Back to Guides
Guide16 September 2026

What You Need to Know About the EU AI Act Regulation in 2026

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. Key takeaways
  2. What is the EU AI Act and why does it matter?
  3. Who does the regulation cover?
  4. How does the risk - based classification work?
  5. Which AI practices are banned outright?
  6. What obligations do high - risk AI providers face?
  7. When do the compliance deadlines apply?
  8. How are general - purpose AI models regulated?
  9. What are the enforcement mechanisms and potential penalties?
  10. How does the AI Act interact with existing EU legislation?
  11. What should companies do right now to prepare?
  12. Where can I find more detailed guidance?

Key takeaways

What is the EU AI Act and why does it matter?

The EU AI Act is a Europe - wide regulation that creates a uniform legal framework for developing, placing on the market and using AI systems. It matters because it applies extraterritorially, forces companies worldwide to meet EU standards if their AI impacts EU users, and introduces the first comprehensive risk - based approach to AI governance.

Who does the regulation cover?

The regulation covers any provider that places an AI system or a general - purpose AI model on the EU market, any user (deployer) of AI located in the EU or whose output is used in the EU, as well as importers, distributors, product manufacturers and authorised representatives. Natural persons using AI for purely personal non - professional activity, pure scientific research and exclusive military use are excluded.

How does the risk - based classification work?

Risk tierDefinitionTypical obligations
UnacceptablePractices that are outright prohibited (e.g., real - time remote biometric ID in public spaces)No deployment allowed
HighAI that poses significant health, safety or fundamental - rights risks or is a safety component of regulated productsConformity assessment, CE marking, technical documentation, post - market monitoring, data - governance, human - oversight
LimitedAI with limited impact, such as chatbotsTransparency notice to users
MinimalLow impact AINo specific EU obligations

Which AI practices are banned outright?

Prohibited practices listed in Article 5 include real - time remote biometric identification in public spaces, biometric categorisation of individuals, government - run social - scoring and AI that manipulates human behaviour to cause physical or psychological harm. Companies must ensure these systems are not placed on the market or used in the EU.

What obligations do high - risk AI providers face?

High - risk providers must:

  1. Perform a conformity assessment (self - assessment or notified - body).
  2. Create and maintain detailed technical documentation and a register of logs.
  3. Implement post - market monitoring and report serious incidents to national authorities.
  4. Apply data - quality and governance measures, including data - set documentation and bias mitigation.
  5. Ensure human - oversight mechanisms are built into the system and provide clear user - facing transparency.

When do the compliance deadlines apply?

How are general - purpose AI models regulated?

Providers of GPAI models that exceed 10^25 FLOP must notify the European Commission, conduct systemic - risk assessments and publish a model - card with transparency information. They must also follow a “General - Purpose Code of Practice” overseen by the AI Office.

What are the enforcement mechanisms and potential penalties?

Violations of prohibited - practice rules can be fined up to €35 million or 7 % of worldwide annual turnover, whichever is higher. Other breaches (e.g., missing documentation, inadequate post - market monitoring) attract lower but still significant fines, enforced by national authorities coordinated by the European Artificial Intelligence Board.

How does the AI Act interact with existing EU legislation?

The AI Act works alongside the New Legislative Framework (Reg EC No 765/2008, Decision No 768/2008/EC, Reg EU 2019/1020) and complements sector - specific rules such as medical - device, automotive and product - safety directives. This coordination ensures that AI components embedded in regulated products are covered consistently.

What should companies do right now to prepare?

  1. Inventory every AI system, model or service that is offered to EU users.
  2. Classify each system using the four - tier risk matrix.
  3. For any high - risk or prohibited - risk AI, start building the required technical documentation and plan conformity - assessment pathways.
  4. If you develop large - scale GPAI, begin drafting a model - card and conduct a systemic - risk assessment.
  5. Establish a post - market monitoring process and assign a compliance lead.
  6. Monitor the European AI Board and AI Office for guidance updates.

Where can I find more detailed guidance?


This article follows the latest publicly available facts as of September 2026.

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary