EU AI Act update: Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. Check the consolidated AI Act and route-specific application dates before relying on older timelines. Consolidated AI Act EU AI Act update: Regulation (EU) 2026/1744 is in force; check route-specific application dates. Consolidated AI Act
Deployer Readiness Tracker

EU AI Act Application-Date Tracker After Regulation (EU) 2026/1744

The current consolidated AI Act should be treated as a route-specific evidence buildout programme. Deployers should classify AI systems, map Article 26 duties, check Article 50 transparency triggers, and retain the records that show who reviewed, approved, monitored, and escalated each deployed AI system.

Published: 2026-04-30 Last updated: 2026-09-02 Source basis checked against official sources Author: Abhishek G Sharma
EU AI Act deployer evidence map showing inventory, classification, vendor evidence, human oversight, Article 50, logs and incident routes
A deployer readiness view for AI inventory, Article 26 evidence, Article 50 disclosure, and Annex III triage.

Quick answer

Deployers should use the current consolidated AI Act to complete four practical jobs: classify deployed AI systems, confirm whether Article 26 duties apply, check Article 50 transparency triggers, and retain evidence. Do not wait for guidance to start the AI inventory, oversight log, vendor file, disclosure register, and decision record.

The August 2026 failure mode will not be “we had no policy.” It will be “we cannot open the file for one real AI system and show who owned, reviewed, monitored, and escalated it.”

Current Digital Omnibus status, reviewed 2 September 2026

Regulation (EU) 2026/1744 is published and in force. EU AI Compass separates duties already applicable from the statutory Article 6(2)/Annex III date of 2 December 2027 and Article 6(1)/Annex I date of 2 August 2028.

Regulatory update

Regulation (EU) 2026/1744 is in force. Apply the amended route-specific dates.

Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It moves Article 6(2) / Annex III high-risk obligations to 2 December 2027 and Article 6(1) / Annex I product-integrated high-risk rules to 2 August 2028. Article 50 transparency, AI literacy, prohibited-practice and other duties retain route-specific dates. Continue inventory, role classification, vendor evidence, Article 50 trigger review and evidence-file preparation.

What changes for deployers on 2 August 2026?

Under Article 113, Regulation (EU) 2024/1689 generally applies from 2 August 2026. Chapters I and II have applied from 2 February 2025, selected governance and general-purpose AI provisions from 2 August 2025, and Article 6(1) plus corresponding obligations apply from 2 August 2028. For deployers, Article 50 generally applied from 2 August 2026, while the relevant Article 6(2)/Annex III high-risk duties, including associated Article 26 routes, apply from 2 December 2027.

Current consolidated-law application dates

Regulation (EU) 2026/1744 is in force. Use the consolidated AI Act and the applicable route date in controls, policies and board reporting; do not treat entry into force as universal application.

DateCurrent-law itemDeployer action
2 February 2025Chapters I and II apply, including AI literacy and prohibited AI practices.Keep AI literacy evidence and prohibited-practice screening live now.
2 August 2025Selected governance, GPAI, penalties, and Article 78 provisions apply.Track GPAI/vendor dependencies and update procurement evidence.
2 August 2026General application date for most AI Act rules; Article 50 generally applied, subject to route-specific exceptions.Complete deployer inventory, Article 50 review, and evidence ownership.
2 December 2027The relevant Article 6(2)/Annex III high-risk provisions apply.Complete Annex III classification and the applicable Article 26 evidence route.
2 August 2028The relevant Article 6(1)/Annex I high-risk provisions apply.Separate Annex I/product-safety systems from Annex III deployer systems.

Which AI systems should deployers track first?

Start with AI systems that affect people, access to services, employment, education, credit, insurance, biometric data, or public-facing synthetic content. The practical question is not “do we use AI?” It is “which deployed systems can create legal, operational, privacy, or fundamental-rights exposure if nobody can show the evidence trail?”

