The EU AI Act does not switch on all at once. It applies in phases, and for most enterprises the phases that matter are still ahead. The prohibitions and AI-literacy provisions already apply, general-purpose AI model obligations have begun, and the transparency duties started on 2 August 2026. The obligations that touch the largest number of organisations — those for high-risk AI systems — were pushed back in July 2026 by the Digital Omnibus on AI, to 2 December 2027 for Annex III systems and 2 August 2028 for AI inside regulated products.
| Date | What applies (as amended by Regulation (EU) 2026/1744) |
|---|---|
| 2 February 2025 | Prohibited practices; AI literacy (softened in 2026 to supporting staff literacy) |
| 2 August 2025 | General-purpose AI model obligations; governance bodies and penalties framework |
| 27 July 2026 | Digital Omnibus on AI in force |
| 2 August 2026 | Article 50 transparency duties; enforcement by national authorities |
| 2 December 2026 | End of the watermarking grace period for systems placed on the market before 2 August 2026 |
| 2 December 2027 | High-risk obligations for stand-alone Annex III systems |
| 2 August 2028 | High-risk obligations for AI in products covered by Annex I |
This is not a legal guide, and nothing here is legal advice. It is an operational readiness view for deployers: organisations using AI systems in regulated contexts, who need to know what lands when and what infrastructure makes each obligation demonstrable. Where the obligations assume traceability, human oversight, and record-keeping, an on-premises platform is often the most direct way to hold the evidence yourself rather than depend on a provider for it.
First, know your role and your risk category
Two questions determine what applies to you before any date does.
Are you a provider or a deployer? A provider develops a system or places it on the market under its own name. A deployer uses a system under its own authority. Most enterprises adopting AI are deployers — and deployers of high-risk systems have their own obligations, including operating the system according to instructions, ensuring human oversight, monitoring operation, and keeping logs. If you fine-tune or substantially modify a system, you may take on provider obligations too. This distinction, and where it moves under private deployment, is explored in Human Oversight in AI Systems: EU AI Act Requirements.
Is the system high-risk? The heaviest obligations attach to high-risk systems — broadly, those listed in Annex III (areas such as employment, essential services, law enforcement, and critical infrastructure) and those that are safety components of regulated products under Annex I. Many enterprise systems are not high-risk and carry lighter, mainly transparency-oriented duties. Getting the classification right is the first readiness task; over- and under-classifying both carry cost.
The important point for planning: the obligations follow the risk category and your role, not the hosting model. Running on-premises does not reduce what the law requires. What it changes is your ability to produce the evidence yourself.
The phases, and what each one asks of a deployer
Phase 1 — In effect: prohibitions and AI literacy (from 2 February 2025)
The Act’s prohibited practices and the AI-literacy obligation already apply. For a deployer this means two things are due now: confirming that no system in use falls into a prohibited category, and ensuring staff who operate or oversee AI have a level of AI literacy appropriate to their role.
Readiness: maintain an inventory of AI systems in use with a documented risk classification for each, and run role-appropriate AI-literacy enablement for operators and overseers.
Phase 2 — In effect: general-purpose AI and governance (from 2 August 2025)
Obligations for general-purpose AI model providers have begun, national competent authorities are being stood up, and the EU-level governance structures are operational. Deployers are mainly affected indirectly — through the documentation and instructions that GPAI and system providers must now supply.
Readiness: collect and retain provider documentation for the models and systems you deploy. If you route across multiple models, know which models you use and keep their documentation on file — a task made easier when model routing is an explicit, catalogued decision rather than a hidden default.
Phase 3 — In effect: transparency duties and enforcement (from 2 August 2026)
The Article 50 transparency obligations kept their original start date. People must be told when they are interacting with an AI system unless it is obvious, deployers of emotion recognition or biometric categorisation must inform the people exposed to it, and deepfakes and certain AI-generated text must be disclosed as such. Providers of generative systems must mark synthetic output in a machine-readable way; systems already on the market before 2 August 2026 have until 2 December 2026 to add that marking.
Readiness: list every user-facing assistant and generative workflow you run, and confirm each one discloses that it is AI and carries whatever content marking your provider supplies.
Phase 4 — Next: high-risk systems under Annex III (from 2 December 2027)
This is the phase most enterprises are preparing for. The Digital Omnibus moved the core obligations for stand-alone Annex III high-risk systems (employment, credit scoring, essential services, education, law enforcement, border control and similar uses) from 2 August 2026 to 2 December 2027.
