--- name: "EU AI Act (Regulation (EU) 2024/1689)" description: "The EU's risk-tiered AI regulation, its phased application timeline, GPAI obligations, and the Digital Omnibus (Reg. (EU) 2026/1744, in force 27 July 2026) that postponed the high-risk deadlines." keywords: "EU AI Act, Regulation (EU) 2024/1689, Digital Omnibus 2026/1744, high-risk AI systems, Annex III, GPAI obligations, Article 50 transparency, AI-generated content marking, conformity assessment, FRIA, AI Act penalties, AI Office enforcement" type: reference source_id: eu_ai_act source_url: "https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng" about_type: Legislation about_identifier: "Regulation (EU) 2024/1689" about_jurisdiction: "European Union" last_observed_at: "2026-09-05T00:00:00Z" last_observed_commit_or_version: "Reg. (EU) 2024/1689 in force 2024-08-01; amended by Digital Omnibus Reg. (EU) 2026/1744 (in force 2026-07-27); Commission guidelines: Art. 50 transparency (final, 2026-07-20), high-risk classification (draft, 2026-05-19); Commission opinion on the Code of Practice on AI-generated content (2026-07-09); enforcement by the AI Office and national authorities since 2026-08-02 (Commission release 2026-07-31, first list of 180+ signatories of the Code of Practice on transparency of AI-generated content)" provenance_chain: - timestamp: "2026-09-05T00:00:00Z" pr: "manual refresh (September 2026)" change: substantive - timestamp: "2026-06-16T00:00:00Z" pr: "baseline (manual)" change: baseline - timestamp: "2026-08-02T00:00:00Z" pr: "manual" change: version_bump --- # EU AI Act (Regulation (EU) 2024/1689) !!! info "Provenance & licence" **Source:** [EUR-Lex ELI permalink](https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng) · **Last observed:** `2026-09-05` · **Version:** Base regulation in force 2024-08-01; amended by **Digital Omnibus** Reg. (EU) 2026/1744, in force 2026-07-27 · **Status:** planned — automated watch adapter not yet live; this page is updated manually (see provenance chain) · **Licence:** © European Union (EUR-Lex), Decision 2011/833/EU (`open-attribution`) !!! info "Now law — Digital Omnibus, Reg. (EU) 2026/1744 (in force 27 July 2026)" The *Digital Omnibus on AI* — proposed **19 November 2025**, provisionally agreed in the May 2026 trilogue — was adopted on **8 July 2026**, published in the Official Journal on **24 July 2026** as **[Regulation (EU) 2026/1744](https://eur-lex.europa.eu/eli/reg/2026/1744/oj)** and **entered into force on 27 July 2026**. Headline change: the high-risk regime is deferred — stand-alone **Annex III** systems to **2 December 2027**, **Annex I** product-embedded AI to **2 August 2028** (fixed dates, replacing the proposal's conditional "standards-ready" trigger). It also adds an **Art. 5 prohibition** on CSAM/NCII generation, grants a marking grace period, strengthens the **AI Office**'s enforcement powers over GPAI-based systems, softens the [Art. 4](https://artificialintelligenceact.eu/article/4/ "EU AI Act Article 4 — AI literacy: providers and deployers must ensure a sufficient level of AI literacy in their staff; the Omnibus softened this from guaranteeing competence to supporting literacy measures.") AI-literacy duty from *guaranteeing* to *supporting*, extends the [Art. 10(5)](https://artificialintelligenceact.eu/article/10/ "EU AI Act Article 10(5) — the legal ground to process special categories of personal data strictly for bias detection and correction; the Omnibus extends it beyond high-risk to all AI systems, with a strict-necessity threshold.") bias-detection ground to **all** AI systems, reinstates registration for [Art. 6(3)](https://artificialintelligenceact.eu/article/6/ "EU AI Act Article 6(3) — the derogation that lets a system escape high-risk classification when it performs only narrow procedural or preparatory tasks; the Omnibus reinstates the duty to register such carve-outs in the EU database.") carve-outs, narrows "safety component" and extends SME simplifications to small mid-caps — **all dates in the [application timeline](#application-timeline-as-amended-by-the-omnibus) below**. The Omnibus also amends Reg. (EU) 2018/1139 (aviation) and Reg. (EU) 2023/1230 (machinery). ## Summary The EU AI Act (Regulation (EU) 2024/1689) is the first comprehensive, horizontal AI law. It classifies AI systems by risk — **unacceptable (prohibited), high-risk, limited-risk (transparency), and minimal** — and imposes obligations scaled to that tier, with separate