The EU AI Act creates a phased compliance timeline for organizations that deploy AI systems in the European Union. Deployers of high-risk systems face the most pressing obligations, while general-purpose AI and limited-risk systems follow their own schedules.
Who counts as a deployer
A deployer is any natural or legal person using an AI system under their authority. If your organization integrates an AI tool into products, services, or internal processes used in the EU, the Act likely applies to you.
Key deadlines and obligations
- Prohibited AI practices: Banned from the Act’s entry into force.
- General-purpose AI models: Transparency and systemic-risk obligations apply within 12 months for the largest models.
- High-risk AI systems: Requirements around risk management, data governance, technical documentation, human oversight, and registration apply before systems are placed on the market or put into service.
- Limited-risk AI systems: Transparency obligations, such as disclosure that users are interacting with AI, apply before deployment.
What deployers should do now
- Inventory AI systems and classify risk under Annex III.
- Review procurement and vendor contracts for compliance allocations.
- Establish human oversight, incident reporting, and record-keeping processes.
- Build a readiness roadmap with legal, IT, and business stakeholders.
Key takeaways
- Risk classification determines your timeline and obligations.
- High-risk deployers need documentation, oversight, and monitoring processes in place before deployment.
- Start with an inventory and gap analysis; the timeline is shorter than it appears.
Published on August 10, 2026. This article is for informational purposes and does not constitute legal advice.