HomeInfosec Essentials

EU AI Act: Risk Levels, Rules, and Compliance Deadlines

September 25, 2026
•
1 min
EU AI Act: Risk Levels, Rules, and Compliance Deadlines
In This Article
Key takeaways:
  • The EU AI Act is the first broad, dedicated AI law in the world. It entered into force on August 1, 2024, and phases in obligations through 2028.
  • The regulation sorts AI systems into four risk tiers: unacceptable, high, limited, and minimal. The tier determines which obligations apply.
  • A July 2026 amendment, the Digital Omnibus on AI, pushed the deadline for stand-alone high-risk systems to December 2, 2027, and for high-risk systems embedded in regulated products to August 2, 2028.
  • Extraterritorial scope means any organization whose AI system output reaches people in the EU falls under the law, regardless of where the organization is based.
  • Prohibited practices carry fines of up to 35 million EUR or 7 percent of global annual turnover, among the strictest AI-related penalties anywhere.

What is the EU AI Act?

The EU AI Act is a European Union regulation that classifies AI systems by risk level and sets legal obligations for how organizations build, deploy, and govern them. It applies to providers, deployers, importers, and distributors of AI systems used in the EU, regardless of where the organization is headquartered. The regulation entered into force on August 1, 2024, and phases in prohibitions, transparency duties, and high-risk obligations on a fixed timetable running through 2028.

The EU AI Act is the first law of its kind, as a dedicated, cross-sector framework for AI rather than a set of guidelines or an update to an existing data law. Its stated goal is human-centric AI governance, restricting practices that pose unacceptable risk to safety or fundamental rights while letting lower-risk AI operate under lighter requirements.

The law has drawn wide attention since generative and agentic AI tools moved from pilot projects into daily enterprise workflows, because it is the first regulation to attach binding, tiered obligations directly to how those tools classify, document, and disclose their own risk.

How the EU AI Act Classifies AI Risk

The EU AI Act works by matching an AI system to a risk tier based on its intended purpose and the context in which it operates, not the underlying technology itself. Two systems built on the same model can land in different tiers depending on what they are used for.

Classification generally follows this sequence:

  1. Check the system against Article 5: If it matches a prohibited practice, such as social scoring or certain forms of biometric categorization, it cannot be placed on the market at all.
  2. Check whether the system falls under Annex III: This annex lists specific high-risk use areas, including employment, credit scoring, education, and law enforcement.
  3. Apply the Article 6(3) carve-outs: A system that falls in an Annex III area is not automatically high-risk. It can be excluded if it performs only a narrow procedural task, improves the output of work a person has already completed, detects patterns without replacing human judgment, or performs preparatory work, provided it does not profile individuals.
  4. Check Annex I: Systems embedded in products already regulated elsewhere, such as medical devices or machinery, are classified as high-risk through that separate annex.
  5. Assign the remaining tier: Anything that does not fall into the categories above is limited-risk (subject to transparency duties) or minimal-risk (largely unregulated).

This use-case-driven approach is why the same underlying model can carry different obligations depending on the deployment.

The Four EU AI Act Risk Levels

Risk levelWhat it coversExamplePrimary obligation
UnacceptablePractices banned outrightSocial scoring, real-time biometric surveillance in public spaces (with narrow exceptions)Prohibited from the market entirely
HighSystems in Annex III or Annex I that meet the criteriaHiring and recruitment tools, credit scoring, safety components in regulated machineryConformity assessment, technical documentation, human oversight
LimitedSystems with transparency riskChatbots, deepfake generators, AI-generated contentDisclosure that the person is interacting with or viewing AI output
MinimalEverything elseSpam filters, AI-enabled inventory toolsNo specific EU AI Act obligations

There are four risk levels under the EU AI Act, and most day-to-day enterprise AI tools fall into limited or minimal risk. High-risk classification is narrower than many organizations initially assume, largely because of the Article 6(3) exemptions described above.

