EU AI Act Compliance Checklist for Deployers: Deadlines Mapped Through 2028
In short
Regulation (EU) 2026/1744, in force since 27 July 2026, moved the high-risk deployer duties in Articles 26 and 27 to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I products. Prohibitions, AI literacy, penalties and the Article 50 transparency duties already apply, and the next fixed date for deployers is 2 December 2026.
If your organization uses AI systems under its own authority in the EU, whether that means screening candidates, scoring credit or publishing AI-drafted content, you are a deployer under Regulation (EU) 2024/1689. As of 30 September 2026, three sets of duties already bind you: the Article 5 prohibitions and the Article 4 AI literacy duty (since 2 February 2025), the penalty regime (since 2 August 2025), and the Article 50 transparency duties (since 2 August 2026). Two new prohibitions follow on 2 December 2026. The Article 26 and 27 high-risk deployer obligations were postponed by the Digital Omnibus on AI, Regulation (EU) 2026/1744, to 2 December 2027 for Annex III systems and 2 August 2028 for AI embedded in regulated products.
Both the "the AI Act is delayed, relax" reading and the "everything hits at once" panic are wrong. The omnibus is not a compliance holiday for deployers. Three sets of duties bind you now, one more arrives in two months, and the fourteen months of runway to December 2027 is roughly what the slow work in Articles 26 and 27 takes: system inventory, oversight design, log-retention plumbing and fundamental rights impact assessments do not compress into one quarter.
The checklist below has five deadline buckets and twenty obligations, each with a Monday-morning action and an evidence column. Every date was checked on 30 September 2026 against the Official Journal text and the European Commission's own pages, both listed in the sources.
Four questions decide whether this checklist applies to you
Work through these before the tables, because the answers change which sections bind you.
- Do we use AI systems under our authority in the course of a professional activity in the EU? If yes, you are a deployer (Article 3(4)). "Under our authority" is the operative phrase: a vendor's chatbot embedded in your hiring workflow is your deployment even though you did not build it.
- Do any of those systems fall in an Annex III category (employment, credit scoring, education, essential services, biometrics, law enforcement, migration, justice)? If yes, the December 2027 bucket is your main event, and classification deserves its own analysis.
- Have we rebranded, substantially modified or repurposed any AI system? If yes, Article 25 may have made you a provider. The section on Article 25 below covers the three triggers.
- Are we a public body, a private entity providing public services, or a deployer of credit-scoring or life and health insurance risk-assessment systems? If yes, the Article 27 fundamental rights impact assessment applies to you specifically, not to all high-risk deployers.
If you answered no to question 1, you may still be in scope as a provider, importer or distributor. This article covers deployers only.
The deployer calendar has five dates behind it and six ahead
Get the omnibus status right, because getting it wrong is the fastest way to embarrass yourself in front of a board. The European Commission proposed the Digital Omnibus on AI on 19 November 2025. The co-legislators reached a trilogue agreement on 7 May 2026, Parliament's plenary approved it on 16 June 2026, the Council adopted it on 29 June 2026, and it was signed on 8 July 2026 (European Parliament Legislative Train). It was published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744 and entered into force on the third day after publication, 27 July 2026 (EUR-Lex; European Commission).
One correction to the way this is usually reported: do not say "the AI Act was delayed." The omnibus set new fixed dates for the two high-risk tranches and left everything else on schedule. It also reworded Article 4, added two prohibitions and extended the lower-of fine rule to small mid-cap companies for the two lower fine tiers.
