The European regulation on artificial intelligence progressively governs AI systems, including those already built into your everyday tools (Microsoft 365 Copilot, for example). SYAGA helps you inventory your actual usage, understand the obligations that apply to you, and build an action plan, without jargon and without unverified numerical promises.
A European regulation that already applies, often without the company having noticed
Regulation (EU) 2024/1689 (source: EUR-Lex) governs the governance of artificial intelligence systems within the European Union. Its entry into application takes place in successive tiers depending on the type of obligation concerned.
Artificial intelligence features are already built into office suites widely deployed in companies, such as Microsoft 365 Copilot. Many organizations use them without having formally inventoried this scope.
Between tools provided by vendors, internal developments, and automated agents deployed on existing platforms, the actual scope of AI systems in use is rarely documented centrally.
As with any new regulation, it is better to clarify your exposure early than to discover an obligation during an audit or a request from a client, an insurer, or a partner.
A 5-step support process, calibrated with you according to your actual scope of AI systems
Understand the context, the tools already in place, and ongoing or planned AI projects. Goal: define a realistic scope of analysis, not a theoretical list.
Vendor tools (including AI features already included in your office suites), internal developments, automations, and agents deployed on your existing platforms.
Determine, for each system identified, to what extent you are a provider or a deployer within the meaning of the regulation, and what general obligations arise for your organization.
A structured action plan, prioritized by risk and effort, without any promise of legal outcome: sensitive points are flagged for verification by specialized legal counsel.
Delivery of the mapping file and the action plan, with time for discussion to answer your teams' questions.
Concrete working documents, tailored to your actual scope
Structured inventory of the usages identified during scoping and mapping.
A plain-language document linking each identified system to the major categories of obligations under the regulation.
An operational roadmap for your organization.
The AI Act cannot be analyzed in isolation: it interacts with texts you already know
Reference text on the governance of artificial intelligence systems within the European Union. Source: EUR-Lex.
Whenever an AI system processes personal data, GDPR obligations (Regulation (EU) 2016/679) remain applicable alongside the obligations specific to the AI Act.
Mapping AI usage naturally fits into a broader IT governance approach (security policy, risk management), particularly if your organization is already concerned by NIS2 or an ISO 27001 process.
Features like Copilot introduce AI into tools already used daily. Their use falls within the scope to be mapped, even without a "visible" AI project.
The scope of an AI Act diagnosis varies too much depending on the number and nature of AI systems in use to offer a generic price. We provide a quote after the scoping phase.
Scope established with you from the scoping stage
What the European AI text actually says, digested into plain language. Each point links to its official source (European Commission, EUR-Lex). Information collected on 17/07/2026.
This is a European regulation (the "AI Act", text 2024/1689), published on 12 July 2024 and
already "in force". It sets common rules for artificial intelligence across the whole European
Union, whatever your sector of activity.
official source →
The regulation applies in stages: the prohibitions have been active since 2 February 2025;
the governance rules and the obligations on general-purpose AI since 2 August 2025; most of
the other obligations (including "high-risk" AI) take effect on 2 August 2026.
Note: the Commission proposed on 19 November 2025 to adjust some of these deadlines, so
these dates may still shift slightly.
official source →
The text classifies AI uses into 4 categories: unacceptable risk (prohibited), high
risk (strictly regulated), limited risk (information obligation), and minimal risk - the
vast majority of current uses (for example a spam filter or a video game), which are
not affected by any new rules.
official source →
Certain uses are now outlawed everywhere in Europe: manipulating or deceiving people
through AI, exploiting a person's vulnerabilities, scoring citizens with a "social
score", predicting that a person will commit a crime based on their profile, mass
scraping of photos from the web or CCTV footage to build facial recognition databases,
analysing emotions at work or at school, or using biometrics to infer origin, religion
or orientation.
official source →
Examples cited by the Commission: a tool that screens CVs, that manages access to
credit, or that acts as a safety component in transport. In that case, you must assess
and limit the risks, use quality data, keep activity logs, document the system, clearly
inform users, provide for human oversight, and ensure a good level of robustness and
cybersecurity.
official source →
For prohibited uses: up to 35 million euros or 7% of worldwide turnover (whichever
is higher). For other breaches of the regulation: up to 15 million or 3%. For giving
misleading information to the authorities: up to 7.5 million or 1%. For SMEs and
start-ups, the LOWER of the two amounts applies
(see the sourced detail further below in "The AI Act penalties, in plain terms").
official source →
A "European AI Office" has been created within the European Commission (more than
125 people) to ensure consistent application of the regulation, supported by a board
bringing together a representative from each Member State. Each country must also
designate its own national supervisory authorities.
official source →
The Commission offers a voluntary commitment, the "AI Pact", to get ahead of
compliance before the legal deadlines. More than 230 companies (large groups and SMEs)
have already signed it. These commitments are not legally binding.
official source →
Unlike GDPR or NIS2, the AI Act does not set a simple threshold based on headcount or turnover. What triggers the obligations is your role (provider or deployer) and the risk level of the AI system concerned. Information collected on 18/07/2026, official sources European Commission and EUR-Lex.
