The AI Industry

The EU AI Act in 2026: What Actually Applies Now

Transparency duties and GPAI enforcement went live in August 2026. Most high-risk obligations slipped to 2027 and 2028. Here is the current schedule.

Tobias Reyes

AI Industry & Policy Analyst

Published 6 min read
European Union and Estonian flags wave under a clear blue sky, symbolizing unity and harmony.
In this story 6 sections

The EU AI Act is the European Union's risk-based regulation of artificial intelligence. As of September 2026, prohibited-practice bans, general-purpose AI model obligations, and Article 50 transparency duties apply, and the AI Office can exercise enforcement powers over general-purpose AI providers. Most high-risk system obligations have been deferred to December 2027 and August 2028.

The single most common error in coverage of the EU AI Act is treating it as one deadline. It is a staged schedule, parts of it moved in 2026, and which obligations bind you depends on the date and your role.

This explainer covers what applies now, what was deferred and until when, how the risk tiers work, and which role you occupy under the law. It is written for teams building or deploying AI systems that reach users in the European Union.

Fact-checked as of September 22, 2026. Implementation dates have been amended more than once; confirm current obligations against the official European Commission material before relying on them.

How the EU AI Act's Risk Tiers Work

The regulation sorts systems into four tiers, and the tier determines the obligations rather than the model architecture.

  • Prohibited practices. A short list including certain social scoring, manipulative techniques, and specified biometric uses. These are banned outright.
  • High risk. Systems used in areas like employment, credit, education, essential services, and certain regulated products. Heavy documentation, data governance, human oversight, and conformity assessment duties.
  • Limited risk. Systems subject to transparency duties, such as disclosing that content is AI-generated or that a user is interacting with an AI system.
  • Minimal risk. Everything else, with no specific obligations.

General-purpose AI models sit on a separate track with their own duties around technical documentation, training-data summaries, and copyright policy, plus additional requirements for models presenting systemic risk.

A concrete case shows how the tiers actually bite. A mid-size HR software company embeds a resume-screening feature into its product. That is not a chatbot. It is a high-risk system under Annex III, since employment screening is explicitly listed there. That single feature can pull the entire product into the high-risk regime, even though the rest of the platform is ordinary SaaS.

The authoritative source is the European Commission's own material on the regulatory framework for artificial intelligence, which is where amendments to the timeline appear first. Vendor summaries lag it, sometimes by months.

Front view of the historic Idaho State Capitol Building under blue skies in Boise.

What Applies as of September 2026

Three sets of obligations are live for organizations operating in the European Union.

Prohibited practices and AI literacy. The bans took effect in February 2025, along with a duty for providers and deployers to ensure staff working with AI systems have adequate AI literacy.

General-purpose AI model obligations. These applied from August 2, 2025, covering technical documentation, information for downstream providers, copyright policy, and a public summary of training content. More than twenty providers have signed the associated Code of Practice as of August 2026.

Article 50 transparency and AI Office enforcement. Transparency duties under Article 50 apply from August 2, 2026, and the AI Office's supervision and enforcement powers over general-purpose AI providers became exercisable on the same date.

What Applies as of September 2026
ObligationApplies fromWho it binds
Prohibited practices, AI literacyFebruary 2025Providers and deployers
GPAI model dutiesAugust 2025GPAI model providers
Article 50 transparencyAugust 2026Providers and deployers
AI Office enforcement over GPAIAugust 2026GPAI model providers
Annex III high-risk dutiesDecember 2027Providers of listed systems
Annex I embedded high-riskAugust 2028Regulated product makers
Close-up of a person signing a divorce decree on a desk.

What Was Deferred, and Until When

The timeline changed in 2026, and this is the part most commentary has not caught up with.

High-risk obligations for standalone systems listed in Annex III, which covers areas such as hiring, credit scoring, education, and critical infrastructure, were deferred to December 2, 2027. High-risk AI embedded in products already regulated under EU product law, including medical devices and machinery, moved to August 2, 2028.

What did not move is equally important. The Article 50 transparency duties and the AI Office's enforcement powers took effect on schedule in August 2026, and the earlier prohibitions were never deferred.

Practical consequence: a delay in the high-risk regime is not a delay in the parts that already bind a general-purpose model provider or a company disclosing AI-generated content. Treat them as separate schedules.

Evidence duties are the part teams underestimate. A high-risk system needs documented data governance, logging, and post-market monitoring, and retrofitting that onto a system already in production is slower than building it alongside. Measurement discipline helps here, for the same reasons set out in our guide to recording the conditions behind an evaluation result.

Deferral also does not stop the preparation clock. Conformity assessment, data governance documentation, and post-market monitoring for a high-risk system take many months to build, and the systems in scope are usually already in production.

Early compliance estimates from EU-based consultancies put the cost of a full conformity assessment package for one high-risk system in the low-to-mid six figures. That figure covers legal review, technical documentation, and audit logging. Teams that start this work in early 2027, expecting to finish before the December deadline, are already behind. Most of the cost is labor, not software, and labor does not scale by adding budget alone.

A black and white view of the historic courthouse facade in Hampton, Virginia, showcasing classic architecture.

Are You a Provider or a Deployer Under the EU AI Act?

You are a provider if you develop the system and place it on the EU market under your own name, and a deployer if you use someone else's system under your own authority. Most teams hold both roles across their AI portfolio, often without realizing it, which is why the distinction matters more than it first appears.

The Act assigns different duties to different roles, and most teams occupy more than one.

A provider develops an AI system or model and places it on the EU market under its own name. Providers carry the heaviest documentation and conformity obligations.

A deployer uses an AI system under its own authority in a professional context. Deployer duties are lighter but real, including human oversight, using the system as instructed, and certain transparency toward affected people.

Scale of the model matters for the general-purpose track specifically, since additional systemic-risk duties attach above a compute threshold rather than to any particular architecture. Which parameter count that threshold refers to is not always obvious, a distinction our explainer on total versus active parameters in sparse models sets out.

The trap is that substantially modifying or rebranding a system can make a deployer into a provider. Fine-tuning a general-purpose model and shipping it in a high-risk use case is the common path into that status, and it is easy to do without noticing.

We have seen this happen inside a single product team. A support tool built on a licensed foundation model got fine-tuned on the company's own claims data. It was then repackaged as a standalone "claims triage" feature and sold to other insurers. That rebrand and resale moved the team from deployer to provider overnight, along with the full documentation burden that comes with it. Nobody flagged the change until a customer's legal team asked for the conformity paperwork.

Documentation practice helps regardless of jurisdiction. The AI Risk Management Framework from the National Institute of Standards and Technology (NIST) is voluntary and American, not a compliance route for the EU AI Act, but the artifacts it asks for overlap heavily with what the Act requires.

Stack of legal and literature books in a library showcasing various volumes.

What to Do Now

Four steps, in order, for a team with EU exposure.

  1. Inventory your AI systems and label the tier. Most organizations underestimate how many systems are in scope, especially embedded vendor features.
  2. Determine your role per system. Provider and deployer duties differ, and a single company frequently holds both across its portfolio.
  3. Ship Article 50 disclosures now. These already apply. Marking AI-generated content and disclosing AI interaction is the nearest live obligation for most teams.
  4. Start high-risk documentation early. December 2027 sounds distant. Data governance evidence and conformity assessment do not assemble quickly.

Model choice affects this work. Running open weights inside your own environment changes who holds the documentation duty, a tradeoff covered in our comparison of open-weight and closed models in 2026. Whichever you pick, the provenance chain has to be documented, and that is harder with fine-tuned models built on other fine-tunes.

In our reporting at Emergent Wire, the teams furthest along are not the ones with the most legal advice. They are the ones that built a system inventory first and discovered how much was in scope.

The Short Version for 2026

As of September 2026, the EU AI Act's prohibitions, general-purpose AI model duties, and Article 50 transparency obligations are live, with AI Office enforcement powers active. The bulk of the high-risk regime arrives in December 2027 and August 2028.

Build your system inventory, settle your role for each one, and ship the transparency disclosures that already apply. Emergent Wire tracks the AI Act by effective date rather than by announcement, because those two calendars have diverged more than once.

Emergent Wire covers AI models, capabilities, and the industry building them.

What parts of the EU AI Act apply in 2026?
As of September 2026, the prohibited-practice bans and AI literacy duty apply, general-purpose AI model obligations have applied since August 2025, and Article 50 transparency duties took effect on August 2, 2026. The AI Office can exercise enforcement powers over general-purpose AI providers from that date.
Were the EU AI Act high-risk rules delayed?
Yes. Obligations for standalone high-risk systems listed in Annex III, covering areas like hiring, credit scoring, and education, were deferred to December 2, 2027. High-risk AI embedded in already-regulated products such as medical devices moved to August 2, 2028.
What is the difference between a provider and a deployer?
A provider develops an AI system or model and places it on the EU market under its own name, carrying the heaviest documentation and conformity duties. A deployer uses a system under its own authority professionally, with lighter obligations around human oversight and transparency.
Can fine-tuning a model make my company a provider?
It can. Substantially modifying a system, or putting it on the market under your own name, can shift you from deployer to provider. Fine-tuning a general-purpose model and shipping it into a high-risk use case is the most common route into that status.
Does the EU AI Act apply to companies outside Europe?
Yes, where the system's output is used in the European Union or the system is placed on the EU market. A US company serving EU users can fall in scope. The practical first step is an inventory of which systems reach EU users and in what role.