EU AI Act in 2026: What Tech Companies Must Do Now

Last Updated: September 10, 2026 | By Mihail Sebastian | Laws of AI

The EU AI Act's main obligations now apply. What the risk tiers, GPAI rules, and deployer duties mean for tech companies, and where to start.

EU AI Act in 2026: What Tech Companies Must Do Now
Photo by Christian Lue on Unsplash

The EU AI Act entered into force in August 2024 as the world’s first comprehensive AI statute. Two years on, it is no longer something to prepare for. Its main obligations apply, and companies selling or using AI in the EU are expected to meet them.

The Act’s reach extends well beyond Europe. It applies to providers and deployers anywhere in the world whenever their system is placed on the EU market or its output is used in the EU.

This post covers where the Act stands in September 2026, what it asks of tech companies by role, and how to build a defensible position.

Where the Act Stands Now

The Act applies in phases, and most of those phases have now passed. The prohibitions on certain AI practices took effect first, in early 2025. Obligations for providers of general-purpose AI models followed in August 2025.

The main obligations for high-risk AI systems began applying in August 2026. That is the milestone that changes daily work for most companies: hiring tools, credit models, and medical AI now have to meet the high-risk requirements rather than plan for them.

The statute is only part of the picture. The standards, guidance, and market surveillance being built around it are AI regulation in the broader sense, and they keep moving. A company reads the law to learn its obligations and watches regulators to learn how those obligations will be interpreted and enforced.

The Four Risk Tiers

The core of the EU AI Act is its four risk tiers. Obligations attach to the AI use case, not to the company, so one vendor can face all four at once.

  1. Prohibited practices: Uses judged incompatible with fundamental rights are banned outright, including social scoring by public authorities and real-time remote biometric identification in public spaces, the latter with narrow law-enforcement exceptions.
  2. High-risk systems: AI used in areas such as hiring, credit scoring, medical devices, and law enforcement must meet requirements for risk management, data governance, technical documentation, human oversight, and accuracy and robustness, and pass a conformity assessment before reaching the market.
  3. Transparency obligations: Systems that interact with people or generate content carry disclosure duties. A chatbot must reveal that it is one, and AI-generated media must be identifiable as such.
  4. Minimal risk: Everything else, from spam filters to game AI, faces no new obligations.

The tier system is why a single company can ship a minimal-risk spam filter, a chatbot with a disclosure duty, and a CV screener that carries the full high-risk program. Classification is the first compliance decision, and everything else follows from it.

Provider or Deployer: Obligations by Role

The Act splits duties between two roles. The provider builds the system or places it on the market; the deployer uses it in its own operations. Most tech companies are both, providers of some systems and deployers of many more.

Providers of high-risk systems carry the heavier load. They must set up risk management, document training data and design choices, build in human oversight, pass the conformity assessment, and monitor the system after launch, including reporting serious incidents. Depending on the system, the assessment is an internal check or a third-party evaluation.

Deployers have their own duties, and buying a compliant tool does not discharge them. A bank deploying a vendor’s credit model must use it as intended, keep human-in-the-loop oversight working in practice, and retain the logs the system produces. In recruitment, credit, and medical settings, the deployer is the one facing the affected person, which is exactly where regulators look.

The split matters when things go wrong. A deployer cannot point at the vendor’s conformity assessment if its own staff routinely waved the model’s decisions through unread, and a provider cannot point at the deployer if the documentation was wrong from the start.

General-Purpose AI and Foundation Models

The Act also regulates the layer beneath applications: general-purpose AI (GPAI) models, the foundation models behind chatbots and generative tools. Their providers carry documentation and transparency duties, including technical documentation for downstream developers and disclosures about training content.

Models designated as posing systemic risk carry heavier duties on top: model evaluation, risk assessment and mitigation, and incident reporting. The designation targets the most capable models, not every LLM on the market.

For most tech companies the practical question is downstream. If you build a product on a foundation model, your own obligations still come from your use case’s risk tier, but your provider’s GPAI documentation is input you will need for your own technical file.

Agentic AI Under the Act

The Act has no chapter on AI agents. But agents, systems that plan and act across tools rather than answer single prompts, concentrate the Act’s existing obligations in uncomfortable ways, mostly on the deployer.

Human oversight is the sharpest example. An agent that executes multi-step tasks autonomously stretches the question of what meaningful oversight looks like: someone must be able to understand what the agent is doing and intervene. Logging follows the same pattern, since an agent’s actions across tools are exactly the record a regulator or auditor will ask for, which is what agent observability exists to provide.

The quieter problem is knowing what you run. Agents multiply fast, borrow credentials, and reach tools nobody reviewed, and an obligation to classify your AI systems assumes you can list them. An AI registry that covers agents and the tools they reach, not just models, is where that answer lives.

What to Do Now

With the main obligations applying, “wait and see” has run out of runway. The useful posture is short and concrete, and it starts with knowing what you have.

The penalties reward taking this seriously. Fines reach €35 million or 7% of worldwide turnover for prohibited practices, and €15 million or 3% for most other violations, and authorities can order corrective action or pull a system from the market.

The Act also offers some relief. Regulatory sandboxes let companies test systems under supervision, and small and medium-sized enterprises receive guidance and support.

The Strategic View

Compliance with the EU AI Act is a market-access requirement, and increasingly a procurement one: enterprise buyers now ask vendors for the same documentation regulators do. A company that can produce its classification records and technical files on request closes deals that a scrambling competitor cannot.

The work compounds. The inventory, classification, and ownership discipline the Act forces is the same discipline every other AI rule, and every internal governance question, will draw on. Companies that built it early are finding that the Act was the reason, not the whole return.

Frequently Asked Questions

Written by

Mihail Sebastian

Mihail Sebastian

Editor, AI Guv

Mihail works in AI and writes about artificial intelligence topics for people who need to understand it without building it. He comes from more than 20 years of product design in startups.

Read the Governor's Letter

Stay ahead with Governor's Letter, the newsletter delivering expert insights, AI updates, and curated knowledge directly to your inbox.

By subscribing to the Governor's Letter, you consent to receive emails from AI Guv.
We respect your privacy - read our Privacy Policy to learn how we protect your information.