01
In one minute
The AI Act has applied in stages since February 2025. In July 2026 the Digital Omnibus amended it: the high-risk rules come later, AI literacy became a duty to take measures, and two new bans were added. For most companies three things apply today: the prohibitions, AI literacy and, wherever people meet AI, transparency.
Most companies are deployers, and most of their systems carry minimal or limited risk. The work is knowing which systems you have, which role you hold for each, and which of them sit in a high-risk area before December 2027.
- The law
- Regulation (EU) 2024/1689In force since 1 August 2024.1
- The amendment
- Regulation (EU) 2026/1744Digital Omnibus on AI of 8 July 2026. Published 24 July 2026, in force 27 July 2026.23
- Applies now
- Bans, literacy, GPAI, Art. 50Since 2 February 2025, 2 August 2025 and 2 August 2026.4
- Next date
- 2 December 2026New bans on sexual deepfakes and child sexual abuse material. Marking for generative systems already on the market.56
- High-risk
- 2 Dec 2027 · 2 Aug 2028Annex III areas first, then AI in regulated products under Annex I.3
- Highest fine
- 35 million euros or 7 %Of worldwide annual turnover, whichever is higher, for prohibited practices.7
02
Does it apply to you?
The Act covers AI systems and general-purpose AI models that are placed on the EU market, put into service or used in the EU. It also reaches providers and deployers outside the EU when the output of their system is used here. It does not cover purely personal, non-professional use, military, defence and national security uses, or AI developed and used only for scientific research.1
Your duties follow your role, and the role is decided per system, not per company. The same bank can be the deployer of a chatbot it buys and the provider of a scoring model it builds.
Develops an AI system or model, or has it developed, and places it on the market or puts it into service under its own name or trademark, paid or free.
- Typical
- You sell a CV screening tool. Or you build one for your own HR team: putting it into service for your own use counts too.
- Duties
- Most duties for high-risk systems (Art. 16 ff.), the AI disclosure for chatbots and the marking of generated content (Art. 50(1), (2)).
Uses an AI system under its authority, except in a purely personal, non-professional activity.
- Typical
- Your support team uses a bought chatbot. Your staff draft with a copilot.
- Duties
- For high-risk: use as instructed, human oversight, relevant input data, logs, informing workers (Art. 26). For everyone: disclose deepfakes and emotion recognition (Art. 50(3), (4)).
Located or established in the EU, and places on the market an AI system that bears the name or trademark of a person established outside the EU.
- Typical
- You bring a US vendor’s high-risk system onto the EU market under the vendor’s brand.
- Duties
- Before placing a high-risk system on the market: check the conformity assessment, the documentation, the CE marking and the authorised representative (Art. 23).
Any other person in the supply chain, other than the provider or the importer, that makes an AI system available on the EU market.
- Typical
- A reseller or marketplace that passes on a system already on the EU market.
- Duties
- Check CE marking, declaration of conformity and instructions; hold back a high-risk system you have reason to think does not conform (Art. 24).
Providers of high-risk systems and of general-purpose models established outside the EU need an authorised representative in the EU (Art. 22, Art. 54).
03
Four risk classes
The Act sorts by use, not by technology. The same model can be minimal risk in a marketing tool and high-risk in a hiring tool. Classify every use case and write down why.
- ProhibitedArt. 5since 2 Feb 2025
Manipulation and exploitation of vulnerabilities that cause significant harm; social scoring; predicting crimes from profiling alone; untargeted scraping of facial images for databases; emotion recognition at work and in education, except for medical or safety reasons; biometric categorisation to infer sensitive traits; real-time remote biometric identification in public spaces for law enforcement, with narrow exceptions. The Omnibus adds two bans from 2 December 2026: AI that generates non-consensual intimate or sexually explicit images, video or audio of identifiable people, and AI that generates child sexual abuse material.154
- High-riskArt. 62 Dec 2027 · 2 Aug 2028
Two routes. Annex I: the AI is a safety component of a product, or is the product, under EU product safety law that requires a third-party conformity assessment, such as machinery, medical devices, toys or lifts. From 2 August 2028. Annex III: the AI is used in one of eight areas: biometrics; critical infrastructure; education; employment and worker management; access to essential private and public services, including credit scoring of people and pricing of life and health insurance; law enforcement; migration and border control; justice and democratic processes. From 2 December 2027.13The exit in Art. 6(3). An Annex III system is not high-risk if it poses no significant risk of harm, for example because it only performs a narrow procedural task, improves the result of a finished human activity, detects decision patterns without replacing human assessment, or does preparatory work. It never applies when the system profiles people. The provider documents the assessment before go-live (Art. 6(4)) and registers the system; the Omnibus kept that registration but reduced what goes into it.8
- TransparencyArt. 50since 2 Aug 2026
On top of any class. Chatbots and voice agents tell people they are talking to an AI, unless it is obvious (provider). Generated audio, images, video and text are marked in a machine-readable way (provider; systems already on the market before 2 August 2026 have until 2 December 2026). People exposed to emotion recognition or biometric categorisation are informed (deployer). Deepfakes, and AI-generated text published to inform the public, are disclosed unless a human reviewed the text and someone holds editorial responsibility (deployer). The Commission published final guidelines on Art. 50 on 20 July 2026.169
- Minimal—no date
Everything else: spam filters, recommendations, most internal assistants. No specific duties beyond AI literacy (Art. 4). Voluntary codes of conduct are encouraged (Art. 95).
