alt
Lihi Lutan April 15, 2026

What Is the EU AI Act? Compliance Beyond the Deadline

Post image

The EU AI Act is no longer theoretical. A Belgian retailer has already paid €4.2 million for misclassifying a biometric AI system. Germany and France have opened investigations into recruitment and credit-scoring AI. And on August 2, 2026, the EU AI Office gains full penalty enforcement powers. For most companies, the question is no longer “what is the EU AI Act?” It is “which of our vendors deploy AI, and who carries the liability?”

The regulation lands its heaviest weight not on the labs that build AI but on the companies that deploy it inside the software they buy. If your HR platform screens candidates with a model, if your CLM extracts clauses with one, if your finance tool flags anomalies with one, you are a deployer under the law. That obligation is now landing in boardrooms, audit committees, and procurement departments across every industry with European exposure.
Lihi Lutan, Co-Founder and CEO, Opstream
By Lihi Lutan, Co-Founder and CEO, Opstream
Co-Founder and CEO of Opstream, previously COO of StokeTalent (acq. Fiverr) and VP Operations at Taboola where she helped scale the company from $8M to $1B in revenue.
View LinkedIn profile →

Key takeaways

  The Digital Omnibus is now law. High-risk AI obligations are deferred to December 2027, but transparency enforcement begins August 2, 2026.
  Enforcement is real: Belgium issued a €4.2 million fine, and Germany and France have opened formal investigations into AI vendors.
  The real compliance gap is not legal interpretation. It is the inability to inventory AI across your vendor stack at scale.
  Customers and M&A acquirers are running AI vendor diligence on their own clock, regardless of what Brussels decides.
  Procurement is the natural home for AI vendor governance because the data already flows through it.

What is the EU AI Act, and why does it matter now?

The EU AI Act is a risk-based rulebook that puts legal weight on every company using AI inside the EU, not just the labs that build it. Brussels passed it in 2024 as Regulation (EU) 2024/1689 and sorts AI systems into four buckets: prohibited, high-risk, limited-risk and minimal-risk. The rules tighten as the risk goes up. (For the full schedule, see the official implementation timeline, noting that the Digital Omnibus adopted in July 2026 has since amended several key dates.) Most coverage is written by lawyers for other lawyers, which misses the point for an operator. The regulation matters because it assigns direct responsibility to the buyer of AI, not just the seller. General counsel cannot solve it alone. Neither can the CISO or the head of procurement. The obligations cut horizontally across functions, which pushes the problem into the C-suite by default. A second pressure lands alongside the regulation. Customers, acquirers and insurers are running their own AI vendor diligence today, regardless of what Brussels does next.

What happened in July 2026, and what is about to change?

The past 90 days turned the EU AI Act from a future compliance exercise into an active enforcement regime. The Digital Omnibus is now law. The European Parliament approved the package on June 16, 2026. The Council adopted it on June 29. It entered into force in July 2026. The Omnibus defers high-risk AI obligations for Annex III systems (employment screening, credit scoring, and most enterprise-relevant categories) from August 2, 2026 to December 2, 2027. Annex I systems (product-regulated AI) move to August 2, 2028. A new “small mid-cap” category (under 750 employees, under €150M turnover) qualifies for simplified documentation requirements. Chatbot disclosure is already enforceable. Since July 10, 2026, any AI chatbot or virtual assistant interacting with EU users must disclose that the user is talking to an AI. This applies to every vendor in your stack that ships a conversational interface. August 2, 2026 is not quiet. Even with the high-risk deferral, three major obligations land on that date:
Article 50 transparency obligations become fully enforceable: synthetic content marking, deepfake labeling, AI-generated content disclosure.
The EU AI Office gains full penalty enforcement powers over general-purpose AI (GPAI) model providers, with fines up to €15 million or 3% of worldwide turnover.
Supply chain transparency breaches now carry first-tier fines: 3% of turnover or €15 million for failing to disclose AI components to downstream deployers.
Enforcement is real. National authorities have moved from guidance to action:
Country Case Outcome
Belgium Retailer deployed facial-recognition warehouse entry systems, misclassified as “non-AI” access control €4.2 million fine
Germany Federal Network Agency investigating recruitment AI vendor for systematic candidate disadvantage Investigation open
France Major bank’s AI credit scoring model under examination for Article 13 transparency failures Under examination
The Belgian case is instructive. The company did not deploy a rogue system. It deployed a standard access-control product and classified it incorrectly. That classification error cost €4.2 million. The lesson: the risk is not in malicious intent. It is in not knowing what your vendors are actually running under the hood.

