Artificial Intelligence has officially entered the era of regulation.
After nearly two years of phased implementation, the European Union AI Act has now reached one of its most significant milestones. From 2 August 2026, several key provisions including transparency obligations, governance mechanisms, and enforcement powers are officially in force across the European Union.
For organizations developing, deploying, or integrating AI systems into products and services used within the EU, compliance is no longer optional. It is now a legal requirement.
Whether you're building your own foundation models, integrating OpenAI or Anthropic APIs into enterprise applications, or deploying AI-powered customer solutions, the EU AI Act is likely to impact how your AI systems are designed, documented, and governed.
At Hrida AI, we build AI-powered products across HR and learning, enterprise operations, and client-facing multi-agent systems which means this regulation touches several of the categories we build for directly.
That's why we've broken it down here.
Why This Act Matters
Artificial Intelligence has evolved faster than any previous digital technology, transforming industries ranging from healthcare and finance to education, manufacturing, and public services. Until recently, there was no unified legal framework defining how AI systems should be developed, deployed, governed, and held accountable.
To address this gap, the European Union introduced the Artificial Intelligence Act (EU AI Act) - the world's first comprehensive legal framework dedicated exclusively to artificial intelligence.
Unlike privacy regulations such as GDPR, which govern how personal data is collected and processed, the EU AI Act governs how AI systems themselves are designed, trained, deployed, monitored, and used throughout their lifecycle. Its objective is to ensure that AI deployed within the European Union is safe, transparent, human-centric, and accountable, while still enabling responsible innovation.
The regulation officially entered into force on 1 August 2024 and is being implemented in phases. Initial provisions, including the prohibition of certain unacceptable AI practices, became applicable in February 2025, followed by obligations for General-Purpose AI (GPAI) model providers in August 2025. The latest milestone came on 2 August 2026, when key transparency obligations under Article 50, governance mechanisms, and enforcement powers became operational across the European Union, marking the start of active regulatory enforcement for many AI systems.
For organizations worldwide including those in India, the United States, Australia, and elsewhere , the Act has significant implications. Any company that develops AI systems, integrates third-party foundation models, or offers AI-powered products and services to users within the European market may fall within scope, regardless of where the company is headquartered. Compliance with the EU AI Act is therefore becoming an essential consideration for organizations building AI products for a global market.
Understanding the EU AI Act's Risk-Based Framework
Rather than regulating every AI application equally, the EU AI Act follows a risk-based approach, where compliance obligations increase according to the level of risk an AI system poses to individuals, businesses, and society.

| Risk Level | Legal Basis | What It Means | % of AI Systems | Real-World Examples |
|---|---|---|---|---|
| Unacceptable Risk | Article 5 - banned since 2 February 2025 | Prohibited outright, with no conformity path available. These systems pose a serious threat to people's safety, rights, or freedoms and generally cannot be developed, sold, or used within the EU. | ~1% | Social scoring by governments, real-time biometric surveillance in public spaces (outside narrow exceptions), manipulation of vulnerable individuals, untargeted facial-image scraping to build recognition databases, emotion inference in workplaces or education, biometric categorisation by sensitive attributes, and predictive policing based solely on profiling. |
| High Risk | Annex III use cases + Annex I embedded products - full obligations from 2 December 2027 (Annex III) and 2 August 2028 (Annex I) | Significant risk to health, safety, or fundamental rights. Subject to comprehensive conformity assessment, technical documentation, human oversight, and registration requirements. | ~8–10% | CV screening, interview analysis, and performance monitoring in HR; admissions, grading, and proctoring in education; credit scoring, insurance underwriting, and benefits eligibility; face recognition and biometric identification; predictive policing and evidence analysis; critical infrastructure management; border and migration risk profiling; legal research and sentencing tools. |
| Limited Risk | Article 50 - applies from 2 August 2026 | Primarily chatbots, deepfake generators, and AI-content generators. Must disclose AI involvement to users and label AI-generated content. No conformity assessment is required, but transparency obligations are mandatory and enforceable. | ~15–20% | Chatbots and interactive AI systems must inform users they are interacting with AI rather than a human; deepfakes must include machine-readable labels; publishers of AI-generated text on public-interest topics must disclose its AI-generated origin; deployers of emotion-recognition AI must notify affected individuals. |
| Minimal Risk | No mandatory rules; voluntary codes of conduct encouraged | Covers the vast majority of everyday AI applications, with no mandatory obligations attached. | ~70% | Spam filtering, grammar correction, recommendation engines, internal productivity tools, and AI used in video games. |
Note: The percentage estimates above are commonly cited approximations from AI Act compliance guides rather than official EU statistics and should be treated as indicative, not precise.
Example
A well-known example often associated with the Unacceptable Risk category is Clearview AI. The company created a facial recognition database by scraping billions of publicly available images from the internet without individuals' consent.Several European privacy regulators including those in France, Italy, Greece, and the Netherlands ruled that these practices violated the General Data Protection Regulation (GDPR) and collectively imposed nearly €100 million in fines.However, it's important to note that these penalties were issued under GDPR, not the EU AI Act. At the time, the AI Act had not yet introduced its specific prohibition on untargeted facial image scraping. That ban only became applicable in February 2025 under Article 5 of the EU AI Act.
The Clearview AI case is therefore best understood as an example of the type of AI practice that is now prohibited under the EU AI Act, rather than as an enforcement action taken under the Act itself.
