Skip to content
Artificial Intelligence Act

The obligationfollows the role,not thetechnology.

The AI Act does not ask what a system is. It asks what it is used for, and who put it there. A company that buys a model is a deployer; a company that fine-tunes one, rebrands it or puts its own name on the output can find it is the provider, and the provider carries almost all of the duties.
In force
1 August 2024
Amended
27 July 2026
High-risk duties
2 December 2027
Fines up to
7% of worldwide turnover
The dates that moved

The high-risk deadline is no longer August 2026. Most of what is written about this Act still says it is.

Regulation (EU) 2026/1744, in force since 27 July 2026, deferred the obligations for high-risk systems listed in Annex III from 2 August 2026 to 2 December 2027, and for high-risk AI embedded in products already regulated under Annex I to 2 August 2028. What was not deferred is the transparency duty in Article 50, which has applied since 2 August 2026. Anyone planning against a page written before last July is planning against a repealed date.

What applies, and when

Art. 5, from 2 Feb 2025

Some uses are simply closed

The prohibited practices have been in force since February 2025, and the July 2026 amendment added to them. This is the only tier where the ceiling is 35 million euro or 7% of worldwide annual turnover, under Article 99(3).

GPAI, from 2 Aug 2025

General-purpose models carry their own duties

Obligations for providers of general-purpose AI models, and the governance structure that supervises them, have applied since August 2025. The July 2026 amendment widened the AI Office's enforcement role.

Art. 50, from 2 Aug 2026

People must be told they are dealing with a machine

A system that interacts directly with a person has to say that it is a system, and synthetic image, audio or video has to be disclosed as artificially generated. This duty was not part of the deferral and is live now.

Art. 6(2), from 2 Dec 2027

The high-risk regime, sixteen months later than first written

Systems in the Annex III use cases — employment, education, credit, essential services, law enforcement, and others — take the full high-risk regime from 2 December 2027. Where the AI sits inside a product already regulated under Annex I, 2 August 2028.

Art. 16 and Art. 26

Provider and deployer are different jobs with different exposure

The provider carries the quality management system, the documentation, the logs and the conformity of the system itself. The deployer has a narrower set: use it as instructed, keep human oversight real, and tell a person when a high-risk system is deciding about them. The line between the two is where a business is most likely to be wrong about which one it is.

Art. 99

Three ceilings, and most exposure sits in the middle one

Prohibited practices reach 35 million euro or 7% of worldwide annual turnover. Breaching the provider duties in Article 16, the deployer duties in Article 26 or the transparency duties in Article 50 reaches 15 million or 3%. Giving a notified body or an authority incorrect, incomplete or misleading information reaches 7.5 million or 1%.

Source

Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, as amended by Regulation (EU) 2026/1744. Dates and penalty tiers are as stated by the European Commission's AI Act Service Desk. Nothing on this page is legal advice, and whether a given system is high-risk is a question for counsel, not for a website.
Technology

Underwriting isan informationproblem. We treatit as one.