The risk-based approach of the EU AI Act
The EU AI Act does not regulate “AI” as one uniform technology. The intended purpose, the specific use and the role of each party determine the obligations. Certain practices are prohibited. Subject to the statutory conditions, these include harmful manipulative uses, certain forms of social scoring and particular biometric practices. High-risk systems are subject to extensive requirements covering risk management, data quality, technical documentation, logging, human oversight, accuracy, robustness and cybersecurity.
A system cannot be classified from its product name alone. The AI Act identifies fields including employment, education, access to essential private or public services, critical infrastructure and certain biometric uses. A writing assistant used for internal drafts may fall outside those categories, while the same foundation model used as part of an automated candidate-screening process may trigger a much stricter classification. Each use case therefore needs its own description and assessment.
The company's role matters just as much. A business using a third-party system in accordance with its intended purpose will normally be a deployer. A company that places a system on the market under its own name, changes its intended purpose or makes a substantial modification may become a provider. Deployer controls are then no longer sufficient. White-label products, deep integrations and independently configured decision logic should be reviewed carefully against that boundary.
At the editorial cut-off on 21 July 2026, the timetable has to be described in two layers: the law currently in force and the amendment already adopted by the EU legislature. The AI Act was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024. The general provisions, prohibited practices and Article 4 on AI literacy have applied since 2 February 2025. Governance rules and obligations for providers of general-purpose AI models have applied since 2 August 2025. Providers of such models placed on the market before that date generally have until 2 August 2027 to comply. Under the currently binding Article 113 AI Act, most remaining provisions, including the Article 50 transparency duties, apply from 2 August 2026. Under that version, the high-risk requirements for Annex III systems also start on that date, while Article 6(1) systems linked to regulated products in Annex I remain subject to the date of 2 August 2027.
The European Parliament and the Council have meanwhile adopted the Digital Omnibus on AI. The final text dated 8 July 2026 moves the high-risk requirements for Annex III systems to 2 December 2027 and those for product-related Annex I systems to 2 August 2028. It also gives providers of certain systems generating synthetic audio, image, video or text content that were already placed on the market before 2 August 2026 until 2 December 2026 to comply with Article 50(2). The amendment becomes legally binding only on the third day after publication in the Official Journal. As of 21 July 2026, it had not yet been published there and had no final regulation number. Until it enters into force, the existing Article 113 remains the operative legal basis, although businesses may already take the adopted timetable into account for planning purposes.
Transparency does not operate in the same way for every AI-assisted output. Article 50 covers, among other matters, certain interactive systems and artificially generated or manipulated content. The European Commission published final guidelines on 20 July 2026. Businesses should derive notices and labelling from the relevant channel and their legal role rather than applying one generic label to every piece of AI-assisted content.