Reference · European Union
EU AI Act Obligations and Dates After the Digital Omnibus
Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744
The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and phases in by chapter under Article 113. The Digital Omnibus on AI (Regulation (EU) 2026/1744), published in the Official Journal on 24 July 2026 and in force since 27 July 2026, moved the application date of the high-risk regime and left the rest of the schedule in place. This entry lists the obligations, the articles they sit in, and the dates that now apply, read from the deployer's side.
Who it applies to
Providers placing AI systems on the EU market wherever they are established, deployers located in the EU, and providers and deployers in third countries where the system's output is used in the EU. Most regulated firms are deployers: they license a system and put it to work. A firm that substantially modifies a system or markets it under its own name can take on provider obligations.
Annex III names the uses treated as high-risk. Point 5(b) covers AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score, with an exception for systems used to detect financial fraud. Point 5(c) covers risk assessment and pricing in relation to natural persons in life and health insurance. Point 4 covers recruitment, selection, promotion, termination, task allocation, and performance monitoring.
In force since 2 February 2025
- Article 5, the prohibited practices. The Omnibus added a prohibition on AI systems that generate non-consensual intimate imagery and child sexual abuse material, which applies from 2 December 2026.
- Article 4, AI literacy. As amended by the Omnibus, providers and deployers take measures to support the development of AI literacy among their staff and the people operating AI on their behalf; the original wording required a sufficient level of literacy.
In force since 2 August 2025
- Chapter V, the obligations on providers of general-purpose AI models (Article 53 among them), together with the governance chapter and the penalties chapter.
- Article 99 sets the fine ceilings: up to EUR 35 million or 7% of total worldwide annual turnover for prohibited practices, and up to EUR 15 million or 3% for most other infringements, whichever is higher in each case.
In force since 2 August 2026
2 August 2026 is the Act's general application date, and the Omnibus kept it. Article 50 applies from that date: providers of systems that interact directly with natural persons must ensure those persons are informed they are interacting with an AI system (Article 50(1)); providers of systems generating synthetic audio, image, video, or text must mark outputs in a machine-readable format and make them detectable as artificially generated (Article 50(2)); deployers of systems that generate deep fakes must disclose that the content was artificially generated or manipulated (Article 50(4)).
One transitional rule: systems placed on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking requirement in Article 50(2).
Deferred: the high-risk regime
Before the Omnibus, the obligations for Annex III high-risk systems applied from 2 August 2026, and those for high-risk systems embedded in products covered by the Union harmonisation legislation in Annex I from 2 August 2027. The Omnibus moved them to 2 December 2027 and 2 August 2028 respectively. For a deployer of a credit-scoring, insurance-pricing, or employment system, the duties arriving on 2 December 2027 are:
- Article 26(1): take appropriate technical and organisational measures to use the system in accordance with the provider's instructions for use.
- Article 26(2): assign human oversight to natural persons who have the necessary competence, training, authority, and support.
- Article 26(5): monitor the system's operation on the basis of the instructions for use, inform the provider of risks identified, and report serious incidents to the provider and the market surveillance authorities.
- Article 26(6): keep the logs the system automatically generates, to the extent they are under the deployer's control, for a period appropriate to the intended purpose and of at least six months, unless Union or national law provides otherwise.
- Article 26(7): before putting a high-risk system into service at a workplace, inform workers' representatives and the affected workers.
- Article 27: carry out a fundamental rights impact assessment before first use. It applies to bodies governed by public law, private entities providing public services, and deployers of the Annex III point 5(b) and 5(c) systems, which is to say lenders and life and health insurers.
- Article 12 requires the system itself to technically allow the automatic recording of events over its lifetime; the provider builds it, and the deployer keeps what it produces.
Other Omnibus changes
- National AI regulatory sandboxes must be established by 2 August 2027.
- The provisions permitting the processing of special categories of personal data for bias detection and correction extend to all AI systems rather than only high-risk ones.
Control mapping
What a reviewer expects to be able to see.
| Obligation | What the system must do | Evidence a reviewer expects |
|---|---|---|
| Classification (Annex III) | Map every AI system in use to a tier, and record the provider-or-deployer determination for each | Inventory with tier, role, Annex III point, and the dated rationale |
| AI literacy (Art. 4) | Take measures supporting the AI literacy of staff and others operating AI on the firm's behalf | Program description, coverage of the people using AI, and delivery records |
| Transparency (Art. 50) | Disclose AI interaction, mark synthetic output, and label deep fakes on customer-facing surfaces | Disclosure text, marking implementation, and the surfaces they cover |
| Logs (Art. 12, 26(6)) | Retain the logs a high-risk system generates for at least six months, or longer where other law requires | Retention policy per system and the retained log record itself |
| Human oversight (Art. 14, 26(2)) | Name the people overseeing each high-risk system and show they have authority to intervene | Oversight assignments, training records, and intervention records |
| Impact assessment (Art. 27) | Complete a fundamental rights impact assessment before first use of a credit-scoring or insurance-pricing system | The assessment, its date, and the notification to the market surveillance authority |
Key dates
- 1 August 2024Regulation (EU) 2024/1689 enters into force.
- 2 February 2025Chapters I and II apply: prohibited practices (Article 5) and AI literacy (Article 4).
- 2 August 2025General-purpose AI model obligations (Chapter V), governance, and penalties apply.
- 24 July 2026Digital Omnibus on AI (Regulation (EU) 2026/1744) published in the Official Journal.
- 27 July 2026Digital Omnibus enters into force.
- 2 August 2026General application date; Article 50 transparency obligations apply.
- 2 December 2026Article 50(2) marking applies to systems placed on the market before 2 August 2026; new Article 5 prohibition on non-consensual intimate imagery applies.
- 2 August 2027Deadline for national AI regulatory sandboxes.
- 2 December 2027Annex III high-risk obligations apply (moved from 2 August 2026).
- 2 August 2028Annex I product-embedded high-risk obligations apply (moved from 2 August 2027).
Primary sources
Common gaps
Where deployers most often misread the schedule.
- Reading the deferral as a pause on everything. The Omnibus moved the Annex III date. Article 4, Article 5, Chapter V, and Article 50 were binding before it was published and remain so.
- No classification on file. Until each system is mapped to a tier, the firm cannot say which obligations it carries or when they arrive. A classification memo with a date is the first document a supervisor will ask for.
- A customer chatbot without disclosure. Article 50(1) has applied since 2 August 2026. A support assistant that presents as a person is a finding visible from a screenshot.
- Logs that start in 2027. Article 26(6) sets a minimum retention period. It says nothing about when to begin, and a deployer that starts logging in November 2027 arrives at the application date with weeks of history.
- Becoming a provider by accident. Substantially modifying a licensed system, or putting the firm's own name on it, can shift the firm into the provider role with its own set of obligations. Record the decision either way.
Related
Last reviewed September 4, 2026. This reference summarises publicly available regulatory guidance and is provided for general information. It is not legal advice. Obligations depend on an institution's charter, registration status, size, and activities. Verify against the primary sources cited above and consult counsel before relying on any summary here.