Responsible AI
EU AI Act: Obligations, GPAI, Transparency, and the 2026 Timeline
Operationalize EU AI Act duties for high-risk systems, GPAI models, transparency, literacy, post-market monitoring, incidents, and staged applicability.
By the end you can
- Explain why EU AI Act readiness requires a maintained obligation register that connects roles and systems to exact duties, dates, evidence, controls, and updates
- Distinguish High-risk system provider, GPAI model provider, and Deployer
- Identify evidence that connects early obligations to post-market and enforcement
- Design a review that moves from build the obligation register to maintain the legal baseline
Visual
Duties that arrive on different dates
The Act does not switch on. Prohibitions and AI literacy came first. GPAI documentation came next. The high-risk lifecycle comes after that. Transparency and post-market duties run across all of it, all the way through.
- 1
Early obligations
Prohibited practices, AI literacy, and initial governance milestones.
- 2
GPAI layer
Model documentation, downstream information, copyright policy, training-content summary, and systemic-risk duties where applicable.
- 3
High-risk lifecycle
Risk management, data governance, documentation, records, transparency, oversight, accuracy, robustness, cybersecurity, QMS, conformity, and monitoring.
- 4
Transparency duties
Human interaction, synthetic content, deepfakes, and specified biometric or emotion uses.
- 5
Post-market and enforcement
Monitoring, serious incidents, corrective action, authority cooperation, penalties, and evidence retention.
Steps
Article, role, date, owner
The artifact is an obligation register: article, role, date, owner. The four steps after it are how that register turns into evidence.
1. Build the obligation register
Map article, role, system, effective date, owner, evidence, and dependency.
2. Prioritize immediate duties
Prohibitions, literacy, GPAI, transparency, and currently applicable controls.
3. Implement lifecycle controls
Connect risk, quality, data, documentation, oversight, testing, monitoring, and incidents.
4. Validate readiness
Run evidence reviews, role exercises, disclosure tests, and authority cooperation drills.
5. Maintain the legal baseline
Monitor official sources, standards, guidance, changes, and product reclassification.
Example
One checklist, written as if one date
A multinational writes one "AI Act ready" checklist in 2024. By August 2026 the checklist has not moved. It still treats every duty as starting on one date. It omits GPAI obligations that are already applicable. It assumes every Annex III high-risk requirement is fully in force today. Three errors, one cause: the document was finished.
- Timeline error: Provisions apply on different dates, and later changes moved some high-risk timing again.
- Role mixing: GPAI-provider duties sit in the same rows as deployer duties for downstream applications.
- Control mismatch: The policy names technical documentation but never the lifecycle evidence or the owner.
- Transparency gap: Notices for generated content, interaction, emotion recognition, and biometric categorization are mapped to no product surface.
- Change risk: Nobody owns amendments, codes, standards, or Commission guidance.
Effective dates are what a policy lacks
Implementing the EU AI Act is role-specific and date-specific work. A register connects each provision to four things: the systems it covers, the actor who owes it, the date it starts, and the evidence that it is met. The same rows reach outward to standards, operating controls, authorities, and change monitoring.
One column separates a register from a policy: the effective date. The 2024 checklist carried one date. The Act carries a series.
Plan obligation by obligation. A staggered series has no single day on which the organization becomes compliant.
Case
The dates the Act actually carries
The Act entered into force on 1 August 2024. Prohibited practices and AI literacy started on 2 February 2025. Governance and GPAI duties started on 2 August 2025. Broad application, transparency included, started on 2 August 2026.
Then the high-risk deadline moved. The Digital Omnibus on AI came into force on 27 July 2026, six days before 2 August. It pushed the Chapter III high-risk obligations out to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. The amending text is Regulation (EU) 2026/1744.
Six days. Anyone whose roadmap named 2 August 2026 as the high-risk date was holding the wrong date before the week was out. Check the official text, not last quarter's slide.
Case
Article 51(2)’s single number, and Article 99(3)’s ceiling
European regulations rarely name a number. Article 51(2) names one. A general-purpose model trained with more than 10^25 floating point operations is presumed to have high-impact capabilities. Two more numbers sit in Article 99(3): a top penalty of 35 million euros or 7% of worldwide annual turnover, whichever is higher.
The compute figure is a proxy, and everyone involved knows it. It is still the line a compliance team has to plan against.
Comparison
High-risk system provider, GPAI model provider, or Deployer?
One deployment can sit under all three roles at once. None of the three discharges the duties of the other two.
High-risk system provider
Governs a specific high-risk AI system through its lifecycle.
- Risk and quality management
- Technical documentation and records
- Conformity and registration where required
- Post-market monitoring and incident duties
GPAI model provider
Governs a general-purpose model supplied downstream.
- Model documentation and downstream information
- Copyright-compliance policy and training-content summary
- Additional duties for systemic-risk models
- Does not replace downstream system governance
Deployer
Controls professional use of an AI system.
- Follows instructions and local monitoring
- Ensures relevant input and human oversight where required
- Keeps logs and provides information in covered contexts
- Manages local impact and affected-person obligations
Example
Dates on every row
A register that does not carry dates is a list. These four exercises turn it into a program.
- Date-aware register: Give each obligation its own row, carrying role, system, start date, evidence, and current interpretation.
- Transparency surface test: Walk every user-facing and public interface where a disclosure may be required.
- GPAI handoff: List what downstream providers need in order to understand capabilities and limitations.
- Serious-incident drill: Test detection, assessment, notification, cooperation, and corrective action. Run it against all three clocks: 15 days as the general rule, 2 days for a widespread infringement, 10 days where a person has died.
Key idea
Accurate on the day it was written
Dates and classifications go stale. A slide, a blog post, an old legal memo — each was right once. So do not hard-code one "AI Act deadline" into a roadmap. And do not treat a harmonized standard as proof that every substantive obligation is met.
The AI literacy duty used to be a result. Providers and deployers had to "ensure, to their best extent, a sufficient level of AI literacy". Then the Digital Omnibus replaced Article 4 in full. Now they must "take measures to support the development of AI literacy", and no specific individual level need be guaranteed. Whoever wrote the old duty into a policy wrote down a sentence that no longer exists.
Standards, codes of practice, templates, guidance, amendments, and enforcement practice all keep maturing, each on its own schedule. So the register has to hold the legal interpretation, the control evidence, the exceptions, and an update mechanism someone owns. A citation from last quarter may no longer point at the current text. The multinational's 2024 checklist was accurate on the day it was written. So was every stale compliance artifact ever produced.
Every compliance artifact carries an expiry date it does not print. Ask of a memo not whether it was right, but when it was last checked.
Carry this EU AI Act operational obligations boundary forward
Obligations arrive on a schedule. The interpretation keeps moving. The register is therefore a maintained document, never a completed one.
One question to carry out of this lesson: which readiness gap, guidance change, or reclassification would force the provider to redesign, restrict, remedy, or retire the system? Name it now, while naming it is cheap.
Key takeaways
- EU AI Act implementation is role-specific, system-specific, and date-specific.
- Prohibited-practice and AI-literacy duties began before broad application of the Act.
- GPAI duties and downstream high-risk-system duties govern different objects.
- Transparency obligations should be mapped to actual product and distribution surfaces.
- Technical documentation must connect to operating controls, post-market evidence, and incident response.
- Official sources, standards, amendments, and guidance require an owned change-management process.