EU AI Act tracker
Which obligations of Regulation (EU) 2024/1689 apply to providers, deployers, and general-purpose AI model providers, from when — every claim linked to the official text. Each tracked tool's page maps its own risk tier to this reference.
Not legal advice. This page is source-backed information to orient a compliance review. Obligations depend on how your organisation develops or deploys a system; confirm against the official text and your counsel.
Canonical starting point at the source: the European Commission's AI regulatory framework overview (opens in a new tab).
Where the law stands as of 23 Aug 2026
Legislative status sourceAs of 23 August 2026: the Digital Omnibus on AI is in force as Regulation (EU) 2026/1744. The prohibitions on unacceptable-risk AI practices and AI-literacy duty have applied since 2 February 2025, GPAI provider obligations since 2 August 2025, and the AI Act's general application date was 2 August 2026. The amendment fixed later dates for high-risk requirements: 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for systems embedded in Annex I regulated products.
Application timeline
Subscribe to deadlines (.ics)- Prohibited AI practices and AI literacy
In force. Bans on unacceptable-risk practices (Article 5) and deployer AI-literacy duties (Article 4) apply.
Source - Governance rules and general-purpose AI model obligations
In force. GPAI model transparency obligations and the AI Act governance bodies apply; Commission enforcement powers over GPAI providers begin 2 August 2026.
Source - General application of the AI Act
The AI Act's general application date. Regulation (EU) 2026/1744 moved Sections 1–3 of the high-risk chapter to fixed later dates while other obligations due on this date continue to apply.
Source - Stand-alone Annex III high-risk AI systems
Regulation (EU) 2026/1744 fixes this application date for Sections 1–3 of the high-risk chapter as they apply to stand-alone Annex III high-risk systems.
Source - High-risk AI systems embedded in regulated products
Regulation (EU) 2026/1744 fixes this application date for Sections 1–3 of the high-risk chapter as they apply to Annex I product-embedded systems.
Source
Providers of AI systems
Organisations that develop an AI system and place it on the EU market or put it into service under their own name.
Providers and deployers must take measures to ensure a sufficient level of AI literacy in staff and other persons operating AI systems on their behalf.
Applies from
Official textPlacing on the market, putting into service, or using AI systems for the unacceptable-risk practices listed in Article 5 (e.g. social scoring, exploitative manipulation, untargeted facial-image scraping) is banned outright.
Applies from
Official textProviders of high-risk AI systems must implement a risk-management system, data governance, technical documentation, automatic event logging, transparency to deployers, human oversight, and appropriate accuracy, robustness, and cybersecurity. These requirements apply from 2 December 2027 to stand-alone Annex III systems and from 2 August 2028 to systems embedded in Annex I regulated products.
Applies from
Official textHigh-risk AI systems must pass the applicable conformity-assessment procedure, carry CE marking, and be registered in the EU database before being placed on the market or put into service. The obligations apply from 2 December 2027 to stand-alone Annex III systems and from 2 August 2028 to systems embedded in Annex I regulated products.
Applies from
Official textPeople must be informed when they interact with an AI system; synthetic audio, image, video, and text content must be marked as artificially generated, and deepfakes disclosed.
Applies from
Official textProviders of high-risk AI systems must operate a post-market monitoring system and report serious incidents to market-surveillance authorities within the deadlines set by Article 73.
Applies from
Official textFor AI systems outside the high-risk tier, the Act encourages voluntary codes of conduct that apply some high-risk requirements proportionately — no mandatory obligations attach to minimal-risk systems beyond AI literacy. (voluntary)
Applies from
Official textDeployers of AI systems
Organisations using an AI system under their authority in the EU — the role most enterprise buyers of the tools tracked here hold.
Providers and deployers must take measures to ensure a sufficient level of AI literacy in staff and other persons operating AI systems on their behalf.
Applies from
Official textPlacing on the market, putting into service, or using AI systems for the unacceptable-risk practices listed in Article 5 (e.g. social scoring, exploitative manipulation, untargeted facial-image scraping) is banned outright.
Applies from
Official textDeployers of high-risk AI systems must use them per the provider's instructions, assign competent human oversight, ensure relevant and representative input data where they control it, monitor operation, retain automatically generated logs, and report serious incidents. These duties apply from 2 December 2027 to stand-alone Annex III systems and from 2 August 2028 to systems embedded in Annex I regulated products.
Applies from
Official textBodies governed by public law, private entities providing public services, and deployers of certain Annex III systems must assess the impact on fundamental rights before first use of a high-risk AI system.
Applies from
Official textPeople must be informed when they interact with an AI system; synthetic audio, image, video, and text content must be marked as artificially generated, and deepfakes disclosed.
Applies from
Official textFor AI systems outside the high-risk tier, the Act encourages voluntary codes of conduct that apply some high-risk requirements proportionately — no mandatory obligations attach to minimal-risk systems beyond AI literacy. (voluntary)
Applies from
Official textGeneral-purpose AI model providers
Providers of general-purpose AI models (foundation models), regardless of how the model reaches the market.
Providers of general-purpose AI models must maintain technical documentation, supply information to downstream providers, put in place a copyright-compliance policy, and publish a summary of training content. Commission enforcement powers begin 2 August 2026.
Applies from
Official textProviders of general-purpose AI models classified as posing systemic risk must additionally perform model evaluations, assess and mitigate systemic risks, report serious incidents, and ensure adequate cybersecurity protection.
Applies from
Official textHow tracked tools map to this
Every tool record carries a source-backed EU AI Act risk tier in its governance posture. The tool's page shows the obligations implicated by that tier. Start from a category hub — agents, orchestration, governance, or assistants — or use the guided evaluation, which already asks for your EU AI Act role.