In short: The EU AI Act (Regulation (EU) 2024/1689) sorts AI into four risk tiers - prohibited, high-risk, limited, and minimal - and most systems are not high-risk. Under Article 2 it reaches providers and deployers outside the EU where the system’s output is used inside the EU, so a company with no European presence can still be caught. High-risk classification runs through Annex I and III with an Article 6(3) carve-out the organisation must document. The application timeline is phased and being reformed by the Digital Omnibus, so the exact dates must be re-verified before acting. Article 99 penalties reach up to €35m or 7% of worldwide turnover, and the Act runs concurrently with data-protection law under Article 2(7).
The chief executive was blunt about it. “We’re a Johannesburg company. We sell into the EU sometimes, but we have no office there, no subsidiary, not one employee on European soil. Whatever this AI Act is, it is somebody else’s problem.” Around the table, heads nodded. Then the group’s legal counsel slid a single page across the desk. It described the firm’s new recruitment screening tool. That tool ranked candidates, and some of those candidates were being placed into a European subsidiary of a client. The output was landing in the EU. And with that one fact, the CEO’s confident sentence quietly stopped being true.
Four tiers, not one
Start with the structure, because the structure defeats the biggest myth. The EU AI Act, Regulation (EU) 2024/1689, does not declare that all artificial intelligence is dangerous and must be locked down. It sorts systems by risk into four broad bands. At the top sits a small set of prohibited practices under Article 5, such as certain manipulative or social-scoring uses. Below that sits the high-risk category, which carries the heavy compliance obligations. Below that again sits limited risk, where the duty is mainly transparency - telling people they are dealing with a machine. And at the base, the largest band by far, sits minimal risk, where most everyday systems live with essentially no new obligations. If you remember nothing else structurally, remember this: most AI is not high-risk. The Act is targeted, not blanket.
What actually counts as high-risk
The Act points you to two annexes. Annex I covers AI embedded as a safety component in products already regulated under existing EU product law. Annex III lists specific high-stakes use cases - and this is the list that catches most organisations, because it names areas like employment and worker management, access to essential services, and creditworthiness. Here is the part directors routinely miss. Even when a use case appears on the Annex III list, Article 6(3) provides a carve-out: a provider may document that its system does not, in fact, pose a significant risk of harm, and on that basis conclude it is not high-risk. That is not a loophole to be waved through. It is a documented, defensible assessment your organisation owns. The board’s question is never simply “is it on the list?” It is “have we classified this system properly, and can we show our working?”
Why the reach follows the output
Now to the reach, and back to that recruitment tool. The instinct in the room was that a law made in Brussels binds companies established in Brussels. Article 2 tells a different story. The Act extends to providers and deployers established outside the EU where the output produced by the AI system is used in the European Union. Read that slowly. It is not about where your company sits. It is not about where your servers sit. It is about where the output lands. A candidate ranking generated in Johannesburg, relied upon to make a decision inside a European subsidiary, is output used in the EU. So the extraterritorial reach is not an aggressive interpretation - it is the plain effect of the reach provision, and it is exactly why “we have no EU office” is not the safe harbour boards assume it to be.
Reach is a board question, not an IT one
The moment reach depends on where output travels rather than where the company is registered, mapping your exposure stops being a purely technical exercise. Someone has to know which of the organisation’s AI systems produce output that crosses into the EU, whether directly through your own operations or indirectly through clients and subsidiaries. That is a governance question about the organisation’s footprint, and it belongs on the board’s radar, not buried in a systems inventory nobody at the table has read. A director who cannot say whether any of the organisation’s AI output reaches the EU cannot say whether this binding layer applies.
Two definitions you cannot blur
Directors are asked to sign disclosures, and precision protects you. First, what the Act means by an AI system. Article 3(1) defines it as a machine-based system that operates with varying levels of autonomy, that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations or decisions. Notice the word “may” before adaptiveness: adaptiveness is not mandatory, and the distinguishing element is that the system infers how to generate outputs. Second, do not confuse two neighbouring articles. Article 4 imposes the AI-literacy duty on providers and deployers; Article 3(56) is the definition of AI literacy itself. Article 4 is the obligation, Article 3(56) is the meaning. Blur them in a board paper and you have misstated the law.
