2026-11-05

🤖🎓 Webinar: make AI your ally for course creation → Save your spot

x

September 3, 2026

EU AI Act: A Complete Guide to European AI Regulation and How to Comply

Cristina Sánchez

CONTENT CREATED BY:

Cristina Sánchez
Digital PR Specialist at isEazy

Table of contents

The EU AI Act (Regulation EU 2024/1689) is the world’s first comprehensive law regulating artificial intelligence. It entered into force in August 2024 and is rolling out its obligations in phases through to 2028. As of today, several are already enforceable: the ban on unacceptable AI practices since February 2025, the AI literacy requirement also since February 2025, and transparency obligations since August 2026. If your organisation uses AI — even occasionally — it already falls within the scope of this regulation.

What is the European AI Regulation (EU AI Act)?

The AI Act establishes a common legal framework for the development, commercialisation and use of artificial intelligence systems in the European Union. Unlike a directive, it is a regulation: it requires no national transposition and has been directly applicable in all EU member states since it entered into force on 1 August 2024.

Its central logic is proportionality to risk: the greater the potential impact of an AI system on people, the stricter the obligations. This translates into a four-tier classification — unacceptable, high, limited and minimal risk — which determines what each organisation must comply with, based on how and why it uses AI.

The AI Act is not designed solely for large tech companies. It applies to any organisation that develops, distributes or simply uses AI systems — from a customer service chatbot to a tool that filters CVs or analyses employee performance. If AI makes or supports decisions affecting people within the European market, the regulation applies, regardless of the company’s size or headquarters.

From an HR and corporate training perspective, the AI Act introduces a particularly relevant obligation: Article 4 requires organisations to ensure AI literacy for all staff working with AI systems. This requirement has not been postponed and has been in force since February 2025.

The EU AI Act (Regulation EU 2024/1689) is the first European regulation to comprehensively govern artificial intelligence systems. It classifies each system by risk level and sets proportionate obligations: absolute prohibitions, technical requirements for high-risk systems, transparency for all, and mandatory AI literacy for any organisation using AI.
Regulation (EU) 2024/1689 — European Parliament and Council, 2024

Risk classification of AI systems

The AI Act groups all artificial intelligence systems into four categories according to the risk they pose to people. This classification determines which obligations apply and when they become enforceable.

Risk levelExamples in a business contextKey obligations
Unacceptable (prohibited)Social scoring, emotion recognition in workplaces or educational settings, real-time biometric identification in public spacesAbsolute prohibition since February 2025. No technical adaptation is possible.
High risk (Annex III)CV screening, AI-based performance evaluation, credit scoring, AI-driven decisions in educationRisk management, data governance, technical documentation, human oversight. Applicable from December 2027 (Digital Omnibus).
Limited riskCustomer service chatbots, AI-generated content, deepfakes in communicationsTransparency obligations (Art. 50): users must be informed when interacting with an AI. Enforceable since August 2026.
Minimal riskSpam filters, content recommendation systems, AI in video gamesNo specific AI Act obligations beyond the general transparency and literacy requirements.

The Digital Omnibus: the most significant regulatory change of 2026

Regulation (EU) 2026/1744, known as the Digital Omnibus, was published in the Official Journal of the EU on 24 July 2026. It introduces a partial but highly significant delay for organisations using AI: the obligations for high-risk AI systems listed in Annex III — covering employment, education, credit and essential services — have been moved from 2 August 2026 to 2 December 2027. Systems listed in Annex I (embedded in regulated products such as medical devices or machinery) have been pushed back to 2 August 2028.

However, the Digital Omnibus did not delay everything. The transparency obligations under Article 50 and the AI literacy requirement under Article 4 remain enforceable from August 2026. Treating the Omnibus as a general pause is the most common misinterpretation — and the one most likely to leave organisations exposed to enforcement action.

Updated EU AI Act Timeline 2024–2028

The AI Act is being applied in stages. This is the current state as of August 2026, incorporating the changes introduced by the Digital Omnibus:

DateWhat comes into force
1 August 2024The AI Act enters into force as a European Regulation. Adaptation period begins.
2 February 2025Ban on unacceptable-risk systems (Art. 5). AI literacy obligation (Art. 4) becomes enforceable for all organisations.
2 August 2025Obligations for general-purpose AI (GPAI) models, such as GPT or Claude. AESIA gains sanctioning powers over prohibited practices.
2 August 2026Transparency obligations (Art. 50): notify users when AI is involved, label AI-generated content. AESIA holds full inspection competencies.
2 December 2027High-risk AI systems listed in Annex III (employment, education, credit). Deadline extended by the Digital Omnibus (previously: August 2026).
2 August 2028High-risk AI systems listed in Annex I (medical devices, machinery). Deadline extended by the Digital Omnibus.

