← Blog
Compliance AI Act

AI Act: classifying risk without panic

by Team P3·2 July 2026·9 min read

The AI Act is Regulation EU 2024/1689: it classifies AI systems into four risk tiers — prohibited practices, high-risk, transparency, minimal risk — and assigns proportionate obligations. The vast majority of systems used in the EU today are minimal risk. And the Omnibus approved on 29 June 2026 moves high-risk to 2 December 2027. What you need is an inventory, not panic.

01What is the AI Act, and why is panic the wrong response?

The AI Act is Regulation (EU) 2024/1689, the world's first general legal framework on artificial intelligence: published in the Official Journal on 12 July 2024, in force since 1 August 2024, with staggered application through 2027-2028 (EUR-Lex, Reg. EU 2024/1689). Being a regulation, not a directive, it applies directly across all Member States, with no national transposition.

The point the background noise makes you miss: the AI Act does not ban AI and does not impose the same obligations on everyone. It is built on a risk-based approach: the higher the risk to health, safety and fundamental rights, the heavier the obligations. And according to the European Commission itself, the vast majority of AI systems currently used in the EU fall into the minimal-risk category, the one with no specific obligations (European Commission, AI Act). For an SME the real question is not "can I still use AI?", but "which box do the systems I use fall into?".

A regulation, not a directive. The AI Act needs no national transposition law to be binding. The European text is already the operating rule, identical in Tallinn, Rome and Madrid.

02How does the risk pyramid work?

The whole AI Act rests on four tiers. They are not academic labels: they determine what you must do, and when.

The right question is not "does the AI Act forbid me from using AI?". It is "do I know which AI systems I am using, and with which data?".

03Is your system really "high-risk"?

This is where most of the panic comes from, and where reading the text pays off. Being in an Annex III area is not enough to make a system high-risk. Article 6(3) excludes systems that pose no significant risk to health, safety or fundamental rights, when they perform a narrow procedural task, improve the result of a previously completed human activity, detect decision-making patterns without replacing the human assessment, or perform a preparatory task to an assessment (EUR-Lex, Reg. EU 2024/1689, Art. 6). One hard exception: profiling of natural persons always remains high-risk. And the exclusion must be documented before putting the system into service, with registration (Art. 49).

The role matters too. The AI Act distinguishes the provider (who develops and places on the market) from the deployer (who uses the system under its own authority). Most SMEs are deployers, with much lighter obligations: use the system according to the instructions, ensure human oversight, keep input data relevant. The heavy obligations — conformity assessment, technical documentation, CE marking — sit with the provider.

The trap of the deployer who becomes a provider. If you put your trademark on a high-risk AI system, substantially modify it or change its intended purpose so that it becomes high-risk, the provider's obligations shift to you (Art. 25). This also applies to anyone "re-branding" someone else's model inside their own product.

04The dates and numbers that matter

Three citable figures, from official sources, frame the perimeter without noise.

2 Feb 2025
prohibitions (Art. 5) and AI literacy already in force
2 Dec 2027
new date for high-risk Annex III (2026 Omnibus; was 2 Aug 2026)
€35M / 7%
maximum fine for prohibited practices (Art. 99)

The full calendar, after the Omnibus: prohibitions and AI literacy since 2 February 2025; GPAI model rules and governance since 2 August 2025; general application and transparency obligations from 2 August 2026, with the technical marking of generated content (watermarking) moved to 2 December 2026; high-risk Annex III from 2 December 2027; AI embedded in regulated products from 2 August 2028 (AI Act Service Desk, official timeline; European Parliament, 16 June 2026).

On penalties, Article 99 sets three bands: up to €35 million or 7% of worldwide annual turnover for prohibited practices; up to €15 million or 3% for breaching the other obligations; up to €7.5 million or 1% for supplying incorrect information to authorities. For large companies the higher of the two applies; for SMEs and start-ups, the lower (EUR-Lex, Reg. EU 2024/1689, Art. 99).

05What changes with the June 2026 Omnibus?

The AI Act's implementation was structurally late: harmonised standards not ready, national authorities not designated. The Commission proposed the Digital Omnibus package in November 2025; the political agreement came on 7 May 2026, the European Parliament approved it on 16 June 2026 with 423 votes in favour, and the Council gave its final green light on 29 June 2026. The text enters into force on the third day after publication in the Official Journal (Council of the EU, 29 June 2026).

What changes in practice: the obligations for high-risk systems are deferred (Annex III to 2 December 2027, Annex I products to 2 August 2028); the exemptions designed for SMEs extend to small mid-caps; processing personal data to detect and correct bias becomes permitted, with safeguards; and a new prohibition arrives — systems generating non-consensual intimate imagery ("nudify" apps) or child sexual abuse material, outlawed from 2 December 2026 (European Parliament, 16 June 2026).

What the Omnibus does not do: it does not touch the prohibitions already in force, does not cancel transparency, does not repeal high-risk. It is a technical deferral, driven by the missing standards, not a change of heart. Anyone reading "deferral" as "shelved" will arrive in December 2027 in the same state many arrived at the GDPR in May 2018.

The deferral to 2027 is not an amnesty. It is the time to do calmly what was done in a panic with the GDPR.

06Where to start, concretely

As with DORA and NIS2, you start with the snapshot, not the policy. First: an inventory of the AI systems in use — including those hidden inside the SaaS you already use — with three questions for each: what data does it touch, who is the provider, from which jurisdiction is it served. Second: classification by risk tier, with the Art. 6(3) derogation at hand. Third: the role — are you a deployer, or are you becoming a provider without knowing it? Meanwhile, AI literacy (Art. 4) is already due: whoever uses AI systems in the company must understand what they are using.

There is also an architecture choice that reduces exposure even before compliance: sovereign AI. A model running on controlled infrastructure, on-premise or EU-hosted, makes data governance, logging and human oversight demonstrable — and removes the dependency on a non-EU API that can change terms, model or jurisdiction without asking you. It is the same principle we defend on European digital sovereignty and apply in our sovereign AI products: control is measured by who touches the data, not by the vendor's brochure. If you want to start from the snapshot — network, data, AI systems included — the first step is a seven-day on-prem audit. To discuss your case, write to us.

In short. The AI Act is Reg. EU 2024/1689: four risk tiers, proportionate obligations, and the vast majority of systems in use at minimal risk. Prohibitions in force since 2 February 2025; transparency from 2 August 2026; high-risk deferred by the Omnibus to 2 December 2027 (Annex III) and 2 August 2028 (products). Fines up to €35M/7%, but for SMEs the lower amount applies. Start with the inventory of your AI systems, not with panic.
[P3]
Team P3
Technical boutique · EU-hosted
P3 team notes on compliance and ICT resilience, written by those who apply them for European SMEs. Write to us →
Need to classify the AI you use?

Start with the inventory of your AI systems.

[ Book Munin ]