The risk levels
Unacceptable risk practices, such as social scoring or certain manipulative or biometric uses, are prohibited. High risk systems, for example AI used in recruitment, credit scoring, education or critical infrastructure, must meet requirements on risk management, data quality, documentation, human oversight, accuracy and cybersecurity. Limited risk systems, such as chatbots and generated content, have transparency obligations. Most other uses, minimal risk, have no specific obligations.
Timeline after the Digital Omnibus
The prohibitions have applied since February 2025 and the rules for general purpose AI models since August 2025. The transparency obligations in Article 50 apply from August 2026. The Digital Omnibus on AI, in force since 27 July 2026, moved the deadline for high risk systems listed in Annex III to 2 December 2027, and for AI embedded in regulated products to 2 August 2028.
Who it affects
Not only AI developers. Companies that use AI systems in their operations are deployers and have their own duties, especially for high risk uses: using the system as instructed, ensuring human oversight, monitoring it and keeping logs. Fines for prohibited practices can reach 35 million euros or 7% of global annual turnover. In Spain, the supervisory authority is AESIA.
Where to start
The first step is an inventory of the AI systems in use and their risk level. Our free EU AI Act Checker gives a first indication of where a company stands. ISO 42001 offers a management system to organise AI governance, and the full text is on EUR-Lex.




