Help understanding and complying with the new EU rules for artificial intelligence.
Rechtsstand: 2. September 2026
Regulation (EU) 2024/1689 · Legal status September 2026
The EU AI Act is here. The only question left is how well prepared you are.
Since August 2, 2026, the AI Regulation has been largely in effect. The Digital Omnibus has softened some deadlines — but not the obligation to know which AI you use and who is responsible for it.
- Current deadlines under the Digital Omnibus of July 2026
- Concrete examples from eight industries
- Honest assessment: what ISO 42001 covers — and what it doesn't
- Aug 2, 2026
- AI Regulation generally applicable
- Dec 2, 2027
- High-risk AI under Annex III
- Aug 2, 2028
- AI in regulated products (Annex I)
- up to €35 million
- Fine framework
Transparency obligations under Art. 50 take effect
postponed by the Digital Omnibus
postponed by the Digital Omnibus
or 7% of global annual turnover for prohibited practices
Deadlines
What applies when — as of September 2026
The Digital Omnibus on AI was published in the Official Journal on July 24, 2026, and entered into force on July 27, 2026. It significantly postpones the obligations for high-risk AI — everything else remains in place.
February 2, 2025
Prohibited AI practices (Art. 5) and AI literacy obligation (Art. 4)
applies — unaffected by the OmnibusAugust 2, 2025
Obligations for general-purpose AI models (GPAI, Art. 53)
applies — enforcement since August 2026August 2, 2026
General applicability of the Regulation, transparency obligations (Art. 50)
has applied for one monthDecember 2, 2027
High-risk AI under Annex III (standalone systems)
postponed, originally August 2, 2026August 2, 2028
High-risk AI under Annex I (AI in regulated products)
postponed
What the postponement does not mean: it is not an all-clear. Prohibited practices, AI literacy, transparency obligations and the GPAI rules already apply. And anyone who has to demonstrate high-risk compliance in 2027 does not have 15 months for it — rather, they must operate a functioning risk management system by then, one that requires data from ongoing operations.
Applicability
Two questions determine your obligations
1 – What role do you have? The regulation distinguishes above all between *providers* — those who develop an AI system or place it on the market under their own name — and *deployers*, who use an AI system under their own responsibility. Most companies are deployers. Deployer obligations are leaner, but they exist: use as intended, human oversight, information of affected persons, logging.
2 – Which risk class does the system fall into? Prohibited, high-risk, subject to transparency obligations, or minimal risk. You carry out the classification yourself — no one does it for you. And this is exactly where most fail: there is no register, so there is no classification either.
- Prohibited
Social scoring, emotion recognition in the workplace, untargeted scraping of facial images, and other practices under Art. 5. In effect since February 2025.
- High risk
including personnel selection, creditworthiness, access to education, critical infrastructure, law enforcement, plus AI in regulated products.
- Subject to transparency obligations
Chatbots, generated content, deepfakes: people must know that they are dealing with AI. In effect since August 2026.
- Minimal risk
the majority. No special obligations, but the AI competence obligation under Art. 4 still applies.
Eight industries, eight concrete cases
Abstract risk classes help no one. Here is how the regulation lands on the table in practice.
HR and Recruiting
Selection, promotion, performance evaluation — under Annex III generally high risk
A company uses automated CV screening. From December 2027, this will require risk management, evidence of data quality, logging, and documented human oversight. Those who start today will have the evidence by then. Those who start in 2027 will not.
Finance and Insurance
Credit scoring of natural persons and risk assessment in life and health insurance — high risk
A credit institution with AI-supported scoring must be able to explain which characteristics are factored in, how bias was checked, and who can override a rejection.
Health and Medical Technology
AI as a medical device falls under Annex I — deadline August 2028, but with full product conformity
A provider of image analysis software must integrate the AI requirements into its existing conformity assessment, not alongside it.
Industry and mechanical engineering
AI as a safety component in machinery — Annex I
A machine manufacturer with AI-supported fault detection on the press needs the AI documentation as part of the machinery conformity.
Public administration
Access to services, access to education, migration and law enforcement context — high risk, partly additional fundamental rights impact assessment
An authority that pre-sorts applications must keep the decision comprehensible and contestable — and inform those affected.
