OKAMIOPS · COMPLIANCE · MAR · 20264 min

EU AI Act: the real calendar and what it means for Brazilian companies

The AI Act entered force in August 2024 with phased applicability. As of February 2025 prohibited practices apply. By August 2026 most obligations kick in. Brazilian companies selling to the EU or processing EU citizens' data need to decide their posture now — not in 2027.

The AI Act risk framework has four levels: unacceptable (prohibited — social scoring, subliminal manipulation), high (health, credit, HR, critical infrastructure — requires strict documentation, human oversight, activity logging), limited transparency (chatbots, deepfakes — requires labeling) and minimal (spam filters, games — no obligation).

For SMBs, direct impact comes through two paths: (1) if you operate or sell to the EU with any AI feature, you must classify risk and document; (2) if you're a B2B supplier to a European company, you'll receive their compliance questionnaire and must answer — without that, they won't contract you.

June 2026 update: the Digital Omnibus was approved (Parliament June 16, Council June 29) and deferred high-risk obligations — standalone Annex III to Dec 2027 and product-embedded systems to Aug 2028. But the August 2026 general applicability was upheld, including Article 50 transparency duties (labeling AI interaction and deepfakes). And 80% of required controls overlap with ISO 27001, GDPR and LGPD — instrument those and the path is largely paved.

▸ TAKEAWAY

If your company touches EU customers with any AI, the documentation must be ready before August 2026 — not after.

// free resource

SecOps Baseline for CI/CD — free

An 8-page guide + open-source script with the 5 minimum security controls for your pipeline: SCA, secrets, containers, IaC and audit-ready evidence.