The EU AI Act in 2026: What Actually Applies Now
Transparency duties and GPAI enforcement went live in August 2026. Most high-risk obligations slipped to 2027 and 2028. Here is the current schedule.
In this story 6 sections
The EU AI Act is the European Union's risk-based regulation of artificial intelligence. As of September 2026, prohibited-practice bans, general-purpose AI model obligations, and Article 50 transparency duties apply, and the AI Office can exercise enforcement powers over general-purpose AI providers. Most high-risk system obligations have been deferred to December 2027 and August 2028.
The single most common error in coverage of the EU AI Act is treating it as one deadline. It is a staged schedule, parts of it moved in 2026, and which obligations bind you depends on the date and your role.
This explainer covers what applies now, what was deferred and until when, how the risk tiers work, and which role you occupy under the law. It is written for teams building or deploying AI systems that reach users in the European Union.
Fact-checked as of September 22, 2026. Implementation dates have been amended more than once; confirm current obligations against the official European Commission material before relying on them.
How the EU AI Act's Risk Tiers Work
The regulation sorts systems into four tiers, and the tier determines the obligations rather than the model architecture.
- Prohibited practices. A short list including certain social scoring, manipulative techniques, and specified biometric uses. These are banned outright.
- High risk. Systems used in areas like employment, credit, education, essential services, and certain regulated products. Heavy documentation, data governance, human oversight, and conformity assessment duties.
- Limited risk. Systems subject to transparency duties, such as disclosing that content is AI-generated or that a user is interacting with an AI system.
- Minimal risk. Everything else, with no specific obligations.
General-purpose AI models sit on a separate track with their own duties around technical documentation, training-data summaries, and copyright policy, plus additional requirements for models presenting systemic risk.
A concrete case shows how the tiers actually bite. A mid-size HR software company embeds a resume-screening feature into its product. That is not a chatbot. It is a high-risk system under Annex III, since employment screening is explicitly listed there. That single feature can pull the entire product into the high-risk regime, even though the rest of the platform is ordinary SaaS.
The authoritative source is the European Commission's own material on the regulatory framework for artificial intelligence, which is where amendments to the timeline appear first. Vendor summaries lag it, sometimes by months.
What Applies as of September 2026
Three sets of obligations are live for organizations operating in the European Union.
Prohibited practices and AI literacy. The bans took effect in February 2025, along with a duty for providers and deployers to ensure staff working with AI systems have adequate AI literacy.
General-purpose AI model obligations. These applied from August 2, 2025, covering technical documentation, information for downstream providers, copyright policy, and a public summary of training content. More than twenty providers have signed the associated Code of Practice as of August 2026.
Article 50 transparency and AI Office enforcement. Transparency duties under Article 50 apply from August 2, 2026, and the AI Office's supervision and enforcement powers over general-purpose AI providers became exercisable on the same date.
| Obligation | Applies from | Who it binds |
|---|---|---|
| Prohibited practices, AI literacy | February 2025 | Providers and deployers |
| GPAI model duties | August 2025 | GPAI model providers |
| Article 50 transparency | August 2026 | Providers and deployers |
| AI Office enforcement over GPAI | August 2026 | GPAI model providers |
| Annex III high-risk duties | December 2027 | Providers of listed systems |
| Annex I embedded high-risk | August 2028 | Regulated product makers |
What Was Deferred, and Until When
The timeline changed in 2026, and this is the part most commentary has not caught up with.
High-risk obligations for standalone systems listed in Annex III, which covers areas such as hiring, credit scoring, education, and critical infrastructure, were deferred to December 2, 2027. High-risk AI embedded in products already regulated under EU product law, including medical devices and machinery, moved to August 2, 2028.
What did not move is equally important. The Article 50 transparency duties and the AI Office's enforcement powers took effect on schedule in August 2026, and the earlier prohibitions were never deferred.
Practical consequence: a delay in the high-risk regime is not a delay in the parts that already bind a general-purpose model provider or a company disclosing AI-generated content. Treat them as separate schedules.
