Does the EU AI Act apply to me?
The AI Act reaches UK, US and other non-EU companies too. Answer five questions about what you do with AI, where you are based, your link to the EU and the use case, and see your role, your risk tier, what applies already and what applies from 2027.
Yes, if you build, sell or use AI with a link to the EU, wherever you are based: you place AI on the EU market, you are in the EU, or your AI's output is used there. UK and US companies are covered on those terms. Duties depend on role and risk tier. Prohibitions have applied since February 2025 and transparency since August 2026; high-risk duties start in December 2027.
Result
Since 2 August 2026, providers must make sure people know they are talking to an AI unless it is obvious, and that synthetic audio, image, video and text is marked in a machine-readable way. Deployers must disclose deepfakes and AI-generated text published to inform the public. Systems on the market before 2 August 2026 have until 2 December 2026 for the marking duty. This applies to UK, US and other non-EU companies in the same way as EU ones: Article 2 covers providers placing systems on the EU market wherever they are established, and non-EU providers and deployers whose AI output is used in the EU.
- Now: add a clear AI disclosure at the first interaction, and check that generated output carries a watermark or metadata marker.
- Literacy: Article 4 applies too: record the AI training your team has had.
- Governance: see what else a company building on LLMs needs with the AI governance checker.
Who the Act covers
Article 2 applies the Act to providers that place AI systems or general-purpose AI models on the EU market, wherever they are established; to deployers established or located in the EU; to providers and deployers in third countries whose AI output is used in the EU; to importers and distributors; to product manufacturers shipping AI under their own name; and to authorised representatives of non-EU providers. A US or Indian company with EU customers is in scope in the same way as a European one.
The Act does not apply to AI used exclusively for military, defence or national security; to AI developed solely for scientific research; to research and testing before market placement (real-world testing is not excluded); or to individuals' purely personal use. Free and open-source AI is excluded unless it is high-risk, prohibited or subject to Article 50.
The four roles
A provider develops an AI system or model, or has one developed, and puts it out under its own name, paid or free. A deployer uses an AI system under its authority in a professional capacity. An importer is an EU entity placing a non-EU provider's system on the market; a distributor makes it available further down the chain. Roles attach to each system, so one company can be the provider of its product and a deployer of the tools its staff use. A deployer or distributor that rebrands or substantially modifies a high-risk system becomes its provider (Art. 25).
The risk tiers
Prohibited practices (Art. 5) are banned. High-risk systems are AI that is a safety component of a product under the EU laws in Annex I, or a use listed in Annex III; they carry the heaviest duties. Transparency duties (Art. 50) cover chatbots, emotion recognition, biometric categorisation and synthetic content. General-purpose AI models (Arts. 51 to 55) have their own regime, with more for models carrying systemic risk. Everything else is minimal risk, with AI literacy (Art. 4) as the one general duty.
EU AI Act applicability dates
The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and is adopted law. It moved the high-risk dates and added two prohibitions; it did not move the prohibitions already in force, the general-purpose AI rules or Article 50 transparency. Much published guidance still gives the original August 2026 and 2027 high-risk dates.
| Date | What applies | Legal basis |
|---|---|---|
| 2 February 2025 | Definitions, AI literacy (Art. 4) and the prohibited practices (Art. 5) | Art. 113(a) |
| 2 August 2025 | General-purpose AI model duties, governance, notified bodies, penalties (except GPAI fines) | Art. 113(b) |
| 27 July 2026 | Digital Omnibus on AI in force; Articles 102 to 110 apply | Reg. 2026/1744 |
| 2 August 2026 | General application: Article 50 transparency, Commission fines for GPAI providers (Art. 101) | Art. 113 |
| 2 December 2026 | Two new prohibitions (intimate imagery, child sexual abuse material); Article 50(2) marking for generative systems on the market before 2 August 2026 | Art. 113(a), Art. 111(4), as amended |
| 2 August 2027 | Deadline for GPAI models placed on the market before 2 August 2025 | Art. 111(3) |
| 2 December 2027 | High-risk duties for Annex III systems (hiring, credit, education, essential services and more) | Art. 113(c)(i), as amended |
| 2 August 2028 | High-risk duties for AI in Annex I products (medical devices, toys, lifts and more) | Art. 113(c)(ii), as amended |
| 2 August 2030 | High-risk systems used by public authorities and already on the market must comply | Art. 111(2), as amended |
Dates as amended by Regulation (EU) 2026/1744, the Digital Omnibus on AI, which is adopted law.
Penalties
Fines reach EUR 35 million or 7% of worldwide annual turnover for prohibited practices; EUR 15 million or 3% for most other operator duties, including Article 50; and EUR 7.5 million or 1% for misleading information to authorities. In each case the higher figure is the cap, except for SMEs and start-ups, and since the Omnibus small mid-caps, where the lower figure applies. National authorities enforce most of this; the Commission fines GPAI providers directly. See EU AI Act penalties.
Sources
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), EUR-Lex
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), EUR-Lex
- European Commission: AI Act regulatory framework
- European Commission: AI literacy questions and answers
- European Commission AI Act Service Desk: EU AI Act Compliance Checker (official, complementary tool)
Facts checked against these sources in October 2026. Laws, thresholds and guidance change: check the source before you rely on a figure.
The things people ask us
Does the EU AI Act apply to US companies?
Yes, if they place AI systems on the EU market or their AI's output is used in the EU (Article 2(1)(a) and (c)). Where a provider is established does not matter; what matters is the EU link.
Does the EU AI Act apply to UK companies?
Yes, on the same terms as any non-EU company. Brexit does not take a UK provider out of scope if it sells AI systems into the EU or its AI's output is used there, and non-EU providers of high-risk systems must appoint an authorised representative in the EU.
What are the EU AI Act applicability dates?
Prohibitions and AI literacy from 2 February 2025; general-purpose AI models from 2 August 2025; Article 50 transparency from 2 August 2026; high-risk duties from 2 December 2027 (Annex III) and 2 August 2028 (Annex I), as amended by the Digital Omnibus.
Is using ChatGPT at work covered by the AI Act?
Yes. A company using an AI system professionally is a deployer. For general workplace use, the main duty is Article 4 AI literacy; the deployer duties in Article 26 apply only to high-risk uses, such as screening job applicants.
Did the Digital Omnibus delay the transparency rules?
No. Article 50 has applied since 2 August 2026. The Omnibus only gave generative systems already on the market before that date until 2 December 2026 to add machine-readable marking.
What are the fines under the EU AI Act?
Up to EUR 35 million or 7% of worldwide turnover for prohibited practices, and up to EUR 15 million or 3% for most other breaches. For SMEs and start-ups, the lower of the two figures is the cap.
If I build on OpenAI or Anthropic models, am I a provider?
Usually yes, of your own AI system, if you offer it under your name. The model's maker is the provider of the general-purpose model; you carry the duties for your system, such as transparency or high-risk requirements.
Does the AI Act require AI literacy training?
Article 4 requires providers and deployers to take measures to support their staff's AI literacy. The Omnibus made clear that no specific level is mandated, and the Commission says no certificate is needed; an internal record of training is enough.
See what applies to you, and track it.
TryTrustable maps your controls to every framework you need and keeps the evidence current.