EU AI Act 2026: what French companies really need to know (timeline, obligations, penalties)

AI Act 2026: the real timeline after the Digital Omnibus, risk levels, concrete obligations, and penalties. A clear guide for mid-market executives and CIOs.
Published on
13.08.2026
EU AI Act 2026: what French companies really need to know (timeline, obligations, penalties)

Introduction

The AI Act (EU Regulation 2024/1689) is often described as "the GDPR of artificial intelligence" — and for good reason. Like the GDPR before it, it generates real anxiety among executives: an unclear timeline, legal jargon, fear of penalties, and news that's still evolving (the "Digital Omnibus" reshaped part of the timeline in the first half of 2026).

This guide lays things out clearly, without alarmism: who's affected, what already applies, what's been postponed, and above all, what a mid-sized company needs to do concretely, starting now.

The AI Act in one sentence

The AI Act classifies every AI system used by a company according to its level of risk, and imposes obligations proportionate to that risk — from an outright ban for the most dangerous uses, to no constraint at all for the most harmless ones.

The key point to remember: the AI Act doesn't apply to a company as a whole, but to each AI system based on how it's used. The same company can therefore have tools with no particular constraints and a tool subject to heavy obligations, depending on what that tool is used for.

The 4 risk levels

  1. Unacceptable risk — uses banned since February 2025: social scoring, behavioral manipulation, certain surveillance biometrics uses.
  2. High risk — uses listed in Annex III of the regulation: recruitment, credit scoring, education, certain HR uses, biometrics. Heavy obligations around documentation, human oversight, and traceability.
  3. Limited risk — chatbots, generative AI, synthetic content: the main obligation is to inform the user they're interacting with an AI.
  4. Minimal risk — the majority of everyday enterprise uses, with no specific constraints.

For a typical mid-sized company, the uses to watch most closely are often CV-screening tools, customer scoring, or employee evaluation tools — which can potentially fall into the "high risk" category.

The real timeline after the Digital Omnibus

The AI Act's original timeline was partially revised in 2026 by a text called the "Digital Omnibus," which postpones certain deadlines considered too close by part of Europe's economic and political actors. Here is the state of the timeline as it stands based on the latest announcements:

August 1, 2024 — The regulation enters into force.

February 2, 2025 — Bans on unacceptable-risk uses, plus a general "AI literacy" obligation (training staff on the responsible use of AI).

August 2, 2025 — Obligations applicable to general-purpose AI (GPAI) models.

August 2, 2026 — Transparency obligations (Article 50): informing users that they are interacting with an AI or with AI-generated content.

December 2, 2027 — Most obligations for high-risk systems under Annex III (postponed from the original August 2026 deadline).

August 2, 2028 — Obligations for AI systems embedded in certain regulated products, Annex I (postponed from the original August 2027 deadline).

A note of caution: at the time of writing, certain formal validation steps for the Digital Omnibus (notably publication in the EU's Official Journal) are still being finalized. The dates above reflect the most recent political agreement, but we recommend confirming them officially before making any binding decision.

What's already mandatory today

Contrary to a common assumption, the AI Act isn't just a distant deadline: two obligations are already in force for any company using AI in Europe.

  • The ban on unacceptable-risk uses, in force since February 2025.
  • The "AI literacy" obligation: training staff on responsible, informed use of artificial intelligence, regardless of company size.

These two points, often overlooked because they receive little media coverage, already expose companies that haven't put anything in place.

Concrete obligations for high-risk systems

For companies using or developing a system classified as "high risk," the obligations typically cover:

  • A mapping of AI uses across the company, to precisely identify which tools are affected and at what risk level.
  • Formalized internal governance: who approves the use of an AI tool, who oversees automated decisions, who can intervene in case of error.
  • Compliance documentation demonstrating control over the system (data used, tests carried out, known limitations).
  • Effective human oversight over decisions with a major impact on the people concerned (recruitment, credit, evaluation).

Who is actually affected?

Any company using AI in Europe is affected, at minimum, by the staff training obligation. Beyond that, the regulation distinguishes between several roles:

  • The provider, who develops an AI system.
  • The deployer, who uses an AI system developed by a third party as part of its activity — this is the role the vast majority of French mid-sized companies fall under, since they use AI tools rather than build them.

Understanding your status as a "deployer" is often the first clarification to make, even before asking which specific obligations apply.

The penalties at stake

The regulation sets out a multi-tiered penalty regime depending on the severity of the breach, which can reach a high amount calculated on the company's global revenue for the most serious breaches (banned uses). The exact amounts vary depending on the source and the latest political discussions; what matters at this stage for a mid-sized company isn't the precise figure but the principle: failing to comply with the AI Act isn't a mere administrative formality, but a genuine financial and reputational risk, following the same pattern as GDPR.

Where to concretely start

  1. Map existing AI uses across the company — including informal uses that haven't been officially approved ("shadow AI"), which the regulation doesn't treat any differently from official uses.
  2. Classify the risk level of each use identified.
  3. Train teams on the responsible use of AI — this is already a mandatory obligation.
  4. Put in place clear governance for upcoming AI projects, particularly those touching recruitment, evaluation, or customer relations.

This is exactly the scoping logic that should precede any AI agent deployment in the enterprise: compliance isn't bolted on afterward, it's built into the initial scoping workshop.

FAQ

Is an SME with fewer than 50 employees affected by the AI Act?

Yes. The regulation doesn't set a headcount threshold as a general exemption criterion — it's how AI is used that determines the obligations, not the size of the company.

Is using a consumer-grade generative AI tool (writing, images) enough to be considered "at risk"?

Most of these uses fall under limited risk, with the main obligation being to inform the user they're interacting with AI-generated content. The risk becomes higher when the tool is used to make a decision that impacts a person (recruitment, credit, evaluation).

Does the Digital Omnibus mean the AI Act as a whole has been pushed back?

No. Only certain deadlines related to high-risk systems have been shifted; the bans and the staff training obligation have remained in force since 2025, and the 2026 transparency obligations still stand.

Do you need a dedicated DPO or lawyer to be compliant?

Not necessarily a dedicated role for a mid-sized company, but one person clearly identified as responsible for internal AI governance, working alongside external support if needed.

Take action

AI Act compliance isn't just a legal matter: it's also an opportunity to reset governance over all of a company's AI uses, both formal and informal. At Qolaig, our scoping workshop systematically builds in this dimension from the very first conversation, so that every AI agent deployed is compliant by design rather than brought into compliance after the fact. Let's talk about your project.

Jonathan Yana
Jonathan Yana
CEO @ Qolaig

Let's discuss your first AI assistant: audit + ROI estimation in 30 minutes

Let's discuss your AI project
Blog

Our latest articles

How to Calculate the ROI of an AI Agent: the complete method (formula, examples, metrics)

How to Calculate the ROI of an AI Agent: the complete method (formula, examples, metrics)

How do you calculate the ROI of an AI agent in the enterprise? Formula, worked example, metrics to track, and mistakes to avoid. The complete Qolaig guide.
Read article
AI Agents in the Enterprise: the complete 2026 guide (definition, use cases, ROI, methodology)

AI Agents in the Enterprise: the complete 2026 guide (definition, use cases, ROI, methodology)

What is an AI agent in the enterprise? Definition, use cases by sector, ROI calculation, deployment methodology. The reference guide by Qolaig.
Read article
Tech Events in Paris 2026-2027: the complete calendar for IT and AI decision-makers

Tech Events in Paris 2026-2027: the complete calendar for IT and AI decision-makers

Discover the calendar of must-attend tech events in Paris from September 2026 to August 2027: AI, data, cybersecurity, blockchain.
Read article