The deadlines set forth in the EU AI Act apply to every company that uses or offers an AI system. By familiarizing yourself with them early on, you can spread out your compliance efforts over several years instead of rushing to meet a deadline at the last minute.
The EU AI Act applies in stages. The ban on certain AI practices and the AI literacy obligation have applied since February 2025, and the transparency obligation under Article 50 since August 2026. The high-risk obligations were postponed to December 2027 and August 2028 by the Digital Omnibus Regulation. The following measures can be implemented immediately: conducting an assessment, performing a risk assessment, and providing employee training.
An Overview of the Deadlines Under the EU AI Act
Since 2 February 2025 the first two obligations of the regulation have applied: the ban on certain AI practices and the AI literacy obligation under Article 4 (European Commission, AI Act Service Desk). On July 27, 2026, the Digital Omnibus Regulation (EU) 2026/1744 entered into force (EUR-Lex). It has postponed several deadlines, including those for high-risk systems.
| Date | Requirement | Who It Affects First |
|---|---|---|
| 02.02.2025 | Prohibited AI Practices, Mandatory AI Competency under Article 4 | All companies that use AI |
| 02.08.2026 | Transparency Requirements Under Article 50 | Customer Service, Marketing, Website |
| 02.12.2026 | End of the transition period for labeling synthetic content in legacy systems | Marketing and Communications |
| 02.12.2027 | Requirements for High-Risk Systems under Annex III | Human Resources, Lending |
| 02.08.2028 | Requirements for High-Risk Systems under Annex I | AI as a Safety Component in Products |
The postponement of the high-risk deadlines gives companies more lead time, but it is no reason to leave preparation aside (HLP Beratung, KI-Verordnung Fristen, 08/2026). Those who only begin classifying their systems shortly before the cut-off date regularly underestimate how long a sound risk assessment takes.
The difference between Annex I and Annex III lies in the type of systems covered. Annex I covers AI as a safety-related component in products that are already regulated, such as machinery or medical devices. Annex III covers standalone high-risk applications, for example in human resources or credit lending. For companies engaged in traditional manufacturing, both annexes are often relevant.
The transparency requirements of the EU AI Act have been in effect since August 2026
As of August 2, 2026, companies must disclose when users are interacting with an AI system rather than a human. This applies to chatbots in customer service as well as automated replies in email inboxes. For synthetic content—that is, text, images, or audio files generated by AI—existing systems are subject to a transition period until December 2, 2026. New systems must comply with the labeling requirement from the outset.
This requirement may sound technical, but in practice it often affects marketing and communications departments first. The labeling itself is usually straightforward to implement; in most cases, a brief note or a small symbol is sufficient. The real challenge lies in even knowing where AI-generated content is being produced within one’s own organization. In a centrally managed marketing department, this can be determined quickly, but in the case of multiple locations with their own sales teams, this assessment takes significantly longer.
What to Do Now If the High-Risk Period Still Seems Far Away
of companies now see regulation as a factor influencing their AI strategy. Three steps can be tackled immediately, regardless of the high-risk timetable.
KPMG, July 2026
- Taking Stock. A list of all AI systems in use, including their purpose, data source, and the person responsible.
- Risk classification. An initial classification into the four categories: prohibited, high, limited, and minimal.
- Training pursuant to Article 4. The AI competency requirement has been in effect since February 2025, but many companies are still not taking it seriously.
We describe the exact assignment of roles and approval processes for this classification in the article on AI Governance in the Workplace. If you consider governance and deadline management together from the very beginning, you only have to conduct the assessment once, rather than repeating it for each requirement.
One aspect that is often overlooked in many compliance projects is the documentation itself. The regulation requires, in several places, evidence of how a system works and what data it processes. Anyone who waits to write this documentation until a regulatory agency requests it wastes valuable time. A regularly updated overview—even if it initially consists of nothing more than a simple table—saves a great deal of effort in the event of an emergency.
Classify the system landscape into risk classesWe'll review the AI systems you're using and let you know which deadline applies to each system and what needs to be done by then.
Frequently Asked Questions
Does the EU AI Act also apply to smaller companies?
Yes. The regulation does not distinguish based on company size, but rather on the risk class of the system in use. A small business that uses a chatbot to interact with customers is subject to the same transparency requirements as a large corporation. The AI competence requirement under Article 4 also applies regardless of company size. As an EU regulation, the AI Act applies directly in Austria as well; separate national implementation is not necessary.
What should a company implement right away?
The first step is to compile a list of all AI systems in use, including their purpose, data source, and the person responsible. This is followed by classifying them into a risk category. Systems that interact with customers should also be reviewed for compliance with the transparency requirement under Article 50, as the deadline for this is already in effect. At the same time, it is worthwhile to provide initial training for the workforce on the AI competency requirement.
What are the consequences of noncompliance with the EU AI Act?
Fines are tiered by the severity of the breach, from breaches of prohibited practices to breaches of transparency or documentation obligations. The exact amount depends on the individual case and on the company's revenue. For most operations the risk of having to adapt or switch off an already productive system at short notice weighs more heavily than the level of the fine. In practice, a production outage caused by a shutdown at short notice often weighs more heavily than the fine itself.
The Next Step
torck supports companies in industry and retail with the technical implementation of the AI Act obligations, from documentation to the labelling of AI interactions. As a software company with its own teams in Maxhütte-Haidhof, Vienna, and Rabat, we build the necessary systems ourselves. In the initial consultation we classify your own system landscape into the risk classes together. Schedule an Initial Consultation.
This article refers to laws and regulations to put technical decisions in context. It is not legal advice. Whether and how a rule applies to your company is a question for your legal department or a law firm.