The technical side, not the legal one. We establish which AI systems you actually run, what has to be documented and built so compliance can be evidenced — and which of it applies already.
The Digital Omnibus, in force since 27 July 2026, deferred the obligations for high-risk systems. That is the change that made the headlines — and the one most often read as meaning nothing need be done until 2027. The deferral covers only one part of the regulation.
| Date | What it covers |
|---|---|
| in force2 February 2025 | Prohibited practices (Article 5) and the AI literacy duty (Article 4). |
| in force2 August 2025 | Obligations for general-purpose AI (GPAI) model providers, governance rules and penalties. |
| in force2 August 2026 | Transparency obligations (Article 50): telling people they are interacting with AI, and marking generated content. Systems already in service have until 2 December 2026 for machine-readable marking. |
| from2 December 2027 | Annex III high-risk systems — moved from 2 August 2026 by the Digital Omnibus. This is the change that got the coverage. |
| from2 August 2028 | High-risk systems embedded in regulated products (Annex I) — moved from 2 August 2027. |
Verified 19 August 2026. This area moves quickly — two of the dates above were deferred after the regulation came into force. Confirm them with your own lawyer before making decisions on them.
Three groups of obligations apply regardless of the deferral, and reach a far wider set of companies than high-risk systems do:
The deferral is worth using, though: retrofitting documentation, logging and oversight onto a system already in production is considerably harder than designing them in. Companies that treat 2027 as the deadline will be doing this under pressure.
This boundary matters more than usual here, so we state it before describing the work.
The audit ends in a document, not a presentation. It contains three things, in order:
The scope follows the audit and the classification, but the same elements recur whatever the sector. They are also the areas the regulation names explicitly for high-risk systems — and worth having before then.
Article 4 has applied since February 2025 and, after the July 2026 amendment, requires taking measures that support the development of AI literacy, accounting for knowledge, experience and context of use — not guaranteeing a particular level for each individual. It is an obligation of effort rather than of result, but a real one.
In practice it means the people using a system understand what it does, where it is unreliable, and when not to trust it. We run that training as part of AI implementation — and document it, because an undocumented measure is hard to evidence later.
For the high-risk obligations, yes: 2 December 2027 for Annex III systems. But the deferral covers only that part. Transparency obligations have applied since 2 August 2026, prohibited practices and the AI literacy duty since February 2025, and the general-purpose model rules since August 2025. "Nothing to do until 2027" is the most common wrong conclusion drawn from the coverage of the delay.
Legal advice tells you how the regulation applies to your situation and what risk it carries. We tell you what has to be built so that compliance can be evidenced: how systems are documented, what is logged, where a human can genuinely intervene, and what evidence is produced automatically. Legal classification stays with your lawyer — we work from their conclusions rather than in place of them.
Most likely yes, but as a deployer rather than a provider — a different and usually much lighter set of obligations. The AI literacy duty covers people operating a system on your behalf regardless of who built it. If the tool talks to customers or generates content, transparency obligations come into play too.
A register of the AI systems in use with their role and context, an assessment of what is missing against both the obligations that apply now and those arriving in 2027, and a list of technical tasks ranked by urgency and cost. Without that register, a conversation about compliance is a conversation about systems nobody has counted.
No. Since the July 2026 amendment, Article 4 requires taking measures that support the development of AI literacy, accounting for knowledge, experience and context of use — not guaranteeing a particular level for each individual, and not any specific certificate. What matters in practice is that the people operating a system understand what it does, where it gets things wrong, and when to stop it.
The AI Act and the GDPR overlap but are separate regimes: the GDPR governs personal data, the AI Act governs AI systems, including ones that process no personal data at all. The audit flags where the two meet; a full GDPR assessment is separate work.
The dates and scopes above rest on the text of the regulation and the changes made by the Digital Omnibus, in force since 27 July 2026. Verified 19 August 2026. Current texts:
A free consultation, after which you know which AI systems you actually run and which of today's obligations reach you.