The EU AI Act deadline
didn't move for you.
Everyone heard "the EU delayed the AI Act." That's half true, and dangerous. The high-risk deadline moved to 2027, but Article 50 transparency obligations still apply from 2 August 2026, and they hit any organisation running a chatbot, a generative feature, or any AI that interacts with people. Penalties reach €35 million or 7% of global turnover.
⏱ Time Until Article 50 Enforcement
Feb 2025, Article 5 prohibitions + Article 4 AI literacy (in force)
Aug 2025, GPAI obligations Arts. 51–56 (in force)
2 Aug 2026, Article 50 transparency (most) + Article 49 registration + MSA powers
2 Dec 2026, Article 50(2) watermarking + new Article 5 CSAM/NCII ban
2 Dec 2027, Annex III high-risk AI (moved from 2 Aug 2026)
2 Aug 2028, Annex I embedded high-risk (moved from 2 Aug 2027)
Start Your Compliance Work, Right Now, No Email Required
Six tools that take you from “is my system in scope?” to “which Articles apply?” without installing anything or signing up. Built on Regulation (EU) 2024/1689, verified against the Official Journal text.
Risk Classifier (Full)
Map your AI system to Prohibited / High-Risk / Limited / Minimal with article-grounded scoring covering Article 5, 6, Annex III, Article 50, and Article 6(3) profiling override. Personalized PDF brief by email.
Take the classifier → 3-question quizAnnex III Quick Check
Is your AI system high-risk under one of the 8 Annex III points? Get a verdict in under 60 seconds. (Top of funnel, quick first pass.)
Run quick check → Article 27FRIA Template
Fundamental Rights Impact Assessment, mandatory before deployment for public-sector and essential-service high-risk AI.
Open template → 58 checkpointsCompliance Checklist
Article-by-Article review covering Articles 8–29 plus post-market obligations, mapped to your internal controls.
See the 58 points → Article 99Penalty Calculator
Estimate maximum exposure: €35M / 7% for prohibited, €15M / 3% for high-risk violations, €7.5M / 1% for misleading information to authorities.
Calculate exposure → Live counterCountdown Timer
Phased enforcement timeline, what still applies 2 Aug 2026, what's new 2 Dec 2026, and the 18-month runway to 2 Dec 2027 Annex III obligations under the 7 May Omnibus deal.
Track the deadline →What Is the EU AI Act, and Does It Apply to You?
The EU AI Act is the European Union's landmark regulation governing the development, deployment, and use of artificial intelligence systems, the first comprehensive AI law anywhere in the world.
Published in the EU Official Journal on 12 July 2024 and entering into force on 1 August 2024, the Regulation establishes a risk-based compliance framework that classifies AI systems into four tiers: Prohibited, High-Risk, Limited-Risk, and Minimal-Risk. Each tier carries distinct obligations proportionate to the potential harm.
The Act applies to any organisation, regardless of where it is headquartered, that places an AI system on the EU market, deploys one within the EU, or whose AI output affects EU-based individuals. This extra-territorial scope mirrors the GDPR model and means thousands of non-EU companies must also comply.
Non-compliance carries administrative fines of up to €35 million or 7% of global annual worldwide turnover for the most serious violations, with a tiered structure reaching down to €7.5 million for information offences.
Read the Complete Guide →EU AI Act Risk Classification Framework
The Act classifies all AI systems into four tiers. Your compliance obligations, and the penalties for non-compliance, depend entirely on your system's classification.
| Risk Tier | Examples | Key Obligations | Max Penalty | Deadline |
|---|---|---|---|---|
| ● Prohibited | Social scoring by governments; real-time remote biometric ID in public spaces; subliminal manipulation; exploitation of vulnerabilities | Complete prohibition. No deployment permitted. | €35M / 7% | 2 Feb 2025 |
| ● High-Risk | Biometric systems; AI in recruitment; credit scoring; critical infrastructure management; medical devices; law enforcement tools | Risk management system; technical documentation (Annex IV); data governance; human oversight; registration in EU database | €15M / 3% | 2 Dec 2027 |
| ● Limited-Risk | Chatbots; deepfakes; emotion recognition systems; AI-generated content | Transparency obligations (Art. 50): users must be informed they are interacting with AI and that content is AI-generated. Watermarking (Art. 50(2)): 2 Dec 2026. | €15M / 3% | 2 Aug 2026 |
| ● Minimal-Risk | Spam filters; AI in video games; recommendation systems; inventory management | No mandatory requirements. Voluntary codes of conduct encouraged. | None | No deadline |
Why Compliance Cannot Wait
The EU AI Act creates the most significant compliance burden for technology organisations since GDPR. These numbers define the risk landscape.
Article 5 Prohibitions
Certain AI practices are completely prohibited since 2 February 2025. These include government social scoring, exploiting psychological vulnerabilities, and most real-time remote biometric identification in public spaces.
Review Article 5 →GPAI Obligations
General-Purpose AI model providers face transparency and documentation requirements active since 2 August 2025. Models above 10²⁵ FLOPs face additional systemic risk obligations including adversarial testing.
