# EU AI Act for Deployers: What Applies in 2026 and What Comes Later
> A deployer checklist for the EU AI Act as it stands in 2026: what applies now, what the Digital Omnibus deferred, and the obligations most organisations have missed.
- Author: [Maximilian Betz](https://www.offgen.ai/en/authors/maximilian-betz)
- Published: 2026-08-26
- Updated: 2026-08-26
- Category: Security & EU Regulation
- Labels: Security & EU Regulation, Regulated Industries
- Canonical URL: https://www.offgen.ai/en/blog/eu-ai-act-deployer-checklist
> This article is for information only and does not constitute legal advice.
## Evidence for this article

This article supports its claims with 4 sources. Key sources include:

1. [Regulation (EU) 2024/1689 (Artificial Intelligence Act)](https://eur-lex.europa.eu/eli/reg/2024/1689/oj?locale=en) (EUR-Lex)
2. [Regulation (EU) 2026/1744 (Digital Omnibus on AI)](https://eur-lex.europa.eu/eli/reg/2026/1744/oj) (EUR-Lex)
3. [AI Act regulatory framework and implementation timeline](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai) (European Commission)

[Full source list](#sources)
If you buy and use AI tools rather than build them, you are almost certainly a deployer under the EU AI Act, and your obligations are narrower than a provider's but they are not zero.

Here is where the position stands in 2026, what changed in July, and the specific things I see organisations missing.

<Callout title="Scope and legal review">
  This is operational guidance, not legal advice. Your obligations depend on your role, the systems you deploy, their classification and your national context. AI Act counsel should review your assessment, and this area moves quickly enough that a review every 90 to 180 days is reasonable.
</Callout>

## The timeline as it stands [#the-timeline-as-it-stands]

| Date            | What applies                                                                           |
| --------------- | -------------------------------------------------------------------------------------- |
| 1 August 2024   | The AI Act entered into force                                                          |
| 2 February 2025 | Prohibited practices under Article 5, and the AI literacy duty under Article 4         |
| 2 August 2025   | Obligations for general purpose AI models, and governance rules                        |
| 2 August 2026   | General application of the AI Act, including transparency obligations under Article 50 |
| December 2026   | The additional prohibited practice introduced by the Digital Omnibus                   |
| 2 December 2027 | Obligations for Annex III high risk systems, deferred from 2 August 2026               |
| 2 August 2028   | Obligations for high risk systems embedded in products under Annex I                   |

## What the Digital Omnibus actually changed [#what-the-digital-omnibus-actually-changed]

Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It amends the AI Act and related instruments.

The headline change: obligations for standalone high risk systems classified under Annex III moved from 2 August 2026 to 2 December 2027, and for AI embedded in products already covered by EU product safety law under Annex I to 2 August 2028. It also narrowed scope in places, reduced some documentation requirements for smaller organisations, and added a further prohibited practice covering AI generated non consensual intimate imagery and child sexual abuse material.

Now the part organisations keep getting wrong. The Omnibus did not defer Article 4 and it did not defer Article 50. Both are live. If your compliance programme treats the AI Act as a 2027 problem, you have two obligations in force right now that your programme does not address.

I would also note what a deferral is and is not. It moved a date. Annex III systems will be high risk in December 2027 exactly as they would have been in August 2026, and organisations that used the extra time to prepare will be in a very different position from those that used it to stop thinking about it.

## Step 1: inventory your AI systems [#step-1-inventory-your-ai-systems]

You cannot assess obligations for systems you have not listed. This step is boring and it is where most programmes are weakest.

Include:

* Systems procured explicitly as AI products.
* AI features inside tools you bought for another purpose, which is where most of the surprise sits.
* Systems used by third parties operating on your behalf.
* Systems in use without formal approval. These need attention most urgently, not least because their users have had no literacy training.

For each, record the business function, the owner, the data involved, the users, whether output influences decisions about people, and the provider.

## Step 2: confirm your role for each system [#step-2-confirm-your-role-for-each-system]

Deployer or provider, per system. Most organisations are deployers for most systems.

The distinction matters and it can shift. If you substantially modify a system, put your own name on it, or use it for a purpose different from the intended purpose the provider declared, the analysis can change. That is a legal question with facts specific to your arrangement, and it belongs with counsel rather than with an assumption.

Fine tuning a model on your own data, in particular, deserves a specific look rather than a default answer.

## Step 3: check the prohibitions [#step-3-check-the-prohibitions]

Article 5 prohibitions have applied since 2 February 2025, and the Omnibus added a further one applying from December 2026.

Run every system against the prohibited practices, and document that you did. This is usually a short exercise with a clear answer, and the documentation matters more than the conclusion because the conclusion is normally that nothing is prohibited.

## Step 4: assess classification [#step-4-assess-classification]

For each system, determine whether it falls into the high risk categories under Annex III or Annex I.

Annex III includes categories that touch ordinary business functions more than people expect: biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential private and public services, law enforcement, migration and border control, and administration of justice.

Two of those catch organisations by surprise. **Employment and worker management** covers recruitment, selection, task allocation and evaluation, which reaches a lot of HR technology. **Access to essential private and public services** includes creditworthiness evaluation and, for life and health insurance, risk assessment and pricing.

Document the assessment and the reasoning for every system, including the ones you conclude are not high risk. A supervisor asking about a system wants to see that you thought about it. And set a trigger to reassess when a system's use expands, because that is how a not high risk system quietly becomes one.

## Step 5: the obligations that apply now [#step-5-the-obligations-that-apply-now]

### AI literacy, Article 4, since 2 February 2025 [#ai-literacy-article-4-since-2-february-2025]

Take measures to ensure, to your best extent, a sufficient level of AI literacy among staff and other persons operating or using AI systems on your behalf, taking into account their technical knowledge, experience, education and training, the context of use, and the persons on whom the systems are used.

Applies to any AI system, not only high risk. This is the single most missed obligation and the easiest to start on.

### Transparency, Article 50, since 2 August 2026 [#transparency-article-50-since-2-august-2026]

Obligations covering, among other things, disclosure when a person is interacting with an AI system, marking of AI generated synthetic content, and disclosure of deepfakes. Assess where your deployments fall within scope, particularly anything customer facing.

### Prohibitions, Article 5, since 2 February 2025 [#prohibitions-article-5-since-2-february-2025]

Do not deploy a prohibited practice. Document that you checked.

## Step 6: prepare for what comes in December 2027 [#step-6-prepare-for-what-comes-in-december-2027]

If you deploy an Annex III high risk system, deployer obligations will apply from 2 December 2027. Broadly, and subject to the detail and to counsel, these include using the system in accordance with the instructions for use, assigning human oversight to people with the necessary competence, training and authority, ensuring input data is relevant and sufficiently representative for the intended purpose, monitoring operation and reporting serious incidents, keeping logs where they are under your control, informing affected persons where required, and cooperating with authorities.

None of that is achievable in the fortnight before the deadline. The organisations that will be ready are building the operating model now: the oversight roles, the competence to fill them, the logging, the monitoring and the incident route.

## Step 7: the interaction with the GDPR [#step-7-the-interaction-with-the-gdpr]

These are separate frameworks and conflating them produces bad assessments in both directions.

The GDPR applies to processing of personal data regardless of AI Act classification. A system that is not high risk under the AI Act can still process large volumes of personal data with all the obligations that carries. Conversely, a high risk classification under the AI Act does not automatically mean a DPIA is required, although in practice the two frequently coincide.

Run both assessments. Document both conclusions separately, even where one vendor review gathered evidence for each.

## The deployer checklist [#the-deployer-checklist]

<Checklist>
  * A complete inventory of AI systems, including features inside other tools and unapproved usage.
  * Role determined per system, deployer or provider, with reasoning where it is not obvious.
  * Every system checked against the Article 5 prohibitions, with the check documented.
  * Classification assessed per system, with reasoning recorded including for negative conclusions.
  * A reassessment trigger set for when a system's use or configuration expands.
  * An AI literacy programme in place, covering all staff who use AI systems on your behalf.
  * Literacy depth scaled by role, with reviewers and approvers treated as a distinct tier.
  * Article 50 transparency obligations assessed for all deployments, especially customer facing.
  * Human oversight arrangements defined, with named people who have competence and authority.
  * Logging and monitoring arrangements defined for systems where obligations will apply.
  * An incident identification and reporting route connected to your existing process.
  * Vendor documentation obtained: instructions for use, system information, provider role.
  * GDPR assessment run separately, with its own documented conclusions.
  * A review cycle of 90 to 180 days, with the last review date recorded.
</Checklist>

## The five most common gaps [#the-five-most-common-gaps]

**Treating the whole Act as a 2027 problem.** Two obligations are in force now.

**Missing AI literacy entirely.** It applies to any AI system and has since February 2025.

**No inventory.** You cannot assess what you have not listed, and AI features inside other products are where the surprises live.

