Your business is in scope for the EU AI Act.
Its regulators have been able to enforce it since 2 August 2026.
The EU AI Act applies to any business — anywhere in the world — with EU employees, EU customers, or EU operations. Not just EU companies. If you use AI tools that produce outputs EU users see, you have compliance obligations. Most businesses don't know this yet.
EU AI Act transparency duties enforceable since 2 August 2026
See the full enforcement timeline →Important
The transparency duties land on one date, they apply to you at any size, and there is no "wait and see" option.
From 2 August 2026, the Article 50 transparency duties are enforceable. Businesses that interact with EU customers or employees using AI — regardless of size, regardless of country — are in scope on day one. The Act does make allowances for smaller firms elsewhere: simplified technical documentation (Article 11), priority sandbox access (Article 62), lighter quality-management duties for microenterprises (Article 63), and fines capped at the lower figure (Article 99(6)). None of them delays the transparency duties above, and none of them applies automatically — you have to have done the work. If you haven't started, you are already behind.
Not sure if you're in scope? Answer 7 questions and get your free EU AI Act exposure report — instant, no sign-up.
Take the Free Check →Most businesses think the EU AI Act doesn't apply to them. They're wrong.
The EU AI Act has the same extra-territorial reach as GDPR. You don't need to be based in the EU to be in scope. You need to have a connection to the EU.
If your website, product, or service is used by people in EU member states, you're in scope.
Any AI used in HR decisions, performance reviews, or hiring that affects EU-based staff triggers deployer obligations.
Supply chain obligations mean your AI practices may need to meet EU standards even in B2B contexts.
Article 50 transparency obligations apply whenever an AI system — chatbot, recommendation engine, content generator — produces outputs that EU citizens interact with.
Fines for non-compliance: up to €35 million or 7% of global annual turnover, whichever is LOWER for a small or medium business — in practice 7% of turnover.
The EU AI Act is already in force. Here's what's live.
The EU AI Act becomes law. The clock starts.
Unacceptable-risk AI systems (social scoring, certain biometric uses) are prohibited. Any business using these practices is already non-compliant.
Rules for the providers of general-purpose AI models (including ChatGPT, Copilot, Claude) have applied since this date. The Commission's power to fine those providers (Article 101) followed on 2 August 2026.
Article 50 transparency disclosures are enforceable, and national regulators have their enforcement powers. This is the milestone that affects most businesses. The duties on businesses using high-risk AI (Article 26) were moved later by the Digital Omnibus — see below.
New prohibitions take effect and the transitional period for marking AI-generated content under Article 50(2) closes.
Obligations for stand-alone high-risk systems — recruitment, credit scoring, education, essential services — apply. Deferred from August 2026 by the Digital Omnibus, adopted 29 June 2026.
High-risk AI embedded in regulated products (medical devices, machinery, vehicles) comes into scope under Annex I.
Article 4 — AI literacy
The Act expects you to help your staff understand the AI they use. Here is what that means in practice.
Article 4 asks any business deploying AI to take measures that support the AI literacy of the people using it — taking into account what those people already know, and what the tool is being used for. It does not demand a set level from any one person. It is not a training certificate you buy once. It is four things you keep doing.
-
01
Know what you run
Every AI tool actually in use, who uses it, and what it touches. Most businesses find tools nobody had written down.
-
02
Set the bar per role
What each role needs to understand, scaled to the harm that role could do with the tool. A receptionist and a recruiter do not need the same thing.
-
03
Build it into the work
Training that lands where the tool is used, not a slide deck nobody opens — and a record that it happened.
-
04
Show it is working
Evidence you can hand a regulator, and an honest list of the gaps still open.
Then round again. New tool, new starter, new use for an old tool — each one reopens step one. That is why it is a cycle and not a checklist, and it is the part most businesses get wrong.
Article 50 — transparency
If a person cannot tell they are dealing with AI, you have to tell them.
This is where most ordinary businesses land — not the high-risk tier, just the duty to say so. Four situations, four sentences you owe someone. These duties have been enforceable since 2 August 2026.
-
If you run
A chatbot or virtual assistant an EU user can talk to — including a basic customer service bot.
→You must sayThat they are talking to an AI, not a person.
-
If you publish
Text, images, audio or video an AI generated.
→You must sayThat it was AI-generated, labelled so a machine can read it too.
-
If you use
Emotion recognition, or systems that sort people by biometric characteristics.
→You must sayWhat the system is, to the people it is pointed at.
-
If you produce
A deepfake — synthetic media of a real person or event.
→You must sayClearly, that it is artificial.
The catch. None of this depends on your size, your sector, or whether you built the AI yourself. If an EU resident meets it, the duty is yours — including on a bot you bought from someone else.