Timing, honestly
This is the part that is genuinely in motion, and it calls for candour rather than false certainty. The Act’s application is phased - prohibitions, general-purpose AI rules and high-risk rules apply on different dates - and a reform is in progress. The Council of the EU gave its final green light to the Digital Omnibus on AI on 29 June 2026, following European Parliament endorsement on 16 June 2026. Once that reform is in force, it sets new application dates of 2 December 2027 for stand-alone Annex III high-risk systems and 2 August 2028 for product-embedded Annex I high-risk systems. But as at the source unit’s currency date of 22 July 2026, that reform had not yet been published in the Official Journal, and until publication and entry into force, the original 2 August 2026 general application date remained the legal baseline. The correct board briefing is not a single confident deadline: the baseline stands until publication, the deferred dates take over on publication, and this specific fact must be re-verified immediately before anything is acted upon.
Concurrent, not replaced
Be equally precise about what the Act does not do. It does not replace data-protection law. Article 2(7) preserves the application of the General Data Protection Regulation, and the two regimes apply concurrently. The European Data Protection Board adopted Opinion 28/2024 on 17 December 2024, confirming that both frameworks operate in parallel. For a high-risk use case, that can mean you owe both a data-protection impact assessment and a fundamental-rights impact assessment, not one instead of the other. Carry the principle across to your own jurisdiction: wherever you operate, an AI-specific instrument sitting on top of your existing data-protection regime almost never cancels it. It stacks on it.
What the penalties signal
Article 99 sets the penalty tiers, and they are structured to reflect the seriousness of the breach. The most serious tier, for breaches of the prohibited practices, reaches up to thirty-five million euro or seven percent of total worldwide annual turnover, whichever is higher. A middle tier for most other obligation breaches reaches up to fifteen million euro or three percent of worldwide turnover. And a lower tier, for supplying incorrect or misleading information to authorities, reaches up to seven and a half million euro or one percent of turnover. Turnover-based penalties are the tell: they are designed so that the cost of getting this wrong scales with the size of the organisation, which is precisely why this cannot sit below board sight lines.
One caution on enforcement stories
Governance discussions love a dramatic enforcement story, and those stories age badly. It is tempting to point to a large regulator fine as proof of the Act’s teeth - be careful. Enforcement outcomes get appealed, and appeals get won. A widely cited fifteen-million-euro data-protection penalty against a major AI provider was annulled in its entirety by the Court of Rome on 18 March 2026. Taught as a standing precedent, it would simply be wrong. Before any enforcement example enters a board paper as settled fact, verify that it still stands. An overturned penalty presented as live law is exactly the kind of unverified claim that undermines a board’s credibility.
The question worth asking on Monday
The comfortable sentence - “the EU AI Act is somebody else’s problem” - does not survive a single honest question about where your organisation’s AI output actually travels. Reach follows output, not address. The risk tiers reward organisations that classify carefully and punish those that assume. The timeline is moving, so certainty comes from re-verification, not from memory. Walk into your next board meeting and ask one thing: can we say, with evidence, which of our AI systems produce output that reaches the EU, and how each of them is classified? If the honest answer is a shrug, the duty has not yet been discharged.
Can your board map its AI footprint?
The interactive AI Governance Oversight Checklist helps your board test whether it knows where its AI systems operate and how each is classified - the first questions the EU AI Act asks. No email required to start. Enrolment in Celagenix® Academy unlocks the full learning unit this article is drawn from.
Take the free AI Governance Oversight Checklist →Frequently asked questions
It can. Article 2 extends the Act to providers and deployers established outside the EU where the output produced by the AI system is used in the European Union. The trigger is where the output lands, not where the company or its servers are located, so an organisation with no EU office, subsidiary or staff can still be in scope if its AI output is relied upon inside the EU.
No. The Act uses four risk tiers - prohibited practices (Article 5), high-risk, limited risk, and minimal risk - and most everyday systems fall in the minimal-risk band with essentially no new obligations. The Act is targeted rather than blanket.
Through two annexes: Annex I (AI embedded as a safety component in already-regulated products) and Annex III (specific high-stakes use cases such as employment, access to essential services, and creditworthiness). Even for an Annex III use case, Article 6(3) lets a provider document that the system does not pose a significant risk of harm and conclude it is not high-risk - a defensible assessment the organisation must own and evidence.
Application is phased, and a reform (the Digital Omnibus on AI, given final Council approval on 29 June 2026) sets new dates of 2 December 2027 for stand-alone Annex III high-risk systems and 2 August 2028 for product-embedded Annex I systems. As at the source material’s currency date of 22 July 2026 the reform had not been published in the Official Journal, so the original 2 August 2026 general application date remained the baseline. These dates must be re-verified before any action is taken.
Article 99 sets tiered penalties: up to €35 million or 7% of total worldwide annual turnover for prohibited-practice breaches; up to €15 million or 3% for most other obligation breaches; and up to €7.5 million or 1% for supplying incorrect or misleading information to authorities. The turnover-linked structure scales the cost of non-compliance with the size of the organisation.