rules for **general-purpose AI (GPAI) models**. It entered into force on 1 August 2024 and applies in phases. As of August 2026, prohibitions, GPAI model rules and the Art. 50 transparency duties are in force; the high-risk regime has been deferred to December 2027 / August 2028 by the Digital Omnibus (Reg. (EU) 2026/1744 — see box above). ## In plain language !!! note "Our explanation, not the official text" Plain-language summary in our own words — not the normative text. Follow the source for the authoritative wording. This is general information, not legal advice. The EU AI Act is a binding law that sorts AI systems by how risky they are and attaches duties to each level: some uses are banned, "high-risk" uses carry heavy obligations, and general-purpose models have their own rules. In short — the riskier the use, the more you must document, test, and supervise it. A 2026 "Digital Omnibus" amendment — in force since 27 July 2026 — pushed the high-risk deadlines to December 2027 / August 2028, so always check the *amended* timeline, not the original one. ## Key terms - **High-risk system** — an AI use listed in Annex III (or a safety component of a regulated product) that triggers the heaviest duties. - **GPAI** — a general-purpose AI model, with its own transparency and copyright duties. - **Conformity assessment** — the check (self- or third-party) that a high-risk system meets the rules before market. - **FRIA** — a fundamental-rights impact assessment some deployers must perform. - **CETS 225** — the Council of Europe AI Convention; the EU approved it in 2026 and implements it **exclusively through the AI Act** (Council Decision (EU) 2026/1080, Art. 3). See the [CETS 225 page](reference_coe_ai_convention.md). ## Application timeline (as amended by the Omnibus) The dates below reflect [Art. 113](https://artificialintelligenceact.eu/article/113/ "EU AI Act Article 113 — entry into force and application: the staggered schedule that determines when each chapter of the Act starts to apply.") **as amended** by Reg. (EU) 2026/1744 — the anchor an auditor checks first, because it decides which obligations are actually in force at the engagement date. | Date | What applies | | ---- | ------------ | | `2024-08-01` | Entry into force of Reg. (EU) 2024/1689. | | `2025-02-02` | [Art. 4](https://artificialintelligenceact.eu/article/4/ "EU AI Act Article 4 — the AI-literacy duty for providers and deployers (softened by the Omnibus from guaranteeing to supporting literacy).") AI literacy + [Art. 5](https://artificialintelligenceact.eu/article/5/ "EU AI Act Article 5 — the prohibited AI practices: manipulation, exploitation of vulnerabilities, social scoring, untargeted facial scraping and, per the Omnibus, CSAM/NCII generation.") prohibitions + general provisions. | | `2025-08-02` | [GPAI rules (Art. 51 ff.)](https://artificialintelligenceact.eu/article/51/ "EU AI Act Articles 51–56 — obligations for general-purpose AI models: documentation, copyright policy, training-data summary; added duties for systemic-risk models."), governance (AI Office, AI Board), notified-body chapter, [penalties framework (Art. 99)](https://artificialintelligenceact.eu/article/99/ "EU AI Act Article 99 — the national fine bands: up to €35 m / 7 % of worldwide turnover for prohibited practices, €15 m / 3 % for most other violations, €7.5 m / 1 % for misleading information.") except Art. 101. | | `2026-08-02` | General application **(except the deferred high-risk regime)** — incl. [Art. 50](https://artificialintelligenceact.eu/article/50/ "EU AI Act Article 50 — transparency duties: disclose AI interaction, mark synthetic content machine-readably, label deep fakes.") transparency and [Art. 101](https://artificialintelligenceact.eu/article/101/ "EU AI Act Article 101 — Commission fines for GPAI-model providers: up to 3 % of worldwide annual turnover or €15 m, whichever is higher.") GPAI fines. | | `2026-12-02` | Grace periods end: [Art. 50(2)](https://artificialintelligenceact.eu/article/50/ "EU AI Act Article 50(2) — machine-readable marking of synthetic content; the Omnibus granted systems already on the market before 2 Aug 2026 a grace period until 2 Dec 2026.") marking for pre-Aug-2026 systems; the new Art. 5 CSAM/NCII prohibition fully applies. | | `2027-08-02` | National [regulatory sandboxes](https://artificialintelligenceact.eu/article/57/ "EU AI Act Article 57 — each Member State must have at least one operational AI regulatory