| Date | What applies | Deployer relevance | Status on 30 Sep 2026 |
|---|---|---|---|
| 1 Aug 2024 | Entry into force (Reg. 2024/1689, Art 113) | Clock starts | In force |
| 2 Feb 2025 | Chapters I and II: Art 4 AI literacy and Art 5 prohibitions | Direct: both bind deployers | Applies; Art 4 reworded from 27 Jul 2026 |
| 2 Aug 2025 | General-purpose AI obligations, governance, penalties (Chapter XII except Art 101) | Indirect: model providers are regulated and the fining regime is live | Applies |
| 27 Jul 2026 | Regulation (EU) 2026/1744 (Digital Omnibus on AI) enters into force | Sets the dates below | In force |
| 2 Aug 2026 | General application, including Art 50 transparency; enforcement by national authorities and the AI Office | Direct: Art 50(3) and 50(4) are deployer duties | Applies |
| 2 Dec 2026 | New Art 5(1)(ba) and (bb) prohibitions; providers of generative systems already on the market must meet Art 50(2) marking | Direct for the prohibitions, indirect for marking | Ahead |
| 2 Aug 2027 | Legacy general-purpose AI models must comply (Art 111(3)); national sandboxes operational (Art 57(1)) | Indirect: vendor diligence | Ahead |
| 2 Dec 2027 | Chapter III Sections 1 to 3 for Annex III systems, including deployer Arts 26 and 27 (moved from 2 Aug 2026) | Direct: the core deployer workload | Ahead |
| 2 Aug 2028 | Chapter III Sections 1 to 3 for Annex I products (moved from 2 Aug 2027) | Direct where AI sits in regulated products | Ahead |
| 2 Aug 2030 | Providers and deployers of high-risk systems intended for public authorities must comply (Art 111(2)) | Direct for public-sector deployers | Ahead |
| 31 Dec 2030 | AI components of Annex X large-scale IT systems placed on the market before 2 Aug 2027 (Art 111(1)) | Public-sector edge case | Ahead |
Sources for the table: Articles 111 and 113 of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, and the Commission's application timeline.
The deployer checklist sorts every obligation into five dated buckets
Deadlines are stated as of 30 September 2026. "Evidence to retain" is what a market surveillance authority, or your own auditor, could ask for. The canonical source throughout is Regulation (EU) 2024/1689 on EUR-Lex, read together with the amending Regulation (EU) 2026/1744.
Bucket 1: binding since 2 February 2025
| # | Obligation (plain language) | Legal basis | Which deployers | Deadline | Monday-morning action | Evidence to retain |
|---|---|---|---|---|---|---|
| 1 | Do not use prohibited AI practices: social scoring, untargeted scraping of facial images, emotion recognition in workplaces and schools, harmful manipulation and the other Article 5 categories | Art 5 | All | Applies since 2 Feb 2025; two more items from 2 Dec 2026 (bucket 4) | Screen the AI inventory against the Article 5 list and the Commission's guidelines on prohibited practices; retire or re-scope anything close to a prohibited use | Inventory record; dated legal memo per borderline system |
| 2 | Take measures to support the AI literacy of staff and other people who operate or use AI systems on your behalf, taking into account their knowledge, experience and the context of use | Art 4 (replaced by Reg. 2026/1744) | All | Applies since 2 Feb 2025; reworded from 27 Jul 2026 | Keep role-based training and log completions; cover the concrete failure modes of the tools people actually use | Curriculum, attendance records, refresh schedule |
Two notes for counsel. First, Article 4 was rewritten, not repealed. Deployers still "shall take measures to support the development of AI literacy," but the text now says the duty "does not require providers or deployers to guarantee any specific level of AI literacy of any individual," and the Commission and Member States take on a supporting role. Do not dismantle a training program on the strength of the softer wording. Second, treat literacy as a control: if your teams use language-model tools in regulated workflows, the training should cover their failure modes, the territory mapped in our analysis of LLM accuracy on regulatory text.
Bucket 2: binding since 2 August 2025
| # | Obligation (plain language) | Legal basis | Which deployers | Deadline | Monday-morning action | Evidence to retain |
|---|---|---|---|---|---|---|
| 3 | The penalty regime is live: Article 5 breaches carry the top fining tier today, not in 2027 | Art 99 | All | Applies since 2 Aug 2025 | Brief the board: prohibited-practice exposure is current, at up to EUR 35 million or 7% of turnover | Board minutes or risk committee paper |
| 4 | Know which general-purpose AI model sits under each chat and copilot tool, and what your vendor says about it. If you integrate such a model into a system you supply to others or under your own name, you may be a provider | Arts 25, 53, 111(3) | All using tools built on general-purpose models | Model obligations apply since 2 Aug 2025 (models placed on the market earlier: 2 Aug 2027) | Ask each vendor which model it uses and how it meets its AI Act duties; if you build on a model yourself, request the Article 53(1)(b) documentation and file it | Vendor statements, contract clauses, model documentation on file |
Article 53(1)(b) obliges model providers to make documentation available to providers of AI systems who integrate the model. A deployer that only uses a vendor's finished system should look to that vendor's instructions for use instead.
