Key Takeaways
Most EU AI Act content on the internet became outdated in a single week.
Here is the timeline. The European Commission proposed the “Digital Omnibus on AI” on November 19, 2025. The Council and European Parliament reached provisional agreement on May 7, 2026. Parliament adopted it on June 16, 2026 (423 votes in favour, 57 against, 174 abstentions). The Council gave its final green light on June 29, 2026. It was signed July 8, published in the Official Journal on July 24, 2026 as Regulation (EU) 2026/1744, and entered into force on July 27, 2026 — expedited because the AI Act’s general application date lands on August 2.
What the Omnibus changed:
What the Omnibus did not change:
the prohibitions in force since February 2, 2025;
the GPAI obligations in force since August 2, 2025;
the full Article 99 penalty regime; and — critically for anyone shipping product right now — all Article 50 transparency obligations, which still apply from August 2, 2026.
If your product has a chatbot, an AI copilot, AI-generated content, or any user-facing AI feature serving EU users, the deadline that matters is days away — not next year.
That is the context for this EU AI Act compliance checklist. The deferral bought high-risk providers a 16-month runway. It bought providers of everyday AI features almost nothing.
For most readers of this blog, yes — and earlier than you’d expect.
Under Article 2 of Regulation (EU) 2024/1689, the Act applies to: providers placing AI systems on the EU market or putting them into service in the EU, regardless of where the provider is established; deployers located in the EU; and — the clause that catches US startups — providers and deployers located in third countries where the output produced by the AI system is used in the EU.
No EU entity. No EU staff. No EU servers. If your customers, their users, or the output of your AI reach the EU, you are in scope.
Two practical consequences for US-based AI startups:
Nothing else on this EU AI Act compliance checklist works until you know which role you occupy — because providers and deployers carry very different obligations.
The practical test for a startup: if you build a product on top of a foundation model and serve EU users, you are a system provider. If you only use AI tools internally (ChatGPT, Copilot, Cursor), you are a deployer for those tools.
Three clarifications that resolve most confusion:
Write a one-page role-determination memo per AI system. It is the cheapest artifact on this list and the one that prevents the most expensive mistakes.
The Act is risk-tiered. Every system in your inventory lands in one of four tiers.
Prohibited (Article 5 — in force since February 2, 2025). Eight banned practices, including manipulative techniques causing significant harm, exploitation of vulnerabilities, social scoring, untargeted facial-image scraping, emotion recognition in workplaces and schools, and biometric categorisation inferring sensitive attributes. From December 2, 2026, two more join the list: AI generating non-consensual intimate imagery and AI-generated CSAM — with a safe-harbour for systems that implement effective preventive safeguards (refusal training, output filtering, abuse detection).
High-risk (Article 6 and Annex III). Eight use-case areas: biometrics; critical infrastructure; education and vocational training; employment and worker management; access to essential private and public services (including creditworthiness and life/health insurance pricing); law enforcement; migration and border control; administration of justice. Note the Article 6(3) derogation: an Annex III system is not high-risk if it only performs a narrow procedural task, improves the result of a completed human activity, detects decision patterns without replacing human assessment, or performs a preparatory task — but any system that profiles natural persons is always high-risk. If you claim the derogation, you must document the assessment before market placement and still register the system.
Limited risk (Article 50 — live August 2, 2026). Transparency obligations for chatbots, generative systems, emotion recognition, and deepfakes. This is the tier most AI startups actually sit in — and the one with the imminent deadline.
Minimal risk. Everything else. Voluntary codes of conduct.
This is the operational core. Each step names the obligation, the article, and the deadline status as of this week. Work them in order.
Step 1 — Build your AI system inventory (do now)
Every AI system you provide or deploy: in-product features, internal tools, fine-tuned models, agents, shadow AI. Capture purpose, owner, model in use, data flows, whether output reaches the EU, and a preliminary risk tier. A Cloud Security Alliance research note (March 2026) found more than half of organisations lack a systematic AI inventory — which makes this the most common failing step and the reason everything downstream stalls.
Step 2 — Write a role-determination memo (do now)
One page per system: provider or deployer, with reasoning. Flag any fine-tuned models (you are likely the provider of those) and any Article 25 triggers (substantial modification, white-labelling, repurposing).
Step 3 — Screen every system against Article 5 prohibitions (live now)
The prohibitions have been enforceable since February 2, 2025, and carry the top penalty tier. For generative products, plan now for the December 2, 2026 additions: if your system could foreseeably be misused to generate intimate imagery of identifiable people, the safe-harbour depends on documented preventive safeguards.
Step 4 — Document your AI-literacy measures (live now)
Article 4 has applied since February 2, 2025. The Omnibus softened it — you must take measures to support AI literacy for staff operating AI systems, without guaranteeing any specific level. A short training log and an onboarding module satisfy the spirit; document both.