System typeWhy it goes firstFirst evidence artifact
Recruitment, screening, promotion, task allocation, performance monitoringEmployment and worker-management systems are listed in Annex III.AI inventory entry, HR owner, vendor file, worker-notice check, human oversight log.
Creditworthiness, credit scoring, life or health insurance pricingEssential private service and insurance use cases are listed in Annex III.Decision-flow map, model/vendor evidence, DPIA/FRIA routing, complaint/escalation path.
Education access, assessment, proctoring, student monitoringEducation and vocational training use cases are listed in Annex III.Purpose statement, learner-impact review, oversight assignment, testing and appeal record.
Biometric categorisation, emotion recognition, remote biometric identificationBiometrics are listed in Annex III and may also trigger Article 50 notices.Legal basis review, Article 50 notice check, DPIA/FRIA routing, approval record.
Public-facing AI-generated text, image, audio, or videoArticle 50 may require disclosure or provider-side marking depending on the use case.Disclosure decision register, editorial review note, label placement record.
AI agents or workflow automation that act on business systemsAgent workflows can hide provider/deployer boundaries and create monitoring gaps.Role map, action boundary, escalation path, logs, vendor instruction file.

Free tool path: start the AI system inventory, then check whether the system maps to Annex III high-risk use cases.

Article 26 deployer readiness checklist

Article 26 is where deployer readiness becomes evidence work. A policy is not enough. The deployer needs records showing that the system is used according to instructions, human oversight is assigned to competent people, input data is controlled where relevant, operation is monitored, logs are kept, and incidents or risks can be escalated.

Control questionEvidence to retainOwner
Are provider instructions available and followed?Provider instructions, configuration record, accepted-use note, deviation approvals.System owner + legal/procurement
Has human oversight been assigned to a competent person?Named oversight owner, training/competence note, escalation authority, review cadence.Business owner + compliance
Does the deployer control input data?Input-data relevance and representativeness check, data source list, exception log.Data owner + system owner
Is operation monitored against instructions?Monitoring log, exception review, vendor update review, risk notes.System owner
Are logs kept where under deployer control?Log-retention setting, access control, retention period, privacy review.IT/security + data protection
Is incident and risk escalation defined?Serious incident register, provider notification path, authority-escalation decision note.Risk/compliance + legal
Is the system used at work?Worker representative notice, affected worker notice, HR sign-off.HR + legal
Does the system assist decisions about natural persons?Affected-person notice review, DPIA/FRIA routing, appeal or review process.Legal + business owner

Free tool path: run the free Deployer Obligation Self-Assessment, then download the EU AI Act deployer obligations checklist.

Article 50 transparency trigger table

Article 50 is not a generic “AI was used” slogan. It is a trigger-based disclosure obligation. For deployers, the highest-risk misses are emotion recognition, biometric categorisation, deepfake media, and AI-generated public-interest text. The evidence question is simple: when the trigger fires, can you show the disclosure decision, label wording, placement, and owner?

TriggerLikely deployer questionEvidence artifact
Emotion recognition or biometric categorisationHave exposed people been informed of the system’s operation?Notice wording, placement record, privacy review, DPIA route.
Deepfake image, audio, or videoDoes the content need disclosure that it was artificially generated or manipulated?Disclosure label, creative/editorial exception note if relevant.
AI-generated text published to inform the public on matters of public interestIs disclosure needed, or was there human review and editorial responsibility?Editorial review note, publication owner, disclosure decision register.
Direct interaction with an AI systemIs it obvious to a reasonably well-informed person that they are interacting with AI?User-interface notice, chatbot/system wording, first-interaction screenshot.
Synthetic outputs generated by provider-side AI systemsAre machine-readable marking and detection obligations relevant upstream?Vendor/provider evidence request, technical marking statement.

Free tool path: review Article 50 AI content marking triggers, then read the Article 50 transparency guide.

Annex III high-risk triage table

Annex III is the triage layer for many deployers. The goal is not to label everything high-risk. The goal is to record a defensible classification decision, route high-risk candidates to evidence owners, and keep non-high-risk decisions versioned with the facts used at the time.

Annex III areaExamples to checkFirst action
BiometricsRemote biometric identification, sensitive biometric categorisation, emotion recognition.Pause deployment until legal/privacy review confirms lawful basis and Article 50 notice position.
Critical infrastructureSafety components in digital infrastructure, traffic, water, gas, heating, electricity.Map safety role, operator responsibility, and incident escalation.
Education and vocational trainingAdmission, assessment, learning-outcome evaluation, proctoring, student monitoring.Record learner impact, oversight path, and challenge route.
Employment and worker managementRecruitment, candidate filtering, promotion, termination, task allocation, performance monitoring.Assign HR/legal evidence owner and worker-notice review.
Essential services and benefitsPublic benefits, creditworthiness, life/health insurance, emergency triage or dispatch.Route to DPIA/FRIA, affected-person notice, and appeal path.
Law enforcementRisk assessment, evidence reliability, profiling, polygraphs or similar tools.Specialist legal review required. Do not use generic business templates.
Migration, asylum, border controlRisk assessment, application examination, identity detection or recognition.Specialist legal review required. Maintain strict authority and purpose controls.
Justice and democratic processesJudicial assistance, election or referendum influence.Escalate to senior legal and governance review before use.

