EU AI Act Compliance: The Complete 2026 Guide
Last updated 2 August 2026 — reflects the Digital Omnibus on AI.
Everything a product, legal, or engineering team needs to understand EU AI Act compliance in 2026 — the updated timeline after the Digital Omnibus, who is in scope, what applies today, and what the fines are.
On this page
If your company builds, sells, or deploys AI and touches the European market, the EU AI Act (Regulation (EU) 2024/1689) is now your baseline. It is the world's first comprehensive AI law, and after the Digital Omnibus on AI reshaped several deadlines in mid-2026, a lot of the advice published in 2024 and 2025 is out of date. This guide is the current, plain-English picture as of August 2026 — what applies today, what was pushed back, who is in scope, and what the fines are.
What is the EU AI Act?
The EU AI Act is a risk-based regulation. Instead of writing rules for specific technologies, it sorts AI systems into risk tiers and attaches obligations to each tier. The higher the risk to health, safety, or fundamental rights, the heavier the requirements.
- Unacceptable risk — banned outright (Article 5): social scoring, untargeted scraping of facial images, most real-time remote biometric identification in public, manipulative or exploitative systems.
- High risk — permitted but heavily regulated (Annex III and Annex I): AI in recruitment, credit scoring, education, critical infrastructure, biometrics, law enforcement, medical devices, and more.
- Limited risk — transparency duties only (Article 50): chatbots, generative AI output, deepfakes, emotion recognition.
- Minimal risk — no specific obligations: spam filters, most recommendation and productivity tools.
EU AI Act timeline: what applies when (2024–2028)
This is the part that changed. The original Act front-loaded high-risk obligations onto 2 August 2026. The Digital Omnibus on AI — politically agreed on 8 July 2026 and awaiting publication in the Official Journal — pushed those back. Here is the current schedule:
| Date | What applies | Status |
|---|---|---|
| 1 Aug 2024 | Act enters into force | Done |
| 2 Feb 2025 | Prohibited practices (Art 5) + AI literacy duty (Art 4) | In force |
| 2 Aug 2025 | GPAI model obligations (Art 53–55); governance bodies | In force |
| 2 Aug 2026 | Transparency obligations (Art 50) | Now live |
| 2 Dec 2026 | Grace period ends for watermarking of existing systems; new prohibition on AI-generated non-consensual intimate imagery / CSAM | Upcoming |
| 2 Dec 2027 | High-risk stand-alone systems (Annex III) — deferred from Aug 2026 | Deferred |
| 2 Aug 2028 | High-risk embedded in regulated products (Annex I) — deferred from Aug 2027 | Deferred |
What the Digital Omnibus on AI changed
The Digital Omnibus is a simplification package. For the AI Act specifically, the headline changes are:
- High-risk deadlines pushed back. Annex III stand-alone systems move to 2 December 2027; Annex I product-embedded systems move to 2 August 2028. That is roughly 16 extra months for the heaviest obligations.
- Transparency stays on schedule. Article 50 was not deferred — it applies from 2 August 2026 as planned.
- A short watermarking grace period. Systems already on the market get until 2 December 2026 to implement machine-readable marking of AI-generated content.
- A new prohibition covering AI-generated non-consensual intimate imagery and CSAM, with a transitional period ending 2 December 2026.
Two cautions. First, the Omnibus was still awaiting formal publication in the Official Journal at the time of writing; treat the deferred dates as the firm political agreement rather than a settled statutory text. Second, a longer runway is not a reason to stop — high-risk documentation takes months to build, and the transparency rules that are live already touch most companies.
Does the EU AI Act apply to my company?
Almost certainly, if you have European users. Like GDPR, the Act has extraterritorial reach. You are in scope if you are:
- A provider placing an AI system or GPAI model on the EU market — wherever you are headquartered.
- A deployer (business user) of an AI system that is established or located in the EU.
- A provider or deployer outside the EU whose AI system's output is used in the EU.
So a US or UK startup with EU customers, or an agency deploying an AI tool for an EU client, is squarely in scope. A company with no EU users and no EU output is generally not.
EU AI Act penalties and fines
The fines are tiered and, at the top end, larger than GDPR:
| Violation | Maximum fine |
|---|---|
| Prohibited practices (Art 5) | €35 million or 7% of global annual turnover |
| Other obligations — including Article 50 transparency and high-risk duties | €15 million or 3% of global turnover |
| Supplying incorrect information to authorities | €7.5 million or 1.5% of turnover |
Whichever figure is higher applies. SMEs and startups face proportionally reduced caps, but are not exempt.
What to do now: a practical checklist
- Inventory your AI. List every AI system and model you build or use, including third-party APIs embedded in your product.
- Classify each system by risk tier. Most SaaS products land in "limited risk," which means Article 50 transparency — the obligation that is live today.
- Ship the transparency basics now: disclose AI chatbots, mark AI-generated content in a machine-readable way, and label deepfakes. See our Article 50 guide.
- Stand up governance. An ISO 42001 AI management system gives you a defensible, auditable framework that maps cleanly onto the Act.
- Meet the AI literacy duty (Art 4) — already in force — by training staff who build or operate AI.
- Use the deferral wisely. If any of your systems are high-risk, start Annex IV technical documentation now; the December 2027 deadline arrives faster than it reads.
Need help getting AI Act–ready?
GenAI Labs helps teams classify their AI systems, produce the documentation the Act requires, and ship compliant products. Book a working session with our team.
Talk to GenAI Labs →Frequently asked questions
When does the EU AI Act apply?
The Act entered into force on 1 August 2024 and applies in stages. Prohibited practices and the AI literacy duty applied from 2 February 2025, GPAI model obligations from 2 August 2025, and transparency obligations (Article 50) from 2 August 2026. Following the Digital Omnibus on AI, high-risk obligations were deferred to 2 December 2027 (Annex III stand-alone systems) and 2 August 2028 (Annex I product-embedded systems).
What is the difference between the original AI Act deadlines and the Digital Omnibus dates?
The original AI Act required most high-risk obligations from 2 August 2026 (Annex III) and 2 August 2027 (Annex I). The Digital Omnibus on AI, agreed on 8 July 2026, deferred these to 2 December 2027 and 2 August 2028 respectively. Transparency obligations under Article 50 were not deferred and apply from 2 August 2026.
Does the EU AI Act apply to companies outside the EU?
Yes. Like the GDPR, the AI Act has extraterritorial reach. It applies to any provider placing an AI system on the EU market, any deployer located in the EU, and any provider or deployer whose AI system output is used in the EU, regardless of where the company is based.
What are the fines for breaching the EU AI Act?
Up to €35 million or 7% of global annual turnover for prohibited practices; up to €15 million or 3% for breaching other obligations, including transparency and high-risk duties; and up to €7.5 million or 1.5% for supplying incorrect information. The higher of the fixed sum or turnover percentage applies. SMEs face reduced caps.
Is the EU AI Act in force now in 2026?
Yes. Multiple parts are already in force: prohibited practices (since February 2025), GPAI obligations (since August 2025), and transparency obligations under Article 50 (since 2 August 2026). Only the high-risk obligations remain in the future, deferred to December 2027 and August 2028.