EU AI Act: Compliance Roadmap Through 2028


Cover Image: EU AI Act – Timeline Through 2028

The deadlines set forth in the EU AI Act apply to every company that uses or offers an AI system. By familiarizing yourself with them early on, you can spread out your compliance efforts over several years instead of rushing to meet a deadline at the last minute.

In a nutshell

The EU AI Act applies in stages. The ban on certain AI practices and the AI literacy obligation have applied since February 2025, and the transparency obligation under Article 50 since August 2026. The high-risk obligations were postponed to December 2027 and August 2028 by the Digital Omnibus Regulation. The following measures can be implemented immediately: conducting an assessment, performing a risk assessment, and providing employee training.

An Overview of the Deadlines Under the EU AI Act

Since 2 February 2025 the first two obligations of the regulation have applied: the ban on certain AI practices and the AI literacy obligation under Article 4 (European Commission, AI Act Service Desk). On July 27, 2026, the Digital Omnibus Regulation (EU) 2026/1744 entered into force (EUR-Lex). It has postponed several deadlines, including those for high-risk systems.

Schedule of Deadlines Under the Digital Omnibus Regulation, as of August 2026
Date Requirement Who It Affects First
02.02.2025 Prohibited AI Practices, Mandatory AI Competency under Article 4 All companies that use AI
02.08.2026 Transparency Requirements Under Article 50 Customer Service, Marketing, Website
02.12.2026 End of the transition period for labeling synthetic content in legacy systems Marketing and Communications
02.12.2027 Requirements for High-Risk Systems under Annex III Human Resources, Lending
02.08.2028 Requirements for High-Risk Systems under Annex I AI as a Safety Component in Products

The postponement of the high-risk deadlines gives companies more lead time, but it is no reason to leave preparation aside (HLP Beratung, KI-Verordnung Fristen, 08/2026). Those who only begin classifying their systems shortly before the cut-off date regularly underestimate how long a sound risk assessment takes.

The difference between Annex I and Annex III lies in the type of systems covered. Annex I covers AI as a safety-related component in products that are already regulated, such as machinery or medical devices. Annex III covers standalone high-risk applications, for example in human resources or credit lending. For companies engaged in traditional manufacturing, both annexes are often relevant.

Merely using AI puts you in scopeThe regulation applies not only to companies that develop their own AI models. Anyone who uses an AI system—whether it’s a chatbot in customer service or software for pre-screening job applications—is subject to the same obligations as the provider, often with additional operational requirements of their own.

The transparency requirements of the EU AI Act have been in effect since August 2026

As of August 2, 2026, companies must disclose when users are interacting with an AI system rather than a human. This applies to chatbots in customer service as well as automated replies in email inboxes. For synthetic content—that is, text, images, or audio files generated by AI—existing systems are subject to a transition period until December 2, 2026. New systems must comply with the labeling requirement from the outset.

This requirement may sound technical, but in practice it often affects marketing and communications departments first. The labeling itself is usually straightforward to implement; in most cases, a brief note or a small symbol is sufficient. The real challenge lies in even knowing where AI-generated content is being produced within one’s own organization. In a centrally managed marketing department, this can be determined quickly, but in the case of multiple locations with their own sales teams, this assessment takes significantly longer.

What to Do Now If the High-Risk Period Still Seems Far Away

82 %

of companies now see regulation as a factor influencing their AI strategy. Three steps can be tackled immediately, regardless of the high-risk timetable.

KPMG, July 2026

  1. Taking Stock. A list of all AI systems in use, including their purpose, data source, and the person responsible.
  2. Risk classification. An initial classification into the four categories: prohibited, high, limited, and minimal.
  3. Training pursuant to Article 4. The AI competency requirement has been in effect since February 2025, but many companies are still not taking it seriously.

We describe the exact assignment of roles and approval processes for this classification in the article on AI Governance in the Workplace. If you consider governance and deadline management together from the very beginning, you only have to conduct the assessment once, rather than repeating it for each requirement.

One aspect that is often overlooked in many compliance projects is the documentation itself. The regulation requires, in several places, evidence of how a system works and what data it processes. Anyone who waits to write this documentation until a regulatory agency requests it wastes valuable time. A regularly updated overview—even if it initially consists of nothing more than a simple table—saves a great deal of effort in the event of an emergency.

Classify the system landscape into risk classesWe'll review the AI systems you're using and let you know which deadline applies to each system and what needs to be done by then.

Request Classification

Frequently Asked Questions

Does the EU AI Act also apply to smaller companies?

Yes. The regulation does not distinguish based on company size, but rather on the risk class of the system in use. A small business that uses a chatbot to interact with customers is subject to the same transparency requirements as a large corporation. The AI competence requirement under Article 4 also applies regardless of company size. As an EU regulation, the AI Act applies directly in Austria as well; separate national implementation is not necessary.

What should a company implement right away?

The first step is to compile a list of all AI systems in use, including their purpose, data source, and the person responsible. This is followed by classifying them into a risk category. Systems that interact with customers should also be reviewed for compliance with the transparency requirement under Article 50, as the deadline for this is already in effect. At the same time, it is worthwhile to provide initial training for the workforce on the AI competency requirement.

What are the consequences of noncompliance with the EU AI Act?

Fines are tiered by the severity of the breach, from breaches of prohibited practices to breaches of transparency or documentation obligations. The exact amount depends on the individual case and on the company's revenue. For most operations the risk of having to adapt or switch off an already productive system at short notice weighs more heavily than the level of the fine. In practice, a production outage caused by a shutdown at short notice often weighs more heavily than the fine itself.

The Next Step

torck supports companies in industry and retail with the technical implementation of the AI Act obligations, from documentation to the labelling of AI interactions. As a software company with its own teams in Maxhütte-Haidhof, Vienna, and Rabat, we build the necessary systems ourselves. In the initial consultation we classify your own system landscape into the risk classes together. Schedule an Initial Consultation.

Legal note
This article refers to laws and regulations to put technical decisions in context. It is not legal advice. Whether and how a rule applies to your company is a question for your legal department or a law firm.

Questions about this post?

Just a couple of sentences about your situation will suffice. The person responding builds these kinds of systems himself.

We'll respond within one business day.torck · code with torque
Florian Blischke
Managing Director of torck GmbH · Over 20 years of software development experience
Florian Blischke is the managing director of torck GmbH and has been working in software development for over 20 years. He is responsible for custom software solutions for industry and retail, ranging from the integration of physical processes and IoT to cloud architecture and data- and AI-driven systems. At torck, he oversees, among other projects, the Jouvoli energy platform and the KVM Fleet fleet management product. torck develops software at its locations in Maxhütte-Haidhof, Vienna, and Rabat, and places a strong emphasis on software that actually works in real-world operations.

Are you facing the same question?

We’ve been building software for industry and retail since 2017, based in Maxhütte-Haidhof, with teams in Vienna and Rabat. An initial consultation lasts 30 minutes and is free of charge. Afterward, you’ll know whether the project is worth pursuing—even if the answer is no.

More Articles

AI Funding Programs in Germany and Austria in 2026

AI Funding Programs in 2026 in Germany and Austria

Germany and Austria will fund AI projects in 2026 through several programs with varying funding rates and maximum grant amounts. This article categorizes the Research Grant, ZIM, KMU-innovativ, FFG, and aws programs and outlines the technical requirements for submitting an application.

Read more »