EU AI ActUpdated 4 Sep 202612 min read

EU AI Act 2026: what applies now — and what comes next

The AI Act is no longer a future compliance project. Most of the Regulation became applicable on 2 August 2026, Article 50 transparency duties are live, and enforcement powers are expanding — while key high-risk requirements now follow a 2027–2028 timeline.

Author: SundAIScope: EU organisations using or providing AILast verified: 4 September 2026
Answer first

As of September 2026, organisations should treat AI governance as an operational requirement, not a 2027 project. The AI Act is generally applicable; Article 50 transparency obligations apply; the Commission has enforcement powers for general-purpose AI model obligations; and prohibited-practice rules already apply. The major high-risk system requirements, however, apply later: 2 December 2027 for Annex III systems and 2 August 2028 for high-risk AI embedded in regulated products under Annex I.

NowInventory AI, assign roles, apply transparency measures and maintain evidence.
NextPrepare higher-risk use cases for the 2027/2028 requirements before procurement and design decisions harden.
AvoidAssuming every AI system is high-risk — or assuming the high-risk delay means nothing applies today.

The September 2026 timeline

DateWhat appliesPractical implication
2 Feb 2025Initial prohibited-practice rules and AI-literacy provisions began applying.Organisations needed controls around prohibited uses and staff capability.
2 Aug 2025Governance rules and obligations for providers of general-purpose AI models began applying.GPAI providers entered the Act’s dedicated governance regime.
2 Aug 2026The Regulation became generally applicable; Article 50 transparency rules apply; enforcement powers expand.Transparency, role mapping, documentation and operational governance need to be live.
2 Dec 2027High-risk rules for systems classified under Article 6(2) and Annex III apply.Relevant systems in areas such as employment, education, biometrics, critical infrastructure and migration need full high-risk readiness.
2 Aug 2028High-risk rules for AI systems covered through Article 6(1) and Annex I regulated products apply.Product-integrated high-risk AI receives the longer transition.

What organisations should do now

1. Build one accountable AI inventory

Record approved tools, embedded AI, pilots, internally built systems and material shadow AI. For each entry, capture purpose, supplier, users, data categories, outputs, business owner, technical owner, geography and whether the organisation is acting as provider, deployer, importer or distributor. The inventory is the bridge between legal classification and operational control.

2. Separate role, risk and obligation

Do not start with a single label such as “compliant” or “high-risk”. First determine the organisation’s role in the value chain, then the system’s intended purpose and risk category, and only then the obligations that follow. A company using a third-party assistant as a deployer has a different responsibility profile from a company substantially modifying a system or placing its own AI product on the market.

3. Operationalise Article 50 transparency

Article 50 applies from 2 August 2026. The Commission’s July 2026 guidance explains transparency duties for certain interactive and generative AI systems, AI-generated or manipulated content, deepfakes, emotion-recognition and biometric-categorisation contexts. Organisations should identify which interfaces and content flows need disclosure, machine-readable marking or visible labelling, then test that those measures actually survive the publishing workflow.

4. Treat evidence as a product of the process

Keep decision logs, supplier assessments, testing records, approvals, incident records, transparency decisions and significant model or configuration changes. Evidence created continuously is far more reliable than reconstructing a compliance story after an incident or audit.

5. Start high-risk preparation before the legal deadline

The later 2027 and 2028 dates are transition time, not dead time. Procurement clauses, logging architecture, data-quality controls, human-oversight design and technical documentation are difficult to bolt on after deployment. If a use case could fall within Annex III or an Annex I product context, treat the transition period as a design window.

A practical 30-day baseline

Important: A delayed high-risk deadline does not mean “the AI Act is delayed”. The Act is generally applicable, and several obligations already apply. Equally, not every AI use case is high-risk. Classification should be evidence-based and use-case-specific.

How SundAI connects the work

SundAI’s approach is to connect regulation with operational controls: an AI inventory, ownership model, supplier review, security baseline, human-oversight design, evidence model and prioritised roadmap. The objective is proportionate governance — enough structure to control real risk without turning every low-impact use case into a legal project.

Frequently asked questions

Is the EU AI Act fully applicable in September 2026?

The Regulation is generally applicable from 2 August 2026, but important high-risk requirements have later dates: 2 December 2027 for Annex III systems and 2 August 2028 for relevant Annex I product-integrated systems.

Do Article 50 transparency obligations already apply?

Yes. The Article 50 transparency obligations apply from 2 August 2026. Organisations should use the Commission’s final July 2026 guidance when assessing scope and implementation.

Does using ChatGPT or another general-purpose AI tool automatically make an organisation high-risk?

No. Risk classification depends on the intended use, role and context. A general productivity use is not automatically high-risk. The same underlying technology can, however, be part of a higher-risk use case depending on how it is deployed.

Primary sources

This page is practical governance information, not legal advice. Legal classification depends on the specific system, role, intended purpose and jurisdiction. Last source review: 4 September 2026.

Need a structured AI Act readiness baseline?

SundAI focuses on practical inventories, controls, supplier reviews, security and evidence models for European organisations.

Explore EU AI Act readiness →
← All insightsNext: Article 50 checklist →