The AI Act you planned for is not the AI Act in force.
On 27 July 2026 the Digital Omnibus amended the AI Act. High-risk obligations moved to December 2027. Transparency, AI literacy, GPAI and registration did not move at all. Most published summaries still describe the old text.
This site tracks what is actually in force, with the article number and the source next to every claim, so you can check us rather than trust us.
Which of these is your situation?
Your obligations and your deadline depend on what your AI does, not on your company size or sector. Pick the closest match.
You must tell people they are interacting with an AI system. Applies since 2 August 2026. Up to €15M or 3% under Art. 99(4).
Read the obligation → 02 We generate images, audio, video or text — 2 Dec 2026Output must be marked as artificially generated. New systems from 2 Aug 2026; systems already on the market get until 2 Dec 2026.
Marking rules → 03 Our AI touches hiring, credit, education, biometrics or essential services — 2 Dec 2027Likely Annex III high-risk. Risk management, technical documentation, data governance, human oversight, conformity assessment, registration.
Check Annex III → 04 We train or fine-tune general-purpose models — in force nowArticles 51–56 have applied since 2 August 2025. Documentation, downstream information, copyright policy, training-data summary.
GPAI obligations → 05 Customers are asking us to prove we govern AI responsiblyThis is a procurement problem, not a deadline problem. It usually resolves to an ISO/IEC 42001 management system and a documented Statement of Applicability.
ISO 42001 toolkits → 06 We genuinely don't know which of these we areTwelve questions, five minutes, no email required. Maps your system against Articles 5, 6, 50 and Annex III.
Run the classifier →The timeline, as amended
Dates below reflect the consolidated text: Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744.
-
1 Aug 2024 in force
The AI Act enters into force. Published in the Official Journal 12 July 2024.
-
2 Feb 2025 applies
Article 5 prohibited practices. Article 4 AI literacy, which applies to every provider and deployer at every risk tier and is the most commonly missed live obligation.
-
2 Aug 2025 applies
General-purpose AI model obligations, Articles 51–56. Models presenting systemic risk carry additional evaluation, incident reporting and cybersecurity duties.
-
2 Aug 2026 applies
Article 50 transparency. Article 49 registration. National market surveillance authority enforcement powers. Penalties become applicable to these obligations.
-
2 Dec 2026 next
Article 50(2) marking for systems placed on the market before 2 August 2026. New Article 5 prohibition on AI systems designed to generate non-consensual intimate imagery or child sexual abuse material.
-
2 Dec 2027 high-risk
Annex III stand-alone high-risk systems. Articles 8–15, 17, 26, 27, 43, 49, 72 and 73 become applicable to them.
-
2 Aug 2028 embedded
High-risk AI embedded as a safety component in products regulated under the Annex I legislation, medical devices, machinery, toys, vehicles.
-
2 Aug 2030 legacy
Article 111 transition ends for AI systems already used by public authorities.
The delay is narrower than the headlines
"The EU delayed the AI Act" describes one clause of one amendment. Four obligation sets are live today and carry penalties. If you deploy a customer-facing AI feature in the EU, your deadline was last week, not next year.
Penalties are tiered. Most summaries quote the wrong tier.
€35M / 7% is the maximum for breaching the Article 5 prohibitions. It is not the figure for high-risk non-compliance, and it is not the figure for a transparency breach.
| What you breached | Maximum fine | Basis |
|---|---|---|
| Article 5 prohibited practices Social scoring, untargeted scraping for facial recognition, most real-time remote biometric ID in public spaces, and from 2 Dec 2026, NCII/CSAM generation |
€35M or 7% whichever is higher |
Art. 99(3) |
| Other operator obligations Includes high-risk requirements (Arts. 8–15, 16, 26) and Article 50 transparency |
€15M or 3% | Art. 99(4) |
| Misleading information to authorities | €7.5M or 1% | Art. 99(5) |
| GPAI provider obligations Enforced by the Commission, not national authorities |
€15M or 3% | Art. 101 |
For SMEs including start-ups, each cap is the lower of the fixed amount and the percentage. Penalties in detail →
Does ISO 42001 make us EU AI Act compliant?
No, and anyone telling you otherwise is selling something. ISO/IEC 42001 is not a harmonised standard under the AI Act and does not give you the Article 40 presumption of conformity. CEN-CENELEC JTC 21 looked at 42001 for the Article 17 quality management requirement, found it did not align, and wrote a separate European standard instead.
What is true is more useful: prEN 18286 contains an annex mapping its requirements onto ISO/IEC 42001 Annex A controls. If you already run a 42001 management system, you are reusing structure rather than starting over, and you have the governance evidence your customers are asking for today, independent of any deadline.
