More in
AI at Work News
OpenAI Opened ChatGPT Advertising to Small Businesses at Any Budget
Jun 6, 2026
AI Is Everywhere at Work. Only 1 in 10 Say It Transformed the Job
Jun 6, 2026
Vibe Coding's $10.5B Moment: AI Now Starts Most New Software Builds
Jun 6, 2026
AI Agents Now Have More System Access Than Your Employees. Few Are Secured
Jun 5, 2026
Should You Build Your AI or Buy It? Watch What the Giants Bought.
Jun 5, 2026
Uber Caps Employee AI Spending at $1,500 Per Seat After a Budget Blowout
Jun 5, 2026
Trump's AI Executive Order Is Deregulatory. Your Compliance Risk Didn't Move
Jun 4, 2026
AI Pushed 220 Unicorns Below $1B. Pre-ChatGPT Companies Face a Reckoning
Jun 4, 2026
Token Prices Fell 67% This Year. Your AI Bill Is Going Up Anyway
Jun 3, 2026
Small Businesses Using AI Report Higher Revenue and Shorter Workdays
Jun 3, 2026
Is Your Company's AI Use High-Risk Under the EU AI Act?

Turn this article into takeaways for your work.
Each assistant summarizes the article only for you and suggests best practices for your work.
Most executives who've heard of the EU AI Act assume it's a problem for AI companies, not for companies that simply buy and use AI tools. That's wrong for a lot of businesses, including plenty that have never sold a product in Europe.
The two questions that actually matter are simpler than the headlines suggest: does the law apply to your company at all, and if it does, which of your AI uses would count as high-risk. This article answers both in plain language, with a self-check you can run this week. For the separate question of what compliance groundwork to build regardless of how deadlines shift, see our companion piece on AI compliance that survives regulation changes.
A note before we go further: this is general business information, not legal advice. Confirm your specific exposure with qualified counsel.
Does the EU AI Act Apply to You? It's Not Just About Where You're Headquartered
The single most common mistake is assuming the EU AI Act is a European problem for European companies. It isn't. The Act's reach is tied to where an AI system is used or where its outputs affect people, not where the company that owns it is incorporated.
Article 2 of the Act spells out three ways in. It covers providers that put AI systems on the EU market wherever they are based, deployers established or located in the EU (so a European office running an AI hiring tool counts), and providers and deployers outside the EU when the output of their AI system is used in the EU. Headquarters location doesn't exempt you, and the bar for being "touched" by the Act is lower than most leadership teams assume.
If any part of your business sells into the EU, employs people there, or runs AI-driven decisions affecting EU-based customers or staff, treat the Act as a live question, not background noise about a foreign regulation.
Provider or Deployer? The Distinction That Changes Everything
Once you know the Act might apply, the next question is which role you play, because the obligations are very different depending on the answer.
A provider builds and places an AI system on the market. That's OpenAI, Anthropic, your ATS vendor, your credit-scoring software company. A deployer uses an AI system under its own authority in the course of business. If your company bought an AI-powered recruiting tool, a performance management platform with an AI scoring layer, or a credit decisioning tool, and didn't build it, you're a deployer, not a provider.

Most B2B companies reading this are deployers, and that matters because deployer obligations are lighter than provider obligations but not zero. Deployers of high-risk AI systems are still expected to maintain human oversight over consequential decisions, monitor the system's operation, and keep records of how it's used. The vendor is responsible for building the system to spec; you're responsible for how you operate it. Those are separate obligations, and the standard SaaS-procurement assumption, that the vendor "handles compliance," only covers half the picture. Ask vendors for their compliance documentation, but don't treat a yes as the end of your own responsibility.
What Counts as High-Risk, in Plain English
The EU AI Act doesn't classify AI systems as high-risk based on how sophisticated they are. It classifies them based on what kind of decision they inform. A simple tool that ranks job candidates is high-risk. A far more advanced AI system that drafts marketing copy generally is not.

