Skip to content
Amended. Regulation (EU) 2026/1744 entered into force 27 July 2026. See what moved →
EU AI Act ChecklistIndependent reference
Regulation (EU) 2024/1689 · as amended

The AI Act you planned for is not the AI Act in force.

On 27 July 2026 the Digital Omnibus amended the AI Act. High-risk obligations moved to December 2027. Transparency, AI literacy, GPAI and registration did not move at all. Most published summaries still describe the old text.

This site tracks what is actually in force, with the article number and the source next to every claim, so you can check us rather than trust us.

What Regulation (EU) 2026/1744 changed
Annex III stand-alone high-risk systems 2 Aug 20262 Dec 2027
Annex I embedded high-risk systems 2 Aug 20272 Aug 2028
Art. 50(2) marking, systems already on the market 2 Aug 20262 Dec 2026
New Art. 5 prohibition: AI-generated NCII and CSAM 2 Dec 2026
Art. 4 literacy · Arts. 51–56 GPAI · Art. 49 · Art. 50 (most) unchangedunchanged
Reg. (EU) 2026/1744OJ L, 24 Jul 2026in force 27 Jul 2026
Start here

Which of these is your situation?

Your obligations and your deadline depend on what your AI does, not on your company size or sector. Pick the closest match.

Application dates

The timeline, as amended

Dates below reflect the consolidated text: Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744.

  1. 1 Aug 2024 in force

    The AI Act enters into force. Published in the Official Journal 12 July 2024.

  2. 2 Feb 2025 applies

    Article 5 prohibited practices. Article 4 AI literacy, which applies to every provider and deployer at every risk tier and is the most commonly missed live obligation.

  3. 2 Aug 2025 applies

    General-purpose AI model obligations, Articles 51–56. Models presenting systemic risk carry additional evaluation, incident reporting and cybersecurity duties.

  4. 2 Aug 2026 applies

    Article 50 transparency. Article 49 registration. National market surveillance authority enforcement powers. Penalties become applicable to these obligations.

  5. 2 Dec 2026 next

    Article 50(2) marking for systems placed on the market before 2 August 2026. New Article 5 prohibition on AI systems designed to generate non-consensual intimate imagery or child sexual abuse material.

  6. 2 Dec 2027 high-risk

    Annex III stand-alone high-risk systems. Articles 8–15, 17, 26, 27, 43, 49, 72 and 73 become applicable to them.

  7. 2 Aug 2028 embedded

    High-risk AI embedded as a safety component in products regulated under the Annex I legislation, medical devices, machinery, toys, vehicles.

  8. 2 Aug 2030 legacy

    Article 111 transition ends for AI systems already used by public authorities.

The delay is narrower than the headlines

"The EU delayed the AI Act" describes one clause of one amendment. Four obligation sets are live today and carry penalties. If you deploy a customer-facing AI feature in the EU, your deadline was last week, not next year.

Arts. 4, 5, 49, 50, 51–56, 99, 111Reg. 2024/1689as amended by Reg. 2026/1744

Full timeline analysis, article by article →

Article 99

Penalties are tiered. Most summaries quote the wrong tier.

€35M / 7% is the maximum for breaching the Article 5 prohibitions. It is not the figure for high-risk non-compliance, and it is not the figure for a transparency breach.

What you breachedMaximum fineBasis
Article 5 prohibited practices
Social scoring, untargeted scraping for facial recognition, most real-time remote biometric ID in public spaces, and from 2 Dec 2026, NCII/CSAM generation
€35M or 7%
whichever is higher
Art. 99(3)
Other operator obligations
Includes high-risk requirements (Arts. 8–15, 16, 26) and Article 50 transparency
€15M or 3% Art. 99(4)
Misleading information to authorities €7.5M or 1% Art. 99(5)
GPAI provider obligations
Enforced by the Commission, not national authorities
€15M or 3% Art. 101

For SMEs including start-ups, each cap is the lower of the fixed amount and the percentage. Penalties in detail →

The question we get most

Does ISO 42001 make us EU AI Act compliant?

No, and anyone telling you otherwise is selling something. ISO/IEC 42001 is not a harmonised standard under the AI Act and does not give you the Article 40 presumption of conformity. CEN-CENELEC JTC 21 looked at 42001 for the Article 17 quality management requirement, found it did not align, and wrote a separate European standard instead.

