Regulation11 min readOctober 2026

The EU AI Act for companies: what changes and what to do

What applies to a company that uses AI today, which dates the Digital Omnibus moved, and a checklist you can run this month.

Snow-covered peaks of the Jungfrau region above a deep valley, with cable car lines crossing the foreground on the left
Jungfrau region, Switzerland

The EU AI Act for companies covers two groups: the firms that build AI, and every company that uses it at work. For an SME running AI on email, documents or the CRM, three things apply today: support AI literacy among your staff (Article 4), tell people when they deal with an AI system (Article 50), and stay clear of the practices banned by Article 5. The heavy rules for high-risk uses, such as screening CVs or scoring a person's credit, now start on 2 December 2027. The Digital Omnibus moved them there in July 2026.

Not legal advice

This article explains the regulation as it stands on 10 October 2026, from the official texts linked in each section. For a decision about your own system, ask a lawyer who knows your sector.

Part 01

The EU AI Act for companies: who it applies to

The AI Act, Regulation (EU) 2024/1689, sorts companies by role. A provider develops an AI system, or has one developed, and offers it under its own name. A deployer uses an AI system under its own authority in a professional setting. The accounting firm that lets an agent sort its shared inbox is a deployer. The software company that sells that agent is the provider. An SME that buys its AI tools is a deployer, and the deployer duties are far lighter.

Roles can shift. If you build your own agent on top of a language model and put it into service under your name, you are its provider. If you put your name on a high-risk system or change it substantially, Article 25 treats you as the provider too.

The reach is wide. Article 2 covers providers that place AI systems on the EU market wherever they are based, deployers established in the EU, and providers and deployers in third countries "where the output produced by the AI system is used in the Union". A company outside the EU that ranks EU job applicants with AI is covered for that use.

The number of deployers is rising. According to Eurostat, 20.0% of EU enterprises with 10 or more employees used AI in 2025, up from 13.5% in 2024.

Share of EU enterprises using AI in 2025, by size All enterprises with 10 or more employees: 20.0%. Small enterprises (10 to 49 employees): 17.0%. Medium (50 to 249): 30.4%. Large (250 or more): 55.0%. 0% 15% 30% 45% 60% All enterprises Small, 10 to 49 Medium, 50 to 249 Large, 250+ 20.0% 17.0% 30.4% 55.0%
Figure 1Share of EU enterprises that used at least one AI technology in 2025, by number of employees. Each of them is at least a deployer under the AI Act. Source: Eurostat, Use of artificial intelligence in enterprises, December 2025.

Switzerland and the national supervisors

The AI Act is not Swiss law, but Article 2 reaches Swiss companies that sell AI systems into the EU or whose AI output is used there. A Swiss provider of a high-risk system must appoint an authorised representative in the EU before selling there (Article 22). At home, the Federal Council decided on 12 February 2025 to ratify the Council of Europe AI Convention and to keep regulating AI sector by sector, for example in healthcare and transport. Switzerland signed the Convention on 27 March 2025. The Federal Department of Justice and Police has until the end of 2026 to draft rules on transparency, data protection, non-discrimination and oversight (Federal Office of Justice).

Inside the EU, each country names its supervisors. Spain has AESIA, its AI supervisory agency, based in A Coruña. Its statute, Royal Decree 729/2023, makes it responsible for supervising and, where applicable, sanctioning AI systems. On 26 May 2026 the Spanish government sent Congress a bill that names AESIA the main supervisor for uses such as employment, biometrics and education, and the single point of contact. The Congress record lists that bill as lapsed since 6 October 2026. The EU regulation applies directly either way.

Part 02

The four risk tiers, with everyday examples

The European Commission describes four levels of risk. The duties depend on the use, not on the technology. The same language model can sort invoices (minimal risk) or rank job applicants (high-risk).

