Regulation11 min readOctober 2026
The EU AI Act for companies: what changes and what to do
What applies to a company that uses AI today, which dates the Digital Omnibus moved, and a checklist you can run this month.
The EU AI Act for companies covers two groups: the firms that build AI, and every company that uses it at work. For an SME running AI on email, documents or the CRM, three things apply today: support AI literacy among your staff (Article 4), tell people when they deal with an AI system (Article 50), and stay clear of the practices banned by Article 5. The heavy rules for high-risk uses, such as screening CVs or scoring a person's credit, now start on 2 December 2027. The Digital Omnibus moved them there in July 2026.
Not legal advice
This article explains the regulation as it stands on 10 October 2026, from the official texts linked in each section. For a decision about your own system, ask a lawyer who knows your sector.
Part 01
The EU AI Act for companies: who it applies to
The AI Act, Regulation (EU) 2024/1689, sorts companies by role. A provider develops an AI system, or has one developed, and offers it under its own name. A deployer uses an AI system under its own authority in a professional setting. The accounting firm that lets an agent sort its shared inbox is a deployer. The software company that sells that agent is the provider. An SME that buys its AI tools is a deployer, and the deployer duties are far lighter.
Roles can shift. If you build your own agent on top of a language model and put it into service under your name, you are its provider. If you put your name on a high-risk system or change it substantially, Article 25 treats you as the provider too.
The reach is wide. Article 2 covers providers that place AI systems on the EU market wherever they are based, deployers established in the EU, and providers and deployers in third countries "where the output produced by the AI system is used in the Union". A company outside the EU that ranks EU job applicants with AI is covered for that use.
The number of deployers is rising. According to Eurostat, 20.0% of EU enterprises with 10 or more employees used AI in 2025, up from 13.5% in 2024.
Switzerland and the national supervisors
The AI Act is not Swiss law, but Article 2 reaches Swiss companies that sell AI systems into the EU or whose AI output is used there. A Swiss provider of a high-risk system must appoint an authorised representative in the EU before selling there (Article 22). At home, the Federal Council decided on 12 February 2025 to ratify the Council of Europe AI Convention and to keep regulating AI sector by sector, for example in healthcare and transport. Switzerland signed the Convention on 27 March 2025. The Federal Department of Justice and Police has until the end of 2026 to draft rules on transparency, data protection, non-discrimination and oversight (Federal Office of Justice).
Inside the EU, each country names its supervisors. Spain has AESIA, its AI supervisory agency, based in A Coruña. Its statute, Royal Decree 729/2023, makes it responsible for supervising and, where applicable, sanctioning AI systems. On 26 May 2026 the Spanish government sent Congress a bill that names AESIA the main supervisor for uses such as employment, biometrics and education, and the single point of contact. The Congress record lists that bill as lapsed since 6 October 2026. The EU regulation applies directly either way.
Part 02
The four risk tiers, with everyday examples
The European Commission describes four levels of risk. The duties depend on the use, not on the technology. The same language model can sort invoices (minimal risk) or rank job applicants (high-risk).
Prohibited
Article 5 has banned eight practices since 2 February 2025. The ones a company can run into: emotion recognition in the workplace or in education (medical and safety reasons excepted), social scoring, manipulative techniques that cause significant harm, biometric categorisation to infer race, political views, religion or sexual orientation, and building facial recognition databases by scraping the internet or CCTV. From 2 December 2026, two more bans apply: AI that generates intimate or sexual images of real people without consent, and AI that generates child sexual abuse material.
High-risk
Annex III lists eight areas: biometrics, critical infrastructure, education, employment and workers' management, access to essential services (creditworthiness of individuals, pricing of life and health insurance, public benefits), law enforcement, migration and border control, and justice and democratic processes. AI that is a safety component of a regulated product, such as a machine or a medical device, is high-risk through Annex I.
