Post-Omnibus Edition · Updated 14 July 2026

The EU AI Act deadline
didn't move for you.

Everyone heard "the EU delayed the AI Act." That's half true, and dangerous. The high-risk deadline moved to 2027, but Article 50 transparency obligations still apply from 2 August 2026, and they hit any organisation running a chatbot, a generative feature, or any AI that interacts with people. Penalties reach €35 million or 7% of global turnover.

Regulation EU 2024/1689 Reflects the adopted Omnibus (Council, 29 June 2026) Legally verified content

⏱  Time Until Article 50 Enforcement

2 August 2026
--Days
--Hours
--Mins
--Secs
Phased enforcement (post-Omnibus):
Feb 2025, Article 5 prohibitions + Article 4 AI literacy (in force)
Aug 2025, GPAI obligations Arts. 51–56 (in force)
2 Aug 2026, Article 50 transparency (most) + Article 49 registration + MSA powers
2 Dec 2026, Article 50(2) watermarking + new Article 5 CSAM/NCII ban
2 Dec 2027, Annex III high-risk AI (moved from 2 Aug 2026)
2 Aug 2028, Annex I embedded high-risk (moved from 2 Aug 2027)

Key Enforcement Numbers, EU AI Act (Regulation EU 2024/1689)

📋   58-point   compliance checklist
⚖️   €35M / 7%   max penalty
🗓   2 Dec 2027   Annex III deadline (post-Omnibus)
🌍   27 EU states   + EEA scope
📁   8 Annex III   high-risk domains
Free Interactive Tools

Start Your Compliance Work, Right Now, No Email Required

Six tools that take you from “is my system in scope?” to “which Articles apply?” without installing anything or signing up. Built on Regulation (EU) 2024/1689, verified against the Official Journal text.

NEW · 12 questions, 5 min

Risk Classifier (Full)

Map your AI system to Prohibited / High-Risk / Limited / Minimal with article-grounded scoring covering Article 5, 6, Annex III, Article 50, and Article 6(3) profiling override. Personalized PDF brief by email.

Take the classifier →
3-question quiz

Annex III Quick Check

Is your AI system high-risk under one of the 8 Annex III points? Get a verdict in under 60 seconds. (Top of funnel, quick first pass.)

Run quick check →
Article 27

FRIA Template

Fundamental Rights Impact Assessment, mandatory before deployment for public-sector and essential-service high-risk AI.

Open template →
58 checkpoints

Compliance Checklist

Article-by-Article review covering Articles 8–29 plus post-market obligations, mapped to your internal controls.

See the 58 points →
Article 99

Penalty Calculator

Estimate maximum exposure: €35M / 7% for prohibited, €15M / 3% for high-risk violations, €7.5M / 1% for misleading information to authorities.

Calculate exposure →
Live counter

Countdown Timer

Phased enforcement timeline, what still applies 2 Aug 2026, what's new 2 Dec 2026, and the 18-month runway to 2 Dec 2027 Annex III obligations under the 7 May Omnibus deal.

Track the deadline →
The Regulatory Framework

What Is the EU AI Act, and Does It Apply to You?

The EU AI Act is the European Union's landmark regulation governing the development, deployment, and use of artificial intelligence systems, the first comprehensive AI law anywhere in the world.

Published in the EU Official Journal on 12 July 2024 and entering into force on 1 August 2024, the Regulation establishes a risk-based compliance framework that classifies AI systems into four tiers: Prohibited, High-Risk, Limited-Risk, and Minimal-Risk. Each tier carries distinct obligations proportionate to the potential harm.

The Act applies to any organisation, regardless of where it is headquartered, that places an AI system on the EU market, deploys one within the EU, or whose AI output affects EU-based individuals. This extra-territorial scope mirrors the GDPR model and means thousands of non-EU companies must also comply.

Enforcement is not future tense. Article 5 prohibited practices have been active since 2 February 2025. GPAI obligations under Articles 51–56 became mandatory on 2 August 2025. The Annex III high-risk deadline moved to 2 December 2027 under the Digital Omnibus (adopted by Parliament 16 June 2026, Council adoption 29 June 2026), but Article 50 transparency and Article 49 registration still apply from 2 August 2026, so compliance programmes should already be underway.

Non-compliance carries administrative fines of up to €35 million or 7% of global annual worldwide turnover for the most serious violations, with a tiered structure reaching down to €7.5 million for information offences.