Education and further training
Admission, assessment, examination monitoring — high risk
A provider with automated exam assessment needs proof of fairness, error rates and a path to human review.
Software and SaaS
Role can shift from operator to provider — the most costly misjudgement in practice
A SaaS provider integrates a third-party model and markets the feature under its own name. This makes it a provider — with significantly more far-reaching obligations than its team assumes.
Retail and marketing
Chatbots, generated content, personalization — transparency obligations under Art. 50, since August 2026
A retailer with an AI chatbot and AI-generated product images must label both. This is not a future scenario, it applies now.
Where ISO 42001 structurally covers the obligations of the regulation
Not a substitute for a conformity assessment — but the structure in which the required evidence is generated in the first place.
What ISO 42001 provides for this
- Risk management system (Art. 9)AI risk assessment and treatment across the entire lifecycle
- Data and data governance (Art. 10)Requirements for the origin, quality and use of data
- Technical documentation (Art. 11)Documented information and system inventory
- Record-keeping obligations and logging (Art. 12)Monitoring, measurement, recording of AI systems
- Transparency towards operators (Art. 13)Transparency and communication requirements
- Human oversight (Art. 14)Roles, responsibilities, intervention options
- Accuracy, robustness, cybersecurity (Art. 15)partially — cybersecurity mainly via ISO/IEC 27001
- Provider's quality management system (Art. 17)that is exactly an AIMS according to 42001
- AI literacy (Art. 4)Competence, training and awareness requirements
- Conformity assessment and CE (Art. 43)not covered — separate procedure
- Registration in the EU database (Art. 49)not covered — separate obligation
Coverage
- Risk management system (Art. 9)high
- Data and data governance (Art. 10)high
- Technical documentation (Art. 11)medium — the product-specific depth comes from Annex IV, not from the standard
- Record-keeping obligations and logging (Art. 12)medium
- Transparency towards operators (Art. 13)medium
- Human oversight (Art. 14)high
- Accuracy, robustness, cybersecurity (Art. 15)medium (combination with 27001 recommended)
- Provider's quality management system (Art. 17)high
- AI literacy (Art. 4)high
- Conformity assessment and CE (Art. 43)none
- Registration in the EU database (Art. 49)none
Plain text
What an ISO 42001 certificate delivers — and what it doesn't
A lot is currently being claimed in the market. So here is our position, as clearly as possible:
An ISO 42001 certificate establishes no presumption of conformity under the AI Act. This arises exclusively from harmonised standards listed in the Official Journal of the EU; the corresponding European standardisation work is still ongoing. Anyone who promises you otherwise is selling you a risk.
What ISO 42001 delivers: it forces your organisation to do what the regulation requires anyway — know which AI is in use, assign responsibility, assess risks, govern data, ensure oversight, handle incidents. And it has this externally audited. When an authority, a major client or an insurer asks, the difference between "we're working on it" and an audited management system is substantial.
Frequently Asked Questions about the EU AI Act
Very likely yes, as soon as you place AI systems on the market in the EU or their outputs are used in the EU. The regulation has effect beyond the EU border, similar to the GDPR.
Even then, you are a deployer. The obligation for AI literacy under Art. 4 applies regardless of the risk class, and internal applications in the HR area can very well be high-risk.
It was published on 24 July 2026 and entered into force on 27 July 2026. The obligations for high-risk AI under Annex III are postponed to 2 December 2027, and for Annex I to 2 August 2028. Prohibited practices, AI literacy, GPAI rules and transparency obligations remain unchanged.
Up to €35 million or 7% of worldwide annual turnover for prohibited practices; lower thresholds apply for other violations. The applicable amount is always the higher one.
No. It does not establish a presumption of conformity, but it covers a large part of the organizational requirements and is the best available evidence of maturity today.
A provider develops or places on the market under its own name; a deployer uses it under its own responsibility. Anyone who offers a third-party model under their own brand or significantly modifies it can become a provider — this is regularly underestimated in practice.
With the inventory. Without knowing which AI systems are running in-house, no class can be determined and no obligation can be derived. This is exactly where ISO 42001 also starts.
No. We present the current state in an understandable way; the classification of your systems and the legal assessment in individual cases belong in expert hands.
From "we should sometime" to "we can prove it"
Fill out the self-check or directly calculate what ISO 42001 — alone or with 27001 — costs for you.