Transparency
Article 50 applies since 2 August 2026. Systems that talk to people must tell them they are dealing with AI, unless that is obvious. Providers of systems that generate text, images, audio or video must mark the output as AI-generated in a machine-readable way. Deployers must disclose deepfakes, and AI-generated text published to inform the public on matters of public interest, unless a person reviewed it and someone holds editorial responsibility.
Minimal
Everything else. The Commission names spam filters and video games. Inbox triage, document extraction, internal knowledge search and report building usually sit here too. The AI Act adds no duties for them beyond AI literacy.
| Use in a company | Tier | What it means for you | From |
|---|---|---|---|
| Inbox triage with drafts for staff review | Minimal | AI literacy for the people who use it | 2 Feb 2025 |
| Invoice and document extraction into the ERP | Minimal | AI literacy | 2 Feb 2025 |
| Chat assistant answering customers on your website | Transparency | Customers must know they are talking to AI | 2 Aug 2026 |
| Realistic AI-generated images or video in marketing | Transparency | Disclose that the content is AI-generated | 2 Aug 2026 |
| Ranking job applicants or filtering CVs | High-risk (Annex III, 4) | Deployer duties under Article 26 | 2 Dec 2027 |
| Credit scoring of private customers | High-risk (Annex III, 5) | Deployer duties under Article 26 | 2 Dec 2027 |
| Reading employees' emotions on video calls | Prohibited | Do not use | 2 Feb 2025 |
Part 03
The timeline: what applies now and what moved
The AI Act entered into force on 1 August 2024 and applies in stages. Two dates changed this year. The Commission proposed the Digital Omnibus on AI on 19 November 2025. Council and Parliament reached a political agreement on 7 May 2026, and the Council gave its final approval on 29 June 2026. The result is Regulation (EU) 2026/1744 of 8 July 2026, in force since 27 July 2026. This is adopted law, not a proposal.
What the Omnibus changed for a typical company:
- High-risk rules for Annex III uses moved from 2 August 2026 to 2 December 2027. Those for AI in regulated products moved from 2 August 2027 to 2 August 2028.
- Article 4 was rewritten. Providers and deployers now "shall take measures to support the development of AI literacy" of their staff, and the Commission and Member States take a larger role in promoting it. The duty stays. The wording is softer.
- Some relief that applied only to SMEs now extends to small mid-caps, including the cap on fines.
- Providers of generative systems already on the market before 2 August 2026 have until 2 December 2026 to mark their output under Article 50(2).
What did not move: the Article 5 bans, the Article 50 transparency rules for chatbots and deepfakes, and the start of enforcement on 2 August 2026.
Part 04
Is my use case high-risk? A five-question test
Being in an Annex III area is not enough on its own. Article 6(3) takes a system out of high-risk when it poses no significant risk and does one of four things: a narrow procedural task, improving the result of work a person already finished, spotting patterns in past decisions without replacing human review, or a preparatory task before an assessment. One exception overrides all four. A system in an Annex III area that profiles people is always high-risk.
Two examples from recruiting. An agent that checks whether each application is complete and in the right language does a narrow procedural task. An agent that ranks candidates by predicted fit evaluates people, so it is very likely high-risk. In finance, an agent that matches invoices to purchase orders is outside Annex III altogether. Scoring the creditworthiness of private customers is inside it. Annex III excludes fraud detection from that point explicitly.
If a provider decides its Annex III system is not high-risk, Article 6(4) requires it to document that assessment before the system goes on the market. As a deployer, ask your vendor for that document.
If your use is high-risk, Article 26 sets your duties from 2 December 2027. Use the system according to its instructions. Assign human oversight to people with the competence, training and authority to overrule it. Monitor how it runs. Keep the logs it generates for at least six months. Inform workers and their representatives before you use it at the workplace.
Part 05
What an SME using AI agents must do now
Take a property manager with fifty staff. An agent triages tenant requests, another extracts data from invoices, and a chat assistant answers tenants on the website at night. None of this is high-risk. Two duties apply today: AI literacy for the team that works with the agents, and a clear notice in the chat that tenants are talking to an AI system. Article 50(1) puts that duty on the provider of the chat tool, so check that yours does it. If the same company later uses AI to pre-select tenants by creditworthiness, it enters Annex III territory.