Bucket 3: binding since 2 August 2026, Article 50 transparency
Article 50 has applied since 2 August 2026, and it applies to in-scope systems regardless of when they were placed on the market, with one exception: providers of generative systems placed on the market before that date have until 2 December 2026 to meet the Article 50(2) marking duty (Article 111(4), bucket 4). Most coverage misses that Article 50(1) and 50(2), the chatbot disclosure and the machine-readable marking, are provider duties. Deployers own 50(3) and 50(4), and the timing rule in Article 50(5) is "at the latest at the time of the first interaction or exposure."
Two Commission documents now sit around the article. The Commission's guidelines on the transparency obligations were approved in content on 20 July 2026; the Commission will formally adopt them once all language versions exist, and says they apply only from then, so treat them as its stated reading in the meantime. The Code of Practice on Transparency of AI-generated Content was assessed by the Commission on 8 July 2026 as adequately covering Articles 50(2), 50(4) and 50(5), with the caveat that adherence "does not constitute conclusive evidence of compliance." The guidelines add a practical point for anyone who does not sign the code: they should be ready to show how their labeling meets the article by other means, and may face more detailed information requests.
| # | Obligation (plain language) | Legal basis | Which deployers | Deadline | Monday-morning action | Evidence to retain |
|---|---|---|---|---|---|---|
| 5 | Inform people exposed to an emotion recognition or biometric categorization system that it is operating, and process the personal data under the GDPR | Art 50(3), 50(5) | Deployers of those systems | Applies since 2 Aug 2026 | Place a clear notice at or before first exposure; the guidelines say it need not give the reasons for the system but must reach children too; align with GDPR notices | Notice text, placement photos or screenshots, rollout date |
| 6 | Disclose deep fakes: image, audio or video content that resembles existing people, objects, places, entities or events and would falsely appear authentic must be labeled as artificially generated or manipulated | Art 50(4), first subparagraph | Any deployer using AI to generate or manipulate such content for professional purposes | Applies since 2 Aug 2026 | Inventory workflows that produce synthetic media and add a disclosure step; for evidently artistic or satirical works the disclosure only has to avoid hampering the display | Workflow policy, sample disclosures |
| 7 | Disclose AI-generated or manipulated text published to inform the public on matters of public interest, unless it has had human review or editorial control and a person or entity holds editorial responsibility | Art 50(4), second subparagraph | Publishers of AI-drafted public-interest text | Applies since 2 Aug 2026 | Decide per channel: documented substantive review with a named responsible party, or a label | Editorial-review policy, review logs or labels |
| 8 | Know your enforcer: national market surveillance authorities and the AI Office began enforcing on 2 August 2026, and anyone with grounds may lodge a complaint | Arts 70, 74, 85 | All | Applies since 2 Aug 2026 | Identify your Member State authority or authorities; note that text generated before 2 August but published after it needs a label | One-page enforcement map |
On row 7, the guidelines are specific in ways that matter to compliance teams. Review must be substantive, with fact-checking as a minimum; spell-checking, an editorial policy on paper or cursory approval does not qualify; and a substantive AI edit after sign-off voids the exception. The person or function holding editorial responsibility should have its identity and contact details published somewhere easy to find. The examples include AI-manipulated corporate reports on a listed company's website containing investor information, which are in scope unless reviewed, while private correspondence, organization-internal communications and AI-manipulated compliance advice from a consultant to a client are not. Deep fakes generated or manipulated before 2 August 2026, and public-interest texts generated and published before that date, do not need retroactive labels, but text generated earlier and published on or after that date does.
Bucket 4: 2 December 2026, the omnibus's own deployer deadline
The omnibus is mostly read as a postponement. It also added two prohibitions to Article 5. Point (ba) covers AI systems that generate or manipulate realistic images, video or audio of an identifiable person's intimate parts or sexually explicit activities without that person's consent, and point (bb) covers material within the child sexual abuse directive. For deployers, Article 5(1a) narrows the prohibition to using a system "for the purpose of generating or manipulating" such material, while providers are caught where that is the intended purpose or the design makes it a foreseeable, reproducible outcome without adequate safeguards. Both apply from 2 December 2026.
