The EU AI Act Breakdown
The EU AI Act reaches businesses with no European office, no European staff and no European servers. Anthropic, an American company, signed the Act’s Article 50(2) Code of Practice on Transparency of AI-Generated Content, and by its own description the resulting marking applies to Claude output “wherever Claude is offered, worldwide”. A European transparency rule now shapes what an American model returns to a user in Lagos, Toronto or Singapore.
Two routes put a company outside Europe inside this law. Selling into the Union is the obvious one. The other is quieter, it catches firms who have never thought about Europe at all, and it sits in one line of Article 2.
TL;DR
- The trigger is where the output is used, not where your company sits. Article 2 catches firms in a third country "where the output produced by the AI system is used in the Union."
- Four tiers: unacceptable risk is prohibited, high risk is heavily controlled, transparency risk requires disclosure, minimal risk carries no special AI Act controls. Most ordinary business use is minimal.
- Three sets of obligations are already in force: prohibitions and AI literacy since February 2025, general-purpose model rules since August 2025, Article 50 transparency since August 2026.
- Article 50 is the one most businesses meet first, because it attaches to ordinary generative AI rather than to sensitive decisions. Anthropic's implementation is the clearest public example of what it asks for.
- The high-risk deadlines moved. The Digital Omnibus deferred Annex III systems to 2 December 2027 and AI in regulated products to 2 August 2028.
- Your role decides your obligations. Provider, deployer, importer, distributor. Building a product on somebody else's model can make you the provider.
- Maximum fines run to 35 million euro or 7% of worldwide turnover, whichever is higher, for prohibited practices.
The line that reaches past Europe
Most coverage of this law starts with the risk pyramid. That is the second question. The first is whether the Regulation reaches you at all, and the answer sits in Article 2, which applies the Act to:
providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union.
Every country outside the Union is a third country. The test runs on where the output of your system gets used, so ask whether any of it lands with somebody in the Union.
Call it the output test. It has an answer, and the answer is usually available from your customer list in an afternoon.
Two things follow. A software company selling into Europe is exposed through its customers. A company with European employees is exposed through its own internal systems, because a tool used to screen or monitor those employees produces output used in the Union.
Many firms will run the output test and find they sit outside the Act. That is a real answer and it is worth having in writing, because the next procurement questionnaire will ask.
The four tiers
The Act sorts AI by what it is used for and how much harm it could cause. It is a product-safety law in structure, so the obligations attach to categories of use rather than to the technology.
Unacceptable risk is prohibited outright and has been since February 2025. The list includes manipulative techniques that materially distort behaviour and cause significant harm, exploitation of vulnerabilities related to age or disability, social scoring, predictive policing based solely on profiling, building facial recognition databases by untargeted scraping, emotion recognition in workplaces and schools subject to narrow exceptions, and biometric categorisation to infer sensitive characteristics such as political opinions or religion.
High risk is permitted and carries the heaviest control set in the Regulation. A system gets there by one of two routes: it is a safety component of a product already covered by EU product-safety law, or it appears in the Annex III list of sensitive decisions. Annex III covers employment decisions, education access, creditworthiness, certain insurance, eligibility for essential public services, biometrics, critical infrastructure, and law enforcement, migration and justice.
Transparency risk is permitted provided people are told. Chatbots have to disclose that they are AI unless it is obvious. Providers of systems generating synthetic audio, video, images or text have to support machine-readable identification of that output. Deep fakes have to be disclosed as artificially generated.
Minimal risk carries no special AI Act controls, and it is where most ordinary business use sits. A general rule that every AI system needs government approval does not exist in this law.
Worth keeping
- Run the output test before the risk assessment. The tiers are irrelevant if the Regulation does not reach you.
- Being in scope and being high-risk are different findings. Most in-scope systems are not high-risk.
- An Annex III system can fall outside high-risk where it performs a narrow procedural task, though profiling people generally keeps it in.
What transparency looks like in practice
Article 50 has applied since 2 August 2026, and it is the tier most businesses meet first, because it attaches to ordinary generative AI rather than to sensitive decisions.
Anthropic’s implementation is the clearest public example of what a provider does about it. It signed the Article 50(2) Code of Practice as a provider of both generative AI models and generative AI systems, and Claude models launched in the EU on or after 2 August 2026 support machine-readable marking at launch. Text gets an imperceptible watermark woven into it, so the mark travels when the text is copied elsewhere. Files of supported types get signed provenance metadata following the C2PA standard, which records that a file was processed by Claude and reveals whether it has since been tampered with.
Two details matter more than the technique.
The first is reach. Marking applies across the API, the Claude apps, Claude Code and the cloud platforms Claude is offered through, and it applies worldwide rather than only inside the Union. Splitting a product by jurisdiction costs more than applying the higher standard everywhere, so the higher standard travels. That is the mechanism by which an EU rule becomes a global product decision, and it is worth watching for in every vendor you buy from.