What does the EU AI Act actually require of deployers under Article 26?

Article 26 is the part of the law that lands on you. It defines a deployer as any organization that puts an AI system to use under its own authority, which describes every company running AI-powered SaaS. The European Commission’s AI Act Service Desk spells out the core obligations.
  1. Use the system as instructed. Read the provider’s instructions, follow them and document that you did. Off-label use shifts liability onto you.
  2. Assign competent human oversight. A trained person with the authority to intervene must be watching the system. “Our admin clicks approve” is not a defense.
  3. Manage input data. When you control what goes in, you are responsible for its quality and relevance.
  4. Keep logs for six months minimum. Most SaaS contracts do not give you log export rights by default. Read yours.
  5. Notify affected people. If a high-risk system makes or assists a decision about a person, you have to tell that person. In the workplace, that includes workers and their representatives.
  6. Report serious incidents to the provider and, where required, to the national competent authority within 15 days.
None of these obligations disappeared because Brussels deferred the enforcement date. The spec your vendor stack has to meet is the same whether you act now or in 2027.

What are the EU AI Act transparency requirements?

Article 50 transparency obligations become enforceable on August 2, 2026, and they apply regardless of risk classification. Three requirements land immediately on any company deploying AI with EU exposure:
AI chatbot disclosure: Any system that interacts with people must inform them they are communicating with AI, not a human. Already enforceable since July 10, 2026.
Synthetic content marking: AI-generated text, audio, image or video must be machine-readably marked as artificially generated. Systems already on the market have until December 2, 2026 to comply.
Deepfake labeling: Content that depicts existing persons or events in ways that appear authentic must be clearly labeled as AI-generated or manipulated.
For procurement teams, the transparency requirements create a new question for every vendor review: does this product generate content or interact with end users? If yes, is the vendor compliant with Article 50? The GPAI Code of Practice, published in July 2025, adds a voluntary but closely watched framework. Providers who do not adopt it face heightened scrutiny from the AI Office. Procurement teams should be asking vendors whether they have adopted the Code of Practice and requesting documentation of their transparency measures.

Why is your vendor inventory the real EU AI Act compliance gap?

You cannot govern what you cannot see, and almost no enterprise can map its AI vendor footprint clearly today. This is the actual compliance gap, and it has nothing to do with the legal text. In the past 18 months, half the average SaaS stack has quietly added AI features without much fanfare. The CLM now extracts clauses with a model. The spend analytics tool predicts anomalies. The background check provider scores risk. The support platform writes draft replies. Each is a deployer obligation waiting to land on a compliance officer’s desk, and none of them show up in the existing vendor risk register. The information is buried in documents that already exist. Vendor MSAs, DPAs and AI addenda describe what the system does and how it processes data. The problem is that those documents are 60 to 200 pages long, written by lawyers, and scattered across SharePoint, email, a CLM and the CISO’s laptop. Reading them at scale is not a job a procurement team can do with spreadsheets.
Ask a procurement leader “which of your 180 vendors deploy AI, and in what categories?” and the answer is usually silence. Not because they are negligent. Because the answer requires a project that does not fit anyone’s job description.
The European Commission anticipated this problem. The updated Model Contractual Clauses for AI procurement (MCC-AI), available in 24 EU languages, provide standard contract language for both high-risk and non-high-risk AI. They specify exactly what documentation a vendor must supply: conformity assessments, technical documentation, model cards, safety specs, log access provisions, and incident reporting timelines. Procurement teams that adopt these clauses now will close the documentation gap before enforcement catches up.

How do enterprise buyers and acquirers force the issue regardless of Brussels?

Even if the EU AI Act vanished tomorrow, the question has to be answered for two other audiences who are not waiting. The first is enterprise customers. Companies selling into financial services, healthcare, government or any large European employer are now receiving an “AI vendor questionnaire” alongside the usual security review. Banks in Frankfurt and insurers in Paris are not asking out of curiosity. They are asking because their compliance teams need to document the AI exposure inside their vendor stack. Failing the questionnaire kills the deal. The second is the diligence team on the other side of any M&A or fundraise. AI vendor inventories are now showing up in the IT and data sections of due diligence checklists from every serious acquirer. A company that cannot answer “how is AI used in your stack and what are your deployer obligations” inside the data room has a finding. Findings depress valuations and derail timelines. Set the regulator clock aside for a moment. The customer clock and the M&A clock are real, and they are running today.