The official text is clear: the regulation applies "to both public and private
actors inside and outside the EU, who place an AI system or general-purpose AI model
on the EU market, or put an AI system into service or use it in the EU". In concrete
terms, a company established outside the EU can be affected as soon as the output of
its AI system is intended to be used within the Union.
official source →
Whoever develops the AI system or places it on the market. Example given by the
European Commission: "a developer of a CV-screening tool". Providers of general-purpose
AI models are also covered.
official source →
Whoever uses the system in their professional activity. Example given by the
Commission: "a bank using this screening tool". Strictly personal, non-professional use
is excluded from this definition.
official source →
official source (EUR-Lex) → · official source (Commission FAQ) →
SMEs and start-ups remain within the scope of the regulation, but benefit from
administrative fines proportionate to their size, lighter technical documentation
obligations (the "AI omnibus" agreement), and "regulatory sandboxes" to test their AI
projects under supervised conditions.
official source →
The regulation classifies all uses into 4 risk levels (unacceptable, high, limited,
minimal). It is this level, determined by the nature of the system and its use, that
triggers (or not) obligations, regardless of the headcount or turnover of the
organisation using it.
official source →
Indicative list of the main families of uses that may fall under "high risk", as presented by the European Commission:
No legal jargon: 8 concrete questions, a simple answer, and the official source (European Commission, EUR-Lex) behind each answer.
Click on a question to see the answer and its source.
In the vast majority of cases, no, not by specific obligations. Using an off-the-shelf chatbot or copilot, without integrating it into or turning it into a product, remains outside the core of the regulation as long as it is not a "high-risk" AI system. You do, however, remain a "deployer" of the tool: you must use it in accordance with its instructions for use.
This is an obligation set out in the regulation (Article 4, "AI literacy"), in force since 2 February 2025. The idea: give your teams - those who provide, use or are affected by an AI system - the understanding needed to make informed decisions about these tools. The Commission has published a collection of practices ("living repository") to help companies organise themselves, without imposing a single training format.
Yes, from 2 August 2026 (Article 50 of the regulation). A person interacting with a chatbot must be able to know they are talking to a machine. Content generated by AI (text, image, video) must remain identifiable as such, and "deepfakes" or AI-generated texts published on matters of public interest must be clearly and visibly labelled. A voluntary code of practice on labelling this content was published on 10 June 2026 to guide companies.
Only if you are a provider of a "high-risk" AI system: in that case, registration in a public European database is mandatory. Public authorities deploying a high-risk system must also register, except for critical infrastructure. Everyday use of off-the-shelf AI tools is not covered by this register.
No. The regulation sets 3 tiers of penalties (up to €35M or 7% of worldwide turnover for prohibited practices; €15M or 3% for other breaches; €7.5M or 1% for providing false information to authorities), always applying the higher of the two amounts. For SMEs and start-ups, the rule is reversed: the LOWER amount of each tier applies, never the higher. Full sourced detail in the "AI Act penalties, in plain terms" section.
Yes. The Commission has set up an "AI Act Service Desk" offering an FAQ, a "Compliance Checker" tool to assess your own obligations, an "AI Act Explorer" to navigate the text article by article, and a form to ask a question directly to a team of experts.
Yes, these are typical uses classified as "high-risk" by the regulation. As a deployer, you must in particular assign human oversight carried out by staff who are "sufficiently equipped and empowered", inform your employees BEFORE deploying such a system in their workplace, and inform any person whenever an AI takes part in a decision that concerns them (for example screening an application). The regulation also requires transparency, technical documentation and record-keeping for these uses.
Yes, that is precisely the role of "regulatory sandboxes" and real-world testing provided for by the regulation, designed for SMEs and start-ups. An amendment of 7 May 2026 further widened access to this scheme: more innovators can now access it, including via an EU-level sandbox, and eligibility has been extended to "small mid-caps" (small mid-sized companies).
The European AI regulation does not apply all at once: it rolls out in stages between 2024 and 2028. Here are the dates to remember, what is already active and what is coming, each with its official source. Information collected on 18/07/2026.
