The AI Act is Regulation EU 2024/1689: it classifies AI systems into four risk tiers — prohibited practices, high-risk, transparency, minimal risk — and assigns proportionate obligations. The vast majority of systems used in the EU today are minimal risk. And the Omnibus approved on 29 June 2026 moves high-risk to 2 December 2027. What you need is an inventory, not panic.
01What is the AI Act, and why is panic the wrong response?
The AI Act is Regulation (EU) 2024/1689, the world's first general legal framework on artificial intelligence: published in the Official Journal on 12 July 2024, in force since 1 August 2024, with staggered application through 2027-2028 (EUR-Lex, Reg. EU 2024/1689). Being a regulation, not a directive, it applies directly across all Member States, with no national transposition.
The point the background noise makes you miss: the AI Act does not ban AI and does not impose the same obligations on everyone. It is built on a risk-based approach: the higher the risk to health, safety and fundamental rights, the heavier the obligations. And according to the European Commission itself, the vast majority of AI systems currently used in the EU fall into the minimal-risk category, the one with no specific obligations (European Commission, AI Act). For an SME the real question is not "can I still use AI?", but "which box do the systems I use fall into?".
02How does the risk pyramid work?
The whole AI Act rests on four tiers. They are not academic labels: they determine what you must do, and when.
- Unacceptable risk — banned. Eight practices prohibited since 2 February 2025 (Art. 5): harmful manipulation, social scoring, emotion recognition in the workplace, real-time biometric identification in public spaces for law enforcement save for exceptions, and others (European Commission, AI Act).
- High risk — heavy obligations. Systems that are safety components of regulated products (Annex I) or that operate in the Annex III areas: biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration, justice. They require risk management, data quality, logging, documentation, human oversight, conformity assessment.
- Transparency risk — disclose. Art. 50: anyone interacting with a chatbot must know it; deepfakes and AI-generated content must be labelled.
- Minimal risk — no specific obligations. Spam filters, AI in video games, most office tools with AI inside.
03Is your system really "high-risk"?
This is where most of the panic comes from, and where reading the text pays off. Being in an Annex III area is not enough to make a system high-risk. Article 6(3) excludes systems that pose no significant risk to health, safety or fundamental rights, when they perform a narrow procedural task, improve the result of a previously completed human activity, detect decision-making patterns without replacing the human assessment, or perform a preparatory task to an assessment (EUR-Lex, Reg. EU 2024/1689, Art. 6). One hard exception: profiling of natural persons always remains high-risk. And the exclusion must be documented before putting the system into service, with registration (Art. 49).
The role matters too. The AI Act distinguishes the provider (who develops and places on the market) from the deployer (who uses the system under its own authority). Most SMEs are deployers, with much lighter obligations: use the system according to the instructions, ensure human oversight, keep input data relevant. The heavy obligations — conformity assessment, technical documentation, CE marking — sit with the provider.
04The dates and numbers that matter
Three citable figures, from official sources, frame the perimeter without noise.
The full calendar, after the Omnibus: prohibitions and AI literacy since 2 February 2025; GPAI model rules and governance since 2 August 2025; general application and transparency obligations from 2 August 2026, with the technical marking of generated content (watermarking) moved to 2 December 2026; high-risk Annex III from 2 December 2027; AI embedded in regulated products from 2 August 2028 (AI Act Service Desk, official timeline; European Parliament, 16 June 2026).
On penalties, Article 99 sets three bands: up to €35 million or 7% of worldwide annual turnover for prohibited practices; up to €15 million or 3% for breaching the other obligations; up to €7.5 million or 1% for supplying incorrect information to authorities. For large companies the higher of the two applies; for SMEs and start-ups, the lower (EUR-Lex, Reg. EU 2024/1689, Art. 99).
05What changes with the June 2026 Omnibus?
The AI Act's implementation was structurally late: harmonised standards not ready, national authorities not designated. The Commission proposed the Digital Omnibus package in November 2025; the political agreement came on 7 May 2026, the European Parliament approved it on 16 June 2026 with 423 votes in favour, and the Council gave its final green light on 29 June 2026. The text enters into force on the third day after publication in the Official Journal (Council of the EU, 29 June 2026).
What changes in practice: the obligations for high-risk systems are deferred (Annex III to 2 December 2027, Annex I products to 2 August 2028); the exemptions designed for SMEs extend to small mid-caps; processing personal data to detect and correct bias becomes permitted, with safeguards; and a new prohibition arrives — systems generating non-consensual intimate imagery ("nudify" apps) or child sexual abuse material, outlawed from 2 December 2026 (European Parliament, 16 June 2026).
What the Omnibus does not do: it does not touch the prohibitions already in force, does not cancel transparency, does not repeal high-risk. It is a technical deferral, driven by the missing standards, not a change of heart. Anyone reading "deferral" as "shelved" will arrive in December 2027 in the same state many arrived at the GDPR in May 2018.
06Where to start, concretely
As with DORA and NIS2, you start with the snapshot, not the policy. First: an inventory of the AI systems in use — including those hidden inside the SaaS you already use — with three questions for each: what data does it touch, who is the provider, from which jurisdiction is it served. Second: classification by risk tier, with the Art. 6(3) derogation at hand. Third: the role — are you a deployer, or are you becoming a provider without knowing it? Meanwhile, AI literacy (Art. 4) is already due: whoever uses AI systems in the company must understand what they are using.
There is also an architecture choice that reduces exposure even before compliance: sovereign AI. A model running on controlled infrastructure, on-premise or EU-hosted, makes data governance, logging and human oversight demonstrable — and removes the dependency on a non-EU API that can change terms, model or jurisdiction without asking you. It is the same principle we defend on European digital sovereignty and apply in our sovereign AI products: control is measured by who touches the data, not by the vendor's brochure. If you want to start from the snapshot — network, data, AI systems included — the first step is a seven-day on-prem audit. To discuss your case, write to us.