Six dates, one Article that lands on almost every SaaS product, and two high-risk annexes that were postponed — not cancelled.
General information for software and technology companies, not legal advice for your specific facts or jurisdiction — no lawyer-client relationship. See full terms.
Six binding dates carry the EU AI Act through 2028. The one to act on now is 2 August 2026: Article 50's transparency duties (AI disclosure, content marking, deepfake labelling) plus full enforcement power. Annex III high-risk obligations now land 2 December 2027, and Annex I high-risk obligations 2 August 2028 — both postponed once already, so build toward them rather than assuming more room appears.
Two of these were postponed once already — treat both as live, not distant.
Article 5's prohibited AI practices took effect, alongside the Act's scope and definitions — including the newer prohibitions on manipulative AI targeting children or vulnerable groups, and on AI-generated child-sexual-abuse-adjacent and non-consensual intimate-image-adjacent content.
General-purpose AI model provider obligations, the AI Office and national competent authorities, notified-body rules, and the confidentiality and penalty framework all became applicable.
The transparency obligations in Article 50 — the ones that actually reach most SaaS products — apply from this date, alongside the enforcement powers in Article 99. For most companies reading this, this is the date that matters most.
The technical-standards grace period for machine-readable AI-content marking closes, and the transitional arrangement for the newer Article 5 prohibitions ends.
Obligations for the standalone high-risk use-case list — employment and HR decisioning, credit scoring, biometric categorisation, law enforcement and similar — apply from this date, pushed back once already from the original 2 August 2026 date.
Obligations for AI embedded in products already regulated under EU product-safety law — medical devices, machinery, toys and similar — apply from this date, pushed back from the original 2 August 2027 date.
This is the part of the Act most software companies actually have to act on — regardless of whether anything they do counts as "high-risk."
Any system intended to interact directly with a natural person must make clear the person is talking to an AI, unless that's obvious from the circumstances to a reasonably well-informed user. A persistent label in the chat UI is the common approach for SaaS support and sales bots.
AI-generated or manipulated audio, image, video or text must carry a machine-readable marking identifying it as artificially generated — unless it's undergone only assistive editorial changes, or is evidently part of an artistic, creative, satirical or fictional work.
Deployers of emotion-recognition or biometric-categorisation systems must inform the natural persons exposed to them — a notice requirement most companies embedding these features from a vendor don't realise sits with them, not the vendor.
AI-generated or manipulated image, audio or video content that resembles real people, objects, places or events must be disclosed as artificially generated or manipulated, with a lighter-touch disclosure for evidently artistic or satirical works, and exceptions for authorised law-enforcement use.
The question that comes up most in practice isn’t whether a company is “high-risk” — it’s whether it even knows what its own AI vendors have quietly made it responsible for. Map deployer obligations before worrying about Annex III; for most SaaS companies, Article 50 is the one that actually bites first, and it bites in 2026.
You run a customer-support chatbot for a B2B SaaS product, and use a generative-AI tool to draft marketing images and voiceovers. From 2 August 2026: the chatbot needs a clear, persistent "you're talking to an AI" disclosure unless it's obvious from context, and the generated images and voiceovers need machine-readable provenance marking before they go out under your brand. Penalty exposure for getting the Article 5 prohibited-practices list wrong: up to €35M or 7% of global annual turnover, whichever is higher. For Article 50 transparency misses specifically: up to €15M or 3% of turnover — still not a rounding error for a Series A company.
Core obligations: Regulation (EU) 2024/1689 (the EU AI Act), Articles 5, 50 and 99 — full consolidated text on EUR-Lex. The Annex III and Annex I dates reflect the postponement adopted through the European Commission's 2025–2026 simplification review — treat AI Office implementation guidance as the live source, since a regulation-level date and Commission guidance can diverge until formally consolidated. Current as of 21 July 2026 — verify against the AI Office's official timeline before a board or funding deadline turns on it.
Need a defensible position, not just the dates?
Yes. It applies to any provider or deployer placing an AI system on the EU market, or whose system's output is used in the EU, regardless of where the company is established (Article 2) — the same extraterritorial logic as GDPR.
A provider develops an AI system (or has one developed) and places it on the market under its own name; a deployer uses an AI system under its authority in a professional context. Most SaaS companies embedding a third-party model are deployers for that model, but providers of their own AI-enabled feature built on top of it.
No. Most SaaS chatbot or copilot features are minimal- or limited-risk, meaning Article 50 transparency duties only. High-risk status attaches to the specific listed use-cases in Annex III — employment and HR decisioning, credit scoring, biometric categorisation, and similar. Check the annex; don't assume.
Enforcement powers — audits, orders, fines — become active from that date under Article 99. A missed Article 50 disclosure is a live compliance gap from day one, not a future one.
30 minutes, fixed fee, with the person who does the work — not a sales call.