Step 5 — Risk-classify each system (do now)
Run every inventoried system through Annex III and the Article 6(3) filter. Document the classification — including any derogation claim — before market placement. This single artifact answers the most common EU AI Act question in enterprise security reviews.
Step 6 — Implement Article 50 transparency disclosures (deadline: August 2, 2026)
The imminent one. If your product includes a chatbot or AI interaction, users must be informed they are interacting with AI at first contact, unless it is obvious. Deployers of deepfake content must disclose artificial origin. Per Article 50, this is product and UX work — not paperwork — and it applies from August 2, 2026. Data from artificialintelligenceact.eu’s Compliance Checker suggests transparency obligations are the second most common trigger across assessed organisations, affecting roughly a third of respondents.
Step 7 — Plan machine-readable marking of synthetic content (deadline: December 2, 2026 for pre-existing systems)
Generative systems placed on the market before August 2, 2026 have until December 2, 2026 to implement Article 50(2) machine-readable marking of AI-generated audio, image, video, and text — a grace period the Omnibus shortened, not extended. Systems entering the market from August 2, 2026 must comply immediately. The Commission adopted 51 pages of Article 50 guidelines on July 20, 2026; a Code of Practice on transparent AI is in the endorsement pipeline.
Step 8 — Use the runway to build high-risk documentation (deadline: December 2, 2027 for Annex III)
If any of your systems classified high-risk in Step 5, the deferral is your build window, not a reprieve. The provider obligations are substantial: a lifecycle risk management system (Article 9), data governance (Article 10), technical documentation per Annex IV (Article 11 — SMEs may use a simplified form), automatic logging (Article 12), instructions for deployers (Article 13), human oversight by design (Article 14), accuracy, robustness and cybersecurity (Article 15), and a quality management system proportionate to your size (Article 17). Most Annex III categories use internal-control conformity assessment — self-assessment without a notified body — followed by the EU declaration of conformity, CE marking, and registration in the EU database. Sixteen months is enough time to do this well. It is not enough time to start in October 2027.
Step 9 — Determine whether you need a Fundamental Rights Impact Assessment (before first use, where applicable)
Article 27 FRIAs apply to a narrower group than most checklists imply: public bodies deploying Annex III systems, private entities providing public services with those systems, and any deployer using high-risk AI for creditworthiness scoring or life/health insurance pricing. Most product startups are not in these categories. Don’t over-engineer — but if you sell into credit or insurance decisioning, this lands on you as the deployer’s obligation your customers will push into contracts.
Step 10 — Appoint an EU authorised representative if you are a non-EU high-risk provider (before market placement)
Article 22 requires non-EU providers of high-risk systems to mandate an EU-established authorised representative in writing before placing the system on the EU market. Budget for this in your Step 8 runway.
Key Deadlines: What Is Live Now vs. Deferred
| Date | What applies | Status |
|---|---|---|
| Feb 2, 2025 | Article 5 prohibitions; Article 4 AI literacy | Live |
| Aug 2, 2025 | GPAI obligations (Articles 51–55); penalty framework | Live |
| Aug 2, 2026 | General application; all Article 50 transparency obligations | Days away |
| Dec 2, 2026 | Machine-readable marking for pre-existing generative systems; new NCII and AI-CSAM prohibitions | Fixed |
| Dec 2, 2027 | Standalone high-risk (Annex III) obligations | Deferred by Omnibus |
| Aug 2, 2028 | Embedded high-risk (Annex I) obligations | Deferred by Omnibus |
| Aug 2, 2030 | High-risk systems used by public authorities | Unchanged |
Two enforcement realities worth knowing: no fines under the AI Act have been publicly reported anywhere in the EU as of this writing, and national authority designations remain incomplete — one enforcement tracker counted 11 of 27 Member States having formally designated and notified their authorities as of March 2026. Do not mistake a slow start for a soft law. GDPR enforcement looked the same in year one.
The headline numbers under Article 99: up to €35M or 7% of total worldwide annual turnover (whichever is higher) for prohibited practices; up to €15M or 3% for most other violations, including Article 50 transparency and high-risk obligations; up to €7.5M or 1% for supplying incorrect information to authorities.
The under-reported clause: Article 99(6) inverts the rule for SMEs and startups — the fine is the lower of the fixed sum or the percentage. A startup with €2M in annual turnover faces a maximum top-tier fine of €140,000, not €35M. That is a real statutory cap, and it changes the risk calculus from “existential” to “seriously painful but survivable.”
