Updated: July 2026. The AI Act is a rapidly evolving framework — this article is revised as official texts are released (last major development: the Digital Omnibus agreement, May 2026).
Fewer than one in four companies using AI in the Union had, by the end of 2024, a formal AI training program — even though an obligation for AI literacy has been in effect since February 2025. In other words: most organizations are affected by the AI Act and are not yet aware of it.
The European Regulation on Artificial Intelligence — the 'AI Act' — is the world's first comprehensive legal framework on AI. But for a company, the real question is not 'what is it?': it is 'what does it change for me, and when?' This guide answers that operationally and up to date — including delays decided in 2026 — and provides you with a concrete roadmap.
Who is this guide for? For executives, HR directors, compliance officers, and managers of companies and SMEs that use or develop AI. What you will be able to do after reading it: situate your organization (supplier or deployer), classify your uses by risk level, identify your actual obligations to date, and launch an action plan.
The AI Act in one sentence
Regulation (EU) 2024/1689, which came into force on August 1, 2024, regulates AI according to a risk-based logic: the riskier the use is for the rights and safety of individuals, the stricter the obligations. It does not target specific technologies but uses, and its scope is extraterritorial — it applies as soon as an AI system is placed on the market or used in the Union, regardless of the supplier's country (Article 2).
The implementation timeline (updated with the Omnibus from May 2026)
The AI Act does not apply all at once: its obligations arrive in waves. And this timeline has just shifted. In response to an implementation deemed too burdensome, the Commission presented a 'Digital Omnibus' for simplification on November 19, 2025; a political agreement was reached in May 2026, and then the text was adopted — with European Parliament approval on June 16 and final Council of the EU green light on June 29, 2026. The heaviest obligations are therefore postponed, with publication in the Official Journal finalizing these delays (effective from the third day following publication).

| Date | What applies |
|---|
| August 1, 2024 | Entry into force (no obligations yet active) |
| February 2, 2025 | Prohibited practices (Article 5) + AI literacy obligation (Article 4) |
| August 2, 2025 | Obligations for general-purpose AI models (GPAI) + governance (AI Office, national authorities); states had to set their sanction rules |
| August 2, 2026 | Most rules + transparency obligations (Article 50) + enforcement powers — still active date |
| December 2, 2027 | High-risk systems from Annex III (recruitment, credit, education…) — postponed by the Omnibus (initial deadline: August 2, 2026) |
| August 2, 2028 | AI integrated into regulated products (Annex I: medical devices, machines…) — postponed by the Omnibus |
The key takeaway: the Omnibus mainly postpones the 'high-risk' obligations to the end of 2027 and 2028. But two requirements remain of immediate relevance — AI literacy (since February 2025) and transparency (August 2, 2026). (Source: official timeline from the Commission / AI Act Service Desk; analyses of the Omnibus agreement — see Sources.)
The 4 levels of risk: where do you fit in?
The core of the AI Act is its risk classification. Each use falls into one of four categories, with increasing obligations.

- Unacceptable risk (prohibited) — social scoring, manipulation, exploitation of vulnerabilities. Prohibited since February 2025. (The Omnibus adds a prohibition on non-consensual intimate content generated by AI and child pornography.)
- High risk — recruitment AI, credit granting, education, access to essential services… Heavy obligations (risk management, data governance, technical documentation, human oversight). Applicable by December 2, 2027 for Annex III.
- Limited risk — chatbots, consumer generative AI. Obligation of transparency: inform that you are interacting with AI, label generated content (Article 50). Effective from August 2, 2026.
- Minimal risk — the vast majority of uses (anti-spam, recommendations, spell-checkers…). No specific obligations.
To make this concrete, here is how common uses in business are classified:
| Actual Use | Typical Role | Risk Level | Main Obligation |
|---|
| Automated CV Screening (recruitment) | Deployer | High risk (Annex III) | Human oversight, documentation |
| Credit scoring / solvency | Deployer | High risk | Risk management, transparency |
| Customer service chatbot | Deployer | Limited risk | Inform the user they are speaking with AI |
| Generation of marketing visuals/texts | Deployer | Limited risk | Label generated content |
| Anti-spam filter, recommendation engine | Deployer | Minimal risk | None (literacy recommended) |
| Social scoring of individuals | — | Prohibited | Prohibited use |
Supplier or deployer? The role that determines your obligations
This is the most misunderstood — and most structuring — distinction. The AI Act does not only address those who build AI:
- A supplier develops an AI system (or a model) and places it on the market under its name.
- A deployer uses an AI system in the context of its professional activity.
Almost all companies are deployers — as soon as they use a CRM with predictive functions, a generative assistant, a candidate screening tool, etc. And the same organization can be both at once.