Read the Complete Guide →
Risk Tiers

EU AI Act Risk Classification Framework

The Act classifies all AI systems into four tiers. Your compliance obligations, and the penalties for non-compliance, depend entirely on your system's classification.

Risk Tier Examples Key Obligations Max Penalty Deadline
● Prohibited Social scoring by governments; real-time remote biometric ID in public spaces; subliminal manipulation; exploitation of vulnerabilities Complete prohibition. No deployment permitted. €35M / 7% 2 Feb 2025
● High-Risk Biometric systems; AI in recruitment; credit scoring; critical infrastructure management; medical devices; law enforcement tools Risk management system; technical documentation (Annex IV); data governance; human oversight; registration in EU database €15M / 3% 2 Dec 2027
● Limited-Risk Chatbots; deepfakes; emotion recognition systems; AI-generated content Transparency obligations (Art. 50): users must be informed they are interacting with AI and that content is AI-generated. Watermarking (Art. 50(2)): 2 Dec 2026. €15M / 3% 2 Aug 2026
● Minimal-Risk Spam filters; AI in video games; recommendation systems; inventory management No mandatory requirements. Voluntary codes of conduct encouraged. None No deadline

Detailed Risk Classification Guide →

The Stakes

Why Compliance Cannot Wait

The EU AI Act creates the most significant compliance burden for technology organisations since GDPR. These numbers define the risk landscape.

€35M
Max fine for prohibited AI violations (Art. 5)
7%
of global annual turnover, whichever is higher
8
Annex III high-risk AI domains requiring full compliance
27+
EU member states plus EEA and UK alignment scope

ACTIVE NOW

Article 5 Prohibitions

Certain AI practices are completely prohibited since 2 February 2025. These include government social scoring, exploiting psychological vulnerabilities, and most real-time remote biometric identification in public spaces.

Review Article 5 →
ACTIVE NOW

GPAI Obligations

General-Purpose AI model providers face transparency and documentation requirements active since 2 August 2025. Models above 10²⁵ FLOPs face additional systemic risk obligations including adversarial testing.

GPAI Compliance Guide →
2 DEC 2027

High-Risk AI Deadline

Annex III high-risk AI systems require a risk management system (Art. 9), technical documentation (Annex IV), data governance protocols, human oversight mechanisms, and EU database registration. The deadline moved from 2 August 2026 to 2 December 2027 under the Digital Omnibus.

Annex III Guide →
Risk Assessment Tool

Calculate Your Maximum Exposure

Enter your organisation's global annual revenue and the type of potential violation to estimate your maximum penalty exposure under the EU AI Act.

The Act uses a two-track calculation: a fixed maximum and a percentage of global annual turnover. The higher of the two applies, meaning large organisations face substantially greater risk.

This calculator provides indicative figures for risk planning purposes. Actual penalties depend on severity, intent, duration, and cooperation with supervisory authorities.

Full Penalties Guide →

EU AI Act Penalty Calculator

Maximum Penalty Exposure

Who this is for

The Omnibus didn't let you off the hook. It just changed which hook.

The "delay" only touched high-risk systems. If any of these is you, 2 August 2026 is still a live deadline.

💬

You run a chatbot or AI assistant

Article 50 says people must be told when they're interacting with AI. Customer-facing bot, support agent, virtual assistant, this applies to you on 2 August 2026, not 2027.

🎨

You ship generative or synthetic content

Generate text, images, audio, or video? Article 50(2) marking obligations hit new systems from 2 August 2026, existing ones by 2 December 2026. No grace period for launches this autumn.

⚖️

You advise clients on compliance

Consultants and law firms: the white-label licence lets you deliver these frameworks under your own brand, without rebuilding them from the regulation yourself.

Why buy, not build

Three ways to get compliant documentation. One is fast.

The regulation requires the same evidence however you produce it. Here's what each path costs.

Path 1

Hire a law firm

€10,000–€40,000

Accurate and expensive. Weeks of billable hours to produce documentation you could start from today.

Path 2

Read the regulation yourself

Weeks + real risk

144 articles, 13 annexes, plus the Omnibus amendments. Miss one Article 50 obligation and the penalty is up to €35M.

Path 3 · recommended

Start from the packs

$149–$999 · today

Every framework verified against Regulation (EU) 2024/1689 and the adopted Omnibus. Editable, yours, ready now.