Who does the European AI Regulation affect?

The AI Act does not distinguish by company size or sector. It applies to two main categories of actor:

  • Providers: companies that develop or place AI systems on the market, whether for internal use or for third parties.
  • Deployers: companies that use AI systems developed by third parties in their internal processes. If your organisation uses an AI-powered CRM, an automated recruitment tool, or a virtual assistant, you are a deployer with your own obligations under the regulation.

The regulation also has extraterritorial reach: a company headquartered outside the EU is still subject to the AI Act if its systems are used or have an effect within the European market.

Both AI developers and AI users are covered

A common misconception is that the AI Act only targets large technology companies. It does not. Any organisation that uses AI — even a third-party tool embedded in its standard software — falls within the scope of the regulation. In practice, this includes the majority of mid-sized and large companies operating in Europe today.

Sectors under heightened scrutiny: HR, education, healthcare and beyond

Annex III of the AI Act identifies eight areas where AI use is considered high-risk due to its potential impact on individuals:

  • Employment and HR management: CV screening systems, AI-based performance evaluation, shift allocation, or contract decisions made or supported by AI.
  • Education and training: tools that determine access to programmes or automatically assess students.
  • Financial services: AI-driven credit scoring or insurance assessment.
  • Healthcare: AI-assisted diagnosis, automated triage, clinical decision support.
  • Critical infrastructure, justice, biometrics and migration.

For these sectors, high-risk obligations apply from December 2027 following the Digital Omnibus. However, transparency and literacy requirements are already enforceable now.

To understand the specific risks of AI use in corporate training, this article covers the key blind spots that organisations frequently overlook.

Risks and penalties for non-compliance with the EU AI Act

The AI Act’s penalty regime is one of the most stringent in European regulation — surpassing even the GDPR at its highest tier. Fines are structured across three levels based on the severity of the breach:

Fines, restrictions and reputational damage

  • Up to €35 million or 7% of global annual turnover (whichever is higher): for using prohibited AI systems or breaching the bans under Article 5.
  • Up to €15 million or 3%: for breaching other substantive obligations, including the transparency requirements of Article 50.
  • Up to €7.5 million or 1%: for providing incorrect or misleading information to supervisory authorities.

For SMEs and startups, Article 99(6) provides a proportionality mechanism: the lower of the fixed amount and the turnover percentage applies — not the higher. Even so, for a company with €5 million in revenue, a serious breach could still result in a fine of up to €150,000.

Beyond financial penalties, non-compliance can lead to a market withdrawal order for the AI system in question, restrictions on use, and significant reputational damage at a time when trust in AI has become a key decision criterion for customers and business partners.

In Spain, the authority responsible for supervision and enforcement is AESIA (Agencia Española de Supervisión de la Inteligencia Artificial), based in A Coruña. Since August 2026 it holds full inspection competencies over transparency obligations and can open formal sanctioning proceedings.

For a broader view of how to approach regulatory compliance from a training and organisational perspective, see our article on compliance management.

Training as a key pillar of AI Act compliance

Complying with the AI Act is not solely a legal or technical matter — it has a mandatory training dimension that falls directly within the remit of HR and L&D teams.

Article 4: the AI literacy obligation that is already enforceable

Article 4 of the AI Act requires both providers and deployers to ensure a sufficient level of AI literacy among their staff and any third parties operating AI systems on their behalf. This obligation has been in force since 2 February 2025 and was not postponed by the Digital Omnibus.

The regulation does not prescribe a specific certification or minimum number of hours, but it does require that training be proportionate to each employee’s role and the risk level of the AI system they use. According to European Commission data, 78% of companies still do not have a documented AI literacy plan in place.

AESIA can request evidence of the training programme in the context of an inspection. A record that includes participants, content, dates and completion evidence is the minimum recommended documentation.

New competencies required by the regulation

Article 4 literacy training is not a prompt engineering workshop. It aims to ensure that employees understand what an AI system can and cannot do, what risks it introduces, what biases it may carry, and what it means to use it responsibly in each specific context. A compliant AI literacy programme should cover:

  • Fundamentals of how AI systems work and their limitations.
  • Risk classification: recognising whether a system falls under the AI Act’s categories.
  • Ethics and algorithmic bias: identifying situations involving discrimination or lack of fairness.
  • Transparency and rights: informing people when they are interacting with AI.
  • Human oversight: knowing when and how to escalate a decision that should not be left to the system.
  • Data protection and alignment with the GDPR.
  • AI incident reporting.

