Introduction
You built an AI product, and the European Union built a sorting machine for it. One of the categories that machine sorts into carries fines of up to 15,000,000 euros or 3 per cent of global turnover, and the one above it reaches 35,000,000 euros or 7 per cent. So the single most valuable thing you can do before shipping is find out which category is yours.
Here is the mental model nobody hands you. The AI Act, Regulation (EU) 2024/1689, does not regulate artificial intelligence. It regulates risk. Every system lands in one of four tiers, being prohibited, high-risk, subject to transparency obligations only, or effectively unregulated, and your obligations, your costs, and your deadline all flow from which tier you occupy. The good news is that most AI products are not high-risk. The bad news is that guessing is not a strategy. Note also that the Regulation reaches beyond the Union: under Article 2, it applies to providers placing systems on the EU market irrespective of where they are established, and to providers and deployers in third countries where the output of the system is used in the Union.
This article walks down the pyramid, from the prohibited tier through the two doors into high-risk, the derogation that lets some systems out again, what a high-risk classification actually costs, the deadlines as they now stand after the Digital Omnibus, and the training data question that almost nobody audits.
Tier One: The Prohibited List
The top tier is not a demanding compliance regime. It is a ban. Article 5 lists practices that are unlawful in the Union with no compliance path available, and they carry the heaviest penalty in the Regulation, being up to 35,000,000 euros or 7 per cent of total worldwide annual turnover, whichever is higher. For small and medium-sized enterprises including start-ups, Article 99(6) applies the lower of those two figures rather than the higher, which is a meaningful mitigation but still a number that ends a financial year.
The prohibitions cover, among others, social scoring of natural persons leading to detrimental treatment, manipulative or subliminal techniques and the exploitation of vulnerabilities, untargeted scraping of facial images from the internet or CCTV to build facial recognition databases, emotion recognition in the workplace and in education outside narrow medical and safety purposes, and biometric categorisation to infer sensitive attributes. There is no form to file that makes any of these acceptable.
A new prohibition matters enormously if you work anywhere near generative image, video, or audio models. Regulation (EU) 2026/1744, the Digital Omnibus on AI, added to Article 5 a ban on AI systems that generate or manipulate realistic non-consensual intimate imagery of real persons and on systems that generate or manipulate child sexual abuse material. It applies from 2 December 2026. Read the structure carefully, because it is more nuanced than a blanket ban on image generators. It reaches systems intended for that purpose, systems placed on the market where such output is a reasonably foreseeable and reproducible outcome without adequate safeguards, and deployers who intentionally use a system to produce that content. The practical message for a legitimate generative AI business is therefore not to abandon the product. It is to implement genuine guardrails, with refusal training, prompt guardrails, content filtering, and abuse detection expressly recognised as protective measures, and to keep documentary evidence that you implemented them before the deadline.
Tier Two: The Two Doors Into High-Risk
There are exactly two routes into the high-risk category, and knowing which one you are looking at saves a great deal of wasted analysis.
The first door is Annex I, reached through Article 6(1). Your AI is a safety component of a product already covered by Union harmonisation legislation, or is itself such a product, and that product must undergo third-party conformity assessment. Medical devices, machinery, lifts, motor vehicles, toys, and radio equipment are the familiar examples. If your model is part of what keeps a regulated physical product safe, you are through this door.
The second door is Annex III, reached through Article 6(2), and this is the one that catches software companies. Annex III lists eight areas, being biometrics, critical infrastructure, education and vocational training, employment and workers management and access to self-employment, access to essential private and public services and benefits, law enforcement, migration and asylum and border control, and the administration of justice and democratic processes. A system intended for use in one of these areas is presumed high-risk. So a tool that screens CVs and ranks candidates is high-risk, a model that evaluates creditworthiness is high-risk, exam proctoring software is high-risk, and a system that determines pricing or eligibility for health or life insurance is high-risk. The pattern is consistent: each involves an AI system making, or substantially shaping, a decision about a person’s life.
The Article 6(3) Derogation and Its Two Catches
Landing inside one of the eight Annex III areas is not automatically fatal. Article 6(3) provides that such a system is not high-risk where it does not pose a significant risk of harm to health, safety, or fundamental rights, including by not materially influencing the outcome of decision-making, and where it meets any of four conditions:
- The system is intended to perform a narrow procedural task.
- The system is intended to improve the result of a previously completed human activity.
- The system is intended to detect decision-making patterns or deviations from prior patterns and is not meant to replace or influence the previously completed human assessment without proper human review.
- The system is intended to perform a preparatory task to an assessment relevant to an Annex III use case.