The four risk tiers of the EU AI Act A pyramid. Top: prohibited practices under Article 5, banned since 2 February 2025. Second: high-risk uses under Article 6 and Annex III, from 2 December 2027. Third: transparency obligations under Article 50, since 2 August 2026. Base: minimal risk, no new duties beyond AI literacy. Art. 5 Art. 6, Annex III Art. 50 No new duties Prohibited High-risk Transparency Minimal Social scoring, emotion recognition of staff. Banned since 2 Feb 2025. CV screening, credit scoring of people, exam grading. Applies from 2 Dec 2027. Customer chatbots, realistic AI images and video. Applies since 2 Aug 2026. Email triage, invoice extraction, spam filters. AI literacy only (Art. 4).
Figure 2The four risk tiers and where common company uses land. General-purpose AI models, such as the ones behind ChatGPT or Claude, follow a separate set of rules for their providers. Sources: Article 5, Annex III, Article 50, AI Act Service Desk, consolidated text as at 27 July 2026.

Prohibited

Article 5 has banned eight practices since 2 February 2025. The ones a company can run into: emotion recognition in the workplace or in education (medical and safety reasons excepted), social scoring, manipulative techniques that cause significant harm, biometric categorisation to infer race, political views, religion or sexual orientation, and building facial recognition databases by scraping the internet or CCTV. From 2 December 2026, two more bans apply: AI that generates intimate or sexual images of real people without consent, and AI that generates child sexual abuse material.

High-risk

Annex III lists eight areas: biometrics, critical infrastructure, education, employment and workers' management, access to essential services (creditworthiness of individuals, pricing of life and health insurance, public benefits), law enforcement, migration and border control, and justice and democratic processes. AI that is a safety component of a regulated product, such as a machine or a medical device, is high-risk through Annex I.

Transparency

Article 50 applies since 2 August 2026. Systems that talk to people must tell them they are dealing with AI, unless that is obvious. Providers of systems that generate text, images, audio or video must mark the output as AI-generated in a machine-readable way. Deployers must disclose deepfakes, and AI-generated text published to inform the public on matters of public interest, unless a person reviewed it and someone holds editorial responsibility.

Minimal

Everything else. The Commission names spam filters and video games. Inbox triage, document extraction, internal knowledge search and report building usually sit here too. The AI Act adds no duties for them beyond AI literacy.

Use in a companyTierWhat it means for youFrom
Inbox triage with drafts for staff reviewMinimalAI literacy for the people who use it2 Feb 2025
Invoice and document extraction into the ERPMinimalAI literacy2 Feb 2025
Chat assistant answering customers on your websiteTransparencyCustomers must know they are talking to AI2 Aug 2026
Realistic AI-generated images or video in marketingTransparencyDisclose that the content is AI-generated2 Aug 2026
Ranking job applicants or filtering CVsHigh-risk (Annex III, 4)Deployer duties under Article 262 Dec 2027
Credit scoring of private customersHigh-risk (Annex III, 5)Deployer duties under Article 262 Dec 2027
Reading employees' emotions on video callsProhibitedDo not use2 Feb 2025

Part 03

The timeline: what applies now and what moved

The AI Act entered into force on 1 August 2024 and applies in stages. Two dates changed this year. The Commission proposed the Digital Omnibus on AI on 19 November 2025. Council and Parliament reached a political agreement on 7 May 2026, and the Council gave its final approval on 29 June 2026. The result is Regulation (EU) 2026/1744 of 8 July 2026, in force since 27 July 2026. This is adopted law, not a proposal.

EU AI Act timeline as amended by the Digital Omnibus 1 August 2024: entry into force. 2 February 2025: prohibitions and AI literacy. 2 August 2025: general-purpose AI models, governance and penalties. 2 August 2026: most rules, Article 50 transparency and enforcement. Today, 10 October 2026. 2 December 2026: new prohibitions and Article 50(2) marking for systems already on the market. 2 December 2027: high-risk rules for Annex III, moved from 2 August 2026. 2 August 2028: high-risk rules for Annex I products, moved from 2 August 2027. 1 Aug 2024 2 Feb 2025 2 Aug 2025 2 Aug 2026 2 Dec 2026 2 Dec 2027 2 Aug 2028 Today, 10 Oct 2026 Entry into force Prohibitions and AI literacy General-purpose AI models Most rules, Article 50, enforcement New bans, AI content marking High-risk, Annex III High-risk in regulated products, Annex I Regulation (EU) 2024/1689 starts to count. No duties yet. Article 5 bans apply. Article 4: support AI literacy of staff. Duties for model providers. Authorities and penalties in place. Tell people when they deal with AI. Authorities start enforcing. Sexual deepfake ban. Article 50(2) marking for older systems. Hiring, credit, insurance, education. Was 2 Aug 2026. Machinery, toys, medical devices. Was 2 Aug 2027.
Figure 3Application dates of the AI Act as amended by Regulation (EU) 2026/1744. Filled dots: already in force. Source: Article 113 and the AI Act Service Desk timeline, European Commission, checked 10 October 2026.