See the packs →
Professional Resources

Compliance Documentation Built for Legal and Compliance Teams

Our compliance packs contain the exact documentation frameworks your legal team needs. Every document is structured around, and verified against, the full text of Regulation (EU) 2024/1689, Annex III, and the GPAI Code of Practice (July 2025).

Starter
EU AI Act Compliance Checklist Pack
$ 149 one-time

5 essential compliance documents for organisations beginning their EU AI Act compliance programme. Everything needed to assess exposure and present to leadership.

  • 58-Point Compliance Checklist, complete Article-by-Article assessment
  • Annex III Classification Matrix, determine your risk tier with confidence
  • AI System Inventory Template, catalogue all AI in use across the organisation
  • FRIA Starter (Article 27), Fundamental Rights Impact Assessment framework
  • Board Executive Briefing Template, present compliance status to leadership
Purchase, $149 →
Professional
EU AI Act White-Label Consultant License
$ 999 / year

Annual license to use, rebrand, and resell all 11 compliance documents to your clients. One client engagement typically covers the full annual cost.

  • All 11 documents from the Full Bundle
  • White-label license, brand with your firm's identity
  • Client-ready formatting for immediate deployment
  • Annual updates as regulatory guidance evolves
  • Use across unlimited client engagements
  • Suitable for law firms, consultancies, and compliance advisors
Purchase, $999/yr →

View Full Product Comparison →

Representative Scenarios

How Compliance Teams Use These Documents

Three common use cases for the Checklist Pack, Full Bundle, and White-Label License, based on the compliance journey of mid-size EU organisations preparing for Annex III enforcement.

Scenario 1 · DPO at SaaS Company

"The Annex III Classification Matrix made it immediately clear our hiring-automation feature was in scope. What would have been a multi-week legal review became a two-hour structured assessment with a defensible paper trail for the board."

Applicable product: Checklist Pack ($149)

Scenario 2 · Head of Compliance at Fintech

"We had ISO 42001 certification in progress and the EU AI Act obligations looming. The Mapping Matrix showed us which controls satisfied both frameworks simultaneously, cutting our documentation workload roughly in half."

Applicable product: Full Readiness Bundle ($499)

Scenario 3 · Partner at Boutique Consultancy

"The White-Label License paid for itself on the first engagement. Having pre-built, defensible frameworks meant we could focus advisory time on judgement calls rather than drafting boilerplate, and clients perceived higher value from the structured deliverables."

Applicable product: White-Label License ($999/yr)

Representative scenarios illustrating typical use cases, not direct quotations from named clients.

Enforcement Timeline

EU AI Act Phased Implementation Schedule

The EU AI Act does not enforce all requirements simultaneously. Understanding the phased schedule is critical to prioritising your compliance programme correctly.

The most immediate obligations, Article 5 prohibitions and GPAI requirements, are already active. Many organisations incorrectly assume nothing applies until the high-risk deadline, when in reality the Article 5 prohibitions (since February 2025) and GPAI obligations (since August 2025) are already in force.

Full Deadline Analysis →
12 July 2024
Regulation Published in EU Official Journal
Regulation EU 2024/1689 officially published. The 20-day entry-into-force countdown began.
1 August 2024
Regulation Entered Into Force
EU AI Act became binding EU law. National competent authorities began establishing governance structures.
2 February 2025, ACTIVE
Article 5 Prohibitions + Article 4 AI Literacy
All prohibited AI practices fully enforceable (max €35M / 7%). Article 4 AI literacy obligation simultaneously active for all AI providers and deployers across all risk tiers, this is the most-overlooked live obligation.
2 August 2025, ACTIVE
GPAI Obligations (Arts. 51–56) Enforceable
General-Purpose AI providers must comply with transparency, documentation, and copyright policies.
2 August 2026, STILL APPLIES
Article 50 Transparency (most) + Article 49 Registration + MSA Powers
Article 50 transparency obligations (chatbots, deepfakes, emotional-recognition disclosure) apply as enacted. Article 49 EU database registration applies. National market surveillance authority enforcement powers commence. Only Article 50(2) watermarking shifted under the Omnibus.
2 December 2026, NEW UNDER OMNIBUS
Article 50(2) Watermarking + New Article 5 CSAM/NCII Prohibition
Synthetic-content watermarking shifted four months (originally 2 Aug 2026). New Article 5 prohibition on AI generating non-consensual intimate imagery or CSAM applies from this date. Affects every generative AI provider.
2 December 2027, ANNEX III HIGH-RISK
Annex III High-Risk AI, Articles 9, 10, 11, 12, 13, 14, 15, 17, 27, 43, 72, 73
Moved from 2 August 2026 under the Digital Omnibus (adopted by Parliament 16 June 2026, Council adoption 29 June 2026), a 16-month deferral. Risk management, technical documentation, data governance, human oversight, FRIA, conformity assessment, post-market monitoring, serious-incident reporting.
2 August 2028
Annex I Embedded High-Risk AI
AI embedded as safety components in regulated products under Annex I (medical devices, machinery, vehicles) must comply. Moved from 2 August 2027 under the Omnibus, a 12-month deferral.
2 August 2030
Public Sector Legacy Systems (Art. 111)
Legacy AI systems used by public authorities granted extended transition period until August 2030.
Common Questions

EU AI Act, Frequently Asked Questions

The EU AI Act (Regulation EU 2024/1689) is the world's first comprehensive legal framework governing artificial intelligence. It entered into force on 1 August 2024 and applies to any organisation that develops, deploys, or imports AI systems in the EU, or whose AI output affects EU-based individuals, regardless of where the organisation is headquartered.

Enforcement is phased. Article 5 prohibitions and Article 4 AI literacy obligations became applicable on 2 February 2025; GPAI obligations (Arts. 51–56) on 2 August 2025. Under the Digital Omnibus (adopted by Parliament 16 June 2026, Council adoption 29 June 2026), Annex III high-risk obligations move from 2 August 2026 to 2 December 2027; Article 50(2) watermarking shifts to 2 December 2026; a new Article 5 prohibition on AI generating CSAM/NCII applies from 2 December 2026. However, Article 50 transparency obligations (most), Article 49 EU database registration, and national market surveillance authority enforcement powers still apply from 2 August 2026 as enacted.

Penalties are tiered based on the nature of the violation. The maximum fine for prohibited practices under Article 5 is €35 million or 7% of global annual worldwide turnover, whichever is higher. For high-risk AI non-compliance: up to €15 million or 3%. For incorrect, incomplete or misleading information supplied to authorities under Article 99(5): up to €7.5 million or 1%. Article 50 transparency obligations fall under Article 99(4) at €15 million or 3%.

The "whichever is higher" mechanism means large global enterprises face substantially greater exposure than the fixed euro amounts suggest.

Yes. The Act has explicit extra-territorial scope, applying to providers established outside the EU if their AI systems are placed on the EU market or their output affects EU-based individuals. This mirrors the GDPR model and means US, UK, Asian, and other non-EU companies must comply if they serve EU users or operate AI systems that affect EU persons.

Annex III lists 8 domains where AI systems are automatically classified as high-risk: biometric identification and categorisation; AI for critical infrastructure; education and vocational training; employment and worker management; access to essential private and public services; law enforcement; migration and border management; and administration of justice.

High-risk classification triggers a full compliance burden including a risk management system (Art. 9), technical documentation (Annex IV), data governance, human oversight, and registration in the EU AI database.

General-Purpose AI (GPAI) refers to AI models with broad applicability, typically large language models and foundation models. Articles 51–56 impose obligations on GPAI providers including technical documentation, transparency information for downstream providers, copyright compliance policies, and summaries of training data. These obligations became active on 2 August 2025.

Models trained on compute exceeding 10²⁵ FLOPs are classified as GPAI with systemic risk and face additional obligations including adversarial testing, cybersecurity measures, and incident reporting to the European AI Office.

The EU AI Act and GDPR operate in parallel and frequently intersect. Many high-risk AI systems process personal data, requiring simultaneous compliance with both regimes. The FRIA (Fundamental Rights Impact Assessment) required under Article 27 of the AI Act complements the DPIA (Data Protection Impact Assessment) under GDPR Article 35. Supervisory authorities from both frameworks may have overlapping jurisdiction. Read our detailed comparison guide for a full analysis.

Free Resource

Where Does Your AI Stand Against the New Phased Timeline?
Find Out in 5 Minutes

Download our EU AI Act 5-Point Express Compliance Check, a structured self-assessment covering risk classification, Annex III applicability, documentation gaps, and board-level exposure. Delivered as a PDF immediately after submit.

No spam. No marketing lists. PDF delivered immediately after submit. Privacy Policy

✓   Your checklist is downloading now. Check your inbox for a copy.