← All resources
For software and technology companies · EU AI Act

The EU AI Act deadlines that actually bind you.

Six dates, one Article that lands on almost every SaaS product, and two high-risk annexes that were postponed — not cancelled.

Xprofesso · Resources~7 min readCurrent as of 21 July 2026Cited to source

General information for software and technology companies, not legal advice for your specific facts or jurisdiction — no lawyer-client relationship. See full terms.

TL;DR

Six binding dates carry the EU AI Act through 2028. The one to act on now is 2 August 2026: Article 50's transparency duties (AI disclosure, content marking, deepfake labelling) plus full enforcement power. Annex III high-risk obligations now land 2 December 2027, and Annex I high-risk obligations 2 August 2028 — both postponed once already, so build toward them rather than assuming more room appears.

The timeline

Six dates. Not one.

Two of these were postponed once already — treat both as live, not distant.

2 FEB 2025 · LIVE

Prohibited practices and scope

Article 5's prohibited AI practices took effect, alongside the Act's scope and definitions — including the newer prohibitions on manipulative AI targeting children or vulnerable groups, and on AI-generated child-sexual-abuse-adjacent and non-consensual intimate-image-adjacent content.

2 AUG 2025 · LIVE

GPAI models and governance

General-purpose AI model provider obligations, the AI Office and national competent authorities, notified-body rules, and the confidentiality and penalty framework all became applicable.

2 AUG 2026 · LIVE NOW

Article 50 transparency + enforcement

The transparency obligations in Article 50 — the ones that actually reach most SaaS products — apply from this date, alongside the enforcement powers in Article 99. For most companies reading this, this is the date that matters most.

2 DEC 2026

Watermarking grace period ends

The technical-standards grace period for machine-readable AI-content marking closes, and the transitional arrangement for the newer Article 5 prohibitions ends.

2 DEC 2027 · POSTPONED

Annex III high-risk systems

Obligations for the standalone high-risk use-case list — employment and HR decisioning, credit scoring, biometric categorisation, law enforcement and similar — apply from this date, pushed back once already from the original 2 August 2026 date.

2 AUG 2028 · POSTPONED

Annex I high-risk systems

Obligations for AI embedded in products already regulated under EU product-safety law — medical devices, machinery, toys and similar — apply from this date, pushed back from the original 2 August 2027 date.

Article 50, unpacked

The obligation that lands on almost every SaaS product.

This is the part of the Act most software companies actually have to act on — regardless of whether anything they do counts as "high-risk."

OBLIGATION 1

Disclose that it's AI

Any system intended to interact directly with a natural person must make clear the person is talking to an AI, unless that's obvious from the circumstances to a reasonably well-informed user. A persistent label in the chat UI is the common approach for SaaS support and sales bots.

OBLIGATION 2

Mark synthetic content

AI-generated or manipulated audio, image, video or text must carry a machine-readable marking identifying it as artificially generated — unless it's undergone only assistive editorial changes, or is evidently part of an artistic, creative, satirical or fictional work.

OBLIGATION 3

Notify for emotion and biometric systems

Deployers of emotion-recognition or biometric-categorisation systems must inform the natural persons exposed to them — a notice requirement most companies embedding these features from a vendor don't realise sits with them, not the vendor.

OBLIGATION 4

Label deepfakes

AI-generated or manipulated image, audio or video content that resembles real people, objects, places or events must be disclosed as artificially generated or manipulated, with a lighter-touch disclosure for evidently artistic or satirical works, and exceptions for authorised law-enforcement use.

Specialist note

The question that comes up most in practice isn’t whether a company is “high-risk” — it’s whether it even knows what its own AI vendors have quietly made it responsible for. Map deployer obligations before worrying about Annex III; for most SaaS companies, Article 50 is the one that actually bites first, and it bites in 2026.

In practice

A worked example.

IN
PRACTICE

You run a customer-support chatbot for a B2B SaaS product, and use a generative-AI tool to draft marketing images and voiceovers. From 2 August 2026: the chatbot needs a clear, persistent "you're talking to an AI" disclosure unless it's obvious from context, and the generated images and voiceovers need machine-readable provenance marking before they go out under your brand. Penalty exposure for getting the Article 5 prohibited-practices list wrong: up to €35M or 7% of global annual turnover, whichever is higher. For Article 50 transparency misses specifically: up to €15M or 3% of turnover — still not a rounding error for a Series A company.

Sources & dating

Cited, not guessed.

Core obligations: Regulation (EU) 2024/1689 (the EU AI Act), Articles 5, 50 and 99 — full consolidated text on EUR-Lex. The Annex III and Annex I dates reflect the postponement adopted through the European Commission's 2025–2026 simplification review — treat AI Office implementation guidance as the live source, since a regulation-level date and Commission guidance can diverge until formally consolidated. Current as of 21 July 2026 — verify against the AI Office's official timeline before a board or funding deadline turns on it.

Need a defensible position, not just the dates?

Questions

Before you act on this.

Does the AI Act apply if my company isn't based in the EU?

Yes. It applies to any provider or deployer placing an AI system on the EU market, or whose system's output is used in the EU, regardless of where the company is established (Article 2) — the same extraterritorial logic as GDPR.

What's the difference between a "provider" and a "deployer"?

A provider develops an AI system (or has one developed) and places it on the market under its own name; a deployer uses an AI system under its authority in a professional context. Most SaaS companies embedding a third-party model are deployers for that model, but providers of their own AI-enabled feature built on top of it.

Is using an LLM API in my product automatically "high-risk"?

No. Most SaaS chatbot or copilot features are minimal- or limited-risk, meaning Article 50 transparency duties only. High-risk status attaches to the specific listed use-cases in Annex III — employment and HR decisioning, credit scoring, biometric categorisation, and similar. Check the annex; don't assume.

What happens if I miss the 2 August 2026 deadline?

Enforcement powers — audits, orders, fines — become active from that date under Article 99. A missed Article 50 disclosure is a live compliance gap from day one, not a future one.

Want a founder-level read on your own setup?

30 minutes, fixed fee, with the person who does the work — not a sales call.