do we buy and run someone else's (a deployer)? Most enterprises are deployers.
  • Does any AI system we use touch hiring, performance management, credit or insurance decisions, biometric identification, critical infrastructure, or law enforcement, border or justice processes? If yes, check it against Annex III.
  • Does the output of any AI system we use reach an EU person or the EU market, regardless of where we are headquartered? If yes, scope applies even without an EU entity.

What is a provider versus a deployer under the Act?

Most of the confusion CEOs run into starts with these four roles.

  • Provider. Builds the AI system or model, or has it built and places it on the market under its own name. Carries the heaviest duties.
  • Deployer. Uses an AI system under its own authority in a professional context. Most enterprises buying AI tools are deployers. The duty set is materially lighter than a provider's, but it is not zero: human oversight, monitoring, informing affected people, and specific deployer duties for Annex III use cases all still apply.
  • Importer. Brings a non-EU provider's AI system into the EU market. Mainly a verification and documentation role, checking that the provider has done its job.
  • Distributor. Makes an AI system available within the EU supply chain without being the original provider or importer. Similar verification duties.

The same company can hold different roles for different systems. A retailer that buys a third-party fraud-detection tool is a deployer for that tool, but becomes a provider the moment it fine-tunes a model and ships it under its own brand.

Who enforces the EU AI Act?

Enforcement is dual-layered. The European AI Office, sitting inside the European Commission, enforces directly against general-purpose AI model providers and coordinates the wider framework. National competent authorities and market surveillance authorities in each member state enforce high-risk and other obligations for AI systems generally, and run conformity assessments. The European Artificial Intelligence Board coordinates positions across member states. For a CEO, the practical point is simple: enforcement is real, and it runs both at EU level for frontier model providers and at national level for everyone else.

What happens if we don't comply?

The fines are structured in three bands, plus a specific band for general-purpose AI providers.

BreachMaximum fine
Prohibited practices (Article 5)€35 million or 7% of total worldwide annual turnover, whichever is higher
High-risk system non-compliance and other substantive obligations€15 million or 3% of total worldwide annual turnover, whichever is higher
Incorrect, incomplete or misleading information to authorities€7.5 million or 1% of turnover, whichever is higher
GPAI provider fines (Article 101), enforced by the EU AI Office€15 million or 3% of global annual turnover

There is a genuinely favourable carve-out for smaller companies. For SMEs, including start-ups, each fine is capped at the lower of the fixed amount or the percentage, reversing the "whichever is higher" rule that applies to large undertakings. It is a real difference in exposure and worth knowing before assuming the headline numbers apply in full.

What should a CEO actually do this year?

The deferral bought time. It did not remove the work. An eight-step sequence covers what most boards need to start now.

  • Classify, don't assume. Inventory every AI system in use across the business, not just the flagship product, including AI embedded inside vendor tools such as HR platforms, fraud detection and customer service bots. Most companies find AI they did not know they were deploying.
  • Establish role, per system. Provider or deployer, decided system by system and use case by use case. The same company can be a deployer for one tool and a provider for another it has built or heavily customised.
  • Map against Annex III. The employment, credit and biometric categories catch a surprising number of ordinary SaaS and HR tools. This is where most enterprises discover exposure they did not expect.
  • Build governance now, not in 2027. Appoint an accountable owner, not necessarily a new hire; often the CTO, general counsel, or a data-protection officer with an expanded brief. Build the risk-management and documentation habit before it is mandatory, because retrofitting audit trails onto systems already in production costs far more than building them in from the start.
  • Review vendor contracts. Where AI is bought rather than built, check what obligations the vendor, as provider, has already discharged, versus what the buyer inherits as deployer. Contracts should specify the split explicitly.
  • Treat transparency duties as live now. Chatbots, synthetic content and deepfakes need labelling under Article 50, which stayed close to its original schedule while high-risk obligations moved. This is the one duty not to defer mentally along with the rest.
  • Treat the deferral as a budget and hiring runway. The proof requirements do not get lighter, they arrive later. Boards that start the governance and audit-trail build now reach December 2027 already compliant.
  • Watch the codes of practice and harmonised standards as the AI Office publishes them. They turn the Act's general language into concrete technical requirements, and most of the real compliance detail will land through 2026 and 2027 in this form rather than in the statute text itself.

