Foxnut Studios

Definition

The EU AI Act for operators

What the EU AI Act asks of companies running AI in Europe, date by date, read as operator practice from a studio working in Paris and Bengaluru. Description and method, not legal advice.

Reviewed by Ameya Sahasrabudhe and Swati Thakur,

What the EU AI Act is, and who it reaches

The EU AI Act - Regulation (EU) 2024/1689 - is the European Union’s law governing AI systems, and EU AI Act compliance turns on two questions: which role a company plays under the Act (provider, deployer, importer, distributor), and which risk tier the system falls into. Its reach does not stop at Europe’s border. Under Article 2, the Act applies to providers placing AI systems on the EU market irrespective of where they are established, and to providers and deployers in third countries whenever the system’s output is used in the Union. A company entering the European market with AI inside its product, or running AI on work for European customers, can be in scope without ever opening an office there.

This page holds the Act the way an operator entering Europe needs to hold it: what already applies, what changed in July 2026, and which questions to take into the market. It describes; it does not advise. What the law requires of a specific company is a question for licensed counsel in the target market, which is the boundary the AI consulting territory at Foxnut Studios keeps on every regulatory subject, in Europe and everywhere else the studio builds.

Most of the Act’s early dates have already passed

The Act entered into force on 1 August 2024 and applies in phases, and an operator reading about it in 2026 is reading about a law already partly in application. The bans on certain AI practices and the AI literacy obligation have applied since 2 February 2025. The obligations on providers of general-purpose AI models, and the Act’s governance machinery, have applied since 2 August 2025. The Act’s general application date - the default for everything not given its own date, including the transparency obligations described below - is 2 August 2026, days away as this page is written. Every date, with the article it comes from and a source per row, sits in the dated milestone table for the Act; this page carries the structure, that one carries the numbers.

What changed in July 2026

The timeline most published guides still describe is no longer the timeline. On 8 July 2026 the EU adopted Regulation (EU) 2026/1744, the “Digital Omnibus on AI”, which entered into force on 27 July 2026 and moved the high-risk application dates: rules for systems in the Act’s listed high-risk areas - biometrics, critical infrastructure, education, employment, migration and border control among them - now apply from 2 December 2027, and rules for AI embedded in regulated products such as lifts or toys apply from 2 August 2028. The stated reason is the delayed availability of harmonised standards and national authorities. The practical consequence for an operator is blunt: any AI Act summary written before mid-2026 is out of date on exactly the dates that matter most, and worth re-checking against the amending regulation before it informs a plan.

The Act sorts systems into tiers, and the tier decides the obligation

The Act is not one set of rules; it is several, sorted by what the system does. The table below lays out the tiers and where each one stands after the July 2026 amendment - it is the shape of the whole law in five rows.

TierWhat it coversWhere it stands today
Prohibited practicesAI uses the EU has banned outrightIn application since 2 February 2025
High-risk, listed areasSystems used in areas listed by the Act: biometrics, critical infrastructure, education, employment, migration and othersApply from 2 December 2027, as amended in July 2026
High-risk, product-embeddedAI as a safety component of products under EU product law, such as machinery, lifts and toysApply from 2 August 2028, as amended in July 2026
Transparency obligationsSystems that interact directly with people must disclose it; synthetic audio, image, video and text must be marked machine-readably as generatedUnder the Act’s general application date of 2 August 2026
General-purpose AI modelsObligations on the providers of the models themselvesIn application since 2 August 2025; from 2 August 2026 the Commission can fine model providers up to 3% of worldwide turnover or EUR 15 million, whichever is higher

Two of these rows touch most operators long before any high-risk assessment does. The transparency row reaches any company whose product talks to users or generates content for them. And the general-purpose model row sits underneath every company building on someone else’s model: the obligations rest on the model’s provider, but a buyer’s product inherits the model it is built on, which makes “which model, from whom, documented how” a commercial question and not only a technical one.

The questions an operator entering the EU should be able to answer

An operator does not need to hold the whole regulation; it needs to be able to answer five questions about its own system, because every conversation with counsel, customers or procurement starts from them. Which role does the company occupy for this system - provider, deployer, importer or distributor - given that the same company can occupy different roles for different systems? Which tier does the system sit in, and is that an assessment or an assumption? Which dates govern that tier after the July 2026 amendment? What documentation exists today about how the system was built, tested and changed - the material every tier’s obligations draw on? And who supplies the answers the company cannot produce alone - which counsel in which member state, engaged when? These are understanding questions, not compliance steps; the answers are what make the eventual legal work fast instead of exploratory.

The fourth question is the one operators underestimate, and it connects this page to a neighbouring territory: the record of how an AI system was built, evaluated and changed is the same artefact set a good handover produces, so a system documented well enough to hand over is a system documented well enough to explain.

How Foxnut Studios reads the Act, as an operator

Foxnut Studios works from Paris and Bengaluru and builds AI systems into clients’ commercial operations, so the Act is not an abstraction to the studio; it is the regulatory weather over half of its own footprint, arriving on dates it can read in the Official Journal like everyone else. What the studio can say first-hand about operating under it is the part only the founders can supply, and this page will not invent it. The founders’ answer starts before the Act. The studio held itself to high documentation and compliance standards already, for an operational reason: working with dozens of clients at a time has meant hundreds of deployed projects functioning today without the studio’s involvement, and every tool eventually needs maintenance, upgrades and small edits. The time those take is inversely proportional to the discipline with which the decisions, frameworks and data flows were documented during the build - and the same discipline is what keeps the work future-proof against new legislation, this Act included, rather than blindsided by it.

On disclosure, the studio practises radical transparency, because it wants to be on the same team as its clients: essentially everything is disclosed, with one exception - proprietary algorithms, agentic systems and assets the studio developed and owns the IP to, whose inner workings stay closed. Even for those, the client receives detailed documentation of how the system works in their business context and how it complies with every regulation of the day. And on counsel: questions answered before are not re-sent; every genuinely new question goes through the studio’s own counsel first, so what gets built is built the right way.

What the page can already say is where the line sits. The studio’s market-entry work treats regulation as operator practice: understanding which questions the Act raises for a commercial plan, and sequencing them, is commercial work; determining what the law requires of a specific company is legal work, and belongs with licensed professionals in the target market. An operator who arrives in Europe holding the five questions above, with documentation in hand, buys less of the second kind of work - which is the most useful thing a description like this one can do.

Sources

  1. Regulation (EU) 2024/1689 (the AI Act), full text on EUR-Lex: Article 2 scope, Article 50 transparency, Article 101 fines, Article 113 application dates Retrieved
  2. Regulation (EU) 2026/1744 (Digital Omnibus on AI), amending the AI Act's high-risk application dates, on EUR-Lex Retrieved
  3. European Commission: AI Act policy page, application timeline as amended Retrieved

Foxnut Studios works on briefs like this one from Bengaluru and Paris. If you want the shape of that before you talk to anyone, here is how an AI engagement is scoped and priced.