What the EU AI Act Requires, and When It Applies
The EU AI Act’s most expensive deadline moved. A package known as the Digital Omnibus pushed the high-risk obligations that were due on 2 August 2026 out to December 2027 and August 2028, while leaving the transparency rules and the general-purpose AI regime broadly where they were. If your compliance plan was built against the original Article 113 timeline, it is now wrong in both directions: some things are later than you think, and some are already live.
The four risk tiers
The Act regulates uses, not technologies. The European Commission’s own regulatory framework page, last updated in August 2026, sorts systems into four bands.
- Unacceptable risk. Nine banned practices, including harmful manipulation and deception, social scoring, and AI that generates non-consensual sexually explicit material. Eight of the nine have applied since February 2025; the ninth follows in December 2026.
- High risk. Systems posing serious risks to health, safety or fundamental rights, covering employment, education, credit scoring, biometrics and critical infrastructure. These carry the heavy obligations: risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness, conformity assessment.
- Transparency risk. Systems where the duty is disclosure rather than engineering: chatbots that must say they are chatbots, synthetic content that must be machine-detectable. Live since August 2026.
- Minimal risk. Everything else, which the Commission notes is the vast majority of AI in use in the EU today, and which faces no requirements.
The timeline as it now stands
The Digital Omnibus reached provisional political agreement on 6 May 2026 and was confirmed by member states the following week, as Gibson Dunn set out at the time. It entered into force on 27 July 2026 following publication in the Official Journal, according to Usercentrics’ tracker, and the Commission’s own dates now reflect the new schedule.
| Date | What applies |
|---|---|
| 1 August 2024 | Regulation enters into force; no obligations yet |
| 2 February 2025 | Prohibited practices and the AI literacy duty |
| 2 August 2025 | GPAI model obligations, governance, notified bodies, confidentiality; member states designate authorities and set penalties |
| 2 August 2026 | Article 50 transparency obligations |
| 2 December 2026 | Article 50(2) watermarking grace period ends for generative systems already on the market before 2 August 2026; prohibition on non-consensual intimate imagery and CSAM applies |
| 2 August 2027 | GPAI models placed on the market before 2 August 2025 must be compliant |
| 2 December 2027 | High-risk requirements for standalone Annex III systems (moved from 2 August 2026) |
| 2 August 2028 | High-risk requirements for Annex I systems, meaning AI embedded in products already covered by EU product-safety law (moved from 2 August 2027) |
Two details are easy to misread. The deferral applies to the high-risk obligations, not to the definition of high risk. A system that is Annex III today is still Annex III, you simply have longer to document it. And Article 50 was not deferred. If you ship a chatbot, a voice clone, a deepfake tool or anything that emits synthetic media into the EU, your disclosure and marking duties are already in effect, with only a four-month grace on watermarking for systems that predate August 2026.
Provider or deployer, and why it decides your budget
The Act assigns obligations by role, and most startups are one role for their own model and a different role for everyone else’s. Article 3 defines a provider as a person or body “that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge.”
A deployer is “a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity.” — AI Act, Article 3(4)
The trademark clause is the trap. Wrap a third-party model in your product, put your name on it, and you are the provider of that AI system with the full provider obligation set, not a deployer. Article 3 also defines importers, who must be established in the Union and who place on the market a system bearing a third-country entity’s name, and distributors, who make a system available without being provider or importer.
What GPAI model providers owe
If you train and release a general-purpose model, Article 53 requires four things: technical documentation covering training, testing and evaluation results per Annex XI, kept current and available to the AI Office on request; information for downstream providers per Annex XII so they can understand the model’s capabilities and limitations; a policy to comply with Union copyright law, specifically respecting rights reservations made under Article 4(3) of Directive (EU) 2019/790; and a publicly available “sufficiently detailed summary about the content used for training,” on the AI Office’s template.
There is a genuine open-source carve-out. The documentation and downstream-information duties do not apply to models released under a free and open-source licence with publicly available parameters and architecture, but that exemption explicitly does not extend to models with systemic risk, and the copyright policy and training-content summary survive it.