The second is honesty about the limits. Anthropic publishes them alongside the commitment: a detected mark says the content may have been processed by Claude, and an absent mark says nothing at all, because short passages, heavy editing and format conversion all strip the signal. A vendor who describes the failure modes of their own control is giving you something you can plan around.
For a deployer, Article 50 arrives differently. Disclose that a chatbot is AI unless it is obvious to a reasonably well-informed person. Disclose deep fakes as artificially generated. Published text that informs the public is exempt where a person took editorial responsibility for it, which is the provision covering ordinary business writing that had a human editor.
What already applies
The date most firms remember is August 2026. The dates that already bind them arrived earlier.
The high-risk dates moved. The Digital Omnibus entered into force on 27 July 2026 and deferred Annex III obligations to 2 December 2027, and high-risk AI embedded in regulated products to 2 August 2028. The reason given was the state of the harmonised standards those obligations depend on.
What else the Omnibus changed
Reporting the Omnibus as a deadline extension misses half of it, and this is where most current explainers are now wrong.
The Omnibus prohibits AI systems that generate non-consensual sexually explicit and intimate content, and child sexual abuse material. Any list of prohibited practices dated before July 2026 is incomplete.
Article 4 was rewritten from taking measures to "ensure to their best extent a sufficient level" of AI literacy to taking measures to "support the development of" it. The revised provision does not require guaranteeing any specific level for any individual.
Some simplifications previously reserved for SMEs now extend to small mid-cap companies, which widens the set of firms that get the lighter administrative path.
Access to regulatory sandboxes was widened and an EU-level sandbox introduced, which matters to anyone building rather than buying.
Processing special categories of personal data is now permitted to detect and correct bias, which resolves a real tension between fairness testing and data protection.
The AI literacy change deserves a note of its own, because the pre-Omnibus wording is still circulating and it is more demanding than the law now is. The duty is one of effort rather than result, and the Commission and Member States are obliged to support it. Training your people remains sensible. Telling your board they must guarantee a literacy level overstates the obligation.
Which role are you
Obligations attach to a role, so the role is the thing to settle first. The definitions are precise and worth reading as written rather than paraphrased.
-
Provider
You develop an AI system, or have one developed, and place it on the market or put it into service under your own name or trademark. Building a recruitment product on somebody else's foundation model makes you the provider of the recruitment system.
-
Deployer
You use an AI system under your own authority in a professional capacity. An employer using a hiring tool, a bank using a credit model. A deployer controls the context in which the system affects people, which is why it carries duties of its own.
-
Importer and distributor
An importer is established in the Union and places a third-country provider's system on the market. A distributor makes a system available in the EU supply chain without being provider or importer.
-
Authorised representative
Someone in the Union holding a written mandate from a non-EU provider to carry out its obligations. A provider outside the Union that is in scope will generally need one.
Roles move. A deployer, importer or distributor becomes treated as a provider by putting its own name on a system, making a substantial modification, or changing the intended purpose in a way that makes the system high-risk. That last one catches firms who buy a general tool and point it at hiring.
What the penalties look like
Maximum fines run to 35 000 000 euro or 7% of total worldwide annual turnover for prohibited practices, 15 000 000 euro or 3% for most other operator obligations, and 7 500 000 euro or 1% for supplying incorrect or misleading information. For an undertaking the applicable figure is the higher of the two. For SMEs and start-ups, Article 99 provides that each fine is up to the amount or percentage, whichever is lower.
Fines are the headline and rarely the operative risk. Regulators can also require corrective action, restrict a system, withdraw a product and recall it from the market. For a software company, a withdrawal order reaches customers in a way a fine does not.
What to do first
-
Run the output test
List where the output of each AI system you run is used, including customers, employees and anyone whose decision it feeds. If none of it lands in the Union, record that finding and revisit it when you next sell into Europe.
-
Build the inventory
Purchased AI software, AI embedded in platforms you already pay for, internal automations, custom agents, customer-facing chatbots, models reached through APIs, and the tools people adopted without telling anyone. The last category is usually the largest surprise.
-
Sort by what the system decides
Hiring, performance, credit, insurance, education, health, benefits, biometrics and access to essential services are the areas Annex III covers. A system touching one of those is the one to take advice on.
-
Settle your role for each system
Provider, deployer, importer, distributor. Write it down per system, because the same company holds different roles for different tools and the obligations differ.
-
Write down what you can evidence
Ownership, intended use, risk classification, vendor assessments, data flows, oversight procedures, testing, logging, incident handling and training. This is the durable work, and it is the same evidence your own regulator or a large customer will ask for.
Step five is the point of the whole exercise. The Act asks a firm to make AI decisions traceable, governed and assignable to somebody accountable. That is worth doing whether or not Europe is in your future, which is why we treat governance as one component of an AI operating system rather than a compliance project bolted on at the end.
Worth keeping
- The output test gives you a definite answer, and a written negative finding is worth having.
- Shadow AI is the part of the inventory that breaks the assessment. Find it before a customer asks.
- The evidence pack is reusable. It answers procurement questionnaires and your own supervisor's questions too.
