Skip to content

EU AI Act Deployer Obligations: What Actually Applies Now

The Digital Omnibus moved the high-risk deadlines to December 2027 and August 2028. What binds an organisation deploying AI today, what was postponed, and why the delay is engineering time rather than relief.

Noorain Fathima · 13 min read
The European Union flag rendered as a compliance timeline, marking the AI Act phases from February 2025 to August 2028
The European Union flag rendered as a compliance timeline, marking the AI Act phases from February 2025 to August 2028
Contents
  1. The quick answer
  2. Key takeaways
  3. What the Digital Omnibus actually changed
  4. Provider or deployer? The question that decides everything
  5. What binds you today
  6. The prohibitions, live since February 2025
  7. AI literacy, and why it is not a training video
  8. Article 50 transparency — the one that did land
  9. General-purpose model obligations
  10. What Article 26 will require, and why to start now
  11. The fundamental rights impact assessment
  12. The calendar as it now stands
  13. Penalties
  14. What the delay does and does not buy you
  15. Frequently asked questions
  16. Did anything at all take effect on 2 August 2026?
  17. Does the AI Act apply to my organisation if we are not in the EU?
  18. Is a general-purpose chatbot a high-risk AI system?
  19. What is the Article 6(3) exemption and can we rely on it?
  20. Do we need to do anything before December 2027?
  21. Final takeaway
  22. Sources and further reading

The compliance calendars drawn up in 2024 all circle the same date: 2 August 2026. That was the AI Act's general application date, the point at which the EU AI Act deployer obligations — the duties binding organisations that use AI rather than build it — were finally supposed to bite.

The date arrived. Most of those duties did not.

Six days earlier, on 27 July 2026, the Digital Omnibus on AI took effect and rewrote the schedule. It amended 42 articles and three annexes of Regulation (EU) 2024/1689 and moved the high-risk deadlines out by sixteen months to two years. The change is easy to misread in both directions: some obligations genuinely did land in August; the ones most organisations were bracing for did not.

The quick answer

As of September 2026, an organisation deploying AI in the EU is bound by three things: the prohibitions in Article 5, the AI literacy duty in Article 4, and the transparency duties in Article 50 — disclosing that a chatbot is a chatbot, labelling deepfakes, and telling people when emotion recognition or biometric categorisation is being applied to them. The full high-risk regime in Article 26 — human oversight, input data quality, log retention, incident reporting — does not reach Annex III systems until 2 December 2027, or product-embedded Annex I systems until 2 August 2028. Penalties have been enforceable since 2 August 2025.

Key takeaways

  • The Digital Omnibus on AI — Regulation (EU) 2026/1744 — entered into force on 27 July 2026 and amended 42 articles of the AI Act.
  • High-risk obligations moved: Annex III systems to 2 December 2027, Annex I product safety components to 2 August 2028.
  • Article 50 transparency duties did apply from 2 August 2026 and bind deployers directly, not just model providers.
  • Two new prohibitions — non-consensual intimate imagery and CSAM generation — take effect on 2 December 2026.
  • Whether you are a "provider" or a "deployer" decides which obligations attach — and it is easier to change accidentally than most teams expect.
  • Fines for breaching deployer duties under Article 26 or Article 50 reach €15 million or 3% of worldwide annual turnover, whichever is higher.

What the Digital Omnibus actually changed

The Commission proposed the package in November 2025 as a simplification measure, arguing the high-risk rules should apply once the harmonised standards exist to implement them — that the adjustment ensures "the rules apply when companies have the right support tools to facilitate implementation, such as standards."

That is a real argument. The standards meant to give providers a presumption of conformity have run late, and a conformity regime without conformity criteria leaves everyone guessing. It is also, unavoidably, a delay.

The amended Article 113 now staggers application across at least seven distinct dates. There is no longer a single "AI Act deadline" to organise a programme around. There are several, they apply to different parts of the same system, and a product combining a chatbot interface with an Annex III decision function now sits astride two of them.

Provider or deployer? The question that decides everything

Every obligation attaches to a role, and the roles are narrow. Article 3(4) defines a deployer as:

"a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity"

A provider, under Article 3(3), develops a system or model — or has one developed — and places it on the market under its own name or trademark, "whether for payment or free of charge".