Article 4: AI literacy, the obligation that already concerns you
If there is one point of the AI Act that concerns almost all companies today, it is this one. Article 4 requires, since February 2, 2025, that suppliers and deployers take measures to ensure a sufficient level of 'AI literacy' of their personnel and those who use AI on their behalf, taking into account their knowledge, the usage context, and the people involved.
The regulation defines AI literacy (Article 3, §56) as the skills, knowledge, and understanding that enable informed use of AI and awareness of its opportunities, risks, and possible harms.
Who is concerned? Suppliers and deployers; personnel and service providers, regardless of seniority level. The Commission even interprets 'other people' acting on behalf of the organization (contractors, service providers, and even clients in some cases) broadly. In practice: if your teams use AI tools, you are concerned.
What does 'sufficient level' mean? The Commission published a dedicated FAQ in May 2025: there is no single curriculum, the approach must be flexible and proportionate. However, it sets a minimal baseline: ensure a general understanding of AI, clarify the organization's role (supplier or deployer), identify the risks of the systems used, consider the context, and adapt training to the actual level of the teams. The Commission emphasizes that it is generally insufficient to simply ask employees to read a tool's manual.
An example of a differentiated literacy plan by profile:
| Profile | Literacy Objective | Typical Content |
|---|
| Executives / Decision-makers | Understand the stakes, risks, and obligations | AI overview, AI Act framework, governance, strategic risks |
| Business roles (marketing, HR, finance…) | Use AI in an informed and responsible manner | Business use cases, limitations (hallucinations, bias), best practices, confidentiality |
| Technical / data teams | Design and operate compliant systems | Documentation, human oversight, security, MLOps, supplier obligations |
How to prove it? The spirit of the text is one of traceability. The Commission recommends keeping documentation of the literacy measures implemented. In practice, authorities will expect a documented program — not just an isolated training event — calibrated by role, refreshed when regulations or tools evolve, with proof that named individuals have indeed completed the relevant modules. This is where training with verifiable skills — not just certified by a sign-in sheet — makes a difference: it provides the required proof.
⚠️ Point of vigilance (Omnibus). Article 4 applies today. But the Omnibus, adopted in June 2026, plans to overhaul it: transferring the mission to promote AI literacy to the member states and the Commission, rather than imposing a vague general obligation on organizations. What remains unchanged: for deployers of high-risk systems, the obligation to train staff in human oversight (Article 26) remains in place; civil liability in case of harm caused by poorly managed use remains; and the operational need to upskill your teams does not disappear. To be followed as the text is adopted.
What to do concretely? The roadmap
Without waiting for the furthest deadlines, here are the basic steps — applicable to any organization.

- Inventory all your AI systems, including third-party tools and AI integrated into your software. In practice, audits often reveal 5 to 12 undeclared AI tools per company, installed by employees themselves.
- Check prohibited practices (Article 5) and cease any affected use.
- Classify each system by risk level and role (supplier/deployer).
- Establish an AI literacy plan tailored to profiles (see table above).
- Document: records, instructions, data governance for high-risk systems, and proof of completed training.
- Implement AI governance and continuous monitoring (texts evolve).
3 concrete cases
Accounting firm. It uses automated data entry software and a generative assistant to draft letters. → Role: deployer. → Risk: limited to minimal (no high-risk system). → Obligations: AI literacy (employees must understand the limitations — hallucinations, customer data confidentiality) + transparency if a chatbot responds to clients. → Action: documented training plan for teams.
SME that screens its applications with AI. The HR department uses an automatic CV pre-selection tool. → Role: deployer of a high-risk system (recruitment = Annex III). → Obligations: human oversight (Article 26 — a competent human retains control over decisions), documentation, candidate information, and enhanced literacy for those in charge. → Action: frame the tool, train recruiters in oversight, track. (High-risk deadline: December 2, 2027, but literacy and civil liability are already at play.)
E-commerce site. It deploys an assistance chatbot and a recommendation engine. → Role: deployer. → Risk: limited (chatbot → transparency) and minimal (recommendation). → Obligations: inform the user that they are interacting with AI, label generated content where applicable, literacy for teams. → Action: transparency banner + training for support and marketing teams.
Sanctions: what financial risk?
The sanction regime (Article 99) is stricter than that of the GDPR, and structured in tiers:
- Prohibited practices (Article 5): up to €35 million or 7% of global revenue.
- Non-compliance with most other obligations (high-risk systems, deployer obligations…): up to €15 million or 3%.
- Incorrect or misleading information to authorities: up to €7.5 million or 1%.
Proportional caps apply to SMEs and startups (the lower of the two amounts). Note: states were to set their sanction rules by August 2025, but most enforcement powers only activate from August 2, 2026. In practice, the absence of training will mainly be seen as an aggravating factor in a broader procedure rather than being sanctioned in isolation.
AI Act and funding: don’t pay full price for your training
Training your teams on AI — that which addresses the literacy issue — generally falls within fundable schemes (OPCO, skills development plan). The requirement then becomes a funded upskilling opportunity. This is especially relevant as the Commission and member states are called, via the Omnibus, to actively promote this upskilling.
In summary
The AI Act is not a wall that falls on August 2, 2026: it is a staggered timeline, with the Omnibus having just postponed the 'high-risk' obligations to the end of 2027 and 2028. But two requirements are already there or imminent: AI literacy (since February 2025, currently being restructured but still of practical relevance) and transparency (August 2026). The right strategy is not to wait — it is to inventory your uses, train your teams demonstrably, and monitor the evolution of the texts.
Do you want to secure your compliance? Review your AI literacy plan with our teams.