Attercop
EU AI Act

The EU AI Act is already partly in force

Some duties bind today. The general-application date is set. The largest obligations have dates attached.

Prohibited practices and AI literacy duties have applied since 2 February 2025, and the general-application date is 2 August 2026. The risk for most businesses is assuming the whole Act is years away, when the classification work that decides your obligations is needed now.

Next AI Act milestone
days remaining
Until 2 August 2026, when the AI Act reaches general application and the Article 50 transparency duties apply. This date holds regardless of the Omnibus.
The dates that matter

The AI Act is phased. Some duties bind now, the rest are dated.

1 August 2024
In force

The AI Act entered into force.

2 February 2025
Prohibitions

Prohibited AI practices and AI literacy duties apply.

2 August 2025
GPAI and governance

Obligations for general-purpose AI models, the governance structure, notified bodies and most penalty provisions apply.

2 August 2026
General application

The Act applies generally. Article 50 transparency duties apply, other than content-marking. The high-risk obligations are deferred (see below).

2 December 2026*
Content marking

Marking of AI-generated content under Article 50(2). Ban on AI nudification tools and on AI-generated CSAM.

Agreed, not yet in force
2 August 2027
Sandboxes and legacy GPAI

National regulatory sandboxes operational in each Member State.* General-purpose AI models placed on the market before 2 August 2025 must be compliant.

2 December 2027*
High-risk, Annex III

High-risk obligations apply for Annex III use-based systems (originally 2 August 2026).

Agreed, not yet in force
2 August 2028*
High-risk, Annex I

High-risk obligations apply for Annex I product-embedded systems (originally 2 August 2027).

Agreed, not yet in force
2 August 2030
Public authorities

High-risk AI systems already used by public authorities must be brought into compliance.

31 December 2030
Legacy IT systems

Annex X large-scale IT systems placed on the market before 2 August 2027 must be compliant.

Some duties already bind. The general-application date is 2 August 2026. Several later obligations are agreed but not yet in force. The classification work that decides which apply to you does not wait for those dates.

* Date set by the Digital Omnibus on AI, agreed in trilogue on 7 May 2026 and approved by the European Parliament on 16 June 2026. It is not yet law. It takes effect only once published in the Official Journal. Until then the original AI Act date applies; for the Annex III high-risk obligations that original date is 2 August 2026.

Status of the dates

The original dates are the law today. The Omnibus changes are agreed, not yet in force.

The Digital Omnibus on AI was agreed in trilogue on 7 May 2026 and approved by the European Parliament on 16 June 2026. It defers several of the high-risk obligations. It is not yet law. Council adoption is expected on 29 June 2026, followed by publication in the Official Journal and entry into force three days later. Until publication the original AI Act dates apply, so the binding date for the Annex III high-risk obligations remains 2 August 2026.

As at 29 June 2026, the Omnibus is approved by Parliament and awaiting Council adoption and Official Journal publication, so it is not yet in force. Where a date is marked with an asterisk it is set by the Omnibus and takes effect only on publication. Until then the original date binds. Article 50 transparency, due at general application, is not deferred by the Omnibus.

Last reviewed: 29 June 2026.

Where it bites

Three questions decide what the AI Act asks of you

Before a portfolio company can answer any compliance question, three things have to be settled. They decide which obligations apply, and to whom. Throughout, we use apply to mean the point at which an obligation becomes enforceable. A high-risk system already on the market before general application is caught only if it is significantly changed after that date.

01 / Scope

What in the AI estate is in scope?

The Act reaches AI systems and general-purpose AI models placed on the EU market or used in the EU. The first task is a clear inventory of what is built, bought or embedded, and where it operates.

02 / Role

Where does the company sit in the value chain?

Provider, deployer, importer or distributor each carry different duties. A contract term or a substantial modification can move a deployer into a provider's position, and with it the heavier obligations.

03 / Classification

Which uses are high-risk, which are transparency-only and which sit outside?

Annex III use cases and Annex I product-embedded systems carry the high-risk obligations. Article 50 brings transparency duties for a wider set. Many internal uses sit outside the regime.

Why timing matters

Classification is the work that unlocks every other answer

Until scope, role and risk class are settled, no compliance question has a stable answer. Settled early the position is clear. Left late it surfaces in diligence, after the build.

Scoped early

Exposure is mapped before the obligations bite. Scope, value-chain role and risk class are settled, and the position is ready to show.

Found late

Classification happens under pressure, in a diligence request or a customer procurement review, against a system already in production.

What Attercop does

Attercop settles the position

We map the AI estate against the Act; we work the value-chain and contractual position company by company; we classify uses against Annex I and Annex III; and we produce the position paper for investors, customers, auditors and the board.

Scope your exposure
Regulatory readiness

Get a clear position before it is asked of you

We scope your portfolio against the EU AI Act, settling scope, role and risk class build by build, and hand you the position your investors, customers, auditors and board will ask for.