Pillar Guide · Last updated 29 July 2026
The EU AI Act, in plain English
The EU AI Act is the world's first comprehensive law on artificial intelligence - a risk-based rulebook that classifies every AI system as prohibited, high-risk, limited-risk or minimal, and attaches obligations to each tier. In July 2026, the Digital Omnibus on AI (Regulation (EU) 2026/1744) was formally adopted and entered into force on 27 July 2026, revising several implementation deadlines. Here is where things stand today, and where to go next.
Go deeper
Pick your next step
This page is the map. Each card below is a full guide focused on one question - pick the one that matches what you need.
What applies on 2 August 2026
Article 50 transparency obligations, the Digital Omnibus deferrals, and what still ships on the original deadline.
Open guideAm I high-risk? Annex III & Annex I
Interactive decision tree, category list and the ten provider obligations for high-risk AI.
Open guideCompliance checklist
A numbered, do-now checklist of governance, inventory, transparency, high-risk and vendor items.
Open guideGlossary - 28 key terms
Plain-English definitions of provider, deployer, GPAI, Annex III, Article 50, conformity assessment and more.
Open guideLatest EU AI Act news
Digital Omnibus decisions, AI Office guidance, national supervisor designations and enforcement actions - dated and sourced.
Open guidePersonalised readiness assessment
Answer a few questions and receive a report with personalised next steps and deadlines.
Open guide- High-risk obligations postponed: Annex III systems now apply from 2 December 2027; Annex I from 2 August 2028.
- Article 50 transparency applies: unchanged by the Omnibus and in effect since 2 August 2026.
- New prohibition on AI-generated non-consensual intimate imagery and CSAM (Article 5), effective 2 December 2026.
- AI literacy softened: providers/deployers must "support the development of" literacy rather than guarantee a level.
- In force since 27 July 2026: Regulation (EU) 2026/1744, signed 8 July 2026 and published in the Official Journal on 24 July 2026.
Updated timeline of obligations
1 Aug 2024
In forceEU AI Act enters into force.
2 Feb 2025
In forceProhibited AI practices banned. AI literacy obligations start (softened by the Omnibus to a duty to 'support' literacy).
2 Aug 2025
In forceGeneral-Purpose AI (GPAI) model obligations apply. AI Office becomes operational.
2 Aug 2026
In forceArticle 50 transparency obligations apply - chatbot disclosure, deepfake & AI-generated content labelling, emotion recognition notices.
Applies since 2 August 2026 - unchanged by the Omnibus.
2 Dec 2026
NewArticle 50(2) watermarking grace period ends for pre-existing systems. New Article 5 ban on 'nudifier' tools and AI-generated CSAM starts.
2 Aug 2027
NewMember states must have AI regulatory sandboxes established (Article 57).
2 Dec 2027
Deferred by OmnibusAnnex III high-risk AI obligations apply - HR, credit scoring, education, law enforcement, biometrics, essential services.
Deferred from 2 Aug 2026 by the Digital Omnibus on AI.
2 Aug 2028
Deferred by OmnibusAnnex I high-risk AI obligations apply - AI embedded in regulated products (medical devices, machinery, vehicles, toys).
Deferred from 2 Aug 2027.
The four risk categories
Prohibited (Art. 5)
Social scoring, manipulative or exploitative systems, real-time biometric ID in public spaces (narrow exceptions), and - new via the Omnibus - AI-generated non-consensual intimate imagery and CSAM.
High-risk (Annex III / Annex I)
AI used in employment, credit, education, essential services, critical infrastructure, biometrics, law enforcement, migration and justice, or embedded in regulated products. Heavy documentation, oversight and monitoring duties.
Limited-risk (Art. 50)
Chatbots, deepfakes, generated content, emotion recognition, biometric categorisation - subject to the transparency and marking obligations that have applied since 2 August 2026.
Minimal-risk
The majority of AI systems (spam filters, game AI, recommenders). No specific AI Act obligations beyond horizontal rules.
What this means for your company
The Act does not treat every company the same. Your obligations depend on how you use AI, not just whether you use it. Here is how the most common profiles are impacted.
You use AI tools bought from vendors
Most SMEs, professional services, marketing, HR, finance teams.
Impact: You are a 'deployer'. Your duties are lighter than providers, and they are triggered by what you actually run: support your staff to building up adequate AI competency (Art. 4) always; human oversight and monitoring where you deploy a high-risk system (Art. 26); and Article 50 disclosures where you run a chatbot, publish AI-generated content, or use emotion recognition or biometric categorisation.
First step: Inventory your AI tools, classify each by risk tier, and document who is accountable internally.
You build or fine-tune AI products
Software vendors, agencies, in-house product teams shipping AI features.
Impact: You may be a 'provider'. If your system falls under Annex III or Annex I, you carry the full weight: technical documentation (Annex IV), risk & quality management, conformity assessment, CE marking, post-market monitoring.
First step: Determine risk tier now, so your 2026-2028 roadmap includes documentation and testing work - not just features.
You operate in a high-risk domain
HR-tech, credit scoring, edtech, medtech, biometrics, critical infrastructure, legal & migration tech.
Impact: Annex III duties apply from 2 Dec 2027, Annex I from 2 Aug 2028 (deferred by the Omnibus). Expect fundamental-rights impact assessments, data governance duties and mandatory registration in the EU database.
First step: Use the extra time. Buyers already ask for AI Act readiness in RFPs - being ready is a sales advantage, not just a legal box.
You use general-purpose AI (GPT, Gemini, Claude…)
Almost everyone: internal copilots, RAG apps, custom GPTs, agents.
Impact: GPAI obligations already apply (since 2 Aug 2025) to the model providers - including their copyright policy and training-data summary; those duties stay with the model provider. As a deployer you owe Article 4 competency support, and Article 50 disclosure or marking where you put AI interactions or synthetic content in front of people.
First step: Set an internal AI usage policy, log high-impact use cases, and make sure any customer-facing output is disclosed as AI-generated.
From confusion to action
Four steps to become AI Act ready
Most companies do not need a compliance army - they need clarity, an inventory, and a plan. Here is the shortest path that actually works.
Discover your AI footprint
List every AI system you build, buy or embed. Include shadow-IT tools your teams already use.
Classify the risk tier
Map each system to prohibited, high-risk, limited-risk or minimal-risk. This decides everything else.
Close the gaps
Add missing documentation, human oversight, disclosures and vendor clauses - proportionate to the risk tier.
Monitor & evidence
Post-market monitoring, incident logging, and regular re-assessment. Compliance is a habit, not a project.
Common myths - cleared up
"The Omnibus means we can wait."
Article 50 has applied since 2 Aug 2026. Prohibited practices, Article 4 and GPAI duties are already live.
"Only Big Tech is affected."
A 20-person HR-tech company using AI-based CV screening is squarely in Annex III.
"We just use ChatGPT - nothing to do."
As a deployer you owe transparency where people meet AI or synthetic content, and you should support your staff to building up adequate AI competency.
"Compliance kills innovation."
Being AI Act ready is quickly becoming a procurement requirement - it opens doors, not closes them.
Not sure where you stand?
Take our free readiness assessment - you'll receive a personalised report with clear next steps.
Start free assessment