As of September 2026, organisations should treat AI governance as an operational requirement, not a 2027 project. The AI Act is generally applicable; Article 50 transparency obligations apply; the Commission has enforcement powers for general-purpose AI model obligations; and prohibited-practice rules already apply. The major high-risk system requirements, however, apply later: 2 December 2027 for Annex III systems and 2 August 2028 for high-risk AI embedded in regulated products under Annex I.
The September 2026 timeline
What organisations should do now
1. Build one accountable AI inventory
Record approved tools, embedded AI, pilots, internally built systems and material shadow AI. For each entry, capture purpose, supplier, users, data categories, outputs, business owner, technical owner, geography and whether the organisation is acting as provider, deployer, importer or distributor. The inventory is the bridge between legal classification and operational control.
2. Separate role, risk and obligation
Do not start with a single label such as “compliant” or “high-risk”. First determine the organisation’s role in the value chain, then the system’s intended purpose and risk category, and only then the obligations that follow. A company using a third-party assistant as a deployer has a different responsibility profile from a company substantially modifying a system or placing its own AI product on the market.
3. Operationalise Article 50 transparency
Article 50 applies from 2 August 2026. The Commission’s July 2026 guidance explains transparency duties for certain interactive and generative AI systems, AI-generated or manipulated content, deepfakes, emotion-recognition and biometric-categorisation contexts. Organisations should identify which interfaces and content flows need disclosure, machine-readable marking or visible labelling, then test that those measures actually survive the publishing workflow.
4. Treat evidence as a product of the process
Keep decision logs, supplier assessments, testing records, approvals, incident records, transparency decisions and significant model or configuration changes. Evidence created continuously is far more reliable than reconstructing a compliance story after an incident or audit.
5. Start high-risk preparation before the legal deadline
The later 2027 and 2028 dates are transition time, not dead time. Procurement clauses, logging architecture, data-quality controls, human-oversight design and technical documentation are difficult to bolt on after deployment. If a use case could fall within Annex III or an Annex I product context, treat the transition period as a design window.
A practical 30-day baseline
- Nominate one accountable AI-governance owner and a cross-functional review path.
- Create or refresh the AI inventory, including shadow AI and pilots.
- Map provider/deployer and other value-chain roles for priority systems.
- Review Article 50 transparency obligations for chatbots, synthetic content and affected workflows.
- Create a minimum supplier questionnaire covering data use, retention, security, subprocessors and incident handling.
- Define minimum security controls for identity, access, logging, human review and change management.
- Identify possible Annex III / Annex I high-risk candidates and open a readiness workstream.
- Record decisions and evidence in a repeatable governance workflow.
How SundAI connects the work
SundAI’s approach is to connect regulation with operational controls: an AI inventory, ownership model, supplier review, security baseline, human-oversight design, evidence model and prioritised roadmap. The objective is proportionate governance — enough structure to control real risk without turning every low-impact use case into a legal project.
Frequently asked questions
Is the EU AI Act fully applicable in September 2026?
The Regulation is generally applicable from 2 August 2026, but important high-risk requirements have later dates: 2 December 2027 for Annex III systems and 2 August 2028 for relevant Annex I product-integrated systems.
Do Article 50 transparency obligations already apply?
Yes. The Article 50 transparency obligations apply from 2 August 2026. Organisations should use the Commission’s final July 2026 guidance when assessing scope and implementation.
Does using ChatGPT or another general-purpose AI tool automatically make an organisation high-risk?
No. Risk classification depends on the intended use, role and context. A general productivity use is not automatically high-risk. The same underlying technology can, however, be part of a higher-risk use case depending on how it is deployed.
Primary sources
- Consolidated Regulation (EU) 2024/1689 — EUR-Lex
- European Commission — AI Act overview and application timeline
- European Commission — enforcement framework
- European Commission — Article 50 transparency guidelines, 20 July 2026
This page is practical governance information, not legal advice. Legal classification depends on the specific system, role, intended purpose and jurisdiction. Last source review: 4 September 2026.
Need a structured AI Act readiness baseline?
SundAI focuses on practical inventories, controls, supplier reviews, security and evidence models for European organisations.
Explore EU AI Act readiness →