← Back to News

Governance

Governance Without the Handbrake

What the EU AI Act actually changes for deployers.

By Muhammad Beenish08 JUL 20267 min read

Most enterprises are deployers, not providers, and the heaviest obligations just moved to 2027. Here is what actually applies, and why compliance need not slow you down.

The fear, and the reality

Say EU AI Act to a room of technology leaders and you will watch shoulders tense. The assumption is that the world's first comprehensive AI law is a brake pedal. The reality, for the large majority of organizations, is narrower and more manageable than the headlines suggest. Most enterprises are deployers, not providers, and in 2026 the single most consequential development was that the heaviest obligations were pushed back, not forward.

Provider or deployer — the distinction that changes everything

AspectProviderDeployer
Who you areBuilds an AI system, or markets it under its own nameUses an AI system under its own authority
Typical exampleA model vendor, or a firm that heavily fine-tunes and rebrands a modelA firm that licenses a model or platform and integrates it
Core high-risk dutiesRisk management, technical documentation, conformity assessment, CE marking, EU registration, post-market monitoringUse per instructions, human oversight, monitoring, six-month log retention, transparency, rights assessment where required
Watch out forSubstantial modification or own-name marketing can reclassify you as a provider

What actually applies, and when

Timeline of EU AI Act obligations from Feb 2025 through Aug 2028.
The Act arrives in phases. Knowing which one you are in prevents both panic and complacency.
  • Feb 2025 — Prohibited uses and AI literacy duty in force.
  • Aug 2025 — General-purpose AI (GPAI) model rules apply.
  • Aug 2026 — Transparency obligations (including deployer-facing).
  • Dec 2026 — AI-content watermarking (Article 50(2)).
  • Dec 2027 — High-risk standalone systems (Annex III) — deferred by the Digital Omnibus.
  • Aug 2028 — High-risk AI embedded in regulated products.

The headline 2026 change came from the Digital Omnibus package. Under a political agreement reached in May 2026 and given final Council sign-off at the end of June, the core obligations for standalone high-risk systems listed in Annex III are deferred from August 2026 to December 2027. A deferral changes when, not whether — the direction of travel is unchanged.

The deployer's actual to-do list

  1. Use the system as intended, per the provider's instructions.
  2. Keep a human in the loop with competence and authority to intervene.
  3. Watch the inputs — ensure input data you control is relevant and representative.
  4. Monitor operation and report serious incidents to providers and authorities.
  5. Keep the logs the system automatically generates for at least six months.
  6. Tell people when they are interacting with AI; inform workers before deploying AI in the workplace.
  7. Conduct a Fundamental Rights Impact Assessment where the Act requires one.
  8. Build AI literacy — a duty already in force since February 2025.

Why the penalties are not the point, but are still large

Up to €35 million or 7% of global turnover for prohibited practices, up to €15 million or 3% for breaches of high-risk obligations, and up to €7.5 million or 1.5% for supplying incorrect information. The scope is extraterritorial — a UK or US company whose AI output is used in the EU is in scope.

Governance without the handbrake

Almost everything the Act asks a deployer to do — human oversight, monitoring, logging, input-data discipline, transparency — is what a competent deployment looks like anyway. Read that way, the Act is less a handbrake and more a specification for the operational maturity that separates the AI projects that reach production from the ones that stall.

Sources: European Commission, Regulation (EU) 2024/1689, Article 26 text, Digital Omnibus agreement of May 2026 and Council green light of June 2026, plus analyses from Hogan Lovells, Holland & Knight and the Cloud Security Alliance. General information, not legal advice.