- Watch what your vendors do about Article 50. A vendor applying the EU standard globally has made the decision for you.
Common mistakes
- Assuming no EU office means no exposure. Why it fails: Article 2 turns on where the output is used, so a customer or an employee in the Union brings the Regulation with them. Better: run the output test across customers, staff and data subjects.
- Reading a pre-Omnibus explainer. Why it fails: the prohibition list grew, the AI literacy duty was softened and the high-risk dates moved, all on 27 July 2026. Better: check the date on anything you rely on, including this page.
- Treating the 2027 deferral as breathing room. Why it fails: prohibitions, GPAI obligations and transparency duties are already in force, and the deferred obligations are the ones needing the longest lead time. Better: use the deferral to build the evidence rather than to wait.
- Assuming your vendor's compliance covers you. Why it fails: the deployer carries duties the provider cannot discharge, and putting your name on a system can make you the provider. Better: settle your role per system and read what attaches to it.
- Classifying by technology rather than by use. Why it fails: the same model is minimal risk in one workflow and high risk in another, because the tier follows the decision it affects. Better: classify each use, not each tool.
- Calling a person in the loop human oversight. Why it fails: oversight requires that the person understands the system's limits, can interpret the output and has authority to override it. Better: define what the reviewer sees, what they can change and how disagreement is recorded.
What this article does not claim
It does not claim your firm is in scope. Article 2 sets a specific trigger and many firms will fall outside it. The output test is here so you can reach your own answer.
It does not tell you whether a particular system is high-risk. That is a legal determination on specific facts, and it is worth paying for.
It does not name any product as compliant. High-risk obligations do not apply until December 2027, so no product has a compliance record to point at.
This article states the position on 11 August 2026. The timeline has already moved once.
- AI system
- A machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment, and that infers from the input it receives how to generate outputs such as predictions, content, recommendations or decisions.
- Third country
- Any country outside the European Union. Article 2 extends the Regulation to providers and deployers located in a third country where the output of their AI system is used in the Union.
- Provider
- The person or body that develops an AI system or general-purpose model, or has one developed, and places it on the market or puts it into service under its own name or trademark.
- Deployer
- The person or body using an AI system under its authority, other than in the course of a personal non-professional activity.
- Authorised representative
- A person established in the Union holding a written mandate from a provider to carry out that provider's obligations under the Regulation.
- Annex III
- The list of use areas that make a standalone AI system high-risk, covering employment, education, essential services, biometrics, critical infrastructure, and law enforcement, migration and justice.
- General-purpose AI model
- A model capable of supporting many downstream uses, regulated separately from the applications built on it, with heavier duties for models classified as carrying systemic risk.
- Machine-readable marking
- Signals embedded in generated content so a machine can detect it as artificially generated, required of providers of generative AI systems by Article 50(2). Anthropic uses watermarks embedded in text and C2PA provenance metadata on files.
- Conformity assessment
- The process by which a provider demonstrates a high-risk system meets the Regulation's requirements before it is placed on the market.
- Digital Omnibus
- The amending act that entered into force on 27 July 2026, deferring the high-risk dates, adding a prohibition, rewriting the AI literacy duty and widening several simplifications.
Questions firms ask
We have no European entity. Are we in scope?
Possibly. Article 2 applies the Regulation to providers and deployers in a third country where the output produced by the AI system is used in the Union. Check your customers, your employees and anyone whose decisions your output feeds, then record the finding.
Does every AI system need approval?
No. Minimal-risk use carries no special AI Act controls and covers most ordinary business use. The heavy obligations concentrate on prohibited practices, the Annex III and product-safety high-risk categories, and powerful general-purpose models.
Do we have to label AI-generated content?
Providers of systems that generate synthetic audio, image, video or text have to mark that output in a machine-readable format. Deployers have to disclose deep fakes as artificially generated, and disclose that a chatbot is AI unless it is obvious. Published text informing the public is exempt where a person took editorial responsibility for it.
The high-risk rules were delayed. Can we wait?
The prohibitions, the general-purpose model obligations and the transparency duties are already in force. The deferred obligations also carry the longest lead time, because they require documentation, testing and oversight built into how a system is developed.
Is AI literacy still mandatory?
The duty exists and it changed. Since 27 July 2026 it requires taking measures to support the development of AI literacy, rather than ensuring a sufficient level, and it does not require guaranteeing any specific level for an individual.
We use a commercial AI API. Does that make us a provider?
Using an API in your own operations generally makes you a deployer. Building a product on that model and selling it under your own name generally makes you the provider of that product, along with the obligations attached to what your product does.
Does this replace what our own regulator expects?
No. The Act sits alongside sector rules, privacy law and existing liability wherever you operate. The evidence it asks for overlaps heavily with what a sector supervisor asks for. For an example of how one supervisor frames the same questions, see AI governance in financial services.
Where do we start if we have never inventoried our AI?
With the inventory, including tools adopted without approval. Everything else in the Act, and in every questionnaire a large customer sends you, depends on knowing what you run and what it decides.