What Actually Changed on 2 August 2026
This is the detail that many overviews of the Act skim past: 2 August 2026 did not make every provision of the Act applicable overnight. Instead, it activated enforcement of several core requirements - some brand new, others already technically in force and now actively policed.
| Obligation | Legal Basis | Who Must Comply | What's Required | Status as of 2 August 2026 |
|---|---|---|---|---|
| Chatbot / AI disclosure | Article 50 | Providers and deployers of conversational AI | Inform users they're interacting with AI, not a human. | Newly enforceable |
| Deepfake labelling | Article 50 | Any provider generating synthetic audio, video, or image | Machine-readable disclosure that content is AI-generated. | Newly enforceable |
| AI-generated text disclosure | Article 50 | Publishers of AI-generated text on public-interest topics | Clearly disclose that the text is AI-generated. | Newly enforceable |
| Emotion recognition disclosure | Article 50 | Deployers of emotion-recognition AI | Notify individuals that emotion recognition is being used. | Newly enforceable |
| Prohibited practices | Article 5 | All organisations | The eight banned practices include subliminal manipulation, exploiting vulnerabilities, social scoring, real-time biometric identification in public spaces, untargeted facial-image scraping, emotion inference in workplaces or education, biometric categorisation using sensitive attributes, and predictive policing based solely on profiling. | Banned since 2 February 2025 - now under active enforcement |
| GPAI provider obligations | Chapter V | Providers of General-Purpose AI (GPAI) models (e.g., GPT, Gemini, Claude, Llama-class) | Maintain technical documentation, provide downstream documentation, comply with copyright requirements, publish training-data summaries, and (for systemic-risk models) implement adversarial testing, incident reporting, and cybersecurity measures. | Applicable since 2 August 2025 - now under active enforcement |
Some transitional provisions under Article 50(2), covering certain AI-generated illegal content and legacy systems already on the market, are understood to phase in slightly later, around December 2026, rather than applying in full from 2 August 2026. Organizations relying on this timeline for compliance decisions should confirm current subsection-level applicability against the official regulation text or legal counsel, since secondary summaries (including this one) can round off details that matter in practice.
In short, alongside the Article 50 obligations above, the AI Office also gained expanded enforcement powers over GPAI providers, national market surveillance authorities gained authority to investigate and enforce compliance, and governance and oversight mechanisms became operational across EU Member States. Obligations for most High-Risk AI systems continue to follow later implementation milestones in 2027 and 2028.
What AI Providers Should Be Aware Of
Under the EU AI Act, an AI provider is any organization that develops, trains, significantly modifies, or places an AI system or General-Purpose AI (GPAI) model on the European market under its own name.
Providers are expected to integrate compliance into the AI development lifecycle rather than treating it as a post-development exercise. This includes maintaining comprehensive technical documentation, documenting model capabilities and limitations, implementing risk management procedures, ensuring appropriate cybersecurity measures, maintaining traceability throughout the AI lifecycle, and continuously monitoring system performance after deployment.
For generative AI providers, transparency has become particularly important. AI-generated content should include appropriate machine-readable markings where required, and providers must build mechanisms that enable downstream deployers to satisfy their own legal obligations. Organizations should also establish internal AI governance processes that clearly define ownership, accountability, documentation standards, incident management, and compliance reviews before releasing AI systems into production.
What AI Deployers Should Be Aware Of
An AI deployer is an organization that uses an existing AI system within its business operations or customer-facing applications.
Many organizations assume compliance is solely the responsibility of AI vendors. The EU AI Act makes clear that deployers also carry significant responsibilities.
Deployers should first identify every AI system currently used within their organization and understand its regulatory classification. They must ensure that users are informed whenever they are interacting with AI systems where required, provide appropriate disclosures for AI-generated or manipulated content, maintain records of AI usage, implement meaningful human oversight for decision-making processes, and continuously monitor deployed systems to ensure they continue operating safely and responsibly.
Organizations deploying High-Risk AI systems must also use those systems according to the provider's instructions, retain system logs where required, conduct impact assessments where applicable, and establish governance processes that support compliance throughout the operational lifecycle. Compliance is therefore a shared responsibility between those who build AI and those who deploy it.
Why This Matters Beyond Europe
The EU AI Act is widely expected to become for artificial intelligence what GDPR became for data privacy a global benchmark for responsible technology governance.
Many organizations headquartered outside Europe assume the regulation does not apply to them. In reality, if an AI system is placed on the European market or its outputs are used by individuals or organizations within the EU, the Act may still apply, regardless of where the provider or deployer is located.
Beyond avoiding regulatory penalties, organizations that invest early in AI governance will be better positioned to build customer trust, accelerate enterprise adoption, and demonstrate responsible AI practices during procurement, security reviews, and compliance audits. As governments worldwide continue introducing AI-specific regulations, organizations that establish governance, transparency, and accountability today will be significantly better prepared for tomorrow's regulatory landscape.
Conclusion
The enforcement of the EU AI Act marks a turning point in the global AI ecosystem. Artificial intelligence is no longer evaluated solely on model performance or innovation - it is increasingly judged by how responsibly it is developed, deployed, and governed.
For organizations building AI products or delivering AI-powered solutions to the European market, compliance should no longer be viewed as a legal checkbox. It should become an integral part of the AI development lifecycle, encompassing governance, transparency, documentation, risk management, and human oversight from design through deployment.
At Hrida AI, we believe that trustworthy AI is built on more than intelligent models. It is built on security, accountability, transparency, and responsible innovation. As AI regulations continue to evolve globally, organizations that embrace these principles today will be best positioned to scale confidently, earn customer trust, and lead the next generation of enterprise AI.
This article reflects the EU AI Act's implementation timeline and enforcement scope as understood as of August 2026, based on publicly available regulatory guidance. It is intended as general informational content, not legal advice. Organizations should confirm current obligations against the official regulation text (Regulation (EU) 2024/1689) or qualified legal counsel before making compliance decisions.