1. Blog >
  2. Business
  3. Everything You Need to Know About the AI Act, the European Regulation Changing the Rules for AI
September 3, 2026

Everything You Need to Know About the AI Act, the European Regulation Changing the Rules for AI

Published by

  • Jeanne Delozanne
Document titled "IA Act" with a wand icon above, on a blue gradient background, marked as page 1 of 4.

On July 12, 2024, the European Union published in its Official Journal the first global regulatory framework dedicated to artificial intelligence.

Two years later, the regulation is entering its operational phase: transparency obligations for AI systems interacting with the public apply starting in August 2026, while obligations for high-risk systems, including HR and recruitment tools, come into force in December 2027. For the companies concerned, the time has come to understand what the text really means

The regulation governing artificial intelligence in Europe

 The AI Act (Regulation (EU) 2024/1689) is a European regulation that establishes harmonized rules for the development, placing on the market, and use of artificial intelligence systems within the European Union. Adopted by the European Parliament in March 2024 and published in the Official Journal of the EU on July 12, 2024, it entered into force on August 1, 2024.

Its central principle is a risk-based approach: the greater a system's potential for harm to fundamental rights or people's safety, the stricter the obligations that govern it. This logic distinguishes four levels: prohibited practices, high-risk systems, limited-risk systems, and minimal or no-risk systems.

 In short. The AI Act is the first European regulation governing artificial intelligence. Adopted in 2024, it classifies AI systems according to their level of risk and imposes progressive obligations on the companies that develop or use them. It applies to all organizations active in the EU market, regardless of where they are established.

 The regulation applies to any organization that develops, markets, or uses AI systems within the territory of the Union, whether established in Europe or not. A company whose AI systems produce effects on people located in Europe is also subject to the regulation, even if it operates from a third country.

Based on the Regulation (EU) 2024/1689 of the European Parliament and of the Council, OJEU of July 12, 2024.

Who is actually affected by the regulation

The AI Act distinguishes between several categories of actors, and confusion between them is common. The provider is the entity that develops an AI system and places it on the market. The deployer is the entity that uses this system in a professional context, on its own behalf or on behalf of third parties. The importer and the distributor play roles related to making the system available on the European market.

 These distinctions have direct consequences for each party's obligations. Providers bear the heaviest compliance burden: technical documentation, conformity assessment, CE marking (the European certification confirming that a product meets EU regulatory requirements) for high-risk systems. Deployers have more targeted obligations, but they are real and binding.

 Most companies are deployers

An HR department using CV-screening software, an IT department (DSI, responsible for the company's infrastructure and IT tools) deploying a predictive incident-analysis tool, a procurement department using a recommendation engine to qualify suppliers: all of these companies are deployers under the regulation. They did not develop the tools, but they are responsible for them within their context of use.

 This clarification is central. The AI Act's obligations do not apply only to software publishers or research labs: they apply to any organization that integrates AI into its business processes.

 A concrete example: the HR department as deployer

Take a concrete case. An HR department has been using automated application pre-screening software for several months: the tool analyzes CVs received, scores them according to criteria set by the vendor, and ranks candidates for each position. The company did not develop the tool, it purchased it as SaaS and uses it daily to filter several hundred applications per week.

 Under the AI Act, this HR department is a deployer of a high-risk AI system, under Annex III. It cannot hide behind the fact that the tool was designed by a third-party vendor. It must appoint a person responsible for human oversight of the system, ensure that pre-screening decisions remain auditable, keep logs within the limits of its contractual rights, and inform employee representatives about the use of this tool in the recruitment process. If the vendor has not provided the required technical documentation, it is up to the company to request it.

 This scenario is far from marginal. Many organizations have integrated tools of this kind without formalizing the responsibilities that result from it. This is precisely where the AI Act introduces a shift in posture: using an AI system means taking on responsibility for its oversight.

 A regulation built on risk levels

The regulation's logic rests on a risk classification. Understanding this classification means directly identifying what applies to your organization.

 Prohibited practices since February 2, 2025

Certain uses of AI are simply prohibited, with no possible exemption. These include subliminal manipulation techniques, general social scoring systems set up by public authorities, real-time facial recognition in public spaces (with very limited exceptions), emotion recognition in the workplace and in educational institutions, and the creation of biometric databases through mass scraping of the internet.

 These prohibitions have applied since February 2, 2025. Any existing AI system falling into one of these categories must have been withdrawn from the market or substantially modified.

 High-risk AI systems, including HR tools

This is where the most concrete issues for companies are concentrated. Annex III of the regulation lists the AI systems considered high-risk. Several categories directly concern IT, HR, and procurement functions:

·       recruitment tools, tools for screening or evaluating candidates 

·       employee performance evaluation systems, task allocation, or workplace behavior monitoring systems 

·       tools for accessing essential services (credit, insurance, public services) 

·       critical infrastructure management systems 

A matching tool (automated matching between a profile and a position), CV-scoring software (automated scoring of applications according to predefined criteria), or an automated supplier-evaluation system can fall into this category. Deployers of these systems are subject to a set of obligations detailed in the following section.

