Status note — checked 12 August 2026. The EU AI Act’s general application date has passed, and the AI Omnibus is enacted law. It postponed specified high-risk provisions; it did not postpone the entire Act.
For an owner, the useful first question is not “Are we an AI company?” It is: what AI do we provide, modify, import, distribute or deploy in the EU, and which rule attaches to each role? A business that buys an AI tool can still be a deployer. A business that rebrands or substantially modifies a system may have a different role.
Fact: the timetable is now split
The original AI Act entered into force on 1 August 2024. The Commission’s current implementation overview records a staged application: prohibited practices and AI-literacy provisions from 2 February 2025; governance and general-purpose AI (GPAI) model duties from 2 August 2025; and the general application date of 2 August 2026.
The enacted AI Omnibus, Regulation (EU) 2026/1744, entered into force on 27 July 2026. It moved the specified requirements and obligations in Chapter III, Sections 1–3 for:
- Annex III high-risk use cases to 2 December 2027; and
- high-risk systems tied to Annex I regulated products to 2 August 2028.
Those later dates do not erase duties already live elsewhere in the Act.
Dates that matter now
| Date | What the official sources say | Owner-level implication |
|---|---|---|
| 2 February 2025 | Prohibited-practice rules and the revised AI-literacy provision apply. | Screen use cases before procurement or deployment; maintain role-appropriate staff capability. |
| 2 August 2025 | GPAI-provider duties began to apply. | A model provider, or a party whose modification makes it a provider, needs a separate assessment. |
| 2 August 2026 | Article 50 transparency rules apply; Commission enforcement powers for GPAI-provider duties apply. | Interactive AI, synthetic content, deepfakes and some public-interest text need a use-case check now. |
| 2 December 2026 | Pre-2 August 2026 providers of systems generating synthetic audio, images, video or text reach the Omnibus grace date for Article 50(2) marking. New prohibited categories added by the Omnibus also apply from this date. | Do not read the grace period as a blanket delay for deployers or other Article 50 duties. |
| 2 December 2027 | Specified high-risk duties for Article 6(2)/Annex III systems apply. | Prepare evidence and vendor allocation well before the deadline. |
| 2 August 2028 | Specified high-risk duties for Article 6(1)/Annex I product systems apply. | Product development and conformity work may need a multi-year runway. |
The Commission’s Article 50 quick facts say the transparency rules apply from 2 August 2026. Providers may need to make direct AI interaction apparent and add machine-readable marking to covered synthetic content. Deployers may have disclosure duties for emotion recognition, biometric categorisation, deepfakes and certain public-interest text without human review or editorial control. Scope and exceptions matter; use the Commission’s Article 50 guidelines, not a generic “AI-generated” label rule.
For GPAI providers, the Commission’s GPAI guidance says obligations have applied since 2 August 2025, enforcement powers apply from 2 August 2026, and models placed on the market before 2 August 2025 have a transition to 2 August 2027. A normal customer using a third-party model is not automatically the model’s provider.
Signal: the deadline changed, but the operating assumption did not
PARAVEILUX judgment. The hidden risk is a single “AI compliance” workstream with one deadline. Role, use case, model provenance and output path can produce different clocks inside the same business.
Investigate when:
- the inventory says “ChatGPT” or “automation” but not who supplies the model, who configures it, what it decides, or who sees the output;
- a vendor says “the high-risk rules were delayed” without identifying the provision and the system classification;
- marketing, support or publishing teams use synthetic media without an owner for Article 50 marking or disclosure;
- a tool influences recruitment, credit, access to services, education, biometric categorisation or another sensitive decision;
- an open-source or third-party model is fine-tuned, rebranded or placed into a customer-facing product without analysing whether the business has become a provider; or
- contracts do not preserve instructions, documentation, incident cooperation, output provenance and change notice.
Counter-signals
- A documented inventory shows only out-of-scope or minimal-risk functions and records why.
- The business is solely a customer/deployer and the provider supplies current role-specific documentation, change notices and output controls.
- Human review is genuine and evidenced rather than a label attached to an automated decision.
- The relevant transparency feature is technically tested in the actual user journey.
These reduce uncertainty; they do not prove that every other EU rule, including data protection, consumer, employment or product law, is satisfied.
Action: build a role-and-clock register
For each system, record: business owner; technical owner; provider and model; EU availability; intended and reasonably foreseeable use; affected people; inputs and outputs; provider/deployer/importer/distributor status; prohibited-practice screen; Article 50 trigger; GPAI role; possible high-risk category; human review; logs; vendor evidence; and next review trigger.
Implementation checkpoints
- Now — inventory and classify. Find shadow use as well as approved tools. Record uncertainty instead of forcing a category.
- Now — test live duties. Check prohibited practices, revised AI-literacy measures, Article 50 and any GPAI-provider role separately.
- By 2 December 2026 — close specific transition items. Confirm whether any pre-August 2026 synthetic-content system needs Article 50(2) marking changes and whether new prohibited categories are relevant.
- Contract cycle — make evidence portable. Require role allocation, instructions, technical information, material-change notice, incident support, logs where appropriate, and exit/data-return terms.
- Before the high-risk dates — rehearse evidence. If Annex III or Annex I classification is plausible, obtain qualified review and build the required governance and technical record before procurement hardens the design.
Limitations: classification is fact-specific
This is a dated issue-spotting map, not a full statement of the AI Act. The Omnibus changed more than dates, including definitions, governance and proportionality measures. Commission guidelines are useful but non-binding; the regulation, later implementing measures, national competent-authority practice and other laws remain relevant. Whether a system is an AI system, whether a business is a provider or deployer, and whether a use is high-risk depend on its design and actual use.
No deadline in this page is a safe-harbour date. This is general information, not legal or professional advice. Obtain qualified advice for a specific system, role and Member State.
Regulation (EU) 2026/1744 — AI Omnibus. This source supports the identified facts; Paraveilux signals and recommendations remain interpretation.