What is true is more useful: prEN 18286 contains an annex mapping its requirements onto ISO/IEC 42001 Annex A controls. If you already run a 42001 management system, you are reusing structure rather than starting over, and you have the governance evidence your customers are asking for today, independent of any deadline.

Art. 40 presumption of conformityEN 18286 (Approval / Formal Vote)ISO/IEC 42001:2023

What actually transfers

AI policy, roles, objectivesreusable
AI risk assessment & treatmentreusable
AI system inventoryreusable
Supplier & third-party controlsreusable
Annex IV technical documentationgap
Art. 43 conformity assessmentgap
Art. 27 FRIAgap
Art. 49 EU database registrationgap
Who writes this

We are not your lawyers. We are your documentation team.

This site is published by HumanAudit Inc. We build the artefacts a compliance team attaches to an audit file, checklists, classification matrices, impact assessment templates, statements of applicability. We publish this reference because we have to keep it accurate for our own work.

Everything here cites its source in the text. Where the law is unsettled, we say so rather than picking the more dramatic reading. Where we are giving an opinion rather than reporting an obligation, it is labelled.

Our correction policy

If you find an error, tell us and we will fix it and say what changed. Every page carries a review date. If a page has not been reviewed in 90 days we take it down rather than leave it standing.

Report an error →

Common questions

EU AI Act, answered precisely

Did the EU AI Act get delayed?

Partly. Regulation (EU) 2026/1744 moved stand-alone Annex III high-risk obligations from 2 August 2026 to 2 December 2027, and Annex I embedded high-risk obligations from 2 August 2027 to 2 August 2028. It did not move Article 5, Article 4, Articles 51–56, Article 49, or the Article 50 transparency obligations.

Reg. (EU) 2026/1744OJ 24 Jul 2026
What applies from 2 August 2026?

Article 50 transparency, Article 49 registration, and national market surveillance authority enforcement powers. Article 50 requires disclosure that a person is interacting with AI, disclosure of emotion recognition and biometric categorisation to the people exposed to them, and marking of synthetic output. Systems already on the market before that date get until 2 December 2026 for the Article 50(2) marking requirement.

Does ISO/IEC 42001 certification make us EU AI Act compliant?

No. ISO/IEC 42001 is not a harmonised standard and does not confer Article 40 presumption of conformity. It gives you management-system structure that transfers, and prEN 18286 maps to its Annex A controls, but it does not satisfy the AI Act on its own. Full mapping →

Does the Act apply to us if we are outside the EU?

Yes, if you place an AI system on the EU market, put one into service in the EU, or the output your system produces is used in the EU. Article 2 sets the scope and it does not depend on where you are established.

Art. 2Reg. 2024/1689
Are the new dates conditional on harmonised standards being ready?

No, not any more. The Commission's original proposal linked the high-risk application date to a Commission decision confirming that standards were available. The adopted text removed that link and set fixed dates instead.

What is the most commonly missed obligation?

Article 4 AI literacy. It has applied since 2 February 2025, it applies to every provider and deployer at every risk tier including minimal-risk, and it is the one obligation almost nobody has documented. Article 4 explained →

HumanAudit Inc.

If you have read this far, you probably have a specific problem.

Twenty minutes, no deck, no discovery script. Bring the actual question: a customer questionnaire you cannot answer, a system you cannot classify, an audit date you cannot move. If we cannot help, we will say so and point you somewhere that can.

What we actually do

Audit-ready documentation for ISO/IEC 42001 and the EU AI Act. Editable Word, Excel and PDF artefacts, checklists, Annex III classification matrices, FRIA templates, statements of applicability, gap-analysis workbooks, board briefings. Self-serve, instant download, unlimited internal use.

For mid-market teams and consultancies who need defensible documentation without a six-figure retainer.

Guides by role and by sector

The obligations are the same; what lands on your desk is not. These take the same Regulation from a specific starting point.

By role. Board & executive · General counsel · CISO · DPO · CTO · Product manager · Internal audit · Consultants & advisers

By sector. HR & recruitment · Financial services · Insurance · MedTech · Manufacturing · Automotive · B2B SaaS · Law firms · Public sector · Startups & SMEs

Proving it to a buyer. AI governance in procurement · Microsoft SSPA Section K · AI system inventory · Vendor due diligence · Supplier programme · Third-party AI risk · Contract clauses · Maturity self-assessment · AI risk library

Edge cases and scope questions. Open-source exemptions · Regulatory sandboxes (Art. 57) · Global AI regulation · Territorial scope

How this site works. About & funding · Editorial standards · Glossary · Article index