verified_user
Standardful
AI Governance

EU AI Act 2026 Update: What Is Live, What Was Delayed, and What to Do

The EU AI Act is applying, but its high-risk deadlines changed. Separate live transparency and GPAI duties from the December 2027 and August 2028 requirements.

calendar_today•update•schedule 16 min read•personStandardful Team
EU AI Act 2026 Update: What Is Live, What Was Delayed, and What to Do

The EU Artificial Intelligence Act is now applying—but the sentence “high-risk AI rules started in August 2026” is no longer correct.

Regulation (EU) 2026/1744, the adopted Digital Omnibus on AI, entered into force on 27 July 2026 and changed the schedule. The main high-risk requirements now apply:

  • on 2 December 2027 for high-risk use cases under Article 6(2) and Annex III; and
  • on 2 August 2028 for AI embedded in regulated products under Article 6(1) and Annex I.

The rest of the Act did not disappear. Prohibited-practice and AI-literacy rules, general-purpose AI (GPAI) model duties, and governance requirements were already applying. On 2 August 2026, Article 50 transparency duties became applicable and EU and national enforcement of applicable rules began.

For an AI provider or deployer, the practical job is therefore not “wait until 2027.” It is to separate three workstreams:

  1. rules already in application;
  2. the specific 2 December 2026 transition and new prohibitions; and
  3. high-risk evidence due in 2027 or 2028.

This guide provides that map. It reflects official EU law and European Commission guidance available on 12 September 2026.

The amended timeline at a glance

DateRule setCurrent status
1 August 2024Regulation (EU) 2024/1689 enters into forceCompleted
2 February 2025Initial prohibited practices, definitions, and AI-literacy provisions applyLive
2 August 2025GPAI model obligations and EU governance rules applyLive
27 July 2026Regulation (EU) 2026/1744 enters into forceCompleted
2 August 2026General application; Article 50 transparency; enforcement of applicable rulesLive
2 December 2026Additional prohibitions; Article 50(2) transition for specified pre-existing systems endsUpcoming
2 August 2027Member States should have at least one AI regulatory sandbox operationalUpcoming
2 December 2027Main Chapter III requirements apply to Annex III high-risk systemsUpcoming
2 August 2028Main Chapter III requirements apply to Annex I high-risk product systemsUpcoming

The European Commission's official implementation timeline incorporates the 2026 amendment. Use it with the legal text rather than an older chart that still shows August 2026 and August 2027 as the two high-risk dates.

What Regulation (EU) 2026/1744 actually changed

The amendment did more than move dates, but the most important correction for most compliance plans concerns Chapter III Sections 1, 2, and 3. Those sections contain the classification, provider, deployer, technical, conformity-assessment, registration, and related operator requirements for high-risk AI systems.

The adopted regulation sets two fixed dates:

  • Annex III systems: 2 December 2027.
  • Annex I regulated-product systems: 2 August 2028.

The distinction matters because the legal route to “high-risk” differs.

Annex III: sensitive use cases

Article 6(2) and Annex III cover specified uses such as:

  • biometrics;
  • critical infrastructure;
  • education and vocational training;
  • employment, worker management, and access to self-employment;
  • access to essential private and public services;
  • law enforcement;
  • migration, asylum, and border control; and
  • administration of justice and democratic processes.

Not every AI system used somewhere in these sectors is automatically high-risk. The exact Annex III use case, intended purpose, Article 6 conditions, and exclusions must be tested. If the system is classified under this route, the revised Chapter III date is 2 December 2027.

Annex I: regulated products

Article 6(1) concerns AI systems that are safety components of products—or are themselves products—covered by specified EU harmonisation legislation, where the product must undergo third-party conformity assessment. Examples can include certain machinery, medical devices, toys, lifts, and other regulated products, depending on the precise legislation and function.

For this route, the revised Chapter III date is 2 August 2028. Product manufacturers need an integrated plan because the AI evidence, product technical file, notified-body work, cybersecurity, safety, and post-market processes can depend on each other.

