Skip to main content

Thread Transfer

EU AI Act 2025-2026: What Changed, What's Enforced, What's Coming

Article 5 prohibitions are live. GPAI obligations bite in August. High-risk rules layer in through 2026. The mid-2026 update for enterprise compliance leads, with the Q3 checklist.

Thread Transfer

AI Systems for Builders

June 11, 202611 min read
EU AI ActComplianceRegulationAI Governance
EU flag stars dissolving into circuit pattern with 2025-2027 enforcement timeline

The EU AI Act is not a future problem. Article 5 prohibitions went live on 2 February 2025. The GPAI obligations bite on 2 August 2025. High-risk system rules layer in through 2 August 2026, with the legacy GPAI grace period closing 2 August 2027. If you operate inside the EU/EEA and your AI vendor still says "we'll get back to you on the Act," that is a procurement red flag, not a wait-and-see.

This post is the mid-2026 update. What is enforced today, what gets enforced in the next 60 days, what is still drafting at the AI Office, and the documentation a compliance lead must have in their drive before the next board meeting. No abstractions. Article numbers, dates, fines, and a checklist for Q3 2026.

Enforcement Timeline 2025 to 2027

The Act entered into force 1 August 2024, but the obligations switch on in waves. Treat this as your master timeline. If you missed an earlier wave, the answer is not "skip ahead"; the obligation is retroactive on operating systems.

DateObligationWho It HitsMax Penalty
2 Feb 2025Article 5 prohibitions, AI literacy duty (Art. 4)All providers and deployersEUR 35M or 7% global turnover
2 Aug 2025GPAI obligations (Art. 50-55), governance, penalty regimeGPAI providers, importers, distributorsEUR 15M or 3% global turnover
2 Aug 2026High-risk Annex III rules, transparency (Art. 50), most of the ActProviders and deployers of high-risk AIEUR 15M or 3% global turnover
2 Aug 2027Annex I high-risk (regulated products), legacy GPAI compliance deadlineEmbedded AI in regulated products, models placed on market before Aug 2025EUR 15M or 3% global turnover

Note the asymmetry. Prohibitions and GPAI carry the heavier 7% and 3% caps. Supplying incorrect, incomplete, or misleading information to authorities is its own offence at EUR 7.5M or 1%. SMEs get the lower of the two amounts, not the higher. That last detail trips up corporate counsel imported from GDPR practice, where the math is reversed.

Prohibited Practices: What Is Already Illegal

Article 5 has been law for 16 months as of this post. The Commission published its Article 5 guidelines on 4 February 2025 and they remain the operative interpretation. Eight categories are banned outright, with no proportionality test and no "legitimate interest" escape hatch. If your system does any of these, no amount of risk management saves you.

  • Subliminal, manipulative, or deceptive techniques that materially distort behaviour and cause significant harm. Dark-pattern personalisation engines tuned to exploit cognitive bias are the obvious target.
  • Exploitation of vulnerabilities tied to age, disability, or socio-economic situation. Targeting financially distressed users with high-interest products via AI-personalised feeds is in scope.
  • Social scoring by public or private actors leading to detrimental or disproportionate treatment in unrelated contexts.
  • Predictive policing based solely on profiling or personality traits, without objective facts.
  • Untargeted scraping of facial images from the internet or CCTV to build facial recognition databases. This one killed the EU expansion plans of at least two US vendors in 2025.
  • Emotion inference in workplaces and education, except for medical or safety reasons.
  • Biometric categorisation inferring race, political opinions, trade union membership, religion, sex life, or sexual orientation.
  • Real-time remote biometric identification in publicly accessible spaces for law enforcement, with narrow exceptions.

The deployer obligation matters most for enterprises. You do not need to build the system to be liable. If your HR team deploys an off-the-shelf interview tool that infers candidate emotion, your company is the deployer of a prohibited system. Vendor indemnity clauses do not transfer the regulatory penalty; they only cover civil damages between you and the vendor. The EUR 35M fine still lands on your VAT number.

GPAI Obligations and the August Deadline

General-purpose AI is the layer most enterprises overlook because they think it is the model provider's problem. It is, until you fine-tune. The moment your team takes a base model and fine-tunes it on internal data such that the resulting system meaningfully differs in capability or risk profile, you may become a downstream GPAI provider in your own right. The AI Office's draft Code of Practice (third draft, March 2025) defines this trigger around "substantial modification" with a compute and data threshold.