| # | Obligation (plain language) | Legal basis | Which deployers | Deadline | Monday-morning action | Evidence to retain |
|---|---|---|---|---|---|---|
| 9 | Do not use an AI system for the purpose of generating or manipulating non-consensual intimate imagery or child sexual abuse material | Art 5(1)(ba), (bb), 5(1a), 5(1b) | All | 2 Dec 2026 | Add both items to the Article 5 screen and the acceptable-use policy; ask image and video vendors what safeguards block this use | Acceptable-use policy version history, vendor safeguard statements |
| 10 | Confirm that generative-AI vendors will meet machine-readable marking by the end of their transition | Art 50(2), Art 111(4) | Deployers of generative systems placed on the market before 2 Aug 2026 | 2 Dec 2026 | Ask each generative-AI vendor to confirm marking conformity in writing; it does not replace your own visible Article 50(4) labels | Vendor confirmations in the contract file |
Bucket 5: 2 December 2027, the Article 26 and 27 stack for Annex III systems
This is the bucket the omnibus moved from 2 August 2026, and it is where the real deployer workload lives: the paragraphs of Article 26, Article 27 for some deployers, and the Article 86 right to an explanation, which you should be ready to honor. Articles 26 and 27 sit in Chapter III, Section 3, so they follow the Annex III date. Article 86 sits outside Chapter III and formally applies from 2 August 2026, but it attaches to decisions based on Annex III high-risk systems, whose rules start on 2 December 2027, so it is grouped here.
| # | Obligation (plain language) | Legal basis | Which deployers | Deadline | Monday-morning action | Evidence to retain |
|---|---|---|---|---|---|---|
| 11 | Use each high-risk system in accordance with the provider's instructions for use | Art 26(1) | All Annex III deployers | 2 Dec 2027 | Obtain the instructions for every system and gap-check current practice against them | Instructions on file; conformance note |
| 12 | Assign human oversight to named people with the competence, training, authority and support to intervene | Art 26(2) | All Annex III deployers | 2 Dec 2027 | Name the oversight owner per system and write the intervention playbook | Oversight charter, training records |
| 13 | Where you control the input data, make sure it is relevant and sufficiently representative for the intended purpose | Art 26(4) | All Annex III deployers | 2 Dec 2027 | Document what data feeds each system and who owns its quality | Input-data specification per system |
| 14 | Monitor operation against the instructions for use; where the system may present a risk under Art 79(1), inform the provider or distributor and the market surveillance authority without undue delay and suspend use; report serious incidents to the provider first. Financial institutions meet the monitoring duty by complying with their internal governance rules under financial services law | Art 26(5) | All Annex III deployers | 2 Dec 2027 | Define monitoring metrics, an escalation path and a suspension rule; map them to your existing governance framework if you are a financial institution | Monitoring runbook, incident log (even if empty) |
| 15 | Keep automatically generated logs under your control for a period appropriate to the system's purpose and of at least six months, unless other Union or national law, in particular data protection law, provides otherwise; financial institutions keep them as part of the documentation required under financial services law | Art 26(6) | All Annex III deployers | 2 Dec 2027 | Confirm each vendor exposes logs and provision retention now: this is an engineering ticket, not a policy | Retention configuration, sample log extract |
| 16 | Before workplace use, inform workers' representatives and the affected workers | Art 26(7) | Employers | 2 Dec 2027 | Build worker notification into the deployment gate, before go-live | Notification records, works council minutes |
| 17 | Register the use in the EU database, and do not use a system that has not been registered | Art 26(8), Art 49 | Public-authority deployers and Union bodies | 2 Dec 2027 | List which deployments trigger registration and assign an owner | Registration confirmations |
| 18 | Use the provider's Article 13 information for the data protection impact assessment where one is required | Art 26(9) | Annex III deployers processing personal data | 2 Dec 2027 | Link each DPIA to the provider's documentation and refresh stale DPIAs | Updated DPIAs cross-referencing provider information |
| 19 | Inform affected people that a high-risk system is used in decisions about them, and be ready to explain the system's role and the main elements of the decision on request | Art 26(11), Art 86 | Annex III deployers making or supporting decisions about individuals (Art 86 excludes Annex III point 2) | 2 Dec 2027 | Draft the notice and a template explanation; test that you can reconstruct a decision | Notice text; sample explanation with decision trace |
| 20 | Assess the impact on fundamental rights before first use and notify the market surveillance authority of the results using the AI Office questionnaire template | Art 27 | Public-law bodies; private providers of public services; deployers of Annex III point 5(b) credit-scoring and 5(c) life and health insurance systems | 2 Dec 2027, before first use | Confirm whether you sit in the Article 27 categories; if so, put the assessment in the deployment gate | Assessment covering Art 27(1)(a) to (f); notification receipt |
Two scope notes that are easy to get wrong. The fundamental rights assessment is not a duty on all high-risk deployers: only the row 20 categories, with Annex III point 2 (critical infrastructure) excluded. And Article 26(10), the judicial-authorization rule for post-remote biometric identification, covers a narrow law-enforcement scenario, not commercial biometrics. Deployers also owe cooperation with authorities under Article 26(12), which needs no project of its own. One helpful change from the omnibus: Article 27(4) now lets you cross-reference, or copy in, the relevant sections of your data protection impact assessment inside the fundamental rights assessment, and the AI Office's questionnaire template, which already had to include an automated tool, must allow the same.