What the Omnibus changed for a typical company:

  • High-risk rules for Annex III uses moved from 2 August 2026 to 2 December 2027. Those for AI in regulated products moved from 2 August 2027 to 2 August 2028.
  • Article 4 was rewritten. Providers and deployers now "shall take measures to support the development of AI literacy" of their staff, and the Commission and Member States take a larger role in promoting it. The duty stays. The wording is softer.
  • Some relief that applied only to SMEs now extends to small mid-caps, including the cap on fines.
  • Providers of generative systems already on the market before 2 August 2026 have until 2 December 2026 to mark their output under Article 50(2).

What did not move: the Article 5 bans, the Article 50 transparency rules for chatbots and deepfakes, and the start of enforcement on 2 August 2026.

Part 04

Is my use case high-risk? A five-question test

Being in an Annex III area is not enough on its own. Article 6(3) takes a system out of high-risk when it poses no significant risk and does one of four things: a narrow procedural task, improving the result of work a person already finished, spotting patterns in past decisions without replacing human review, or a preparatory task before an assessment. One exception overrides all four. A system in an Annex III area that profiles people is always high-risk.

Decision tree: does my use case fall under high-risk? Question 1: is it a banned practice under Article 5? If yes, prohibited. Question 2: is it a safety component of a regulated product under Annex I? If yes, high-risk from 2 August 2028. Question 3: is the use in one of the eight Annex III areas? If no, not high-risk; check Article 50 and Article 4. Question 4: does it profile people? If yes, high-risk from 2 December 2027. Question 5: is it only a narrow procedural or preparatory task under Article 6(3)? If yes, not high-risk, document why. If no, high-risk from 2 December 2027. 1. Is it a banned practice in Article 5? 2. Is it a safety part of a regulated product? 3. Is the use in one of the 8 Annex III areas? 4. Does it profile people? 5. Only a narrow or preparatory task? Social scoring, emotion recognition at work Machinery, toys, medical devices (Annex I) Hiring, workers, credit, insurance, education Evaluates a person's work, finances or behaviour Article 6(3): no real influence on the decision Yes Yes No Yes Yes No No Yes No No Prohibited High-risk Not high-risk High-risk Not high-risk High-risk from 2 Dec 2027 Do not use it From 2 Aug 2028 Check Art. 50 and Art. 4 From 2 Dec 2027 Document why, Art. 6(4)
Figure 4A first screening, not a legal classification. The sage box is where most email, document and CRM agents end. Sources: Article 6 and Annex III, AI Act Service Desk.

Two examples from recruiting. An agent that checks whether each application is complete and in the right language does a narrow procedural task. An agent that ranks candidates by predicted fit evaluates people, so it is very likely high-risk. In finance, an agent that matches invoices to purchase orders is outside Annex III altogether. Scoring the creditworthiness of private customers is inside it. Annex III excludes fraud detection from that point explicitly.

If a provider decides its Annex III system is not high-risk, Article 6(4) requires it to document that assessment before the system goes on the market. As a deployer, ask your vendor for that document.

If your use is high-risk, Article 26 sets your duties from 2 December 2027. Use the system according to its instructions. Assign human oversight to people with the competence, training and authority to overrule it. Monitor how it runs. Keep the logs it generates for at least six months. Inform workers and their representatives before you use it at the workplace.

Part 05

What an SME using AI agents must do now

Take a property manager with fifty staff. An agent triages tenant requests, another extracts data from invoices, and a chat assistant answers tenants on the website at night. None of this is high-risk. Two duties apply today: AI literacy for the team that works with the agents, and a clear notice in the chat that tenants are talking to an AI system. Article 50(1) puts that duty on the provider of the chat tool, so check that yours does it. If the same company later uses AI to pre-select tenants by creditworthiness, it enters Annex III territory.

Human oversight and logging are legal duties only for high-risk systems. They are still worth building in from the start. They are how you find out an agent is wrong before a customer does, and they give you the records a lawyer or an authority will ask for.

