Skip to main content
Taught by Tech Leads

Master pipelines, cloud & AI to become an operational Data Engineer.

DataScientist.fr
Updated: July 2026. The AI Act is a rapidly evolving framework — this article is revised as official texts are released (last major development: the Digital Omnibus agreement, May 2026).
Fewer than one in four companies using AI in the Union had, by the end of 2024, a formal AI training program — even though an obligation for AI literacy has been in effect since February 2025. In other words: most organizations are affected by the AI Act and are not yet aware of it.
The European Regulation on Artificial Intelligence — the 'AI Act' — is the world's first comprehensive legal framework on AI. But for a company, the real question is not 'what is it?': it is 'what does it change for me, and when?' This guide answers that operationally and up to date — including delays decided in 2026 — and provides you with a concrete roadmap.

Who is this guide for? For executives, HR directors, compliance officers, and managers of companies and SMEs that use or develop AI. What you will be able to do after reading it: situate your organization (supplier or deployer), classify your uses by risk level, identify your actual obligations to date, and launch an action plan.

The AI Act in one sentence

Regulation (EU) 2024/1689, which came into force on August 1, 2024, regulates AI according to a risk-based logic: the riskier the use is for the rights and safety of individuals, the stricter the obligations. It does not target specific technologies but uses, and its scope is extraterritorial — it applies as soon as an AI system is placed on the market or used in the Union, regardless of the supplier's country (Article 2).

The implementation timeline (updated with the Omnibus from May 2026)

The AI Act does not apply all at once: its obligations arrive in waves. And this timeline has just shifted. In response to an implementation deemed too burdensome, the Commission presented a 'Digital Omnibus' for simplification on November 19, 2025; a political agreement was reached in May 2026, and then the text was adopted — with European Parliament approval on June 16 and final Council of the EU green light on June 29, 2026. The heaviest obligations are therefore postponed, with publication in the Official Journal finalizing these delays (effective from the third day following publication).
Frise chronologique d’application de l’AI Act de 2024 à 2028
Date What applies
August 1, 2024 Entry into force (no obligations yet active)
February 2, 2025 Prohibited practices (Article 5) + AI literacy obligation (Article 4)
August 2, 2025 Obligations for general-purpose AI models (GPAI) + governance (AI Office, national authorities); states had to set their sanction rules
August 2, 2026 Most rules + transparency obligations (Article 50) + enforcement powers — still active date
December 2, 2027 High-risk systems from Annex III (recruitment, credit, education…) — postponed by the Omnibus (initial deadline: August 2, 2026)
August 2, 2028 AI integrated into regulated products (Annex I: medical devices, machines…) — postponed by the Omnibus
The key takeaway: the Omnibus mainly postpones the 'high-risk' obligations to the end of 2027 and 2028. But two requirements remain of immediate relevance — AI literacy (since February 2025) and transparency (August 2, 2026). (Source: official timeline from the Commission / AI Act Service Desk; analyses of the Omnibus agreement — see Sources.)

The 4 levels of risk: where do you fit in?

The core of the AI Act is its risk classification. Each use falls into one of four categories, with increasing obligations.
Pyramide des quatre niveaux de risque de l’AI Act
  • Unacceptable risk (prohibited) — social scoring, manipulation, exploitation of vulnerabilities. Prohibited since February 2025. (The Omnibus adds a prohibition on non-consensual intimate content generated by AI and child pornography.)
  • High risk — recruitment AI, credit granting, education, access to essential services… Heavy obligations (risk management, data governance, technical documentation, human oversight). Applicable by December 2, 2027 for Annex III.
  • Limited risk — chatbots, consumer generative AI. Obligation of transparency: inform that you are interacting with AI, label generated content (Article 50). Effective from August 2, 2026.
  • Minimal risk — the vast majority of uses (anti-spam, recommendations, spell-checkers…). No specific obligations.
To make this concrete, here is how common uses in business are classified:
Actual Use Typical Role Risk Level Main Obligation
Automated CV Screening (recruitment) Deployer High risk (Annex III) Human oversight, documentation
Credit scoring / solvency Deployer High risk Risk management, transparency
Customer service chatbot Deployer Limited risk Inform the user they are speaking with AI
Generation of marketing visuals/texts Deployer Limited risk Label generated content
Anti-spam filter, recommendation engine Deployer Minimal risk None (literacy recommended)
Social scoring of individuals Prohibited Prohibited use