Human oversight and logging are legal duties only for high-risk systems. They are still worth building in from the start. They are how you find out an agent is wrong before a customer does, and they give you the records a lawyer or an authority will ask for.
Or 7% of turnover. Banned practices under Article 5. Article 99(3)
Or 3%. Most other duties, incl. deployers and Article 50. Article 99(4)
Or 1%. Misleading information to authorities. Article 99(5)
The percentages refer to total worldwide annual turnover of the preceding year. Large companies face whichever is higher. For SMEs and start-ups, Article 99(6) caps each fine at whichever is lower, and since the Omnibus, small mid-caps get the same treatment for the second and third tier.
A practical checklist
- List every AI system in use.Who uses it, for what, from which vendor, on which data. Include the AI features inside tools you already pay for.
- Classify each one.Run the five questions in Figure 4 and write down the answer and the reason. One page per system is enough.
- Remove anything on the Article 5 list.Check vendor features too, for example tools that infer employees' emotions from voice or video.
- Set up AI literacy by role.A short session for each team on what its tools do, where they fail and when to escalate. Keep a record of who attended.
- Label AI contact.Tell people when they talk to a chatbot or agent directly, and label realistic AI-generated images and video.
- Ask your vendors four questions.Are you the provider under the AI Act? Where is the data processed? Does the system log its decisions? Is any of it high-risk, and is it ready for 2 December 2027?
- Put a person on decisions about people.Hiring, credit, pricing for individuals. Log what the system proposed and what the person decided.
Know where AI runs in your company, who checks it and what it writes down. That covers most of what the AI Act asks of a deployer today.
Alpgency
How we build agents
Every agent we build has a confidence threshold. Below it, or on anything you mark as sensitive, a person approves before anything happens. Each decision goes into a log with the input, the output and who approved it. Data is processed in the EU by default, as a managed service, in your cloud or on your own servers. None of this makes a system compliant on its own. It gives you the records a compliance review asks for.
FAQ
Frequently asked questions
Does the EU AI Act apply to my company if we only use tools like ChatGPT?
Yes. A company that uses an AI system at work is a deployer under the Act. Since 2 February 2025 you must avoid the banned practices and take measures to support AI literacy among the people who use it. Article 50 adds duties when you publish deepfakes, or AI-generated text that informs the public on matters of public interest. The rules for general-purpose AI models fall on the model provider, not on you.
Has the high-risk deadline been postponed?
Yes. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026. The rules for high-risk systems listed in Annex III now apply from 2 December 2027, and those for high-risk AI in regulated products (Annex I) from 2 August 2028. The Article 50 transparency rules did not move: they apply since 2 August 2026.
Does the EU AI Act apply to Swiss companies?
It applies when a Swiss company places an AI system on the EU market, or when the output of its AI system is used in the EU (Article 2). A Swiss provider of a high-risk system must appoint an authorised representative in the EU. Swiss law itself follows its own track: the Federal Council asked for a consultation draft on AI rules by the end of 2026.
What are the fines under the EU AI Act?
Up to 35 million euros or 7% of worldwide annual turnover for banned practices, up to 15 million euros or 3% for most other obligations, including deployer and transparency duties, and up to 7.5 million euros or 1% for giving authorities incorrect information. Large companies face whichever amount is higher. For SMEs and start-ups it is whichever is lower.
Is an AI agent that answers customer emails high-risk?
Usually not. Customer service is not one of the Annex III areas. If the agent writes to customers directly, Article 50 requires that they are told they are dealing with an AI system, unless that is obvious. A draft that a person reviews and sends is a different setup. Check with your lawyer where yours falls.
Start with one use case.
In the free Audit we map your processes, show which uses touch a regulated area and give the first use case a fixed price before you commit.
Book a free Audit

