AI ACT
The rules, the dates, and whose problem each one is.
Most of what you will read about the EU AI Act online was written before 27 July 2026 and is now wrong about the deadlines. This page is current, says which obligations are ours and which stay yours, and does not pretend that buying software makes a company compliant.
Last updated 17 August 2026
What this page is
An account of how Regulation (EU) 2024/1689 — the AI Act — applies to this platform, to us, and to you. It is written for the person who has to answer for it internally. It is not legal advice, and where your situation is close to a line, the answer comes from your counsel and not from a supplier's website.
Where the law actually stands today
The Act came into force in August 2024 and applies in stages. Those stages were changed three weeks ago by the Digital Omnibus on AI — Regulation (EU) 2026/1744 of 8 July 2026, published in the Official Journal on 24 July and in force since 27 July 2026, six days before the deadline it moved. This is the current schedule:
| Date | What applies |
|---|---|
| 2 Feb 2025 passed |
Prohibited practices (Art. 5) and the AI literacy duty (Art. 4). |
| 2 Aug 2025 passed |
Rules for general-purpose AI models, the governance structure, and penalties. |
| 2 Aug 2026 in force now |
The main body of the Act, including the Art. 50 transparency duties. These were not postponed. |
| 2 Dec 2026 | The grace period ends for marking AI-generated content in systems that were already on the market before 2 August 2026 (Art. 50(2)). The new prohibition on systems producing non-consensual intimate imagery or child sexual abuse material takes effect. |
| 2 Dec 2027 | High-risk obligations for the stand-alone systems in Annex III — moved back from 2 August 2026. |
| 2 Aug 2028 | High-risk obligations for AI embedded in products already covered by EU product-safety law (Annex I). |
The practical reading: the high-risk regime bought you sixteen more months, and the transparency duties did not. If a page you are reading says the high-risk rules started in August 2026, it was written before the omnibus and has not been updated since.
The fines are not decorative — up to €35m or 7% of worldwide turnover for a prohibited practice, and €15m or 3% for transparency and high-risk breaches, with a lower ceiling for smaller companies.
Who is responsible for what
The Act allocates duties by role, not by who owns the software. The two that matter here are the provider, who puts an AI system on the market, and the deployer, who uses one. On this platform the roles split like this:
| The thing | Who we are | Who you are |
|---|---|---|
| Vera, the consultant on this website | Ours entirely. The disclosure duty is ours and we meet it. | Nothing. You are a visitor. |
| The studio you build in | We put it on the market under our name, so its own transparency duties are ours. | You are its deployer inside your business. |
| The system you build with it | Nothing. We supply the tooling, we do not operate your system and we cannot answer for what it decides. | You are its provider, its deployer, or both. Every duty in the Act that attaches to that system attaches to you. |
We say that plainly because the alternative — a supplier implying its certificate covers your use — is how companies end up discovering the gap during an inspection rather than before one.
What we do on this site
- You are told Vera is an AI before the microphone is ever requested, in the panel itself, in the language you are reading. That is the Art. 50(1) interaction duty and it has been in place since she launched, not since the deadline.
- No emotion recognition and no biometric identification. Vera does not analyse how you feel and does not identify you by your voice. Art. 50(3) does not arise because the thing it governs is not there.
- No audio is recorded and no transcript is kept. The security page sets out exactly what is retained.
- No deepfakes and no synthetic media of real people anywhere on this site or in the product.
What the platform gives you toward your own obligations
- A record of AI use, per project. Which vendor and model answered, how many requests, how many tokens, what it cost, day by day. If you need that extracted for a project — for an internal audit, or for a customer of yours who is asking — ask and we will produce it.
- A person in the loop by construction. The studio writes software; it does not push it live on its own. Someone reviews and someone releases. That is the shape Art. 14 asks for, and here it is the only shape available.
- Data in the EU. The platform, the database and what you build sit in Frankfurt. The exception is the model processing itself, which may happen outside the EEA under the European Commission's standard contractual clauses.
- A written description of the technical basis under your application, if your own compliance file needs one.
What cannot be built here at all
The terms bar a list of applications outright — medical diagnosis, legal rulings, biometric identification and surveillance, control of critical infrastructure, staff decisions taken without a person, social scoring, and others. That list covers the whole of the Act's prohibited practices under Art. 5, and most of what Annex III calls high-risk.
It is not a clause-by-clause map of Annex III, and we will not claim it is. Annex III also reaches things our list does not name — creditworthiness assessment, pricing of life and health insurance, admission and grading in education, eligibility for public benefits, and some uses in law enforcement, migration and justice. If what you want to build sits in one of those, ask before you build it. The answer is not automatically no, but it is never a decision to take by inference from a webpage.
If you genuinely need a high-risk system
Then, plainly, we are the wrong supplier and you should hear that now rather than in December 2027. Placing an Annex III system on the market means a conformity assessment, a technical file, a quality management system, registration in the EU database, logging held for defined periods, human oversight designed into the system, and post-market monitoring afterwards. We do not provide any of that, and no amount of good infrastructure underneath substitutes for it.
What we can be is the supplier of the ordinary software around the regulated part — the records, the scheduling, the documents, the correspondence. In most companies that is the large majority of the work, and none of it is high-risk.
AI literacy, which is already your duty
Art. 4 has applied since February 2025 and is easy to miss because nobody sends you a form for it. It requires you to see that the people using AI tools, or acting on what they produce, understand well enough what they are dealing with. The July 2026 omnibus softened it — you support that understanding rather than guarantee a level of it — but it did not remove it.
In practice, for a small company: know which of your systems use AI, tell the staff who rely on them that output can be confidently wrong, and write down who checks what before it is acted on. That last sentence is most of a literacy policy.
What you must tell the people your system talks to
These duties are live now, and they follow the system you build, not us:
- If your system converses with people — a chatbot, a phone agent, an assistant on your site — they must be told they are dealing with AI, unless it would be obvious to any reasonable person anyway.
- If it generates content — text, images, audio, video — the output has to be marked as artificially generated in a machine-readable way, so far as that is technically feasible. If your system was already live before 2 August 2026, you have until 2 December 2026 to get that marking in place.
- If it produces deepfakes, or publishes AI-written text on matters of public interest without a person taking editorial responsibility, that has to be disclosed too.
The disclosure has to be clear and given no later than the first interaction. A line in a privacy policy nobody opens does not count.
What we do not have yet
- No machine-readable marking of Vera's synthesised speech. She tells you she is an AI before she says anything else, which is the operative duty for a live conversation someone chose to start, and we are not the provider of the model that generates the voice. We would still rather list it than let you assume a watermark is there.
- No mapping of our barred-use list onto Annex III, clause by clause. It is described above as what it is: broad coverage with named gaps.
- No confirmed retention window for the AI usage record. We can produce it, we have produced it for this platform's own use, and we have not yet pinned down how far back it reaches. If you need the log-keeping the Act asks of a high-risk deployer, settle that with us before you rely on it.
- No AI literacy training programme in a folder. A small team that builds with these tools daily is not the same as a documented programme, and we will not dress one up as the other.
- No certification, no conformity assessment, no notified body. Nothing here is CE-marked as an AI system, because nothing here is required to be.
Asking us something
If you are filling in an assessment, scoping a system that might be high-risk, or simply want to know whether an idea is allowed here, use the contact form. We would far rather answer the question early than have the conversation after something is built.
Sources for the dates above: Regulation (EU) 2024/1689 and Regulation (EU) 2026/1744, both in full text on EUR-Lex.