Independent EU AI Act information resourceLegal text verified against EUR-Lex

Practical guide

What the EU AI Act requires of you right now

The high-risk deadlines moved. Most of the Act did not. If you read the coverage of the Digital Omnibus as “the AI Act was delayed” and stood your programme down, four sets of obligations are already binding you today.

What was actually deferred, and what was not

Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026. It moved two dates. It did not roll back anything already in force, and it added two prohibitions.

Binding today

  • Prohibited practices — since 2 February 2025 (Article 5)
  • AI literacy — since 2 February 2025 (Article 4)
  • General-purpose AI models — since 2 August 2025 (Article 53)
  • Transparency — since 2 August 2026 (Article 50)

Deferred

  • Annex III high-risk — 2 August 2026 moved to 2 December 2027
  • Annex I products — 2 August 2027 moved to 2 August 2028

The stated reason was that the conformity-assessment infrastructure, harmonised standards and designated notified bodies, was not ready. That shortage is not resolved by waiting for it.

There is also a date between the two that is easy to miss. 2 December 2026 brings two new prohibitions, on AI that generates non-consensual intimate imagery and on AI that generates child sexual abuse material, and closes the transitional window for marking generative systems that were already on the market. Neither is grandfathered. What the Omnibus changed, clause by clause.

Check your position

What applies to you

Eight answers, about a minute. Nothing you enter leaves your browser or is stored; the result lives in the page address, so you can send it to a colleague.

1 Does the Act reach you at all?

It does if you place AI on the EU market, use AI inside the EU, or sit outside the EU while the output of your AI is used in it. That last limb catches a great many non-EU companies.

Every obligation this guide covers, dated

8 obligations are live; 3are scheduled. Dates are read from the Act's application timetable as amended, last checked against the consolidated text on 11 August 2026.

EU AI Act obligations by application date and operator role
Applies fromStatusObligationWho it bindsProvision
2 February 2025LiveSupport AI literacy in anyone using AI on your behalfYou must take measures to support a sufficient level of AI literacy among staff and anyone else operating AI systems for you. It binds every provider and deployer, and it was not deferred.Provider, Deployer, Product manufacturerArticle 4
2 February 2025LiveConfirm you are running none of the prohibited practicesEight practices are banned outright across the EU, and none of the deferrals touched them. Two more, covering non-consensual intimate imagery and child sexual abuse material, are added from 2 Dec 2026 with no grandfathering.Provider, Deployer, Importer, Distributor, Product manufacturerArticle 5
2 February 2025LiveWatch for the point where you become the providerRole is fixed per system, not per company. A deployer takes on the provider's obligations by putting its own name or trade mark on a high-risk system, substantially modifying one, or changing its purpose so that it becomes high-risk.DeployerArticle 25
2 August 2025LiveMeet the general-purpose AI model obligationsProviders of GPAI models owe technical documentation, information to downstream providers, a copyright policy and a training-content summary. Models meeting the systemic-risk threshold carry evaluation, incident-reporting and cybersecurity duties on top.ProviderArticle 53
2 August 2026LiveTell people they are dealing with an AIAnyone interacting with your AI system must be able to tell that it is an AI, unless that is obvious from the context. For a chatbot the disclosure has to come before or at the very start of the conversation, not buried in a policy.Provider, DeployerArticle 50(1)
2 August 2026LiveMark synthetic output in a machine-readable formatProviders of systems that generate synthetic audio, image, video or text must mark that output so it is detectable as artificially generated. Systems placed on the market before 2 Aug 2026 have until 2 Dec 2026 to comply.ProviderArticle 50(2)
2 August 2026LiveTell people when emotion recognition or biometric sorting is in useDeployers of emotion recognition or biometric categorisation systems must inform the people exposed to them. Note the prior question: in the workplace and in education, emotion inference is prohibited, so disclosure will not save it.DeployerArticle 50(3)
2 August 2026LiveLabel deep fakes and AI-written public-interest textDeployers must disclose that image, audio or video content is artificially generated or manipulated, and that AI-generated text published to inform the public on matters of public interest is AI-generated.DeployerArticle 50(4)
2 December 2026ScheduledBring already-live generative systems into markingGenerative systems already on the market before 2 Aug 2026 were given a transitional window. It closes on the date shown against this duty.ProviderArticle 50(2)
2 December 2027ScheduledBuild the high-risk regime for your Annex III useThe Annex III high-risk obligations were deferred. That is a schedule change, not a reprieve: risk management, data governance, technical documentation, logging, human oversight and conformity assessment all still have to exist by then, and the work takes longer than the time remaining suggests.Provider, DeployerArticle 6, Annex III
2 August 2028ScheduledFold AI conformity into your existing product routeWhere AI is a safety component of a product already covered by EU harmonisation law, the high-risk obligations apply from this date and are assessed through the sectoral conformity route you already use.Provider, Product manufacturerAnnex I, Article 6(1)

