EU AI Act
Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744
Standard Introduction
The EU Artificial Intelligence Act is Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. It became generally applicable on 2 August 2026: prohibited-practice and AI-literacy rules already applied, GPAI duties had applied since August 2025, and Article 50 transparency duties and enforcement of applicable rules then became operational.
The 2026 Digital Omnibus did not delay the whole Act. It moved the main Chapter III requirements for Annex III high-risk use cases to 2 December 2027 and for Annex I regulated-product AI systems to 2 August 2028. Providers and deployers should therefore separate live obligations from future high-risk evidence while continuing to comply with GDPR, product, consumer, employment, and sector law.
Transparency Rules Are Live
Since 2 August 2026, Article 50 requires disclosures for direct AI interaction and specified uses of emotion recognition, biometric categorisation, deepfakes, and public-interest synthetic text, plus machine-readable marking duties for generated or manipulated content.
High-Risk Dates Were Extended
The 2026 Digital Omnibus moved Chapter III requirements for Annex III high-risk use cases to 2 December 2027 and for Annex I regulated-product systems to 2 August 2028.
Obligations Follow the Role
Providers, deployers, importers, distributors, authorised representatives, product manufacturers, and GPAI model providers have different duties. One organisation can hold several roles for the same AI value chain.
list_alt Current and Upcoming Obligations
- Prohibited-practice controls and AI literacy already apply
- GPAI provider documentation, copyright, and systemic-risk duties already apply
- Article 50 interaction, marking, and labelling transparency duties apply from August 2026
- Specified pre-August 2026 synthetic-content systems have an Article 50(2) transition to December 2026
- Annex III high-risk requirements apply from December 2027
- Annex I regulated-product high-risk requirements apply from August 2028
- AI Office and national authorities now enforce the rules already applicable
- GDPR and other EU product or sector law continue to apply in parallel
Who Needs to Comply?
Providers placing AI systems or general-purpose AI models on the EU market, deployers established or located in the EU, and providers or deployers outside the EU where an AI system's output is used in the EU. Importers, distributors, authorised representatives, and product manufacturers can also have direct duties. Applicability depends on the system, role, use case, and exclusions—not simply whether an organisation calls itself an AI company.
Key Requirements
Inventory Systems, Models, Uses, and Roles
Record each AI system and GPAI model, intended purpose, affected EU market or output, provider and deployer, upstream model, importer or distributor, and whether another regulated product or sector law applies.
Control Rules Already in Application
Test against prohibited practices, operate role-appropriate AI-literacy measures, and meet applicable GPAI obligations. Treat the high-risk extensions as targeted delays, not a pause of the entire AI Act.
Implement Article 50 Transparency
Inform people about direct AI interaction and specified emotion-recognition or biometric-categorisation uses; mark generated or manipulated outputs in machine-readable form where required; and label deepfakes and specified public-interest text.
Prepare High-Risk Evidence by the Correct Date
For Annex III systems, build risk management, data governance, technical documentation, logging, human oversight, accuracy, cybersecurity, conformity-assessment, registration, and post-market evidence for 2 December 2027. Use 2 August 2028 for Annex I product systems.
Monitor Guidance and Enforceability
Track Commission guidance, harmonised standards, common specifications, national competent authorities, and the 2 September 2027 post-market-monitoring guidance deadline. Record which source and effective date supports each compliance decision.
Implementation Roadmap
Map systems, models, roles, and dates
Inventory every AI system and GPAI model developed, placed on the EU market, distributed, integrated, or professionally deployed. Record intended purpose, EU output, value-chain roles, prohibited-practice screening, Article 50 category, and whether high-risk status comes from Annex III or an Annex I regulated product.
Close obligations that are already live
Stop prohibited uses, document AI-literacy measures, assess GPAI provider duties, and implement Article 50 notices, machine-readable marking, and deployer labels. For synthetic-content systems placed on the market before 2 August 2026, determine whether the Article 50(2) transition to 2 December 2026 applies.
Build high-risk evidence against the revised dates
For Annex III systems, plan Chapter III Sections 1–3 readiness for 2 December 2027; for Annex I product systems, plan for 2 August 2028. Build risk management, data governance, technical documentation, logs, human oversight, accuracy, robustness, cybersecurity, quality management, registration, conformity-assessment, and post-market evidence.
Test, monitor, and update the legal map
Test visible disclosures and machine-readable marks, review role and classification decisions, exercise incident and authority-response workflows, and track Commission guidance, harmonised standards, common specifications, and national enforcement. Reassess systems after a substantial modification, new use, model change, or value-chain role change.