**Assuming rather than assessing classification.** The conclusion is usually not high risk. The documented reasoning is what your position rests on, and an assumption is not a reasoning.

**Content and assessments written before July 2026.** The Omnibus changed dates and scope. Anything describing an August 2026 high risk deadline is out of date, and internal guidance drifts faster than anyone expects.

## Where offgen fits [#where-offgen-fits]

As a deployer, you need information from your providers to meet your own obligations. What to ask for: what the system does and its intended purpose, the instructions for use, how it behaves when it lacks evidence, how permissions are enforced, what is logged and for how long, the processing chain, and the provider's own AI Act position.

Our [trust center](/en/security/trust-center), [security overview](/en/security) and [data processing agreement](/en/data-processing-agreement) are written to support that. Where you need something specific for your assessment that is not published, ask us for it. A provider who cannot supply the information you need to meet your deployer obligations has made your compliance harder, and that is a legitimate factor in a procurement decision.

The single action I would take this week if you have not: check whether your AI literacy programme exists and covers everyone using AI on your behalf. It has been an obligation for eighteen months, it is the least burdensome thing on this list, and it is the one that makes every other control you build actually work.
## Frequently asked questions

### What is a deployer under the EU AI Act?

Broadly, a natural or legal person using an AI system under its own authority in a professional activity, as distinct from a provider who develops or places a system on the market. Most organisations buying and using AI tools are deployers, and deployer obligations are narrower than provider obligations but they are not zero.

### What applies to deployers in 2026?

The prohibitions under Article 5 and the AI literacy duty under Article 4 have applied since 2 February 2025. The AI Act became generally applicable on 2 August 2026, including the transparency obligations under Article 50. Deployer obligations attached to Annex III high risk systems now apply from 2 December 2027.

### What did the Digital Omnibus change?

Regulation (EU) 2026/1744, published on 24 July 2026 and in force since 27 July 2026, deferred obligations for Annex III high risk systems from 2 August 2026 to 2 December 2027, and for Annex I embedded systems to 2 August 2028. It also narrowed scope in places, eased some documentation requirements and added a further prohibited practice. It did not defer Article 4 or Article 50.

### Do most organisations deploy high risk AI systems?

Most do not, but the question has to be answered through a documented assessment rather than an assumption. Annex III covers categories including biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and justice, and several of those touch ordinary business functions such as recruitment.

### What is the most commonly missed deployer obligation?

AI literacy under Article 4. It has applied since February 2025, it applies to deployers of any AI system rather than only high risk ones, and a large number of organisations scheduled their whole programme around the high risk date and therefore missed it entirely.

### How often should the assessment be reviewed?

Every 90 to 180 days at present, and immediately when a system's capability or configuration changes materially. This area has moved substantially and repeatedly, and an assessment written before July 2026 does not reflect the current position.
## Sources

1. [Regulation (EU) 2024/1689 (Artificial Intelligence Act)](https://eur-lex.europa.eu/eli/reg/2024/1689/oj?locale=en) — EUR-Lex, 2024-07-12; accessed 2026-08-26.
2. [Regulation (EU) 2026/1744 (Digital Omnibus on AI)](https://eur-lex.europa.eu/eli/reg/2026/1744/oj) — EUR-Lex, 2026-07-24; accessed 2026-08-26.
3. [AI Act regulatory framework and implementation timeline](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai) — European Commission; accessed 2026-08-26.
4. [Regulation (EU) 2016/679 (General Data Protection Regulation)](https://eur-lex.europa.eu/eli/reg/2016/679/oj?locale=en) — EUR-Lex, 2016-04-27; accessed 2026-08-26.
## Related articles

- [EU AI Act AI Literacy: A Practical Training Plan for Professional Teams](https://www.offgen.ai/en/blog/eu-ai-act-ai-literacy-training-plan)
- [AI Presentation Governance: A Practical Framework for Enterprise Teams](https://www.offgen.ai/en/blog/ai-presentation-governance-framework)
- [Enterprise AI Presentation Software: Evaluation Checklist for 2026](https://www.offgen.ai/en/blog/enterprise-ai-presentation-software-checklist)
