As of 8 August 2026, the EU AI Act is generally applicable, its Article 50 transparency duties are in force, and the high-risk dates have changed. Regulation (EU) 2026/1744 moved the Chapter III high-risk rules to 2 December 2027 for Article 6(2)/Annex III systems and 2 August 2028 for Article 6(1)/Annex I product-related systems.
The correct compliance path is: determine whether the Act applies, identify each operator role, screen prohibited practices, classify high-risk and transparency exposure, then map the duties and transition rules for that role. “AI user” and “AI vendor” are not precise enough.
Need a documented role, risk, and deadline map? Start with an AI Act scope and readiness review.
Current application timeline
| Date | Status on 8 August 2026 | Main effect |
|---|---|---|
| 1 August 2024 | Entry into force | Regulation (EU) 2024/1689 entered into force |
| 2 February 2025 | In application | Chapters I and II began to apply, including the original prohibited-practice rules |
| 2 August 2025 | In application | Governance and general-purpose AI model provisions began to apply, subject to transitional rules |
| 27 July 2026 | In force | Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force |
| 2 August 2026 | In application | General application date; Article 50 transparency duties and Commission enforcement powers for GPAI providers apply |
| 2 December 2026 | Future | New Article 5 prohibitions added by the Omnibus apply; the limited Article 50(2) transition for systems placed on the market before 2 August 2026 ends |
| 2 December 2027 | Future | Chapter III Sections 1–3 apply to Article 6(2)/Annex III high-risk systems |
| 2 August 2028 | Future | Chapter III Sections 1–3 apply to Article 6(1)/Annex I product-related high-risk systems |
Do not call 2 August 2026 the universal high-risk deadline. It was the original date for much of Chapter III, but the 2026 amendment replaced it for the two high-risk routes.
Does the AI Act apply?
Article 2 covers, among others:
- providers placing AI systems or general-purpose AI models on the EU market;
- deployers located or established in the EU;
- providers and deployers outside the EU where the output produced by the system is used in the EU;
- importers, distributors, product manufacturers, and authorised representatives in defined circumstances; and
- affected persons located in the EU.
There are exclusions and special rules, including for certain military, defence, national-security, research, open-source, and personal non-professional activities. Apply the exact text; do not infer an exemption from a product label.
Identify the operator role
| Role | Core question |
|---|---|
| Provider | Does the organisation develop an AI system or model, have it developed, and place it on the market or put it into service under its name or trademark? |
| Deployer | Does it use an AI system under its authority, outside a personal non-professional activity? |
| Importer | Is it established in the EU and placing on the market a system bearing the name or trademark of a provider established outside the EU? |
| Distributor | Does it make a system available in the EU supply chain without being the provider or importer? |
| Authorised representative | Has a non-EU provider appointed it in writing to perform specified obligations? |
| Product manufacturer | Does it place a product on the market with an AI system under its name or trademark in the circumstances set by Article 25? |
A deployer can become the provider of a particular system if it applies its name or trademark, makes a substantial modification, or changes the intended purpose so that the system becomes high-risk, subject to the detailed Article 25 rules.
Screen prohibited practices first
Article 5 prohibits specified practices rather than an abstract “unacceptable risk” label. The original prohibitions have applied since 2 February 2025. Regulation (EU) 2026/1744 adds further prohibitions that apply from 2 December 2026.
The screen should cover the full workflow, purpose, affected people, inputs, outputs, and deployment context. Several provisions contain definitions, thresholds, or narrow exceptions. Escalate uncertain cases to qualified counsel; controls cannot legitimise a prohibited practice.
Classify high-risk systems
Article 6(1) and Annex I
This route concerns an AI system used as a safety component of a product, or itself a product, covered by listed Union harmonisation legislation and meeting the relevant conformity-assessment condition. Regulation (EU) 2026/1744 also changes aspects of the interaction with product legislation. The applicable high-risk date for Chapter III Sections 1–3 is 2 August 2028.
Article 6(2) and Annex III
This route covers listed sensitive uses in areas such as biometrics, critical infrastructure, education, employment, access to certain essential services, law enforcement, migration, and justice. Article 6(3) contains qualifications for some systems that do not pose a significant risk of harm, but an Annex III system that performs profiling of natural persons is always considered high-risk. The applicable high-risk date for Chapter III Sections 1–3 is 2 December 2027.
Document the particular Annex entry, intended purpose, facts, exclusions, and reviewer. Do not classify an entire technology—such as “chatbot” or “machine learning”—without the use context.
