verified_user
Standardful
Homechevron_rightStandardschevron_rightEU AI Act
ActiveInternational Standardupdate Standard Updated: July 2026fact_check Fact checked: Oct 7, 2026

EU AI Act

Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744

apartmentPublishing Organization:European Union

Standard Introduction

The EU Artificial Intelligence Act is Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. It became generally applicable on 2 August 2026: prohibited-practice and AI-literacy rules already applied, GPAI duties had applied since August 2025, and Article 50 transparency duties and enforcement of applicable rules then became operational.

The 2026 Digital Omnibus did not delay the whole Act. It moved the main Chapter III requirements for Annex III high-risk use cases to 2 December 2027 and for Annex I regulated-product AI systems to 2 August 2028. Providers and deployers should therefore separate live obligations from future high-risk evidence while continuing to comply with GDPR, product, consumer, employment, and sector law.

visibility

Transparency Rules Are Live

Since 2 August 2026, Article 50 requires disclosures for direct AI interaction and specified uses of emotion recognition, biometric categorisation, deepfakes, and public-interest synthetic text, plus machine-readable marking duties for generated or manipulated content.

event

High-Risk Dates Were Extended

The 2026 Digital Omnibus moved Chapter III requirements for Annex III high-risk use cases to 2 December 2027 and for Annex I regulated-product systems to 2 August 2028.

account_tree

Obligations Follow the Role

Providers, deployers, importers, distributors, authorised representatives, product manufacturers, and GPAI model providers have different duties. One organisation can hold several roles for the same AI value chain.

list_alt Current and Upcoming Obligations

  • Prohibited-practice controls and AI literacy already apply
  • GPAI provider documentation, copyright, and systemic-risk duties already apply
  • Article 50 interaction, marking, and labelling transparency duties apply from August 2026
  • Specified pre-August 2026 synthetic-content systems have an Article 50(2) transition to December 2026
  • Annex III high-risk requirements apply from December 2027
  • Annex I regulated-product high-risk requirements apply from August 2028
  • AI Office and national authorities now enforce the rules already applicable
  • GDPR and other EU product or sector law continue to apply in parallel

Who Needs to Comply?

groups

Providers placing AI systems or general-purpose AI models on the EU market, deployers established or located in the EU, and providers or deployers outside the EU where an AI system's output is used in the EU. Importers, distributors, authorised representatives, and product manufacturers can also have direct duties. Applicability depends on the system, role, use case, and exclusions—not simply whether an organisation calls itself an AI company.

Key Requirements

1

Inventory Systems, Models, Uses, and Roles

Record each AI system and GPAI model, intended purpose, affected EU market or output, provider and deployer, upstream model, importer or distributor, and whether another regulated product or sector law applies.

2

Control Rules Already in Application

Test against prohibited practices, operate role-appropriate AI-literacy measures, and meet applicable GPAI obligations. Treat the high-risk extensions as targeted delays, not a pause of the entire AI Act.

3

Implement Article 50 Transparency

Inform people about direct AI interaction and specified emotion-recognition or biometric-categorisation uses; mark generated or manipulated outputs in machine-readable form where required; and label deepfakes and specified public-interest text.

4

Prepare High-Risk Evidence by the Correct Date

For Annex III systems, build risk management, data governance, technical documentation, logging, human oversight, accuracy, cybersecurity, conformity-assessment, registration, and post-market evidence for 2 December 2027. Use 2 August 2028 for Annex I product systems.

5

Monitor Guidance and Enforceability

Track Commission guidance, harmonised standards, common specifications, national competent authorities, and the 2 September 2027 post-market-monitoring guidance deadline. Record which source and effective date supports each compliance decision.

Implementation Roadmap

1
Phase 1schedule Duration: 3-5 weeks

Map systems, models, roles, and dates

Inventory every AI system and GPAI model developed, placed on the EU market, distributed, integrated, or professionally deployed. Record intended purpose, EU output, value-chain roles, prohibited-practice screening, Article 50 category, and whether high-risk status comes from Annex III or an Annex I regulated product.

2
Phase 2schedule Duration: 4-8 weeks

Close obligations that are already live

Stop prohibited uses, document AI-literacy measures, assess GPAI provider duties, and implement Article 50 notices, machine-readable marking, and deployer labels. For synthetic-content systems placed on the market before 2 August 2026, determine whether the Article 50(2) transition to 2 December 2026 applies.

3
Phase 3schedule Duration: 6-18 months

Build high-risk evidence against the revised dates

For Annex III systems, plan Chapter III Sections 1–3 readiness for 2 December 2027; for Annex I product systems, plan for 2 August 2028. Build risk management, data governance, technical documentation, logs, human oversight, accuracy, robustness, cybersecurity, quality management, registration, conformity-assessment, and post-market evidence.

4
Phase 4schedule Duration: Ongoing

Test, monitor, and update the legal map

Test visible disclosures and machine-readable marks, review role and classification decisions, exercise incident and authority-response workflows, and track Commission guidance, harmonised standards, common specifications, and national enforcement. Reassess systems after a substantial modification, new use, model change, or value-chain role change.

Compliance Checklist

0 / 13

checklist Scope, roles, and dates

checklist Rules already applying

checklist High-risk preparation and assurance

EU AI Act Application Timeline After Regulation (EU) 2026/1744

The Act is already applicable in important areas. The later dates are targeted to the main high-risk system requirements.