Evidence duties are the part teams underestimate. A high-risk system needs documented data governance, logging, and post-market monitoring, and retrofitting that onto a system already in production is slower than building it alongside. Measurement discipline helps here, for the same reasons set out in our guide to recording the conditions behind an evaluation result.
Deferral also does not stop the preparation clock. Conformity assessment, data governance documentation, and post-market monitoring for a high-risk system take many months to build, and the systems in scope are usually already in production.
Early compliance estimates from EU-based consultancies put the cost of a full conformity assessment package for one high-risk system in the low-to-mid six figures. That figure covers legal review, technical documentation, and audit logging. Teams that start this work in early 2027, expecting to finish before the December deadline, are already behind. Most of the cost is labor, not software, and labor does not scale by adding budget alone.
Are You a Provider or a Deployer Under the EU AI Act?
You are a provider if you develop the system and place it on the EU market under your own name, and a deployer if you use someone else's system under your own authority. Most teams hold both roles across their AI portfolio, often without realizing it, which is why the distinction matters more than it first appears.
The Act assigns different duties to different roles, and most teams occupy more than one.
A provider develops an AI system or model and places it on the EU market under its own name. Providers carry the heaviest documentation and conformity obligations.
A deployer uses an AI system under its own authority in a professional context. Deployer duties are lighter but real, including human oversight, using the system as instructed, and certain transparency toward affected people.
Scale of the model matters for the general-purpose track specifically, since additional systemic-risk duties attach above a compute threshold rather than to any particular architecture. Which parameter count that threshold refers to is not always obvious, a distinction our explainer on total versus active parameters in sparse models sets out.
The trap is that substantially modifying or rebranding a system can make a deployer into a provider. Fine-tuning a general-purpose model and shipping it in a high-risk use case is the common path into that status, and it is easy to do without noticing.
We have seen this happen inside a single product team. A support tool built on a licensed foundation model got fine-tuned on the company's own claims data. It was then repackaged as a standalone "claims triage" feature and sold to other insurers. That rebrand and resale moved the team from deployer to provider overnight, along with the full documentation burden that comes with it. Nobody flagged the change until a customer's legal team asked for the conformity paperwork.
Documentation practice helps regardless of jurisdiction. The AI Risk Management Framework from the National Institute of Standards and Technology (NIST) is voluntary and American, not a compliance route for the EU AI Act, but the artifacts it asks for overlap heavily with what the Act requires.
What to Do Now
Four steps, in order, for a team with EU exposure.
- Inventory your AI systems and label the tier. Most organizations underestimate how many systems are in scope, especially embedded vendor features.
- Determine your role per system. Provider and deployer duties differ, and a single company frequently holds both across its portfolio.
- Ship Article 50 disclosures now. These already apply. Marking AI-generated content and disclosing AI interaction is the nearest live obligation for most teams.
- Start high-risk documentation early. December 2027 sounds distant. Data governance evidence and conformity assessment do not assemble quickly.
Model choice affects this work. Running open weights inside your own environment changes who holds the documentation duty, a tradeoff covered in our comparison of open-weight and closed models in 2026. Whichever you pick, the provenance chain has to be documented, and that is harder with fine-tuned models built on other fine-tunes.
In our reporting at Emergent Wire, the teams furthest along are not the ones with the most legal advice. They are the ones that built a system inventory first and discovered how much was in scope.
The Short Version for 2026
As of September 2026, the EU AI Act's prohibitions, general-purpose AI model duties, and Article 50 transparency obligations are live, with AI Office enforcement powers active. The bulk of the high-risk regime arrives in December 2027 and August 2028.
Build your system inventory, settle your role for each one, and ship the transparency disclosures that already apply. Emergent Wire tracks the AI Act by effective date rather than by announcement, because those two calendars have diverged more than once.
Emergent Wire covers AI models, capabilities, and the industry building them.