Insights · July 7, 2026
By Mason Hughes
The EU Artificial Intelligence Act is the world's first comprehensive binding law for AI systems. It entered into force in 2024, and its most significant deadline landed August 2, 2026, when most of its rules became enforceable. It was modeled after GDPR, and it carries the same intention: set a global standard, and apply it far beyond companies actually headquartered in the EU.
The scope is broader than most owners assume, and that's deliberate. The Act applies to providers and deployers outside the EU wherever an AI system's output is used within the EU, not just marketed or targeted there. A US company with no EU office can still be in scope the moment its AI-driven output reaches an EU-based client through any chain, direct or indirect. Company size doesn't exempt anyone: the Act defines small-business treatment as proportionate enforcement, not an exemption from the underlying obligation.
Four. Prohibited practices are banned outright (things like social scoring and manipulative AI). High-risk covers AI making consequential decisions about people, hiring, credit, education. Limited-risk covers chatbots and AI-generated content, mainly a disclosure requirement. Minimal-risk, where most day-to-day business automation sits today, carries the lightest obligations.
A provider builds an AI system for others to use, the model companies themselves. A deployer uses that system in their own business. Every business running AI tools day to day is a deployer, and deployers carry lighter obligations than providers, mainly around oversight, data quality, and log retention for higher-risk uses.
Penalties run in three tiers: up to €35 million or 7% of global turnover for prohibited practices, €15 million or 3% for high-risk violations, and €7.5 million or 1% for misleading information, whichever figure is higher. For a small business the real risk usually isn't the fine itself, it's the disruption of a regulatory inquiry into AI use with no documentation behind it.
Yes. ISO 42001 covers an estimated 70 to 80 percent of the Act's high-risk governance requirements, and organizations already aligned to it tend to reach compliance meaningfully faster than starting from a blank page. MAIDEN's own systems are already built aligned to ISO 42001 for exactly this reason - see our plain-language explainer on the standard itself for what it actually requires.
20 Questions · 5 Minutes
45 Minutes · Free