Duties already relevant in August 2026
AI literacy
The amended Article 4 requires providers and deployers to take measures supporting the development of AI literacy for staff and others operating or using systems on their behalf. It expressly does not require a guarantee that any individual reaches a specified level. Training should be proportionate to the person's knowledge, role, use context, and affected people.
Article 50 transparency
Article 50 applies from 2 August 2026 and assigns the following duties by role.
Provider duties — Article 50(1) and (2)
- informing people when they interact directly with AI unless this is obvious to a reasonably well-informed, observant, and circumspect person in the circumstances;
- making synthetic content outputs detectable in a machine-readable format where Article 50(2) applies.
Deployer duties — Article 50(3) and (4)
- informing exposed people about emotion-recognition or biometric-categorisation systems where permitted; and
- disclosing specified deepfake and public-interest text content, subject to the article's qualifications.
For Article 50(2) systems placed on the market before 2 August 2026, Regulation (EU) 2026/1744 provides a transition until 2 December 2026. Content created before 2 August 2026 does not need retroactive labelling under the Commission's current FAQ.
General-purpose AI models
GPAI provider obligations began applying on 2 August 2025, with transitional treatment for models already on the market. From 2 August 2026, the Commission's enforcement powers apply. Providers of models placed on the market before 2 August 2025 have until 2 August 2027 to comply under the transition described by the Commission.
High-risk provider requirements
When the relevant high-risk date applies, a provider's work includes:
- an iterative risk-management system;
- data and data-governance controls where applicable;
- technical documentation;
- record-keeping capability;
- instructions and transparency for deployers;
- effective human-oversight design;
- accuracy, robustness, and cybersecurity;
- quality management;
- conformity assessment and required registration;
- corrective action and serious-incident processes; and
- post-market monitoring.
Prepare evidence during the transition. A deadline extension does not make it sensible to defer inventory, architecture decisions, logging, data provenance, testing, or contract access.
High-risk deployer requirements
Depending on the system and context, deployers must:
- follow instructions for use;
- assign competent natural persons to human oversight;
- ensure relevant input data is appropriate and sufficiently representative where under their control;
- monitor operation and act on risk or incidents;
- keep automatically generated logs under their control for the required period;
- support worker information duties where applicable;
- complete a fundamental-rights impact assessment where Article 27 applies; and
- cooperate with authorities.
GDPR duties remain separate. A DPIA may be required for high-risk personal-data processing, and Article 22 restrictions on certain solely automated decisions may also be relevant.
General compliance checklist
- Inventory systems and models, including embedded and third-party AI.
- Map entities, geographies, output locations, and operator roles.
- Record intended purpose, actual use, affected people, and system version.
- Complete the Article 5 prohibited-practice screen.
- Assess Article 6(1), Article 6(2), Annex I, and Annex III.
- Assess Article 50 and implement current transparency measures.
- Identify GPAI roles and transition provisions.
- Map GDPR, consumer, employment, accessibility, copyright, cybersecurity, and product law.
- Assign owners, controls, evidence, and review triggers.
- Put change clauses and cooperation duties into AI contracts.
- Test human oversight, incident escalation, and vendor change notification.
- Recheck the map when purpose, model, data, supplier, market, or law changes.
Frequently asked questions
Did the whole AI Act become enforceable on 2 August 2026?
No. That is the general application date, but the regulation has several earlier and later dates. The 2026 Omnibus moved the main high-risk Chapter III requirements to December 2027 or August 2028 depending on the Article 6 route.
Are chatbots automatically high-risk?
No. A chatbot may have Article 50 transparency duties. High-risk status depends on the intended purpose and the Article 6/Annex tests.
Does using a third-party model make us only a deployer?
Not always. Branding, substantial modification, changed intended purpose, integration into a product, or placing a system on the market can affect the role analysis.
Does the AI Act replace GDPR?
No. Personal-data processing must independently comply with GDPR and applicable ePrivacy and sectoral rules.
Sources and review
This guide was substantively reviewed on 8 August 2026 against the current legal text and Commission implementation material.
- Regulation (EU) 2024/1689 — Artificial Intelligence Act
- Regulation (EU) 2026/1744 — Digital Omnibus on AI
- European Commission — current AI Act application timeline
- European Commission — Article 50 transparency FAQ
- European Commission — GPAI provider guidelines
For a system inventory, operator-role map, classification record, and prioritised evidence plan, see Vision Compliance's AI compliance service.
Robert Lozo, mag. iur., is a Partner at Vision Compliance specializing in EU regulatory compliance. He advises organizations on GDPR, NIS2, AI Act, and financial regulation, delivering audit-ready documentation and compliance roadmaps across regulated industries.