sandbox; the Omnibus moved this deadline from 2 Aug 2026 to 2 Aug 2027 and extends priority access to small mid-caps.") operational *(Omnibus: moved from 2026)*. Legacy [GPAI models](https://artificialintelligenceact.eu/article/111/ "EU AI Act Article 111(3) — general-purpose AI models already on the market before 2 August 2025 must comply with the GPAI obligations by 2 August 2027.") placed on the market before 2 Aug 2025 must comply. | | `2027-12-02` | **[Annex III](https://artificialintelligenceact.eu/annex/3/ "EU AI Act Annex III — the list of stand-alone high-risk use cases: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice.") stand-alone high-risk obligations** *(Omnibus: was 2026-08-02)*. | | `2028-08-02` | **[Annex I](https://artificialintelligenceact.eu/annex/1/ "EU AI Act Annex I — the list of Union harmonisation legislation (machinery, medical devices, aviation …); AI safety components of these regulated products follow the product's conformity regime.") product-embedded high-risk obligations** *(Omnibus: was 2027-08-02)*. | | `2030-08-02` | Legacy high-risk systems **in use by public authorities**: providers and deployers must be compliant ([Art. 111(2)](https://artificialintelligenceact.eu/article/111/ "EU AI Act Article 111(2) — high-risk AI systems intended to be used by public authorities: providers and deployers must take the necessary compliance steps by 2 August 2030.")). | | `2030-12-31` | Legacy AI components of large-scale EU IT systems (Annex X) must comply; other pre-existing high-risk systems come into scope only upon significant modification ([Art. 111](https://artificialintelligenceact.eu/article/111/ "EU AI Act Article 111 — transitional rules for AI systems already on the market: large-scale EU IT systems by 31 Dec 2030; other pre-existing high-risk systems only upon significant design change.")). | ## In depth: what counts as an "AI system" > **Reading guide:** the boxed **“Source text”** is the Act's own wording > (verbatim; EU law is reusable under EUR-Lex Decision 2011/833/EU with source > acknowledgement). Text marked **“In our words”** is our explanation. !!! quote "Source text — EU AI Act, Art. 3(1) (© European Union, EUR-Lex)" ‘AI system’ means a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. **In our words —** this single sentence decides whether the whole Act applies to you. The load-bearing phrases are *“machine-based”*, *“varying levels of autonomy”*, *“may exhibit adaptiveness”* and especially *“infers … how to generate outputs”*. A fixed, deterministic script usually falls **outside**; a model that *infers* its outputs falls **inside**. Once you are in scope, the risk **tier** — prohibited · high-risk · limited (transparency) · minimal — decides how heavy your duties are. !!! success "From my training — University of Oxford · *Managing Enterprise AI Risks* (2026)" For high-risk systems the audit pivot I practise is **evidence over intent**: risk classification, **Model Cards**, an **AI-SBOM**, a **living risk register** and **Human-in-the-Loop (HITL)** controls mapped to Art. 9 / 14 / 15 — and I treat the EU AI Act, NIST AI RMF and ISO/IEC 42001 as *one* control set, not three. [Verify certificate ↗](https://certificates.conted.ox.ac.uk/5d483a65-dba2-47a2-92b0-8acfe0dcfd3a) ## In depth: machine-readable transparency (Art. 50 + Recital 133) !!! quote "Source text — EU AI Act, Recital 133, excerpt (© European Union, EUR-Lex)" … it is appropriate to require providers of those systems to embed technical solutions that enable marking in a machine readable format and detection that the output has been generated or manipulated by an AI system and not a human. Such techniques and methods should be sufficiently reliable, interoperable, effective and robust as far as this is technically feasible, taking into account available techniques or a combination of such techniques, such as watermarks, metadata identifications, cryptographic methods for proving provenance and authenticity of content, logging methods, fingerprints or other techniques, as may be appropriate. **In our words —** the Act does not stop at "label your AI content". The binding duty sits in **[Art. 50(2)](https://artificialintelligenceact.eu/article/50/)**: providers of generative systems must mark synthetic output in a **machine-readable** format; **Recital 133** then names the technique families the legislator has in mind — **watermarks, metadata identification, cryptographic provenance/authenticity