The EU AI Act is in force, and its timetable changed this summer. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and moved the high-risk obligations to 2 December 2027. The transparency duties, meanwhile, went live on 2 August 2026 as planned. Here is the current status, the obligations, and what enterprises should do now.

At a Glance - EU AI Act 2026 Status for Enterprises

  • Prohibited AI practices (social scoring, manipulation, emotion recognition at work) and the AI literacy obligation under Art. 4 have been legally binding since February 2025.
  • GPAI transparency and documentation obligations for deployers of general-purpose AI models are in force since August 2025.
  • Live since 2 August 2026: the transparency duties under Art. 50 - disclosing AI interaction, emotion recognition, labelling synthetic content. This deadline was not deferred and is the one that binds today.
  • The critical deadline for high-risk AI systems (including nearly all HR AI) is 2 December 2027 for standalone systems under Annex III, and 2 August 2028 for AI embedded in regulated products under Annex I. Regulation (EU) 2026/1744 made that settled law on 27 July 2026 - neither date is conditional on a further decision. Fines: up to 15 million euros or 3% of global turnover.
  • First step for every organization: complete an AI system inventory covering all officially deployed and shadow AI systems within four to eight weeks.

According to Gartner (2025), fewer than 10% of organizations subject to the EU AI Act have completed their AI system inventory, the foundational step for compliance. The European Commission estimates that over 300,000 enterprises across the EU deploy AI systems that may fall under regulatory scope.

MilestoneDateStatusKey Obligations
Entry into ForceAugust 2024ActiveFramework established
Prohibited Practices + AI LiteracyFebruary 2025ActiveBans on social scoring, manipulation; training obligation
GPAI ObligationsAugust 2025ActiveTransparency, labeling, governance inventory
Transparency Duties (Art. 50)2 August 2026ActiveDisclosure of AI interaction, emotion recognition, labelling of synthetic content
New Art. 5 Prohibitions2 December 2026UpcomingBan on AI generating non-consensual intimate imagery and CSAM
High-Risk Systems, Annex III2 December 2027UpcomingFull compliance: risk mgmt, data gov, human oversight. HR sits here.
High-Risk Systems, Annex I2 August 2028UpcomingSame obligations for AI embedded in regulated products

The World’s First Comprehensive AI Law

The EU AI Act has been in force since August 2024. It is the world’s first comprehensive legislation for regulating artificial intelligence, and it applies to every organization that develops, deploys, or provides AI systems. As of August 2026, four deadlines have passed - the last of them on 2 August 2026, when the transparency duties under Art. 50 became binding. The high-risk deadline now falls on 2 December 2027 for standalone systems. The classification behind it is unchanged, so the additional lead time is exactly that: lead time.

This article provides a sober overview of the current state: what already applies, what is coming when, which obligations affect your organization, and what you should do in the next 90 days.

Timeline: Seven Milestones

The phased implementation of the EU AI Act spans three years. Each milestone activates different obligations.

Aug 2024        Feb 2025        Aug 2025        Aug 2026        Dec 2027        Aug 2028
│               │               │               │               │               │
▼               ▼               ▼               ▼               ▼               ▼
Entry into      Prohibited      GPAI            Art. 50         High-Risk       High-Risk
Force           Practices +     Obligations     Transparency    Annex III       Annex I
                AI Literacy                     Duties          (HR sits here)  (embedded)
ACTIVE          ACTIVE          ACTIVE          ACTIVE          2 DEC 2027      2 AUG 2028

For organizations, this means: four stages are already legally binding, the most recent since 2 August 2026. The stage that is for many enterprises the most demanding - full high-risk conformity - falls due on 2 December 2027. Preparation typically requires four to six months of concentrated work, which is why the sixteen months in between are best treated as a schedule rather than a reprieve.

What Applies Now

Prohibited AI Practices (since February 2025)

Since February 2, 2025, certain AI applications have been fully prohibited in the EU. This covers:

  • Social scoring: AI systems that evaluate individuals based on their social behavior and derive disadvantages in unrelated contexts.
  • Manipulative AI: Systems that manipulate human behavior through subliminal techniques, such as dark patterns that coerce purchasing decisions or consent.
  • Real-time biometrics in public spaces: Real-time biometric identification is fundamentally prohibited. Narrowly defined exceptions exist for law enforcement in cases involving serious crimes, counterterrorism, and missing persons searches, each requiring judicial authorization.
  • Emotion recognition in the workplace and educational institutions: AI systems that detect emotions of employees or learners are impermissible.
  • Predictive policing based on individual characteristics: Risk assessments for criminal behavior based solely on personal attributes.

Penalties: Violations of the prohibition provisions are punishable by fines of up to 35 million euros or 7 percent of global annual turnover, whichever amount is higher.

For most enterprises, these prohibitions are not directly action-relevant because the described applications rarely occur in a business context. But the review is mandatory: ensure that none of your AI systems falls under these categories.

