Is your AI build EU AI Act compliant?
Most teams are checking the wrong deadline. The one that already passed is the one that probably applies to you.
Answered in short
6 things that decide this
- 01Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026. It amended Article 113 of the AI Act and moved the high-risk deadlines back.
- 02High-risk obligations for Annex III systems now apply from 2 December 2027, and for Annex I product-safety systems from 2 August 2028.
- 03Article 50 transparency duties were not delayed. They sit in Chapter IV rather than Chapter III, and they applied from 2 August 2026.
- 04Systems generating synthetic content that were on the market before 2 August 2026 have until 2 December 2026 to meet the marking duty in Article 50(2).
- 05The Act reaches a provider based outside the EU. Ship into the EU market and you are in scope, wherever you sit.
- 06Banned practices under Article 5 have applied since 2 February 2025. They carry the highest penalty tier.
The timeline changed two weeks ago
Almost every guide still says high-risk obligations begin on 2 August 2026. That was correct until very recently and it is no longer the law.
The Digital Omnibus on AI was published in the Official Journal on 24 July 2026. It entered into force on 27 July. Its amended Article 113 sets two new dates. High-risk systems under Article 6(2) and Annex III now start on 2 December 2027. Those under Article 6(1) and Annex I start on 2 August 2028. Recital 40 blames standards, common specifications and national authorities arriving later than planned.
This matters, because several widely used AI Act reference sites still serve the original 2024 text. Check a date against a summary rather than the Official Journal, and your plan rests on a deadline that no longer exists.
What applies, and from when
Checked 11 August 2026 against the OJ text of Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689, and the Commission's regulatory framework page.
| Obligation | Applies from | Changed by the Omnibus? |
|---|---|---|
| Entry into force of the AI Act | 1 August 2024 | No |
| Prohibited practices, Article 5 | 2 February 2025 | No |
| General-purpose AI model obligations | 2 August 2025 | No |
| General application, including Article 50 transparency | 2 August 2026 | No |
| Article 50(2) marking, for systems already on the market | 2 December 2026 | New grandfathering window |
| High-risk, Article 6(2) and Annex III | 2 December 2027 | Yes, moved from 2 August 2026 |
| High-risk, Article 6(1) and Annex I | 2 August 2028 | Yes, moved from 2 August 2027 |
Are you the provider, or is your client?
Article 3(3) says a provider is whoever develops an AI system, or has one built, and puts it on the market under its own name or trademark. That last phrase carries most of the weight.
Build a system your client ships under their own brand, and the client is usually the provider. A deployer, under Article 3(4), is whoever uses the system under their authority at work. Article 25 can shift provider status to whoever puts their name on a system or makes major changes to it. So this is a contract question as much as a technical one.
Geography does not get you out of it. Article 2(1)(a) applies to providers whether they are established in the Union or in a third country. Shipping into the EU market is what matters, not where your engineers sit.
- 01Settle the provider and deployer roles in the contract before you build. The duties follow the role, not the code.
- 02Article 6(3) can take an Annex III system out of high-risk where it does narrow procedural or preparatory work and does not sway the outcome. A system that profiles people is always high-risk.
- Prohibited?Article 5. In force since February 2025.
- Your roleProvider or deployer, under Article 3.
- Annex III?If yes, check the Article 6(3) filter.
- Profiling?Then always high-risk. No filter.
- Chat or synthetic output?Article 50 applies now.
- Document itBefore the December 2027 date, not on it.
The fifth station is the one live today. A chatbot or anything generating synthetic content already has transparency duties, whatever your high-risk answer turns out to be.
Systems built to a documented standard
Related questions
01Does a chatbot make us high-risk?
Not on its own. A customer-facing assistant usually falls under Article 50 transparency instead. High-risk status comes from the uses listed in Annex III, or from Annex I product safety. Where that same assistant screens job applicants or decides who gets a service, the Annex III question becomes live.
02What does the Article 6(3) filter actually let us out of?
It takes an Annex III system out of high-risk where it poses no significant risk to health, safety or fundamental rights. That includes where it does not materially sway a decision. The conditions cover a narrow procedural task, improving finished human work, spotting patterns without replacing human judgement, or doing preparatory work. Profiling of people is excluded from the filter.
03We are outside the EU. Does the Act reach us?
Yes, where you place a system on the EU market or put it into service there. Article 2(1)(a) covers providers based in the Union or in a third country. What triggers it is your customers, not where you are registered.
04What should we build now, given the 2027 date?
The high-risk rules ask for what good engineering wants anyway. Recorded decisions. Runs you can trace. Documented data sources. Human oversight where the outcome matters. Building those now costs less than adding them in 2027. They also make an Article 6(3) argument credible rather than merely asserted.