For a deployer of a high-risk system, the operational obligations include using the system in line with the provider’s instructions, ensuring meaningful human oversight, monitoring operation and reporting serious incidents, and keeping the logs the system automatically generates.
Readiness: this is where infrastructure does real work — see the checklist below.
Phase 5 — Later: high-risk in regulated products under Annex I (from 2 August 2028)
Obligations for high-risk AI that is a safety component of products already covered by EU harmonised legislation, such as medical devices, machinery and vehicles, now apply from 2 August 2028 instead of 2 August 2027. This mainly concerns organisations building or deploying AI inside regulated physical or software products.
Readiness: the same control base as Phase 4, integrated with the existing product-safety and conformity processes those sectors already run.
What the Digital Omnibus changed
The Commission proposed the “Digital Omnibus” in late 2025. Parliament and Council adopted it as Regulation (EU) 2026/1744 on 8 July 2026; it was published in the Official Journal on 24 July and entered into force on 27 July 2026, a week before the original high-risk date would have bitten.
The changes that matter to a deployer:
- High-risk dates moved. Annex III systems now follow 2 December 2027, and AI in Annex I products follows 2 August 2028.
- Transparency did not move. Article 50 still applied from 2 August 2026, with a four-month grace period for watermarking on systems already on the market.
- AI literacy was softened. Providers and deployers must support the development of AI literacy among their staff rather than guarantee a specific level.
- A new prohibition was added. From 2 December 2026, Article 5 also bans AI systems used to generate non-consensual intimate imagery and child sexual abuse material.
For planning, the direction of the obligations is unchanged. The deferral changes when, not whether, and organisations that paused their high-risk programmes in 2026 now have roughly fourteen months to build the control base properly instead of in a rush. Always confirm dates against EUR-Lex, because the Act can be amended again.
The deployer readiness checklist, mapped to on-premises controls
The high-risk deployer obligations translate into a small set of capabilities. Each is easier to demonstrate when you own the infrastructure that produces the evidence.
- System inventory and classification. A living register of AI systems in use, each with a documented risk category, purpose, owner, and the provider documentation on file. This underpins every other obligation.
- Human oversight that is real, not nominal. Defined points where a person can review, approve, or intervene in a high-risk workflow — with the authority and information to do so meaningfully. On-premises deployment lets you place oversight gates exactly where policy requires. See Human Oversight in AI Systems.
- Automatic logging, retained. High-risk systems generate logs; deployers must keep them. Owning the log store means retention, access control, and integrity are yours to set — covered in AI Agent Observability: Logs, Traces, and Audit Trails.
- Traceability of decisions. The ability to reconstruct what a system did, on which data, using which model, and who approved the outcome — the decision-receipt pattern turns raw logs into reviewable records.
- Monitoring and incident reporting. Operational monitoring that can surface serious incidents and malfunctions in time to report them, with a defined path for doing so.
- Documentation that assembles into evidence. The classifications, oversight designs, logs, and provider records need to come together into a coherent pack when an authority asks — the goal of the EU AI Act evidence pack approach, and the architecture behind it in EU AI Act-Ready On-Premises AI Architecture.
No platform delivers compliance out of the box, and none can guarantee it. What owning the infrastructure gives a deployer is direct control over the six capabilities above — the operational substance the obligations assume — rather than a dependency on a third party to produce your evidence for you.
How VDF AI supports deployer readiness
VDF AI is designed for private, on-premises, and air-gapped deployment, which keeps the logs, audit trails, human-oversight points, and documentation for high-risk systems inside infrastructure you control. VDF AI Networks and VDF AI Agents let you place human-in-the-loop approval gates where policy requires, record decisions as traceable receipts, and retain governed logs on your own terms. It does not make an organisation compliant — that depends on your classifications, controls, and documentation — but it provides the operational foundation those obligations assume.
Start from the two questions — your role and your risk category — build the control base now, and keep checking the consolidated text on EUR-Lex, since the Omnibus shows the timeline can still move.
Further reading
- Regulation (EU) 2026/1744 on EUR-Lex
- EU AI Act-Ready On-Premises AI Architecture
- Human Oversight in AI Systems: EU AI Act Requirements
- The EU AI Act Evidence Pack for On-Prem AI
- AI Decision Receipts for Regulated Workflows
Preparing for the high-risk phases? See VDF AI’s approach to governed on-premises AI or book a demo.