The Act regulates providers who build AI systems and deployers who use them. Almost every enterprise is a deployer of general-purpose AI the moment employees use ChatGPT, Copilot or Gemini at work, and a deployer of agents the moment one runs with tool access. AI literacy (Article 4) has applied since February 2025; the Commission and national authorities gained enforcement powers on August 2, 2026; and the high-risk regime lands from December 2027. The common thread across every obligation is the same: you must be able to say what AI runs in your organisation, who uses it, what it touched, and how a human could intervene.
Providers and deployers must ensure a sufficient level of AI literacy among staff operating AI systems — which presupposes knowing which systems staff actually operate.
Use high-risk systems per instructions, assign human oversight to competent people, keep automatically generated logs for at least six months, monitor operation and inform workers.
Public bodies and certain private deployers must assess the impact on fundamental rights before putting a high-risk system into use — and keep that assessment current.
People must be told when they interact with an AI system; synthetic content must be marked; deployers of emotion-recognition or deep-fake systems carry disclosure duties.
High-risk systems must log events automatically and be designed so that natural persons can oversee, override or stop them — obligations deployers inherit operationally.
Serious incidents must be reported to market-surveillance authorities; monitoring must continue for the life of the system, not end at go-live.
General information about the public text of the framework, not legal advice. Mappings describe how AccuroAI controls support each obligation; scope and conformity decisions remain with your legal, compliance and certification partners.
As amended by the Digital Omnibus, adopted June 2026. Earlier dates have passed; the next ones are fixed in the regulation.
Yes, as a deployer. The AI literacy duty (Article 4) applies to everyone operating AI systems, and the transparency rules in Article 50 apply from August 2, 2026. The heavier high-risk obligations only apply if you use AI for an Annex III purpose — recruitment, credit, education, essential services — and those land from December 2, 2027.
The Omnibus — Regulation (EU) 2026/1744, in force since July 27, 2026 — moved the Annex III high-risk application date to December 2, 2027 and Annex I to August 2, 2028. It did not move the GPAI obligations, the Article 50 transparency duties, or the general application date of August 2, 2026; it also added a new prohibition on AI that generates non-consensual intimate imagery, applying from December 2, 2026.
No product does. AccuroAI produces the inventory, logs, oversight controls and transparency evidence that the deployer obligations depend on, and maps that evidence to the Act's articles so your legal and compliance teams can demonstrate it. The legal assessment of scope and risk tier remains yours.
Most organisations have a complete first inventory within the 72-hour discovery pilot: every AI tool, agent and MCP server seen in the browser and on managed endpoints, with owners and risk scores. Deployment typically takes under 30 minutes through your existing MDM and identity provider.
No. This page summarises the public text of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (the Digital Omnibus on AI), as of August 2026 and describes how AccuroAI controls support the obligations. Confirm your obligations with counsel.