Artificial intelligence (AI) is rapidly becoming embedded in day-to-day business operations – from customer service and marketing to recruitment, credit scoring, and risk management. At the same time, regulators are moving from encouraging responsible AI to actively defining what responsible AI must look like in practice. With the EU AI Act, the European Union has introduced the world’s first regulatory framework, fundamentally changing the expectations placed on organizations that develop, provide or use AI.
Recent amendments introduced through the AI Omnibus, which entered into force on 27 July 2026, have extended selected implementation timelines. However, organizations should not mistake revised deadlines for reduced regulatory scrutiny. Transparency obligations and enforcement mechanisms remain firmly on track. Additionally, regulators continue to expand oversight activities and publish additional guidance.
Understanding the EU AI Act: Key Requirements
The EU AI Act regulation imposes different requirements depending on the type of an AI system and the organization’s role within the AI value chain. While public discussion focuses on high-risk AI systems, the EU AI Act extends far beyond them. Thus, it also introduces prohibited AI practices, transparency obligations, requirements for General-Purpose AI (GPAI) models, governance provisions, and enforcement mechanisms. Together, these elements form a comprehensive framework for trustworthy AI.
Key requirements at a glance
-
Prohibited AI Practices: The regulation prohibits certain AI practices in the EU, including use-cases of social scoring, manipulative AI systems, exploitation of vulnerable individuals, and specific forms of biometric surveillance.
-
High-Risk AI Systems: Organisations should establish risk management and data governance frameworks, technical documentation, record-keeping, human oversight, conformity assessments, and ongoing monitoring for high-risk AI systems. The regulation distinguishes between high-risk AI systems listed in Annex III and Annex I. Annex III covers use cases of recruitment, employee promotion decisions, credit scoring, and insurance risk assessment. In contrast, Annex I applies to AI systems embedded in products already subject to EU product safety legislation and requiring third-party conformity assessments.
- Transparency Obligations: Transparency requirements apply to a broader range of organizations and AI applications. Organizations must disclose when users are interacting with AI and appropriately label AI-generated or manipulated content, including certain deepfakes (images, videos, or audio that have been edited or generated using AI) and synthetic media.
- General-Purpose AI Models: Providers of General-Purpose AI models must meet dedicated requirements relating to technical documentation, information on training content, and risk management. Additional obligations apply to GPAI models that present systemic risks.
- Governance and Enforcement: The EU AI Act is supported by a comprehensive supervisory framework and enforcement regime. Non-compliance may result in significant penalties, with the most serious breaches potentially attracting fines of up to €35 million or 7% of global annual turnover.
Providers and Deployers Under the EU AI Act: Different Roles and Obligations
One of the most important principles of the EU AI Act is that compliance obligations depend on an organization’s role in the AI value chain. Providers are organizations that develop AI systems or GPAI models and place them on the market under their name or trademark. On the other hand, deployers are organisations that use AI systems under its authority, except where the system is used purely for personal, non-professional activities. Thus, an organisation may be a provider, a deployer, or both.
In practice, many organizations participate in multiple stages of the AI lifecycle simultaneously. For instance, a business may deploy third-party AI solutions while also developing internal models or significantly modifying vendor-provided systems. Therefore, identifying the roles performed within the organization is one of the first steps toward understanding regulatory exposure under the EU AI Act.
Requirements for Deployers of AI Systems
Although deployers carry fewer obligations than providers, they remain in focus of the EU AI Act. Deployers are responsible for using AI systems in accordance with the provider’s instructions, maintaining appropriate human oversight, monitoring the operation of AI systems, and ensuring compliance with transparency requirements when individuals interact with AI or consume AI-generated content.
For many organizations, these obligations are particularly relevant because they arise through the everyday use of AI-enabled software rather than through the development of AI itself. As AI capabilities become increasingly embedded within enterprise platforms, cloud services, and business applications, deployers face the growing challenge of identifying where AI is already being used across the organization and understanding which regulatory requirements may apply.
Unsure how the EU AI Act applies to your organization? Contact us for guidance on your role and compliance requirements!
The Heart of the EU AI Act: A Risk-Based Approach
Unlike a one-size-fits-all regulation, the EU AI Act is built around a risk-based approach. Thus, the regulation imposes stricter obligations as the potential impact on people, safety, and fundamental rights increases.
Minimal Risk – Innovation Without Significant Restrictions
Most AI applications fall into the minimal-risk category and remain largely unrestricted. These systems are considered unlikely to create significant risks and therefore remain permitted without additional regulatory requirements. Nevertheless, organizations should continue monitoring these solutions because risk classifications may change as use cases evolve. Examples include: video game AI, spam filters, recommendation engines, demand forecasting and optimization tools.
Limited Risk – Transparency in Focus
Limited-risk systems remain permitted but must meet transparency requirements. Users should be informed when they are interacting with AI or consuming AI-generated content. As generative AI becomes more common, transparency is emerging as one of the most immediate compliance priorities for organisations. Examples include: chatbots, virtual assistants, AI-generated text, AI-generated images and videos.
