Question 14 of an enterprise procurement questionnaire from a German customer reads: "Describe how your AI features are classified under the EU AI Act." You ship a support chatbot and a résumé-ranking feature. You are not sure whether the answer is a sentence or a project.
Any EU AI Act compliance guide has to start with the EU AI Act deadlines, because they moved. The EU AI Act is a risk-based law that applies to any company placing AI on the EU market, or whose AI output is used in the EU, wherever the company is based. Obligations depend on your role and the risk tier of the system, and the high-risk deadlines are now 2 December 2027 and 2 August 2028, not August 2026.
By the end of this guide you will know whether the Act reaches your company, which obligations apply to your role, and the six things a SaaS startup should do first.
Here is what I will cover:
- What the Act is and who it applies to, including non-EU companies
- The full timeline, with what applies today and what is still ahead
- The four risk categories and where SaaS features typically land
- Requirements by role, general-purpose AI duties, transparency, and AI literacy
- Penalties, a six-step startup plan, and how ISO 42001 fits
What Is the EU AI Act? A Plain-English Start to This EU AI Act Compliance Guide
The EU AI Act (Regulation (EU) 2024/1689) is the European Union's binding law on artificial intelligence. It entered into force on 1 August 2024 and is the first comprehensive AI regulation of its kind. It sorts AI systems by the risk they pose, then attaches duties to the companies that build, sell, import, or use them.
Note what it regulates: uses and roles, not "AI" as a technology. A spell-checker and a hiring screener may run on the same model. The Act treats them very differently.
EU AI Act Compliance Guide: Who It Applies To, From Providers to Non-EU Companies
The Act assigns obligations by role, not by company size or industry. One company can hold several roles at once, and SaaS teams often do.
EU AI Act Providers and Deployers, Importers and Distributors
The European Commission's AI Act Service Desk summary of Article 2 names four operator roles, plus product manufacturers who put AI into their own branded products.
| Role | Who it is | SaaS example |
|---|---|---|
| Provider | Develops an AI system, or has one developed, and places it on the market under its own name | You ship an AI résumé-ranking feature inside your product |
| Deployer | Uses an AI system under its own authority in a professional setting | Your customer running that feature, or you using a third-party AI tool internally |
| Importer | An EU-based entity placing a non-EU provider's system on the EU market | An EU reseller bringing a US AI product into the bloc |
| Distributor | Anyone in the supply chain, other than the provider or importer, who makes a system available in the EU | A marketplace partner listing your AI product |
Some uses fall outside the Act entirely: military and national security systems, research before a system is placed on the market, and purely personal non-professional use. Free and open-source systems are mostly excluded too, unless they are high-risk or trigger the prohibited-practice or transparency rules.
If you build on a third-party model through an API, you are usually the provider of the AI system you built on top of it, not the provider of the underlying model. That distinction matters for the general-purpose AI section below.
Does the EU AI Act Apply to Non-EU Companies?
Yes. The Act has extraterritorial reach, the same way GDPR does. It covers providers placing systems on the EU market wherever they are established, and providers and deployers in third countries whose AI output is used in the Union.
Picture a US startup with a single customer in Amsterdam. If that customer's employees use your AI feature, or its output lands in EU hands, you are in scope. Having no EU office does not change the answer.
Providers established outside the EU also generally have to appoint an EU authorised representative for high-risk systems, so build that into your plan early.
EU AI Act Compliance Guide to Deadlines: The EU AI Act Timeline as of September 2026
Much of the confusion around the EU AI Act deadlines comes from dates that were accurate a year ago. The timeline below reflects the AI Act Service Desk implementation page and law-firm coverage of the adopted Digital Omnibus, as of 29 September 2026.
| Date | What applies | Status |
|---|---|---|
| 1 Aug 2024 | Act enters into force | In effect |
| 2 Feb 2025 | Definitions, AI literacy duty, and prohibited practices | In effect |
| 2 Aug 2025 | General-purpose AI model obligations; governance structures | In effect |
| 2 Aug 2026 | Transparency duties (Article 50), national enforcement, penalty regime, Commission enforcement powers over general-purpose AI | In effect |
| 2 Dec 2026 | New ban on AI generating non-consensual intimate imagery and child sexual abuse material; grace period ends for content marking on systems already on the market | Fixed in law, upcoming |
| 2 Aug 2027 | Member State AI sandboxes due; general-purpose models placed on the market before Aug 2025 must comply | Fixed in law, upcoming |
| 2 Dec 2027 | Stand-alone high-risk systems (Annex III: employment, education, credit, biometrics, and similar) | Fixed in law, upcoming |
| 2 Aug 2028 | High-risk AI embedded in regulated products (Annex I) | Fixed in law, upcoming |
Every EU AI Act deadline in that table is adopted law as of the date above. None is only proposed.