What is already enforceable

The later high-risk dates are not a general standstill. The Commission's current AI Act overview confirms that the Act became generally applicable on 2 August 2026, with specific exceptions.

Prohibited practices and AI literacy

The original set of prohibited practices and the AI-literacy provision have applied since 2 February 2025. Organisations should have:

  • screened current and planned uses against Article 5;
  • blocked procurement, configuration, or deployment of prohibited uses;
  • identified staff and other persons dealing with AI systems on their behalf; and
  • selected literacy measures appropriate to their role, technical knowledge, experience, education, training, and the context of use.

AI literacy is not satisfied by a generic annual video for everyone. A procurement lead assessing GPAI vendors, an engineer building machine-readable content markers, and an HR user overseeing an employment system need different competence.

The 2026 amendment adds prohibited practices concerning non-consensual sexual deepfakes and child sexual abuse material. According to the official timeline, those additions apply from 2 December 2026.

GPAI model obligations

Obligations for GPAI model providers began applying on 2 August 2025. Depending on the model and role, the evidence includes:

  • technical documentation;
  • information for downstream system providers;
  • a policy to comply with EU copyright law;
  • a sufficiently detailed public summary of training content; and
  • for GPAI models with systemic risk, evaluation, risk assessment and mitigation, incident reporting, and cybersecurity measures.

Using a GPAI model through an API does not automatically make the customer its provider. But fine-tuning, modifying, rebranding, integrating, or placing an AI system on the market can create additional roles and duties. Record the contractual and technical value chain rather than relying on labels such as “vendor” and “customer.”

Article 50 transparency

Article 50 has applied since 2 August 2026. The Commission's final transparency guidelines explain which providers, deployers, systems, outputs, and exceptions are covered.

SituationPrimary actorOperational requirement
A person interacts directly with an AI systemProviderInform the person that they are interacting with AI, unless an applicable exception applies
An AI system generates or manipulates audio, image, video, or textProviderMake outputs detectable as artificial or manipulated using machine-readable marking where Article 50(2) applies
A person is exposed to emotion recognition or biometric categorisationDeployerInform the exposed person, subject to the legal conditions and exceptions
A deployer publishes a deepfakeDeployerDisclose that the content was artificially generated or manipulated
AI-generated or manipulated text informs the public on a matter of public interestDeployerDisclose the artificial nature unless the human-review and editorial-responsibility exception applies

The legal question is not merely whether a page contains the word “AI.” Teams need to test notice timing, placement, accessibility, persistence, language, technical marking, alteration through the distribution chain, and exceptions.

The Code of Practice on Transparency of AI-generated Content is voluntary. Article 50 is binding. Signatories can use the code's measures to demonstrate compliance; organisations using another method must be able to demonstrate that their measures are adequately effective.

OpenAI textGrain: an implementation example, not proof of compliance

On 5 October 2026, OpenAI announced a phased EU rollout of textGrain, an invisible statistical watermark for eligible ChatGPT and Codex text. Rather than inserting hidden characters, it adjusts the pattern of model word or token choices so a detector can look for the signal. OpenAI says API customers can opt in for selected models globally, while eligible ChatGPT and Codex output in the EU is being covered through the regional rollout.

This is a concrete example of a provider addressing Article 50(2), but it is not a universal compliance certificate. OpenAI identifies material limitations:

  • short or highly constrained text is harder to detect;
  • outputs from unsupported models or generated before watermarking may contain no signal;
  • editing, rewriting, summarising, or translating a passage can weaken detection;
  • detectors can produce both false positives and false negatives; and
  • a detected watermark says something about likely origin, not accuracy, ownership, legality, or whether the content was later manipulated.

The operational lesson is broader than one vendor. A provider should maintain an output-type and model-version matrix, document which paths receive a machine-readable mark, test survival through normal export and transformation routes, set a false-positive policy, control detector access, and preserve versioned validation evidence. A deployer should separately determine whether a visible disclosure is required for the use case. An invisible provider-side signal does not automatically satisfy every deployer disclosure duty.