Ethics, transparency and responsible AI use

Beyond strict compliance, the regulation encourages organisations to build a culture where AI is used ethically and responsibly. This means embedding concepts such as algorithmic fairness, data governance and the traceability of automated decisions into training programmes.

Organisations that treat AI literacy as a strategic investment — rather than a compliance checkbox — reduce operational incidents, improve the quality of AI-assisted decisions, and build a genuine competitive advantage in a market that increasingly rewards technological trust. For a broader view of how generative AI is reshaping corporate learning, see our article on generative AI: what it is, how it works, and how to use it responsibly.

Recommended training levels by employee profile

Article 4 requires proportionality: not all employees need the same depth of training. This table provides a starting point for structuring your AI literacy plan:

ProfileRecommended training levelKey content areas
Basic user (any employee who uses AI tools)Essential AI literacyWhat AI is, its limitations, basic biases, when not to trust the output, individual rights.
Middle manager / decision-makerAdvanced AI literacyRisk classification, human oversight, algorithmic ethics, how to document AI-assisted decisions.
HR / L&D professionalAI Act and HR specialisationHigh-risk AI in employment, Art. 4 and the training plan, Art. 50 and transparency, GDPR alignment, AESIA.
AI system administrator / internal AI providerTechnical specialisationTechnical documentation, risk management (Art. 9), data governance (Art. 10), EU database registration.

Four steps to prepare your organisation for the EU AI Act

Complying with the AI Act is entirely manageable if approached in the right order. These are the four steps recommended by the European Commission and AESIA as a starting point:

  1. Inventory all AI systems in use. Include those embedded in third-party tools such as ERP, ATS, training platforms or CRMs. Many organisations use AI without explicitly identifying it as such.
  2. Classify each system by AI Act risk level. Determine whether it falls into the prohibited, high-risk, limited or minimal risk category. This defines which obligations apply and when.
  3. Address the immediate obligations: transparency and AI literacy. Art. 50 (notifying users when AI is involved) and Art. 4 (a documented training plan) are already enforceable. These are the most urgent priority for most organisations.
  4. Build a role-based training plan and document it. Segment training by employee profile and the AI systems each group uses. Keep records of participants, content, dates and completion for potential inspection by AESIA.

In parallel, organisations using high-risk AI systems have until December 2027 to bring their risk management, data governance and technical documentation processes into compliance. The extension is not a pause — it is time to get it right.

Prepare your team for the new AI regulatory framework with isEazy Skills

AI Act compliance does not start in the legal department — it starts with training. Article 4 places L&D teams at the centre of regulatory compliance, and the isEazy Skills catalogue includes content specifically designed to meet this obligation.

Pepco, a retail company present in more than 20 European countries, is an example of an organisation that invested in AI training as a cultural transformation lever before the regulation became fully enforceable. Working with isEazy, they built a scalable digital training programme for thousands of employees across multiple countries.
Find out how they did it →

CASE STUDY

How Pepco was able to comprehensively manage employee training with an LMS

See case study

Content aligned with the EU AI Act — training that means business

The isEazy Skills AI Academy offers a course catalogue covering artificial intelligence, digital responsibility, technology ethics and algorithmic bias prevention — designed to address the competency areas that Article 4 of the AI Act identifies as necessary. Content is kept up to date with the current regulatory framework and can be assigned by employee profile, making it straightforward to meet the proportionality requirement the regulation demands.

Practical, flexible training for every profile in your organisation

isEazy Skills combines microlearning, social learning and gamification to achieve high completion rates, even in environments with high turnover or geographically dispersed teams. Courses are available in multiple languages, accessible on any device, and generate activity records that can be used as documentary evidence in an AESIA inspection.

From regulatory obligation to competitive advantage

Organisations that approach AI literacy as a strategic investment — not just a compliance requirement — are building teams that are better equipped to use AI safely and responsibly. In a market where trust in AI is increasingly a supplier and partner selection criterion, training becomes a genuine competitive differentiator. With isEazy Skills, EU AI Act compliance can also be the foundation for a culture of responsible innovation.

