11 May 2026
Getting to know the EU AI Act
The EU AI Act, the world's first comprehensive AI law, promotes human-centric, trustworthy AI in the EU's internal market while protecting health, safety, and fundamental rights including democracy and the rule of law.
Suvi Halttula
Partner & Co-founder, Responsible AI
11 May 2026
Getting to know the EU AI Act
The EU AI Act, the world's first comprehensive AI law, promotes human-centric, trustworthy AI in the EU's internal market while protecting health, safety, and fundamental rights including democracy and the rule of law.
Suvi Halttula
Partner & Co-founder, Responsible AI
Why this matters now
The EU AI Act entered into force in August 2024, with obligations rolling out in phases. Three are already live: the prohibitions on the most harmful AI uses (February 2025), general-purpose AI obligations (August 2025), and now the countdown to the biggest milestone - high-risk obligations under Annex III, which apply from August 2026.
The scope is broader than most teams realise. The Act applies to anyone who provides, deploys, imports, or distributes AI systems on the EU market. If your organisation uses AI for hiring, credit scoring, customer service, fraud detection, or productivity monitoring you are likely in scope.
The penalties are serious: up to €35 million or 7% of global turnover. And here's what catches people out: most compliance work has to happen before the deadlines, not the week of.
The risk-based framework
The Act rests on a four-tier risk pyramid:
Unacceptable risk: eight categories prohibited outright, banned since February 2025.
High risk: allowed, but with extensive obligations. Where most compliance work lives.
Limited risk: transparency obligations: chatbots must tell users they're not human; AI-generated content must be labelled.
Minimal risk: most AI sits here. No specific obligations.
The Act also has a separate regime for general-purpose AI (GPAI) models like GPT, Claude, and Gemini. Most organisations won't be GPAI providers themselves, but if you build on top of these models, you'll inherit downstream obligations through your contracts.
What's prohibited
Eight categories of AI use are now banned:
Manipulation that causes harm
Exploiting vulnerable groups
Sensitive biometric categorisation
Social scoring
Profile-only predictive policing
Untargeted facial scraping
Emotion recognition in workplaces and schools
Real-time biometric ID in public spaces
High-risk AI: where most of the work lives
There are two paths to high-risk classification.
Annex I sweeps in AI built into already-regulated products (e.g., medical devices, machinery, vehicles, aviation). If you operate in those industries, you'll know.
Annex III is the one that catches everyone else. It covers eight use case areas, but the ones most likely to apply to you are hiring and worker management, education, credit and insurance, and access to essential services. CV-screening tools are the classic example.
Narrow carve-outs exist for systems doing only procedural work, or supporting a human decision rather than replacing it, but the burden is on you to document why an exception applies.
And one rule overrides everything else: if your Annex III system profiles individuals, using their data to evaluate things like performance, finances, health, or behaviour, it's automatically high-risk. That single rule sweeps in most HR tech, credit decisioning, personalised insurance, and worker-monitoring tools on the market today.
If a system lands in this category, providers have to put real governance around it: risk management, data quality controls, documentation, human oversight, transparency, accuracy and security. Deployers carry their own duties: using the system as instructed, monitoring it, reporting incidents, informing affected people, and running a Fundamental Rights Impact Assessment where required.
The deadlines that matter
August 2024 — Act entered into force.
February 2025 — prohibited AI rules took effect.
August 2025 — GPAI obligations took effect.
August 2026 — high-risk obligations under Annex III take effect.
August 2027 — high-risk obligations for Annex I products fully apply.
The August 2026 deadline should be on every compliance lead's calendar. If you have Annex III systems and you haven't started classifying, documenting, and building governance, the runway is shorter than it feels.
Where to start: five practical steps
Build an AI inventory. Catalogue every AI system in use, including AI embedded in the SaaS tools your teams already rely on.
Classify each system by risk tier. Apply the Annex III test, the profiling rule, and the carve-out logic. Document your reasoning.
Identify your role for each system. Provider, deployer, importer, or distributor? Obligations differ sharply and be alert: fine-tuning a model can shift you from deployer to provider.
Map obligations and gaps. For each high-risk system, work out what's required and compare against where you are today.
Establish governance ownership. Who owns AI governance: compliance, IT, product engineers or a new committee? This question is unresolved in most organisations and tends to be the bottleneck on everything else.
Where to go from here
At Impaktly we help organisations cut through the regulation and turn it into something operational:
clear AI inventories
defensible risk classifications
governance frameworks that fit how the business runs
training that brings the rest of the organisation along
If this resonates, let’s talk more!
Let's talk about how to make this happen!
Curious what this could mean for your team? Get in touch, we'd love to chat.
Mia Folkesson
Managing Partner
mia@impaktly.com
Let's talk about how to make this happen!
Curious what this could mean for your team? Get in touch, we'd love to chat.
Mia Folkesson
Managing Partner
mia@impaktly.com