The long tail. AI embedded in Annex I regulated products follows on 2 August 2028. Under Article 111(2), high-risk systems already on the market when the high-risk rules start come into scope only on a significant design change, except systems intended for public authorities, which must comply by 2 August 2030 regardless. Components of the Annex X large-scale IT systems have until 31 December 2030. If you deploy a pre-existing system, log the version you run and watch vendor release notes: a "significant change" is what pulls you in.
December 2027 is the runway Article 26 actually needs
The tempting reading of the omnibus is "we got extra time, deprioritize." Walk through rows 11 to 20 and the arithmetic argues otherwise.
The prerequisite for everything is an AI system inventory you would sign your name to. Conformance with instructions for use means obtaining and reading provider documentation per system. Oversight design means naming and training people to intervene, which collides with real org charts. Log retention is an engineering ticket with vendor dependencies. Worker notification runs through works councils on their timetable. A fundamental rights assessment has six mandatory content elements and must be finished before first use. Each item has a lead time of months, and they serialize: you cannot design oversight for systems you have not inventoried.
For that work, across a hypothetical portfolio of ten Annex III systems in four Member States, fourteen months from today is approximately the critical path. Teams that treat December 2027 as a starting gun will find in mid-2027 that a vendor exposes no logs and the works council meets quarterly.
Article 25 quietly turns deployers into providers
The most expensive misclassification in the Act is believing you are a deployer when Article 25(1) has already made you a provider. Any distributor, importer, deployer or other third party is treated as the provider of a high-risk system, with the obligations of Article 16, in three circumstances:
- Rebranding. You put your name or trademark on a high-risk system already on the market, without prejudice to contractual arrangements that allocate the obligations otherwise. White-labeling a vendor's screening tool as "YourCo Talent Insights" is the canonical case.
- Substantial modification. You make a substantial modification to a high-risk system already on the market, in such a way that it remains high-risk.
- Repurposing into high-risk. You modify the intended purpose of an AI system that is not classified as high-risk, including a general-purpose system, so that it becomes high-risk. Wiring a general-purpose model into CV scoring is the pattern to watch: the model's provider never intended employment use, your integration created a high-risk system, and you are its provider.
The consequence is the full provider stack (risk management, technical documentation, conformity assessment, registration) on the provider timeline, not the deployer one. This is why scoping question 3 sits ahead of the checklist: every internal project that customizes a vendor system deserves an Article 25 review before anyone celebrates the lighter deployer duties. One institutional footnote from the omnibus: where the same provider, or its group, supplies both a general-purpose model and the system built on it, the AI Office is exclusively competent to supervise that system, with exceptions that include AI in Annex I products and financial institutions' systems covered by Article 74(6) (Article 75(1) as amended). That competence reaches deployers only when they are also the provider or part of the same undertaking.
Penalties top out at EUR 35 million or 7%, and deployer duties sit one tier down
The fining regime in Article 99 has applied since 2 August 2025, and the AI Office and national authorities began enforcing the Act on 2 August 2026. The tiers as enacted:
| Violation | Maximum fine | Deployer exposure |
|---|---|---|
| Prohibited practices (Art 5) | EUR 35 million or 7% of worldwide annual turnover, whichever is higher | Live today; includes the two new items from 2 Dec 2026 |
| Breach of operator obligations, including deployer duties (Art 26) and transparency (Art 50) | EUR 15 million or 3% | Art 50 from 2 Aug 2026; Art 26 from 2 Dec 2027 |
| Supplying incorrect, incomplete or misleading information to authorities | EUR 7.5 million or 1% | Any interaction with market surveillance |
SMEs pay the lower of the percentage or the fixed amount, which inverts the usual "whichever is higher" rule. Since 27 July 2026, Article 99(6a) gives small mid-cap companies the same treatment for the tiers in paragraphs 4 and 5. Enforcement began only on 2 August 2026, so precedent is thin. The mechanics are more predictable. National market surveillance authorities enforce against deployers, and first scrutiny will plausibly land on the oldest and cheapest duties to check, the Article 5 screens and the Article 50 notices, both visible from outside the organization.