Core GPAI obligations effective 2 August 2025:

  1. Technical documentation for the model: architecture, training data summary, evaluation results, energy consumption, intended use, known limitations. Annex XI of the Act lists the minimum content.
  2. Downstream documentation for providers integrating the model: enough information to allow them to comply with their own obligations.
  3. Copyright compliance policy: a written policy on respecting opt-outs and the EU copyright directive.
  4. Training data summary: a sufficiently detailed summary of training content, published on a template the AI Office finalised in late 2025.

If your model crosses the 10^25 FLOPs training compute threshold, you are presumed to be GPAI with systemic risk. That triggers a heavier regime: model evaluation including adversarial testing, systemic risk assessment, serious incident reporting within 15 days, and cybersecurity protection of model weights. The threshold is intentionally low enough to capture frontier labs; the Commission can adjust it via delegated act.

For most enterprise teams, the practical action is not training a frontier model. It is vendor due diligence. Ask every GPAI vendor in your stack for the Annex XI documentation pack. If they cannot produce it on request as of August 2025, you have a procurement problem dressed up as a compliance problem. We covered the broader procurement angle in our earlier piece on the AI regulatory landscape.

High-Risk Classification: How to Test Your System

The 2 August 2026 milestone is the one most enterprise teams are not ready for. High-risk AI is defined two ways: Annex I (AI as a safety component of products already regulated under EU harmonisation law, like medical devices, machinery, toys), and Annex III (eight standalone use cases). Annex III is where the surprises live.

Annex III DomainTypical Enterprise Use CaseIn-Scope?
BiometricsRemote identification, emotion inference outside workplaceYes if not prohibited
Critical infrastructureAI managing road, water, gas, electricity, digital infrastructureYes
Education and vocational trainingAdmissions scoring, exam grading, proctoring, course assignmentYes
EmploymentCV screening, ranking, task allocation, performance monitoringYes
Essential servicesCredit scoring, life and health insurance pricing, emergency triage, public benefits eligibilityYes
Law enforcementRisk assessment of individuals, evidence reliability evaluationYes
Migration, asylum, border controlVisa risk assessment, document verificationYes
Administration of justice and democratic processesJudicial decision-support, election-influence detectionYes

Article 6(3) carves out a derogation: if your system performs only narrow procedural tasks, improves the result of a prior human activity, detects decision-making patterns without replacing the human, or is preparatory, you can self-classify as not high-risk. The catch: you must document the assessment, register it in the EU database, and the AI Office can override you. The derogation never applies if the system profiles natural persons.

Run this three-question test on every system in your inventory:

  1. Does the system fall within an Annex III domain? If no, you are likely outside high-risk.
  2. Does it materially influence a decision about a natural person, or autonomously make one? If yes, high-risk default applies.
  3. Does Article 6(3) derogation honestly apply, with documentation to back it? If you cannot point to the artefact today, do not claim the derogation.

Documentation and Conformity Assessment

High-risk providers must build a quality management system (Art. 17), maintain technical documentation (Annex IV), keep automatic logs, register the system in the EU AI database before placing on market, run a conformity assessment, and affix CE marking. Deployers carry a lighter but real load: human oversight, input data appropriate to intended purpose, monitoring, logging, and a fundamental rights impact assessment for public bodies and certain private deployers.

The conformity assessment route depends on the system. For most Annex III systems it is internal control (Annex VI). Biometric systems go through notified body assessment (Annex VII). Either way, you need an evidence trail an auditor can walk. The minimum artefacts:

  • Risk management file: hazards identified, residual risk acceptable, mitigations linked to controls.
  • Data governance record: training, validation, and test data characteristics, bias examination, gap analysis.
  • Technical documentation: system description, design choices, performance metrics, accuracy thresholds, expected lifecycle.
  • Logging configuration: which events, retained how long, accessible to whom.
  • Human oversight design: who can stop the system, how they are trained, what they see.
  • Post-market monitoring plan: how you detect drift, how you report serious incidents within 15 days.
  • Instructions for use: what deployers need to know to deploy lawfully.