What is the EU AI Act compliance checklist for deployers?

Here is a 10-step checklist built from Article 26 deployer obligations, the EC’s Model Contractual Clauses (MCC-AI), and the lessons from the first enforcement cases. Procurement, legal and compliance should own this jointly.
  1. Map every vendor’s AI features. Pull your active vendor list. For each, answer: does it use AI, in what category, and what data does it touch? Where contracts are silent, send a direct question to your account contact.
  2. Classify each by EU AI Act risk tier. Apply the four-tier framework: prohibited, high-risk (Annex III), limited-risk, minimal-risk. Focus your compliance work on the small set that touches HR decisions, credit, biometrics, or access to services.
  3. Collect conformity documentation from high-risk vendors. Request CE marking status, conformity assessment results, technical documentation, and known limitations. Use the EC’s MCC-AI clauses as your template.
  4. Add AI governance clauses to all new contracts. At minimum: AI use disclosure, permitted data uses, audit rights, breach notification within 24 to 48 hours, and incident reporting obligations.
  5. Designate human oversight owners. For each high-risk system, assign a named person with the competence, training and authority to monitor outputs, override decisions, and report malfunctions. This cannot be a checkbox; it must be a real person with real authority.
  6. Confirm six-month log retention rights. Check your SaaS contracts for log export and retention clauses. Most standard contracts do not include them. Add them.
  7. Update vendor questionnaires with AI-specific questions. Add: does the product use AI or ML? What data trains the model? Can the deployer access logs? What is the incident notification timeline? Has the vendor adopted the GPAI Code of Practice?
  8. Establish incident reporting protocol. Define the internal process for reporting serious AI incidents to the vendor and (where required) to the national competent authority within 15 days.
  9. Notify workers before deploying workplace AI. This is a pre-implementation obligation. If the AI system makes or assists decisions about employees, notify them and their representatives before deployment, not after.
  10. Stand up quarterly AI vendor review cadence. Annual reviews are no longer sufficient. Regulators under DORA are already citing annual-only vendor risk updates as a visibility gap. Build a quarterly review cycle into your governance calendar.
None of this requires a new hire. It does require a place to centralize the answers, and that is where most teams stall out.

Free download

EU AI Act Deployer Compliance Checklist

The full 10-step checklist as a branded PDF. Includes phased action plan, risk classification table, enforcement cases, and penalty breakdown.

What should your team do in the next 90 days?

Skip the legal-checklist approach you will read everywhere else. Start with two operational moves. First, build an AI vendor inventory in 30 days. Not perfect, just real. Pull every active vendor from your contract repository and answer three questions for each: does it use AI, what category, and what data does it touch? Where the contract is silent, send a one-question email to your account contact. Track responses in whatever tool your team already uses. Second, classify the inventory by deployer risk using the EU AI Act's four-tier framework. Most vendors will land in limited or minimal risk and need little more than transparency notices. Focus on the small set that touch HR decisions, credit decisions, biometric data or access to services. Those carry material Article 26 exposure. Then, in parallel:
Action Owner Timeline
Add AI governance clauses and MCC-AI language to all new vendor contracts Legal + Procurement Next 30 days
Update vendor questionnaire to capture AI use, training data, log access and GPAI Code of Practice adherence Procurement + Security Next 30 days
Assign a named owner for each high-risk vendor's human oversight Executive sponsor Next 60 days
Confirm log retention rights and incident notification clauses in all contracts Legal Next 60 days
Stand up a quarterly AI vendor review cadence Executive + General Counsel Next 90 days

How does Opstream close the AI vendor governance gap?