High Risk – Stricter Controls for Important Decisions
High-risk AI systems are allowed, but they are subject to extensive requirements. Because these systems can significantly impact individuals‘ careers, financial opportunities, or access to services, regulators impose stricter requirements. As a result, organizations must establish robust governance, risk management, documentation, monitoring, and human oversight mechanisms. Examples include: recruitment and candidate screening, employee promotion decisions, credit scoring, insurance risk assessment and pricing from Annex III AI systems, as well as machinery and medical devices from Annex I.
Prohibited Practices banned in the EU
Finally, the EU AI Act prohibits AI practices considered incompatible with European values and fundamental rights. These represent the highest level of regulatory concern and therefore cannot be placed on the market within the EU.
Thus, the challenge is not identifying whether AI exists, but determining where each AI application fits within the risk framework.
The Regulatory Clock: Understanding the Revised EU AI Act Timeline
The AI Act entered into force on 1 August 2024, but its provisions are being phased in over several years. Recent amendments introduced through the AI Omnibus have adjusted certain implementation dates, while leaving other obligations unchanged.
-
1 August 2024 – EU AI Act entered into force.
-
2 February 2025 – Prohibited AI practices became applicable.
-
2 August 2025 – GPAI requirements and penalties became applicable.
-
2 August 2026 – Transparency obligations apply.
-
Deferred → 2 December 2027 – requirements for High-risk AI systems under Annex III become applicable.
-
Deferred → 2 August 2028 – requirements for High-risk AI systems under Annex I become applicable.
- 2030 – Existing systems are expected to meet final compliance milestones.
Despite the shifted timeline for high-risk AI systems, 2 August 2026 remained an important milestone for the application of transparency provisions. Organizations using chatbots, virtual assistants, or AI-generated content should now ensure that the required disclosures and labeling measures are in place.
Regulatory Expectations Continue to Increase Despite Deferred Deadlines
The revised timeline introduced by the AI Omnibus should not be interpreted as a reduction in regulatory expectations. On the contrary, regulators are using this period to strengthen supervisory capabilities, expand oversight activities, and provide additional guidance.
- ECB Focus on AI-Enabled Cybersecurity Threats: The ECB has requested supervised institutions to formalize action plans addressing AI-enabled cybersecurity threats. This demonstrates that supervisory attention is extending beyond AI compliance and into the broader risk landscape associated with AI adoption.
- BaFin Expands AI-Related Supervisory Activity: BaFin has established a dedicated unit responsible for targeted inspections focusing on AI-related cybersecurity risks. At the same time, the authority has publicly highlighted the growing risks associated with AI-driven cyber threats.
- European Commission’s Action Plan on Cybersecurity and AI: The European Commission has launched additional initiatives to evaluate and supervise advanced AI models. These measures are intended to ensure that increasingly capable AI systems remain subject to effective oversight and governance.
- Guidance on AI Act Transparency Requirements: The European Commission has also published further guidance clarifying the scope of transparency obligations under Article 50. Importantly, these requirements apply from August 2026 irrespective of the later deadlines applicable to certain high-risk AI systems.
Key Challenges on the Way to AI Compliance
While some EU AI Act deadlines have been deferred, regulatory expectations continue to increase. Organizations should therefore use this time to address the practical challenges emerging from AI usage rather than delaying their efforts.
-
AI Inventory and Visibility: Institutions and organizations lack full visibility into where AI is already embedded within organisational processes and third-party software solutions.
-
Governance and Accountability: AI systems often operate in complex environments involving developers, data owners, business leaders, and third-party providers. This poses a challenge of defining responsibilities for managing risks, ensuring compliance, monitoring and oversights.
-
Measuring and Assessing AI Risks: Unlike traditional IT systems, AI introduces dynamic and evolving risks such as bias amplification or loss of explainability. Without clear methodologies and monitoring, organizations may struggle to identify vulnerabilities and assess impact.
- Managing Third-Party AI: Certain businesses rely heavily on external vendors and AI-enabled software providers. Understanding the compliance status and ensuring documentation of those systems can be challenging. In addition, overlapping requirements on third-party systems would require organizations to build a coordinated approach.
- Regulatory Change and Evolving Guidance: The regulatory landscape continues to evolve, with expanding guidance from European authorities. Organizations must therefore treat AI governance as an ongoing capability rather than a one-time project.
Act Now: Use the Time to Prepare – Not to Pause
The AI Omnibus has revised timeline, but it did not alter the EU’s ambition to establish trustworthy, transparent, and accountable AI. Regulators continue to strengthen supervisory capabilities, publish guidance, and increase their focus on AI-related risks. Organizations that use this period to understand AI landscape and develop frameworks will be better positioned for AI regulatory readiness. ADVANTA supports institutions and organizations across the AI journey: from understanding regulatory applicability to strengthening governance and transparency. If you would like to discuss how the EU AI Act may affect your organization, get in touch with us!

