The AI Act deadline that already passed, and what to do about it
The main EU AI Act compliance date was 2 August 2026. A practical guide to which obligations bind a mid-sized company, and which do not.

The EU AI Act entered into force in August 2024 with a staggered timetable, and its broadest compliance date — 2 August 2026 — passed last month. If nobody in your company marked it, you are not unusual. You are also not necessarily exposed. Most of the regulation does not apply to most companies, and the fastest way to get this under control is to work out which small part applies to you.
Provider or deployer
The Act splits duties between the organisation that builds and places an AI system on the market (the provider) and the organisation that uses one under its own authority (the deployer). Nearly every obligation people worry about — conformity assessment, technical documentation, CE marking, quality management systems — sits with providers. If you buy your AI from vendors, you are a deployer, and your duties are lighter and mostly organisational.
Two things bind you regardless. The prohibitions on unacceptable-risk practices have applied since February 2025. So has Article 4, which requires you to ensure a sufficient level of AI literacy among staff who operate AI on your behalf. It has no threshold and no exemption for small firms. Training records are the evidence.
The dates, in order
February 2025 brought the prohibitions and the literacy duty. August 2025 brought obligations for general-purpose model providers and switched on the penalty regime. August 2026 brought the high-risk rules for Annex III use cases and the transparency rules in Article 50. August 2027 covers AI embedded as a safety component in already-regulated products, and older general-purpose models.
One caveat: the Commission has proposed pushing some high-risk deadlines back, tied to the readiness of harmonised standards. Watch it, but do not plan around it. The prohibitions, the literacy duty and the transparency rules are not part of that discussion, and they are the ones a mid-sized company is most likely to be breaching today.
Build a list, not a policy
The first deliverable is an inventory, not a framework. List every AI system in use, including the ones you did not buy deliberately: the CV ranking inside your applicant tracking system, the scoring in your credit or fraud tool, the assistant your finance team turned on last quarter, the chatbot on your website. Shadow AI inside purchased SaaS is where the real classification risk hides. Give each entry a named owner in the business, not in IT.
Then sort each one. Prohibited practices are rare but not exotic — emotion inference in the workplace is banned outright, and several HR and wellbeing tools sell exactly that. Annex III high-risk covers recruitment and worker management, creditworthiness assessment for individuals, education, and access to essential services. Transparency obligations cover chatbots, synthetic media and AI-generated text published to inform the public. Everything else is minimal risk and carries no obligations. In a typical mid-sized company, that is the large majority of the list.
If something lands in the high-risk box
As a deployer you must:
- Use the system according to the provider's instructions, and keep those instructions.
- Assign human oversight to people with the competence, training and authority to override the system.
- Make sure input data is relevant and representative for the intended purpose.
- Retain automatically generated logs for at least six months.
- Inform workers and their representatives before putting the system to work.
- Tell affected individuals when a decision about them involves the system, and explain it on request.
That is a management task, not an engineering programme.
The line you can cross without noticing
Article 25 turns a deployer into a provider — with the full compliance burden — if you put your own name or trademark on a system, modify it substantially, or repurpose a general-purpose system into a high-risk use. Fine-tune a model on your hiring history and point it at candidate screening, and you have crossed that line. Review any internal build against it before it ships, and make procurement ask vendors for the declaration of conformity, the instructions for use and the logging capability you are required to keep.
The stakes and the next step
Prohibited practices carry fines up to €35 million or 7% of global turnover; most other breaches up to €15 million or 3%, with SMEs assessed at the lower of the two figures. The realistic risk for a mid-sized firm is not a headline fine but an enforcement question you cannot answer, from a regulator, an auditor or a customer.
Give this a quarter. Inventory, classify, close the transparency gaps, log your training. Where the classification is genuinely unclear, that is the weight worth handing to someone who does it often — the part we take on when clients ask.