Skip to content
AI.info

Responsible AI

EU AI Act: Obligations, GPAI, Transparency, and the 2026 Timeline

Operationalize EU AI Act duties for high-risk systems, GPAI models, transparency, literacy, post-market monitoring, incidents, and staged applicability.

By the end you can

Visual

Duties that arrive on different dates

The Act does not switch on. Prohibitions and AI literacy came first. GPAI documentation came next. The high-risk lifecycle comes after that. Transparency and post-market duties run across all of it, all the way through.

FigureProcess · 5 steps
  1. 1

    Early obligations

    Prohibited practices, AI literacy, and initial governance milestones.

  2. 2

    GPAI layer

    Model documentation, downstream information, copyright policy, training-content summary, and systemic-risk duties where applicable.

  3. 3

    High-risk lifecycle

    Risk management, data governance, documentation, records, transparency, oversight, accuracy, robustness, cybersecurity, QMS, conformity, and monitoring.

  4. 4

    Transparency duties

    Human interaction, synthetic content, deepfakes, and specified biometric or emotion uses.

  5. 5

    Post-market and enforcement

    Monitoring, serious incidents, corrective action, authority cooperation, penalties, and evidence retention.

Steps

Article, role, date, owner

The artifact is an obligation register: article, role, date, owner. The four steps after it are how that register turns into evidence.

FigureProcess · 5 steps
  1. 1. Build the obligation register

    Map article, role, system, effective date, owner, evidence, and dependency.

  2. 2. Prioritize immediate duties

    Prohibitions, literacy, GPAI, transparency, and currently applicable controls.

  3. 3. Implement lifecycle controls

    Connect risk, quality, data, documentation, oversight, testing, monitoring, and incidents.

  4. 4. Validate readiness

    Run evidence reviews, role exercises, disclosure tests, and authority cooperation drills.

  5. 5. Maintain the legal baseline

    Monitor official sources, standards, guidance, changes, and product reclassification.

Example

One checklist, written as if one date

A multinational writes one "AI Act ready" checklist in 2024. By August 2026 the checklist has not moved. It still treats every duty as starting on one date. It omits GPAI obligations that are already applicable. It assumes every Annex III high-risk requirement is fully in force today. Three errors, one cause: the document was finished.

  • Timeline error: Provisions apply on different dates, and later changes moved some high-risk timing again.
  • Role mixing: GPAI-provider duties sit in the same rows as deployer duties for downstream applications.
  • Control mismatch: The policy names technical documentation but never the lifecycle evidence or the owner.
  • Transparency gap: Notices for generated content, interaction, emotion recognition, and biometric categorization are mapped to no product surface.
  • Change risk: Nobody owns amendments, codes, standards, or Commission guidance.

Effective dates are what a policy lacks

Implementing the EU AI Act is role-specific and date-specific work. A register connects each provision to four things: the systems it covers, the actor who owes it, the date it starts, and the evidence that it is met. The same rows reach outward to standards, operating controls, authorities, and change monitoring.

One column separates a register from a policy: the effective date. The 2024 checklist carried one date. The Act carries a series.

Plan obligation by obligation. A staggered series has no single day on which the organization becomes compliant.

Case

The dates the Act actually carries

The Act entered into force on 1 August 2024. Prohibited practices and AI literacy started on 2 February 2025. Governance and GPAI duties started on 2 August 2025. Broad application, transparency included, started on 2 August 2026.

Then the high-risk deadline moved. The Digital Omnibus on AI came into force on 27 July 2026, six days before 2 August. It pushed the Chapter III high-risk obligations out to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. The amending text is Regulation (EU) 2026/1744.

Six days. Anyone whose roadmap named 2 August 2026 as the high-risk date was holding the wrong date before the week was out. Check the official text, not last quarter's slide.

Case

Article 51(2)’s single number, and Article 99(3)’s ceiling

European regulations rarely name a number. Article 51(2) names one. A general-purpose model trained with more than 10^25 floating point operations is presumed to have high-impact capabilities. Two more numbers sit in Article 99(3): a top penalty of 35 million euros or 7% of worldwide annual turnover, whichever is higher.

The compute figure is a proxy, and everyone involved knows it. It is still the line a compliance team has to plan against.

Comparison

High-risk system provider, GPAI model provider, or Deployer?

One deployment can sit under all three roles at once. None of the three discharges the duties of the other two.

FigureComparison · 3 columns

High-risk system provider

Governs a specific high-risk AI system through its lifecycle.

  • Risk and quality management
  • Technical documentation and records
  • Conformity and registration where required
  • Post-market monitoring and incident duties

GPAI model provider

Governs a general-purpose model supplied downstream.

  • Model documentation and downstream information
  • Copyright-compliance policy and training-content summary
  • Additional duties for systemic-risk models
  • Does not replace downstream system governance

Deployer

Controls professional use of an AI system.

  • Follows instructions and local monitoring
  • Ensures relevant input and human oversight where required
  • Keeps logs and provides information in covered contexts
  • Manages local impact and affected-person obligations

Example

Dates on every row

A register that does not carry dates is a list. These four exercises turn it into a program.

  • Date-aware register: Give each obligation its own row, carrying role, system, start date, evidence, and current interpretation.
  • Transparency surface test: Walk every user-facing and public interface where a disclosure may be required.
  • GPAI handoff: List what downstream providers need in order to understand capabilities and limitations.
  • Serious-incident drill: Test detection, assessment, notification, cooperation, and corrective action. Run it against all three clocks: 15 days as the general rule, 2 days for a widespread infringement, 10 days where a person has died.

Key idea

Accurate on the day it was written

Dates and classifications go stale. A slide, a blog post, an old legal memo — each was right once. So do not hard-code one "AI Act deadline" into a roadmap. And do not treat a harmonized standard as proof that every substantive obligation is met.

The AI literacy duty used to be a result. Providers and deployers had to "ensure, to their best extent, a sufficient level of AI literacy". Then the Digital Omnibus replaced Article 4 in full. Now they must "take measures to support the development of AI literacy", and no specific individual level need be guaranteed. Whoever wrote the old duty into a policy wrote down a sentence that no longer exists.

Standards, codes of practice, templates, guidance, amendments, and enforcement practice all keep maturing, each on its own schedule. So the register has to hold the legal interpretation, the control evidence, the exceptions, and an update mechanism someone owns. A citation from last quarter may no longer point at the current text. The multinational's 2024 checklist was accurate on the day it was written. So was every stale compliance artifact ever produced.

Every compliance artifact carries an expiry date it does not print. Ask of a memo not whether it was right, but when it was last checked.

Carry this EU AI Act operational obligations boundary forward

Obligations arrive on a schedule. The interpretation keeps moving. The register is therefore a maintained document, never a completed one.

One question to carry out of this lesson: which readiness gap, guidance change, or reclassification would force the provider to redesign, restrict, remedy, or retire the system? Name it now, while naming it is cheap.

Key takeaways