As of August 2, 2026, the bulk of the AI Act provisions will take effect.
That had been the EU’s objective when it adopted the regulation in June 2024. Since then, the digital omnibus has intervened. It has pushed the main deadlines to 2027 and 2028.
Two delays are evident on two fronts. On the one hand, in establishing the national competent authorities. On the other, in developing harmonized standards and common specifications. CENELEC (European Committee for Electrotechnical Standardization) is in charge. It was initially expected to deliver its copy by August 2025.
A few obligations will nevertheless apply from August 2, 2026. We sum them up here, as well as the rest of the timetable, by combining the reading of the AI Act with the Commission’s guidelines, codes of practice and other instruments published.
Some structuring concepts of the AI Act
AI models vs AI systems
Part of the AI Act’s provisions (Articles 51 to 55) specifically concerns general-use AI models.
Beyond the definition provided by the regulation, the associated guidelines detail some indicative criteria. A model is deemed to be of general use if its training required at least 10^23 flops (the typical computing power threshold for training 1B-scale models, according to Brussels) and it is able to generate language or produce an image or a video from text.
Exceptions are possible, typically where a model is unable to perform a wide range of distinct tasks (for instance, a model specialized in increasing image resolution).
The AI Act’s definition of a “AI system” is likewise accompanied by guidelines. They reproduce in full each key aspect (autonomy, adaptability, inference, etc.). And they set out a few exclusions. Among them, systems intended to accelerate traditional optimization methods (such as linear or logistic regression), those based on classical heuristics, and those dealing with underlying data (e.g., a DBMS filtering data based on criteria, a visualization tool forming a dashboard using statistical methods…).
Suppliers vs deployers
A supplier is any natural or legal person or entity that develops or has developed a system or model and places it on the market or puts it into service under their own name or brand.
A deployer is someone who uses a system under their own authority (personal activities fall outside the AI Act’s scope).
The regulation also defines the roles of importers and distributors. The importer places on the market a system that bears the name or brand of a person established outside the EU. The distributor is part of the supply chain that makes a system available in the EU.
By “placing on the market,” the first availability of an AI system or a general-use AI model in the EU is meant.
Deployment concerns only AI systems. It involves the supply of a system for first use in the EU, directly to the deployer or for their own use.
High risk vs systemic risk
The regulation defines which AI systems are high risk. Among them, those listed in Annex III. Broad domains include:
- Biometrics (remote identification, categorization, emotion recognition)
- Safety components of critical infrastructure
- Education and vocational training (admission, credential evaluation, cheating detection…)
- Employment (recruitment, career progression…)
- Access to essential private and public services (social assistance, credit assessment, prioritization of emergency interventions…)
- Enforcement
- Migration, asylum, border control management
- Administration of justice and democratic processes (interpretation of law, influence on electoral behavior…)
There are exceptions for these systems in cases where there is no significant risk of harm to health, safety or fundamental rights. This can occur, for example, when performing a narrow procedural task or improving a human activity previously carried out.
“Safety components” and “harmonization legislation”
Also high risk is a system that meets both of the following conditions:
- Designed to be used as a safety component of a product covered by EU harmonization legislation (or itself constitutes such a product)
- This component, or the system itself as a product, is subject to third-party conformity assessment under harmonization legislation
This “harmonization legislation” brings together sectoral directives and regulations. The AI Act lists, in Annex I, about twenty, targeting toys, elevators, medical devices, marine equipment, civil aviation, etc.
The digital omnibus clarified the notion of a “safety component” to avoid AI systems being misclassified as high risk. It notably excluded those intended only to perform user assistance, performance optimization, service efficiency, or automation.
Another clarification: integrating an AI system into a product subject to harmonization legislation does not automatically mean it is a safety component.
Characterizing systemic risk in AI models
Specific provisions apply to general-use AI models that present systemic risk. This risk can arise from “high-impact capabilities.” Specifically, at least as powerful as those present in the most advanced models. Systemic risk exists if real or reasonably foreseeable adverse effects on public health, health and fundamental rights could propagate along the value chain.
The guidelines for general-use AI models provide an indicative criterion: 10^25 flops. If training required more computing power, systemic risk may be presumed. The European Commission can also decide there is systemic risk by examining the criteria listed in Annex XIII of the AI Act (number of parameters, data quality or size, input and output modalities, number of end users…).
To estimate the amount of computing power used, Brussels proposes two approaches. They rely respectively on architecture and hardware. They require including resources used to generate synthetic data. And for training if they are not publicly accessible.
The main rules already in force
Training users
Article 4 of the AI Act formed part of the first set of provisions to come into force (February 2025). It requires suppliers and deployers to train their staff and other people responsible for operating and using AI systems on their behalf. This includes, for example, companies that allow their employees to use ChatGPT.
On August 3, 2026, the national competent authorities will officially begin monitoring compliance with this obligation. It is noteworthy that the digital omnibus removed the requirement for a specific level (or “adequate”) per individual.
The European Commission maintains a directory of examples showing how organizations disseminate AI literacy. It includes around forty cases, including Booking.com, Criteo, IBM, Kaspersky, Palantir, SAS and Workday. This database helped produce a report with the Alliance for AI Skills (a project funded by Erasmus+).
For SMEs, Brussels recommends turning to the network of European Digital Innovation Hubs (EDIH). It also mentions the GenAI Skills Academy—a project launched in 2025 under the Digital Europe programme—but which has not yet materialized.
Prohibited practices
The other major item in force since February 2025 is Article 5. Its purpose: prohibited practices. The European Commission has likewise attached guidelines.
Among exceptions, emotion recognition and surveillance in the workplace and in educational settings, as long as it is for medical or safety reasons.
There are also exceptions, among other things, for artistic works. Notably, a practice added by the digital omnibus: sexually explicit content.
General-use AI models
After the February 2025 deadline, August 2025 arrived. At that time, the provisions relating to general-use AI models came into force. They cover:
- Technical documentation
- Communication of information to downstream AI system providers
- Copyright compliance policy
- Public summary of the training data content
There are specific requirements in cases of systemic risks (mitigation of these risks, documentation of serious incidents, cybersecurity safeguards…).
August 2, 2026 will mark the end of the “grace period” granted to suppliers to achieve compliance.
Pending harmonized standards, the principal conformity instrument is the General Code of Practice for General-Use AI. It comprises three chapters: transparency; copyright; safety and security. The latter applies only to models presenting systemic risk.
As of the latest tally, about twenty have signed this code of practice. Namely, Accexible, AI Studio Delta, Aleph Alpha, Almawave, Amazon, Anthropic, Black Forest Labs, Bria AI, Cohere, Domyn, Dweve, Fastweb, Google, IBM, Lawise, LINAGORA, Microsoft, Mistral AI, Open Hippo, OpenAI, Pleias, ServiceNow and WRITER. xAI signed only the safety/security chapter.
Whoever modifies a model can become its supplier
In addition, the European Commission published guidelines on the scope of obligations for suppliers of general-use AI models. They reveal that anyone who modifies a model—even via fine-tuning—can become the supplier. The condition: a significant modification of generality, capabilities or systemic risk. Again, Brussels provides an indicative criterion based on computing power: more than a third of the power used to train the original model.
If the modifier does not know this value, the threshold is one third of the power beyond which a model is deemed to be general-use (i.e., 10^23/3 flops). If it presents systemic risk, it is 10^25/3 flops.
In line with the proportionality principle, the new supplier’s obligations are limited to the modifications made. And, with regard to copyright and disclosure of training data, to the data used for the modification alone.
The European Commission acknowledges that this criterion is largely forward-looking. It broadly considers that it is difficult to define to what extent a modification yields a distinct model. Therefore, as of now, it treats each version arising from the same large-scale training provided by the same supplier as a single model.
Older models must be brought into compliance
The guidelines provide some clarifications on the case of models whose weights are published under an open license. This implies rights of consultation, modification, and distribution, with publication of architecture information.
In the absence of systemic risk, these models escape the requirements for technical documentation to authorities and downstream information to suppliers. But not the implementation of an author-rights policy.
The publication of an open-model version can constitute a market placement, the guidelines specify. The same applies, more broadly, to any internal use if it is essential to supplying a product or a service to third parties in the EU; or if it infringes the rights of individuals in the EU.
For general-use AI models, the AI Act is retroactive: those placed on the market before August 2, 2025 must be brought into compliance by August 2, 2027 at the latest.
There is no comparable regime for AI systems placed on the market or put into service before December 2027 (for those concerned) or August 2028 (for others). Unless they undergo major redesigns. Or if they are used by public authorities. In which case they must comply with the AI Act by August 2030 at the latest. There is also an exception for AI systems integrated into a few large EU information systems:
- Schengen Information System
- Visa Information System
- Eurodac (biometric data)
- Registration of entry and exit data of third-country nationals
- Travel information and authorization
- Criminal records of third-country nationals and stateless persons
Rules applying on August 2, 2026
Transparency of AI systems and content
August 2, 2026 marks the entry into force of Article 50 of the AI Act. It lays down various transparency obligations for AI system suppliers and deployers.
The first paragraph concerns AI systems intended to interact directly with natural persons. It requires their suppliers to ensure proper information to users.
The second paragraph requires suppliers of generative systems to attach machine-readable labeling to outputs. Exemptions apply to systems that provide formatting assistance for standard outputs. The same applies to those that do not substantially modify inputs or their semantics.
Deployers of systems generating deepfake audio and video (including still images) must indicate that the content has been generated or manipulated by AI. The same applies to texts published to inform the public on matters of public interest.
A grace period and content labeling exceptions
The European Commission has published a Code of Practice on content transparency. Adhering to it does not automatically demonstrate compliance.
Consequently, under the digital omnibus, a grace period until December 2, 2026 is confirmed for machine labeling in systems placed on the market before August 2, 2026.
The code specifies that certain outputs are outside the scope of transparency obligations:
- Short sequences of numbers, symbols or letters
- Source code
- Outputs processed solely in machine-to-machine contexts without human exposure
- Outputs used in closed-loop in an industrial or product development context (e.g., film production)
No labeling technique currently satisfies the four criteria set out by the AI Act (effectiveness, interoperability, robustness, reliability). A combination is therefore required. The code of practice suggests pairing signed metadata with an invisible watermark. It adds fingerprinting as an optional method.
Free text cannot transport metadata, so a single layer is considered sufficient. The same applies to generative systems embedded in physical products integrated into a closed, technically controlled environment and mainly instructional in nature.
Detection of content: Europe demands free access… with limits
To offset potentially lower reliability of watermarks on free text, affected suppliers may restrict access to the detection solution to expert users. In all cases, they will preferably implement watermarking at the inference stage rather than post hoc. Objective: facilitate downstream compliance for suppliers of AI systems.
For providing the detection solution, there are three options: specification, software (executable or library) or API service. It will be free… with the possibility to charge “reasonable fees” for AI systems that have at least 1 million monthly active users, in cases where user requests exceed a “reasonable threshold.”
Suppliers are encouraged—though not required—to include provenance information (name of the AI system, model used…). And to provide deployers with the means to apply visible labels at generation. Another option mentioned: a forensic detection mechanism for content whose labeling has been removed.
Practical labeling of deepfakes
The second section of the code of practice covers labeling of deepfakes by deployers.
If a visual disclosure is possible, the label must include, as the main element, an “AI” icon. Unless English usage is incompatible with the national language provisions governing business or administrative use. The letters should have the same vertical dimension. Brussels encourages including, in the icon or nearby, mentions such as “modified” or “generated.”
For audio content, an audio warning should be added at the beginning. Either in English or in the content language. Anticipating downstream changes, this warning should be repeated regularly, at least after interruptions.
In all cases, the label must remain visible long enough for the user to notice it. It should be embedded in the content unless alternative mechanisms—UI overlays—are available. For short texts, a contextual notification can be used to avoid degrading the content.
A toolbox to prepare for 2027-2028 deadlines
The high-risk AI requirements listed in Annex III will apply only in December 2027. It will be August 2028 for others (safety components linked to Annex I).
Meanwhile, the European Commission offers a so-called “conformity checker.” In beta and in English, it helps to understand, by answering a series of questions, which rules are likely to apply to a given model or AI system.
The Brussels toolbox also includes the AI Act Explorer. It is essentially a dashboard with a search engine, a chapter-by-chapter table of contents and grids of considerations and annexes.
Also included is a FAQ compilation (partly translated into French) and a support service (contact form with the AI Office, accessible with an EU login).
All of this can be found on a centralized single portal: the “AI Act Information Platform.”
The FAQ compilation refers to AI agents. A term not legally defined and used for several types of artifacts. However, the rules of the AI Act apply to them.
Among other references are the famous “small caps” (small and mid-capitalization firms). They are not SMEs in the sense of European law, but employ fewer than 750 people and report annual revenue under €150 million and/or assets under €129 million. The digital omnibus makes them beneficiaries of some waivers that the AI Act had originally reserved to SMEs. For example, simplified technical documentation.
The digital omnibus, from small to large waivers
The digital omnibus also had the effect of exempting industrial AI from a large portion of the regulation. The lever: shifting Annex I from Section A to Section B. This excludes it from certain scenarios where the product manufacturer can be considered the supplier of the embedded AI system.
Another liberalization: the limitation of obligations on high-risk AI systems when harmonization legislation (Annex I, Section A) provides health, safety or fundamental rights protection at least equivalent to that under the AI Act. It remains for the Commission to adopt, by August 2027, delegated acts to clarify which AI systems are concerned.
Sensitive data and real-world testing: broader access
The digital omnibus also broadens the exceptional authorization to process sensitive data for detecting and correcting biases. The original text granted this to high-risk AI system providers. As amended, it now also covers providers and deployers of other AI systems and models. The condition remains that biases could threaten health, safety or fundamental rights.
Deployers of most of the AI systems listed in Annex III have access to a “boost” for their fundamental rights impact assessments. They may now include references to analyses of personal data impact.
In the spirit of simplification, high-risk AI systems meeting certain cybersecurity resilience requirements are deemed compliant with the cyber-security requirements of the AI Act.
The digital omnibus also broadens the possibilities for real-world testing of AI systems outside regulatory sandboxes. What was previously allowed for the Annex III-listed systems becomes allowed for those in Annex I. A test can last up to 12 months (6 months extendable).