GPAI Compliance Guide →High-Risk AI Deadline
Annex III high-risk AI systems require a risk management system (Art. 9), technical documentation (Annex IV), data governance protocols, human oversight mechanisms, and EU database registration. The deadline moved from 2 August 2026 to 2 December 2027 under the Digital Omnibus.
Annex III Guide →Calculate Your Maximum Exposure
Enter your organisation's global annual revenue and the type of potential violation to estimate your maximum penalty exposure under the EU AI Act.
The Act uses a two-track calculation: a fixed maximum and a percentage of global annual turnover. The higher of the two applies, meaning large organisations face substantially greater risk.
This calculator provides indicative figures for risk planning purposes. Actual penalties depend on severity, intent, duration, and cooperation with supervisory authorities.
Full Penalties Guide →The Omnibus didn't let you off the hook. It just changed which hook.
The "delay" only touched high-risk systems. If any of these is you, 2 August 2026 is still a live deadline.
You run a chatbot or AI assistant
Article 50 says people must be told when they're interacting with AI. Customer-facing bot, support agent, virtual assistant, this applies to you on 2 August 2026, not 2027.
You ship generative or synthetic content
Generate text, images, audio, or video? Article 50(2) marking obligations hit new systems from 2 August 2026, existing ones by 2 December 2026. No grace period for launches this autumn.
You advise clients on compliance
Consultants and law firms: the white-label licence lets you deliver these frameworks under your own brand, without rebuilding them from the regulation yourself.
Three ways to get compliant documentation. One is fast.
The regulation requires the same evidence however you produce it. Here's what each path costs.
Hire a law firm
€10,000–€40,000
Accurate and expensive. Weeks of billable hours to produce documentation you could start from today.
Read the regulation yourself
Weeks + real risk
144 articles, 13 annexes, plus the Omnibus amendments. Miss one Article 50 obligation and the penalty is up to €35M.
Start from the packs
$149–$999 · today
Every framework verified against Regulation (EU) 2024/1689 and the adopted Omnibus. Editable, yours, ready now.
See the packs →Compliance Documentation Built for Legal and Compliance Teams
Our compliance packs contain the exact documentation frameworks your legal team needs. Every document is structured around, and verified against, the full text of Regulation (EU) 2024/1689, Annex III, and the GPAI Code of Practice (July 2025).
5 essential compliance documents for organisations beginning their EU AI Act compliance programme. Everything needed to assess exposure and present to leadership.
- 58-Point Compliance Checklist, complete Article-by-Article assessment
- Annex III Classification Matrix, determine your risk tier with confidence
- AI System Inventory Template, catalogue all AI in use across the organisation
- FRIA Starter (Article 27), Fundamental Rights Impact Assessment framework
- Board Executive Briefing Template, present compliance status to leadership
The complete compliance documentation system. 11 professional documents covering every obligation under the EU AI Act, from risk management to GPAI governance.
- Everything in the Checklist Pack (5 documents)
- ISO 42001 / EU AI Act Mapping Matrix, align to international standards
- Annex IV Technical Documentation Checklist, complete documentation framework
- Vendor AI Readiness Questionnaire, audit your AI supply chain
- LLM & Generative AI Governance Policy, board-ready policy document
- Ongoing Compliance Monitoring Calendar, ongoing compliance schedule
- GPAI Compliance Checklist, Arts. 51–56 obligations
Annual license to use, rebrand, and resell all 11 compliance documents to your clients. One client engagement typically covers the full annual cost.
- All 11 documents from the Full Bundle
- White-label license, brand with your firm's identity
- Client-ready formatting for immediate deployment
- Annual updates as regulatory guidance evolves
- Use across unlimited client engagements
- Suitable for law firms, consultancies, and compliance advisors
How Compliance Teams Use These Documents
Three common use cases for the Checklist Pack, Full Bundle, and White-Label License, based on the compliance journey of mid-size EU organisations preparing for Annex III enforcement.
Scenario 1 · DPO at SaaS Company
"The Annex III Classification Matrix made it immediately clear our hiring-automation feature was in scope. What would have been a multi-week legal review became a two-hour structured assessment with a defensible paper trail for the board."
Applicable product: Checklist Pack ($149)
Scenario 2 · Head of Compliance at Fintech
"We had ISO 42001 certification in progress and the EU AI Act obligations looming. The Mapping Matrix showed us which controls satisfied both frameworks simultaneously, cutting our documentation workload roughly in half."
Applicable product: Full Readiness Bundle ($499)
Scenario 3 · Partner at Boutique Consultancy
"The White-Label License paid for itself on the first engagement. Having pre-built, defensible frameworks meant we could focus advisory time on judgement calls rather than drafting boilerplate, and clients perceived higher value from the structured deliverables."
Applicable product: White-Label License ($999/yr)
Representative scenarios illustrating typical use cases, not direct quotations from named clients.
EU AI Act Phased Implementation Schedule
The EU AI Act does not enforce all requirements simultaneously. Understanding the phased schedule is critical to prioritising your compliance programme correctly.