Most enterprise teams have fragments of this in MLOps tooling, model cards, and risk registers. The work is consolidation and gap-filling, not greenfield. We mapped this onto general governance structures in our piece on AI governance frameworks, and on the operational discipline side in audit-ready AI. The point both posts make: documentation that lives in someone's laptop is not documentation, it is a liability.

Fundamental Rights Impact Assessment (FRIA)

Article 27 is the obligation enterprise compliance leads keep underestimating. Deployers that are public bodies, or private entities providing services of general interest, or deploying high-risk systems for credit scoring or insurance, must conduct a FRIA before first use. The FRIA covers process description, intended purpose, categories of affected persons, specific risks of harm, human oversight measures, and remediation if risks materialise.

The output goes to the national market surveillance authority on request. A FRIA is not a one-shot document. It must be updated when the system or context changes. The Commission is finalising a template through 2026; in the interim, the Spanish AESIA and the French CNIL have published interim templates that map cleanly to Article 27.

Transparency Obligations

Article 50 applies to all providers and deployers, not just high-risk. Three concrete duties from 2 August 2026:

  • Disclose AI interaction: users must be informed when interacting with an AI system, unless obvious from context. Your chatbot needs a label.
  • Mark synthetic content: deepfakes and AI-generated or manipulated text published to inform the public on matters of public interest must be labelled, with limited artistic and journalistic exceptions.
  • Mark machine-readable outputs: AI-generated audio, image, video, and text must be marked in a machine-readable format. C2PA and similar provenance standards are the obvious implementation path.

Practical Checklist for Q3 2026

If you are reading this in mid-2026, here is the action list. Do not over-engineer. Do the inventory first.

  1. Build the AI system inventory. Every model, every fine-tune, every embedded vendor system. Owner, purpose, data classes, decision impact. Spreadsheet is fine for week one.
  2. Classify each system against Article 5 (prohibited), Article 6 / Annex III (high-risk), GPAI status, and minimal-risk default. Flag the Article 6(3) derogations and write the justification now.
  3. Confirm AI literacy training (Art. 4). This has been mandatory since February 2025. Workforce dealing with AI systems needs documented training. A 30-minute module with attestation closes the obligation.
  4. Run vendor diligence on every GPAI provider in the stack. Request Annex XI documentation. If not provided, escalate to procurement.
  5. Map your role per system: provider, deployer, importer, distributor. The same legal entity can wear different hats per system.
  6. For each high-risk system, gap-assess against Annex IV. Identify missing artefacts. Assign owners. Aim to be assessment-ready by 2 August 2026.
  7. Draft the FRIA template for systems where Article 27 applies. Pilot on one system before rolling out.
  8. Plug into the EU AI database registration flow. Test the submission now, not the week of go-live.
  9. Update vendor contracts. Add allocation clauses for documentation production, incident reporting, audit cooperation, and indemnity for regulatory exposure caused by vendor breach.
  10. Set up serious incident reporting. 15 days is short. The runbook needs to exist before the incident.

What Is Still Drafting

Three workstreams at the AI Office are open as of June 2026. The GPAI Code of Practice is in iterative drafting; signatories get a presumption of compliance. Harmonised standards under request M/593 are with CEN-CENELEC and ETSI, with expected publication late 2026 into 2027; conformity with these standards will give a presumption of conformity with the Act's requirements. The Commission's implementing acts on conformity assessment procedures, EU database, and post-market monitoring templates are landing in tranches.

Translation: if you wait for everything to settle, you miss the August 2026 deadline. Build to the Act and Annex IV today. Refit to the harmonised standards when they publish. The cost of refit is bounded; the cost of non-compliance is not.

Bottom Line

Three things to walk away with. One: the Act is partly enforced today, not in 2027. Prohibitions and AI literacy have been live since February 2025; GPAI since August 2025. Two: high-risk classification is a deliberate exercise, not a one-line vendor question. Walk the Annex III table against your real inventory and document the derogation calls. Three: documentation is the deliverable. Risk management file, technical documentation, FRIA, logging, post-market monitoring, vendor evidence pack. If those seven artefacts exist and are versioned, you are most of the way to defensible.

For organisations that built a credible GDPR programme between 2016 and 2018, the muscle memory transfers. For those that did not, the lesson is the same: the regulator does not credit good intentions, only artefacts. Start the inventory this week.