Article 25 — the one-way door
You bought the AI in. The law can still treat you as the company that made it.
Most businesses are deployers — you use a tool somebody else built. Three things flip you to provider, and with it the full set of maker's obligations. It is easy to trip by accident, usually by branding.
First, the bit most write-ups leave out. This switch only applies to high-risk AI. If your use is not high-risk — an ordinary customer service chatbot is not — Article 25 does not reach you at all. Anyone telling you that fine-tuning a model always makes you a provider is overstating it.
You are a deployer
You use a high-risk system built by someone else. You owe human oversight, monitoring, keeping the logs, and telling the people affected.
- Put your own name or trademark on it.
- Substantially modify it.
- Use it for something it was not sold to do, and that use is high-risk.
You are the provider
The law now treats you as its maker: conformity assessment, technical documentation, quality management, EU database registration.
Where this actually bites. White-labelling. If a high-risk tool carries your logo rather than your supplier's, you may already have walked through the door without anyone deciding to.
Using ChatGPT, Copilot, or any AI tool with EU users? You're already in scope.
Most businesses think the EU AI Act only affects AI developers. It doesn't. It affects any business that deploys or uses AI systems — which means almost every business today.
- ChatGPT or Copilot used to produce content that EU customers see
- AI chatbot or virtual assistant interacting with EU users (Article 50 disclosure required)
- AI-assisted hiring, performance review, or HR decisions involving EU employees
- AI recommendation engines showing products or content to EU customers
- AI credit scoring, insurance pricing, or financial decision-making affecting EU citizens
- Any AI system making or influencing decisions about education, housing, or legal services for EU persons
28 dates that decide whether you are compliant.
14 of them have already passed.
Europe is one line of 9. The EU AI Act is the busiest line, and not the only one. Yours is marked. The others reach the same business through its customers, its staff and its suppliers, wherever it is established.
Europe this page
- in force Obligations for general-purpose AI models.
- in force Article 50 transparency duties and enforcement powers for national regulators.
- coming New prohibitions, and Article 50(2) marking of synthetic content.
- coming Every Member State must have an AI regulatory sandbox running.
- coming High-risk obligations for Annex III systems — including AI used in recruitment, credit scoring, education and essential services.
- coming High-risk obligations for Annex I systems — AI embedded in products already covered by EU product safety law.
United Kingdom
- in force Most Part 5 data protection provisions of the Data (Use and Access) Act 2025, including the wider lawful bases for solely automated decisions and the safeguards that come with them.
- in force The duty on controllers to operate a complaints procedure and respond to data protection complaints within set time limits.
United States
- in force New York City Local Law 144 — an employer or agency using an automated employment decision tool for a New York City job needs a bias audit within the past year, published results, and notice to candidates.
- in force Washington My Health My Data Act (RCW 19.373) — consent before collecting or sharing consumer health data and a published health data privacy policy, for any business targeting Washington consumers; small businesses from 30 June 2024. A breach is an unfair practice under the Consumer Protection Act.
- in force Utah Artificial Intelligence Policy Act (SB 149, 2024) — a business using generative AI with a consumer must say so when the consumer clearly asks; licensed professions must disclose it up front in high-risk interactions. Narrowed by SB 226 from 7 May 2025, with a safe harbour for disclosing at the start.
- in force Texas HB 149, the Responsible Artificial Intelligence Governance Act — prohibited uses, government AI disclosure, and Attorney General enforcement.
- in force California SB 942, the AI Transparency Act — free AI detection tool and latent provenance disclosure for large generative AI providers. Delayed from 1 January 2026 by AB 853.
- coming Colorado SB 26-189 — developer and deployer duties for automated decision-making technology used in consequential decisions. It repealed and reenacted SB 24-205, which never took effect. California SB 1050 (Chapter 246, Statutes of 2026) — an advert shown in California that prominently features an AI-generated performer who looks or sounds human must say so clearly, in words like "this performance features a synthetic performer". Any size of business; enforced as false advertising. California CCPA regulations on automated decisionmaking technology (Cal. Code Regs. tit. 11, s. 7200) — a business using ADMT for a significant decision about a consumer must give pre-use notice, opt-out and access rights. In force 1 January 2026; businesses already using ADMT must comply by this date. Only businesses within the CCPA. Connecticut Public Act 26-15, sections 4 to 6 — duties on operators of AI companions, including detecting and responding to signs of self-harm. Washington HB 2225 (Chapter 168, Laws of 2026) — AI companion chatbots must disclose that they are not human, with safeguards for minors and a private right of action. A customer-service bot that does not sustain a relationship is excluded. Oregon SB 1546 (Chapter 85, Oregon Laws 2026) — operators of AI companions must tell users they are not talking to a person, keep a protocol for users who express thoughts of suicide or self-harm, and add safeguards for minors; a user who is harmed can sue. Software used solely for customer service, business operations or productivity is excluded.