Conclusion: The EU AI Act is present reality, not a future concern

The European AI regulation is not a threat on the horizon — it is a framework already in force. As of today, the prohibitions are active, the AI literacy obligation has been enforceable for over a year, and transparency requirements have applied since August 2026. The Digital Omnibus has given organisations more time for high-risk systems, but it has not paused a single obligation that was already in effect.

For HR and L&D teams, this means that AI Act compliance runs substantially through training. A documented AI literacy plan, segmented by employee profile and aligned with the risk level of the systems each team uses, is today the first line of defence against a potential AESIA inspection — and the foundation for the organisation to use AI with judgement and responsibility.

Organisations that act early will not just avoid penalties: they will be better positioned to capture the opportunities AI offers in a regulated environment. AI Act compliance can be the starting point for a culture of responsible innovation that, over the medium term, becomes a genuine competitive advantage.

If you want to know where to begin, isEazy can help you design the AI training plan your organisation needs to comply with Article 4 and prepare your teams for the new regulatory landscape. Request an isEazy Skills demo →

Frequently asked questions about the EU AI Act

What is the EU AI Act and when does it apply?

The EU AI Act (Regulation EU 2024/1689) is the world’s first comprehensive legal framework for artificial intelligence. It entered into force on 1 August 2024, with obligations phasing in gradually: prohibitions from February 2025, rules for general-purpose AI models from August 2025, and transparency and AI literacy requirements from August 2026. As a European regulation — not a directive — it requires no national transposition and applies directly in all EU member states.

Which companies does the European AI regulation affect?

The AI Act applies to any company that develops or uses AI systems within the European market, regardless of size or headquarters location. It also has extraterritorial reach: companies based outside the EU are still subject to it if their AI systems affect the European market. Two main categories are covered: providers (those who develop or place AI on the market) and deployers (those who use third-party AI in their internal processes). If your company uses an AI-powered applicant tracking system, a chatbot, or any automated decision-making tool, you are likely a deployer with your own obligations under the regulation.

What is the Digital Omnibus and what did it postpone?

The Digital Omnibus (Regulation EU 2026/1744), published in the Official Journal of the EU on 24 July 2026, introduced a significant but partial delay for certain AI obligations. Specifically, it postponed the requirements for high-risk AI systems listed in Annex III — which includes systems used in employment, education, credit, and essential services — from 2 August 2026 to 2 December 2027. Systems in Annex I (integrated into regulated products such as medical devices or machinery) were pushed back to 2 August 2028. However, the Digital Omnibus did not delay the transparency obligations under Article 50 or the AI literacy requirements under Article 4, both of which have been enforceable since August 2026.

What does Article 4 of the EU AI Act require for AI training?

Article 4 of the AI Act requires both providers and deployers to ensure a sufficient level of AI literacy among their staff and any third parties operating AI systems on their behalf. This obligation has been in force since 2 February 2025 and was not postponed by the Digital Omnibus. The regulation does not mandate a specific certification or minimum number of training hours, but training must be proportionate to each employee’s role and the risk level of the AI system they use — a generic company-wide course does not meet the standard. Critically, the programme must be documented, as the relevant national authority (in Spain, AESIA) can request evidence of AI literacy plans during an inspection.

What are the penalties for non-compliance with the EU AI Act?

The AI Act’s penalty regime is among the strictest in European regulation — exceeding even the GDPR at its upper end. Fines are structured across three tiers based on the severity of the breach. Using prohibited AI systems or violating the bans under Article 5 can result in fines of up to €35 million or 7% of global annual turnover (whichever is higher). Breaches of other substantive obligations — including Article 50 transparency requirements — can reach €15 million or 3%. Providing incorrect or misleading information to supervisory authorities carries fines of up to €7.5 million or 1%. For SMEs and startups, Article 99(6) provides proportionality: the lower of the fixed amount and the turnover percentage applies. In Spain, the competent authority is AESIA.

What is AESIA and what role does it play in AI Act enforcement?

AESIA (Agencia Española de Supervisión de la Inteligencia Artificial — the Spanish Agency for the Supervision of Artificial Intelligence), established by Royal Decree 729/2023 and headquartered in A Coruña, Spain, is the national authority designated to supervise and enforce the AI Act in Spain. It has held sanctioning powers over prohibited practices since August 2025, and as of August 2026 it has full inspection competencies covering transparency and AI literacy obligations. If a company fails to comply, AESIA can open investigation procedures and ultimately impose the fines set out in the Regulation. Companies operating in Spain should treat AESIA as the primary regulatory contact for AI compliance matters.