The systemic-risk threshold
Article 51 presumes a model has high-impact capabilities when “the cumulative amount of computation used for its training measured in floating point operations is greater than 10^25.” Article 52 then requires the provider to notify the Commission “without delay and in any event within two weeks after that requirement is met.” For the overwhelming majority of startups this threshold is irrelevant, sitting well above what a Series A training budget reaches. But if you are fine-tuning at scale, the number is cumulative training compute, so track it.
The practical compliance route is the General-Purpose AI Code of Practice, published on 10 July 2025 with chapters on transparency, copyright, and safety and security. It is voluntary, but the Commission treats adherence as an adequate means of demonstrating compliance, with lower administrative burden and more legal certainty than building your own case. Twenty-one companies had signed as of the page’s July 2026 update, including Amazon, Anthropic, Cohere, Google, IBM, Microsoft, Mistral AI, OpenAI and ServiceNow, with xAI signing only the safety and security chapter.
Penalties
Article 99 sets three tiers, each expressed as a euro figure or a share of worldwide annual turnover, whichever is higher.
- Breaching the Article 5 prohibitions: up to €35 million or 7% of worldwide annual turnover.
- Breaching operator obligations, meaning provider duties under Article 16, authorised representatives, importers, distributors, deployer duties under Article 26, notified body requirements, and the Article 50 transparency duties: up to €15 million or 3%.
- Supplying incorrect, incomplete or misleading information to notified bodies or national authorities: up to €7.5 million or 1%.
SMEs, including startups, get the inverse of the whichever-is-higher rule: for them the cap is whichever of the euro figure and the percentage is lower. That is a meaningful concession for a company with revenue under €10 million, and no help at all once you scale.
What a non-EU startup actually has to do
Being incorporated in Toronto, Delaware or Bangalore does not put you outside the Act. Article 2(1)(a) covers providers placing AI systems or GPAI models on the Union market “irrespective of whether those providers are established or located within the Union or in a third country.” Article 2(1)(c) reaches further, covering third-country providers and deployers “where the output produced by the AI system is used in the Union.” Serving EU customers from Canadian infrastructure is squarely in scope.
- Inventory your systems and pick a role for each. Write down, per system, whether you are provider, deployer, importer or distributor, and whether you have put your own name on someone else’s model.
- Classify against Annex III honestly. Recruitment screening, credit decisions, education assessment, biometric identification and workplace monitoring are the categories that catch B2B SaaS companies who think they sell productivity tools.
- Ship the Article 50 disclosures now. These are live, they are cheap, and they are the most visible thing a regulator or a customer’s procurement team will check.
- Appoint an authorised representative in the Union if you are a third-country provider of a high-risk system. Article 22(1) requires the appointment by written mandate prior to making the system available on the Union market.
- Start the technical file even though the deadline moved. Risk management, data governance and logging are engineering work, not paperwork, and retrofitting them into a shipped product is where the real cost lands.
- Do the AI literacy duty. It has applied since February 2025, it applies to providers and deployers alike, and it is the cheapest box on this list to tick.
What to put in this quarter’s plan
Treat 2 December 2027 as an engineering deadline and 2 August 2026 as a shipping one that has already passed. The transparency obligations and the AI literacy duty are live now, the GPAI regime has been live for over a year, and the high-risk documentation burden is eighteen months out but only if the omnibus schedule holds. Given that the Commission has already deferred these dates once under industry pressure, build the technical file as if it will not be deferred again, and re-check the Commission’s own timeline page before you commit a roadmap, because as of September 2026 this is a regulation that has moved twice.
Sources
- European Commission — AI Act regulatory framework
- EU Artificial Intelligence Act — Implementation Timeline
- AI Act Article 3 — Definitions
- AI Act Article 53 — Obligations for providers of general-purpose AI models
- AI Act Article 99 — Penalties
- European Commission — The General-Purpose AI Code of Practice
- Gibson Dunn — EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes
- Usercentrics — EU AI Act Deal: Digital Omnibus Now in Force



Post Comment