EUAIACTUS.COM

Regulation (EU) 2024/1689 • updated for 2026

EU AI Act: what companies need to know in 2026

The EU AI Act is in active implementation. The 2026 Digital Omnibus changed important timelines, Article 50 transparency rules now apply, GPAI obligations are already live, and high-risk systems require a longer-term readiness plan.

Updated and legally reviewed: 26 September 2026.

The framework

The Act regulates different AI risks in different ways.

Prohibited practices

Certain AI practices are prohibited. These rules are already part of the applicable framework and should be screened before downstream classification work.

Transparency-risk systems

Article 50 imposes disclosure, marking and labelling obligations for specified interactive, generative, biometric, emotion-recognition and deepfake-related uses from 2 August 2026.

High-risk AI

High-risk systems face extensive requirements on risk management, data, documentation, logs, transparency, human oversight, accuracy, robustness and cybersecurity, but the amended application timetable is now 2027/2028.

GPAI

General-purpose AI model providers have separate obligations, with additional duties for GPAI models with systemic risk. These obligations have applied since 2 August 2025.

2026 legal status

The timeline changed — but compliance work did not stop.

27 July 2026

Regulation (EU) 2026/1744 — the Digital Omnibus on AI — entered into force and amended the AI Act.

2 August 2026

Article 50 transparency obligations apply. The Commission and national authorities also began broader enforcement of applicable AI Act rules.

2 December 2027

Chapter III Sections 1–3 apply to Article 6(2) / Annex III high-risk systems under the amended timetable.

2 August 2028

The corresponding high-risk rules apply to Article 6(1) / Annex I product-linked systems.

For U.S. companies

EU establishment is not the only route into scope.

Article 2 can reach non-EU providers placing AI systems or GPAI models on the EU market and certain non-EU providers or deployers where an AI-system output is used in the Union. Role and facts matter.

Operational sequence

A defensible program starts with the system, not the checklist.

1. Inventory

Identify AI systems, intended purposes, model dependencies, users, affected persons, geography and vendors.

2. Role map

Determine provider, deployer, importer, distributor, product manufacturer, GPAI-provider or representative roles per system.

3. Risk classify

Screen prohibited practices, transparency obligations, GPAI duties and high-risk pathways.

4. Build controls

Translate requirements into policies, ownership, technical controls, documentation, vendor evidence, monitoring and review.