proofs, logging methods and fingerprints**. A recital is interpretive, not operative — but it signals where compliance practice is heading: provenance signals embedded in the content itself and travelling along the digital value chain (in practice, C2PA-style "Content Credentials" metadata combined with watermarking). Two timeline anchors: Art. 50 applies since **2 August 2026**; systems already on the market before that date have a marking grace period until **2 December 2026** (Digital Omnibus, Reg. (EU) 2026/1744). Note the scope carve-out in the recital: purely **assistive/standard-editing** functions that do not substantially alter the input are not covered. Cross-framework: the NIST GenAI Profile (600-1) makes **information integrity / content provenance** a primary focus area — see [NIST AI RMF](reference_nist_ai_rmf.md). ## Key Sections - **[Art. 5 — Prohibited practices](https://artificialintelligenceact.eu/article/5/ "EU AI Act Article 5 — the AI practices banned outright: manipulation, exploitation of vulnerabilities, social scoring, untargeted facial scraping, and (per the Omnibus) CSAM/NCII generation.")** — manipulative, exploitative, social-scoring, untargeted scraping, and (per the Omnibus) CSAM/NCII generation. - **[Art. 6](https://artificialintelligenceact.eu/article/6/ "EU AI Act Article 6 — the classification test that determines whether an AI system counts as high-risk.") + [Annex III](https://artificialintelligenceact.eu/annex/3/ "EU AI Act Annex III — the list of stand-alone high-risk use cases (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice) that triggers the heaviest duties.") — High-risk classification** — the test for whether a system is high-risk; Art. 6(1) treated separately in the timeline. - **[Art. 16 — Provider obligations](https://artificialintelligenceact.eu/article/16/ "EU AI Act Article 16 — the duties a provider of a high-risk AI system owes: risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy, robustness and cybersecurity.")** — risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy/robustness/cybersecurity. - **[Art. 26 — Deployer obligations](https://artificialintelligenceact.eu/article/26/ "EU AI Act Article 26 — the duties of a deployer of a high-risk AI system: use per instructions, assign competent human oversight, control input data, monitor operation, retain logs, inform affected workers and persons.")** — using the system per instructions, assigning competent human oversight, input-data control, operation monitoring, log retention. - **[Art. 27 — Fundamental Rights Impact Assessment (FRIA)](https://artificialintelligenceact.eu/article/27/ "EU AI Act Article 27 — the Fundamental Rights Impact Assessment certain deployers of high-risk AI must perform before use.")** — required of certain deployers of high-risk systems. - **[Art. 40 — Harmonised standards](https://artificialintelligenceact.eu/article/40/ "EU AI Act Article 40 — high-risk systems that apply harmonised standards (developed by CEN/CENELEC on Commission request) enjoy a presumption of conformity; the delay of these standards was the main driver of the Omnibus deferral.")** — presumption of conformity when applying harmonised standards; their CEN/CENELEC delay was the driver of the Omnibus deferral. - **[Art. 43 — Conformity assessment](https://artificialintelligenceact.eu/article/43/ "EU AI Act Article 43 — the conformity-assessment routes (internal control vs notified body) a high-risk system must pass before market entry.")** — internal control vs notified-body routes. - **[Art. 50 — Transparency & content marking](https://artificialintelligenceact.eu/article/50/ "EU AI Act Article 50 — transparency duties for certain AI systems: disclose AI interaction, mark synthetic content in a machine-readable format (Art. 50(2), fleshed out by Recital 133: watermarks, metadata, cryptographic provenance proofs, logging, fingerprints), label deep fakes. Applies since 2 Aug 2026; marking grace period for pre-existing systems until 2 Dec 2026.")** — AI-interaction disclosure, machine-readable marking of synthetic content (Rec. 133), deep-fake labelling. - **GPAI ([Art. 51 ff.](https://artificialintelligenceact.eu/article/51/ "EU AI Act Article 51 onwards — obligations for general-purpose AI models: documentation, copyright policy, training-data summary; systemic-risk models carry added duties."))