Back to Journal
AI Strategy 10 min read

EU AI Act Compliance for Shipping Teams: The 2026 Playbook

How to classify your system into the right risk tier, meet the GPAI and transparency obligations landing 2 August 2026, and ship AI to EU users without inheriting a rebuild or a fine.

Key Takeaways

  • Every AI system shipped to EU users falls into one of four tiers: unacceptable (banned), high-risk (heavy obligations), limited-risk (transparency duties), or minimal-risk (no new obligations). Classification is step one and determines everything else.
  • The obligations that hit most product teams – Article 50 transparency labeling and general-purpose AI (GPAI) documentation – apply from 2 August 2026. GPAI provider duties have already been live since 2 August 2025.
  • Fines reach up to €35 million or 7% of total worldwide annual turnover for prohibited practices, so this is a board-level risk, not a legal footnote.
  • You are almost certainly a deployer, not a provider – but deployers of high-risk systems still carry real duties: human oversight, input-data controls, logging, and monitoring. Read the roles before you assume you are exempt.
  • Most consumer and B2B AI products land in limited-risk, where compliance is mostly disclosure: tell users they are interacting with AI and label synthetic content. That is a few days of work if you scope it now, a scramble if you wait.
  • Retrofitting compliance after launch costs far more than designing for it. Budget classification, documentation, and a transparency layer into the build – not into a post-launch remediation project.

If you ship AI to EU users, the EU AI Act sorts your system into one of four risk tiers – unacceptable, high, limited, or minimal – and that classification decides everything you owe. The obligations that catch most product teams, Article 50 transparency labeling and general-purpose AI (GPAI) documentation, become applicable on 2 August 2026; GPAI provider duties have already been live since 2 August 2025. The Act is extraterritorial like GDPR, so a US or UK team whose output reaches the EU is in scope regardless of where its servers sit.

This matters because the penalties are not symbolic. According to Article 99 of the EU AI Act, 2024, deploying a prohibited AI practice can draw administrative fines of up to €35 million or 7% of total worldwide annual turnover, whichever is higher for a company. That makes AI classification a board-level decision, not a legal footnote – and the good news is that for most teams, compliance is a scoping exercise you can finish in days if you start before launch instead of after.

What are the four EU AI Act risk tiers?

The Act is risk-based: the heavier your system's potential to harm people's rights or safety, the heavier the obligations. Almost every product AI feature lands in the limited or minimal tier, but you cannot know that until you classify each feature deliberately. Here is the full map:

Risk tierWhat it coversYour obligations
Unacceptable (prohibited)Social scoring, manipulative subliminal techniques, untargeted facial scraping, workplace emotion recognitionBanned outright – do not build or deploy
High-risk (Annex III)Recruitment, worker management, credit scoring, essential services, biometrics, critical infrastructureRisk management, data governance, human oversight, logging, technical docs, conformity assessment
Limited-riskChatbots, support agents, generative content tools, most B2B and consumer AI featuresTransparency: disclose AI interaction, label synthetic content (Article 50)
Minimal-riskSpam filters, AI in games, inventory or ranking helpersNo new legal obligations under the Act

The single most valuable artifact you can produce this month is a one-page classification: list every AI feature, its intended purpose, and its tier. That document drives your entire obligation set, takes an afternoon, and is the thing an auditor, an enterprise buyer, or your own legal counsel will ask for first.

Are you a provider or a deployer – and why does it matter?

The Act splits duties by role, and most teams misjudge which one they are. A provider develops an AI system, or a GPAI model, and places it on the market under its own name. A deployer uses an AI system under its authority in a professional setting. If you build a product on top of a foundation model from OpenAI or Anthropic, you are a deployer of that model but a provider of the application you wrap around it – and the moment you fine-tune or substantially modify a system, you can become its provider, inheriting the full provider obligation set.

This distinction is where the biggest compliance surprises hide. Deployers of high-risk systems are not exempt: they must ensure human oversight, use the system according to its instructions, control the input data they feed it, keep logs, and monitor operation. Providers carry the far heavier load of conformity assessment, technical documentation, and post-market monitoring. Write down, per feature, which role you hold and against which model – because the answer changes your work by an order of magnitude, and it is not always the role you assumed.

What do the GPAI obligations require, and who do they hit?

General-purpose AI model obligations became applicable on 2 August 2025, a full year ahead of the main transparency rules. If you train or substantially fine-tune a general-purpose model, you are a GPAI provider and owe technical documentation, a summary of training-data sources, a copyright compliance policy, and information passed downstream to teams building on your model. Models designated as carrying systemic risk face additional model-evaluation and incident-reporting duties.

For the vast majority of product teams, this is inherited rather than original work: you consume a GPAI model, you do not build one. Your job is to confirm your model provider publishes the documentation you need to meet your own downstream obligations, and to keep that paperwork on file. If you are fine-tuning open-weights models heavily enough to shift their capabilities, revisit whether you have crossed into provider territory – a judgment call worth making with counsel rather than assuming.

What actually lands on 2 August 2026?

2 August 2026 is when the bulk of the Act becomes applicable, and two things bite product teams directly. First, the Article 50 transparency obligations: you must tell users when they are interacting with an AI system, label AI-generated or manipulated content such as deepfakes, and mark synthetic audio, image, and video as artificially generated in a machine-readable format. Second, the high-risk requirements for systems listed in Annex III come into force in full.

