The European AI Act is the world's first regulatory framework dedicated to artificial intelligence. It concerns any organization using an AI tool in Europe — including third-party SaaS software. Themio identifies your obligations and structures your compliance, without an in-house lawyer.
The AI Act — also called AIA (Artificial Intelligence Act) or Regulation (EU) 2024/1689 — is the European legislation that governs the development and use of artificial intelligence systems within the European Union. Published in August 2024, it is the world's first comprehensive regulatory framework dedicated to AI.
Its goal is twofold: to ensure trustworthy AI that respects fundamental rights and privacy — while preserving space for innovation. By legislating first, Europe is taking a global strategic lead on this issue.
The regulation applies to any organisation that develops OR uses an artificial intelligence system in Europe. Under the official definition, an AI system is any automated system designed to generate predictions, recommendations, decisions, or content that influence real or virtual environments.
In practice: a SaaS software with an AI feature falls under the regulation as soon as it influences a decision or automates a workflow — even if you didn't write a single line of code.
| Provider | Deployer |
|---|---|
| Develops or places an AI system on the market | Uses an AI system developed by a third party |
| E.g.: vendor of an automated HR scoring tool | E.g.: SME using that tool to recruit |
| Maximum obligations — documentation, compliance, registration | Verification, monitoring, and transparency obligations |
| Few SMEs in this category | The vast majority of SMEs are deployers |
Important note: If your SME uses a CRM with AI scoring, an automated recruitment tool, or a decisional chatbot, you are a deployer — and you have obligations. To audit and map these undeclared AI usages across your teams, check our deep-dive on Shadow AI in SMEs .
AI systems presenting unacceptable risks have been strictly banned since 2 February 2025. They are incompatible with European fundamental rights.
Specifically banned:
This is the most impactful level for SMEs and mid-caps. It covers use cases already deployed in many business functions. The regulation identifies 8 high-risk areas ( Annex III of the Regulation ):
| Domain | Concrete example for an SME |
|---|---|
| Recruitment & HR | Automated resume screening, candidate scoring |
| Credit & Insurance | Financial scoring or creditworthiness evaluation |
| Healthcare | Automated medical diagnostic support |
| Education | Automated student grading or evaluation |
| Critical Infrastructure | Automated energy or transport network management |
| Justice | Judicial decision support tools |
| Law Enforcement | Automated surveillance systems |
| Migration | Automated border control systems |
Good news for SMEs: the Omnibus extends SME simplifications to small mid-caps (< 750 employees, < €150M turnover), with streamlined documentation templates and priority access to regulatory sandboxes.
These systems do not present major structural risks, but must adhere to transparency requirements. Users must be informed that they are interacting with an AI.
Examples:
The majority of general-purpose AI applications fall into this category. They are not subject to any specific regulatory obligations under the AI Act, although the GDPR and other regulations may still apply.
Examples:
| Date | Obligation | Status |
|---|---|---|
| August 2024 | Publication of the regulation in the Official Journal of the EU |
In effect
|
| February 2025 | Prohibition of unacceptable risk systems (Level 1) |
In effect
|
| August 2025 | Obligations for General Purpose AI models (GPAI) |
In effect
|
| 27 July 2026 | Digital AI Omnibus formally adopted — entered into force |
In effect
|
| 2 August 2026 | Article 50 transparency obligations (AI-generated content labeling, chatbot disclosure) — not postponed |
In effect
|
| Dec. 2, 2027 | Mandatory compliance for high-risk systems Annex III (HR, credit, education...) |
Confirmed — postponed
|
| Aug. 2, 2028 | Full application — high-risk systems Annex I (medical devices, machinery...) |
Confirmed — postponed
|
The Digital AI Omnibus is now law. Formally adopted by Parliament (16 June 2026) and the Council (29 June 2026), signed 8 July 2026, and in force since 27 July 2026, it confirms the postponed deadlines: 2 December 2027 for standalone high-risk systems (Annex III), and 2 August 2028 for high-risk AI embedded in regulated products (Annex I). Note: Article 50 transparency obligations were not postponed and have applied since 2 August 2026. The obligations have not disappeared — only the calendar changed. This is still the right window to start your compliance before deadline pressure returns. Themio determines your risk level in a few minutes.
The AI Act imposes a structured compliance process: classifying your systems, documenting your obligations, and producing evidence for the regulator. Themio transforms this process into an automated workflow. For a step-by-step roadmap, explore our 5-step compliance guide and our 2026 compliance tools benchmark .
Themio determines the risk level of each AI system you use or deploy — via a deterministic rules engine, not a guessing chatbot. Result: Unacceptable, High, Limited, or Minimal, with an article-by-article explanation.
Once your risk level is established, Themio lists the precise obligations that apply to you — based on your role (provider or deployer), your sector, and your systems. No generic lists. Your obligations, linked to the applicable article.
Risk management plans, AI governance policies, system registers, transparency notices — generated automatically and ready to present to your regulator or investors.
Methodological guides, regulatory breakdowns, and software benchmarks to navigate European AI compliance step-by-step.
Inventory, risk classification, staff literacy, technical documentation, and continuous monitoring.
National regulator coordination, Article 4 AI literacy duties, and SME relief mechanisms.
Comprehensive benchmark comparing SaaS compliance platforms, law firms, and manual spreadsheets.
How unapproved employee AI usage triggers deployer liabilities under the European AI Act.
Test your conversational chatbots, assistants, and generated media to verify whether your user disclosures satisfy mandatory Article 50 requirements.
Themio classifies your AI systems, maps your obligations article by article,
and generates your governance documents — without an internal legal team or costly consultants.
🔒 EU Hosting · Data not shared · No commitment