The EU AI Act Digital Omnibus: What Changed and What Is Not Final
The European Commission proposed the Digital Omnibus on AI in November 2025, citing late technical standards and slow designation of national authorities. Parliament and Council reached political agreement on 7 May 2026. Parliament approved the text on 16 June, the Council adopted it on 29 June, and it was signed on 8 July. It was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026.
What it moved: Annex III high-risk obligations from 2 August 2026 to 2 December 2027, and Annex I product-embedded systems from 2 August 2027 to 2 August 2028. What it did not move: transparency duties still began on 2 August 2026, and the general-purpose AI obligations are unchanged.
It also made two changes worth knowing. Small mid-cap companies now get some of the documentation relief previously limited to SMEs. And Article 4 (AI literacy) was softened from a duty to ensure a sufficient level of literacy into a duty to take measures that support it.
What is genuinely still open? The harmonised technical standards that would give companies a presumption of conformity are still being finalised by CEN and CENELEC, and Commission guidance on classification keeps arriving in pieces. My read is that those two, not the dates, are what to monitor from here.
That uncertainty is not new: one commenter on a January 2026 Hacker News thread about an open-source AI Act tool wrote that what compliance entails was "in high flux and changing on a weekly basis."
Not everyone expects the new date to bite, either. A Hacker News commenter argued in June 2026 that even at 2 December 2027 the rules "might be intentionally not enforced at all" for a while. That is one anonymous opinion about enforcement, not a legal position, and nothing in the adopted text depends on it.
EU AI Act Risk Categories: The Four Tiers in This EU AI Act Compliance Guide
The Act's whole design rests on four EU AI Act risk categories, which the Commission calls risk tiers. The higher the tier, the heavier the duties.
- Unacceptable risk (banned): practices such as social scoring, manipulation that exploits vulnerabilities, untargeted scraping of facial images, and emotion recognition in workplaces and schools. These have applied since 2 February 2025, and the new intimate-imagery ban joins them on 2 December 2026.
- High risk (strict requirements): systems in areas the Act lists, such as employment, education, essential services, and biometrics.
- Transparency risk (disclosure duties): chatbots, AI-generated content, deepfakes, and emotion recognition or biometric categorisation systems that must be labeled or announced.
- Minimal risk (no specific rules): the majority of AI in use today, like spam filters and recommendation widgets.
Which tier a given feature lands in is a real analysis, not a label you pick. This guide keeps it at the level you need for planning.
EU AI Act High-Risk AI Systems: The Use Cases SaaS Teams Trip Over
EU AI Act high-risk AI systems come in two main kinds: it is a safety component of a regulated product (Annex I), or it falls into a use-case area listed in Annex III. For a SaaS company, Annex III is the one that bites: hiring and worker management tools, education and exam scoring, credit and insurance eligibility, and biometric identification.
EU AI Act Compliance Guide to Requirements: What Providers, Deployers, and GPAI Model Makers Must Do
The EU AI Act requirements below are the ones that matter for planning. The heaviest sit on providers of EU AI Act high-risk AI systems.
Requirements for High-Risk Providers and Deployers
| Role | Core requirements for high-risk systems |
|---|---|
| Provider | Risk management system, data governance, technical documentation, automatic logging, instructions for use, human oversight design, accuracy and cybersecurity, quality management system, conformity assessment, EU database registration, post-market monitoring, serious-incident reporting |
| Deployer | Use the system per its instructions, assign trained human oversight, monitor operation, keep logs, tell workers before workplace use, inform affected people, and run a fundamental rights impact assessment where required |
| Importer | Check the provider completed conformity assessment and documentation before placing the system on the EU market |
| Distributor | Check the required marking and documentation are present before making the system available |
These duties apply to high-risk systems from 2 December 2027 (Annex III) and 2 August 2028 (Annex I). Start earlier anyway. The documentation and oversight work takes longer than the calendar suggests.
