Guide · Regulation
The EU AI Act for product teams: what you actually have to do.
Most teams building AI features aren’t building “high-risk AI” — but many assume they are, or assume the Act doesn’t apply to them at all. Both are expensive mistakes. This guide maps the Act onto typical product decisions, including the timeline changes introduced by the AI Omnibus in 2026.
By Nythrex EngineeringUpdated 4 min read
Prohibited practices
Banned — e.g. social scoring, certain manipulation
High-risk systems
Annex III areas & regulated products — strict obligations
Transparency duties
Chatbots, synthetic content, deepfakes
Minimal risk
Most business AI — no specific obligations
Key dates
| Date | What applies |
|---|---|
| 1 Aug 2024 | The AI Act enters into force |
| 2 Feb 2025 | Prohibited practices apply; AI literacy provisions start |
| 2 Aug 2025 | Obligations for general-purpose AI (GPAI) model providers; governance and penalties framework |
| 2 Aug 2026 | Transparency obligations (Article 50) — e.g. informing people they interact with an AI |
| 2 Dec 2026 | Grace period ends for watermarking of systems already on the market; new prohibition on AI-generated non-consensual intimate imagery applies |
| 2 Dec 2027 | High-risk obligations for stand-alone Annex III systems (deferred by the AI Omnibus) |
| 2 Aug 2028 | High-risk obligations for AI embedded in products regulated under Annex I (deferred) |
Official announcement: AI Omnibus enters into force (European Commission).
Which role are you?
| Role | Typical example | Main idea |
|---|---|---|
| Provider of an AI system | You build and ship an AI feature or product under your name | You carry most obligations for that system, scaled to its risk level |
| Deployer | You use an AI system in your business (e.g. an HR screening tool you bought) | Use it as instructed, ensure human oversight and inform people where required |
| Provider of a GPAI model | You train and release a general-purpose model | Documentation, copyright policy and more; rare for application teams |
Building a product on top of a third-party model API usually makes you the provider of an AI system (your product), not the provider of a GPAI model — the model provider carries the GPAI obligations.
Are you high-risk?
High-risk systems are mainly those listed in Annex III — AI used in areas such as biometrics, critical infrastructure, education, employment and worker management, access to essential private and public services (including credit scoring and certain insurance pricing), law enforcement, migration and the administration of justice — plus AI that is a safety component of products regulated under Annex I. There are exceptions for systems that only perform narrow procedural or preparatory tasks.
Usually not high-risk
- Support copilot that drafts replies for agents
- Internal knowledge assistant (RAG)
- Invoice and document data extraction
- Product description generation
- Sales email drafting
Likely high-risk — plan carefully
- Ranking or filtering job applicants
- Evaluating employee performance for decisions
- Creditworthiness scoring of individuals
- Deciding access to essential public services
- Exam scoring or admission decisions in education
Transparency duties most teams will meet
Practical steps for product teams
- 1
Inventory your AI features
List every place AI is used: purpose, users, data, provider, and whether its output influences decisions about people.
- 2
Classify each one
Prohibited? Annex III area? Transparency duty? Minimal risk? Write the reasoning down.
- 3
Design transparency in
An “AI assistant” label, disclosure text and content marking are cheap if designed early and awkward to retrofit.
- 4
Keep humans in the loop where it matters
Even outside high-risk areas, human review for consequential outputs is good practice — and easy to evidence.
- 5
Keep documentation you’d want anyway
Architecture, data flows, evaluation results and change logs serve the Act, GDPR, customers’ security reviews and your own engineers.
Frequently asked questions
Keep reading
Want a second opinion on your project?
Tell us what you’re building and where you’re stuck. We’ll reply within one business day with the most practical next step — even if that step isn’t us.