Provider or deployer? It is decided per system

This is the single most common error in AI Act compliance work: treating provider and deployer as labels for the company. They are not. They attach to each system, and one organisation is routinely both — the deployer of a support chatbot it bought, and the provider of the scoring model it built.

How the two roles differ
ProviderDeployer
You are this ifYou develop the system, or place it on the market under your own name or trade markYou use the system as supplied, under your own authority
Typical exampleYou built the CV-ranking model, or you white-labelled someone else'sYou subscribe to a recruitment tool and screen candidates with it
Transparency dutyBuild the disclosure and the machine-readable marking into the systemGive notice to the people exposed to it, and label deep fakes
If high-riskThe full Chapter III regime, conformity assessment and registrationUse per instructions, keep logs, assign human oversight, and run the fundamental rights impact assessment

The trap in Article 25

A deployer becomes the provider, with every obligation that carries, by putting its name or trade mark on a high-risk system, substantially modifying one, or modifying its purpose so that it becomes high-risk. Fine-tuning and white-labelling are the two routes organisations take without realising the role has changed underneath them. Read Article 25.

Common questions

Was the EU AI Act delayed?
Part of it. Regulation (EU) 2026/1744 deferred the Annex III high-risk obligations to 2 December 2027 and the Annex I product obligations to 2 August 2028. Nothing already in force was rolled back. The Article 5 prohibitions and the Article 4 AI literacy duty have applied since 2 February 2025, the general-purpose AI model rules since 2 August 2025, and the Article 50 transparency rules since 2 August 2026.
Our AI is not high-risk. Does that mean we have nothing to do?
No. Three sets of obligations apply regardless of risk tier. You must not run any prohibited practice. You owe an AI literacy duty for anyone operating AI on your behalf. And if your AI talks to people or generates content, Article 50 transparency applies to it now, whatever its risk classification.
Are we a provider or a deployer?
Both, usually. The roles attach to each system rather than to the company. You are the provider of a system you develop, or one you place on the market under your own name or trade mark. You are the deployer of a system you use as supplied. Under Article 25 a deployer becomes the provider by putting its name on a high-risk system, substantially modifying it, or changing its purpose so that it becomes high-risk.
Do we have to do anything if we only use ChatGPT or Copilot?
Yes, though not much. You are a deployer. The AI literacy duty applies to your staff, the prohibitions apply to how you use the tool, and if you expose an AI assistant to customers you owe the Article 50 disclosure. You do not inherit the model provider's obligations by using their API.
What is the next EU AI Act deadline?
2 December 2026: two new prohibited practices take effect, covering AI that generates non-consensual intimate imagery and AI that generates child sexual abuse material, and generative systems placed on the market before 2 August 2026 must carry machine-readable marking. Neither is grandfathered.

Where to go next

This page describes Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. It is an independent information resource, not legal advice, and it classifies organisations rather than systems. Where a classification carries consequence, take it through a per-system assessment and record the reasoning.