News · Governance
The AI Act applies in 2026: what changes for businesses
The AI Act broadly applies from 2 August 2026, but the obligations specific to high-risk systems have been postponed. Here is what changes now and how to organise compliance.
The European Union Artificial Intelligence Act entered its general application phase on 2 August 2026. For businesses, that does not mean every obligation starts on the same day. Several rules have applied since 2025, while the Digital Omnibus on AI, now Regulation (EU) 2026/1744, postponed the regime specific to high-risk systems.
The priority is not a single compliance project applied uniformly to every tool. A business should first inventory its AI uses, identify its legal role for each system, and then apply the correct timeline and controls in proportion to risk.
Key points
- Prohibited AI practices and the AI literacy obligation have applied since 2 February 2025.
- Governance rules and an initial set of obligations for general-purpose AI models have applied since 2 August 2025.
- Most other provisions of the AI Act have applied since 2 August 2026.
- Obligations specific to Annex III high-risk systems will apply on 2 December 2027.
- Obligations for high-risk systems embedded in regulated products under Annex I will apply on 2 August 2028.
- The postponement is not a reason to wait. Inventory, accountability, AI literacy, contracts and traceability are immediate priorities.

Operational timeline based on the AI Act and Regulation (EU) 2026/1744. Status verified on 6 August 2026.
What actually applies in August 2026
Regulation (EU) 2024/1689 established a phased application. Article 113 sets 2 August 2026 as the general date, alongside earlier milestones and exceptions. Regulation (EU) 2026/1744, published on 24 July 2026, subsequently amended the schedule for certain high-risk obligations.
This distinction prevents two opposite mistakes. The first is assuming that the AI Act has no effect before 2027. The second is applying the full high-risk compliance regime immediately to every AI tool used by a business.
| Area | Application date | Practical consequence |
|---|---|---|
| Prohibited practices and AI literacy | 2 February 2025 | Train people who use or oversee AI and exclude prohibited uses |
| EU governance, penalties and general-purpose AI models | 2 August 2025 | Check provider responsibilities and the information available about models |
| General application of the AI Act | 2 August 2026 | Apply relevant transparency, governance and cooperation duties |
| Annex III high-risk systems | 2 December 2027 | Prepare risk management, data, documentation, logs and human oversight |
| High-risk systems embedded in Annex I products | 2 August 2028 | Align AI compliance with the sectoral procedure for the relevant product |
These dates describe the general regime. A specific assessment must also consider the type of system, its intended purpose, the sector and the organisation's role.
First step: identify the organisation's role
The AI Act does not treat a provider that develops or places a system on the market in the same way as a deployer using it under its authority, an importer or a distributor. A company can also hold more than one role.
A buyer of a workplace assistant will usually be a deployer. An organisation that substantially modifies a solution, sells it under its own name or changes its intended purpose may move closer to provider responsibilities. The commercial contract alone does not settle the issue. The actual system, its purpose and the modifications made all matter.
For every use, an internal register should at least record:
- the business owner and technical owner;
- the purpose, users and affected people;
- the provider, model and third-party components;
- the data processed and its sensitivity;
- the decisions or actions influenced by the system;
- the organisation's likely role under the AI Act;
- human, technical and contractual controls;
- incidents, version changes and monitoring results.
Obligations that already demand attention
Exclude prohibited practices
Article 5 prohibits several practices, including certain forms of manipulation, exploitation of vulnerabilities, social scoring and biometric categorisation. The Digital Omnibus also added prohibitions concerning non-consensual sexual or intimate content and child sexual abuse material, with those new provisions applying from 2 December 2026.
An internal policy should therefore include prior review of use cases and a clear escalation mechanism. A standard IT procurement questionnaire is insufficient when a system can affect people, access sensitive data or act within a critical process.
Build role-specific AI literacy
Article 4 requires providers and deployers to take measures that ensure a sufficient level of AI literacy for staff and other people operating systems on their behalf. The regulation does not prescribe one course. The required level depends on knowledge, experience, context of use and the people affected.
An effective programme distinguishes users, business owners, technical teams, security staff and control functions. It covers system limitations, confidentiality, output verification, incidents and prohibited uses.
Treat transparency as a system property
Depending on the case, organisations may need to inform people that they are interacting with AI or that content has been artificially generated or manipulated. The detail depends on Article 50 and the organisation's role. Transparency should therefore be designed into interfaces, procedures and metadata, not appended after deployment.
Review general-purpose AI models
Providers of general-purpose AI models have their own obligations. For a business user, the operational question is whether the provider makes usable documentation available on capabilities, limitations, conditions of use and compliance measures. This documentation does not replace evaluation of the final system in its business context.
What the high-risk postponement changes, and what it does not
Regulation 2026/1744 set 2 December 2027 as the application date for Sections 1 to 3 of Chapter III for systems classified as high-risk under Article 6(2) and Annex III. These include certain uses in employment, education, essential services, biometrics, critical infrastructure and border management. For systems connected to Annex I products, the date is 2 August 2028.
The postponement provides time for standards, guidance and implementation. It does not turn a risky system into a risk-free one. Other rules may already apply, including the GDPR, employment law, cybersecurity requirements, consumer law and sector-specific obligations.
An organisation that waits until 2027 to discover its systems, locate their data or assign owners will lose the main benefit of the postponement. The foundational work takes time and already improves operational control.
A 90-day action plan
| Period | Action | Expected output |
|---|---|---|
| Days 1 to 30 | Identify systems and uses, including tools adopted directly by teams | Initial inventory with owners and purposes |
| Days 1 to 30 | Screen for prohibited practices and sensitive processing | Register of blocked cases or cases requiring enhanced review |
| Days 31 to 60 | Determine roles, risk levels and connected laws | Documented qualification matrix |
| Days 31 to 60 | Define an AI literacy programme by audience | Training paths and evidence of completion |
| Days 61 to 90 | Prioritise documentation, logs, evaluations and supplier clauses | Roadmap with accountable owners and deadlines |
| Days 61 to 90 | Organise alerts, incidents and model changes | Monitoring and escalation process |
Common mistakes
- Confusing a tool with a use case. The same model can create very different risk levels depending on the decision it supports.
- Relying on the provider alone. Component compliance does not prove that the integrated system or business process is compliant.
- Reducing AI literacy to general awareness. Expected competence must match each person's responsibilities.
- Ignoring informal adoption. Individual subscriptions and AI features embedded in software create blind spots.
- Waiting for the high-risk dates. Inventory, security, accountability and evidence should exist before the deadline.
The right decision for 2026
In August 2026, businesses should treat the AI Act as an active framework with a high-risk regime whose specific obligations have partly been postponed. The strongest approach connects compliance with engineering: know the systems, measure risks, control data, document decisions and monitor real behaviour.
That foundation allows the organisation to add specific requirements at the right time without rebuilding the programme for every new deadline.
Official sources
- Regulation (EU) 2024/1689, the Artificial Intelligence Act, the original AI Act and Article 113 timeline.
- Regulation (EU) 2026/1744, Digital Omnibus on AI, amending regulation published on 24 July 2026.
- European Commission: Navigating the AI Act, official summary of the timeline and responsibilities.
Sources verified on 6 August 2026. This article provides general operational information and is not legal advice.