Most organisations reading this are deployers. The trap is that the boundary is crossable: put your own brand on a system you bought, substantially modify a high-risk system, or change its intended purpose so that it becomes high-risk, and the Act treats you as its provider — with the conformity assessment, technical documentation and post-market monitoring apparatus that implies.

The practical version of the question, asked at design review rather than at audit: whose name is on the output, and did we change what the system is for? Teams white-labelling a vendor model into a customer-facing product often answer wrongly, because commercially it feels like procurement and legally it looks like manufacturing.

What binds you today

The prohibitions, live since February 2025

Article 5 bans eight practices outright, enforceable for over eighteen months now. The two most likely to catch an ordinary enterprise are emotion inference in the workplace or in education — permitted only for medical or safety purposes — and biometric categorisation used to deduce race, political opinions, religious beliefs, sex life or sexual orientation.

Neither is exotic. Sentiment scoring bolted onto a call-centre quality tool, or an HR analytics vendor inferring engagement from video, can land in the first category without anyone having framed it as emotion recognition. The prohibition follows the function, not the product description.

Two further prohibitions arrive on 2 December 2026, both added by the Omnibus: generating or manipulating realistic intimate imagery of an identifiable person without consent, and generating child sexual abuse material. Anyone running an image or video generation service for third parties should treat that as an engineering deadline, not a policy one.

AI literacy, and why it is not a training video

Article 4 requires providers and deployers to "take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf". The measures must take into account the staff's "technical knowledge, experience, education and training and the context the AI systems are to be used in".

There is no examination and no certification level to hit. What the article requires is proportionality: the literacy a compliance officer needs before signing off a screening tool is not what a warehouse supervisor needs before using a scheduling assistant. A single generic module issued to all staff satisfies the letter of it badly and its purpose not at all.

It is also the obligation most likely to be assessed retrospectively. When a deployed system goes wrong, "what had the operator been told about its limitations?" gets asked immediately — which is why records matter as much as training. UniverseBlend's rundown of the records regulators actually ask to see is a reasonable starting point.

Article 50 transparency — the one that did land

Article 50 applied from 2 August 2026, and unlike most of the Act it puts duties directly on deployers rather than only on providers.

Paragraph 3 requires deployers of emotion recognition or biometric categorisation systems to inform the people exposed to them. Paragraph 4 requires disclosure of deepfake content as artificially generated or manipulated, and of AI-generated text "published with the purpose of informing the public on matters of public interest". Paragraph 5 says disclosure must come "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure".

That last clause has design consequences. A disclosure buried in a terms page is not made at the time of first interaction, and a chatbot that identifies itself only when asked has not satisfied paragraph 1. These are interface decisions — they belong in the build, not the policy binder.

On the provider side, paragraph 2 requires machine-readable marking of synthetic audio, image, video and text output, to a standard "effective, interoperable, robust and reliable as far as this is technically feasible". The AI Act Explorer's timeline notes a grace period, with synthetic media providers given until 2 December 2026 to comply.

General-purpose model obligations

The GPAI chapter has applied since 2 August 2025 and binds model providers, not deployers. It reaches you indirectly: the documentation a provider must supply downstream is the raw material for your own compliance file, and its absence is a procurement problem you inherit. Models placed on the market before 2 August 2025 have until 2 August 2027 to comply, so some of what you build on today runs under an expiring legacy exemption.

That expiry is one of the reasons teams start weighing self-hosting, at which point the licence stops being the binding constraint and the memory footprint of an open-weights model starts being one. UniverseBlend's comparison of GPAI duties against the US state patchwork is useful if you operate on both sides of the Atlantic.

What Article 26 will require, and why to start now

When the high-risk regime arrives, Article 26 is what will govern most organisations. Its twelve paragraphs are worth knowing well before December 2027, because several are architectural rather than procedural.

