Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
- Key takeaways
- When does the EU AI Act actually start applying?
- Which organisations are subject to the AI Act?
- What are the risk categories and what do they mean?
- What specific prohibitions are already in force?
- What transparency obligations must AI providers meet?
- How are general - purpose AI models regulated?
- When do high - risk AI obligations kick in?
- Who enforces the AI Act and how are penalties calculated?
- How can developers prepare before the 2026 deadlines?
- What are the biggest compliance pitfalls to avoid?
- Where can I find more detailed guidance?
Key takeaways
- Full enforcement starts 2 Aug 2026, covering providers, deployers and importers of AI systems in the EU.
- Prohibited AI practices are already banned since 2 Feb 2025; additional bans on non - consensual intimate imagery and CSAM take effect 2 Dec 2026.
- Article 50 requires AI - generated content to be labelled and water - marked from 2 Aug 2026; legacy models have a 2 Dec 2026 deadline.
- High - risk AI obligations phase in through Dec 2027 (use - case) and Aug 2028 (product - safety components).
- Fines reach up to €35 million or 7 % of worldwide turnover for prohibited - practice breaches.
When does the EU AI Act actually start applying?
The act entered into force on 1 Aug 2024, but most provisions become generally applicable on 2 Aug 2026. This staggered rollout means that from that date the European Commission’s AI Office and national authorities can enforce all core obligations.
Which organisations are subject to the AI Act?
The regulation applies to providers placing AI systems or general - purpose AI (GPAI) models on the EU market, to deployers located in the EU, and to importers, distributors, product manufacturers and authorised representatives. Personal non - professional use, pure research, testing, development and military or national - security uses are excluded.
What are the risk categories and what do they mean?
AI systems are classified as:
- Unacceptable risk - outright prohibited (e.g., social - scoring, real - time remote biometric ID in public spaces).
- High risk - listed in Annex III (use - case based) or Annex I (safety components of regulated products) and must meet extensive conformity requirements.
- Limited risk / transparency only - certain generative AI systems must comply with Article 50 transparency duties. Each category triggers different compliance deadlines.
What specific prohibitions are already in force?
Prohibited practices under Article 5 started on 2 Feb 2025. Additional bans on non - consensual intimate imagery and child - sexual - abuse - material become enforceable on 2 Dec 2026. Violations can attract fines up to €35 million or 7 % of worldwide annual turnover, whichever is higher.
What transparency obligations must AI providers meet?
Article 50 requires providers of AI systems that generate synthetic audio, image, video or text to:
- Clearly inform users that they are interacting with AI.
- Attach a machine - readable watermark or metadata to all AI - generated output. Compliance is mandatory from 2 Aug 2026. Systems placed before that date have a later deadline of 2 Dec 2026 to add the required markings.
How are general - purpose AI models regulated?
The GPAI regime imposes technical documentation, training - data summaries, EU - copyright - compliance policies and systemic - risk management. These obligations start on 2 Aug 2025 for new models and become fully enforceable on 2 Aug 2026. Providers of models placed before 2 Aug 2025 have until 2 Aug 2027 to comply; those placed before 2 Aug 2026 must meet the synthetic - content marking deadline of 2 Dec 2026.
When do high - risk AI obligations kick in?
- Annex III (use - case high - risk) compliance deadline: 2 Dec 2027.
- Annex I (product - safety components) compliance deadline: 2 Aug 2028.
- Annex X (large - scale IT - system components) compliance deadline: 31 Dec 2030. These phased dates give providers time to implement risk - management and conformity - assessment procedures.
Who enforces the AI Act and how are penalties calculated?
The European Commission’s AI Office coordinates enforcement, can request documentation and conduct evaluations. National competent authorities in each Member State carry out market surveillance and investigations. Penalties are tiered: up to €35 million or 7 % of worldwide turnover for prohibited - practice breaches, and up to €15 million or 3 % of worldwide turnover for other infringements such as Article 50 or GPAI violations.
How can developers prepare before the 2026 deadlines?
- Audit your AI inventory - list all models, use - cases and generated content types.
- Classify risk - map each system to the Act’s categories using the Annex III and Annex I criteria.
- Implement labeling - add machine - readable watermarks to all synthetic outputs; update UI to show clear AI notices.
- Document GPAI compliance - create technical files, data - set summaries and copyright policies for any general - purpose models.
- Set up AI - literacy training - ensure staff and end - users understand AI limitations; this requirement started on 2 Feb 2025.
- Plan for high - risk conformity - begin gap analysis for Annex III and Annex I obligations well before their 2027 - 2028 deadlines.
What are the biggest compliance pitfalls to avoid?
- Assuming that open - source libraries are exempt - they are covered if placed on the market as high - risk.
- Forgetting to label AI - generated content that was released before 2 Aug 2026; the 2 Dec 2026 deadline still applies.
- Overlooking the GPAI regime for foundation models that are offered as a service.
- Ignoring the AI - literacy requirement; failure to provide staff training can trigger fines.
Where can I find more detailed guidance?
The European Commission’s implementation guidance (e.g., the July 2026 PDF) and the official regulation text (Regulation (EU) 2024/1689, amended by Regulation 2026/1744) provide the authoritative source for all deadlines and obligations.
This article follows the EU AI Act facts as of 2026 and does not constitute legal advice.
Related guides
What is NIST in cybersecurity and why should you care?
NIST is the U.S. agency that creates the Cybersecurity Framework and a suite of standards like SP 800 - 53 that guide risk management for both government and private organizations.
Which NIST Cybersecurity Standards Should My Organization Adopt in 2024 - 2025?
Learn the core NIST publications that form a practical, layered security program, how they map together, and concrete steps to start using them today.
Does the EU AI Act apply to U.S. companies?
Yes - the EU AI Act has extraterritorial reach and can bind U.S. AI providers, deployers, importers or distributors whenever their systems are placed on the EU market, used by an EU entity, or produce output that is used in the Union.