Where does sovereignty, on-prem infrastructure, and auditability fit?

Strip away the legal language and the high-risk obligations are fundamentally an evidentiary problem: can the company show a regulator, after the fact, exactly what an AI system did, on what data, under what human oversight. Technical documentation, logging and human-oversight records exist so that an answer is provable on demand, not just asserted.

Enterprises are taking three broad paths to that evidentiary burden, and all three are legitimate. Some build governance and logging tooling in-house around their existing AI stack. Some buy a dedicated GRC or AI-governance platform that sits alongside their systems and records what happens. Others choose to run on infrastructure with audit trails and human oversight built into the runtime itself, so the record is generated by design rather than bolted on afterwards. Mickai is one credible route into that third path. We built our sovereign intelligence operating system around a per-action verifiable audit chain, so the evidentiary record exists as a by-product of how the system runs, rather than as a separate compliance project layered on top. Whichever path a company chooses, the point that matters for a CEO deciding where to invest is the same: a system that generates its own auditable record by default makes the evidentiary burden lighter than retrofitting logging onto a black-box tool once the deadline is close.

How the fuller sovereign architecture behind offline verifiable compliance fits together is set out at /sovereign-ai, and the film at /film shows the interface in operation.

Frequently asked questions

Is the EU AI Act deadline still 2 August 2026?

No. The Digital Omnibus on AI deferred stand-alone high-risk obligations under Annex III to 2 December 2027, and high-risk obligations for AI embedded in regulated products under Annex I to 2 August 2028. Article 50 transparency duties, covering chatbots and synthetic content labelling, largely stayed on the original schedule and were not deferred.

What are the four risk tiers under the EU AI Act?

Unacceptable risk, banned outright since 2 February 2025; high-risk, carrying heavy compliance duties and now due either 2 December 2027 or 2 August 2028 depending on the route; limited risk, carrying transparency and disclosure duties only; and minimal risk, which covers most commercial AI and carries no obligation under the Act at all. General-purpose AI models sit in a separate track defined by capability rather than use case.

Does the EU AI Act apply to companies outside the EU?

Yes. The Act applies to non-EU providers and deployers whenever their AI system's output is used in the EU, even without an EU office or entity, in the same way the GDPR reaches companies with no EU presence. A company should check whether its AI systems' outputs reach EU persons or the EU market, not just where it is headquartered.

What is the difference between a provider and a deployer under the EU AI Act?

A provider builds the AI system or model, or has it built and places it on the market under its own name, and carries the heaviest duties. A deployer uses an AI system under its own authority in a professional context, which is a lighter but not zero duty set. Most enterprises buying AI tools from vendors are deployers.

What are the fines for non-compliance with the EU AI Act?

Prohibited-practice breaches carry fines of up to €35 million or 7% of global turnover, whichever is higher. High-risk and other substantive breaches carry up to €15 million or 3%. Misleading information to authorities carries up to €7.5 million or 1%. SMEs, including start-ups, get each fine capped at the lower rather than the higher of the fixed amount or the percentage.

Is my chatbot or customer-service AI covered by the EU AI Act?

Yes, under the limited-risk transparency tier. Article 50 requires that people be told they are interacting with AI, and that AI-generated or synthetic content, including deepfakes, be labelled as such. This obligation largely stayed on its original near-term schedule while high-risk obligations for other systems were deferred.

What is a general-purpose AI model and how is it regulated differently?

A GPAI model is regulated by its capability rather than by a specific use case. All GPAI providers owe technical documentation, a copyright policy and a training-content summary, obligations that have been in force since 2 August 2025. Models assessed as carrying systemic risk, based on a compute threshold or Commission designation, face additional evaluation, adversarial testing, incident reporting and cybersecurity duties, enforced directly by the EU AI Office.

Do start-ups get any relief under the EU AI Act penalty structure?

Yes. For SMEs, including start-ups, each fine band is capped at the lower of the fixed euro amount or the turnover percentage, reversing the "whichever is higher" rule that applies to large undertakings. It is a genuine, quantifiable difference in exposure rather than a general goodwill gesture.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/eu-ai-act-explained-for-ceos-2026. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles