Back to Guides
Guide16 September 2026

What Every Developer Needs to Know About the EU AI Act in 2026

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. Key takeaways
  2. When does the EU AI Act actually start applying?
  3. Which organisations are subject to the AI Act?
  4. What are the risk categories and what do they mean?
  5. What specific prohibitions are already in force?
  6. What transparency obligations must AI providers meet?
  7. How are general - purpose AI models regulated?
  8. When do high - risk AI obligations kick in?
  9. Who enforces the AI Act and how are penalties calculated?
  10. How can developers prepare before the 2026 deadlines?
  11. What are the biggest compliance pitfalls to avoid?
  12. Where can I find more detailed guidance?

Key takeaways

When does the EU AI Act actually start applying?

The act entered into force on 1 Aug 2024, but most provisions become generally applicable on 2 Aug 2026. This staggered rollout means that from that date the European Commission’s AI Office and national authorities can enforce all core obligations.

Which organisations are subject to the AI Act?

The regulation applies to providers placing AI systems or general - purpose AI (GPAI) models on the EU market, to deployers located in the EU, and to importers, distributors, product manufacturers and authorised representatives. Personal non - professional use, pure research, testing, development and military or national - security uses are excluded.

What are the risk categories and what do they mean?

AI systems are classified as:

What specific prohibitions are already in force?

Prohibited practices under Article 5 started on 2 Feb 2025. Additional bans on non - consensual intimate imagery and child - sexual - abuse - material become enforceable on 2 Dec 2026. Violations can attract fines up to €35 million or 7 % of worldwide annual turnover, whichever is higher.

What transparency obligations must AI providers meet?

Article 50 requires providers of AI systems that generate synthetic audio, image, video or text to:

  1. Clearly inform users that they are interacting with AI.
  2. Attach a machine - readable watermark or metadata to all AI - generated output. Compliance is mandatory from 2 Aug 2026. Systems placed before that date have a later deadline of 2 Dec 2026 to add the required markings.

How are general - purpose AI models regulated?

The GPAI regime imposes technical documentation, training - data summaries, EU - copyright - compliance policies and systemic - risk management. These obligations start on 2 Aug 2025 for new models and become fully enforceable on 2 Aug 2026. Providers of models placed before 2 Aug 2025 have until 2 Aug 2027 to comply; those placed before 2 Aug 2026 must meet the synthetic - content marking deadline of 2 Dec 2026.

When do high - risk AI obligations kick in?

Who enforces the AI Act and how are penalties calculated?

The European Commission’s AI Office coordinates enforcement, can request documentation and conduct evaluations. National competent authorities in each Member State carry out market surveillance and investigations. Penalties are tiered: up to €35 million or 7 % of worldwide turnover for prohibited - practice breaches, and up to €15 million or 3 % of worldwide turnover for other infringements such as Article 50 or GPAI violations.

How can developers prepare before the 2026 deadlines?

  1. Audit your AI inventory - list all models, use - cases and generated content types.
  2. Classify risk - map each system to the Act’s categories using the Annex III and Annex I criteria.
  3. Implement labeling - add machine - readable watermarks to all synthetic outputs; update UI to show clear AI notices.
  4. Document GPAI compliance - create technical files, data - set summaries and copyright policies for any general - purpose models.
  5. Set up AI - literacy training - ensure staff and end - users understand AI limitations; this requirement started on 2 Feb 2025.
  6. Plan for high - risk conformity - begin gap analysis for Annex III and Annex I obligations well before their 2027 - 2028 deadlines.

What are the biggest compliance pitfalls to avoid?

Where can I find more detailed guidance?

The European Commission’s implementation guidance (e.g., the July 2026 PDF) and the official regulation text (Regulation (EU) 2024/1689, amended by Regulation 2026/1744) provide the authoritative source for all deadlines and obligations.


This article follows the EU AI Act facts as of 2026 and does not constitute legal advice.

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary