# EU AI Act Explained: What Enterprises Need to Know

> The EU AI Act sets risk-based rules, phased deadlines, and extraterritorial duties. See what applies now and how enterprises should prepare for compliance.

Source: https://hyperlake.cloud/blog/eu-ai-act-explained-what-enterprises-actually-need-to-know
Published 2026-10-07 · by Hyperlake Team · Hyperlake

Video: [Watch: EU AI Act Explained   What Enterprises Actually need to know (2:58)](https://www.youtube.com/watch?v=t1Tsphib4lo)

The EU AI Act is a comprehensive, risk-based legal framework governing how artificial intelligence is developed, supplied, and used in the European Union. Enterprises must identify their AI systems, classify their risks, determine their role, and track phased deadlines because prohibited practices, general-purpose AI, transparency, and high-risk systems follow different rules.

The regulation matters beyond Europe because its scope can reach organizations whose AI systems enter the EU market or affect people in the EU. Getting the timeline wrong can leave active obligations untreated while teams wait for unrelated high-risk rules. The video above walks through the core ideas.

## How does the EU AI Act classify AI systems?

The EU AI Act applies different requirements based on an AI system’s risk, purpose, capabilities, and use. Classification is therefore the starting point for determining what an organization must prohibit, disclose, document, test, or govern.

The principal categories discussed for enterprise planning include:

- **Prohibited practices:** These include prohibited forms of social scoring, harmful subliminal manipulation, and certain real-time remote biometric identification by law enforcement in publicly accessible spaces without the required authorization or exception.
- **General-purpose AI:** This category covers foundation models and large language models that can support many downstream applications. Obligations can apply to the organizations providing these models, with additional considerations for models presenting systemic risk.
- **Transparency-regulated systems:** Users may need to know when they are interacting with a chatbot, encountering AI-generated content, or subject to emotion detection or recognition technology.
- **High-risk systems:** Annex III covers specified uses in areas such as employment, credit decisions, healthcare diagnostics, education, and law enforcement.

An application is not automatically high risk merely because it uses a large language model. Its intended purpose, deployment context, effect on people, and the organization’s legal role all matter. Providers, deployers, importers, and distributors may have different responsibilities.

## When do EU AI Act requirements become enforceable?

The EU AI Act entered into force in August 2024, but its requirements have taken effect in phases. Enterprises should maintain a requirement-level timeline instead of treating the regulation as one future deadline.

The main dates are:

1. **February 2025:** Bans on prohibited AI practices became applicable.
1. **August 2025:** General-purpose AI model obligations became active.
1. **August 2026:** Financial penalties became enforceable for general-purpose AI obligations, while chatbot disclosure, emotion detection labeling, and AI-generated content marking requirements also became enforceable.
1. **December 2027:** The Annex III high-risk obligations are scheduled to apply following the Digital Omnibus amendments formally adopted in June 2026.

The December 2027 change applies specifically to Annex III systems. It does not postpone the prohibited-practice bans, general-purpose AI obligations, or transparency requirements, which are already in force. Teams should therefore map every system to its applicable category and deadline rather than using the Annex III delay as a general pause.

![Diagram: EU AI Act timeline from prohibited-practice bans through the Annex III high-risk deadline](https://hyperlake.cloud/blog/img/production/cc95025d6777bf4f4f97dde6f9503e57749fbaf8-1200x750.png?w=1600&fit=max&auto=format)

*Different EU AI Act categories become enforceable on different schedules.*

## Which organizations fall within the EU AI Act’s scope?

The EU AI Act can apply to organizations outside the EU when they place an AI system on the EU market or use one in a way that affects people in the EU. A company’s headquarters alone do not determine whether it is in scope.

For example, a US enterprise may be covered if it serves European customers, operates in Europe, or deploys an AI system whose outputs affect people located in the EU. The same issue arises for AI product companies and service providers installing systems in client environments.

Teams should document where each system is offered, where its outputs are used, whose data it processes, and which legal entity acts as provider or deployer. Data location remains relevant, but it is not the same as legal sovereignty or regulatory scope, as explained in [data residency versus data sovereignty](https://hyperlake.cloud/blog/data-residency-vs-data-sovereignty).

## What must enterprises do for high-risk AI compliance?

Enterprises responsible for high-risk systems need documented controls spanning design, data, testing, human oversight, and deployment. The exact duties depend on the system and the organization’s role, but preparation should begin before the Annex III deadline.

Core requirements described for high-risk systems include:

- A documented risk management system maintained through the system lifecycle.
- Technical documentation explaining the system’s design and intended operation.
- Data governance controls addressing training data quality and bias management.
- Human oversight mechanisms appropriate to the decisions and risks involved.
- Testing for accuracy, robustness, and relevant failure conditions.
- Registration in the EU AI database before deployment where required.

An accurate AI inventory is the practical foundation for all of these controls. Each record should identify the system owner, intended purpose, models and data involved, affected users, deployment regions, legal role, risk classification, applicable deadlines, and supporting evidence.

Without that inventory, an organization cannot reliably determine which obligations apply or demonstrate that it understands its exposure. Inventory evidence should feed into broader [AI audit preparation](https://hyperlake.cloud/blog/ai-audit-checklist-what-regulators-actually-look-for), including access records, approvals, testing results, model documentation, and change history.

![Diagram: Checklist of risk, documentation, data, oversight, testing, and registration controls for high-risk AI](https://hyperlake.cloud/blog/img/production/50b7c79091851f19adfbe6dae229fc229e0a4c04-1200x750.png?w=1600&fit=max&auto=format)

*High-risk compliance depends on documented controls and evidence across the system lifecycle.*

## Key takeaways

- The EU AI Act uses risk-based categories rather than imposing identical controls on every AI application.
- Prohibited-practice, general-purpose AI, and transparency requirements are already active despite the Annex III delay.
- Organizations outside Europe may be covered when their AI systems enter the EU market or affect people in the EU.
- A complete AI system inventory is the foundation for classification, evidence collection, and deadline management.
- High-risk preparation requires documented risk, data, testing, oversight, and registration processes.

## How Hyperlake helps

Hyperlake lets teams deploy and govern data, models, applications, and tools in infrastructure they or their clients control. Its shared controls can support authenticated access, scoped policies, audit records, lineage, network isolation, observability, and repeatable lifecycle operations, while legal classification and compliance decisions remain the organization’s responsibility. To discuss an AI environment with governance requirements, [talk to our team](https://hyperlake.cloud/contact).

## Frequently asked questions

### Does the EU AI Act apply to a US company with European customers?

It can. The EU AI Act has extraterritorial reach when an AI system is placed on the EU market or its use or outputs affect people in the EU. A US company should assess its European customers, operations, users, deployment locations, and legal role rather than assuming its headquarters place it outside the regulation.

### Is every enterprise chatbot considered a high-risk AI system?

No. A chatbot may be subject to transparency requirements without qualifying as an Annex III high-risk system. Classification depends on its intended purpose and context; a general customer-support chatbot differs from a system used to screen employment candidates, assess credit, or support specified healthcare decisions.

### Does the Annex III delay mean enterprises can pause EU AI Act work?

No. The move to December 2027 applies specifically to Annex III high-risk obligations. Prohibited-practice bans, general-purpose AI requirements, and transparency duties follow earlier deadlines and are already in force, so enterprises still need an inventory, classifications, ownership, applicable disclosures, and evidence for the requirements affecting them now.
