The EU AI Act is already partly in force
Some duties bind today. The general-application date is set. The largest obligations have dates attached.
Prohibited practices and AI literacy duties have applied since 2 February 2025, and the general-application date is 2 August 2026. The risk for most businesses is assuming the whole Act is years away, when the classification work that decides your obligations is needed now.
The AI Act is phased. Some duties bind now, the rest are dated.
The AI Act entered into force.
Prohibited AI practices and AI literacy duties apply.
Obligations for general-purpose AI models, the governance structure, notified bodies and most penalty provisions apply.
The Act applies generally. Article 50 transparency duties apply, other than content-marking. The high-risk obligations are deferred (see below).
Marking of AI-generated content under Article 50(2). Ban on AI nudification tools and on AI-generated CSAM.
Agreed, not yet in forceNational regulatory sandboxes operational in each Member State.* General-purpose AI models placed on the market before 2 August 2025 must be compliant.
High-risk obligations apply for Annex III use-based systems (originally 2 August 2026).
Agreed, not yet in forceHigh-risk obligations apply for Annex I product-embedded systems (originally 2 August 2027).
Agreed, not yet in forceHigh-risk AI systems already used by public authorities must be brought into compliance.
Annex X large-scale IT systems placed on the market before 2 August 2027 must be compliant.
Some duties already bind. The general-application date is 2 August 2026. Several later obligations are agreed but not yet in force. The classification work that decides which apply to you does not wait for those dates.
* Date set by the Digital Omnibus on AI, agreed in trilogue on 7 May 2026 and approved by the European Parliament on 16 June 2026. It is not yet law. It takes effect only once published in the Official Journal. Until then the original AI Act date applies; for the Annex III high-risk obligations that original date is 2 August 2026.
The original dates are the law today. The Omnibus changes are agreed, not yet in force.
The Digital Omnibus on AI was agreed in trilogue on 7 May 2026 and approved by the European Parliament on 16 June 2026. It defers several of the high-risk obligations. It is not yet law. Council adoption is expected on 29 June 2026, followed by publication in the Official Journal and entry into force three days later. Until publication the original AI Act dates apply, so the binding date for the Annex III high-risk obligations remains 2 August 2026.
Last reviewed: 29 June 2026.
Three questions decide what the AI Act asks of you
Before a portfolio company can answer any compliance question, three things have to be settled. They decide which obligations apply, and to whom. Throughout, we use apply to mean the point at which an obligation becomes enforceable. A high-risk system already on the market before general application is caught only if it is significantly changed after that date.
What in the AI estate is in scope?
The Act reaches AI systems and general-purpose AI models placed on the EU market or used in the EU. The first task is a clear inventory of what is built, bought or embedded, and where it operates.
Where does the company sit in the value chain?
Provider, deployer, importer or distributor each carry different duties. A contract term or a substantial modification can move a deployer into a provider's position, and with it the heavier obligations.
Which uses are high-risk, which are transparency-only and which sit outside?
Annex III use cases and Annex I product-embedded systems carry the high-risk obligations. Article 50 brings transparency duties for a wider set. Many internal uses sit outside the regime.
Classification is the work that unlocks every other answer
Until scope, role and risk class are settled, no compliance question has a stable answer. Settled early the position is clear. Left late it surfaces in diligence, after the build.
Exposure is mapped before the obligations bite. Scope, value-chain role and risk class are settled, and the position is ready to show.
Classification happens under pressure, in a diligence request or a customer procurement review, against a system already in production.
Attercop settles the position
We map the AI estate against the Act; we work the value-chain and contractual position company by company; we classify uses against Annex I and Annex III; and we produce the position paper for investors, customers, auditors and the board.
Scope your exposure →Get a clear position before it is asked of you
We scope your portfolio against the EU AI Act, settling scope, role and risk class build by build, and hand you the position your investors, customers, auditors and board will ask for.