What actually transfers
| AI policy, roles, objectives | reusable |
| AI risk assessment & treatment | reusable |
| AI system inventory | reusable |
| Supplier & third-party controls | reusable |
| Annex IV technical documentation | gap |
| Art. 43 conformity assessment | gap |
| Art. 27 FRIA | gap |
| Art. 49 EU database registration | gap |
Work the problem, don't read about it
Risk classifier
Twelve questions. Maps your system to prohibited, high-risk, transparency-only or minimal, with the article references behind each verdict.
5 minutes →Annex III quick check
Three questions to test whether your system falls into one of the eight Annex III high-risk domains.
60 seconds →FRIA template
Article 27 Fundamental Rights Impact Assessment structure, for deployers who will need one by December 2027.
Open template →58-point checklist
Article-by-article readiness review covering Articles 8–29 plus post-market obligations.
See the points →Penalty calculator
Maximum exposure by violation type and turnover, using the correct Article 99 tier for each.
Calculate →Annex III domain guides
Eight guides, biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice.
Browse domains →We are not your lawyers. We are your documentation team.
This site is published by HumanAudit Inc. We build the artefacts a compliance team attaches to an audit file, checklists, classification matrices, impact assessment templates, statements of applicability. We publish this reference because we have to keep it accurate for our own work.
Everything here cites its source in the text. Where the law is unsettled, we say so rather than picking the more dramatic reading. Where we are giving an opinion rather than reporting an obligation, it is labelled.
Our correction policy
If you find an error, tell us and we will fix it and say what changed. Every page carries a review date. If a page has not been reviewed in 90 days we take it down rather than leave it standing.
EU AI Act, answered precisely
Did the EU AI Act get delayed?
Partly. Regulation (EU) 2026/1744 moved stand-alone Annex III high-risk obligations from 2 August 2026 to 2 December 2027, and Annex I embedded high-risk obligations from 2 August 2027 to 2 August 2028. It did not move Article 5, Article 4, Articles 51–56, Article 49, or the Article 50 transparency obligations.
What applies from 2 August 2026?
Article 50 transparency, Article 49 registration, and national market surveillance authority enforcement powers. Article 50 requires disclosure that a person is interacting with AI, disclosure of emotion recognition and biometric categorisation to the people exposed to them, and marking of synthetic output. Systems already on the market before that date get until 2 December 2026 for the Article 50(2) marking requirement.
Does ISO/IEC 42001 certification make us EU AI Act compliant?
No. ISO/IEC 42001 is not a harmonised standard and does not confer Article 40 presumption of conformity. It gives you management-system structure that transfers, and prEN 18286 maps to its Annex A controls, but it does not satisfy the AI Act on its own. Full mapping →
Does the Act apply to us if we are outside the EU?
Yes, if you place an AI system on the EU market, put one into service in the EU, or the output your system produces is used in the EU. Article 2 sets the scope and it does not depend on where you are established.
Are the new dates conditional on harmonised standards being ready?
No, not any more. The Commission's original proposal linked the high-risk application date to a Commission decision confirming that standards were available. The adopted text removed that link and set fixed dates instead.
What is the most commonly missed obligation?
Article 4 AI literacy. It has applied since 2 February 2025, it applies to every provider and deployer at every risk tier including minimal-risk, and it is the one obligation almost nobody has documented. Article 4 explained →
If you have read this far, you probably have a specific problem.
Twenty minutes, no deck, no discovery script. Bring the actual question: a customer questionnaire you cannot answer, a system you cannot classify, an audit date you cannot move. If we cannot help, we will say so and point you somewhere that can.
What we actually do
Audit-ready documentation for ISO/IEC 42001 and the EU AI Act. Editable Word, Excel and PDF artefacts, checklists, Annex III classification matrices, FRIA templates, statements of applicability, gap-analysis workbooks, board briefings. Self-serve, instant download, unlimited internal use.
For mid-market teams and consultancies who need defensible documentation without a six-figure retainer.
Guides by role and by sector
The obligations are the same; what lands on your desk is not. These take the same Regulation from a specific starting point.
By role. Board & executive · General counsel · CISO · DPO · CTO · Product manager · Internal audit · Consultants & advisers
By sector. HR & recruitment · Financial services · Insurance · MedTech · Manufacturing · Automotive · B2B SaaS · Law firms · Public sector · Startups & SMEs
Proving it to a buyer. AI governance in procurement · Microsoft SSPA Section K · AI system inventory · Vendor due diligence · Supplier programme · Third-party AI risk · Contract clauses · Maturity self-assessment · AI risk library
Edge cases and scope questions. Open-source exemptions · Regulatory sandboxes (Art. 57) · Global AI regulation · Territorial scope
How this site works. About & funding · Editorial standards · Glossary · Article index