Think about the rules for cars. Before a new car can drive on public roads, it needs working brakes, seat belts, and lights. Nobody thinks these rules stop people from driving. They just make sure the car does not hurt anyone.
The EU AI Act does the same thing for artificial intelligence. If your company builds or uses AI and has users in Europe, this law is now part of your job. The good news: most of it is common sense, and most AI tools only need a few simple steps.
In this guide, we explain the law in plain words, show the dates that matter, and give you a checklist you can use today.
What Is the EU AI Act?
The EU AI Act is the first big law in the world made just for AI. Its official name is Regulation (EU) 2024/1689. It entered into force on 1 August 2024, and its rules switch on step by step until 2028.
The main idea is simple: the more an AI system can hurt people, the more rules it must follow. A spam filter gets almost no rules. An AI that decides who gets a loan or a job gets a lot of rules. Some AI uses are banned completely.
The law wants three things:
- AI that is safe, so it does not harm people's health or safety.
- AI that respects people's rights, so it does not treat anyone unfairly.
- AI that is honest, so people know when they are talking to a machine or looking at fake content.
In July 2026, the EU updated the law with a package called the AI Omnibus. It gave companies more time for the strictest rules and added new bans. We use the updated dates everywhere in this article.
If you want the bigger picture of how to run AI safely inside a company, read our guide on why AI transformation is a problem of governance.
Who Has to Follow the EU AI Act?
Short answer: almost anyone whose AI touches people in the EU.
Your company does not need an office in Europe. If a US startup sells an AI tool to a company in Germany, or if the results of its AI are used in France, the law can apply.
The law gives different jobs to different players. The two you will meet most often are the provider and the deployer.
One thing surprises many teams. A deployer can become a provider. This happens if you put your own name on someone else's high-risk AI system, change it in a big way, or use it for a new high-risk purpose. For example, if you take a general chatbot and turn it into a tool that scores loan applications, you now carry the provider's duties.
What about OpenAI, Anthropic, and other model makers? Big AI models like GPT or Claude are called general-purpose AI models. The companies behind them have their own rules, which started on 2 August 2025. If you build a product on top of these models, you still have your own duties for your product.
The Four Risk Levels, Explained Simply
The whole law is built like a pyramid. At the top are a few AI uses that are banned. At the bottom are the many everyday tools that have almost no rules.

Many everyday business tools land in the bottom two levels. A support chatbot, an internal assistant, or a tool that writes marketing drafts is usually transparency risk or minimal risk.
The tricky part is that risk depends on the use, not on the technology. The same language model can be minimal risk when it summarizes meeting notes and high risk when it ranks job candidates.
Key EU AI Act Dates You Should Know
The law does not switch on all at once. It works like a staircase, with a new step every few months. In July 2026, the AI Omnibus moved the high-risk steps further out.

The delay for high-risk systems is not a reason to wait. Building documentation, logs, and human checks takes months, and it is easier to plan them from day one than to add them to a finished product.
What Happens If You Break the Rules?
The fines are big on purpose. Like GDPR, they are based on a company's worldwide yearly revenue, so they matter even for large companies.
Are the fines real today? Yes. The fines chapter has applied since 2 August 2025. That means a company using a banned AI practice or breaking the transparency rules can be fined right now. The high-risk rules are different: they are not in force yet, so nobody can be fined for them until December 2027 or August 2028.
As of September 2026, we could not find an official public record of an EU AI Act fine against a named company. Each EU country is still setting up its AI regulator, and some are slower than others. So the rules are live, but enforcement is just getting started.
For small and medium companies, including startups, the law uses the lower of the two numbers. That is fair, but even the lower number can hurt a young company.
Fines are not the only risk. A regulator can also order you to take an AI system off the market. For many companies, losing a product or a big EU customer is worse than the fine itself.
EU AI Act Compliance Checklist
You do not need a legal team to start. Use this checklist like a pre-flight check. The first part is for every company that uses AI. The second part is only for high-risk systems.
Part 1: For every AI system
Part 2: Extra steps for high-risk systems
How to Run a Quick EU AI Act Self-Audit
An audit sounds scary, but the first round can take an afternoon. Here is a simple way to do it.
- Open your AI list. Take the list from the checklist above.
- Run each tool through the EU AI Act Compliance Checker. The European Commission made a free online tool for this: the EU AI Act Compliance Checker. You answer short questions about your AI system, and it shows which rules may apply to you and what your duties could be as a provider, deployer, or other player.
- Mark the gaps. For each tool, note what is missing: a chatbot notice, a content label, a training session, a vendor contract, a log.
- Fix the easy things first. Transparency notices and team training are quick wins, and they are already required.
- Plan the big things. If a tool is high risk, plan documentation, logging, and human oversight now, before the December 2027 deadline.
- Repeat every time something changes. A new feature or a new use case can move a tool to a higher risk level.

