Hashlogics
Answers

Is your AI build EU AI Act compliant?

Most teams are checking the wrong deadline. The one that already passed is the one that probably applies to you.

Answered in short

6 things that decide this

  1. 01Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026. It amended Article 113 of the AI Act and moved the high-risk deadlines back.
  2. 02High-risk obligations for Annex III systems now apply from 2 December 2027, and for Annex I product-safety systems from 2 August 2028.
  3. 03Article 50 transparency duties were not delayed. They sit in Chapter IV rather than Chapter III, and they applied from 2 August 2026.
  4. 04Systems generating synthetic content that were on the market before 2 August 2026 have until 2 December 2026 to meet the marking duty in Article 50(2).
  5. 05The Act reaches a provider based outside the EU. Ship into the EU market and you are in scope, wherever you sit.
  6. 06Banned practices under Article 5 have applied since 2 February 2025. They carry the highest penalty tier.
Why the usual answer is out of date

The timeline changed two weeks ago

Almost every guide still says high-risk obligations begin on 2 August 2026. That was correct until very recently and it is no longer the law.

The Digital Omnibus on AI was published in the Official Journal on 24 July 2026. It entered into force on 27 July. Its amended Article 113 sets two new dates. High-risk systems under Article 6(2) and Annex III now start on 2 December 2027. Those under Article 6(1) and Annex I start on 2 August 2028. Recital 40 blames standards, common specifications and national authorities arriving later than planned.

This matters, because several widely used AI Act reference sites still serve the original 2024 text. Check a date against a summary rather than the Official Journal, and your plan rests on a deadline that no longer exists.

Verified against the Official Journal

What applies, and from when

Checked 11 August 2026 against the OJ text of Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689, and the Commission's regulatory framework page.

ObligationApplies fromChanged by the Omnibus?
Entry into force of the AI Act1 August 2024No
Prohibited practices, Article 52 February 2025No
General-purpose AI model obligations2 August 2025No
General application, including Article 50 transparency2 August 2026No
Article 50(2) marking, for systems already on the market2 December 2026New grandfathering window
High-risk, Article 6(2) and Annex III2 December 2027Yes, moved from 2 August 2026
High-risk, Article 6(1) and Annex I2 August 2028Yes, moved from 2 August 2027
The question to answer first

Are you the provider, or is your client?

Article 3(3) says a provider is whoever develops an AI system, or has one built, and puts it on the market under its own name or trademark. That last phrase carries most of the weight.

Build a system your client ships under their own brand, and the client is usually the provider. A deployer, under Article 3(4), is whoever uses the system under their authority at work. Article 25 can shift provider status to whoever puts their name on a system or makes major changes to it. So this is a contract question as much as a technical one.

Geography does not get you out of it. Article 2(1)(a) applies to providers whether they are established in the Union or in a third country. Shipping into the EU market is what matters, not where your engineers sit.

  • 01Settle the provider and deployer roles in the contract before you build. The duties follow the role, not the code.
  • 02Article 6(3) can take an Annex III system out of high-risk where it does narrow procedural or preparatory work and does not sway the outcome. A system that profiles people is always high-risk.
Working out what binds your buildLive
  1. Prohibited?Article 5. In force since February 2025.
  2. Your roleProvider or deployer, under Article 3.
  3. Annex III?If yes, check the Article 6(3) filter.
  4. Profiling?Then always high-risk. No filter.
  5. Chat or synthetic output?Article 50 applies now.
  6. Document itBefore the December 2027 date, not on it.

The fifth station is the one live today. A chatbot or anything generating synthetic content already has transparency duties, whatever your high-risk answer turns out to be.

Questions, answered
01Does a chatbot make us high-risk?

Not on its own. A customer-facing assistant usually falls under Article 50 transparency instead. High-risk status comes from the uses listed in Annex III, or from Annex I product safety. Where that same assistant screens job applicants or decides who gets a service, the Annex III question becomes live.

02What does the Article 6(3) filter actually let us out of?

It takes an Annex III system out of high-risk where it poses no significant risk to health, safety or fundamental rights. That includes where it does not materially sway a decision. The conditions cover a narrow procedural task, improving finished human work, spotting patterns without replacing human judgement, or doing preparatory work. Profiling of people is excluded from the filter.

03We are outside the EU. Does the Act reach us?

Yes, where you place a system on the EU market or put it into service there. Article 2(1)(a) covers providers based in the Union or in a third country. What triggers it is your customers, not where you are registered.

04What should we build now, given the 2027 date?

The high-risk rules ask for what good engineering wants anyway. Recorded decisions. Runs you can trace. Documented data sources. Human oversight where the outcome matters. Building those now costs less than adding them in 2027. They also make an Article 6(3) argument credible rather than merely asserted.

Verified
Start

Anyone can ship the agent. We answer the pager.

We build AI agents and automation, then stay on under an agreed service level. A senior engineer reads every brief, and your call gets scheduled within 24 hours.

What happens next

  1. 01

    You send a brief or book a call

    Two minutes, whichever you prefer.

  2. 02

    A senior engineer replies within 24 hours

    Not a sales rep.

  3. 03

    Honest scoping, in writing

    And if we’re not the right fit, we say so.

Abdul Basit, CEO of Hashlogics

“I started Hashlogics because too many teams ship a demo, get paid, and disappear. We build to a standard we’d run ourselves — and we stay to keep it running.”

Abdul Basit · CEO · a direct line

Not ready to talk? Take the checklist.

12 questions to ask any AI agency before you sign. They separate a demo shop from a team that ships to production.

Get the checklist

Free · no newsletter