30-day deployer evidence sprint

A 30-day sprint will not make a weak AI governance programme complete. It can create the minimum operating file: inventory, classification, owner mapping, disclosure triggers, oversight logs, and a gap list that senior management can act on. That is a better starting point than waiting for perfect guidance.

EU AI Act deployer evidence-file workflow with inventory, classification, vendor evidence, Article 50 review, oversight logs and review cadence
The 30-day evidence sprint: inventory, classify, evidence, disclose, monitor, and review.
WeekWorkstreamOutput
Week 1Inventory and ownershipList AI systems, vendors, business owners, user groups, data categories, and evidence locations.
Week 2Classification and Article 26 scopeAnnex III triage, deployer/provider role notes, Article 26 evidence owner assigned.
Week 3Article 50 and vendor evidenceDisclosure trigger register, label placement decision, vendor instruction/evidence request list.
Week 4Oversight, logs, and management sign-offOversight log, log-retention review, unresolved gaps, decision memo, next review date.

Free tool path: use the Evidence Starter Library to build the folder structure before moving to paid implementation assets.

What to do if guidance or timelines change

Separate the current legal baseline, provision-specific application dates, draft guidance and internal readiness work. The mistake is to mix them in one spreadsheet and let later application dates stop practical evidence work. The inventory, owner map, vendor file, disclosure register and oversight log remain useful.

  1. Keep a current-law row. Record the rule and date as currently enacted.
  2. Add an application-date row. Record the relevant date from the consolidated law and keep future proposals or draft guidance separately labelled.
  3. Version your decisions. Record which source and date the team relied on.
  4. Do not rewrite tool logic too early. Update calculators, notices, and board packs only after final legal change.
  5. Reconcile monthly. Assign a person to check statutory dates, final guidance and separately labelled draft or proposal changes.

Reference path: compare the current statutory application dates.

Common mistakes

Treating vendor paperwork as deployer evidence

Vendor documents help. They do not prove your team assigned oversight, checked input data, issued notices, or retained logs.

Running Article 50 review only in marketing

Article 50 may touch product UX, customer support, content operations, HR, and biometric workflows.

Forgetting workplace notification

If a high-risk AI system is used at work, Article 26 points to worker and worker-representative information duties.

Confusing DPIA and FRIA

A DPIA can be part of the evidence file. It does not automatically answer every fundamental-rights question.

No evidence owner

If nobody owns the file, the evidence will fragment across procurement, product, legal, HR, and IT.

Freezing because guidance is unsettled

Unsettled guidance is not a reason to ignore inventory, classification, notices, logs, and oversight records.

Next step: run the free deployer assessment

Use the self-assessment first. If it exposes repeated evidence gaps, missing owners, unclear Article 50 triggers, or weak board reporting, E1/E2 can become the implementation layer for templates, control mapping, and board-ready evidence packs. The free tracker comes first.

FAQ: EU AI Act application dates for deployers

Source and review note

This page was last reviewed against official sources on 2026-09-02. It is operational guidance for deployer readiness planning. It is not legal advice, does not guarantee compliance, and does not replace review by qualified legal, privacy, regulatory, or sector-specific counsel.

About the author: Abhishek G Sharma is the founder of Move78 International Limited and holds ISO 42001 LA, ISO 27001 LA, CISA, CISM, CRISC, CEH, CCSK, CAIGO, and CAIRO certifications.

Source basis

Update context: Deadline tracker updated to use the provision-specific statutory dates in Regulation (EU) 2026/1744 and the consolidated AI Act.

Source basis: Consolidated Regulation (EU) 2024/1689 current from 27 July 2026, Article 26, Article 50, Article 113, Annex III, and Regulation (EU) 2026/1744.

Digital Omnibus status: Regulation (EU) 2026/1744 is in force. Entry into force does not make every amended provision immediately applicable; use the date for the specific route.

Use limit: This page is for educational and operational planning only. It is not legal advice, a conformity assessment, certification, or a compliance guarantee.