FAQ
Frequently asked questions
What is the EU AI Act?
When does the EU AI Act come into effect?
The EU AI Act entered into force on 1 August 2024 and applies in phases. Prohibitions and AI literacy have applied since February 2025, and general-purpose AI model obligations since August 2025. In July 2026, the Digital Omnibus on AI moved the high-risk deadlines to 2 December 2027 for stand-alone systems and 2 August 2028 for product-embedded ones. Transparency and registration duties still apply from 2 August 2026, so this is a deferral of specific obligations, not of the regulation.
Who does the EU AI Act apply to?
The EU AI Act applies to any organisation that develops, deploys, distributes, or imports AI systems that are placed on the EU market or used within the EU. This includes organisations established outside the EU where the output produced by their AI system is used within the European Union. The regulation defines specific roles (provider, deployer, importer, distributor and more) each with their own set of obligations.
What are the risk categories under the EU AI Act?
The EU AI Act categorises AI systems into four risk levels. Unacceptable risk covers AI practices that are prohibited entirely, such as social scoring by public authorities or private companies. High risk includes AI systems used in areas like recruitment, credit scoring, and biometric identification, which face the strictest requirements. Limited risk systems have transparency obligations, such as disclosing that users are interacting with AI. Minimal risk systems, like spam filters, have no additional requirements under the regulation.
What happens if my organisation does not comply with the EU AI Act?
Non-compliance can result in significant fines, set in three tiers: up to 35 million EUR or 7% of worldwide turnover for prohibited practices, up to 15 million EUR or 3% for most other infringements, and up to 7.5 million EUR or 1% for supplying incorrect information to authorities. For undertakings the higher figure applies. For SMEs and start-ups, Article 99(6) reverses this and the lower figure applies. Non-compliance also affects your ability to keep AI systems on the EU market.
Has the EU AI Act been delayed?
Partly. The Digital Omnibus on AI, in force since 27 July 2026, deferred high-risk obligations to 2 December 2027 and 2 August 2028, because standards and national authorities were not ready in time. Nothing else moved. Prohibitions, general-purpose AI model rules, and the transparency and registration duties due on 2 August 2026 all stand. Two new prohibitions were also added, covering AI-generated intimate imagery and child sexual abuse material, and these apply from 2 December 2026.
How do I know if I am a provider or a deployer under the EU AI Act?
The EU AI Act defines providers as organisations that develop an AI system, or have one developed, and then place it on the market or put it into service under their own name or trademark, while deployers use AI systems under their own authority. If you build AI tools and make them available under your own name, including for your own internal use, you are likely a provider.
If you integrate or use AI systems in your processes, you are likely a deployer. Some organisations may hold both roles. AddComply includes a self-assessment tool that helps you identify your role and understand the obligations that apply.
What are the main obligations for high-risk AI providers?
What are the main obligations for AI deployers?
Deployers of high-risk AI systems must follow the provider’s instructions for use, assign human oversight to people with the necessary competence, training and authority, monitor operation, and keep logs for at least six months. Bodies governed by public law, private entities providing public services, and deployers using AI for credit scoring or for life and health insurance pricing must also complete a fundamental rights impact assessment before first use. Deployers must inform workers’ representatives and affected workers before workplace use, and inform individuals subject to AI-assisted decisions. In certain circumstances a deployer takes on provider obligations. AddComply tracks these responsibilities and manages role transitions as they arise.
What is the AI literacy obligation?
Article 4 requires providers and deployers to take measures supporting AI literacy among staff and others using AI systems on their behalf. It has applied since February 2025 and covers all AI systems, not only high-risk ones. The July 2026 amendments softened it: you must take supporting measures, but need not guarantee any specific level of literacy for any individual.