The regulation governs AI systems according to their risk. Practices posing an unacceptable risk are prohibited under Art. 5 – including social scoring, deliberately manipulative techniques, emotion recognition in the workplace and certain real-time remote biometric identification for law enforcement purposes. High-risk systems (Art. 6 in conjunction with Annexes I and III) – for example in critical infrastructure, education, employment or law enforcement – are subject to comprehensive requirements covering risk management, data quality, technical documentation, human oversight and conformity assessment. Certain systems such as chatbots and generative AI are subject to transparency obligations under Art. 50, which we cover in detail on a dedicated knowledge page. The vast majority of AI systems in use fall into the minimal-risk category and remain free of specific obligations.
EU AI Act: Europe's Rulebook for Artificial Intelligence
Risk classes, deadlines after the Digital Omnibus, roles and penalties: what Regulation (EU) 2024/1689 means for businesses – as of July 2026.
With Regulation (EU) 2024/1689 – the AI Act – the EU has created the first horizontal legal framework for artificial intelligence. The regulation entered into force on 1 August 2024 and has been applying in stages ever since; it follows a risk-based approach ranging from outright prohibition to largely unregulated use. With amending Regulation (EU) 2026/1744 (the “Digital Omnibus on AI”), the EU legislator postponed key deadlines for high-risk systems in the summer of 2026 – the regulation's underlying risk-based approach remains unaffected. For CISOs, IT managers and compliance officers, the question is therefore less whether the AI Act affects them than in which role and from when.
Staggered application timeline
From the first prohibitions to the postponed high-risk deadlines — tap a milestone for details.
Prohibitions and AI literacy
The prohibitions of Art. 5 and the AI literacy obligation (Art. 4) have applied since this date.
GPAI, governance, penalties
The rules for general-purpose AI models (GPAI) as well as the governance and penalty provisions apply.
Remainder of the regulation applies
From this date, the remainder of the regulation applies, including the transparency obligations under Art. 50.
High risk under Annex III
Standalone high-risk systems under Annex III must meet the requirements only from this date — originally 2 August 2026.
High risk under Annex I
Systems embedded in regulated products under Annex I must meet the requirements only from this date — originally 2027.
The Essentials at a Glance
Six topic blocks — tap to expand.
The four risk tiers
From outright prohibition to largely unregulated use — tap a tier.
- Practices posing an unacceptable risk are prohibited — including social scoring, deliberately manipulative techniques and emotion recognition in the workplace.
- Also banned: certain real-time remote biometric identification for law enforcement purposes.
- Comprehensive requirements covering risk management, data quality, technical documentation, human oversight and conformity assessment.
- Applies for example to systems in critical infrastructure, education, employment or law enforcement.
- Certain systems such as chatbots and generative AI are subject to transparency obligations under Art. 50.
- The vast majority of AI systems in use fall into this category and remain free of specific obligations.
AI Act Reality Check — Deadlines, GPAI Enforcement & Agentic AI
Where the AI Act really stands after 2 August 2026: the high-risk deadlines fixed by the Digital Omnibus, the start of enforcement, German supervision — and the duties that already apply to AI agents today.
The real timeline
Reg. (EU) 2026/1744: Annex III fixed from 2 Dec 2027, Annex I from 2 Aug 2028 — Art. 50 and GPAI stayed on schedule.
Enforcement has arrived
AI Office fines since 2 Aug 2026, the German KI-MIG with BNetzA as central authority and full Art. 99 enforcement.
Agentic AI today
Dual disclosure under Art. 50, AI literacy under Art. 4 and the Art. 25 provider trap.
12-move playbook
Twelve concrete moves plus an AI Act calendar to August 2028.
English-language whitepaper · direct download after a short request.
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
Verordnung (EU) 2024/1689 (KI-Verordnung / AI Act)
Base regulation: risk-based approach (Art. 5, 6, 50), provider and deployer obligations (Art. 16, 26), penalties (Art. 99) and application timeline (Art. 113).
Verordnung (EU) 2026/1744 („Digital Omnibus on AI“)
Amending regulation (published 24 July 2026, in force since 27 July 2026): new high-risk deadlines, transition period for Art. 50(2) and two new prohibitions in Art. 5.
AI Act | Shaping Europe's digital future
The Commission's official overview of risk tiers, GPAI obligations and the current application timeline following the Digital Omnibus.
EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes
Legal analysis of the Omnibus agreement, including the Art. 50 transparency obligation, which continues to apply unchanged from 2 August 2026.
EU AI Act Compliance: prEN 18286 and ISO 42001
Research note on the relationship between ISO/IEC 42001 and the emerging harmonised standard EN 18286 (Art. 17), and on the presumption of conformity under Art. 40.
Implementation Timeline
Overview of the original application timeline, including the transitional rule for existing GPAI models under Art. 111(3) (as it stood before the Digital Omnibus).
Related Services
Where does your AI compliance stand?
In a no-obligation initial consultation, we map your AI systems to the AI Act's risk classes and show you exactly which deadlines and obligations apply to you.