EU AI Act FAQ: Answers to the Most Common Questions

SEO & GEO for WordPress websites

The EU AI Act is now actively shaping how businesses develop, deploy, and manage artificial intelligence across Europe and beyond. Whether you run a SaaS platform, a recruitment tool, or a customer service chatbot, the regulation almost certainly touches your operations. This EU AI Act FAQ brings together the most common questions businesses ask, with direct answers grounded in the current state of the law, including the changes introduced by the AI Omnibus in mid-2026.

The Act is not a single deadline or a one-size-fits-all checklist. It is a layered framework with different obligations depending on what your AI system does, who you are in the supply chain, and where your users are located. Getting clear on those distinctions is the fastest way to move from confusion to a workable compliance plan.

Who the EU AI Act actually applies to

The EU AI Act applies to any organization that places an AI system on the EU market, puts one into service in the EU, or produces AI outputs that are used in the EU, regardless of where that organization is headquartered. This extraterritorial scope mirrors the approach taken by the GDPR, and it means a US-based SaaS company whose AI-powered product is used by customers in Germany is fully in scope.

The Act identifies five distinct actor categories: providers (developers who build and place AI systems on the market), deployers (organizations that use AI systems in a professional context), importers, distributors, and authorized representatives of non-EU providers. Each category carries different obligations, so identifying your role for each AI system you touch is the starting point for any compliance effort.

Some systems fall outside the Act’s reach entirely. AI used solely for scientific research, for personal non-professional purposes, or released under open-source licenses with no systemic risk is generally out of scope. The European Commission published guidelines in February 2025 that break the legal definition of an “AI system” into seven components, drawing a clear line between AI and conventional software that operates by fixed, predetermined rules. If a system does not exercise autonomy or inference, it may not qualify as AI under the Act at all.

UK businesses are not directly subject to the Act post-Brexit, but any UK company whose AI output is used by EU residents, or that sells AI products into the EU market, must comply with the relevant provisions.

How AI systems are classified under the Act

The EU AI Act organizes every in-scope system into one of four risk tiers: unacceptable risk (prohibited), high risk (strict compliance obligations), limited risk (transparency requirements), and minimal risk (no mandatory obligations). Classification is based on what the system actually does, not how it is marketed or named.

Unacceptable risk: what is banned outright

Nine AI practices are prohibited under Article 5. The list includes subliminal manipulation, social scoring by public authorities, real-time remote biometric identification in publicly accessible spaces for law enforcement, untargeted facial recognition database scraping, emotion recognition in workplaces and educational institutions, and biometric categorization used to deduce protected characteristics. The AI Omnibus added a ninth prohibition covering AI-generated non-consensual sexually explicit content, effective December 2026. There is no compliance pathway for these practices; they must be discontinued.

High risk: where most compliance work sits

A system is classified as high risk if it matches one of eight use-case categories listed in Annex III, which covers biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration, and the administration of justice. CV screening tools, supplier credit scoring systems, and student assessment AI all fall under this tier. An additional filter under Article 6(3) means that Annex III systems must also pose a significant risk of harm to health, safety, or fundamental rights; low-risk tools in these sectors may be exempt from the full obligations.

Limited and minimal risk

Limited-risk systems, such as chatbots and deepfake generators, face one primary obligation: users must be informed they are interacting with AI. Minimal-risk systems, including spam filters, recommendation engines, and logistics optimization tools, face no mandatory obligations under the Act. Organizations are still advised to document their classification reasoning in case it is ever challenged.

General-purpose AI models

General-purpose AI (GPAI) models, including systems like GPT-4, Claude, and Gemini, operate under a separate compliance framework that sits alongside the four-tier classification. Models trained with compute exceeding 10²⁵ FLOPs are classified as presenting systemic risk and face enhanced safety requirements, including adversarial testing and incident reporting.

