Regulation (EU) 2024/1689 • updated for 2026
EU AI Act: what companies need to know in 2026
The EU AI Act is in active implementation. The 2026 Digital Omnibus changed important timelines, Article 50 transparency rules now apply, GPAI obligations are already live, and high-risk systems require a longer-term readiness plan.
Updated and legally reviewed: 26 September 2026.
The framework
The Act regulates different AI risks in different ways.
Prohibited practices
Certain AI practices are prohibited. These rules are already part of the applicable framework and should be screened before downstream classification work.
Transparency-risk systems
Article 50 imposes disclosure, marking and labelling obligations for specified interactive, generative, biometric, emotion-recognition and deepfake-related uses from 2 August 2026.
High-risk AI
High-risk systems face extensive requirements on risk management, data, documentation, logs, transparency, human oversight, accuracy, robustness and cybersecurity, but the amended application timetable is now 2027/2028.
GPAI
General-purpose AI model providers have separate obligations, with additional duties for GPAI models with systemic risk. These obligations have applied since 2 August 2025.
2026 legal status
The timeline changed — but compliance work did not stop.
27 July 2026
Regulation (EU) 2026/1744 — the Digital Omnibus on AI — entered into force and amended the AI Act.
2 August 2026
Article 50 transparency obligations apply. The Commission and national authorities also began broader enforcement of applicable AI Act rules.
2 December 2027
Chapter III Sections 1–3 apply to Article 6(2) / Annex III high-risk systems under the amended timetable.
2 August 2028
The corresponding high-risk rules apply to Article 6(1) / Annex I product-linked systems.
For U.S. companies
EU establishment is not the only route into scope.
Article 2 can reach non-EU providers placing AI systems or GPAI models on the EU market and certain non-EU providers or deployers where an AI-system output is used in the Union. Role and facts matter.
Operational sequence
A defensible program starts with the system, not the checklist.
1. Inventory
Identify AI systems, intended purposes, model dependencies, users, affected persons, geography and vendors.
2. Role map
Determine provider, deployer, importer, distributor, product manufacturer, GPAI-provider or representative roles per system.
3. Risk classify
Screen prohibited practices, transparency obligations, GPAI duties and high-risk pathways.
4. Build controls
Translate requirements into policies, ownership, technical controls, documentation, vendor evidence, monitoring and review.
Primary sources