The EU AI Act also covers Turkey-based firms supplying products or services to Europe. Its timeline changed in 2026, and that change is easy to misread.
01. Scope
The Act regulates AI systems used in the EU market. Where the provider is established isn't decisive; if the system is used in the EU, it's in scope.
02. Risk Tiers
Systems are split into prohibited, high-risk, limited-risk and minimal-risk. The weight of obligations follows that classification. Most enterprise productivity tools land in the lower tiers.
03. The Timeline Moved
Regulation published in 2026 deferred compliance for standalone high-risk systems to December 2027, and for AI embedded in products to August 2028. Deferral is not cancellation; the preparation window got longer.
04. What Wasn't Deferred
Transparency duties and the labelling of AI-generated content, along with the rules for general-purpose model providers, stayed on schedule. The prohibited-practices regime is also in force.
05. High-Risk Examples
Systems used in recruitment, candidate selection, performance evaluation, task allocation and promotion or termination decisions count as high-risk. Firms using AI in HR should not skip this heading.
06. What to Do
Draw up your inventory and classify each system. For anything landing in high risk, plan documentation, human oversight and record-keeping now; the deferred date is preparation time, not relief.