Who the EU AI Act Applies To

The EU AI Act uses GDPR-style extraterritorial scope: an organization does not need a physical presence in the EU to fall under the law. If an AI system's output is used by people in the EU, the organization is in scope.

Obligations differ by role:

RoleWhat they doExample obligation
ProviderDevelops an AI system or puts it on the market under its own nameConformity assessment, technical documentation
DeployerUses an AI system under its own authorityHuman oversight, monitoring for misuse
ImporterPlaces a non-EU provider's system on the EU marketVerify the provider's conformity documentation
DistributorMakes a system available on the market without altering itConfirm required documentation accompanies the system
GPAI model providerDevelops a general-purpose AI model such as a large language modelTechnical documentation, transparency about training data, and, for the highest-capability models, systemic-risk evaluation

An organization can hold more than one role. A company that integrates a third-party foundation model into its own product and substantially modifies it may become a provider itself, not only a deployer.

Why the EU AI Act Matters for Data Security Teams

When EU AI Act obligations go unaddressed, organizations face two intersecting problems: regulatory exposure and a data visibility gap that most security teams did not budget for. A hiring tool built on a third-party model, a customer support workflow that calls an external API, and an internal assistant that summarizes documents containing regulated data can each carry different obligations, and each depends on the organization knowing what data those systems touch.

This is a data governance problem before it is a legal one. Security and compliance teams cannot document a system's risk classification, data flows, or human-oversight controls if they do not know the system exists. Shadow AI, tools employees adopt without IT approval, is where this gap shows up first: an unsanctioned AI tool has no conformity assessment, no documented data flow, and no owner accountable for its classification.

The EU AI Act's penalty structure raises the stakes further. Prohibited-practice fines reach 7 percent of global annual turnover, higher than the maximum under GDPR, which makes AI data governance a board-level concern rather than a compliance checkbox.

EU AI Act Compliance Deadlines and the 2026 Digital Omnibus Delay

The EU AI Act applies in phases rather than all at once, and the timeline changed materially in mid-2026. Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, entered into force on July 27, 2026, and pushed back several high-risk deadlines. Organizations working from an older explainer may be tracking dates that no longer apply.

Current milestones:

  • August 1, 2024: The EU AI Act enters into force.
  • February 2, 2025: Article 5 prohibitions and the AI literacy obligation become applicable.
  • August 2, 2025: Governance rules, general-purpose AI model obligations, and the Article 99 penalty framework become applicable.
  • August 2, 2026: General application date. Article 50 transparency obligations apply (with a grace period to December 2, 2026, for systems already deployed before this date). The Commission's Article 101 power to fine general-purpose AI model providers directly also activates on this date.
  • December 2, 2026: Two new Article 5 prohibitions take effect, including a ban on AI systems that generate non-consensual intimate imagery.
  • December 2, 2027: High-risk obligations for stand-alone systems under Annex III become applicable. This is a deferral from the original August 2, 2026, date.
  • August 2, 2028: High-risk obligations for systems embedded in already-regulated products under Annex I become applicable.

Penalties follow three tiers under Article 99: up to 35 million EUR or 7 percent of worldwide annual turnover for prohibited practices, up to 15 million EUR or 3 percent for most other provider and deployer obligations, and up to 7.5 million EUR or 1 percent for supplying incorrect or misleading information to authorities. General-purpose AI model providers face a separate regime under Article 101, enforced directly by the European Commission's AI Office rather than by national regulators.