EU AI Act General Purpose AI Obligations
Providers of general purpose AI models, the foundation models behind many products, have had duties since 2 August 2025. They must keep technical documentation, share information with downstream providers, publish a summary of training content, and maintain a copyright policy. Models with systemic risk carry extra duties such as evaluations and incident reporting.
The Commission's enforcement powers over these providers began on 2 August 2026, including the ability to request information and levy fines. Models placed on the market before August 2025 have until 2 August 2027.
Building on someone else's model? Then the model provider owns these duties, and you own the ones for the system you built. Get their documentation in writing, because you will need it.
EU AI Act Transparency Rules and AI Literacy
Since 2 August 2026, Article 50 requires providers to make clear that users are talking to an AI, and to mark AI-generated audio, image, video, and text in a machine-readable format where technically feasible. Deployers must disclose deepfakes and AI-generated text published on matters of public interest, unless a human reviewed it. Systems already on the market have until 2 December 2026 for the machine-readable marking.
AI literacy has applied since 2 February 2025. After the Omnibus, providers and deployers are expected to take measures that support staff AI literacy, rather than guarantee a specific level. In practice that still means a short training program and a record that it happened.
EU AI Act Penalties: What Non-Compliance Costs
The penalty regime has applied since 2 August 2026. Article 99 sets three tiers, each capped at a fixed amount or a share of worldwide annual turnover.
| Violation | Maximum fine |
|---|---|
| Prohibited practices (Article 5) | EUR 35 million or 7% of worldwide annual turnover, whichever is higher |
| Breaching operator obligations, including high-risk duties and Article 50 transparency | EUR 15 million or 3%, whichever is higher |
| Supplying incorrect or misleading information to authorities | EUR 7.5 million or 1%, whichever is higher |
For SMEs, including startups, the rule flips: the fine is capped at the lower of the two figures. That softens the ceiling, not the obligation. National market surveillance authorities enforce most of the Act, and the Commission's AI Office handles general-purpose AI.
Two practical points. Article 4 has no standalone EU-level fine, but a literacy gap can count against you if a regulator is already looking at something else. And Member States can add their own penalty rules within the Act's limits.
EU AI Act Compliance Guide for Startups: Six Steps to Take First
The EU AI Act for startups is mostly a sequencing problem, and the EU AI Act timeline gives you room to sequence it. This is the EU AI Act compliance checklist I would give a founder with a small team and a real product to ship.
Practitioners are warning against treating the pause as a reason to wait: in a May 2026 LinkedIn post, Brian Painting, whose profile headline lists AI data governance, said the risk is "using the delay as a reason to put the whole question down until 2027."
- Inventory every AI feature and tool. Include features you ship and AI tools your own team uses. A spreadsheet is enough to start.
- Name your role for each one. Provider, deployer, or both. This decides which duties attach.
- Check for prohibited practices. Compare each feature against the banned list. Emotion recognition on employees is the one that surprises teams.
- Place each feature in a risk tier. Flag anything that touches hiring, education, credit, or biometrics as potentially high-risk.
- Cover transparency and literacy. Label chatbot and generated-content flows, and run a short AI training for staff.
- Build the evidence trail. Keep vendor model documentation, your classification decisions, and records of who approved what.
ISO 42001 and the EU AI Act: Where a Management System Helps and Where It Does Not
ISO 42001 is a voluntary, certifiable standard for an AI management system. The EU AI Act is law. Certifying against one does not make you compliant with the other.
There is real overlap, though. Both ask for AI risk assessment, impact assessment, documentation, defined roles, and human oversight. ISO 42001 also predates the Act and was not written against it, and it is not a harmonised standard, so it does not give a legal presumption of conformity. What it gives you is a structure that makes the Act's work easier to organize and easier to evidence.
Founders ask whether ISO 42001 gets them EU AI Act compliant. It does not, and saying so early saves a lot of confusion. What it does is give you the risk, documentation, and oversight habits the Act will ask you to prove. — Upendra Varma, CTO at ComplyJet
We list both the EU AI Act and ISO 42001 among the frameworks ComplyJet supports. We do not claim that using ComplyJet makes anyone EU AI Act compliant, and we do not give legal advice: deciding whether a system is high-risk is a question for counsel.