The honest framing for founders: the regulatory fine is rarely the largest cost. The larger cost is the enterprise deal that stalls because your security review answer to “how do you comply with the EU AI Act?” was a shrug. The World Economic Forum’s Global Cybersecurity Outlook 2026 found the share of organisations assessing AI tool security before deployment nearly doubled from 37% to 64% in a single year. IBM’s Cost of a Data Breach Report 2025 found that 97% of organisations that suffered AI-related breaches lacked proper AI access controls, and shadow-AI breaches ran about $670K above the global average. Your buyers have read the same reports. The EU AI Act compliance checklist above is what turns their questions into a two-day review instead of a six-week one.
Ten steps is a program. This week is three actions: build the inventory (Step 1), write the role memos (Step 2), and get your Article 50 disclosures into the product before August 2 (Step 6).
If you want a faster baseline: the free 10-minute Security Readiness Assessment at knowledge.secureflo.net maps your current posture against the EU AI Act alongside ISO 42001, NIST AI RMF, SOC 2, HIPAA, GDPR, and DPDP — and produces a readiness score, a prioritized gap list, and a board-ready PDF. It is, in effect, Steps 1 and 5 of this checklist done in one sitting, plus the artifact you hand your board when they ask what the Omnibus changed.
The startups that treat this week’s deadline as the starting gun — and the December 2027 runway as a build window rather than a snooze button — will walk into 2027 enterprise reviews with documentation their competitors are still scrambling to draft.
Q: What is an EU AI Act compliance checklist? A: An EU AI Act compliance checklist is a sequenced set of actions an organisation takes to meet Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744. For startups it typically covers ten steps: AI inventory, role determination, prohibited-practice screening, AI-literacy measures, risk classification, Article 50 transparency disclosures, synthetic-content marking, high-risk documentation, FRIA applicability, and appointment of an EU authorised representative where required.
Q: Does the EU AI Act apply to US companies? A: Yes, in many cases. Article 2 applies the Act to providers placing AI systems on the EU market regardless of establishment, and to providers and deployers in third countries where the AI system’s output is used in the EU. A US startup with EU users — or whose enterprise customers use its output in the EU — is in scope. Non-EU providers of high-risk systems must also appoint an EU authorised representative under Article 22.
Q: What changed with the Digital Omnibus in July 2026? A: Regulation (EU) 2026/1744, published July 24, 2026 and in force July 27, 2026, deferred standalone high-risk (Annex III) obligations from August 2, 2026 to December 2, 2027 and embedded high-risk (Annex I) obligations to August 2, 2028. It added prohibitions on AI-generated non-consensual intimate imagery and AI-generated CSAM (applicable December 2, 2026), shortened the synthetic-content marking grace period to December 2, 2026, and softened the AI-literacy obligation. It did not defer Article 50 transparency obligations, GPAI obligations, existing prohibitions, or penalties.
Q: When do EU AI Act requirements take effect? A: In phases. Prohibitions and AI literacy: February 2, 2025. GPAI obligations and penalties: August 2, 2025. General application and Article 50 transparency: August 2, 2026. New NCII/CSAM prohibitions and marking deadline for pre-existing generative systems: December 2, 2026. Standalone high-risk obligations: December 2, 2027. Embedded high-risk: August 2, 2028.
Q: What are the EU AI Act penalties? A: Up to €35M or 7% of worldwide annual turnover for prohibited practices; up to €15M or 3% for most other violations including transparency and high-risk obligations; up to €7.5M or 1% for supplying incorrect information. For SMEs and startups, Article 99(6) caps the fine at the lower of the fixed amount or the percentage.
Q: Am I a provider or a deployer under the EU AI Act? A: You are a provider if you develop an AI system (or have one developed) and place it on the market under your own name — including building a product on a foundation model and serving EU users. You are a deployer if you use an AI system under your own authority, such as internal AI tools. A deployer becomes a provider by substantially modifying a system, white-labelling it, or repurposing it into a high-risk use (Article 25).
Q: Does calling the OpenAI or Anthropic API make me a GPAI provider? A: No. Integrating a third-party model via API — including with RAG or custom prompts — makes you a downstream system provider or deployer, not a general-purpose AI model provider under Articles 51–55. Fine-tuning a foundation model, however, generally makes you the provider of the resulting model.
The Omnibus reset the high-risk clock — but Article 50 is live in days, and your enterprise buyers are already asking.
Knowledge by SecureFlo (knowledge.secureflo.net) is a free, 10-minute Security Readiness Assessment built for AI-native startups. It maps your posture against the EU AI Act, ISO 42001, NIST AI RMF, SOC 2, HIPAA, GDPR, and DPDP — and produces a readiness score, a prioritized gap list, and a board-ready PDF report.
No demo gate. No sales call required. The report is the value.
→ Run your Security Readiness Assessment: knowledge.secureflo.net
Free assessment from Secureflo. Calibrated to your industry, country, and stack. Get immediate visibility into your institutional grade reliability.