** — model documentation, copyright policy, training-data summary; systemic-risk models carry added duties. - **[Council Decision (EU) 2026/1080 — CETS 225 implemented through the AI Act](https://eur-lex.europa.eu/eli/dec/2026/1080/oj/eng "Council Decision (EU) 2026/1080 of 21 April 2026 concluding the Council of Europe AI Convention on behalf of the EU — Art. 3: the Convention is implemented in the Union exclusively through Regulation (EU) 2024/1689 and other relevant Union acquis; the annexed declaration applies Chapters II–VI of the Convention to private actors via the AI Act.")** — why "CETS 225 compliance" in the EU means AI Act compliance; the Convention itself is on the [CETS 225 page](reference_coe_ai_convention.md). ## Guidance & codes of practice (soft law) Not legally binding, but the Commission-endorsed compliance path — in practice the documents clients work with first: - **[GPAI Code of Practice (July 2025)](https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai "The voluntary Code of Practice for general-purpose AI models (transparency, copyright, safety & security chapters) — signing it is the Commission-recognised way for GPAI providers to demonstrate Art. 53/55 compliance.")** — the voluntary route for GPAI providers to demonstrate Art. 53/55 compliance (transparency, copyright, safety & security chapters). - **[Guidelines on prohibited AI practices (Feb 2025)](https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act "Commission guidelines interpreting the Art. 5 prohibitions — manipulation, exploitation, social scoring, emotion recognition at work/school, untargeted facial scraping — with practical examples.")** — the Commission's interpretation of the Art. 5 bans, with practical examples. - **[Guidelines on the AI-system definition (Feb 2025)](https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application "Commission guidelines on the Art. 3(1) definition — which software falls inside or outside the Act's scope; the companion to the definition quoted above.")** — which software falls inside the Art. 3(1) definition quoted above. - **[Guidelines on transparency obligations — Art. 50 (July 2026)](https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems "Final Commission guidelines (2026-07-20) on Art. 50: scope, definitions, the four transparency duties and their exceptions — chatbot disclosure, machine-readable marking, emotion/biometric notice, deepfake and public-interest text disclosure.")** — the final reading of the four Art. 50 duties and their exceptions (published 2026-07-20). - **[Commission opinion on the Code of Practice on AI-generated content (July 2026)](https://digital-strategy.ec.europa.eu/en/library/commission-opinion-assessment-code-practice-transparency-ai-generated-content "Commission opinion (2026-07-09) assessing the voluntary Code of Practice on marking and labelling AI-generated content, incl. deepfakes — the practical route to Art. 50(2)/(4) compliance.")** — the Commission's assessment of the voluntary marking/labelling code (2026-07-09). - **[Draft guidelines on high-risk classification — Art. 6 (May 2026)](https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems "Draft Commission guidelines (2026-05-19) on classifying high-risk AI systems under Art. 6 and Annex III — intended purpose, safety components, the Art. 6(3) exceptions. Still a draft under targeted consultation; not final.")** — **draft**, under targeted consultation; do not cite as final. ## Penalties The Act's enforcement teeth — the national fine bands of [Art. 99](https://artificialintelligenceact.eu/article/99/ "EU AI Act Article 99 — administrative fines imposed by national authorities; Member States lay down the detailed penalty regimes."), applicable since 2 August 2025: | Violation | Maximum fine | | --------- | ------------ | | [Art. 5](https://artificialintelligenceact.eu/article/5/ "EU AI Act Article 5 — the prohibited practices; violating them draws the highest fine band.") prohibited practices | **€35 m or 7 %** of worldwide annual turnover (whichever is higher) | | Most other obligations — incl. [Art. 16](https://artificialintelligenceact.eu/article/16/ "EU AI Act Article 16 — provider obligations for high-risk systems."), [Art. 26](https://artificialintelligenceact.eu/article/26/ "EU AI Act Article 26 — deployer obligations for high-risk systems."), [Art. 50](https://artificialintelligenceact.eu/article/50/ "EU AI Act Article 50 — transparency and content-marking duties.") | **€15 m or 3 %** | | Incorrect, incomplete or misleading information to authorities | **€7.5 m or 1 %** | For SMEs and start-ups each cap is the **lower** of the two amounts. GPAI-model providers face separate **Commission** fines of up to **3 % of worldwide annual turnover or €15 m** ([Art. 101](https://artificialintelligenceact.eu/article/101/ "EU AI Act Article 101 — fines for providers of general-purpose AI models, imposed by the Commission rather than national authorities."), applicable since 2 August 2026). By construction, fines for the **deferred** high-risk obligations can only bite once those obligations themselves apply (December 2027 / August 2028 — see the timeline above). ## Audit-Relevant Anchors - **[Annex III](https://artificialintelligenceact.eu/annex/3/ "EU AI Act Annex III — the list of high-risk use cases (recruitment, credit, biometrics, critical infrastructure, etc.) that scopes most conformity work.")** — the high-risk use-case list that scopes most conformity work. - **[Art. 16](https://artificialintelligenceact.eu/article/16/ "EU AI Act Article 16 — the full set of provider obligations for high-risk AI.") + [Annex IV](https://artificialintelligenceact.eu/annex/4/ "EU AI Act Annex IV — the contents of the technical documentation a provider must compile and an auditor inspects.")** — the technical documentation an auditor inspects. - **[Art. 27 (FRIA)](https://artificialintelligenceact.eu/article/27/ "EU AI Act Article 27 — the Fundamental Rights Impact Assessment; directly relevant to the external-auditor engagement model.")** — directly relevant to the external-auditor engagement model. - **[Art. 43](https://artificialintelligenceact.eu/article/43/ "EU AI Act Article 43 — the conformity-assessment procedures for high-risk AI.") + Annex [VI](https://artificialintelligenceact.eu/annex/6/ "EU AI Act Annex VI — the internal-control conformity-assessment route.")/[VII](https://artificialintelligenceact.eu/annex/7/ "EU AI Act Annex VII — the notified-body conformity-assessment route based on QMS and technical-documentation assessment.")** — which conformity route applies, and the evidence each requires. - **[Art. 72](https://artificialintelligenceact.eu/article/72/ "EU AI Act Article 72 — post-market monitoring: providers must run a documented plan that collects and analyses performance data over the system's lifetime and feeds it back into the risk-management system.") + [Art. 73](https://artificialintelligenceact.eu/article/73/ "EU AI Act Article 73 — serious-incident reporting: providers report serious incidents to the market-surveillance authority, at the latest within 15 days of awareness (shorter for deaths and widespread infringements).")** — post-market monitoring plan and the serious-incident reporting clock; core operating evidence after go-live. - **Governance: [Art. 64](https://artificialintelligenceact.eu/article/64/ "EU AI Act Article 64 — the AI Office: the Commission's centre of AI expertise; enforces the GPAI rules and, per the Omnibus, holds exclusive competence and new enforcement powers over GPAI-based systems sharing a developer with the model.") (AI Office) + [Art. 65](https://artificialintelligenceact.eu/article/65/ "EU AI Act Article 65 — the European Artificial Intelligence Board: Member-State representatives coordinating the consistent application of the Act across the Union.") (AI Board) + [Art. 70](https://artificialintelligenceact.eu/article/70/ "EU AI Act Article 70 — each Member State designates national competent authorities (notifying authorities and market-surveillance authorities); the supervisor for deployed systems and the auditor's escalation path for findings.") (national authorities)** — who supervises what: AI Office for GPAI, national market surveillance for deployed systems; the escalation path for audit findings. - **Implementation timeline**{ title="Which EU AI Act obligations are actually in force at the engagement date — reshaped by the Digital Omnibus (Reg. (EU) 2026/1744, in force 27 July 2026): Annex III high-risk from 2 Dec 2027, Annex I products from 2 Aug 2028, Art. 50 transparency from 2 Aug 2026." } — see the [application timeline](#application-timeline-as-amended-by-the-omnibus) table above. - **[Enforcement live since 2 August 2026 — Commission release (2026-07-31)](https://digital-strategy.ec.europa.eu/en/news/commission-starts-enforcing-ai-act-rules-and-new-transparency-requirements-2-august "Commission press release of 31 July 2026: from 2 August 2026 the AI Office and national authorities enforce the AI Act; Art. 50 transparency duties apply (chatbot disclosure, deepfake labelling, machine-readable marking); a first list of more than 180 signatories of the Code of Practice on transparency of AI-generated content was published; the AI Act complaints tool, the whistleblower tool and a complaints channel for downstream providers of GPAI models are open.")** — the official marker that the regime is being enforced, and the signatory list against which a provider's claimed code adherence is checked. ## Auditor Checklist Evidence-oriented checks for a high-risk AI engagement under the Act: - [ ] The system is correctly classified (prohibited / high-risk per Art. 6 + Annex III / limited / minimal). - [ ] A risk-management system is documented and maintained (Art. 9). - [ ] Data governance — training/validation/test data quality and bias — is examined (Art. 10). - [ ] Technical documentation per Annex IV is present and current (Art. 11). - [ ] Logging/record-keeping (Art. 12) and human oversight (Art. 14) are implemented. - [ ] Accuracy, robustness, and cybersecurity are evidenced (Art. 15). - [ ] Deployer duties are evidenced: use per instructions, assigned competent human oversight, input-data control, operation monitoring, log retention (Art. 26). - [ ] A FRIA is performed where required (Art. 27). - [ ] The conformity-assessment route is chosen and evidenced (Art. 43); CE marking (Art. 48) and EU-database registration (Art. 49) done. - [ ] Synthetic output is marked in a machine-readable way — watermark, metadata, cryptographic provenance proof, logging or fingerprint (Art. 50(2) + Rec. 133); grace period for pre-Aug-2026 systems ends 2026-12-02. - [ ] A post-market monitoring plan exists and demonstrably feeds back into the risk-management system (Art. 72). - [ ] A serious-incident process covers detection, assessment and reporting within the Art. 73 deadlines (max. 15 days; shorter for severe cases). - [ ] For GPAI: model documentation, copyright policy, training-data summary (Art. 53+). - [ ] Which obligations are actually in force at the engagement date (Digital Omnibus timeline). ## Cross-Framework Mapping Indicative cross-references, **not** authoritative equivalences. Cells link to the **direct source** where readable (ISO clauses are paywalled, so only the ISO catalogue entry is public — see the [ISO/IEC 42001](reference_iso_42001.md) and [ISO/IEC 23894](reference_iso_23894.md) pages). | EU AI Act | NIST AI RMF | ISO/IEC 42001 | ISO/IEC 23894 | | --------- | ----------- | ------------- | ------------- | | [Art. 9](https://artificialintelligenceact.eu/article/9/) (risk management) | [MAP](https://airc.nist.gov/airmf-resources/playbook/map/) + [MANAGE](https://airc.nist.gov/airmf-resources/playbook/manage/) | Cl. 6.1 + Cl. 8 | Cl. 6 (risk process) | | [Art. 10](https://artificialintelligenceact.eu/article/10/) (data governance) | [MAP](https://airc.nist.gov/airmf-resources/playbook/map/) / [MEASURE](https://airc.nist.gov/airmf-resources/playbook/measure/) | Annex A (data controls) | Annex B (data risk sources) | | [Art. 11](https://artificialintelligenceact.eu/article/11/) + Annex IV (technical documentation) | [GOVERN](https://airc.nist.gov/airmf-resources/playbook/govern/) | Cl. 7.5 (documented information) | Cl. 6.7 (recording & reporting) | | [Art. 12](https://artificialintelligenceact.eu/article/12/) (record-keeping / logging) | [MEASURE](https://airc.nist.gov/airmf-resources/playbook/measure/) | Annex A (traceability controls) | Cl. 6.7 (recording & reporting) | | [Art. 14](https://artificialintelligenceact.eu/article/14/) (human oversight) | [MANAGE](https://airc.nist.gov/airmf-resources/playbook/manage/) | Annex A (oversight controls) | Annex B (human involvement) | | [Art. 15](https://artificialintelligenceact.eu/article/15/) (accuracy/robustness/cyber) | [MEASURE](https://airc.nist.gov/airmf-resources/playbook/measure/) | Cl. 8 + Annex A | Annex B (security & robustness) | | [Art. 17](https://artificialintelligenceact.eu/article/17/) (quality management system) | [GOVERN](https://airc.nist.gov/airmf-resources/playbook/govern/) | Cl. 4–10 (whole AIMS) | — (guidance, not an MS) | | [Art. 72](https://artificialintelligenceact.eu/article/72/) (post-market monitoring) | [MANAGE](https://airc.nist.gov/airmf-resources/playbook/manage/) | Cl. 9 (performance evaluation) | Cl. 6.6 (monitoring & review) | ## Recent Changes (rolling, last 5) | Date | Severity | What changed | | ---- | -------- | ------------ | | `2026-09-05` | substantive | **Commission soft law caught up with Art. 50, and enforcement started.** Final **Guidelines on transparency obligations for providers and deployers** published 2026-07-20; **Commission opinion assessing the Code of Practice on transparency of AI-generated content** published 2026-07-09; **draft Guidelines on the classification of high-risk AI systems** (Art. 6) published 2026-05-19 for targeted consultation — still a draft. Per the Commission release of 2026-07-31, from **2026-08-02** the AI Office and national authorities enforce the Act, a **first list of more than 180 signatories** of the AI-generated-content code is public, and the complaints tool, whistleblower tool and GPAI downstream-provider complaints channel are live; related: the **EU Action Plan on Cybersecurity and AI** (2026-07-07). Application timeline and penalties unchanged since the Omnibus entry. Council Decision (EU) 2026/1080 added as an anchor: the EU implements the CETS 225 Convention exclusively through this Act — see the new [CETS 225 page](reference_coe_ai_convention.md). | | `2026-08-02` | version_bump | **Digital Omnibus is now law.** Reg. (EU) 2026/1744 (adopted 2026-07-08, OJ 2026-07-24) **entered into force 2026-07-27**, amending Reg. 2024/1689: Annex III high-risk → **2027-12-02**; Annex I product-embedded AI → **2028-08-02**; Art. 50(2) marking grace period for pre-existing systems → 2026-12-02; new Art. 5 CSAM/NCII prohibition (transition to 2026-12-02); sandbox deadline → 2027-08-02. Art. 50 transparency itself applies from 2026-08-02 as scheduled; GPAI rules unchanged. | | `2026-06-16` | baseline | Initial baseline. Captured base regulation plus the **2026-05-07 Digital Omnibus provisional agreement** (high-risk deferral to 2027/2028, new Art. 5 prohibition) — pending OJ publication. | ## Sources - **Primary (web):** [EUR-Lex ELI permalink](https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng) · [EC policy hub](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai) · [AI Act Service Desk + Compliance Checker](https://ai-act-service-desk.ec.europa.eu/en) · [Article-by-article (FLI, curated)](https://artificialintelligenceact.eu/) - **Digital Omnibus (primary):** [EUR-Lex — Reg. (EU) 2026/1744 ELI permalink](https://eur-lex.europa.eu/eli/reg/2026/1744/oj) (Digital Omnibus on AI; OJ 2026-07-24, in force 2026-07-27) · [Consilium press release — final Council green light, 2026-06-29](https://www.consilium.europa.eu/en/press/press-releases/2026/06/29/artificial-intelligence-council-gives-final-green-light-to-simplify-and-streamline-rules/) - **Soft law (web):** [GPAI Code of Practice](https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai) · [Guidelines on prohibited practices](https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act) · [Guidelines on the AI-system definition](https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application) - **Digital Omnibus (analysis):** [Gibson Dunn analysis](https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/) · [Bird & Bird — May trilogue agreement](https://www.twobirds.com/en/insights/2026/digital-omnibus-on-ai-provisional-agreement-reached-at-the-may-trilogue) · [Lewis Silkin — entry into force, 2026-07-27](https://www.lewissilkin.com/insights/2026/07/27/the-digital-omnibus-on-ai-enters-into-force-today-102nedo) - **Update 2026-09-05:** [Art. 50 guidelines](https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems) · [Opinion on the AI-generated-content code](https://digital-strategy.ec.europa.eu/en/library/commission-opinion-assessment-code-practice-transparency-ai-generated-content) · [Draft high-risk classification guidelines](https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems) — retrieved 2026-09-05 from the EC policy hub. - **Council of Europe (web):** [EUR-Lex — Council Decision (EU) 2026/1080](https://eur-lex.europa.eu/eli/dec/2026/1080/oj/eng) · [EUR-Lex — CETS 225 text, OJ L 2026/1081](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ%3AL_202601081) — retrieved 2026-09-05; treaty status is maintained on the [CETS 225 page](reference_coe_ai_convention.md). - **Update 2026-09-05 (2):** [EC — Commission starts enforcing AI Act rules (2026-07-31)](https://digital-strategy.ec.europa.eu/en/news/commission-starts-enforcing-ai-act-rules-and-new-transparency-requirements-2-august) · [EC — press release IP/26/1714](https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1714) — retrieved 2026-09-05.