- coming Idaho Conversational AI Safety Act (S 1297, Session Law Chapter 249 of 2026; Idaho Code Title 48, Chapter 21) — a conversational AI service open to the public must say it is AI where a person could be misled, answer prompts about suicide with a crisis referral, and protect account holders who are minors. Enforced by the Attorney General. A chatbot used only for customer service or a business's own operations is excluded.
- coming Connecticut Public Act 26-15 (Substitute SB 5, 2026), sections 7 to 12 — any business doing business in Connecticut that uses an automated employment-related decision technology for a hiring, promotion or discipline decision must disclose it and give written notice before the decision. No size threshold. A breach is an unfair trade practice.
- coming California CCPA regulations, s. 7157 — risk assessments conducted in 2026 and 2027 must be submitted to the California Privacy Protection Agency by this date.
Canada
- in force Ontario ESA / O. Reg. 476/24 — a publicly advertised job posting must disclose the use of AI to screen, assess or select applicants. Employers of 25 or more, including where a third party screens on their behalf.
Australia
- coming Privacy Act 1988 (Cth), APP 1.7 — a privacy policy must say what kinds of personal information a computer program uses to make decisions that could reasonably be expected to significantly affect a person, and what kinds of decisions those are — the automated decision-making (ADM) transparency obligations, regulated by the OAIC.
United Arab Emirates
- in force DIFC Data Protection Regulation 10 — a business deploying an autonomous or semi-autonomous system that processes personal data must tell users, on first use, what the system decides for itself, what it was built to do and what it does with the output.
Saudi Arabia
- in force The Saudi Data and AI Authority's grace period under the Personal Data Protection Law ends, and with it the undertaking not to apply penalties. The authority has said it may extend the grace period for a business that gives it good reason.
South Korea
- in force Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust in force. A business in the AI industry must tell users in advance where a product runs on generative or high-impact AI, and label what generative AI produces. It applies to conduct outside Korea that affects the Korean market or its users.
China
- in force Personal Information Protection Law in force. A business outside China that handles the personal information of people in China — to offer them products or services, or to analyse their behaviour — must have a lawful basis for it and must appoint a representative or a dedicated body inside the country. Nothing in the duty turns on how much data is held.
The Act arrives in phases, and the phases have already moved once.
A framework built for one deadline is out of date at the next. The obligations land in stages — transparency duties, then the high-risk regimes for recruitment, credit and essential services — and those stages have already been rescheduled once, by the Digital Omnibus. Anyone who papered over the original dates now holds a document describing a timetable that no longer exists.
What does not move is what the Act asks you to be able to show: which AI systems you run, what each one is used for, who is accountable for it, what you assessed before deploying it, and how a person can query a decision it made. Build to that and a date change is an update rather than a rewrite. That is what the annual renewal is for: when Brussels shifts a phase, your framework shifts with it, and you are not paying to start again.
Not sure which phase catches you first? Seven questions, no sign-up.
Take the free check →
Your customers decide which law
applies to you. Not your address.
Where your customers are, where your staff are and where your AI has effect — those decide, not where the business is registered. We write frameworks to four legal systems, and serve four more on request.
- United Kingdom UK GDPR, in force now. The Data (Use and Access) Act added automated-decision duties from 5 February 2026.
- European Union The EU AI Act. General-purpose AI obligations already apply; regulators have had enforcement powers since 2 August 2026.
- United States State by state, not federal. Texas from 1 January 2026, California from 2 August 2026, Colorado from 1 January 2027.
- Canada PIPEDA plus provincial law. Ontario's AI hiring disclosure rules applied from 1 January 2026.
EU AI Act Compliance Packages.
Every package builds a documented compliance position for your business before the August 2026 deadline. Prices in GBP — approximate equivalents shown. Stripe accepts all major cards from any country.
~$630 · ~€580
- AI literacy policy (Article 4 compliance)
- Prohibited AI use register
- Article 50 transparency disclosures for customer-facing AI
- AI tool inventory template
- Plain-English employee guidelines
Best for: businesses using only low-risk AI tools (ChatGPT for internal notes, basic automation) with limited EU customer interaction.
In your inbox by the end of the business day
Buy now — £497 →~$1,265 · ~€1,165 per year
- Everything in EU AI Essentials
- Risk classification of all AI tools in use
- Human oversight procedures (Article 26)
- Deployer obligations checklist
- Staff training documentation
- Basic impact assessment template
- ISO/IEC 42001 and NIST AI RMF alignment map
Best for: businesses with EU customers or employees who use AI in any customer-facing or operational capacity.
