Regulation

The EU AI Act: the facts.

The AI Regulation (EU) 2024/1689 has been in force since 1 August 2024 and applies in stages, to anyone offering or professionally deploying AI in the EU. In July 2026, the Digital Omnibus postponed the high-risk deadlines; the transparency obligations apply, unchanged, from 2 August 2026. This is the overview, without commentary around it.

Timeline

1 Aug 2024
The regulation enters into force.
2 Feb 2025
Prohibited practices apply. Obligation of AI literacy (Art. 4).
2 Aug 2025
Obligations for providers of general-purpose AI models. Governance and penalty provisions.
Jul 2026
The Digital Omnibus enters into force and postpones the high-risk deadlines. The original date for Annex III was 2 August 2026.
2 Aug 2026
Transparency obligations apply (Art. 50): disclosing that it is AI, for systems that interact with people and for AI-generated content.
2 Dec 2027
High-risk obligations for stand-alone systems (Annex III).
2 Aug 2028
High-risk obligations for AI as a safety component of regulated products (Annex I).

Risk categories

Four categories, increasing obligations.

Unacceptable risk

Prohibited (Art. 5)

Among others: social scoring, manipulative techniques, emotion recognition in the workplace and in education, untargeted scraping of facial images.

High risk

Heavy obligations (Annex III, from 2 Dec 2027)

AI in, among others, education and examinations, recruitment and selection, critical infrastructure, essential services, law enforcement and the administration of justice. Requires risk management, data quality, technical documentation, human oversight and conformity assessment.

Limited risk

Transparency (Art. 50, from 2 Aug 2026)

Systems that interact with people and AI-generated content: disclosing that it is AI.

Minimal risk

No additional obligations

The vast majority of AI applications.

Obligations differ by role. The provider (whoever develops a system or places it on the market under its own name) carries the heaviest obligations; the deployer (whoever uses a system professionally) has obligations of its own, including human oversight and use according to the instructions. Whoever substantially modifies a system or markets it under its own brand can itself become a provider.

Penalties run up to 35 million euros or 7% of worldwide annual turnover for prohibited practices, and up to 15 million euros or 3% for most other infringements.

In the chain

The question also comes through your customers.

Besides the supervisor, there is a second channel: contracts. Whoever deploys AI must be able to explain to customers and auditors which systems those are and how they are set up. Questionnaires about AI use appear in tenders, supplier assessments and DORA registers. Whoever supplies a larger company receives the regulation through the procurement department, often earlier than through the law.

Where Ramirez stands

Ramirez builds evaluative AI: systems that test documents and processes and flag what does not hold up, before it costs money. We do this in line with this regulation. Our systems evaluate documents, not people. They make no decisions; the human decides.

The exercise the regulation asks of every company, knowing where your AI stands and how it is set up, is one we ran on our own systems first. We deliver that same test on AI accountability statements: your own before you publish them, and your suppliers' before you rely on them.

This is a factual overview, not legal advice. Source: Regulation (EU) 2024/1689, as amended by the Digital Omnibus (July 2026).