Limited and minimal risk

Systems with limited risk, such as chatbots or synthetic content generators, are subject mainly to transparency obligations: the user must know they are interacting with an AI. Systems with minimal risk, such as spam filters or automatic translation tools, are not subject to any specific obligation, although the regulation encourages voluntary compliance practices.

 General-purpose AI models (GPAI), obligations since August 2025

General-purpose AI models, referred to by the acronym GPAI (General Purpose AI), are models trained on large volumes of data and designed to be used in varied contexts: text generation, document analysis, decision support. ChatGPT, Mistral, and the copilots built into office suites are common examples.

 Since August 2, 2025, providers of these models have been subject to specific obligations: technical documentation, transparency policy on training data, and compliance with copyright rules. These obligations apply to providers, not directly to the companies that use these models via a third-party API or SaaS. But this does not exempt deployers from verifying that the models they integrate into their processes comply with these requirements, and documenting their use accordingly as part of their own compliance process.

 What is already in force as of August 2026

 In short. The AI Act has been applying progressively since August 1, 2024. The "Digital Omnibus" regulation, proposed by the Commission in November 2025 and entered into force on July 27, 2026, pushed back certain deadlines. In August 2026, it is the transparency obligations (Article 50) that come into force. The obligations for high-risk AI systems, including HR and recruitment tools, come into application in December 2027

Deadline What comes into application
August 1, 2024
Entry into force of the initial regulation
February 2, 2025
Prohibition of unacceptable-risk AI practices
August 2, 2025
GPAI obligations, governance, AI Office (European AI Office, created within the Commission to oversee enforcement of the regulation)
August 2, 2026
Transparency obligations under Article 50 (chatbots, AI/human interactions), except for synthetic content (audio, image, video, text), for which the deadline is pushed back to December 2, 2026
December 2, 2027
Full application for high-risk AI systems under Annex III (HR, recruitment, employee management tools)
August 2, 2028
AI systems embedded in products already covered by existing safety legislation (Annex I)

August 2026, a key milestone. 

Companies whose AI tools interact directly with users (chatbots, conversational assistants) must comply with the transparency obligations of Article 50 starting now. Deployers of high-risk systems have an additional grace period, but December 2027 is approaching and preparation takes several months.

Based on the Regulation (EU) 2024/1689, Articles 113 and following (application timeline), OJEU of July 12, 2024.

 Concrete obligations for deploying companies

Being a deployer of a high-risk AI system involves a specific set of obligations, detailed in Articles 26 and following of the regulation.

 Human oversight

The deployer must ensure that one or more natural persons are designated to monitor the operation of the AI system. These people must have the skills, authority, and tools needed to intervene, correct, or suspend the system if necessary. This is not symbolic oversight: it must be effective and documented.

 Documentation and informing teams

The deployer must keep the logs generated by the system, to the extent that it has control over them. It must also maintain a register of its uses of high-risk AI systems, and inform its teams when their work is assisted or overseen by such a system. The obligation to inform extends to employee representatives, in accordance with applicable national labor law.

 Compliance with intended use and impact assessment

The deployer may only use an AI system in accordance with the provider's instructions. It cannot alter the intended use of a system certified for a different scope. If a deployer substantially modifies a high-risk AI system, it then takes on the provider's responsibilities.

 Certain categories of deployers, particularly public bodies and operators of financial or essential services, have an additional obligation: to conduct a fundamental rights impact assessment before deploying the system.

Based on the CNIL, artificial intelligence section.

 Penalties provided for by the regulation

The AI Act provides for three levels of administrative penalties, applied by the competent national authorities.

 Failure to comply with the prohibitions (unacceptable-risk practices) carries a fine of up to €35 million or 7% of global annual turnover, whichever is higher. Violations of other obligations applicable to high-risk systems are punishable by fines of up to €15 million or 3%. Providing inaccurate information to supervisory authorities is punishable by up to €7.5 million or 1.5%.

 For SMEs and startups, the absolute value caps apply, which can represent a lighter burden than a percentage of turnover. The substantive obligations remain the same.

 These penalties are enforced in each member state by designated national authorities. In France, the oversight framework relies on a decentralized model involving several sector-specific authorities. According to the designation proposal published by the Directorate General for Enterprises (DGE) in September 2025, three authorities handle the majority of use cases: the CNIL (biometrics, personal data, education), the DGCCRF (prohibited practices, consumer products), and the ARCOM (audiovisual content, text generators). Strategic coordination is provided by the DGE, operational coordination by the DGCCRF. The formal designation of these authorities by legislation had not yet been finalized at the time this article was published.