ParagraphObligationWhy it is a build problem, not a policy one
1Use the system in accordance with the instructions for useRequires the instructions to be retained and version-matched to the deployed system
2Assign human oversight to people with "the necessary competence, training and authority, as well as the necessary support"Authority is the hard word: an overseer who cannot halt the system is decorative
4Where you control input data, ensure it is "relevant and sufficiently representative in view of the intended purpose"Implies data lineage you can evidence, not merely assert
5Monitor operation; report risks and serious incidents to the provider and market surveillance authorityNeeds a detection path, not just a reporting form
6Retain automatically generated logs for at least six monthsLog retention has to be designed in; it cannot be reconstructed after the fact
7Inform workers' representatives and affected workers before workplace deploymentA sequencing constraint on rollout, and often a works council timeline
11Inform individuals subject to decisions made with the systemAnother interface change, in a flow that may not currently have one

Paragraphs 2 and 6 are the ones worth acting on early. Human oversight with real authority tends to require an intervention path the system was not built to expose, and six months of logs is a storage and schema decision. Both are cheap to design in and expensive to retrofit — the argument for treating December 2027 as a build deadline rather than a filing one.

Paragraph 5 deserves a similar reading. Reporting serious incidents presumes you can detect them, and detection is where language model deployments are weakest: logging actions but not the content the model consumed produces incidents nobody can reconstruct. Where agents read untrusted input, the failure modes in our piece on why prompt injection cannot be filtered away are what your incident process has to cope with.

Paragraph 9 is the quiet efficiency in the article: where a data protection impact assessment is already required under the GDPR, deployers are to use the information the provider supplies to help fulfil it. If you have a functioning DPIA process, that is the hook to extend rather than a parallel process to invent.

The fundamental rights impact assessment

Article 27 adds an obligation for a narrower group: public bodies, entities providing public services, and private deployers of certain Annex III systems. Before use, they must assess the system's impact on fundamental rights and notify the market surveillance authority using a template from the AI Office.

Six components are required: the deployer's processes in which the system will be used; the duration and frequency of use; the "categories of natural persons and groups likely to be affected"; the specific risks of harm to them; the human oversight measures; and the arrangements if a risk materialises, "including the arrangements for internal governance and complaint mechanisms".

That last one reaches furthest into the business. A complaint mechanism implies someone receives complaints, someone can act on them, and a decision can actually be revisited. It is an operational commitment, and the part of Article 27 that cannot be written the week before a deadline.

The calendar as it now stands

DateWhat appliesWho it binds
2 February 2025Article 5 prohibitions; Article 4 AI literacyProviders and deployers
2 August 2025GPAI model obligations; governance; penalties; notified bodiesModel providers, member states
27 July 2026Digital Omnibus on AI appliesAmends the Act itself
2 August 2026Article 50 transparency; innovation, database and post-market chaptersProviders and deployers
2 December 2026NCII and CSAM prohibitions; synthetic media marking grace endsProviders and deployers
2 August 2027Legacy GPAI models placed before 2 August 2025 must complyModel providers
2 December 2027High-risk regime for Annex III systems, including Articles 26 and 27Providers and deployers
2 August 2028High-risk regime for Annex I product safety componentsProviders and deployers

Penalties

Article 99 sets three tiers, enforceable since August 2025 even though the conduct they attach to phases in later.

Breaching the Article 5 prohibitions carries fines "up to EUR 35 000 000 or, if the offender is an undertaking, up to 7 % of its total worldwide annual turnover for the preceding financial year, whichever is higher". Breaching operator obligations — a list expressly including Articles 26 and 50 — carries up to €15 million or 3% on the same basis. Misleading information to authorities carries up to €7.5 million or 1%.

For SMEs and start-ups the calculation inverts: the fine is capped at whichever of the fixed amount or the percentage is lower, rather than higher. It is a genuine concession, and it is the only place in the penalty article where company size changes the arithmetic.

What the delay does and does not buy you

It buys time on documentation, conformity evidence and the formal apparatus of Article 26. It buys none on anything a system's architecture determines.

Consider what has to be true by December 2027 for an Annex III deployment: logs retained six months, an oversight path with authority to stop, input data whose provenance can be described, incident detection that surfaces problems to a named function, and a user-facing disclosure in the decision flow. None of those is a document. All are decisions about how the system is built, and all are cheaper now than retrofitted into a system carrying live traffic.