Common Challenges and Misconceptions

  • Many organizations read the Digital Omnibus delay as a reason to pause AI Act work, but Article 5 prohibitions and Article 50 transparency duties remain on their original dates and are already enforceable.
  • Risk classification is not fixed at the model level. The same underlying AI system can be high-risk in one deployment and exempt in another, based on how the Article 6(3) carve-outs apply to that specific use.
  • Deployer obligations apply even when the AI system itself comes from a third-party vendor. Organizations that only track models they built themselves miss this exposure.
  • Shadow AI tools fall outside classification and documentation processes entirely, since no one has assessed or logged them, which makes them a source of prohibited-practice risk that is hard to detect.
  • Harmonized technical standards needed to demonstrate conformity for Annex III systems are still incomplete even under the deferred timeline, leaving some organizations with an obligation but limited guidance on how to satisfy it.

How to Prepare for EU AI Act Compliance

  1. Inventory every AI system in active use, including tools adopted outside formal procurement. A system cannot be classified if it has not been identified.
  2. Classify each system against Article 5 and Annex III, applying the Article 6(3) exemption logic and documenting the reasoning for each determination.
  3. Map the data each AI system touches, including what it ingests, generates, and shares with third-party models or APIs.
  4. Review vendor and model-provider contracts, particularly where a third-party general-purpose AI model sits inside an internally built product. Documentation gaps at the vendor level become the organization's own evidence gaps.
  5. Build monitoring and audit trails for high-risk and limited-risk systems ahead of their applicable deadlines, rather than waiting until the deferred dates approach.
  6. Assign clear ownership for AI governance across legal, security, and the teams that build or procure AI tools, since EU AI Act obligations cross all three functions.

How Cyberhaven Addresses EU AI Act Compliance

Cyberhaven addresses EU AI Act readiness through a unified data security platform that combines AI Security, DSPM, and Data Lineage to give organizations the visibility that classification and documentation depend on. Rather than treating AI governance as a separate workstream, Cyberhaven connects it to the data the organization already needs to protect.

AI Security surfaces shadow AI tools and monitors what sensitive data flows into and out of sanctioned and unsanctioned AI applications, closing the visibility gap that leaves shadow AI outside classification. Data Lineage traces where that data originated and how it moved before reaching an AI system, supporting the documentation that Annex III and Annex I obligations require. DSPM extends this by classifying the underlying data itself, so security teams can show which data sets an AI system touches and why that matters for its risk tier.

Frequently Asked Questions

What is the EU AI Act?

The EU AI Act is a European Union regulation that classifies AI systems by risk level and sets obligations for providers, deployers, importers, and distributors. It entered into force on August 1, 2024, and phases in requirements through 2028, with extraterritorial scope covering any organization whose AI system affects people in the EU.

Why is the EU AI Act important for enterprise security?

The EU AI Act ties legal obligations directly to how an organization documents, monitors, and governs its AI systems. Security teams need visibility into every AI tool in use, including shadow AI, because undocumented systems carry compliance risk and penalties that reach 7 percent of global annual turnover for the most serious violations.

What are the main components of the EU AI Act?

The EU AI Act's main components are its four-tier risk classification system, role-based obligations for providers and deployers, transparency requirements under Article 50, a separate compliance regime for general-purpose AI model providers, and a three-tier penalty structure under Article 99.

How do organizations implement EU AI Act compliance?

Organizations typically start by inventorying every AI system in use, classifying each against Article 5 and Annex III, mapping the data those systems touch, and reviewing vendor contracts for third-party models. Ongoing monitoring and documentation follow as each system's applicable deadline approaches.

What regulations require compliance under the EU AI Act, and what happens if an organization does not comply?

Non-compliance under the EU AI Act triggers administrative fines rather than a separate regulation. Prohibited practices carry fines up to 35 million EUR or 7 percent of global turnover, most other obligations carry fines up to 15 million EUR or 3 percent, and general-purpose AI model providers face a separate fining regime enforced by the European Commission's AI Office.

What is the difference between the EU AI Act and GDPR?

The EU AI Act and GDPR both carry extraterritorial scope and steep penalties, but they regulate different things. GDPR governs how personal data is collected, processed, and protected. The EU AI Act governs how AI systems are classified, documented, and disclosed based on the risk they pose, independent of whether personal data is involved.