The EU AI Act: which obligations apply right now, and to whom?
As at 25 August 2026. Reflects Regulation (EU) 2024/1689 as amended by the Digital Omnibus Regulation (EU) 2026/1744 of 8 July 2026, and the German AI Market Surveillance and Innovation Promotion Act (KI-MIG), in force since 29 July 2026.
The EU AI Act (Regulation (EU) 2024/1689) does not impose one uniform set of obligations on every organisation. Which requirements become relevant depends above all on the organisation's role, the risk class of the AI system, the specific context of use and, in part, on whether transparency obligations or high-risk rules are engaged.
For AI officers, compliance leads and data protection and governance teams in particular, this creates the challenge of inventorying AI applications in a structured way and classifying them cleanly.
1. The central question first: what role does your organisation have?
The AI Act distinguishes several roles along the AI value chain, and the obligations differ considerably between them.
Provider
Put simply, a provider is whoever develops an AI system or places it on the market under their own name. This can also cover integration, a change of intended purpose or central provision. Typical provider obligations: risk management, technical documentation, data and governance requirements, transparency obligations, conformity assessment and CE marking for high-risk systems.
Deployer
Under Article 3(4), a deployer is whoever uses an AI system under its own authority, which covers universities, companies, public authorities and research institutions. Possible deployer obligations: appropriate use, oversight and governance, documentation, human oversight, informing affected persons and data protection assessments.
The common rule of thumb that public institutions are “deployers by default” only holds for systems bought in. Article 3(3) also treats as a provider anyone who develops an AI system, or has it developed, and puts it into service under its own name for its own use — no market and no external supply is required. An institution that builds in its own data centre is therefore regularly both. A prompt template or a simple configuration is not enough for this; what matters is the overall picture: an intended purpose of its own, its own data basis, its own decisions on updates and rollout.
Importer and distributor
Further roles with specific responsibilities along the supply chain. They too must verify conformity and retain documentation.
2. The risk logic of the AI Act
The AI Act takes a risk-based approach, with four levels to distinguish:
- Prohibited AI practices (Article 5): Certain AI practices are prohibited outright, such as social scoring systems or real-time remote biometric identification in uncontrolled environments
- High-risk AI (Annexes I and III): Strict regulatory requirements including conformity assessment and CE marking
- Transparency obligations (Article 50): Specific information duties for generative AI and other systems
- Minimal risk: In principle no specific AI Act obligations
3. High-risk AI systems: Annex I and Annex III
The two annexes cover different cases. Annex I lists legislation for products in which AI is embedded as a safety component — machinery, medical devices or lifts, for example. Annex III lists standalone areas of use, including critical infrastructure, biometrics, employment and education.
For education, Annex III point 3 names four cases: admission and assignment to educational institutions, evaluating learning outcomes, assessing the appropriate level of education, and monitoring prohibited behaviour during examinations.
For these systems the following apply in particular: technical documentation, data quality management, logging, transparency towards users, human oversight and conformity assessment. These requirements do not yet apply, however — the Digital Omnibus postponed them to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). For high-risk systems intended to be used by public authorities and already in use before 2 August 2026, the amended Article 111(2) even sets a deadline of 2 August 2030. State universities are institutions of their federal state.
4. Transparency obligations (Article 50)
The transparency obligations in Article 50 have applied since 2 August 2026. Unlike the high-risk requirements they were not postponed, and they do not depend on how risky a system is classified to be.
The paragraphs address different parties. Article 50(1) binds providers: systems intended to interact directly with people must be designed and developed so that those people are told they are dealing with an AI system. The exception applies only where this is obvious anyway — read narrowly on the prevailing view. Article 50(2) likewise binds providers and requires machine-readable marking of synthetic audio, image, video and text content. Article 50(4), by contrast, addresses deployers and covers deep fakes as well as published text on matters of public interest generated without human review.
The much-quoted deadline of 2 December 2026 is not a general grace period. Article 111(4), inserted by the Digital Omnibus, gives providers of generative systems placed on the market before 2 August 2026 four months to retrofit the machine-readable marking under paragraph 2 alone. The disclosure duty under paragraph 1 is unaffected.
5. AI literacy and governance
Since 2 February 2025, AI literacy (Article 4) has been a mandatory building block of governance. Providers and deployers take measures so that their staff and other persons dealing with AI systems on their behalf have a sufficient level of AI literacy.
The Digital Omnibus recast Article 4 and softened it: the obligation does not require providers or deployers to guarantee any particular level of AI literacy for any given person. The duty remains, but it does not call for evidence of a certified level.
6. Timeline and the Digital Omnibus
The Digital Omnibus is complete: Regulation (EU) 2026/1744 of 8 July 2026 was published in the Official Journal of 24 July 2026. The timeline is therefore settled.
- since 2 February 2025: Prohibited practices (Article 5) and AI literacy (Article 4)
- since 2 August 2025: Obligations for general-purpose AI models
- since 2 August 2026: General application (Article 113), transparency obligations (Article 50), enforcement through market surveillance
- 2 December 2026: Four-month transition for machine-readable marking under Article 50(2) for legacy systems (Article 111(4)); plus two new prohibitions in Article 5
- 2 December 2027: High-risk requirements under Annex III
- 2 August 2028: High-risk requirements under Annex I
- 2 August 2030: Special deadline for legacy high-risk systems intended to be used by public authorities (Article 111(2))
In Germany, enforcement is governed by the KI-MIG. Since 29 July 2026 the Federal Network Agency (Bundesnetzagentur) has been the central market surveillance authority and central complaints body; sector-specific responsibilities remain alongside it. Where state authorities use AI systems, the federal states may designate their own bodies — so for state universities, supervision is not uniform across Germany.
7. Practical consequences for AI officers
The biggest challenge is not documenting individual systems but steering the whole picture in a structured way:
- AI inventory: Systematically recording every AI system in the organisation
- Role clarification: Who is a provider, who is a deployer? Often both within the same organisation
- Risk classification: Structured classification by annex and risk class
- Documentation and governance: Documentation obligations and audit readiness
- Transparency processes: How do we inform users, affected persons and authorities?
- Evidence: Audit trails, decision records, proof of conformity
Conclusion
The AI Act does not require a blanket „AI approval“. What matters is structured classification: What role does the organisation have? Which risk class applies? Which transparency or governance obligations are relevant? Which documentation should be prepared?
For AI officers this means that now is the moment to build solid governance, inventory and documentation structures. The 2026 to 2028 deadlines are approaching, and the first step is a structured overview of every AI system in the organisation and its risk class.
Please note: As at 25 August 2026. This article is for general information only and does not constitute legal advice. For a binding legal assessment of your particular case, please consult your legal department or a qualified lawyer. Sources: Regulation (EU) 2024/1689 (Articles 3, 4, 5, 50, 111, 113, Annexes I and III); Regulation (EU) 2026/1744 of 8 July 2026, OJ L of 24 July 2026; KI-MIG, Article 1 of the Act of 22 July 2026, Federal Law Gazette 2026 I No. 233.
Questions about the EU AI Act?
Talk your requirements through with us and we will show you how UNAIT can help.