AI Literacy (since February 2025)

In parallel with the prohibitions, the AI literacy obligation under Article 4 has been in effect since February 2025. Regulation (EU) 2026/1744 rewrote its wording: providers and deployers no longer have to ensure that everyone operating or using an AI system possesses a sufficient level of AI competence - they must take measures supporting the development of AI literacy. That is an obligation of effort rather than of outcome, and it lowers the bar for what counts as compliance. It does not remove the duty, and the competence expected still scales with context: a developer requires deeper knowledge than an end user who uses a chatbot.

What this means in practice:

  • Training obligation: Organizations must be able to demonstrate that their employees have been trained.
  • Documentation obligation: Training content, participant lists, and refresh intervals must be documented.
  • Context appropriateness: Training must match the role. A generic 30-minute e-learning module is insufficient for decision makers who select and take responsibility for AI systems.

The AI literacy obligation is frequently underestimated because it does not impose high technical requirements. But it is already enforceable, and national authorities began their oversight in August 2026. It applies to every organization that uses AI, regardless of the risk class of the system. The softened wording changes what you must achieve, not whether you must be able to show your work. More on the organizational implications can be found in the article works council & AI Literacy: The Organizational Questions.

GPAI Obligations (since August 2025)

Since August 2025, the transparency and documentation obligations for General-Purpose AI models (GPAI) are in effect. These primarily concern the providers of language models, not the organizations that use them. But as a deployer, an organization that uses a GPAI model in its own applications, you have obligations:

  • Usage notices: If your application generates content that could be mistaken for human-created, you must label it accordingly.
  • Transparency toward users: Individuals interacting with an AI system must be informed of that fact.
  • Governance infrastructure: You must be able to document which GPAI models you deploy, in which context, and with which safeguards.

The GPAI obligations require a clean inventory: Which AI models do you deploy? From which provider? In which application? With which risk classification? This information forms the foundation for the high-risk compliance due on 2 December 2027 - and, more immediately, for the Art. 50 labelling duties that have applied since 2 August 2026.

The High-Risk Deadline: 2 December 2027

The high-risk deadline is the most demanding date in the EU AI Act for most organizations, and it now falls on 2 December 2027. From that date, all standalone AI systems listed in Annex III must be fully compliant. For AI embedded in products already covered by EU product-safety law - Annex I - the date is 2 August 2028. Both were set by Regulation (EU) 2026/1744, in force since 27 July 2026, and neither depends on a further Commission decision. The requirements are extensive; the classification behind them did not change.

Which Systems Fall Under High Risk?

Annex III of the EU AI Act defines eight areas in which AI systems are classified as high-risk. The most relevant for enterprises:

  • Employment, personnel management, and access to self-employment: AI systems for job postings, candidate selection, performance evaluation, promotion decisions, and terminations.
  • Creditworthiness and insurance: Automated credit scoring, risk scoring.
  • Biometric identification: Facial recognition, voice identification, including in non-public spaces.
  • Critical infrastructure: AI systems in energy, water, transportation, telecommunications.
  • Education and vocational training: Automated exam grading, access control to educational institutions.

Requirements for High-Risk Systems

If any of your AI systems is classified as high-risk, you must meet the following requirements by the high-risk deadline - 2 December 2027 for Annex III systems, 2 August 2028 for Annex I systems:

  1. Risk management system: A documented system for identifying, analyzing, and mitigating risks throughout the entire lifecycle of the AI system.
  2. Data governance: Requirements for quality, representativeness, and accuracy of training data. When using pre-trained models: documentation of data provenance and fine-tuning.
  3. Technical documentation: Comprehensive documentation of the system prior to deployment: architecture, training procedures, performance metrics, testing procedures, limitations.
  4. Record-keeping obligations: Automatic logging of all relevant events to ensure the traceability of decisions.
  5. Transparency: Instructions for deployers that enable proper use.
  6. Human oversight: Technical measures that enable effective human monitoring. The Decision Layer is an architecture that implements precisely this requirement.
  7. Accuracy, robustness, cybersecurity: The system must reliably deliver its declared performance and be protected against manipulation.
  8. Conformity assessment: For certain categories, an assessment by a notified body (conformity assessment body) is required. For others, a self-assessment is sufficient.

Penalties: Violations of the high-risk obligations are punishable by fines of up to 15 million euros or 3 percent of global annual turnover.

Particular Relevance for HR

The HR department is the business area where AI applications most frequently fall under the high-risk category. This is due to Annex III, Number 4, Employment and Personnel Management. The classification covers:

Automated screening of applications: high-risk. Any AI system that pre-sorts, evaluates, or filters job applications falls under the high-risk category. Regardless of whether the final decision is made by a human. The pre-selection alone is regulated.

AI-assisted performance evaluations: high-risk. When AI systems analyze performance data and derive evaluations or prepare evaluations from them, that is high-risk. This applies even to systems that only issue recommendations.

Predictive attrition: high-risk. AI systems that predict which employees are likely to leave the organization process personal data to derive employment decisions. That is high-risk.

Automated shift optimization: potentially high-risk. If an AI system creates shift schedules while processing individual preferences, performance data, or health information, it may fall under high-risk. The classification depends on the specific scope of data involved.