Key obligations businesses must meet

EU AI Act compliance obligations vary significantly by risk tier and by your role in the AI supply chain, but one requirement applies universally from 2 February 2025: AI literacy. Every provider and deployer must take measures to ensure a sufficient level of AI literacy among staff and any contractors who deal with AI systems on their behalf. This is not just a training tick-box; it covers anyone who configures, monitors, or makes decisions based on AI outputs.

Obligations for high-risk AI providers

Providers of high-risk AI systems carry the heaviest compliance burden. The core requirements include establishing a risk management system, implementing data governance, producing technical documentation, enabling logging, ensuring transparency to deployers, supporting human oversight, and achieving accuracy and cybersecurity standards. Before placing a high-risk system on the market, providers must complete a conformity assessment, apply CE marking, and register in the EU database.

For most Annex III systems, conformity assessment can be completed through internal self-assessment. Third-party assessment by a notified body is only mandatory for biometric identification systems under Annex III point 1 and AI systems embedded in regulated products under Annex I.

Obligations for deployers

Deployers of high-risk AI systems must use systems according to the provider’s instructions, assign human oversight to named individuals, ensure input data is relevant, retain automated logs for at least six months, and inform workers before high-risk AI is used to assess them. Public-authority deployers must also register their use in the EU database; private-sector deployers are not required to register but must comply with Article 26 obligations.

GPAI obligations

All GPAI model providers must supply technical documentation, instructions for use, and a summary of training data content, and must comply with the EU Copyright Directive. Providers of GPAI models presenting systemic risk must also conduct model evaluations, run adversarial testing, track and report serious incidents, and maintain cybersecurity protections. The GPAI Code of Practice, published in July 2025 following input from nearly 1,000 stakeholders, is a voluntary tool providers can use to demonstrate compliance with these obligations.

Penalties for non-compliance

The Act sets out a three-tier penalty structure. Violations of the prohibited AI practices carry fines of up to €35 million or 7% of global annual turnover. Most other breaches, including high-risk AI obligations, carry fines of up to €15 million or 3%. Providing incorrect or misleading information to regulators carries fines of up to €7.5 million or 1%. For SMBs, the Act applies the lower of the two figures in each tier, which is a meaningful concession for smaller organizations.

EU AI Act timeline and enforcement dates

The EU AI Act follows a phased implementation schedule, and the AI Omnibus that entered into force in mid-July 2026 extended two of the original deadlines. Understanding which rules are already active and which are still incoming is essential for prioritizing compliance work.

  • 1 August 2024: The Act entered into force.
  • 2 February 2025: Prohibitions on unacceptable-risk AI practices (Article 5) became enforceable. The AI literacy obligation (Article 4) began to apply.
  • 2 August 2025: Rules for GPAI model providers became enforceable. The Article 99 penalty regime became applicable for violations that were already active.
  • 3 August 2026: National market surveillance authorities began enforcement of AI literacy obligations.
  • 2 December 2027: Obligations for standalone high-risk AI systems listed in Annex III now apply from this date, extended from the original August 2026 deadline by the AI Omnibus.
  • 2 August 2028: Obligations for high-risk AI systems embedded in regulated products under Annex I apply from this date, also extended by the Omnibus.

The AI Omnibus extended only the two high-risk deadlines. All other timelines, including prohibitions, GPAI rules, transparency obligations, and AI literacy enforcement, remain on their original dates. The post-Omnibus enforcement timeline is now the legally operative schedule for planning purposes.

One important nuance on penalties: Article 99 penalties apply to violations that are currently active. Fines for prohibited practices and GPAI breaches can be imposed now. Fines for high-risk AI system obligations will only become applicable when those obligations come into force in December 2027 and August 2028, respectively.

Common misconceptions about AI Act compliance

Several persistent misunderstandings are causing organizations to either over-invest in compliance areas that do not yet apply to them, or ignore obligations that are already in effect. These are the most common ones worth correcting.

“The Act only applies to EU-based companies”

The Act has explicit extraterritorial reach. Any organization whose AI output is used in the EU is in scope, regardless of where it is incorporated. A company headquartered in Singapore, Canada, or the United States is subject to EU AI Act requirements if its AI systems serve EU users or affect EU residents.