A quick note: the Compliance Checker is in beta, and it is not legal advice. It is a great way to see where you stand, but for high-risk systems you will still need a proper review with legal and technical experts.
How Akveo Builds Compliance-Safe AI Software
At Akveo, we build AI products like AI agents and conversational AI assistants for our clients. For us, safe data and safe models are not an extra feature. They are the starting point of every project.
Here is how our CTO, Evgeny Lupanov, describes our approach to AI data governance:
We build on providers like OpenAI and Anthropic, which offer enterprise-grade no-training policies and Zero Data Retention options, ensuring your data isn't used to train foundation models.
When stricter compliance is required, we deploy the same AI models through AWS Bedrock or Microsoft Azure AI. AWS and Microsoft host the models within their own cloud infrastructure, so your data stays inside your existing cloud environment and compliance perimeter, while delivering the same model capabilities.
Evgeny Lupanov, CTO at Akveo
In simple words: your data is not used to teach public AI models, and when you need extra protection, the AI runs inside the cloud you already trust.
Here is what this looks like in a real project. For a smart manufacturing client in Germany, we built Factory Copilot, an AI chatbot that lets plant operators and managers ask questions about factory data in plain language. It pulls answers from SQL databases, PDF manuals, REST APIs, Azure IoT Hub telemetry, Power BI reports, and SAP ERP. The AI runs on Azure OpenAI (GPT-4) inside the Microsoft Azure environment, and role-based access control and encryption make sure users only see the data they are allowed to see. The result: 50% faster data retrieval, delivered in 5 months, with no trade-off on data protection.
We also build AI products for other European companies, like an AI-powered language learning platform in Czechia built on OpenAI, and a virtual car mechanic app in Sweden built on Anthropic Claude and launched in 1 month.
Compliance also gets easier when the engineers who build the AI work right next to the people who use it. Questions about data, users, and risk then come up early, not after launch. We explain this way of working in our guide to forward deployed engineering.
If you want to see how we bring AI into software delivery in general, take a look at our free AI-Enabled Software Delivery playbook.
Common EU AI Act Mistakes to Avoid
Wrapping Up
The EU AI Act can look huge, but the core idea fits in one sentence: the more your AI can affect people's lives, the more care you must show. For most teams, that means knowing which AI they use, being honest with users, training their people, and protecting their data.
Some rules and fines are already live, and the strictest rules arrive in December 2027 and August 2028. The best time to prepare is while you are still building, not after a regulator or a big customer asks questions.
This article is for general information only and is not legal advice. For decisions about a specific AI system, talk to a qualified legal expert.
{{cta}}
FAQ
Is the EU AI Act already in force?
Yes. The law entered into force on 1 August 2024. Bans on certain AI practices and AI literacy duties apply since 2 February 2025, the fines chapter since 2 August 2025, and transparency rules since 2 August 2026. High-risk rules start on 2 December 2027 and 2 August 2028.
Does the EU AI Act apply to US companies?
Yes, if their AI systems are used in the EU or their AI results are used there. Having no office in Europe does not change that.
What is the EU AI Act Compliance Checker?
It is a free online tool from the European Commission. You answer questions about your AI system, and it shows which rules may apply to you. It is in beta and is not legal advice, so use it as a first step.
What are the fines under the EU AI Act?
Up to €35 million or 7% of worldwide yearly revenue for banned AI practices, up to €15 million or 3% for most other violations, and up to €7.5 million or 1% for giving wrong information to authorities. For small and medium companies, the lower number applies.
Did the AI Omnibus cancel the high-risk rules?
No. It only moved the start dates. Stand-alone high-risk systems now have until 2 December 2027, and AI inside regulated products has until 2 August 2028.