The risk in the other direction is the more common failure. A delay announced eighteen months out reliably causes programmes to stand down, budgets to move and the working group to stop meeting. When the date returns, the institutional knowledge has dispersed and the work restarts colder than it left off.

Worth saying plainly, too: the Act is not the only instrument in play. The GDPR still applies to the personal data moving through these systems, sectoral regulators have their own expectations, and member state implementation adds a layer the Regulation does not settle. Vendor assurances do not close those gaps either — a control such as hardware attestation proves something considerably narrower than procurement usually asks of it.

Frequently asked questions

Did anything at all take effect on 2 August 2026?

Yes. The general application date stood for most of the Act; what moved was the high-risk regime. Article 50 transparency, the innovation chapter, the EU database provisions and post-market monitoring all applied from that date. The distinction is between the Act generally applying and the high-risk requirements specifically applying — conflating the two is the most common misreading right now.

Does the AI Act apply to my organisation if we are not in the EU?

It can. The Regulation reaches providers placing systems on the EU market wherever they are established, and deployers outside the Union where the system’s output is used inside it. The determining factor is the market and the affected people, not the office address. Take specific advice here — extraterritorial scope is fact-dependent.

Is a general-purpose chatbot a high-risk AI system?

Usually not by itself. Classification follows Article 6: either the system is a safety component of an Annex I product requiring third-party conformity assessment, or it falls within an Annex III use case. A chatbot becomes interesting once put to an Annex III purpose — screening job applicants, say — at which point the use case, not the technology, drives classification.

What is the Article 6(3) exemption and can we rely on it?

Article 6(3) lets an Annex III system escape high-risk classification if it poses no significant risk of harm and only performs a narrow procedural task, improves a previously completed human activity, detects deviations without replacing human assessment, or performs a preparatory task. Any system performing profiling of natural persons stays high-risk regardless. The exemption is real but narrow, and documenting it is your burden.

Do we need to do anything before December 2027?

The prohibitions, AI literacy and Article 50 duties are live now, so yes for those. Beyond that, the work worth doing early is technical rather than documentary: log retention, oversight interfaces, data lineage, incident detection. Those take longer than compliance teams estimate, which is why well-run programmes did not stand down when the dates moved.

Final takeaway

August 2026 did not turn out to be the cliff edge it was planned as. That is a fact about the calendar, not the direction of travel. The high-risk regime is coming on a published schedule, and the parts hardest to comply with are precisely those that have to be designed rather than documented.

The organisations that find December 2027 straightforward will be those treating the delay as engineering time. The ones that find it painful will be those that closed the programme in August. Both have the same eighteen months.

This is a description of the Regulation as amended, not legal advice. The Act's application to a specific system depends on facts this article cannot know.

Sources and further reading

0 likes, 0 saves

Found this useful? It helps to know.

Written by Noorain Fathima

AI engineer specialising in agentic systems and founder of MJ Smart Solutions in Bengaluru, building intelligent document processing, voice assistants and multi-agent platforms. Writes the Nexus on compute economics, model governance and agent security. Writing since March 2026. A published researcher and a product and UI/UX designer as well as an engineer, and studied at REVA University. That mix is the standard the Nexus holds itself to: sources opened and read rather than summarised second-hand, figures checked against the footnotes they come from, and every outbound link verified before a piece publishes.

Noorain Fathima on LinkedIn

Comments

No comments yet. Corrections and disagreements are especially welcome.

Leave a comment

Not published. Used only so we can reply.

Comments are reviewed before they appear.

Read Next

See all
A token price list overlaid on an electricity transmission tower, linking inference pricing to power infrastructure

LLM Token Pricing Is a Facilities Question

Emerging Technology

Output costs five times input because decode is memory-bound. Batch costs half because utilisation is the provider's central problem. Beneath both sits a floor made of power contracts and grid queues.

10 Sept 2026 · 12 min read

Subscribe to our newsletter

Occasional dispatches on AI, robotics and the engineering behind them. No spam, unsubscribe in one click.