Who does the AI Act apply to, and does it reach companies outside the EU?
It applies by role, and its reach is deliberately extraterritorial. Providers: whoever develops an AI system or GPAI model and places it on the EU market or puts it into service there, wherever the provider is established; a US company selling an AI product into the EU is a provider. Deployers: organizations using AI systems under their own authority in the course of business (not personal use), the role most companies occupy. Importers and distributors carry verification duties for systems entering the market. Product manufacturers embedding AI in regulated products take provider duties for the embedded system. The extraterritorial hook that surprises people: the Act also applies where the provider or deployer is outside the EU but the system's output is used in the EU, a US analytics vendor whose scoring outputs are consumed by an EU customer is in scope without ever shipping software to Europe. Role conversion is the second trap: a deployer that puts its name on a high-risk system, substantially modifies one, or repurposes one into high-risk use becomes the provider with the full obligation set. Exclusions: systems for military, defense, and national-security purposes; scientific research and development; and free open-source models except where they are GPAI with systemic risk or fall into prohibited or high-risk uses. Every multinational's first task is therefore a role-mapping exercise per system, not a single company-level determination.
What is prohibited outright, and since when?
Article 5's prohibitions have applied since February 2, 2025, ahead of everything else, and they carry the top fine tier (35 million EUR or 7%). Prohibited: subliminal or purposefully manipulative techniques that materially distort behavior causing significant harm; exploiting vulnerabilities of age, disability, or social or economic situation to the same effect; social scoring by or for public and private actors producing detrimental treatment in unrelated contexts; predicting criminal offense risk solely from profiling or personality traits; untargeted scraping of facial images from the internet or CCTV to build facial recognition databases; emotion recognition in workplaces and educational institutions (except medical or safety uses); biometric categorization inferring race, political opinions, trade union membership, religious beliefs, sex life, or sexual orientation from biometric data; and real-time remote biometric identification in publicly accessible spaces for law enforcement, subject to narrow, judicially authorized exceptions (targeted searches for victims, imminent threats, serious-crime suspects). Corporate exposure hides in mundane places: an engagement-optimizing recommender that crosses into materially distorting manipulation, an HR wellness tool inferring emotional state, a fraud model that amounts to social scoring across contexts. The compliance step is a prohibition screen across the AI inventory, documented, refreshed as products change, because 'we did not realize the feature did that' is not a defense the fine tier respects.
What counts as high-risk, and what do high-risk providers actually owe?
Two routes in. Annex I: AI as a safety component of products under existing EU product law (machinery, medical devices, vehicles, toys), where the product regime's conformity assessment absorbs the AI requirements on the 2027 timeline. Annex III: standalone systems in eight areas, biometrics (identification, categorization, emotion recognition where not banned), critical infrastructure management, education and vocational training (admission, assessment, proctoring), employment (recruitment, screening, promotion, termination, task allocation, monitoring), essential services (credit scoring, insurance pricing for life and health, emergency dispatch, public benefits), law enforcement, migration and border control, and administration of justice and democratic processes, with a carve-out where the system performs a narrow procedural task and does not materially influence outcomes (a documented assessment either way). Provider obligations for high-risk systems (Articles 9-15 plus the conformity machinery): an iterative, lifecycle-long risk-management system; data governance for training, validation, and test sets (quality criteria, representativeness, bias examination); Annex IV technical documentation; automatic event logging; instructions and transparency to deployers; human-oversight design; accuracy, robustness, and cybersecurity appropriate to purpose; an Article 17 quality management system; conformity assessment (mostly internal control for Annex III, notified bodies for biometrics and Annex I); an EU declaration of conformity and CE marking; registration in the EU database; post-market monitoring; and serious-incident reporting. The date: August 2, 2026 for Annex III; August 2, 2027 for Annex I.
What do deployers, and companies just using chatbots and generative AI, owe?
Deployer duties are lighter but real, and they are where most organizations actually live. For high-risk systems: use per the provider's instructions; assign human oversight to competent, trained, authorized people; ensure relevant, representative input data where the deployer controls it; monitor operation and report risks and serious incidents; retain the automatically generated logs (minimum six months, subject to other law); inform workers and representatives before workplace deployment; and, for public bodies and certain private deployers of Annex III systems, a fundamental-rights impact assessment before first use (Article 27). Where automated decisions touch individuals, GDPR Article 22 runs in parallel, the human-oversight engineering is the same work. Transparency duties (Article 50, applying August 2, 2026) cover far more companies: people must be informed they are interacting with an AI system (chatbots) unless obvious; synthetic audio, image, video, and text content must be marked machine-readably as artificially generated (providers) and deepfakes disclosed (deployers); emotion recognition and biometric categorization systems require notice to exposed persons. And the AI-literacy duty (Article 4) has applied to providers and deployers alike since February 2, 2025: staff dealing with AI operation and use need sufficient AI literacy, evidenced in practice through role-based training records. The pragmatic deployer program: inventory systems and classify, verify provider documentation and instructions exist, assign and train overseers, wire log retention, screen for transparency triggers, and put an AI clause in procurement so the inventory stays current.
How is the Act enforced, what are the fines, and what should a compliance program look like now?
Enforcement architecture: the EU AI Office (within the European Commission) supervises GPAI models directly and coordinates the regime; national market surveillance authorities enforce against providers and deployers of AI systems in each member state, with powers modeled on product-safety law (information demands, corrective orders, recalls, withdrawal); notified bodies handle third-party conformity assessment where required; and the European Artificial Intelligence Board coordinates national authorities. Fines tier by violation: 35 million EUR or 7% of worldwide annual turnover (whichever is higher) for prohibited practices; 15 million EUR or 3% for most other obligations including the high-risk requirements; 7.5 million EUR or 1% for supplying incorrect or misleading information; SMEs pay the lower of the amounts. Member-state penalty regimes and full enforcement operation date from August 2, 2026, though the prohibitions and GPAI rules are already live. A defensible program in 2026: an AI inventory with role and risk classification per system (including embedded and procured AI, the shadow-AI problem); a prohibition screen, documented; AI-literacy training with records; per-system obligation backlogs against the 2026 and 2027 dates; contract remediation so provider-deployer boundaries, documentation flows, and incident duties are papered; and a governance chassis, an ISO 42001-style AI management system covers much of the Act's Article 17 QMS structure and gives the program a home. Watch items: harmonized standards being drafted by CEN-CENELEC (their Official Journal citation will carry presumption of conformity), AI Office codes of practice and guidance, and the Commission's simplification proposals, none of which change the prudent posture of building to the dates as enacted.