Full disclosure on the bias. Procurement is the natural home for vendor governance, and the vendor inventory your team already maintains is 80% of the answer to the EU AI Act problem. Opstream was built to close the other 20%. The hardest part of compliance is not the regulation. It is reading every vendor's MSA, DPA and AI addendum to figure out how the product actually uses AI. Opstream's AI Document Comparison handles that step automatically. Upload a vendor's contracts and the system extracts AI-use disclosures, training-data clauses, log retention terms and incident notification language against a configurable playbook. A full day of paralegal work becomes a one-click report that drops into the AI vendor inventory the same morning. Every vendor onboarding and renewal then runs through the same orchestrated workflow, so the inventory updates itself. That is what it means to orchestrate vendor risk rather than chase it. The EU AI Act compliance checklist above maps directly to Opstream's workflow engine. Vendor questionnaires capture AI-specific disclosures at intake. Approval workflows route high-risk vendors through legal and security review automatically. Attributes track risk classification, oversight assignments, log retention status and review cadence across every vendor record. And when the next regulatory update lands, the framework adapts without rebuilding your process.

See how Opstream handles AI vendor governance →

Frequently asked questions

What is the EU AI Act in simple terms?

The EU AI Act is the European Union's risk-based law for artificial intelligence. It classifies AI systems by risk, bans the most harmful uses, and places legal obligations on both the companies that build AI and the ones that deploy it. It applies to any organization with EU exposure, regardless of where they are headquartered.

Who is a "deployer" under the EU AI Act?

A deployer is any organization that uses an AI system under its own authority for a professional purpose. If your business uses an AI-powered SaaS product, you are a deployer, even if you did not build the underlying model. Article 26 sets out the obligations that apply to deployers of high-risk AI systems.

Has the EU AI Act been delayed?

Partially. The Digital Omnibus, formally adopted in July 2026 (European Parliament June 16, Council June 29), defers high-risk AI obligations for Annex III systems to December 2, 2027 and for Annex I systems to August 2, 2028. However, GPAI provider obligations (in force since August 2025), transparency requirements, and the AI Office's enforcement powers all proceed on the original August 2, 2026 timeline.

What are the penalties for EU AI Act non-compliance?

Penalties for prohibited AI practices reach €35 million or 7% of global annual turnover. Most other violations carry fines up to €15 million or 3%. Supply chain transparency breaches carry the same €15 million ceiling. Belgium has already issued a €4.2 million fine to a retailer for misclassifying a biometric AI system, demonstrating that enforcement is active.

How do I know which of my SaaS vendors use AI?

Start with your contract repository, not your application catalog. Every vendor MSA, DPA and AI addendum signed in the past 24 months should describe whether and how the product uses AI. For vendors with no clear contract language, send a one-question email to your account manager. Opstream's AI Document Comparison can extract these disclosures from vendor contracts automatically, reducing weeks of manual review to minutes.

What are the EU AI Act transparency requirements?

Article 50 requires three types of disclosure, all enforceable from August 2, 2026: AI chatbot identification (users must know they are interacting with AI), synthetic content marking (AI-generated content must be machine-readably labeled), and deepfake labeling (AI-manipulated depictions of real people or events must be clearly disclosed). Chatbot disclosure has been enforceable since July 10, 2026.

What is the EU AI Act compliance checklist for deployers?

A deployer compliance checklist covers 10 areas: (1) map every vendor's AI features, (2) classify by risk tier, (3) collect conformity documentation from high-risk vendors, (4) add AI governance clauses to contracts, (5) designate human oversight owners, (6) confirm six-month log retention rights, (7) update vendor questionnaires with AI-specific questions, (8) establish incident reporting protocol, (9) notify workers before deploying workplace AI, and (10) stand up quarterly AI vendor review cadence. The EC's Model Contractual Clauses for AI (MCC-AI) provide standard language for items 3, 4 and 6.

About the author

Lihi Lutan, Co-Founder and CEO, Opstream
Lihi Lutan, Co-Founder and CEO, Opstream

Lihi Lutan is the Co-Founder and CEO of Opstream, changing the way companies buy.

Throughout her career, Lihi built and scaled business operations at startups and large corporations. Early in her career, Lihi was with Cyota (acq. RSA Security) as a team leader and project manager before moving to Thomson Reuters and Fundtech to manage global projects. Later, Lihi joined Taboola (NSDQ: TBLA) as employee 15, as VP Professional Services and Operations, leading the department as the company scaled from $8M to $1B in revenue. Transitioning from Taboola to StokeTalent (acq. Fiverr), Lihi served as the company's COO.

Lihi holds an LLB of Law and BSc of Computer Science from Tel Aviv University.

Connect with Lihi on LinkedIn →

Want to see how it works?

Book a demo with our team or reach out at support@opstream.ai