The EU AI Act Is Already Law
10 Mar 2026 · RS Management
TL;DR
- Regulation 2024/1689 is in force. Some obligations already apply.
- An organisation using AI professionally carries duties that no contract can transfer to the vendor, even when the tool was bought compliant from a reputable producer.
- Start with a system inventory and risk classification, not with waiting for a final interpretation.
Update, August 2026. The legal position has moved since this post was published: the transparency obligations of Article 50 started applying on 2 August 2026, and Regulation (EU) 2026/1744 postponed the high-risk deadlines to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). The current timeline and takeaways are covered in The AI Act after 2 August 2026. The text below has been updated with the new dates.
For most of the last few years, the EU AI Act was easy to file under “future regulation.” It was being negotiated, then drafted, then finalized. That phase is over. The Act, formally Regulation (EU) 2024/1689, has been in force since August 2024. Its obligations are landing in stages rather than all at once. Several stages have already passed. For leadership teams in banking, pharmaceuticals, energy and other regulated sectors, the relevant question is no longer whether the Act applies. It is how ready the organization is for the obligations already active and the ones still ahead.
Organizations should confirm specific obligations with qualified counsel. What follows is meant to help leaders ask the right questions and start preparing before enforcement catches up with them.
What changed
The Act does not switch on all at once. It phases in by obligation type, and the calendar now looks like this: the Regulation entered into force on 1 August 2024; prohibited practices and the baseline staff AI literacy duty (Article 4) have applied since 2 February 2025; obligations for general purpose AI models, supervisory authorities and penalties since 2 August 2025; and the transparency obligations of Article 50, including telling people they are interacting with an AI system, since 2 August 2026. The high-risk deadlines were postponed by Regulation (EU) 2026/1744 to 2 December 2027 for Annex III use cases and 2 August 2028 for AI embedded in regulated products under Annex I. Regulators keep publishing guidance on classifying high-risk systems: the enforcement infrastructure is being built now, and the postponement has not stopped it.
The enforcement mechanism itself follows a structure many organizations already recognize from GDPR: tiered penalties, calculated as a fixed amount or a percentage of global annual turnover, whichever is higher, with the more serious violations sitting at the steeper end of that scale. For small and medium-sized enterprises and startups, the cap is the lower of the two amounts (Article 99(6)).
The practical implication: some obligations are not sitting on a future deadline. They already apply.
Who is affected
A common misunderstanding is that AI regulation is a vendor’s problem. It is not. The Act distinguishes between providers (the organizations that build AI systems) and deployers (the organizations that use them in a professional context). Deployer obligations exist separately from provider obligations. They cannot be delegated away by contract.
Consider a bank using a third party model for credit scoring, a pharmaceutical company using AI in clinical or quality workflows and an energy company using AI for grid or asset management: each of these is a deployer in its own right. Buying a compliant tool from a reputable vendor does not automatically satisfy the buyer’s own obligations around oversight, monitoring, incident reporting and risk management. Responsibility sits with whoever puts the system to use, not only with whoever built it.
What high-risk means
The Act organizes AI systems into risk categories rather than treating all AI the same way. At a high level: certain practices are prohibited outright, a defined set of use cases is treated as high-risk and subject to the strictest obligations, another set carries lighter transparency obligations and everything else falls into a minimal risk category with few binding requirements.
| Category | What it covers | Weight of obligations |
|---|---|---|
| Prohibited practices | Uses excluded from the market | Absolute ban |
| High risk | Employment, creditworthiness, critical infrastructure | Heaviest: oversight, documentation, logs |
| Transparency obligations | Chatbots, synthetic content, deepfakes | Notification and marking |
| Minimal risk | Everything else | Few binding requirements |
High-risk is the category that matters most for regulated industries, because it typically covers systems used in employment decisions, creditworthiness assessment, critical infrastructure operation and other contexts where an AI system’s output materially affects a person’s rights or a company’s safety obligations. Exactly which systems in a given organization qualify as high-risk and exactly when each obligation starts to apply depends on the specific system and how it is used. That classification exercise is not optional or informal. It deserves a documented process, ideally with input from both technical and legal stakeholders.
The obligation most teams miss
Article 4 of the Act introduces a requirement that gets far less attention than the risk categories: AI literacy. Organizations must ensure that staff and others operating AI systems on their behalf have a sufficient understanding of those systems to use them responsibly. This obligation already applies. It is not limited to high-risk systems. It is a baseline requirement across the board.
For most organizations, this means AI literacy cannot stay an informal skill picked up on the job. It needs to become a documented training obligation, sized to the role and the system in question.
What to do now
None of this requires a finished compliance program by next quarter. It does require a starting point. The organizations furthest ahead right now are the ones that treated this as operational work rather than a legal filing exercise. A reasonable starting sequence:
- Build an inventory of every AI system in use across the organization, including tools adopted informally by individual teams.
- Classify each system against the Act’s risk categories, with a named owner accountable for the decision.
- Review the transparency documentation available from vendors of any general purpose AI used in production.
- Establish documentation and audit trail habits for AI-assisted decisions, particularly anywhere the output touches people, money or safety.
- Put an AI literacy program in place for staff who interact with these systems, sized to their role.
None of these steps require a final legal opinion to begin. They require ownership, a working inventory and a willingness to treat AI governance as a standing function rather than a one-time project.
Where this leaves you
The organizations that handle this well will not be the ones scrambling once enforcement reaches their sector. They will be the ones that used this window to get their own house in order: a clear inventory, a defensible classification and documentation that would hold up under scrutiny.
The current legal position after 2 August 2026, together with the new calendar and the implications for HR teams, is covered in The AI Act after 2 August 2026. RS Management advises leadership teams in banking, pharmaceuticals, energy and other regulated sectors on AI governance and compliance readiness. If your organization is weighing how exposed its current AI use is, we would welcome a conversation.
RS Management is an advisory practice run by one person. Who stands behind it and with what experience: About.
Blog content is informational and educational. It does not constitute legal or tax advice, nor individual business advisory. The scope of our services is described in the terms.
This topic is covered by the AI Strategy package: 4 weeks of analysis + strategy and a 90-day schedule.
See the package: AI Strategy