Governance and enforcement

From 2 August 2026, the AI Office and Member State authorities began enforcing rules already in application. The AI Office has direct powers in relation to GPAI models and specified AI systems under the amended allocation of competence. The Commission has also launched complaints and whistleblower channels.

Do not confuse “enforcement has started” with “every article applies to every system.” An authority must still identify the actor, system, applicable provision, date, and facts. Your evidence should make those same links.

The 2 December 2026 transition for existing synthetic-content systems

Regulation (EU) 2026/1744 created a narrow transition for specified providers of systems that generate synthetic audio, image, video, or text.

If such a system—including a GPAI-based system—was placed on the market before 2 August 2026, the provider must take the necessary steps to comply with Article 50(2) by 2 December 2026.

This is not:

  • an extension for every Article 50 obligation;
  • an extension for systems first placed on the market on or after 2 August 2026; or
  • a reason to postpone deployer disclosure duties that are already applicable.

For each product version, record the date it was placed on the market, the provider entity, output types, whether Article 50(2) applies, the marking method, validation results, and the deployment date of the compliant release.

A role-first scope test

One organisation can be a provider for one system and a deployer for another. It can also become a provider by placing a system on the market under its own name or by making a substantial modification.

Build an inventory with one row per system and use:

FieldDecision it supports
Intended purpose and actual useProhibited, high-risk, transparency, or other classification
Provider and model providerOwnership of system and GPAI duties
Professional deployerHuman use, notices, monitoring, and deployer obligations
Importer, distributor, authorised representativeEU market-access and verification duties
EU market, establishment, or outputTerritorial scope
Annex III use-case analysis2 December 2027 high-risk route
Annex I product legislation and safety function2 August 2028 high-risk route
Personal data and affected peopleParallel GDPR and fundamental-rights work
System version and substantial modificationsReclassification and conformity triggers

The official EU AI Act Compliance Checker can help structure the analysis, but it is a beta informational tool and does not represent a Commission decision or legal advice.

How to use the added time for high-risk systems

The revised dates give teams time to implement the requirements properly. They do not reduce the eventual evidence set.

For Annex III systems due in December 2027

Work backward from 2 December 2027:

  1. Confirm the intended purpose, Annex III category, Article 6 conditions, role, and exclusions.
  2. Establish the provider's quality-management system and lifecycle risk-management process.
  3. Govern training, validation, and testing data as applicable.
  4. Create and maintain technical documentation and automatic logging.
  5. Design provider transparency, deployer instructions, and effective human oversight.
  6. Validate accuracy, robustness, and cybersecurity.
  7. Define the conformity-assessment and EU database registration route.
  8. Establish post-market monitoring, serious-incident reporting, corrective action, and record retention.

For Annex I product systems due in August 2028

Start with the product legislation. Identify the product manufacturer, safety function, conformity-assessment route, notified body, technical file, software lifecycle, cybersecurity obligations, and post-market system. Then integrate AI Act evidence into that plan.

A disconnected “AI governance” file can fail if it does not match the product version, intended purpose, hazard analysis, clinical or safety evidence, change control, and conformity route.

The amended regulation requires the Commission to publish post-market-monitoring guidance, including a voluntary template, by 2 September 2027. Teams should build a workable system now and plan a controlled update when that guidance arrives.

What the delay does not change

An AI system can be lawful under one AI Act date and still violate another law today. The amendment does not suspend:

  • the General Data Protection Regulation (GDPR);
  • consumer-protection and anti-discrimination law;
  • employment and worker-consultation rules;
  • medical-device, machinery, automotive, or other product law;
  • cybersecurity obligations; or
  • contractual, procurement, intellectual-property, and sector rules.

For systems processing personal data, coordinate the AI Act evidence with GDPR records, lawful-basis analysis, transparency, data protection impact assessment, security, data-subject rights, and automated-decision safeguards where applicable.

ISO/IEC 42001 can provide an AI management system, while ISO/IEC 42005 provides impact-assessment guidance. They can reduce duplicate governance work, but neither automatically creates legal conformity. Map each standard artifact to a specific legal requirement and keep the unmapped legal gaps visible.