The most immediate obligations, Article 5 prohibitions and GPAI requirements, are already active. Many organisations incorrectly assume nothing applies until the high-risk deadline, when in reality the Article 5 prohibitions (since February 2025) and GPAI obligations (since August 2025) are already in force.
Full Deadline Analysis →EU AI Act, Frequently Asked Questions
The EU AI Act (Regulation EU 2024/1689) is the world's first comprehensive legal framework governing artificial intelligence. It entered into force on 1 August 2024 and applies to any organisation that develops, deploys, or imports AI systems in the EU, or whose AI output affects EU-based individuals, regardless of where the organisation is headquartered.
Enforcement is phased. Article 5 prohibitions and Article 4 AI literacy obligations became applicable on 2 February 2025; GPAI obligations (Arts. 51–56) on 2 August 2025. Under the Digital Omnibus (adopted by Parliament 16 June 2026, Council adoption 29 June 2026), Annex III high-risk obligations move from 2 August 2026 to 2 December 2027; Article 50(2) watermarking shifts to 2 December 2026; a new Article 5 prohibition on AI generating CSAM/NCII applies from 2 December 2026. However, Article 50 transparency obligations (most), Article 49 EU database registration, and national market surveillance authority enforcement powers still apply from 2 August 2026 as enacted.
Penalties are tiered based on the nature of the violation. The maximum fine for prohibited practices under Article 5 is €35 million or 7% of global annual worldwide turnover, whichever is higher. For high-risk AI non-compliance: up to €15 million or 3%. For incorrect, incomplete or misleading information supplied to authorities under Article 99(5): up to €7.5 million or 1%. Article 50 transparency obligations fall under Article 99(4) at €15 million or 3%.
The "whichever is higher" mechanism means large global enterprises face substantially greater exposure than the fixed euro amounts suggest.
Yes. The Act has explicit extra-territorial scope, applying to providers established outside the EU if their AI systems are placed on the EU market or their output affects EU-based individuals. This mirrors the GDPR model and means US, UK, Asian, and other non-EU companies must comply if they serve EU users or operate AI systems that affect EU persons.
Annex III lists 8 domains where AI systems are automatically classified as high-risk: biometric identification and categorisation; AI for critical infrastructure; education and vocational training; employment and worker management; access to essential private and public services; law enforcement; migration and border management; and administration of justice.
High-risk classification triggers a full compliance burden including a risk management system (Art. 9), technical documentation (Annex IV), data governance, human oversight, and registration in the EU AI database.
General-Purpose AI (GPAI) refers to AI models with broad applicability, typically large language models and foundation models. Articles 51–56 impose obligations on GPAI providers including technical documentation, transparency information for downstream providers, copyright compliance policies, and summaries of training data. These obligations became active on 2 August 2025.
Models trained on compute exceeding 10²⁵ FLOPs are classified as GPAI with systemic risk and face additional obligations including adversarial testing, cybersecurity measures, and incident reporting to the European AI Office.
The EU AI Act and GDPR operate in parallel and frequently intersect. Many high-risk AI systems process personal data, requiring simultaneous compliance with both regimes. The FRIA (Fundamental Rights Impact Assessment) required under Article 27 of the AI Act complements the DPIA (Data Protection Impact Assessment) under GDPR Article 35. Supervisory authorities from both frameworks may have overlapping jurisdiction. Read our detailed comparison guide for a full analysis.
Track the Regulation as It Moves
The EU AI Act is not static. The Digital Omnibus package, Member State implementation laws, and Commission guidance are all evolving. Our editorial desk tracks the signals that matter for buyers, counsel, and compliance leads.
Digital Omnibus Adopted by Parliament, 16 June 2026
The European Parliament formally adopted the Digital Omnibus on 16 June 2026 (423–57), following the 7 May trilogue agreement. Council formal adoption 29 June 2026; Official Journal publication and entry into force pending. Annex III high-risk obligations move to 2 December 2027. New Article 5 prohibition on CSAM/NCII. Article 50(2) watermarking to 2 December 2026. Full analysis of what changed and what survived.
Read the analysis → 27-country trackerMember State Implementation Tracker
Who has named competent authorities? Who is late? Who is bundling implementation with GDPR reform? A country-by-country view, Germany's KI-VO DG adopted, Ireland's 15-authority model, France's CNIL-led approach.
Open the tracker → Compliance playbookWhat Still Applies on 2 August 2026, Post-Omnibus Playbook
The Omnibus deferred Annex III to 2 December 2027, but Article 50 transparency, Article 49 registration, GPAI enforcement, and national MSA powers still hit 2 August 2026. Plus what's new 2 December 2026 (watermarking + CSAM/NCII ban). Work plan sequenced by what authorities examine first.
Start the playbook →Where Does Your AI Stand Against the New Phased Timeline?
Find Out in 5 Minutes
Download our EU AI Act 5-Point Express Compliance Check, a structured self-assessment covering risk classification, Annex III applicability, documentation gaps, and board-level exposure. Delivered as a PDF immediately after submit.