Based on the Directorate General for Enterprises (DGE), 2025.

 The particular case of unmapped AI uses

Complying with the AI Act requires knowing which AI systems are actually used within the organization. This is precisely where one of the most common blind spots lies: undeclared uses, sometimes referred to as shadow AI.

 An employee using ChatGPT to draft candidate analyses, a text-generation tool built into an HR SaaS product without IT validation, an AI copilot enabled by default in a Microsoft 365 environment without internal governance: these uses exist in many organizations, often without IT or procurement teams having a consolidated view of them. Yet, if one of these tools falls under the high-risk category per Annex III, the company is a deployer and bears obligations, whether or not it has formalized this use.

 Mapping existing AI uses, the first step in the compliance process presented in the next section, is therefore not a formality. It determines the organization's ability to identify its actual exposure and prioritize its actions.

 Where to start structuring your AI compliance

Complying with the AI Act cannot be handled in a single action or in a few weeks. It is a structured process that follows a logic of priorities, and its starting point is not legal: it is operational.

 Mapping existing AI uses

Before qualifying risks or designating responsible parties, an organization must know which AI systems it actually uses. This requires identifying, department by department, tools with an AI component: HR pre-screening software, scoring or matching tools, copilots built into office suites, chatbots interacting with customers or candidates, predictive analysis systems deployed by IT.

 This mapping must include uses validated by the IT department as well as undeclared uses, often present in business teams without formal governance.

 This is cross-functional work that involves, at minimum, IT, HR, and procurement. Without this foundation, it is impossible to identify the organization's actual exposure.

 Qualifying the risk level of each identified system

Once the inventory is complete, each tool must be positioned within the AI Act's classification. The central question is simple: does the system significantly influence a decision affecting an individual, in one of the areas listed in Annex III? If the answer is yes, the system is high-risk and triggers a specific set of obligations.

 In case of doubt about how to classify a tool, the recommended approach is to consult the technical documentation provided by the vendor and explicitly ask which category they place their product in. The absence of a clear response from the vendor is in itself informative about their level of compliance maturity.

 Prioritizing actions according to risk level

The third step is to sequence compliance actions. Already-deployed high-risk systems are the top priority, especially as the December 2027 deadline approaches in a context where oversight, documentation, and team-information processes have not yet been formalized.

 The following table summarizes the actions to take depending on the type of system and the function concerned.

AI System TypeRisk LevelPriority ActionsFunction ConcernedDeadline
CV-screening tool, candidate scoring
High risk (Annex III)
Appoint a human oversight officer, build the usage register, inform employee representatives, verify contractual compliance with the provider
HR
December 2027
HR chatbot, customer conversational assistant
Limited risk
Implement the transparency obligation (Article 50): inform the user they are interacting with an AI
IT, HR
August 2026
IT incident predictive-analysis tool
High risk depending on use
Qualify with the provider, document the intended use, appoint an oversight officer
IT
December 2027
Supplier recommendation engine
Potentially high risk (Annex III)
Map the exact use, verify technical documentation, qualify the risk level
Procurement
December 2027
AI office copilot (Microsoft 365, etc.)
Minimal to limited risk depending on use
Inventory actual uses, verify none fall under a high-risk category, define contractual scope
IT
August 2026

To go further on each of these areas, this AI Governance hub offers dedicated resources on the specific obligations for high-risk systems, internal AI governance, and the contractual framework for AI vendors.

AI Governance Checklist: questions to ask before deploying an AI tool

Before deploying or continuing to use an AI system in your organization, check these seven points:

·       Have you identified the system's risk level according to the AI Act classification (Annex III)? 

·       Do you know the intended use defined by the provider, and does your organization comply with that scope? 

·       Is a person designated to ensure effective human oversight of the system? 

·       Do you have the logs and a register of high-risk AI uses? 

·       Have the relevant teams been informed that AI systems are used in their processes? 

·       Does your contract with the provider specify its responsibilities under the AI Act? 

·       Do you have a procedure in place for reporting incidents or malfunctions of the system? 

 Key takeaways

The AI Act is not a text to watch from a distance. Transparency obligations apply starting in August 2026 for tools interacting with users, and obligations for high-risk systems, including HR and recruitment tools, come into application in December 2027. Compliance follows a progressive logic: mapping uses, identifying shadow AI, qualifying risks, prioritizing actions. Organizations that start this process now have a head start on the first decisions from national authorities, which will set the interpretive standards.

To quickly identify and mobilize experts in AI compliance, data governance, or digital transformation for your projects, to quickly identify and mobilize experts in AI compliance or data governance, LittleBig Connection connects companies with qualified consultants, available according to your timelines and scope.

FAQ

Everything You Need to Know About the AI Act, the European Regulation Changing the Rules for AI

LittleBig Connection Blog

Find out more articles
on the same subject