Blog

    EU AI Act: The Complete Guide for 2026

    AI Regulation Compliance Procurement
    EU AI Act: The Complete Guide for 2026

    Artificial intelligence is now regulated in the European Union. The EU AI Act is the first comprehensive AI law, with eight categories of AI systems already banned since February 2025. It applies to organisations that build, deploy, import, or distribute AI systems reaching EU users, regardless of physical presence in the European Union. This guide explains the four risk tiers, the fines, the deadlines, and what compliance actually involves.

    Aug 2026

    1. What is the EU AI Act? What is its Scope in 2026?

    EU AI Act Summary

    The EU AI Act is the world’s first regulation governing the development and use of artificial intelligence in the European Union. It is also called the Artificial Intelligence Act. It establishes a risk-based AI classification system, applying different rules to AI systems according to the 4 types of risk they pose. The act bans certain unacceptable risk AI use cases and implements strict governance, risk management and transparency requirements for others. The regulation has extraterritorial reach. Any non-EU company is in scope if its AI systems or outputs involve EU users.

    Who does the EU AI Act apply to?

    • Providers: Organizations or people developing or placing an AI system or general-purpose AI (GPAI) models on the EU market, irrespective of where they are located
    • Deployers: Organizations or people using AI systems in the EU in a professional capacity
    • Importers of AI systems
    • Distributors of AI systems

    Key Exemptions: The regulation does not apply to AI systems used and developed for:

    Yes. The EU AI Act has extraterritorial reach. A physical presence in EU does not matter. It governs the EU market and any non-EU companies, including US companies whose AI systems or outputs touch EU users is in scope.

    Example: A US employer uses an AI tool to recruit or assess candidates in the EU. It is potentially covered, even without an EU legal entity.

    JAGGAER AI

    JAI is a Source-to-Pay AI which combines ISO 42001-certified governance with GDPR-aligned EU data residency.

    2. The 4 Risk Categories

    These are 4 defined risk categories for AI systems under the act as per EU Artificial Intelligence Act. Not sure which tier your system falls into? Our complete guide to EU AI Act risk levels walks through each one with real examples. Each tier determines the compliance obligations that apply.

    Compliance Obligations

    High-risk AI systems have the most detailed compliance obligations under the act. Organizations deploying high-risk AI systems must comply with the following obligations:

    3. Fines and Penalties

    The EU AI Act fines and penalties for various violations as per EU Artificial Intelligence Act are listed below. Want to know if you are exposed? Run through our EU AI Act compliance and fines checklist.

    ViolationWho it applies toMaximum fine
    Prohibited AI practices (Article 5)Companies / operators€35M or 7% of global annual turnover, whichever is higher
    Other obligation breaches (providers, deployers, importers, distributors, authorised reps, notified bodies, transparency)Companies / operators€15M or 3% of global annual turnover, whichever is higher
    Incorrect, incomplete, or misleading information to authoritiesCompanies / operators€7.5M or 1% of global annual turnover, whichever is higher
    Any breach (Article 5 or other)SMEs and startupsThe lower of the percentage or fixed amount
    GPAI model provider violations (Article 101)General-purpose AI model providers€15M or 3% of global annual turnover, whichever is higher
    Prohibited AI practices (Article 5)EU institutions, bodies, agencies€1.5M
    Other breachesEU institutions, bodies, agencies€750,000

    4. EU AI Act Timeline: Key Dates Through 2026 and Beyond

    Deadlines are arriving fast. The EU AI Act effective date was 1 August 2024, with obligations rolling out in phases through 2027 as per European Commission AI Act. Map your obligations against the full compliance timeline so nothing catches you off guard.

    1st August 2024 ✓ In Force

    The EU AI Act came into force.

    2nd February 2025 ✓ Active
    • Prohibitions on certain AI systems and regulatory requirements came into effect
    2nd August 2025 ✓ Active
    • Rules for general-purpose AI (GPAI) models, governance, confidentiality and penalties came into effect

    EU AI Act obligations for general-purpose AI models

    2nd August 2026 ↗ Approaching
    • Remaining rules under the act including high-risk AI system obligations and transparency rules will come into effect
    • Member States should have established at least one AI regulatory sandbox at national level
    2nd August 2027 Upcoming
    • Rules for AI systems that are products or safety components of products regulated under Article 6(1) of act will apply
    • Providers of GPAI models that were placed on the market before 2 August 2025 must comply with rules for GPAI models by this date

    JAGGAER AI

    JAGGAER’s AI is embedded across sourcing, contracts, and supplier management in one Source-to-Pay platform.

    5. EU AI Act vs. GDPR: How They Interact?

    GDPR and the EU AI Act are complementary, not competing. Both take a risk-based approach, but they are built on different objectives.

    GDPR Data & Privacy


    GDPR focuses on protecting personal data and individual privacy across the EU. The act applies to any organisation collecting and/or processing personal data related to EU citizens, regardless of where the organisation is based.