What we can do is help you run the ISO 42001 program, including the evidence and documentation work that sits underneath it. For the standard itself, see our ISO 42001 guide and the ISO 42001 certification cost breakdown.
EU AI Act Compliance Guide: Mistakes to Avoid
- Working from the August 2026 high-risk date. It was replaced on 27 July 2026. Planning against it means rushing work the law no longer requires yet, while missing duties that already apply.
- Assuming the delay covers everything. Prohibited practices, general-purpose AI duties, transparency, and penalties are all live.
- Assuming being non-EU means being out of scope. If your output is used in the EU, you are in scope.
- Treating a third-party model as someone else's problem. The model provider owns model duties. You own the system you built on it.
- Skipping the inventory. You cannot classify what you have not listed, and unlisted internal AI tools count.
- Confusing certification with compliance. ISO 42001 helps, but it is not a legal safe harbor.
FAQs
What Is the EU AI Act?
Regulation (EU) 2024/1689, the EU's risk-based law on AI. It entered into force on 1 August 2024 and applies in stages. Its duties depend on your role and on the risk tier of each AI system.
Where Should an EU AI Act Compliance Guide Start for a Startup?
With an inventory of every AI feature and tool, plus your role for each. Everything else, from classification to documentation, depends on that list. The six-step plan above walks through the order.
Who Does the EU AI Act Apply To?
Who does the EU AI Act apply to? Providers, deployers, importers, and distributors of AI systems, plus providers of general purpose AI models. It applies based on where the AI is placed or used, not just where the company sits.
Do Non-EU Companies Have to Follow the EU AI Act?
Yes. Providers placing systems on the EU market are covered wherever they are established, and so are providers and deployers in third countries when their AI output is used in the Union.
When Does the EU AI Act Take Effect?
In stages. Prohibitions and AI literacy from 2 February 2025, general-purpose AI from 2 August 2025, transparency and enforcement from 2 August 2026, and high-risk obligations from 2 December 2027 and 2 August 2028.
Did the EU Delay the EU AI Act?
Partly. The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved Annex III high-risk obligations to 2 December 2027 and Annex I to 2 August 2028. It entered into force on 27 July 2026. Prohibitions, general-purpose AI duties, and transparency were not delayed.
What Are the EU AI Act Penalties?
Up to EUR 35 million or 7% of worldwide turnover for prohibited practices, EUR 15 million or 3% for most other breaches, and EUR 7.5 million or 1% for misleading information. SMEs pay the lower of the two figures.
What Is a High-Risk AI System Under the EU AI Act?
A system that is a safety component of a regulated product, or that falls into an Annex III area such as employment, education, credit, or biometrics. High-risk systems face the strictest requirements.
Is ISO 42001 the Same as EU AI Act Compliance?
No. ISO 42001 is a voluntary management-system standard and the Act is law. They overlap on risk, documentation, and oversight, but certification does not confer legal compliance.
Is There an EU AI Act Compliance Guide to Help With Deadlines?
Yes, the timeline table above lists every date as of 29 September 2026. Re-check it against the AI Act Service Desk before you plan, because guidance and standards are still being finalised.
Related Reading
- What Is ISO 42001? The Complete AI Management System Guide, for the voluntary standard explained
- ISO 42001 Certification: Requirements, Process, and Cost, for the audit process and budget
- ISO 27001 and AI Compliance: The Complete Comparison, for how an existing ISMS relates to AI governance
- GDPR Compliance Requirements, for the privacy law that often applies to the same feature
- ComplyJet Frameworks, for the full list of supported frameworks
Sources and as-of date: All dates and status statements are as of 29 September 2026.
Milestone dates from the European Commission's AI Act Service Desk implementation timeline. Scope from the Service Desk's Article 2 page and penalties from its Article 99 page.
Digital Omnibus adoption path from the European Parliament Legislative Train; publication and entry-into-force dates from Cooley's July 2026 client alert and Abreu Advogados' analysis; changes to deadlines, transparency, and prohibitions cross-checked against Gibson Dunn, Freshfields, and Jones Walker coverage.
Risk tiers from the Commission's AI Act overview. ISO 42001 not being a harmonised standard: DLA Piper (January 2024) and ISMS.online analysis.