The categories most relevant to ordinary B2B companies, under Annex III of the Act, include:
Employment and worker management. Recruiting tools that screen or rank candidates, AI features in performance management or promotion decisions, and monitoring tools that inform disciplinary or termination decisions. If your applicant tracking system has an AI scoring layer, and most current ones do, you're likely operating a high-risk use case.
Credit and access to essential services. AI that assesses the creditworthiness of individual people, prices life or health insurance for individuals, or decides access to other essential services. This can reach beyond banks when a business uses AI to judge an individual's credit, such as a sole trader or a personal guarantor. Credit decisions about other companies generally sit outside this category, which is why B2B lead scoring and forecasting usually carry far less exposure.
Education and vocational training. AI systems used to evaluate students, score exams, or determine access to training or educational programs.
Law enforcement and migration/border control are also high-risk categories in the Act, but rarely touch an ordinary B2B business.
What's NOT High-Risk
This is the part that calms most executives down once they see it in writing. The bulk of everyday workplace AI, drafting assistants, meeting summarizers, internal search, code-completion tools, and general productivity features in tools like Rework, does not fall under the high-risk categories. High-risk status attaches to AI that makes or substantially informs a consequential decision about a specific person. A tool that helps your team write or organize work faster doesn't meet that bar on its own.
Quick Self-Check
| Question | If yes |
|---|---|
| Do you sell to, employ people in, or operate AI systems affecting people in the EU? | The Act is a live question for your company |
| Did you buy the AI tool rather than build it? | You're likely a deployer, with oversight and monitoring duties, not a provider's full obligations |
| Does the tool score, rank, or decide something about a specific person's job, credit, or education access? | Treat it as potentially high-risk until legal confirms otherwise |
| Is the AI used for internal productivity (drafting, summarizing, search, scheduling)? | Likely outside the high-risk categories |
Where the Deadlines Stand (as of October 2026)
The compliance questions above don't change with the calendar, but when each one becomes enforceable did move. The EU's Digital Omnibus on AI, in force since late July 2026, rewrote the enforcement timeline for high-risk systems, according to Orrick's analysis of the final text.
The obligations tied to the Annex III categories above, employment, credit, and education among them, no longer take effect on August 2, 2026. Jones Walker's breakdown of the delay and Morgan Lewis's client alert both confirm the new date is December 2, 2027. High-risk obligations for AI embedded in regulated products, like medical devices or machinery under Annex I, move further out, to August 2, 2028.
Not everything moved. The Act's transparency rules under Article 50, requiring disclosure when someone is interacting with AI, viewing AI-generated content, or being scored emotionally or biometrically, still apply from August 2026. One narrow carve-out: providers of systems already on the market before August 2, 2026 get until December 2, 2026 to implement technical watermarking.
Key Facts
- High-risk obligations under Annex III (employment, credit, education, and similar uses) are deferred from August 2, 2026 to December 2, 2027.
- High-risk obligations for product-embedded AI under Annex I are deferred to August 2, 2028.
- Transparency obligations under Article 50 (AI-interaction disclosure, deepfake labeling) still apply from August 2026, largely unaffected by the delay.
- A narrower grace period pushes technical watermarking compliance, for systems already on the market before August 2026, to December 2, 2026.
- Morgan Lewis frames the delays as "an extension of time to complete their AI Act compliance efforts, rather than... a material relaxation of the underlying obligations."
The dates moved. The categories that count as high-risk didn't. Whether your company is in scope, and which of your AI uses would qualify, is the same answer it was before the Digital Omnibus.
What to Do in the Next 30 Days
You don't need outside counsel to complete the first three steps. You do need it before you rely on any conclusion you draw from them.

- List every AI tool your teams actually use, including features bundled into software you didn't buy specifically for AI. Your HR, sales, finance, and customer success leads each know tools legal has never heard of.
- Run each tool through the self-check table above. Does it touch EU people or markets? Did you buy it rather than build it? Does it score or decide something about a specific person's job, credit, or education access?
- Flag anything that lands in a high-risk category, even with the deadline pushed to December 2027. Building the documentation and oversight process for an employment or credit decision tool takes months, not weeks.
- Check your transparency obligations now, since Article 50 is already live. Does every AI-generated customer communication disclose that it's AI?
- Bring in legal counsel for the formal classification call. With the inventory and the preliminary self-check done, you'll have what they need to give you a real answer instead of a general one.
If your AI-driven sales or lead-scoring tools touch EU customers, our RevOps compliance checklist for AI lead scoring under the EU AI Act walks through the function-specific version of this inventory. For the documentation side once you know what's in scope, see our guide to building an AI governance policy for your department and the AI readiness assessment templates. If you're weighing EU exposure against a looser US posture, our look at the deregulatory US executive order explains why one jurisdiction loosening doesn't cancel obligations in another, and our piece on why AI agents now carry more system access than most companies have secured covers the related security angle.
Frequently Asked Questions about the EU AI Act for Businesses
Does the EU AI Act apply to companies outside the EU?
Yes, if your AI systems are used in the EU, affect people in the EU, or your outputs reach EU customers or employees. Headquarters location doesn't exempt you. Confirm your specific exposure with counsel.
My company only uses AI tools we bought from vendors. Are we still covered?
Likely yes, but as a deployer rather than a provider. Deployers of high-risk AI systems still need human oversight, monitoring, and records, even though the vendor carries the provider-side obligations.
Which everyday AI tools are NOT considered high-risk?
General productivity AI, drafting assistants, meeting summarizers, internal search, and scheduling tools generally fall outside the high-risk categories, because they don't make or substantially inform a consequential decision about a specific person.
If the high-risk deadline moved to December 2027, why should I check this now?
The deferral buys time to prepare, not a reason to skip preparing. Classifying your AI uses and building an oversight process takes months, and the categories that count as high-risk didn't change, only the enforcement date did.
What's still enforceable in 2026 if the high-risk rules were delayed?
Article 50's transparency obligations, disclosing AI interactions, AI-generated content, and emotional or biometric scoring, still apply from August 2026. Those are separate from the high-risk rules and worth checking regardless of your high-risk classification.
Sources: Orrick, "EU AI Act Update: Digital Omnibus Finalizes 8 Compliance Changes" (July 2026) | Jones Walker, "Yes, August 2 Still Matters: The EU Approved a High-Risk AI Delay, but Most Transparency Obligations Remain" (July 2026) | Morgan Lewis, "EU Approves Delays and Other Amendments to Certain EU AI Act Obligations: What Businesses Should Know" (June 2026)
This article is general business information, not legal advice. AI regulation changes quickly and varies by jurisdiction. Confirm your specific obligations with qualified legal counsel before making compliance decisions.
