Most writing about the AI Act was produced for large corporations. This was not. It assumes you have between ten and two hundred and fifty people, that you use AI rather than build it, and that you have very little time. It also assumes you may not be in the EU at all — which, as it turns out, changes less than you would hope.
Very probably yes — but almost certainly less heavily than you fear. The regulation has no headcount threshold and no turnover threshold. It distinguishes by role and by risk, not by size.
Your role decides most of it. A company that only uses AI tools is a deployer, and the catalogue of duties for deployers is short. You become a provider, with substantially more obligations, only when you place a system on the market or put it into service under your own name or trade mark, or when you substantially modify one or change its intended purpose — putting a branded chatbot on your website is the classic example.
This is the part that catches English-speaking readers, and it is worth more than a footnote. Article 2 defines the scope by effect. It covers:
The third limb is the one that surprises people. It does not ask where your servers are, where your company is registered, or whether you have any EU entity. It asks where the output lands.
Conversely, a purely domestic US business whose AI output never reaches the EU is not brought into scope by this regulation. Being honest about that boundary matters as much as being honest about the reach.
There is one further asymmetry worth knowing. Providers outside the EU that place systems on the EU market must appoint an authorised representative established in the Union under Article 22 — and Article 22 is in the penalty catalogue. Deployers do not carry that duty. If you are unsure which side of the provider/deployer line you sit on, that question is worth resolving before anything else.
The Digital Omnibus was finally adopted on 29 June 2026 and entered into force in July 2026. It is applicable law, not an announcement, and the postponements in it are real.
| Date | What applies |
|---|---|
| 2 Feb 2025 | Prohibited practices (Art. 5) · AI literacy obligation (Art. 4) |
| 2 Aug 2025 | Obligations for general-purpose AI models, governance, national penalty regimes |
| 2 Aug 2026 | Transparency obligations (Art. 50) · national market surveillance operational |
| 2 Dec 2026 | Art. 50(2) extends to systems already on the market · further prohibitions take effect |
| 9 Dec 2026 | Transposition deadline of the new EU Product Liability Directive (EU) 2024/2853 — software and AI count as products |
| 2 Dec 2027 | High-risk obligations for standalone systems — postponed |
| 2 Aug 2028 | High-risk obligations for AI embedded in regulated products — postponed |
The short version: if you build high-risk AI, you have gained time. If you merely use AI, your dates have already passed.
9 December 2026 is the transposition deadline for Directive (EU) 2024/2853 on liability for defective products. It brings software and AI systems within the definition of a product, extends the notion of damage to include destruction or corruption of data, and eases the burden of proof for claimants in technically complex cases.
That is a civil liability regime, not a regulatory one — it does not depend on an authority noticing you. It depends on someone suffering damage and bringing a claim. For a company deploying AI in customer-facing processes, that is a more probable route to a bad afternoon than a market surveillance inspection.
Everything beyond that — conformity assessment, technical documentation, registration in the EU database, post-market monitoring — concerns providers and high-risk systems. That is a small minority of mid-sized companies, and it is worth checking whether you are in it rather than assuming either way.
Of the eight areas in Annex III, only two come up regularly for smaller companies:
If you deploy something in either area: document it, escalate it to management, and take legal advice. The December 2027 deadline buys you time to comply, not time to work out whether you are in scope. The classification should be on paper now.
Enforcement sits with the national market surveillance authorities designated by each member state, coordinated at Union level by the European AI Office and the AI Board. Which authority that is varies by country — some have handed it to their telecoms or data protection regulator, others created something new. If you sell into several member states, you may deal with more than one.
The Commission also runs an AI Act Service Desk as a single entry point for questions, aimed particularly at SMEs, alongside the regulatory sandboxes that each member state was required to establish.
Realistically, authorities do not open with fines. They open with a request for information and an order to remedy. A company that can produce its inventory, its policy and its training records at that point is through the process.
And the more frequent trigger is not a regulator at all. It is a supplier questionnaire from a business customer. The five questions on those have become remarkably standardised: your register of AI systems, your internal policy, your training status, your named responsible person, and whether you deploy any high-risk systems. That is the deadline that turns out to be real, and it arrives without warning.
For a company of around fifty people that uses AI rather than builds it:
That is the realistic envelope. Anyone trying to sell you a six-figure consulting project is describing a different size of company — one with a legal department, a model risk function and an obligation to answer to a supervisory board. If that is you, this page is not the right one.
If it is not, the free quick check takes two minutes and tells you which of the ten points you have already covered. Where the gaps warrant more than a checklist, the compliance kit supplies the register, the policy template and the training material as a package.
Yes. There is no headcount or turnover threshold. The regulation distinguishes by role and risk, not by size. For companies that only use AI, however, the catalogue of duties is short.
It can. Article 2 covers providers placing AI systems on the EU market irrespective of establishment, deployers located in the Union, and providers and deployers in third countries where the output produced by the AI system is used in the Union. A UK, US or Swiss firm whose AI output reaches people in the EU is in scope for that activity.
Deployers use an AI system in a professional capacity — that covers most companies. Providers develop a system or place it on the market under their own name. A company that offers a bought-in system under its own brand, substantially modifies it, or changes its intended purpose becomes a provider in law.
Partly. The Digital Omnibus moved the high-risk obligations to December 2027 and August 2028. The date of 2 August 2026 for the transparency obligations and the start of market surveillance was left unchanged.
No such appointment is required by law, unlike the data protection officer under the GDPR. In practice it has become standard, because the duties fall on the company and without a named person nobody discharges them. It is also the first question on most supplier questionnaires.
For a company of around fifty people: half a day to a day for initial set-up, roughly thirty minutes of training per person, and two to six hours a month on an ongoing basis.
That is the transposition deadline for the new EU Product Liability Directive (EU) 2024/2853, under which software and AI systems count as products. It is a civil liability regime: it eases the burden of proof for claimants and extends damage to include corruption of data. It does not depend on a regulator taking an interest.
The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.
Start the quick check — free