Skip to content
Tekoälli

Regulation

The AI Act: what applies, and when

The high-risk deadline moved in the summer of 2026, but most guides still quote the old dates. What an organisation using AI actually needs to know.

Harri Salomaa8 min

A timeline on which one deadline has moved later. The old date is faded and an arrow points to the new one.
Contents (9)

If you search for information about the EU AI Act right now, you will probably get an out-of-date answer. Almost every guide says that obligations for high-risk systems begin on 2 August 2026. That date has just passed, and the obligations did not begin.

In the summer of 2026, amending Regulation (EU) 2026/1744 was adopted, known as the Digital Omnibus on AI. It entered into force on 27 July 2026 and pushed the high-risk obligations back by more than a year. The reason was practical: harmonised standards and national authority arrangements were not ready by the time the requirements were due to start.

This article gives the position as it stood on 6 August 2026, written for somebody who uses AI at work rather than building models. It is a plain-language explanation and not legal advice, and the dates are worth checking against the source before anything is built on them.

The timetable now in force

WhatWhenStatus
Prohibited practices and staff AI literacy2 Feb 2025in force
General-purpose model obligations, supervisory structures, penalties2 Aug 2025in force
Transparency obligations (Article 50)2 Aug 2026in force now
New prohibition on non-consensual intimate material2 Dec 2026coming
Transitional period for labelling older systems2 Dec 2026coming
High risk, Annex III: recruitment, credit, education, workforce management2 Dec 2027moved, was 2 Aug 2026
High risk, Annex I: systems embedded in products2 Aug 2028moved, was 2 Aug 2027

The amending regulation did more than move deadlines. It also softened the wording on AI literacy, added two new prohibitions, narrowed the definition of a safety component and reduced the administrative burden on small companies. The postponement is therefore not permission to forget about it but extra time to prepare, and preparing means knowing, before December 2027, which of your own use cases fall under Annex III.

The category comes from the use, not the technology

This is the Act's most important and most frequently skipped premise. The regulation does not classify models but purposes. The same language model can sit in four different categories at once inside one organisation.

  • Prohibited. Manipulation causing significant harm, social scoring, scraping facial images into recognition databases, inferring emotions in the workplace or in education, and certain biometric categorisations. These may not be done at all, and the prohibition has applied since February 2025.
  • High risk. As a rule of thumb, a system that makes or prepares a significant decision about a person's life: recruitment and selection, promotion and dismissal, granting credit, access to education, critical infrastructure, healthcare, law enforcement. Legally, though, the category is not settled by a rule of thumb but by Article 6 together with Annexes I and III, and Article 6 also contains exceptions under which a listed use can fall outside the category. These carry the most obligations, and the deadline is now December 2027.
  • Transparency obligation. Chatbots, artificial content, emotion recognition. Few obligations, but they apply now.
  • Everything else. Most everyday use. No specific obligations, though other law still applies.

A practical rule follows. The question is not "do we have AI" but "what decisions is it used for". Drafting marketing copy and pre-screening applications are two entirely different matters with the same tool.

Two roles, and the role can change by accident

The Act recognises several roles, of which two are enough for most:

  • A provider develops a system or places it on the market under its own name.
  • A deployer uses a system in its own operations.

Most organisations are deployers, and a deployer's obligations are considerably lighter. There is a trap here worth knowing in advance, though: a deployer becomes a provider if it puts its own name or trade mark on a high-risk system, substantially changes what the system is for, or makes a significant modification to it.

In practice that means an in-house recruitment tool built on top of a ready-made model can make your organisation a provider even though you trained nothing yourself. Then you do not have a few obligations but the whole list.

What a deployer has to do now

Two things apply to a deployer today, regardless of whose model it is.

Staff AI literacy (Article 4). The obligation has applied since February 2025, but its wording was softened in the amending regulation. Previously an organisation had to ensure a sufficient level of competence. Now it must take measures that support the development of competence, and no particular individual level has to be guaranteed. It is an obligation of effort, not of outcome. The measures are proportionate to what people do, what background they have, and what a mistake would cause. No certificate is required. This is the obligation most organisations have missed, because it does not sound like one.

Transparency (Article 50), in force since 2 August 2026. The obligations split in two, and the split decides whether something is yours or your supplier's.