30-day action plan

  • Replace old August 2026/August 2027 high-risk dates.
  • Identify systems subject to live prohibited-practice, AI-literacy, GPAI, or Article 50 rules.
  • Separate Annex III systems from Annex I regulated-product systems.
  • Record provider, deployer, importer, distributor, and product-manufacturer roles.

Days 11–20: test live transparency

  • Test direct-interaction notices on every supported interface and language.
  • Validate machine-readable marking through generation, export, compression, editing, and distribution.
  • Review deepfake and public-interest publication workflows.
  • Record legal exceptions and responsible approvals.
  • Identify pre-August 2026 systems using the December 2026 transition.

Days 21–30: rebaseline high-risk delivery

  • Assign 2 December 2027 or 2 August 2028 to every potential high-risk system.
  • Define the required evidence, dependency, owner, completion criterion, and review gate.
  • Integrate privacy, safety, cybersecurity, product, and sector obligations.
  • Set monitoring for Commission guidance, harmonised standards, common specifications, and competent-authority instructions.

FAQ

Did the EU delay the entire AI Act?

No. Prohibited-practice and AI-literacy rules, GPAI obligations, Article 50 transparency duties, governance, and enforcement of rules already applicable remain live. Regulation (EU) 2026/1744 moved the main Chapter III high-risk system requirements to later dates.

When do Annex III high-risk AI requirements apply?

Chapter III Sections 1, 2, and 3 apply from 2 December 2027 to systems classified as high-risk under Article 6(2) and Annex III, including specified uses in employment, education, essential services, biometrics, critical infrastructure, law enforcement, migration, and justice.

When do high-risk rules for Annex I regulated products apply?

The main Chapter III high-risk requirements apply from 2 August 2028 to AI systems classified under Article 6(1) and Annex I, such as AI used as a safety component in specified regulated products.

Which EU AI Act transparency duties are already live?

Article 50 has applied since 2 August 2026. Depending on the system and role, it covers direct AI-interaction notices, machine-readable marking of generated or manipulated content, and disclosures for specified emotion-recognition, biometric-categorisation, deepfake, and public-interest text uses.

What changes on 2 December 2026?

Additional prohibited practices introduced by Regulation (EU) 2026/1744 start applying. It is also the Article 50(2) transition deadline for specified synthetic-content systems, including GPAI-based systems, that were placed on the market before 2 August 2026.

Does ISO/IEC 42001 prove EU AI Act compliance?

No. ISO/IEC 42001 can structure an AI management system and support reusable governance evidence, but it does not automatically satisfy the AI Act or replace system-, role-, use-, and date-specific legal analysis.

Research and review note

This article was materially revised and fact-checked against EU legislation, European Commission implementation material, and OpenAI's primary implementation disclosures available on 7 October 2026. Regulation (EU) 2026/1744 is adopted law, not the earlier Commission proposal. Binding legislation controls over explanatory pages, voluntary codes, beta tools, company claims, and this guide.

The Commission may publish further guidance, harmonised-standard references, common specifications, templates, and enforcement material. This article provides general information, not legal, conformity-assessment, product-safety, data-protection, or certification advice.

Official sources

  1. Regulation (EU) 2024/1689 — Artificial Intelligence Act — original legal act
  2. Regulation (EU) 2026/1744 — Digital Omnibus on AI — adopted amendment and revised dates
  3. European Commission AI Act overview — current application and enforcement summary
  4. Official EU AI Act implementation timeline — milestone map incorporating the 2026 amendment
  5. Article 50 transparency guidelines — actor, scope, exception, and implementation guidance
  6. Code of Practice on Transparency of AI-generated Content — voluntary compliance measures
  7. EU AI Act Compliance Checker — official beta decision-support tool
  8. OpenAI: Our approach to EU text provenance rules — 5 October 2026 rollout announcement, design and stated limitations
  9. OpenAI provenance signals — current product coverage and textGrain explanation

Related Topics

EU AI ActRegulation (EU) 2026/1744AI TransparencyHigh-Risk AIGPAIAI GovernanceDigital Omnibus