Nythrex

Guide · Regulation

The EU AI Act for product teams: what you actually have to do.

Most teams building AI features aren’t building “high-risk AI” — but many assume they are, or assume the Act doesn’t apply to them at all. Both are expensive mistakes. This guide maps the Act onto typical product decisions, including the timeline changes introduced by the AI Omnibus in 2026.

By Nythrex EngineeringUpdated 4 min read

  1. Prohibited practices

    Banned — e.g. social scoring, certain manipulation

  2. High-risk systems

    Annex III areas & regulated products — strict obligations

  3. Transparency duties

    Chatbots, synthetic content, deepfakes

  4. Minimal risk

    Most business AI — no specific obligations

The Act’s risk pyramid, drawn top-down. Most product features land in the bottom two layers.

Key dates

Dates as amended by the AI Omnibus. Source: European Commission and published analyses; check the Official Journal for the authoritative text.
DateWhat applies
1 Aug 2024The AI Act enters into force
2 Feb 2025Prohibited practices apply; AI literacy provisions start
2 Aug 2025Obligations for general-purpose AI (GPAI) model providers; governance and penalties framework
2 Aug 2026Transparency obligations (Article 50) — e.g. informing people they interact with an AI
2 Dec 2026Grace period ends for watermarking of systems already on the market; new prohibition on AI-generated non-consensual intimate imagery applies
2 Dec 2027High-risk obligations for stand-alone Annex III systems (deferred by the AI Omnibus)
2 Aug 2028High-risk obligations for AI embedded in products regulated under Annex I (deferred)

Official announcement: AI Omnibus enters into force (European Commission).

Which role are you?

RoleTypical exampleMain idea
Provider of an AI systemYou build and ship an AI feature or product under your nameYou carry most obligations for that system, scaled to its risk level
DeployerYou use an AI system in your business (e.g. an HR screening tool you bought)Use it as instructed, ensure human oversight and inform people where required
Provider of a GPAI modelYou train and release a general-purpose modelDocumentation, copyright policy and more; rare for application teams

Building a product on top of a third-party model API usually makes you the provider of an AI system (your product), not the provider of a GPAI model — the model provider carries the GPAI obligations.

Are you high-risk?

High-risk systems are mainly those listed in Annex III — AI used in areas such as biometrics, critical infrastructure, education, employment and worker management, access to essential private and public services (including credit scoring and certain insurance pricing), law enforcement, migration and the administration of justice — plus AI that is a safety component of products regulated under Annex I. There are exceptions for systems that only perform narrow procedural or preparatory tasks.

Usually not high-risk

  • Support copilot that drafts replies for agents
  • Internal knowledge assistant (RAG)
  • Invoice and document data extraction
  • Product description generation
  • Sales email drafting

Likely high-risk — plan carefully

  • Ranking or filtering job applicants
  • Evaluating employee performance for decisions
  • Creditworthiness scoring of individuals
  • Deciding access to essential public services
  • Exam scoring or admission decisions in education

Transparency duties most teams will meet

0/4

Practical steps for product teams

  1. 1

    Inventory your AI features

    List every place AI is used: purpose, users, data, provider, and whether its output influences decisions about people.

  2. 2

    Classify each one

    Prohibited? Annex III area? Transparency duty? Minimal risk? Write the reasoning down.

  3. 3

    Design transparency in

    An “AI assistant” label, disclosure text and content marking are cheap if designed early and awkward to retrofit.

  4. 4

    Keep humans in the loop where it matters

    Even outside high-risk areas, human review for consequential outputs is good practice — and easy to evidence.

  5. 5

    Keep documentation you’d want anyway

    Architecture, data flows, evaluation results and change logs serve the Act, GDPR, customers’ security reviews and your own engineers.

Frequently asked questions

Want a second opinion on your project?

Tell us what you’re building and where you’re stuck. We’ll reply within one business day with the most practical next step — even if that step isn’t us.

Start a project