Insights – EU AI Act

What your board needs to know about the EU AI Act

What is already in force, what changed in August 2026, what remains for December 2027, and how the Product Liability Directive changes the picture again.

Feb 2025 Prohibitions & AI literacy – already in force
Aug 2025 GPAI rules & governance – already in force
Aug 2026 Transparency & labelling rules – now in force
Dec 2027 High-risk (Annex III) obligations – deferred to here
Fundamentals
What is the EU AI Act, and does it apply to my organisation?

The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive AI-specific regulation. It entered into force on 1 August 2024 and applies in phases rather than all at once.

Its reach extends well beyond companies headquartered in the EU: it applies to any provider placing an AI system on the EU market, any deployer using an AI system within the EU, and – under its extraterritorial reach – to providers and deployers outside the EU where the system's output is used within the EU. For a UK board, this means the Act is relevant the moment your organisation sells into, or deploys AI touching, the EU market, regardless of where you are headquartered.

Already live
What EU AI Act rules are already in force?

Two tranches are already live. From 2 February 2025, the Act's prohibitions on unacceptable-risk AI practices took effect – including social scoring, certain forms of biometric categorisation, and manipulative or exploitative AI systems – alongside a general obligation on providers and deployers to ensure staff have a sufficient level of AI literacy.

Feb 2025 Prohibitions & AI literacy duty
Aug 2025 GPAI rules & governance bodies
Immediate For new GPAI models placed on market since

From 2 August 2025, the rules for general-purpose AI (GPAI) models became applicable, including the additional regime for GPAI models presenting systemic risk, and Member States were required to have their governance structures, penalty regimes, and competent authorities in place. Any GPAI model placed on the market after that date must comply immediately.

August 2026
What changed under the EU AI Act on 2 August 2026?

2 August 2026 was the headline date in the Act's original text, and most of the remaining provisions did become applicable on schedule – principally the Article 50 transparency obligations, including labelling of AI-generated or manipulated content, and disclosure requirements where a person is interacting with an AI system rather than a human.

However, a targeted amendment package agreed in the first half of 2026 pushed back several of the higher-stakes obligations that were originally due on this date, in response to concerns that the underlying technical standards were not yet ready. The practical effect is that 2 August 2026 was a real deadline, but a narrower one than originally drafted – transparency and labelling rules landed, while the heaviest high-risk system obligations did not.

The delay
Why were some high-risk AI obligations postponed, and to when?

The 2026 amendment package deferred obligations for high-risk AI systems under Annex III – the use-based category, covering areas such as employment, credit scoring, and law enforcement – from 2 August 2026 to 2 December 2027, a sixteen-month delay. High-risk systems under Annex I, which are already regulated as components of other products such as medical devices, lifts, or radio equipment, were also deferred, on a similar timeline.

The obligation on Member States to stand up at least one national AI regulatory sandbox moved from 2 August 2026 to 2 August 2027. Separately, the transparency obligation to mark AI-generated synthetic content in a machine-readable format was deferred by four months, from 2 August 2026 to 2 December 2026, but only for systems already on the market before August 2026 – anything placed on the market after that date must comply immediately, with no grace period.

"The delayed timeframes reflect the challenges with operationalizing several provisions of the AI Act, particularly for high-risk systems requiring testing, documentation, and third-party assessment."

On the 2026 amendment package

The stated reason across all of these deferrals is the same: the European standards bodies responsible for the underlying technical conformity standards were not ready in time, and the delay is intended to close that gap rather than to weaken the obligations themselves.

December 2027
What EU AI Act obligations land in December 2027?

2 December 2027 is now the effective date for the Annex III high-risk AI obligations – the use-based category most likely to touch a typical mid-market organisation, covering systems used in recruitment, employee monitoring, creditworthiness assessment, and similar decisions with material consequences for individuals.

Providers and deployers of these systems will need conformity assessments, technical documentation, human oversight arrangements, and post-market monitoring in place by this date. For most boards, this is the deadline that actually matters more than the August 2026 date that dominated earlier headlines, because it is where the bulk of the compliance burden for ordinary commercial AI use now sits.

August 2027
What else remains outstanding for August 2027?

2 August 2027 carries several distinct deadlines. Providers of GPAI models that were already on the market before 2 August 2025 have until this date to bring themselves into full compliance, since the original rules only applied immediately to new models. Article 6(1), which sets out part of the classification methodology for determining whether an AI system is high-risk, also becomes applicable from this date – later than the rest of the Act's core provisions.

High-risk AI systems that are components of the large-scale EU IT systems listed in Annex X – large government and border-management databases – must be brought into compliance by this date if they were placed into service before it. And the national AI regulatory sandbox obligation, deferred from 2026, falls due here too.

Risk classification
What is a high-risk AI system, and does my organisation have one?

The Act defines high-risk AI by reference to two annexes rather than a single test. Annex I covers AI that is a safety component of, or is itself, a product already regulated under existing EU product-safety law – medical devices, machinery, lifts, and similar. Annex III covers AI used in eight specific use-based domains regardless of the underlying product, including recruitment and employment decisions, access to essential services such as credit, biometric identification, and law enforcement.

Most mid-market organisations that encounter the high-risk category do so through Annex III rather than Annex I – typically an HR platform used for CV screening, a credit-scoring tool, or an AI system making decisions that materially affect an individual's access to a service. A useful early question for the board is simply whether any deployed or planned AI system falls into one of those eight Annex III domains, since that determines whether the December 2027 obligations apply at all.

Board action
What should the board be doing now, ahead of these deadlines?

Three things are worth board-level attention now rather than closer to the deadlines. First, an inventory. Most organisations do not have a complete list of where AI is actually deployed, particularly where it has been adopted inside a third-party platform rather than built in-house, and that inventory is the precondition for everything else.

Second, a classification exercise against Annex I and Annex III, so the board knows which systems, if any, will need conformity assessment and documentation by December 2027 – this is a matter of months of lead time, not weeks.

Third, given the AI Act works alongside other instruments rather than in isolation – GDPR, the Product Liability Directive, and sector-specific regulation – the governance response is usually stronger when framed as a single AI governance programme rather than a series of separate compliance projects run by different teams.

Footnote – a related but separate instrument
Product Liability Directive
How does the new Product Liability Directive interact with the AI Act?

The revised Product Liability Directive (EU) 2024/2853 is a separate instrument from the AI Act, running on its own calendar, and boards are well advised not to conflate the two. It entered into force in December 2024 and must be transposed into national law by Member States by 9 December 2026, applying to products placed on the market or put into service after that date.

9 Dec 2026 Transposition deadline & application date
Strict No-fault liability regime
Software Now explicitly classed as a "product"

Its significance for AI is that it explicitly reclassifies software – including AI systems and digital manufacturing files – as a "product" for the purposes of no-fault, strict liability, and it shifts the burden of proof in favour of an injured party where the system in question is technically complex or operates as a "black box".

Where the AI Act is a regulatory compliance regime enforced by public authorities, the Product Liability Directive is a civil liability regime enforced through the courts – together they create what some practitioners are calling a "double exposure": regulatory obligations from 2 August 2026 under the AI Act, and civil liability exposure from 9 December 2026 under the Directive, for essentially the same underlying AI systems.

This page summarises publicly available regulatory timelines as of September 2026. It is not legal advice, the EU AI Act timeline has already shifted once, and it may shift again – verify against current guidance or your own counsel before relying on any date here for a compliance decision.