“Open-source AI is exempt”

The open-source exemption is not a blanket pass. It does not apply to prohibited AI practices, high-risk AI systems, GPAI models with systemic risk, or open-source models that are monetized through paid APIs, hosting services, or personal data processing. Open-source status reduces some documentation obligations for GPAI models, but it does not remove them entirely.

“All facial recognition is banned”

Real-time remote biometric identification in publicly accessible spaces is prohibited for law enforcement use, with narrow exceptions. Not all facial recognition is banned; some biometric systems fall under the high-risk category with compliance obligations rather than an outright prohibition. The distinction between what is prohibited and what is heavily regulated is significant for product and security teams.

“Compliance is a one-time project”

AI Act compliance is an ongoing governance function. Reassessment is required whenever a system’s intended purpose, deployment environment, or underlying model changes. A 2026 readiness report found that 78% of organizations had not taken meaningful steps toward compliance despite being aware the Act exists, and 74% lacked a designated internal owner for it. Treating compliance as a project with a single end date is one of the fastest ways to fall behind.

“There is a single two-year grace period”

The Act has multiple staggered deadlines, not one unified grace period. Prohibited practices have been enforceable since February 2025. GPAI rules have been active since August 2025. The high-risk deadlines now run to December 2027 and August 2028. Organizations that assumed they had until “sometime in 2026” to begin compliance work are already behind on some obligations.

Practical first steps toward EU AI Act readiness

EU AI Act readiness starts with knowing what AI you actually use. Many organizations discover during their first compliance review that AI is embedded in tools they did not actively choose, including third-party HR platforms, CRM systems, and content tools. Without an inventory, classification is impossible.

Step 1: Build an AI inventory

Identify every AI system in use, in development, or under consideration for procurement. Map each system to the Act’s four risk tiers. This inventory becomes the foundation for every subsequent compliance decision, from documentation requirements to training obligations.

Step 2: Screen for prohibited practices immediately

Article 5 prohibitions have been enforceable since 2 February 2025. Any system that falls under a banned category must be discontinued. There is no compliance pathway for prohibited AI, and the penalty exposure is the highest in the Act.

Step 3: Determine your role for each system

Organizations often act simultaneously as providers, deployers, importers, or distributors depending on the system. The obligations differ significantly by role. Assigning the correct role to each AI system before building compliance tasks prevents duplication and gaps.

Step 4: Implement AI literacy training

The Article 4 literacy obligation applies to all staff and contractors who deal with AI systems. Training should be documented. National market surveillance authorities began enforcement of this obligation from 3 August 2026, so organizations without a documented literacy program are already exposed.

Step 5: Build documentation and governance for high-risk systems

For any system that will fall under the Annex III high-risk obligations from December 2027, technical documentation, data governance records, model performance metrics, and human oversight procedures need to be built now. The lead time for getting these in order is longer than most organizations expect.

Step 6: Align with overlapping frameworks

The EU AI Act works alongside, not instead of, the GDPR. When AI systems process personal data, both frameworks apply simultaneously. ISO 42001, the AI management system standard, is frequently referenced as a complementary governance tool that helps organizations structure their AI Act compliance work within a broader risk management system.

If your organization needs to produce compliant, AI-ready content at scale while navigating these regulatory requirements, the Act’s high-level summary is a useful reference for understanding which content-related AI obligations apply to your publishing workflows. Scaling content production through tools like the WP SEO Agent can help you meet both your growth goals and your transparency obligations, since the hybrid model keeps human specialists in the loop at every stage of the process.

The EU AI Act is complex, but it is navigable. The organizations that will find it most manageable are those that treat it as an ongoing governance discipline rather than a compliance sprint, start with what is already enforceable, and build their processes in proportion to the actual risk level of the AI they use.

This content was generated with the help of AI and it may contain mistakes

Your customers are asking AI. Are you part of the answer?

In a quick demo, we show how WP SEO AI tracks your AI visibility, finds content gaps, and helps your website appear in ChatGPT, Google AI Overviews and more.

Dive deeper in