Supplier or deployer? The role that determines your obligations

This is the most misunderstood — and most structuring — distinction. The AI Act does not only address those who build AI:
  • A supplier develops an AI system (or a model) and places it on the market under its name.
  • A deployer uses an AI system in the context of its professional activity.
Almost all companies are deployers — as soon as they use a CRM with predictive functions, a generative assistant, a candidate screening tool, etc. And the same organization can be both at once.
Arbre de décision : suis-je fournisseur ou déployeur au sens de l’AI Act ?Comparatif des obligations : fournisseur vs déployeur

Article 4: AI literacy, the obligation that already concerns you

If there is one point of the AI Act that concerns almost all companies today, it is this one. Article 4 requires, since February 2, 2025, that suppliers and deployers take measures to ensure a sufficient level of 'AI literacy' of their personnel and those who use AI on their behalf, taking into account their knowledge, the usage context, and the people involved.
The regulation defines AI literacy (Article 3, §56) as the skills, knowledge, and understanding that enable informed use of AI and awareness of its opportunities, risks, and possible harms.
Who is concerned? Suppliers and deployers; personnel and service providers, regardless of seniority level. The Commission even interprets 'other people' acting on behalf of the organization (contractors, service providers, and even clients in some cases) broadly. In practice: if your teams use AI tools, you are concerned.
What does 'sufficient level' mean? The Commission published a dedicated FAQ in May 2025: there is no single curriculum, the approach must be flexible and proportionate. However, it sets a minimal baseline: ensure a general understanding of AI, clarify the organization's role (supplier or deployer), identify the risks of the systems used, consider the context, and adapt training to the actual level of the teams. The Commission emphasizes that it is generally insufficient to simply ask employees to read a tool's manual.
An example of a differentiated literacy plan by profile:
Profile Literacy Objective Typical Content
Executives / Decision-makers Understand the stakes, risks, and obligations AI overview, AI Act framework, governance, strategic risks
Business roles (marketing, HR, finance…) Use AI in an informed and responsible manner Business use cases, limitations (hallucinations, bias), best practices, confidentiality
Technical / data teams Design and operate compliant systems Documentation, human oversight, security, MLOps, supplier obligations

How to prove it? The spirit of the text is one of traceability. The Commission recommends keeping documentation of the literacy measures implemented. In practice, authorities will expect a documented program — not just an isolated training event — calibrated by role, refreshed when regulations or tools evolve, with proof that named individuals have indeed completed the relevant modules. This is where training with verifiable skills — not just certified by a sign-in sheet — makes a difference: it provides the required proof.

⚠️ Point of vigilance (Omnibus). Article 4 applies today. But the Omnibus, adopted in June 2026, plans to overhaul it: transferring the mission to promote AI literacy to the member states and the Commission, rather than imposing a vague general obligation on organizations. What remains unchanged: for deployers of high-risk systems, the obligation to train staff in human oversight (Article 26) remains in place; civil liability in case of harm caused by poorly managed use remains; and the operational need to upskill your teams does not disappear. To be followed as the text is adopted.

What to do concretely? The roadmap

Without waiting for the furthest deadlines, here are the basic steps — applicable to any organization.
Feuille de route de mise en conformité à l’AI Act en 6 étapes
  1. Inventory all your AI systems, including third-party tools and AI integrated into your software. In practice, audits often reveal 5 to 12 undeclared AI tools per company, installed by employees themselves.
  2. Check prohibited practices (Article 5) and cease any affected use.
  3. Classify each system by risk level and role (supplier/deployer).
  4. Establish an AI literacy plan tailored to profiles (see table above).
  5. Document: records, instructions, data governance for high-risk systems, and proof of completed training.
  6. Implement AI governance and continuous monitoring (texts evolve).

