Cosmic Brokkoli
Published
The AI Act already applies. High-risk rules arrive in 2027 and 2028 — Nexus Business is ready for both

From 20 September 2026 the EU AI Act management module is available in Nexus Business.
The message is not that every deployer duty already bites today. It is sharper than that. AI literacy and prohibited-practice governance are already mandatory. Transparency rules and enforcement have applied since 2 August 2026. And organisations now have a concrete window to prepare for the principal high-risk obligations that arrive on 2 December 2027 and 2 August 2028. That is the readiness problem the module is built for.
Most organisations still cannot answer three questions in the same meeting: which AI systems do we actually deploy, who is allowed to use them and who oversees them, and where is the evidence. A policy PDF answers none of the three. Nexus Business answers them as a control system: registered AI systems with a named owner; a classification wizard that records why a use was judged prohibited, high-risk, limited-risk or minimal-risk; a catalogue of the SaaS tools staff have already switched on; a high-risk register; FRIA records; transparency notices; incident logs; human-oversight procedures; explanation requests; literacy assignments; supplier and model catalogues; reminders; and a dossier you can export — with evidence linked to the Drive and QMS documents you already keep.
A short reminder of what the Act is, because it is still discussed as if it only concerned model builders. Regulation (EU) 2024/1689, as amended, classifies uses on a risk pyramid: prohibited practices, high-risk systems, limited-risk uses that carry transparency duties, and minimal-risk uses that still sit inside an organisation which must not drift into a banned pattern by accident. Most organisations buying this module are not placing a medical device or a recruitment engine on the Union market. They are employers, service companies and public bodies that buy software, embed models and let staff use tools. That is the deployer role — and it is already inside the Act, even where some high-risk obligations still sit behind transitional periods.
The duties that already affect organisations are concrete. Article 4 requires providers and deployers to take measures to ensure a sufficient level of AI literacy among the people dealing with AI systems on their behalf, taking account of their knowledge, experience, training and the context in which the systems are used. Article 5 requires organisations to ensure that their uses do not fall within prohibited AI practices. Since 2 August 2026, Article 50 also imposes transparency obligations for certain AI systems and AI-generated or manipulated content — with chatbot disclosure primarily a provider duty for systems that interact directly with people, and specific deployer duties for deepfakes, emotion recognition or biometric categorisation, and certain AI-generated text published on matters of public interest.
Additional duties apply to deployers of high-risk AI systems under Articles 26 and 27, including appropriate use of the system, human oversight by people with the necessary competence, training and authority, monitoring, logging and, for bodies governed by public law, private entities providing public services and certain Annex III use cases, a fundamental-rights impact assessment. Where a deployer identifies a serious incident, Article 26 requires it to inform the provider and the relevant market surveillance authorities without delay; the formal reporting channel under Article 73 sits primarily with the provider. Under the revised implementation timetable introduced by the 2026 simplification amendments, however, the main high-risk rules for Annex III systems apply from 2 December 2027 and those for Annex I systems from 2 August 2028. Preparing the inventory, responsibilities, evidence and governance processes before those dates is therefore part of compliance readiness — not evidence that every high-risk obligation is already legally applicable today.
The timeline is no longer theoretical. The Act entered into force on 1 August 2024. Prohibited AI practices and the AI literacy obligation have applied since 2 February 2025, while governance rules and obligations for providers of general-purpose AI models started applying on 2 August 2025. From 2 August 2026, the AI Act became generally applicable and important transparency obligations under Article 50 entered into force, together with the enforcement powers of the competent authorities. The transition is not complete, however. Following the revised implementation timetable, the principal rules for high-risk AI systems listed in Annex III will apply from 2 December 2027, while those concerning high-risk AI systems embedded in products covered by Annex I will apply from 2 August 2028. Organisations operating in September 2026 are therefore already inside the AI Act framework, while some of the most extensive high-risk-system obligations remain subject to transitional periods.
Which brings us to the part nobody enjoys discussing. The Act sets maximum administrative fines: up to €35 million or 7% of worldwide annual turnover for prohibited practices, up to €15 million or 3% for breaches of other operator obligations, and up to €7.5 million or 1% for supplying incorrect, incomplete or misleading information to authorities. For undertakings that are not SMEs, the higher of the fixed amount and the percentage applies; for SMEs, the lower of the two. Money is not the only exposure, and usually not the first one. A competent authority can require corrective action or order that a use be stopped — which, for a company that has built an operational process around an assistant, is more expensive than a fine. Procurement is the second lever: public buyers and large customers increasingly ask for the inventory, the literacy register and the oversight procedure as an attachment, and an answer of "we are working on it" loses the contract. The third is evidentiary. Diligence that was never recorded is, in practice, diligence that never happened.
Nexus Business does not pay a fine and does not make a use lawful. It makes diligence visible: what you deploy, at what risk, under whose responsibility, with which people trained, and with which record when something goes wrong. The AI Act copilot inside the module can draft classifications, notices and assessments, but it proposes — a named person confirms before anything is committed. That is the same principle we apply everywhere else in the platform, and it is the one the Act itself is built on.
To be explicit about the limits: the module is a deployer control and evidence workspace. It is not certification, it does not perform conformity assessment, it does not CE-mark anything, it does not file on your behalf in the EU database of high-risk systems, and it is not a legal opinion. Take specialist counsel before relying on any figure quoted above.
The module is available now in Nexus Business, in all supported languages. If you want to check where your organisation stands before talking to anyone, the six-question test on the AI Act page is a fair place to start.