Skip to content
← All resources
For software and technology companies · EU AI Act

The EU AI Act deadlines that actually bind you.

Six dates, one Article that lands on almost every SaaS product, and two high-risk annexes that were postponed — not cancelled.

Xprofesso · Resources~7 min readCurrent as of August 2026Cited to source

General information for software and technology companies, not legal advice for your specific facts or jurisdiction — no lawyer-client relationship. See full terms.

The timeline

Six dates. Not one.

Two of these were postponed once already — treat both as live, not distant.

2 FEB 2025 · LIVE

Prohibited practices and scope

Article 5's prohibited AI practices took effect, alongside the Act's scope and definitions — including the newer prohibitions on manipulative AI targeting children or vulnerable groups, and on AI-generated child-sexual-abuse-adjacent and non-consensual intimate-image-adjacent content.

2 AUG 2025 · LIVE

GPAI models and governance

General-purpose AI model provider obligations, the AI Office and national competent authorities, notified-body rules, and the confidentiality and penalty framework all became applicable.

2 AUG 2026 · LIVE

Article 50 transparency + enforcement

The transparency obligations in Article 50 — the ones that actually reach most SaaS products — have been in force since 2 August 2026, alongside the enforcement powers in Article 99. For most companies reading this, this is the obligation set that binds today.

2 DEC 2026

Watermarking grace period ends

The technical-standards grace period for machine-readable AI-content marking closes, and the transitional arrangement for the newer Article 5 prohibitions ends.

2 DEC 2027 · POSTPONED

Annex III high-risk systems

Obligations for the standalone high-risk use-case list — employment and HR decisioning, credit scoring, biometric categorisation, law enforcement and similar — apply from this date, pushed back once already from the original 2 August 2026 date.

2 AUG 2028 · POSTPONED

Annex I high-risk systems

Obligations for AI embedded in products already regulated under EU product-safety law — medical devices, machinery, toys and similar — apply from this date, pushed back from the original 2 August 2027 date.

Article 50, unpacked

The obligation that lands on almost every SaaS product.

This is the part of the Act most software companies actually have to act on — regardless of whether anything they do counts as "high-risk."

OBLIGATION 1

Disclose that it's AI

Any system intended to interact directly with a natural person must make clear the person is talking to an AI, unless that's obvious from the circumstances to a reasonably well-informed user. A persistent label in the chat UI is the common approach for SaaS support and sales bots.

OBLIGATION 2

Mark synthetic content

AI-generated or manipulated audio, image, video or text must carry a machine-readable marking identifying it as artificially generated — unless it's undergone only assistive editorial changes, or is evidently part of an artistic, creative, satirical or fictional work.

OBLIGATION 3

Notify for emotion and biometric systems

Deployers of emotion-recognition or biometric-categorisation systems must inform the natural persons exposed to them — a notice requirement most companies embedding these features from a vendor don't realise sits with them, not the vendor.

OBLIGATION 4

Label deepfakes

AI-generated or manipulated image, audio or video content that resembles real people, objects, places or events must be disclosed as artificially generated or manipulated, with a lighter-touch disclosure for evidently artistic or satirical works, and exceptions for authorised law-enforcement use.

Specialist note

The question that comes up most in practice isn’t whether a company is “high-risk” — it’s whether it even knows what its own AI vendors have quietly made it responsible for. Map deployer obligations before worrying about Annex III; for most SaaS companies, Article 50 is the one that actually bites first, and it bites in 2026.

In practice

A worked example.

IN
PRACTICE

You run a customer-support chatbot for a B2B SaaS product, and use a generative-AI tool to draft marketing images and voiceovers. From 2 August 2026: the chatbot needs a clear, persistent "you're talking to an AI" disclosure unless it's obvious from context, and the generated images and voiceovers need machine-readable provenance marking before they go out under your brand. Penalty exposure for getting the Article 5 prohibited-practices list wrong: up to €35M or 7% of global annual turnover, whichever is higher. For Article 50 transparency misses specifically: up to €15M or 3% of turnover — still not a rounding error for a Series A company.

Sources & dating

Cited, not guessed.

Core obligations: Regulation (EU) 2024/1689 (the EU AI Act), Articles 5, 50 and 99 — full consolidated text on EUR-Lex. The Annex III and Annex I dates reflect Regulation (EU) 2026/1744, the Digital Omnibus on AI, published in the Official Journal on 24 July 2026 and in force since 27 July. Checked 2 August 2026: the Commission’s own AI Act Service Desk timeline still showed the superseded dates and described the Omnibus as a proposal — check it yourself. Where guidance and the regulation diverge, the regulation governs. No consolidated text of the amended AI Act had been published at that date, which is why the amending regulation is cited here rather than a consolidated Article 113. Current as of August 2026.

Need a defensible position, not just the dates?

Questions

Before you act on this.

Does the AI Act apply if my company isn't based in the EU?

Yes. It applies to any provider or deployer placing an AI system on the EU market, or whose system's output is used in the EU, regardless of where the company is established (Article 2) — the same extraterritorial logic as GDPR.

What's the difference between a "provider" and a "deployer"?

A provider develops an AI system (or has one developed) and places it on the market under its own name; a deployer uses an AI system under its authority in a professional context. Most SaaS companies embedding a third-party model are deployers for that model, but providers of their own AI-enabled feature built on top of it.

Is using an LLM API in my product automatically "high-risk"?

No. Most SaaS chatbot or copilot features are minimal- or limited-risk, meaning Article 50 transparency duties only. High-risk status attaches to the specific listed use-cases in Annex III — employment and HR decisioning, credit scoring, biometric categorisation, and similar. Check the annex; don't assume.

What happens if I miss the 2 August 2026 deadline?

Enforcement powers — audits, orders, fines — become active from that date under Article 99. A missed Article 50 disclosure is a live compliance gap from day one, not a future one.

Want a founder-level read on your own setup?

20 minutes, free, with the person who does the work — a scoping call, not a sales call.