For HR departments, this means: inventory all AI systems used in employment contexts. Review the classification. Begin compliance preparation. The high-risk deadline is 2 December 2027, and the classification stands, so the lead time is there to reach full conformity rather than to postpone starting. One duty is not on that schedule at all: an HR chatbot or an AI-drafted candidate communication needs its Art. 50 disclosure now. Further information on the interplay of AI and HR can be found at HR & AI Agents.

The Digital Omnibus Is Law: What Regulation (EU) 2026/1744 Changed

The Digital Omnibus on AI was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026 as Regulation (EU) 2026/1744. It amends the AI Act rather than replacing it. Four changes matter for enterprises.

The high-risk deadlines moved. Standalone systems under Annex III go from 2 August 2026 to 2 December 2027; AI embedded in products already covered by EU product-safety law under Annex I goes to 2 August 2028. The earlier proposal had made the deferral conditional on harmonised standards being available. The adopted text did not: both dates are fixed and require no further Commission decision.

The transparency duties did not move. Article 50 applied from 2 August 2026 as originally scheduled. Generative systems already on the EU market before that date received a grace period for the machine-readable marking requirement, running to 2 December 2026. Everything else - disclosing that a person is interacting with AI, disclosing emotion recognition, labelling deepfakes - binds now.

Two prohibitions were added. From 2 December 2026, AI systems that generate or manipulate non-consensual intimate imagery, and those that generate child sexual abuse material, join the banned practices in Article 5. Both carry the top penalty tier.

Article 4 was softened. The duty to ensure a sufficient level of AI literacy became a duty to take measures supporting its development - effort rather than outcome.

The penalty framework is untouched: up to 35 million euros or 7% of global annual turnover for the Article 5 prohibitions, up to 15 million euros or 3% for most other infringements.

The recommendation: Plan against 2 December 2027, and do not read it as a pause. Risk management, data governance, record-keeping, and enforced human oversight are architectural properties - cheap to design in, expensive to retrofit into a system already carrying production traffic. Sixteen months is roughly one budget cycle, which is what it takes to build these deliberately instead of under deadline pressure. Meanwhile the duty that is actually live is the Art. 50 one, and it is the cheapest to fail: an unlabelled chatbot is visible from outside the company.

Practical Recommendation: Start an AI System Inventory

Regardless of whether your AI systems fall under high-risk or not: the first step is always the same. You need a complete inventory of all AI systems in your organization.

What Must Be Captured

For each AI system, document:

  • System designation and description: What does the system do? Which process does it support?
  • Provider and model: Which AI model is being used? From which provider? Cloud API or self-hosted?
  • Your organization’s role: Are you the provider, deployer, or both?
  • Risk classification: Does the system fall under one of the categories in Annex III (high-risk)? Under the prohibition provisions in Article 5? Or is it a system with limited risk?
  • Affected individuals: Which persons are affected by the system’s decisions or outputs?
  • Data processing: What data does the system process? Personal data? Trade secrets?
  • Safeguards: What technical and organizational measures are implemented? Human oversight? Audit trail?

Timeline

An AI system inventory for a mid-sized organization is achievable in four to eight weeks. The effort depends on the number of systems, the state of documentation, and internal coordination. Start with the obvious systems, the officially procured AI tools, and then expand to shadow AI: AI systems that employees use independently without IT knowledge.

The inventory is not a one-time task. It must be continuously updated as new systems are added, existing systems are modified, and regulatory assessments evolve. The governance infrastructure must be designed so that the inventory remains a living document.

Summary: What You Should Do Now

  1. Review the prohibition provisions. Ensure that none of your AI systems falls under the practices prohibited since February 2025.
  2. Fulfill the AI literacy obligation. Document training for all AI users in your organization. The obligation is in effect now.
  3. Create an AI system inventory. Capture all AI systems, their providers, deployment context, and risk classification. Timeframe: four to eight weeks.
  4. Identify high-risk systems. Review the HR area, credit decisions, and automated processes with direct impact on individuals in particular.
  5. Check your Art. 50 transparency duties. This is the deadline that has already passed. Every chatbot, every AI-generated image, every synthetic voice in customer contact needs its disclosure or label. Systems on the market before 2 August 2026 have until 2 December 2026 for machine-readable marking, and no longer.
  6. Begin high-risk compliance. For systems falling under Annex III: establish risk management system, data governance, technical documentation, and human oversight. Deadline: 2 December 2027 - fixed by Regulation (EU) 2026/1744, not conditional. For Annex I systems: 2 August 2028.

📘 Enterprise AI Infrastructure Blueprint 2026 - Article Series

All articles in this series: Enterprise AI Infrastructure Blueprint 2026


Gosign supports organizations with EU AI Act compliance, from system inventory to conformity assessment. If you want to know where your organization stands, talk to us.

Book a consultation. 30 minutes to assess your compliance status.

Bert Gogolin

Bert Gogolin

CEO & Founder, Gosign

AI Governance Briefing

Enterprise AI, regulation, and infrastructure - once a month, directly from me.

No spam. Unsubscribe anytime. Privacy policy