---
title: "EU AI Act: an operational guide for companies, between obligations in force and moving deadlines"
url: https://zerofive.ai/en/blog/compliance/eu-ai-act-operational-guide-companies
canonical: https://zerofive.ai/en/blog/compliance/eu-ai-act-operational-guide-companies
language: en
published: 2026-02-03
updated: 2026-09-18
author: "ZeroFive.AI"
tags: EU AI Act, AI Act company obligations, AI Act deadlines, Digital Omnibus, AI compliance
abstract: "What the EU AI Act requires of companies: obligations already in force, the deadline calendar, the Digital Omnibus proposal and the first operational steps."
---

# EU AI Act: an operational guide for companies, between obligations in force and moving deadlines

There is a misunderstanding we meet in almost every committee where the AI Act comes up, and it is worth clearing at the start: Regulation (EU) 2024/1689 also concerns, and above all, those who use artificial intelligence systems, not only those who develop them. The company adopting candidate-screening software, the bank employing models in credit evaluation, the business integrating generative AI into customer-facing processes: all fall within the perimeter, with defined roles and obligations. The second misunderstanding, its mirror image, is thinking there is time. Part of the regulation is already in force and already sanctionable.

## What is already law, today

The regulation entered into force on 1 August 2024, with staggered application. Since 2 February 2025 two blocks apply to everyone. The first is the Article 5 bans on unacceptable-risk practices, from social scoring to subliminal manipulation to emotion recognition in the workplace, with narrow exceptions. The second, far more cross-cutting than its media profile suggests, is Article 4 on literacy: organisations must ensure an adequate level of AI literacy for staff operating these systems, which makes training a regulatory obligation as well as good practice.

Since 2 August 2025 the obligations for providers of general-purpose AI models have been added, together with the European governance architecture and the sanctions framework, which in its highest band reaches 7% of annual worldwide turnover. Anyone treating the AI Act as a topic for the future is, in practice, accumulating a backlog on rules that already apply.

## The calendar ahead, and the Omnibus variable

The next milestone set by the text is 2 August 2026, the date of general application of the regulation, which includes the transparency obligations of Article 50 (informing people when they interact with an AI, marking generated content) and, in the original calendar, the requirements for high-risk systems under Annex III: risk management, data quality, technical documentation, human oversight, registration.

Here enters the variable anyone planning 2026 needs to know. On 19 November 2025 the Commission presented the simplification package known as the Digital Omnibus, which proposes, among other things, to tie the application of high-risk obligations to the actual availability of harmonised standards and support tools, with backstop dates pushed beyond August 2026. The legislative process is ongoing as we write, and until any publication in the Official Journal the original dates remain formally valid.

The operational reading we give clients is prudent on both fronts: plan as if August 2026 holds, and welcome a possible postponement as time gained to do things properly rather than as a free pass, not least because the substance of the obligations is not under discussion, only the when is.

## The four steps to take now

Experience on compliance programmes suggests a sequence that holds regardless of the Omnibus outcome, because it builds capacity that is needed anyway.

The first step is the census: an inventory of AI systems in use or under development, including those purchased inside other software and those used informally by teams, because you cannot classify what you cannot see. The second is the risk classification of each system according to the regulation's categories, which determines which obligations apply and in which role (provider, deployer, importer). The third is the compliance check on obligations already in force, bans and literacy first, with a documented training plan. The fourth is the assignment of responsibilities, because AI Act readiness cuts across legal, IT, risk, HR and business, and without an owner holding an explicit mandate it dissolves into meetings.

On this journey our usual warning applies: we talk about gap analysis and preparation, never about guaranteed compliance, which no serious advisor can promise and which the regulation itself frames as a continuous process, never a stamp.

## Compliance as a by-product of governance

The strategic mistake to avoid is treating the AI Act as an isolated compliance project, a legal workstream to close and archive. The things the regulation asks for, knowing which systems you use, assessing their risks, documenting decisions, training people, overseeing data, are exactly the components of AI governance done well, the kind needed to generate value even before avoiding sanctions. In our AI Rating the Risk dimension measures precisely this distance, with precise references to the regulation's articles for every gap found, inside an overall maturity evaluation.

If your board or risk committee has put the AI Act on this year's agenda, the fastest way to turn the agenda into a plan is measuring the starting point: calendly.com/fabiolalli/zerofive, or hello@zerofive.ai. The deadlines may still move, the direction will not, and the distance to cover is the same either way: better to know it as a number.
