Most enterprises are deployers, not providers, and the heaviest obligations just moved to 2027. Here is what actually applies, and why compliance need not slow you down.
The fear, and the reality
Say EU AI Act to a room of technology leaders and you will watch shoulders tense. The assumption is that the world's first comprehensive AI law is a brake pedal. The reality, for the large majority of organizations, is narrower and more manageable than the headlines suggest. Most enterprises are deployers, not providers, and in 2026 the single most consequential development was that the heaviest obligations were pushed back, not forward.
Provider or deployer — the distinction that changes everything
| Aspect | Provider | Deployer |
|---|---|---|
| Who you are | Builds an AI system, or markets it under its own name | Uses an AI system under its own authority |
| Typical example | A model vendor, or a firm that heavily fine-tunes and rebrands a model | A firm that licenses a model or platform and integrates it |
| Core high-risk duties | Risk management, technical documentation, conformity assessment, CE marking, EU registration, post-market monitoring | Use per instructions, human oversight, monitoring, six-month log retention, transparency, rights assessment where required |
| Watch out for | — | Substantial modification or own-name marketing can reclassify you as a provider |
What actually applies, and when

- Feb 2025 — Prohibited uses and AI literacy duty in force.
- Aug 2025 — General-purpose AI (GPAI) model rules apply.
- Aug 2026 — Transparency obligations (including deployer-facing).
- Dec 2026 — AI-content watermarking (Article 50(2)).
- Dec 2027 — High-risk standalone systems (Annex III) — deferred by the Digital Omnibus.
- Aug 2028 — High-risk AI embedded in regulated products.
The headline 2026 change came from the Digital Omnibus package. Under a political agreement reached in May 2026 and given final Council sign-off at the end of June, the core obligations for standalone high-risk systems listed in Annex III are deferred from August 2026 to December 2027. A deferral changes when, not whether — the direction of travel is unchanged.
The deployer's actual to-do list
- Use the system as intended, per the provider's instructions.
- Keep a human in the loop with competence and authority to intervene.
- Watch the inputs — ensure input data you control is relevant and representative.
- Monitor operation and report serious incidents to providers and authorities.
- Keep the logs the system automatically generates for at least six months.
- Tell people when they are interacting with AI; inform workers before deploying AI in the workplace.
- Conduct a Fundamental Rights Impact Assessment where the Act requires one.
- Build AI literacy — a duty already in force since February 2025.
Why the penalties are not the point, but are still large
Up to €35 million or 7% of global turnover for prohibited practices, up to €15 million or 3% for breaches of high-risk obligations, and up to €7.5 million or 1.5% for supplying incorrect information. The scope is extraterritorial — a UK or US company whose AI output is used in the EU is in scope.
Governance without the handbrake
Almost everything the Act asks a deployer to do — human oversight, monitoring, logging, input-data discipline, transparency — is what a competent deployment looks like anyway. Read that way, the Act is less a handbrake and more a specification for the operational maturity that separates the AI projects that reach production from the ones that stall.
Sources: European Commission, Regulation (EU) 2024/1689, Article 26 text, Digital Omnibus agreement of May 2026 and Council green light of June 2026, plus analyses from Hogan Lovells, Holland & Knight and the Cloud Security Alliance. General information, not legal advice.