Scope your AI systems this week and sequence the work before 2 December 2026
Run the four scoping questions this week and put your name on the answers. Then sequence the work:
- Close the Article 50 gaps now, since the duties already apply: label deepfakes, decide per channel whether public-interest text gets substantive review with a named responsible party or a label, and place notices for any emotion recognition or biometric categorization.
- Refresh the Article 5 screen with the two new items and update the acceptable-use policy before 2 December.
- Put the December 2026 vendor confirmations on a named owner's calendar.
- Start the Annex III inventory, because it gates everything in bucket 5.
If you also operate in crypto or US markets, the parallel clocks (our MiCA checklist covers one, and the US state privacy laws tracker another) argue for one consolidated register rather than per-regime spreadsheets. How compliance teams track this at scale is its own topic.
The checklist becomes a control when its rows turn into owned deadlines. Convert each applicable row into an entry in your obligations register (our register template works) with an owner, the deadline above and the evidence column as the artifact you attach when the row closes. RegWatch, my company, is built around that workflow: a watchlist on the AI Act and its national implementations produces findings on the schedule you set, triage turns relevant ones into alerts with cited reasoning, and an accepted alert converts to an obligation with an owner, a deadline and evidence. The mechanics are in how AI agents do regulatory compliance monitoring. For the impact-assessment discipline to hang off each change, start from our regulatory change impact assessment template. More of this regime lives in the AI compliance hub.
Whatever the tooling, check whether your deadline map changed with a dated change record when the omnibus reached the Official Journal on 24 July 2026, or silently went stale.
This article is general information, not legal advice.
Questions
When do EU AI Act obligations apply to deployers?
In stages. The Article 5 prohibitions and Article 4 AI literacy have applied since 2 February 2025, penalties and general-purpose AI rules since 2 August 2025, and Article 50 transparency since 2 August 2026. Two new prohibitions start on 2 December 2026. The Article 26 and 27 high-risk deployer duties apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I products.
Has the EU AI Act been delayed?
Only the high-risk tranches. Regulation (EU) 2026/1744, published on 24 July 2026 and in force since 27 July 2026, moved Annex III systems to 2 December 2027 and Annex I products to 2 August 2028. Prohibitions, AI literacy, general-purpose AI rules, penalties and Article 50 transparency kept their dates, and Article 50 has applied since 2 August 2026.
Which deployers must run a fundamental rights impact assessment?
Under Article 27, bodies governed by public law, private entities providing public services, and deployers of Annex III point 5(b) credit-scoring and point 5(c) life and health insurance systems. Critical-infrastructure systems under Annex III point 2 are excluded. The assessment comes before first use, and the results go to the market surveillance authority using the AI Office questionnaire template.
What fines can deployers face under the AI Act?
Up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices, up to EUR 15 million or 3% for breaching Article 26 or the Article 50 transparency duties, and up to EUR 7.5 million or 1% for misleading authorities. Whichever is higher applies, except that SMEs pay whichever is lower and, since July 2026, so do small mid-caps for the two lower tiers.
When does a deployer become a provider under the AI Act?
Under Article 25(1), in three cases: you put your name or trademark on a high-risk system already on the market, you substantially modify a high-risk system so that it stays high-risk, or you change the intended purpose of a non-high-risk system, including a general-purpose one, so that it becomes high-risk. You then take on the provider obligations under Article 16.
Terms in this guide
Sources
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), EUR-Lex accessed 30 Sep 2026
- Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 (Digital Omnibus on AI), Official Journal, 24 July 2026 accessed 30 Sep 2026
- European Parliament Legislative Train: Digital Omnibus on AI accessed 30 Sep 2026
- European Commission: AI Act, regulatory framework and application timeline accessed 30 Sep 2026
- European Commission: AI omnibus enters into force (updated 31 July 2026) accessed 30 Sep 2026
- European Commission: Commission starts enforcing AI Act rules and new transparency requirements on 2 August (31 July 2026) accessed 30 Sep 2026
- European Commission: Guidelines on the transparency obligations under Article 50 (annex to C(2026) 5054 final, content approved 20 July 2026) accessed 30 Sep 2026
- European Commission: Opinion on the assessment of the Code of Practice on Transparency of AI-generated Content accessed 30 Sep 2026
- AI Act Service Desk: Timeline for the implementation of the EU AI Act accessed 30 Sep 2026