Two catches follow. First, the same paragraph provides that an Annex III system shall always be considered high-risk where it performs profiling of natural persons. Profiling therefore closes this door entirely, and the Commission’s draft guidelines treat profiling within the meaning of the GDPR and the Law Enforcement Directive as excluding the derogation outright. Second, you do not simply decide you are exempt and move on. Article 6(4) requires the provider to document its assessment before the system is placed on the market or put into service, to supply that documentation to national authorities on request, and to register the system in the EU database under Article 49(2). The Digital Omnibus streamlined the information required for that registration but expressly retained the obligation, because it was considered essential to market surveillance and public accountability.
One drafting rule underpins all of this. Classification follows your stated intended purpose, meaning what your instructions for use, technical documentation, and promotional materials say your product does. The Commission’s draft guidelines on the classification of high-risk AI systems, published on 19 May 2026, place the intended purpose at the centre of the analysis under both Article 6(1) and Article 6(2). You cannot market a system as artificial intelligence that decides who to hire and then shelter behind small print describing it as a mere suggestion. As with crypto marketing, your promotional copy is a legal statement.
What a High-Risk Classification Actually Costs
If your system is high-risk, Chapter III imposes a substantial and interlocking set of obligations. You will need a risk management system under Article 9, data and data governance measures under Article 10, technical documentation under Article 11, automatic record-keeping and logging under Article 12, transparency and instructions for use for deployers under Article 13, effective human oversight under Article 14, and appropriate accuracy, robustness, and cybersecurity under Article 15. On top of that sit provider obligations including a quality management system under Article 17, a conformity assessment under Article 43, CE marking under Article 48, registration under Article 49, post-market monitoring under Article 72, and serious incident reporting under Article 73. Failure to comply with these obligations attracts fines of up to 15,000,000 euros or 3 per cent of total worldwide annual turnover under Article 99(4). This is not a weekend of paperwork. A genuine high-risk build routinely takes a year or more.
The Deadlines, As They Now Stand
This is where most commentary is out of date, so the current position matters. The original date for high-risk obligations was 2 August 2026. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026, and entered into force on 27 July 2026, just ahead of that deadline. This is settled law, not a political agreement awaiting adoption.
The revised timeline is as follows. Standalone Annex III high-risk systems now become subject to the high-risk obligations from 2 December 2027. Annex I systems embedded as safety components in regulated products follow from 2 August 2028. High-risk systems already in use by public authorities have until 2 August 2030. Meanwhile, obligations that already apply have not moved: the Article 5 prohibitions and the Article 4 AI literacy duty since 2 February 2025, the general-purpose AI model obligations in Chapter V since 2 August 2025, and the Article 50 transparency obligations, together with the governance and penalty framework, since 2 August 2026, with a grace period to 2 December 2026 for marking AI-generated content in systems placed on the market before that date. The extra runway is real, but a build that takes a year or more does not benefit from being started late. Classify now, and use the time.
The Part Nobody Audits: Your Training Data
This is where AI regulation and intellectual property law collide, and where founders are most exposed. Two distinct problems live in the same dataset.
The first is quality. If your system is high-risk, Article 10 requires training, validation, and testing datasets to be relevant, sufficiently representative, and to the best extent possible free of errors and complete, with examination for possible biases. Poor data is no longer merely an engineering weakness. It is a compliance failure attracting the Article 99(4) fine level.
The second is ownership, and this is the one that ends companies. Under Article 4 of Directive (EU) 2019/790, text and data mining of lawfully accessible works is permitted for any purpose, including commercial AI training, but only where the rightsholder has not expressly reserved that use in an appropriate manner, which for content made publicly available online means machine-readable means. Ignore a properly expressed reservation and the mining falls outside the exception, which puts the foundation of your model in question. If you train a general-purpose AI model yourself, Article 53(1)(c) and (d) require you to put in place a policy to comply with Union copyright law, including respecting those reservations, and to publish a sufficiently detailed summary of the content used for training according to the template provided by the AI Office. Those obligations have applied since 2 August 2025. If you build on somebody else’s model, get contractual assurance and documentation that they did this properly, because the commercial consequences of an unlawful training corpus flow downstream to the products built on it.
Conclusion
In summary, four tiers govern every AI system on the EU market. If your product sits on the prohibited list, there is no compliance path, and the new prohibition on non-consensual intimate imagery and child sexual abuse material begins applying on 2 December 2026, with real safeguards and documented evidence of them being the answer for legitimate generative AI products. Two doors lead into high-risk, being safety components of regulated products under Annex I and the eight sensitive areas under Annex III, which in practice means AI that decides things about people’s lives. If you think the Article 6(3) derogation applies, document the assessment and register the system anyway, and remember that profiling closes that door. High-risk classification means a year or more of substantive obligations and exposure to fines of up to 15,000,000 euros or 3 per cent of turnover, now due from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. And audit your training data for both quality and provenance before a regulator or a rightsholder does it for you.