---
title: "EU AI Act Compliance: What Your Business Must Do Now"
description: "AI literacy and transparency rules already apply. High-risk obligations are delayed to late 2027. What to arrange now under the EU AI Act, by risk tier."
canonical: "https://www.whatsnext-ai.com/blog/eu-ai-act-compliance"
published: "2026-09-04T00:00:00.000Z"
updated: "2026-09-03T06:57:12.828Z"
---

# EU AI Act Compliance: What Your Business Must Do Now

AI literacy and transparency rules already apply. High-risk obligations are delayed to late 2027. What to arrange now under the EU AI Act, by risk tier.

![EU AI Act risk tiers, from unacceptable to minimal, on a phased 2025 to 2028 timeline](https://fgzcpjbyiakhjifaciaj.supabase.co/storage/v1/object/public/media/pexels-dusan-cvetanovic-254415846-12541594.jpg)

The EU AI Act sorts AI into four risk tiers: unacceptable, high, limited, and minimal. The ban on prohibited uses and the AI-literacy duty already apply; transparency rules since August 2026. The heavy high-risk duties are deferred to late 2027.

That last sentence is the part most businesses miss. This isn't legal advice, it's a practical reader: what actually applies today, and what you can leave alone for now with a clear conscience.

### What is the EU AI Act, in short?

The EU AI Act (Regulation (EU) 2024/1689) is the world's first broad AI law. It sorts AI systems by risk and attaches obligations to each level. The higher the risk to people, the heavier the requirements. The full definition lives in our [glossary entry for the AI Act](https://www.whatsnext-ai.com/glossary/ai-act); here the question is what it means for you as a business.

The core is a risk-based approach. You don't have to "do the whole law". You have to know which tier your AI use falls into, and then arrange only the duties for that tier.

### The four risk tiers, with an example

- Unacceptable: uses the EU considers unacceptable, which are simply banned. Think social scoring of citizens, or manipulative systems that exploit vulnerable groups. This ban is already in force.
- High-risk: AI that decides about people in sensitive areas: recruitment and selection, access to education, credit scoring, medical applications. This is where the heaviest duties land: documentation, human oversight, a conformity assessment. For most businesses, this is the tier to watch closely.
- Limited-risk: mostly transparency duties. The best known: tell people when they're talking to a chatbot, and label AI-generated content and deepfakes as such (Article 50).
- Minimal-risk: the large majority, such as spam filters, recommendations, and most internal productivity tools. Light to no extra requirements.

Most of what an average business does with AI sits in the bottom two tiers. That's reassuring, but it doesn't excuse you from knowing where you sit.

### What already applies, and what's deferred?

Here's the misconception running through most articles right now. August 2026 was long treated as the big enforcement moment. That's no longer accurate. As of September 2026: the prohibited-practice ban and AI-literacy duty are live, general-purpose AI (GPAI) duties have applied since August 2025, transparency rules since August 2026, and the heavy high-risk obligations are now deferred to December 2027 and August 2028.

In July 2026 the EU adopted the Digital Omnibus ([Regulation (EU) 2026/1744](https://eur-lex.europa.eu/eli/reg/2026/1744/oj), in force since 27 July 2026), which deferred the heaviest high-risk obligations. The full phased timeline:

- 2 February 2025: the ban on prohibited practices and the AI-literacy duty (Article 4) are in force. This applies now.
- 2 August 2025: the obligations for providers of general-purpose AI (GPAI), plus the governance framework and the penalty rules, took effect. This applies now.
- 2 August 2026: the transparency rules (Article 50) apply, unchanged by the Digital Omnibus. Generative systems already on the market have until 2 December 2026 to add machine-readable marking. This applies now.
- 2 December 2027: the main obligations for standalone high-risk systems (Annex III, including AI in employment and education) apply, deferred from the original August 2026 date.
- 2 August 2028: high-risk AI embedded in products already covered by EU product-safety law (Annex I) follows a year later.

What to take from this: the duties hitting you now are AI literacy and transparency, not the heavy high-risk requirements. Those you get more time for. But "more time" isn't the same as "nothing to do", as the next section shows.

### What should you actually arrange now?

Three things, and none of them needs a lawyer as the first step:

- Document AI literacy. Article 4 requires you to give staff who work with AI an appropriate level of understanding. In practice: a short, documented training and a written policy on responsible use. This applies now, and it's the cheapest duty to tick off.
- Get your transparency right. Is a customer talking to a chatbot? Say so. Are you generating content or imagery with AI that could mislead people? Label it. This is Article 50, in force since August 2026.
- Inventory your AI use. This is the most important and the most underrated step. You can't determine a risk tier if you don't know which AI is running in your organisation, visible and invisible. Without that overview, compliance is guesswork.

That third step, knowing what's actually in use, is exactly where most businesses get stuck. AI use creeps into an organisation through loose tools, plug-ins, and individual teams' experiments. More on that blind-spot risk in [can your AI assistant become your biggest security risk](https://www.whatsnext-ai.com/blog/can-your-ai-assistant-become-your-biggest-security-risk).

### Compliance isn't a PDF, it's in how you build

The reflex is to treat compliance as a document: a policy, a checklist, a folder. That helps for the audit, but it doesn't make your AI compliant. The real assurance lives in how a system is built: an auditable trail per decision, human oversight built in rather than bolted on afterwards, and risk classification as part of the system itself.

This isn't theory. For [Backstage IT](https://www.whatsnext-ai.com/cases/backstage-it-ai-readiness-scan) we built an AI Employee Scan that does exactly this. When it assesses the data readiness of 130+ developers, every flag is classified against the EU AI Act's four risk tiers and tagged with any GDPR concern. A data flag cites the regulation and the remediation, not a hand-wave. The scan holds itself to the same standard: a built-in PII check runs over the interview data, so personal information is handled deliberately instead of slipping through unchecked.

The result: 130+ developers assessed in days rather than weeks, at roughly 80x lower cost per developer than one-by-one interviews. Compliance and speed aren't opposites here, because the governance lives in the code.

“AI-readiness used to be a story we told. Now it's a number we can show, per developer and per team, and re-measure every quarter. That completely changes the conversation with a client.” Sander Geels, Co-founder and CEO, Backstage IT.

That's the difference between compliance-by-design and compliance-on-paper. A business that has an AI system built that it owns, with an auditable trail and EU hosting, has the core of the high-risk requirements built in before they start counting in 2027.

### What you shouldn't wait for

The deferral to 2027 is a trap. It sounds like breathing room, but the two duties already in force (AI literacy and transparency) have no delayed date. And the inventory you'll need to prove out your high-risk systems later is far better built now than reconstructed in a panic in the final months of 2027.

Waiting for the deadline doesn't move the work, it stacks it up. The businesses standing calm in 2027 will be the ones that mapped their AI use back in 2026.

### Check your own situation

The practical first question is simple: which risk tier am I actually in? You don't need a consulting engagement to find out. Our [EU AI Act Scan](https://www.whatsnext-ai.com/tools/eu-ai-act-scan) answers six short questions and returns a directional readiness report: your risk tier, the priority gaps, and where to start. A free, self-serve first step.

If you then want to pressure-test what the outcome means for your situation, or you're unsure your self-assessment holds up, [book a free consultation](https://www.whatsnext-ai.com/contact). We'll validate the risk tiering and pick the first two moves worth making, well before enforcement lands. And if the conclusion is that you need to build something, we'll lay out the [build-versus-buy trade-off](https://www.whatsnext-ai.com/blog/why-hiring-an-ai-agency-beats-building-it-yourself) honestly.

*Sources: the EU AI Act provisions and dates are from Regulation (EU) 2024/1689 and the Digital Omnibus (Regulation (EU) 2026/1744), linked above. The figures of 130+ developers assessed and roughly 80x lower cost per developer are our own first-party results from the [Backstage IT AI-readiness case](/cases/backstage-it-ai-readiness-scan).*