Rule setApplication dateWho should actImmediate evidence
Initial prohibitions and AI literacy2 February 2025Providers and deployers within scopeUse screening, policy, training scope and completion records
GPAI model obligations2 August 2025GPAI model providersTechnical file, downstream information, copyright policy and training-content summary
Article 50 transparency and enforcement2 August 2026Providers and deployers of covered AI systemsInteraction notice, machine-readable mark, disclosure design and testing
Annex III high-risk requirements2 December 2027Providers, deployers and other operators of Annex III systemsChapter III controls, conformity and post-market evidence
Annex I high-risk product systems2 August 2028Product manufacturers and AI value-chain operatorsIntegrated product-law and AI conformity evidence

Common Misconceptions

cancel
Myth

The Digital Omnibus delayed the entire AI Act until 2027 or 2028.

check_circle
Reality

Prohibitions, AI literacy, GPAI duties, Article 50 transparency, governance, and enforcement of applicable rules are already live. Only specified high-risk requirements received the later dates.

cancel
Myth

All high-risk AI systems now have the same deadline.

check_circle
Reality

Annex III use cases move to 2 December 2027, while Annex I regulated-product systems move to 2 August 2028.

cancel
Myth

The transparency code is the binding law.

check_circle
Reality

Article 50 is binding. The Commission's code is a voluntary compliance tool; organisations may use other measures but must demonstrate that they are adequately effective.

cancel
Myth

Using ISO/IEC 42001 automatically creates EU AI Act conformity.

check_circle
Reality

ISO/IEC 42001 can structure AI governance, but it is not by itself proof of legal compliance or a substitute for the Act's system-, role-, and use-specific requirements.

Penalties & Enforcement

warning

Maximum administrative fines remain tiered: prohibited-practice breaches can reach EUR 35 million or 7% of worldwide annual turnover; many other operator breaches can reach EUR 15 million or 3%; and supplying incorrect information can reach EUR 7.5 million or 1%. The applicable cap and proportionality rules depend on the infringement and enterprise type.

Frequently Asked Questions

Who does the EU AI Act apply to?

expand_more

It applies primarily to providers that develop or place AI systems on the EU market and to deployers that use them in a professional context, as well as importers and distributors. Its reach is extraterritorial: providers and deployers outside the EU are covered when the output of their AI system is used within the EU. This means many non-EU technology and enterprise organizations fall in scope even without an EU establishment.

Did the whole EU AI Act get delayed?

expand_more

No. The Act became generally applicable on 2 August 2026, and rules on prohibited practices, AI literacy, GPAI models, governance, and Article 50 transparency are already applying on their respective dates. Regulation (EU) 2026/1744 specifically moved the main Chapter III high-risk requirements to later dates.

When do Annex III high-risk AI requirements apply?

expand_more

The requirements in Chapter III Sections 1, 2, and 3 apply from 2 December 2027 to AI systems classified as high-risk under Article 6(2) and Annex III, including specified uses in biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice.

When do Annex I regulated-product AI requirements apply?

expand_more

The same Chapter III Sections 1, 2, and 3 requirements apply from 2 August 2028 to high-risk AI systems classified under Article 6(1) and Annex I, such as AI used as a safety component in specified regulated products.

What Article 50 transparency rules apply now?

expand_more

Since 2 August 2026, providers must disclose direct AI interaction where required and add machine-readable marking to generated or manipulated content where Article 50(2) applies. Deployers have duties for specified emotion-recognition and biometric-categorisation exposure, deepfakes, and certain public-interest text. Exceptions and presentation requirements depend on the exact use.

What is the 2 December 2026 AI transparency transition?

expand_more

Specified providers of AI systems, including GPAI-based systems, that generate synthetic audio, image, video, or text and were placed on the market before 2 August 2026 must take the necessary steps to comply with Article 50(2) by 2 December 2026. This is not a general extension for all Article 50 duties.

What obligations apply to general-purpose AI models?

expand_more

GPAI model providers must maintain technical documentation, provide information to downstream providers, implement a copyright-compliance policy, and publish a sufficiently detailed training-content summary. Models with systemic risk face additional evaluation, risk-mitigation, incident, and cybersecurity duties. These rules began applying in August 2025.

Do the high-risk extensions pause GDPR or product-law duties?

expand_more

No. The deadline changes do not suspend the GDPR, consumer law, employment law, medical-device rules, machinery rules, or other applicable EU and national law. Organisations should maintain one obligation map that distinguishes AI Act dates from requirements already imposed by adjacent regimes.

Official Documentation

View All

Implementation Timeline

gavel
Aug 2024
Regulation (EU) 2024/1689 entered into force
block
Feb 2025
Initial prohibited-practice and AI-literacy rules began applying
psychology
Aug 2025
General-purpose AI model obligations and governance rules began applying
update
Jul 2026
Regulation (EU) 2026/1744 entered into force and revised the implementation timeline
visibility
Aug 2026
General application, Article 50 transparency rules, and enforcement of applicable rules began
event
Dec 2026
New prohibited practices apply; transition ends for specified pre-existing synthetic-content systems
warning
Dec 2027
Chapter III high-risk requirements apply to Annex III use cases
verified
Aug 2028
Chapter III high-risk requirements apply to Annex I regulated-product systems

Related Categories