For a limited-risk product – which is where most chatbots, support agents, and generative features sit – meeting the transparency bar is genuinely modest engineering: a clear "you are chatting with an AI" disclosure and a content-labeling layer. Scoped into the build, that is a few days of work. Discovered the week before an enterprise security review, it is a scramble that stalls the deal. The date is fixed and public; the only variable is whether you plan for it or react to it.

What does a practical readiness checklist look like?

You do not need a compliance department to get this right – you need a disciplined sequence. Run these steps in order:

1. Inventory and classify. List every AI feature, its purpose, and its risk tier. Flag anything touching recruitment, credit, essential services, or biometrics for high-risk review immediately.

2. Assign roles. For each feature, record whether you are provider or deployer, and against which model. Note any fine-tuning that could reclassify you.

3. Build the transparency layer. Add AI-interaction disclosure and machine-readable labeling of synthetic content. This is your Article 50 baseline and applies to nearly everyone.

4. Document GPAI provenance. Keep on file the documentation your model provider publishes, so your downstream obligations are covered by paper you can produce on request.

5. If anything is high-risk, start the real program. Risk management, data governance, human oversight, logging, and technical documentation are a multi-week effort with legal review, not an afterthought. This overlaps heavily with the controls in our enterprise AI security checklist and with the structure in our AI governance framework for enterprises, so build them together rather than as separate initiatives.

The economics favor doing this during the build. A focused AI MVP runs roughly $50k–150k over a 30–45 day window, and folding classification, a transparency layer, and documentation into that scope adds days, not weeks. Retrofitting the same controls after launch – once the architecture has hardened and enterprise buyers are already asking – routinely turns into its own remediation project that can rival the cost of a new feature ($15k–50k) and delays revenue while you rebuild.

Compliance is not a tax on shipping AI to Europe; it is a design constraint you either honor early or pay for late. Classify your system, assign your roles, ship the transparency layer, and reserve the heavy program for the genuinely high-risk features that warrant it. If you want a partner who scopes the AI Act into the build instead of tacking it on at the end, see how we ship production AI on our services page – regulatory readiness included, not invoiced later.

Frequently Asked Questions

Does the EU AI Act apply to my company if we are not based in the EU?

Yes, if your AI system's output is used in the EU. The AI Act is extraterritorial, like GDPR: it applies to providers and deployers established outside the EU whenever the output of the system is used within the Union. A US startup with EU customers, or an AI feature whose results reach EU users, is in scope. Location of your servers or headquarters does not exempt you; where the output lands does.

What is the difference between a provider and a deployer under the EU AI Act?

A provider develops an AI system (or a general-purpose AI model) and places it on the market or puts it into service under its own name. A deployer uses an AI system under its authority in a professional context. Most teams building on top of OpenAI, Anthropic, or an open-weights model are deployers of the underlying model but providers of the application they wrap around it. The distinction matters because obligations differ sharply, and if you fine-tune or substantially modify a system you can become a provider of it.

What obligations land on 2 August 2026?

2 August 2026 is when the bulk of the AI Act becomes applicable, including the Article 50 transparency obligations and the high-risk requirements for systems listed in Annex III. Transparency means disclosing that users are interacting with AI, labeling AI-generated or manipulated content such as deepfakes, and marking synthetic audio, image, and video as artificially generated in a machine-readable way. GPAI model provider obligations have been in force since 2 August 2025, a year earlier.

How much can you be fined under the EU AI Act?

There are three tiers. Deploying a prohibited AI practice can cost up to 35 million euros or 7% of total worldwide annual turnover, whichever is higher for a company. Most other breaches – failing high-risk or transparency obligations – carry up to 15 million euros or 3% of turnover. Supplying incorrect, incomplete, or misleading information to authorities can cost up to 7.5 million euros or 1%. For SMEs and startups the lower of the two figures applies, which is a deliberate proportionality carve-out.

Is my AI chatbot or customer support agent high-risk?

Usually not. A general customer support or productivity chatbot is limited-risk: your main duty is transparency, telling users they are talking to an AI. A system becomes high-risk only when it falls into an Annex III category – for example AI used in recruitment and worker management, access to essential services, credit scoring, biometric identification, or critical infrastructure. If your agent screens job applicants or decides loan eligibility, it is high-risk and carries the full obligation set; if it answers product questions, it does not.

What is the fastest way to get compliant if we ship in weeks, not months?

Classify first: write down each AI feature, its purpose, and its risk tier, because that single document determines your entire obligation set and takes an afternoon. For the common limited-risk case, add a clear AI-interaction disclosure and content labeling – a few days of engineering. If any feature is high-risk, that is a different program involving risk management, data governance, human oversight, logging, and technical documentation, and you should plan several weeks and legal review rather than trying to bolt it on at the end.

Free Tools

Game Changer Labs

Tell us what you're building — book a free scoping call.

Pick a time that works and walk us through your project — 30 minutes, straight to the point. You leave with a concrete plan, timeline, and cost. No sales pitch — if we're not the right fit, we'll say so.

Keep Reading

Get new playbooks by email

Occasional, no-fluff field notes on building production AI — new guides and tools, straight to your inbox. Unsubscribe anytime.

Published: July 25, 2026Game Changer Labs