In your inbox by the end of the business day · Covers you for 12 months, renews yearly
Buy now — £997/year → or book a scoping call first~$2,530 · ~€2,330 per year
- Everything in EU AI Foundation
- Full Fundamental Rights Impact Assessment (FRIA)
- Incident response procedure
- Data governance documentation for AI systems
- Monitoring and logging procedures
- ISO/IEC 42001 and NIST AI RMF alignment map
- Your AI compliance dashboard: a to-do list, your AI tools, staff sign-off, an incident log, every document and a shareable statement
Best for: regulated businesses, businesses using high-risk AI, or any business that wants a fully auditable compliance position.
In your inbox by the end of the business day · Covers you for 12 months, renews yearly
Renews yearly — policy updates applied as new guidance is issued throughout your cover.
Buy now — £1,997/year → or book a scoping call firstFoundation and Complete are annual — your fee covers 12 months of protection, with policy updates applied as the Act evolves and new guidance is issued, and renews yearly so your cover never lapses.
The same work, done in-house.
144 pages of primary law to read, 12 documents to write, and 15 records a year to keep afterwards. Costed against what a member of staff on the median UK salary actually costs an hour:
£2,708
Your own staff — 104 hours of their time
£997/year
EU AI Act Compliance — in your inbox by the end of the business day
Bought, built and delivered without a meeting.
Buy it
Buy it on this page. There is no call to book and no slot to wait for. If you would rather talk it through first, that option is there too.
Tell us about you
A dozen questions: your sector, your size, where in the EU you operate, the AI systems you use, and what those systems decide.
It arrives
Each system you named is placed in its risk tier and your framework is written around it — policies, procedures, disclosures and impact assessments — in your inbox by the end of the business day. PDF and Word, the full pack and every document on its own.
It stays current
For 12 months we watch the Act’s phases and the guidance under it. When something moves, we confirm it against the official text, rebuild your documents and email them to you. Renews yearly.
Straight answers.
Does the EU AI Act apply to a UK or US business?
Yes — if your products, services, or AI outputs reach EU residents or employees, the Act applies to you regardless of where your business is based. This mirrors how GDPR works: it's based on where your users are, not where you are. A UK business with French customers, or a US SaaS company with German users, is in scope.
What is Article 50 and do I need to comply?
Article 50 requires you to tell people when they're interacting with an AI system — chatbots, automated content, AI-generated images, and emotion recognition tools all require disclosure. If any EU user interacts with AI on your platform, this applies from 2 August 2026.
What counts as "high-risk" AI under Annex III?
Annex III lists specific high-risk categories: AI used in employment decisions (CV screening, performance scoring), AI in education (automated student assessment), AI in financial services (credit scoring), AI in essential services (insurance, healthcare), and AI used in law enforcement or border control. If you use AI in any of these areas and your decisions affect EU citizens, you face the strictest compliance obligations.
I only use ChatGPT for internal notes — am I in scope?
If the outputs never reach EU customers or employees, and you're not making consequential decisions with it, your obligations are minimal — an AI literacy policy and a prohibited use register covers you. That's the EU AI Essentials tier. If you're using it to draft customer-facing content, emails, or support responses that EU users see, Article 50 transparency obligations apply.
What are the fines for non-compliance?
They are set in three tiers. Using a prohibited AI practice: €35M or 7% of global annual turnover. Breaching high-risk obligations, and most other duties: €15M or 3%. Supplying incorrect information to a regulator: €7.5M or 1%.
Which of the two figures applies depends on your size, and this is the part most summaries get backwards. For a large undertaking it is whichever is higher. For a small or medium business Article 99(6) makes it whichever is lower — so in practice the percentage of turnover, never the headline euro ceiling. Enforcement sits with national market surveillance authorities alongside the European AI Office.
Is this legal advice?
No. We produce compliance documentation frameworks and policy documents — we are not EU legal advisers. For businesses in regulated sectors (financial services, healthcare, legal) with high-risk AI systems, we recommend reviewing your documentation with EU-qualified legal counsel. For most SMBs using standard AI tools, our frameworks provide a solid, well-evidenced compliance position.
EU regulators have had enforcement powers since August 2026.
Get compliant now.
Most businesses in scope haven't started yet. Getting your documentation in place now means you can answer a regulator today — and you won't be scrambling when the high-risk duties follow in December 2027.
See the Packages →Or book a free 20-minute call to discuss your specific situation — hello@opsintel.io