The European text on artificial intelligence officially becomes a regulation in
force across the European Union. This is the starting point: all subsequent
deadlines are counted from this date.
official source →
Manipulation of individuals, social scoring, mass facial recognition... the most
dangerous practices are now outlawed everywhere in Europe (detail in the
"regulatory watch" section above). The rules on AI awareness within organisations
also apply from this date.
official source →
The supervisory authorities provided for by the text (including the European AI
Office) are officially in place, and providers of large generative AI models (such
as conversational assistants) must comply with transparency and technical
documentation obligations.
official source →
This is the date that the original text set for its general application (24
months after entry into force): the obligation to inform users when facing AI, and
most "high-risk" AI systems used autonomously. Part of the high-risk scope has
however been postponed in the meantime (see the next two stages).
official source →
On 19 November 2025, the European Commission proposed simplifying and delaying
certain deadlines of the regulation, to allow time for the necessary technical
standards to be ready. The European Parliament and the Council reached a political
agreement on this text on 7 May 2026. Concrete consequence: two "high-risk"
deadlines have been pushed back (the next two stages below). As of this page's
date, this political agreement has not yet been published in its final form in the
Official Journal of the EU.
official source →
New deadline for high-risk AI systems used notably in biometrics, critical
infrastructure, education, employment, or migration/asylum/border control. These
obligations, which were originally due to apply in August 2026, are postponed to
this date to allow time for technical standards to be finalised.
official source →
For AI systems that are safety components in products already regulated
elsewhere (lifts, toys, medical devices...), the deadline was set at August 2027 in
the original text (36 months after entry into force). It is now postponed to this
date.
official source →
The prohibitions and governance rules have been active since 2025; the regulation's general deadline falls in the very next few days (2 August 2026); and two families of high-risk systems (sensitive sectors, regulated products) get an additional delay until the end of 2027 then mid-2028, to allow time for technical standards to be ready.
No panic, no shock figure: here is exactly what the European text says about fines, who imposes them, and since when they actually apply. Each amount is the one written in black and white in Regulation (EU) 2024/1689, articles 99 to 101.
The higher of the two amounts is applied. It covers exclusively the 8 uses prohibited by Article 5: manipulation or deception through AI, exploitation of a person's vulnerabilities, social scoring, predicting a risk of offending based on profiling alone, mass scraping of faces to build a facial recognition database, emotion recognition at work or school, biometric categorisation of protected characteristics, and "real-time" biometric identification by law enforcement in public spaces.
Regulation (EU) 2024/1689, Article 99§3 →This is the tier that most directly affects companies that use an AI tool: obligations of providers (Article 16), authorised representatives (22), importers (23), distributors (24), deployers, i.e. companies using a high-risk AI system (Article 26), notified bodies, and transparency obligations towards users (Article 50 - for example disclosing that a chatbot is AI).
Regulation (EU) 2024/1689, Article 99§4 →Applies when a company provides incorrect, incomplete or misleading information to a notified body or a competent national authority that has made an official request.
Regulation (EU) 2024/1689, Article 99§5 →Explicit rule in the text: for SMEs and start-ups, each fine is capped at the lower of the two terms (percentage or fixed sum), never the higher. In practice, a fine based on a percentage of your actual turnover almost always replaces the multi-million-euro cap designed for multinationals.
Regulation (EU) 2024/1689, Article 99§6 →The text requires the authority to take into account, before setting an amount: the gravity and duration of the breach, the number of people affected, the size and turnover of the company, whether it was intentional or negligent, the degree of cooperation with the authority, and any measures already taken to correct the issue.
Regulation (EU) 2024/1689, Article 99§7 →Each Member State must designate at least one national "market surveillance authority", responsible for enforcing the regulation on its territory. At European level, the European AI Office coordinates the whole. To date, no official source consulted confirms the name of the authority definitively designated for France - so we are not inventing one.
Regulation (EU) 2024/1689, Article 70 →The Article 5 prohibitions (and their fines of up to €35M) have applied since 2 February 2025. The entire penalty regime (Chapter XII, Article 99) has been in application since 2 August 2025. This is therefore not a distant deadline: the fines framework is already active today.
Regulation (EU) 2024/1689, Article 113 →Providers of large general-purpose AI models (the "foundations" behind tools such as AI assistants) fall under a separate regime: it is the European Commission itself that can impose a fine of up to €15M or 3% of their worldwide turnover. This regime targets the model's publisher, not the company using it day-to-day.
Regulation (EU) 2024/1689, Article 101 →The regulation requires each Member State to submit to the Commission every year a report on fines actually imposed. No first edition of this report has been identified to date in the official sources consulted - so we do not cite any concrete case or any amount actually imposed until it is officially published.
Regulation (EU) 2024/1689, Article 99§11 →In Europe, each country has its own authorities. Here, for the 30 countries of the European Economic Area, is the data protection authority (your GDPR contact) and the national cybersecurity authority. Each name links to the official website.
Sources: official websites of the authorities and the EDPB members list (edpb.europa.eu), consulted on 18 July 2026. Data protection authorities confirmed: 30/30. Cybersecurity authorities confirmed: 28/30. The "to confirm" labels indicate an official source not yet stabilised to date.
Write to us for an initial discussion and a personalized quote.
Free: your score + your gaps. The detailed report and the attestation: 499 EUR excl. VAT, only if you decide to.
contact@syaga.eu