The provider's responsibility:

  1. The system says it is a machine. Systems that converse with people must be designed so the user knows they are talking to AI, unless that is obvious.
  2. A machine-readable mark. Audio, images, video and text produced or modified by AI are marked so the mark can be detected by machine. There are several exceptions, for example short strings, source code and assistive editing functions.

The deployer's responsibility:

  1. A visible notice on a deepfake. An artificial image, sound or video that looks genuine must be clearly labelled, at the first encounter at the latest. In an artistic, satirical or fictional work it is enough to say so in a way that does not spoil the work.
  2. AI text published on matters of public interest. If you publish AI-generated text to inform the public about a matter of societal importance, it must be labelled. No label is required if the text has been through human editorial review and somebody answers for it.
  3. Emotion recognition and biometric categorisation. The people the system is applied to must be told how it works.

The visible marks have to be noticeable to a person without special tools. For systems placed on the market before August 2026, the machine-readable mark has a transitional period running to the beginning of December 2026.

The practical consequence for an ordinary organisation: the machine-readable mark is not your problem but the tool maker's. What you publish, and how you label it, is yours.

What high-risk use will require later

If your own use falls under Annex III, from December 2027 a deployer is expected to do, among other things, the following:

  • use the system in accordance with its instructions, not outside them
  • have named human oversight, with the competence and the authority to intervene
  • ensure input data is appropriate and representative for the purpose
  • keep logs
  • inform employees when a high-risk system is applied to them
  • and, for public bodies and certain private ones, carry out a fundamental rights impact assessment

None of these is a technical task. They are decisions about who answers for what, which is why they are worth making before the system is in production.

Who supervises

Supervision is national, so the competent authority depends on the country as well as the sector. Finland's complementary national legislation entered into force on 1 January 2026, and supervision there is divided among roughly fifteen authorities according to the sector concerned.

  • Traficom acts as the single point of contact and coordinates supervision.
  • The Office of the Data Protection Ombudsman supervises prohibited practices, part of the high-risk systems, and the realisation of fundamental rights.
  • Tukes supervises systems relating to products and industry.
  • The rest divide by sector: healthcare, medicines, energy, occupational safety.

The practical consequence: the right authority depends on what the AI is used for, not on which company built it.

Penalties

The maximums come in three tiers:

InfringementMaximum penalty
A prohibited practice35 million euros or 7% of worldwide turnover
Other obligations, for example transparency15 million euros or 3%
Supplying incorrect information to an authority7.5 million euros or 1%

For a larger operator the higher of the two applies, and for a small or medium-sized enterprise the lower. The figures are ceilings, not a tariff.

What to do about it this week

Four things that need no lawyer:

  1. List the use cases, not the tools. Record what decisions or preparations AI is used for, and who makes the decision.
  2. Mark the ones that concern people. Recruitment, assessment, credit, monitoring and access to services are the ones for which the December 2027 deadline matters.
  3. Check transparency. Does the chat tell the customer it is a machine, and is published artificial imagery labelled?
  4. Record your induction. Supporting competence is already an obligation, and demonstrating the measures taken is easier if there is a record of them.

In one sentence

The AI Act does not ask which model you have but what decision you use it for, and two obligations already apply to a deployer today, even though the high-risk deadline moved to December 2027.

Sources

Updated 6 August 2026.

  1. Regulation (EU) 2026/1744, Digital Omnibus on AI · EUR-Lexthe amending regulation that moved the high-risk deadlines and changed the wording of Article 4
  2. Regulatory framework for AI · European Commissionthe application timetable in force
  3. FAQ on the transparency obligations under Article 50 · European Commissionhow obligations divide between provider and deployer
  4. Regulation (EU) 2024/1689, the AI Act · EUR-Lexthe original text, including Article 6 and Annexes I and III
  5. Regulation of artificial intelligence · TraficomFinland's national contact point and the division of work between authorities
  6. Powers of the supervisory authorities · Office of the Data Protection Ombudsman, FinlandFinland's supervisory arrangements from 1 January 2026

Regulation changes. Check the dates against the original source before making decisions that rest on them.

regulationAI Actcomplianceresponsibility

Harri Salomaa · Forty years in software, twenty of them in the United States and Germany: from collecting process data and analysing network data to immersive computing, and most recently AI.

Share this article