Compliance Checklist
checklist Scope, roles, and dates
checklist Rules already applying
checklist High-risk preparation and assurance
EU AI Act Application Timeline After Regulation (EU) 2026/1744
The Act is already applicable in important areas. The later dates are targeted to the main high-risk system requirements.
| Rule set | Application date | Who should act | Immediate evidence |
|---|---|---|---|
| Initial prohibitions and AI literacy | 2 February 2025 | Providers and deployers within scope | Use screening, policy, training scope and completion records |
| GPAI model obligations | 2 August 2025 | GPAI model providers | Technical file, downstream information, copyright policy and training-content summary |
| Article 50 transparency and enforcement | 2 August 2026 | Providers and deployers of covered AI systems | Interaction notice, machine-readable mark, disclosure design and testing |
| Annex III high-risk requirements | 2 December 2027 | Providers, deployers and other operators of Annex III systems | Chapter III controls, conformity and post-market evidence |
| Annex I high-risk product systems | 2 August 2028 | Product manufacturers and AI value-chain operators | Integrated product-law and AI conformity evidence |
Common Misconceptions
The Digital Omnibus delayed the entire AI Act until 2027 or 2028.
Prohibitions, AI literacy, GPAI duties, Article 50 transparency, governance, and enforcement of applicable rules are already live. Only specified high-risk requirements received the later dates.
All high-risk AI systems now have the same deadline.
Annex III use cases move to 2 December 2027, while Annex I regulated-product systems move to 2 August 2028.
The transparency code is the binding law.
Article 50 is binding. The Commission's code is a voluntary compliance tool; organisations may use other measures but must demonstrate that they are adequately effective.
Using ISO/IEC 42001 automatically creates EU AI Act conformity.
ISO/IEC 42001 can structure AI governance, but it is not by itself proof of legal compliance or a substitute for the Act's system-, role-, and use-specific requirements.
Penalties & Enforcement
Maximum administrative fines remain tiered: prohibited-practice breaches can reach EUR 35 million or 7% of worldwide annual turnover; many other operator breaches can reach EUR 15 million or 3%; and supplying incorrect information can reach EUR 7.5 million or 1%. The applicable cap and proportionality rules depend on the infringement and enterprise type.
Frequently Asked Questions
Who does the EU AI Act apply to?
expand_more
It applies primarily to providers that develop or place AI systems on the EU market and to deployers that use them in a professional context, as well as importers and distributors. Its reach is extraterritorial: providers and deployers outside the EU are covered when the output of their AI system is used within the EU. This means many non-EU technology and enterprise organizations fall in scope even without an EU establishment.
Did the whole EU AI Act get delayed?
expand_more
No. The Act became generally applicable on 2 August 2026, and rules on prohibited practices, AI literacy, GPAI models, governance, and Article 50 transparency are already applying on their respective dates. Regulation (EU) 2026/1744 specifically moved the main Chapter III high-risk requirements to later dates.
When do Annex III high-risk AI requirements apply?
expand_more
The requirements in Chapter III Sections 1, 2, and 3 apply from 2 December 2027 to AI systems classified as high-risk under Article 6(2) and Annex III, including specified uses in biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice.
When do Annex I regulated-product AI requirements apply?
expand_more
The same Chapter III Sections 1, 2, and 3 requirements apply from 2 August 2028 to high-risk AI systems classified under Article 6(1) and Annex I, such as AI used as a safety component in specified regulated products.
What Article 50 transparency rules apply now?
expand_more
Since 2 August 2026, providers must disclose direct AI interaction where required and add machine-readable marking to generated or manipulated content where Article 50(2) applies. Deployers have duties for specified emotion-recognition and biometric-categorisation exposure, deepfakes, and certain public-interest text. Exceptions and presentation requirements depend on the exact use.
What is the 2 December 2026 AI transparency transition?
expand_more
Specified providers of AI systems, including GPAI-based systems, that generate synthetic audio, image, video, or text and were placed on the market before 2 August 2026 must take the necessary steps to comply with Article 50(2) by 2 December 2026. This is not a general extension for all Article 50 duties.
What obligations apply to general-purpose AI models?
expand_more
GPAI model providers must maintain technical documentation, provide information to downstream providers, implement a copyright-compliance policy, and publish a sufficiently detailed training-content summary. Models with systemic risk face additional evaluation, risk-mitigation, incident, and cybersecurity duties. These rules began applying in August 2025.
Do the high-risk extensions pause GDPR or product-law duties?
expand_more
No. The deadline changes do not suspend the GDPR, consumer law, employment law, medical-device rules, machinery rules, or other applicable EU and national law. Organisations should maintain one obligation map that distinguishes AI Act dates from requirements already imposed by adjacent regimes.
Official Documentation
EU AI Act (EU) 2024/1689
EUR-Lex • Full Regulation Text • All EU Languages
European Commission AI Policy
External Link • digital-strategy.ec.europa.eu • Regulatory Framework
Official AI Act Compliance Checker
External Link • AI Act Service Desk • Beta Decision Tool