04
General-purpose AI models
A general-purpose AI model can competently perform a wide range of distinct tasks and be built into many downstream systems, like the large language models behind today’s assistants. The Commission’s guidelines take training compute above 10²³ FLOP, together with the ability to generate language, images or video, as the indicative criterion.10
Their providers have had duties since 2 August 2025 (Art. 53): technical documentation, information for downstream providers, a copyright policy and a public summary of the training content. Models with systemic risk, presumed above 10²⁵ FLOP of training compute, add model evaluations, adversarial testing, serious-incident reporting and cybersecurity (Art. 55). Models placed on the market before 2 August 2025 have until 2 August 2027. Since 2 August 2026 the Commission can enforce these duties, including with fines.511
05
The dates, drawn to scale
One row per obligation. A filled dot is the date it applies from, a diamond a later step, a hollow dot the date the Omnibus moved it from. The orange line is today.
- AI Act in forceReg. (EU) 2024/16891 August 2024
- ProhibitionsArt. 5since 2 Feb 2025 · two new bans from 2 Dec 2026
- AI literacyArt. 4since 2 Feb 2025 · reworded 27 Jul 2026
- General-purpose modelsArt. 53–55since 2 Aug 2025 · fines from 2 Aug 2026 · older models 2 Aug 2027
- TransparencyArt. 50since 2 Aug 2026 · marking for systems already on the market 2 Dec 2026
- High-risk, Annex IIIArt. 6(2)from 2 Dec 2027 · was 2 Aug 2026
- High-risk, Annex IArt. 6(1)from 2 Aug 2028 · was 2 Aug 2027
Two things stand out. As of September 2026 the first high-risk date is about fourteen months away, and for a system that is already live, adding risk management and logging is a project, not a sprint. And December 2026 is a real deadline, not only a detail about marking.
06
What the Omnibus changed
- 01
- 02
- 03
- 04
- 05Relief for small mid-caps
Simplified documentation, proportionate quality management, priority access to sandboxes and lower fine caps, so far for SMEs, now also for small mid-caps, as defined in Recommendation (EU) 2025/1099: fewer than 750 employees and, in short, up to 150 million euros turnover.126
- 06Lighter registration
Annex III systems that the provider assesses as not high-risk under Art. 6(3) are still registered, with less information.8
- 07Bias detection
Processing special categories of personal data to detect and correct bias is allowed beyond high-risk providers, where strictly necessary and with safeguards such as pseudonymisation, access controls and timely deletion.12
- 08A stronger AI Office
Exclusive supervision of AI systems built on a provider’s own general-purpose model, and of AI in very large online platforms and search engines.12
- 09
What did not change: the prohibitions of 2025, the duties for general-purpose models, the date for Art. 50 and the maximum fines.
07
Fines and who enforces
- Prohibited practicesArt. 99(3)35 million euros or 7 %
- Most other duties: providers, importers, distributors, deployers, transparencyArt. 99(4)15 million euros or 3 %
- Incorrect or misleading information to authoritiesArt. 99(5)7.5 million euros or 1 %
- General-purpose model providers, fined by the CommissionArt. 10115 million euros or 3 %
Who enforces: national market surveillance authorities for AI systems, the AI Office at the Commission for general-purpose models. In Germany the KI-MIG, in force since 29 July 2026, makes the Bundesnetzagentur the market surveillance authority, contact point and complaints office; it also runs an AI service desk for companies. For regulated financial institutions, their financial supervisor is the authority for high-risk AI linked to their services (Art. 74(6)).151
Fines are the ceiling. What you control is whether you can show the inventory, the classification and the reasons behind it when someone asks.
08
What to do now
Fourteen steps, filtered by role. Tick what is done. Add the rest to your void and it travels with your brief.
0 / 14 done
09
Questions
We only use ChatGPT and Copilot. Does the Act apply to us?
Yes, as a deployer. For general assistants that usually means AI literacy measures and, if you publish AI-generated content, the Art. 50 disclosures. The model duties stay with the vendor.
Is our customer chatbot high-risk?
Usually not. It has a transparency duty: people must know they are talking to an AI. It becomes high-risk when it decides in an Annex III area, for example on credit or on access to public benefits.
The high-risk rules moved to 2027. Can we wait?
With the paperwork, a little. With the design, no. Risk management, data governance, logging and human oversight are architecture; retrofitting them in 2027 costs more than building them in now. And the prohibitions, literacy and transparency apply already.
Do we need an AI officer?
The Act does not require one, and the Bundesnetzagentur says so explicitly for AI literacy. You do need someone who owns the inventory and the classification. Call the role what you like.16
Does ISO 42001 make us compliant?
No. It helps you produce the evidence, but the Act is assessed per system, against the law. The comparison
Not legal advice Our reading of the law as of September 2026. It is not legal advice. For a binding view of your case, ask counsel.