€35M

Or 7% of turnover. Banned practices under Article 5. Article 99(3)

€15M

Or 3%. Most other duties, incl. deployers and Article 50. Article 99(4)

€7.5M

Or 1%. Misleading information to authorities. Article 99(5)

The percentages refer to total worldwide annual turnover of the preceding year. Large companies face whichever is higher. For SMEs and start-ups, Article 99(6) caps each fine at whichever is lower, and since the Omnibus, small mid-caps get the same treatment for the second and third tier.

A practical checklist

  1. List every AI system in use.Who uses it, for what, from which vendor, on which data. Include the AI features inside tools you already pay for.
  2. Classify each one.Run the five questions in Figure 4 and write down the answer and the reason. One page per system is enough.
  3. Remove anything on the Article 5 list.Check vendor features too, for example tools that infer employees' emotions from voice or video.
  4. Set up AI literacy by role.A short session for each team on what its tools do, where they fail and when to escalate. Keep a record of who attended.
  5. Label AI contact.Tell people when they talk to a chatbot or agent directly, and label realistic AI-generated images and video.
  6. Ask your vendors four questions.Are you the provider under the AI Act? Where is the data processed? Does the system log its decisions? Is any of it high-risk, and is it ready for 2 December 2027?
  7. Put a person on decisions about people.Hiring, credit, pricing for individuals. Log what the system proposed and what the person decided.

Know where AI runs in your company, who checks it and what it writes down. That covers most of what the AI Act asks of a deployer today.

Alpgency

How we build agents

Every agent we build has a confidence threshold. Below it, or on anything you mark as sensitive, a person approves before anything happens. Each decision goes into a log with the input, the output and who approved it. Data is processed in the EU by default, as a managed service, in your cloud or on your own servers. None of this makes a system compliant on its own. It gives you the records a compliance review asks for.

FAQ

Frequently asked questions

Does the EU AI Act apply to my company if we only use tools like ChatGPT?

Yes. A company that uses an AI system at work is a deployer under the Act. Since 2 February 2025 you must avoid the banned practices and take measures to support AI literacy among the people who use it. Article 50 adds duties when you publish deepfakes, or AI-generated text that informs the public on matters of public interest. The rules for general-purpose AI models fall on the model provider, not on you.

Has the high-risk deadline been postponed?

Yes. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026. The rules for high-risk systems listed in Annex III now apply from 2 December 2027, and those for high-risk AI in regulated products (Annex I) from 2 August 2028. The Article 50 transparency rules did not move: they apply since 2 August 2026.

Does the EU AI Act apply to Swiss companies?

It applies when a Swiss company places an AI system on the EU market, or when the output of its AI system is used in the EU (Article 2). A Swiss provider of a high-risk system must appoint an authorised representative in the EU. Swiss law itself follows its own track: the Federal Council asked for a consultation draft on AI rules by the end of 2026.

What are the fines under the EU AI Act?

Up to 35 million euros or 7% of worldwide annual turnover for banned practices, up to 15 million euros or 3% for most other obligations, including deployer and transparency duties, and up to 7.5 million euros or 1% for giving authorities incorrect information. Large companies face whichever amount is higher. For SMEs and start-ups it is whichever is lower.

Is an AI agent that answers customer emails high-risk?

Usually not. Customer service is not one of the Annex III areas. If the agent writes to customers directly, Article 50 requires that they are told they are dealing with an AI system, unless that is obvious. A draft that a person reviews and sends is a different setup. Check with your lawyer where yours falls.

Start with one use case.

In the free Audit we map your processes, show which uses touch a regulated area and give the first use case a fixed price before you commit.

Book a free Audit

Keep reading

Guide

AI agents for business: what they are, what they do and what they cost

What an AI agent does inside the tools your company already uses, what sets its price, how far European companies have got with AI, and the questions to ask a provider before you sign.

Guide

Chatbot vs AI agent: which one does your company need?

A chatbot answers. An agent does the work. How to tell which one your problem needs, what each one costs to run and where each one fails.

Guide

AI consulting for companies: where to start with AI

How to choose your first AI use case, score it with a simple weighted matrix, decide whether to build or buy, and what a good AI Audit should hand you at the end.