AI Governance and the EU AI Act: What Changes With the New Rules

AI Governance and the EU AI Act: What Changes With the New Rules

For years, artificial intelligence grew faster than the rules meant to govern it. With the EU AI Act, Europe decided to change that, giving the world its first major legal framework for AI. To make it clearer, think of it as the traffic code for artificial intelligence: it doesn’t ban driving, but it sets who can do what, and with what caution, depending on how risky the road is. At H-FARM College we follow this shift closely, because it changes how companies work and use AI, and it opens entirely new careers. In this article we’ll look together at what the EU AI Act is, which dates matter, what it means for companies, and which jobs are emerging around AI governance.

What the EU AI Act is and why it is a turning point

Before diving into the deadlines and obligations of the regulation, it helps to understand what the EU AI Act really is and the logic it rests on.

The world’s first legal framework for artificial intelligence

The EU AI Act is the first comprehensive law dedicated to artificial intelligence, in force since 2024 with a phased rollout in the following years. It doesn’t target a single technology like large language models, but concerns every AI system used in Europe, aiming to make them safe, transparent, and respectful of people’s rights.

The risk-based approach: the four categories

The heart of the Act is risk. What does that mean? To understand it, let’s start here: systems are split into four categories. Unacceptable risk covers banned uses. High risk, for example in healthcare or hiring, carries strict obligations. Limited risk brings transparency duties. Minimal risk stays essentially free. The more a system can affect people, the more rules it must follow.

Risk categoryExamplesObligations
Unacceptable riskBanned uses (e.g. social scoring)Full ban
High riskHealthcare, hiringStrict obligations
Limited riskChatbots, generated contentTransparency duties
Minimal riskSpam filters, video gamesNo specific obligations

The dates that matter: what applies and when

As we mentioned, the EU AI Act applies gradually, spread across several years. Here are the main milestones to keep in mind.

The transparency obligations from 2 August 2026

From 2 August 2026, the transparency obligations under Article 50 apply, such as clearly flagging when content is generated by AI. It is one of the steps that directly touches anyone thinking about the future of work and AI, and it is also one of the most debated points of recent times.

High-risk systems and the 2027-2028 postponement

The heavier obligations, those for high-risk systems, were postponed by the Digital Omnibus adopted in mid-2026. High-risk systems listed in Annex III apply from 2 December 2027, and those embedded in already-regulated products (Annex I) from 2 August 2028. The regulation’s architecture stays the same, only some deadlines moved, so it is always worth checking official sources before making decisions. Here is a summary table:

DateWhat applies
1 August 2024The EU AI Act enters into force
2 August 2026Transparency obligations (Article 50)
2 December 2027High-risk systems (Annex III)
2 August 2028High-risk embedded in products (Annex I)

What it means for companies, tech and non-tech

The EU AI Act doesn’t only concern big tech. This regulation concerns anyone who develops, distributes, or uses AI systems with effects in Europe, and that includes small businesses and non-EU companies too. A bank using AI to assess loans, a company filtering résumés, a hospital adopting diagnostic tools: all need to understand which risk category they fall into.

The penalties are not symbolic. Prohibited practices can be fined up to €35 million or 7% of global annual turnover, while other breaches are capped at €15 million or 3% of turnover. That is why understanding which risk category you fall into is also a budget decision.

AI governance: from principles to practice

This is where AI governance comes in, the set of rules, processes, and responsibilities through which an organization decides how to use artificial intelligence in a compliant and trustworthy way. It is not only a legal matter: it means documenting systems, assessing their risks, ensuring data quality and human oversight. It is the bridge between what technology can do and what it is right and lawful to let it do.

Building the skills to govern AI

At H-FARM College, supporting students in learning about and using artificial intelligence means preparing them to understand its implications, responsibilities and opportunities. That is why AI is integrated into our study programmes not only as a technology, but also as a tool to be understood and governed responsibly. Our goal is to prepare professionals who can navigate the intersection of technology, business and ethics, understanding how to use AI responsibly and how to turn its potential into value for organisations and society.

The new careers in AI governance

Around these rules, a new generation of roles is emerging: the AI Governance Specialist, the AI Compliance Manager, the Responsible AI Lead. These are hybrid profiles that combine technical, legal, and business skills, able to talk to developers and management alike. Demand is set to grow as the regulation’s deadlines approach, and we at H-FARM College are ready to support you.

Studying AI and business at H-FARM College

At H-FARM College, in fact, we believe the future of AI plays out exactly on this border between technology, business, and responsibility. In the Master’s in AI for Business Transformation, for example, the Business Strategy with AI module deals directly with governance, compliance and the ethical management of AI, while in the Bachelor’s Degree in AI & Data Science the AI & Ethics module builds exactly the skills roles like the AI Governance Analyst require, one of the program’s career outcomes. Both award a University of Chichester degree and combine theory with real projects alongside partner companies.

At H-FARM College, students can round out their study plan with the enhancing courses, extracurricular courses designed to build cross-disciplinary, distinctive skills: among them, the Ethics of AI course lets students explore the ethical implications and responsibilities tied to the use of artificial intelligence.

Want to find out which path is right for you? Join the next Open Day.

ai act cos'è
regolamento europeo intelligenza artificiale
ai governance
ai act

FAQ

frequently asked questions about the EU AI Act

What is the EU AI Act? open accordion Close

The EU AI Act is the world’s first comprehensive law on artificial intelligence, in force since 2024 with a phased rollout in the following years. It classifies AI systems by risk and sets different obligations for each category, from banned systems to high-risk ones down to minimal-risk uses.

What changes in 2026? open accordion Close

From 2 August 2026 the transparency obligations under Article 50 apply, for example flagging when content is AI-generated. The heavier obligations for high-risk systems were postponed by the Digital Omnibus: Annex III systems apply from 2 December 2027 and Annex I from 2 August 2028. Dates can change, so always check official sources.

Does the AI Act only concern big tech companies? open accordion Close

No. It concerns anyone who develops, distributes or uses AI systems that have effects in the EU, including small and non-EU companies. That is why demand is growing for people who can manage AI compliance and governance.

Which jobs are emerging around AI governance? open accordion Close

Roles like AI Governance Specialist, AI Compliance Manager and Responsible AI Lead, which combine technical, legal and business skills to make sure AI is used in a compliant and trustworthy way.

What are the penalties under the EU AI Act? open accordion Close

For prohibited practices, fines reach up to €35 million or 7% of the company’s global annual turnover. For other breaches, such as failing to meet high-risk obligations, the cap is €15 million or 3% of turnover.

Does the EU AI Act apply to companies outside the European Union? open accordion Close

Yes. It applies to anyone who places on the market or uses AI systems that have effects in the EU, even if the company is based elsewhere. What matters is where the system is used, not only where its provider is located.

Apri menu