Regulation · EU AI Act · GDPR
The EU AI Act, in business terms.
The AI Act regulates AI the way Europe regulates products: by risk. Most obligations fall on
“deployers” — companies that use AI, not just those who
build it. In July 2026 the Digital Omnibus on AI deferred the high-risk deadlines.
Deferred — not cancelled. And the quiet part: GDPR was never deferred. It applies
to every prompt your staff sent this morning.
1 Aug 2024
The AI Act enters into force
Regulation (EU) 2024/1689 — the world’s first comprehensive AI law.
2 Feb 2025
Prohibitions & AI literacy apply
Banned practices (social scoring, manipulative systems) and staff AI-literacy duties take effect.
2 Aug 2025
General-purpose AI rules apply
Obligations for GPAI model providers, governance structures and the penalty framework activate.
27 Jul 2026
Digital Omnibus on AI in force — deadlines deferred
High-risk compliance dates are pushed back to give standards and authorities time to catch up. The core high-risk obligations are preserved — alongside targeted amendments elsewhere in the Act.
2 Aug 2026 — you are here
Transparency obligations apply
People must be told when they interact with AI — law today (Art. 50). Machine-readable marking of AI content applies to newly placed systems now; systems already on the market have until 2 Dec 2026.
2 Dec 2027
High-risk obligations apply (Annex III)
Risk pricing in life & health insurance, credit scoring, employment screening, essential services — logging, oversight, data governance and impact assessments become enforceable.
2 Aug 2028
High-risk rules reach regulated products (Annex I)
AI embedded in machinery, medical devices and other regulated products follows.
ZeroTrace™ is compliance infrastructure, not legal advice. It gives you the technical controls and
the evidence trail; your counsel maps them to your obligations under Regulation (EU) 2024/1689 as
amended by the Digital Omnibus on AI (Regulation (EU) 2026/1744), the GDPR and sector rules such as DORA.