PRIVINOTCH  /  Focus areas  /  EU AI Act readiness

Know where the EU AI Act applies to you, and what to do first

Dates have moved, obligations have not gone away. We help you find your AI, classify it, close the gaps that matter and keep the evidence a regulator or customer will ask for.

Last reviewed October 2026. This page is general information, not legal advice.

Timeline

The dates that matter, as they stand

The Digital Omnibus on AI entered into force on 27 July 2026 and moved several deadlines. Always confirm against the Official Journal text for your situation.

1 August 2024
The AI Act enters into force.
In force
2 February 2025
Prohibited practices and AI literacy provisions apply.
Applies now
2 August 2025
Obligations for providers of general-purpose AI models; governance and penalty provisions apply.
Applies now
2 August 2026
General application date for most provisions, including transparency obligations under Article 50 (with grace periods for some systems).
Applies now
2 December 2026
New prohibition on certain non-consensual intimate content systems; end of the grace period for labelling by generative AI systems already on the market before 2 August 2026.
Upcoming
2 August 2027
Member State AI regulatory sandboxes due; general-purpose AI models placed on the market before 2 August 2025 must comply.
Upcoming
2 December 2027
High-risk obligations begin for standalone AI systems listed in Annex III, such as those used in employment, credit and education: risk management, data governance, technical documentation, human oversight and conformity assessment. Moved from 2 August 2026 by the Digital Omnibus.
Key date
2 August 2028
High-risk obligations begin for AI embedded in regulated products (Annex I), such as medical devices, machinery and toys.
Key date
Dates summarised from the European Commission’s AI Act Service Desk timeline and published legal commentary on the Digital Omnibus. Last reviewed October 2026. This page is general information, not legal advice.
Why act now

Delay is not the same as exemption

€35m / 7%

Maximum fines for prohibited practices. Up to €15m or 3% for most other obligations (Article 99).

Extra-territorial

The Act can reach UK and other non-EU organisations whose AI is placed on the EU market or whose output is used in the EU.

Already applying

Prohibitions and AI literacy have applied since 2 February 2025. Customers are asking about the rest in due diligence now.

What we do

A practical route to readiness

01

AI inventory and classification

Find the AI you build, buy and embed, establish your role (provider, deployer or both) and classify each system against the Act’s risk tiers.

02

Gap analysis

Assess practice against the obligations that apply to you, by system and by date, and prioritise what to fix first.

03

High-risk readiness

Where relevant, build risk management, data governance, documentation, human oversight and monitoring into a repeatable process.

04

AI literacy

Design role-based awareness and training so staff using AI understand its limits and their responsibilities.

05

Transparency and generative AI

Work out when users must be told they are interacting with AI and how generated content should be marked.

06

Vendor and general-purpose AI due diligence

Ask the right questions of AI suppliers and foundation-model providers, and keep the evidence.

How we work

Four steps to defensible evidence

Step 1

Discover

Interview stakeholders and build the AI inventory.

Step 2

Classify

Determine role, risk tier and applicable obligations for each system.

Step 3

Close gaps

Prioritised actions, policies, and controls matched to your timetable.

Step 4

Evidence

A records set you can show customers, auditors and regulators.

Questions

Frequently asked

Does the EU AI Act apply to a UK organisation?
It can. The Act applies to providers placing AI systems or general-purpose AI models on the EU market, to deployers established or located in the EU, and to providers and deployers elsewhere where the output of the AI system is used in the EU. Whether it applies to you depends on your facts, so we map this early.
Are the dates still changing?
The Digital Omnibus on AI entered into force on 27 July 2026 and moved several dates, including the application date for standalone high-risk systems to 2 December 2027. We track the position and confirm dates against the Official Journal for each client.
What is the difference between a provider and a deployer?
Broadly, a provider develops an AI system or has one developed and places it on the market under its own name. A deployer uses an AI system under its authority. Many organisations are deployers of third-party AI, and some are both. Your role determines your obligations.
We only use ChatGPT, Copilot or similar. Are we in scope?
Possibly. Using general-purpose AI tools can still trigger obligations such as AI literacy and, depending on use, transparency. The more important question is where those tools are used: use in areas such as recruitment or credit decisions can move you into high-risk territory.
What are the penalties?
Fines can reach €35 million or 7% of worldwide annual turnover for prohibited practices, and €15 million or 3% for most other obligations, whichever is higher for large organisations. For SMEs the lower of the two applies. These are maximums, set out in Article 99.
Talk to us

Find out what the EU AI Act means for you

Tell us what you build or use and where, and we will point you to the right first step.

  • Initial view on whether and how the Act applies
  • Focus on your highest-risk uses first
  • Works alongside your legal counsel

Prefer to talk it through? Book an intro call or email info@privinotch.co.uk.

We use your details to reply to you. See our Privacy Notice.