EU AI Act Transparency obligations apply from 2 August 2026. High-risk obligations follow on 2 December 2027. Check if you're in scope

EU AI Act readiness · Regulation (EU) 2024/1689

What the Act requires,
and what it will cost you to build.

For US engineering and risk leaders who know they are in scope and need to know what attaches. Below: the timeline, the scope test, and the eight duties that generate work.

Not sure you are in scope? Take the two-minute scope check


Application timeline

The Act applies in stages —
and two of them moved in 2026.

The Digital Omnibus on AI, adopted in June 2026, deferred the high-risk obligations. Anything you read citing 2 August 2026 as the high-risk deadline predates it.

  1. 1 Aug 2024 Regulation (EU) 2024/1689 enters into force.
  2. 2 Feb 2025 Prohibited practices and AI literacy obligations apply.
  3. 2 Aug 2025 Obligations for general-purpose AI models apply. Penalties become applicable.
  4. 2 Aug 2026 Transparency obligations under Article 50 apply — disclosure that users are interacting with AI, and marking of generated content.
  5. 2 Dec 2026 New prohibitions on AI-generated non-consensual intimate imagery and CSAM apply. Watermarking obligations for systems already on the market take effect.
  6. 2 Dec 2027 High-risk obligations for standalone Annex III systems apply — deferred from 2 August 2026 by the Digital Omnibus.
  7. 2 Aug 2028 High-risk obligations for AI embedded in regulated products (Annex I) apply — deferred from 2 August 2027.

Reviewed 20 July 2026 against the European Commission's AI Act implementation timeline. Where transitional provisions apply to systems already on the market, we assess them against your specific deployment history.


Are you in scope?

Three questions decide it. Most teams get the second one wrong.

What role do you play? Provider, deployer, importer or distributor — possibly several, across different systems. The heaviest duties fall on providers.

Where is the output used? Not where your model runs, not where you are registered. If the output is used in the Union, that generally brings the system into scope.

Which tier? Prohibited, high-risk, limited, or minimal. Classification drives everything below.

The expensive assumption is that selling only to US customers keeps you out. If your customer has employees in Dublin and your system screens them, it usually does not.

The scope test in full


If a system is high-risk

What actually attaches.

These are the duties that generate work. Most are documentation and process. One of them is an engineering problem.

Art. 9 Risk management system
A continuous, documented process across the system lifecycle — not a one-off assessment filed at launch.
Art. 10 Data governance
Training, validation and testing data examined for relevance, representativeness and bias, with the examination recorded.
Art. 11 · Annex IV Technical documentation
Drawn up before the system is placed on the market and kept current. Annex IV specifies the contents.
Art. 12 Logging
Automatic recording of events across the system’s lifetime, enabling traceability appropriate to its purpose. This is the obligation that most agent architectures fail.
Art. 14 Human oversight
Designed in — oversight a person can actually exercise, with the authority and interface to intervene.
Art. 17 Quality management system
A documented QMS covering design control, testing, data management, incident reporting and record-keeping.
Art. 72 Post-market monitoring
An active, systematic plan to collect and review performance data throughout the system’s life.
Art. 73 Serious incident reporting
Reporting to market surveillance authorities on defined timelines once a serious incident is identified.

What non-compliance costs

Fines run to the higher of a fixed ceiling or a percentage of total worldwide annual turnover — group revenue, not EU revenue.

The fine is rarely what hurts first. Authorities can require corrective action, restrict availability, or order a system withdrawn from the Union market. If your European revenue rests on one product, that is the material risk.

The quieter cost is commercial. EU enterprise procurement now asks suppliers to evidence AI Act posture, and being unable to answer loses deals before any regulator appears.

Penalty tiers in detail


Start with whether it applies to you at all.

The Exposure Assessment answers that in two to three weeks, with a classification you can defend and a gap register your engineers can act on.