    EU AI Act AI Systems


    EU AI Act regulates the development and deployment of AI systems. The act addresses the design, use and governance of AI technologies by introducing a risk-based framework.

    Where they overlap?

    ThemeGDPREU AI Act
    Fundamental Rights & Data Protection Impact assessmentA data protection impact assessment for high-risk processing (Article 35)A fundamental rights impact assessment before the first deployment (Article 27)
    Transparency to peopleInforming data subjects about collection and use of personal data and automated decision making (Article 13, 14, 15(1)(h))Deployers should inform people using high risk AI systems (Article 26(11))
    Human oversightData subjects have the right not to be subject to automated decisions (Article 22)High-risk systems designed and developed for human oversight (Article 14)
    TraceabilityControllers and Processors required to maintain records of processing activities (Article 30)Providers of high-risk AI systems to maintain technical documentation and automatic logging (Article 11,12, 26(6))
    SecurityControllers and Processors to take technical and organizational measures to ensure security (Article 32)Providers must ensure robustness, accuracy, and cybersecurity of high-risk AI systems (Article 15(5))
    Special-category dataProcessing personal data is prohibited unless an exception applies (Article 9)Processing personal data permitted only where strictly necessary for bias monitoring, detection and correction in high-risk AI (Art. 10(5))

    6. What do US Companies Need to Know in 2026?

    The act has extraterritorial reach. U.S. companies providing AI systems to users in the European Union are in the scope of the act. The physical presence of the US company does not matter. See how the act affects US companies in practice. Non-compliance can trigger fines up to €35 million or 7% of global annual turnover.

    For US companies, the main ways the EU AI Act would apply to them is if they:

    01

    Provide AI systems or General-Purpose AI models in the EU, irrespective of a physical presence in EU

    02

    Deploy AI systems from a location within the EU

    03

    Import or distribute AI systems within the EU

    JAGGAER

    A JAGGAER guide on how agentic AI operates across procurement workflows

    7. Frequently Asked Questions

    The EU AI Act is the world’s first law regulating development and use of artificial intelligence. It governs AI systems used in the European Union according to four risk tiers.

    The EU AI Act entered into force on 1 August 2024. Its rules apply in phases, and most obligations will take effect on 2 August 2026.

    The EU AI Act applies to providers, deployers, importers, and distributors of AI systems, including companies based outside the EU when their AI system’s output is used within the Union.

    Yes. The EU AI Act applies to US companies that place AI systems on the EU market, or whose AI outputs are used in the EU.

    The EU AI Act bans AI posing unacceptable risk, including social scoring, manipulative techniques, untargeted facial-image scraping, emotion recognition in workplaces and schools, and most real-time public biometric identification.

    EU AI Act high risk AI systems are those used in sensitive areas like employment, education, essential services, law enforcement, migration, and critical infrastructure.

    The EU AI Act imposes fines up to 35 million euros or 7% of global turnover for banned practices, and up to 15 million euros or 3% for other violations.

    GDPR governs personal data and privacy, while the EU AI Act regulates AI systems by risk level.

    A general-purpose AI model under the EU AI Act is an AI model capable of performing many distinct tasks and being integrated into multiple downstream systems.

    Yes, ChatGPT and models like GPT-5 are general-purpose AI models under the EU AI Act. The most capable models are classed as GPAI with systemic risk, triggering extra obligations.

    Next Steps

    This guide covers the EU AI Act end to end. The five articles below go deeper on the topics that matter most to your situation. Whether you are assessing applicability, mapping risk, calculating exposure, or preparing for a specific deadline, each of the areas have a dedicated guide with the detail this overview cannot fit.

    Find out whether the act applies to your company, what triggers compliance obligations, and what you need to do next.

    Read More

    Learn what each risk tier means and which obligations apply to each level.

    Read More

    Learn which violations trigger which penalties and how enforcement works.

    Read More

    Learn what qualifies as a GPAI model, which obligations apply, and what systemic risk means for your organisation.

    The EU AI Act applies in phases. This guide covers every key compliance deadline with dates and what each means.

    Read More

    Talk to a procurement expert.

    Tell us your challenge. We will show you exactly where JAGGAER One fits into your current setup — with specifics, not a generic demo.

    • Direct or indirect?
      We handle both — on one platform.
    • Already have an ERP?
      JAGGAER Link connects to 1,000+ systems, no rip-and-replace.
    • Need to show ROI fast?
      We define outcomes and KPIs before you sign.
    • Vertical-specific?
      Manufacturing, higher ed, public sector — configured, not customized.

    Related Articles

    Copyright © 2026 JAGGAER – All Rights Reserved

    JAGGAER and the JAGGAER logo are registered trademarks of JAGGAER, LLC. All other registered trademarks, trademarks, and service marks are the property of their respective owners.