3 concrete cases

Accounting firm. It uses automated data entry software and a generative assistant to draft letters. → Role: deployer.Risk: limited to minimal (no high-risk system). → Obligations: AI literacy (employees must understand the limitations — hallucinations, customer data confidentiality) + transparency if a chatbot responds to clients. → Action: documented training plan for teams.
SME that screens its applications with AI. The HR department uses an automatic CV pre-selection tool. → Role: deployer of a high-risk system (recruitment = Annex III). → Obligations: human oversight (Article 26 — a competent human retains control over decisions), documentation, candidate information, and enhanced literacy for those in charge. → Action: frame the tool, train recruiters in oversight, track. (High-risk deadline: December 2, 2027, but literacy and civil liability are already at play.)
E-commerce site. It deploys an assistance chatbot and a recommendation engine. → Role: deployer.Risk: limited (chatbot → transparency) and minimal (recommendation). → Obligations: inform the user that they are interacting with AI, label generated content where applicable, literacy for teams. → Action: transparency banner + training for support and marketing teams.

Sanctions: what financial risk?

The sanction regime (Article 99) is stricter than that of the GDPR, and structured in tiers:
  • Prohibited practices (Article 5): up to €35 million or 7% of global revenue.
  • Non-compliance with most other obligations (high-risk systems, deployer obligations…): up to €15 million or 3%.
  • Incorrect or misleading information to authorities: up to €7.5 million or 1%.
Proportional caps apply to SMEs and startups (the lower of the two amounts). Note: states were to set their sanction rules by August 2025, but most enforcement powers only activate from August 2, 2026. In practice, the absence of training will mainly be seen as an aggravating factor in a broader procedure rather than being sanctioned in isolation.

AI Act and funding: don’t pay full price for your training

Training your teams on AI — that which addresses the literacy issue — generally falls within fundable schemes (OPCO, skills development plan). The requirement then becomes a funded upskilling opportunity. This is especially relevant as the Commission and member states are called, via the Omnibus, to actively promote this upskilling.

In summary

The AI Act is not a wall that falls on August 2, 2026: it is a staggered timeline, with the Omnibus having just postponed the 'high-risk' obligations to the end of 2027 and 2028. But two requirements are already there or imminent: AI literacy (since February 2025, currently being restructured but still of practical relevance) and transparency (August 2026). The right strategy is not to wait — it is to inventory your uses, train your teams demonstrably, and monitor the evolution of the texts.
Do you want to secure your compliance? Review your AI literacy plan with our teams.

Sources

Want to go further?

This topic is part of our Become a Data & AI Project Manager course. Browse the full programme, or get it by email.

FAQ

Take a moment to discuss your training project with an advisor.

Share with

Photo de Dr. Hatim CHAHDI

Dr. Hatim CHAHDI

Directeur Data & IA, CEO AXI Technologies

Expert Data & IA et docteur en intelligence artificielle, Hatim cumule plus de 14 ans d'expérience professionnelle à la croisée de la R&D, l'industialisation et l'impact business. Microsoft Certified Trainer, il a dirigé l'industrialisation de l'un des tout premiers systèmes de machine learning déployés en production sur des données de transactions bancaires en France — du cadrage métier jusqu'à la conformité réglementaire. Fondateur d'AXI Technologies, il accompagne régulièrement de grands comptes dans la définition de leurs roadmaps IA et leurs stratégies de mise en production. Formateur en machine learning, cloud, MLOps et IA générative, il transmet au sein de DataScientist une pédagogie exigeante : Chaque apprenant est traité comme un professionnel en devenir, qui apprend en livrant des projets concrets et mesurables.

» Learn More

Associated trainings

All our trainings
Image de la formation Become a Data & AI Project Manager
Become a Data & AI Project Manager
6 months
Intermediate
Guarantee
Image de la formation Generative AI for Developers
Generative AI for Developers
50 hours
Intermediate
Guarantee

Associated articles

See all our articles