Skip to content
All articles
AI regulation and governance

The EU AI Act in 2026: which dates have passed and which have moved

The Act became applicable on 2 August 2026. Two of its heaviest obligations did not. The Commission's own timeline now places the Annex III high-risk rules at 2 December 2027 and product-embedded high-risk at 2 August 2028.

By Bastion, Cluj-NapocaPublished 7 min read

"The AI Act applies now" is true and useless. The Act has a staircase of application dates, two of them have moved, and the obligation that reaches the most companies arrived quietly more than a year ago.

The dates, from the Commission's own timeline

The European Commission records that the Act “entered into force on 1 August 2024 and became applicable on 2 August 2026”.

Before that, two milestones had already passed: “prohibited AI practices and AI literacy obligations entered into application from 2 February 2025”, and “the governance rules and the obligations for GPAI models became applicable on 2 August 2025”.

Two have moved later. The Commission states that “the rules for high-risk use cases in certain sensitive areas (Annex III) have been extended to 2 December 2027”, and that “the rules for high-risk AI systems embedded into regulated products (Annex I) have an extended transition period until 2 August 2028”. Those extensions come from the AI Omnibus, which entered into force on 27 July 2026.

The obligation most companies already have

AI literacy is not a future item and it is not optional. Article 4 of the Regulation reads:

Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used.

Regulation (EU) 2024/1689, Article 4

Note the word deployers. A company that buys an assistant and gives it to its staff is a deployer. The duty is proportionate, it is tied to the context of use, and it has applied since 2 February 2025.

What a company should have written down

Before any classification argument, there has to be an inventory. For every AI system in use, record the purpose, the provider, the model, the data it processes, who uses it, where the processing happens, the risk classification, the contractual terms and the security controls.

Most organisations discover at this point that the list is longer than they expected, because features inside existing software also count.

You cannot classify what you have not listed. The inventory is the first deliverable, not the policy.

Private deployment does not create an exemption

The Regulation attaches to the AI system, its intended purpose and the role of the organisation. It does not attach to the rack the system sits in. Running the model on your own hardware does not change whether the use case is prohibited, high-risk or neither.

What a private deployment does change is the evidence. Where the processing happens, who can reach the model and which version is running become facts the organisation can state about its own site rather than facts it has to obtain from a supplier.

This timeline is still moving, so a classification decision should be checked against the current text rather than against a summary, including this one.

With Bastion

What Bastion changes

Bastion is a private AI system delivered as one sealed appliance that runs inside your building. One monthly fee covers the hardware, the model, the hardened operating system and support, and nothing your team types leaves the building.

Bastion does not make an AI system compliant and does not claim to. It makes several of the inventory fields answerable without a vendor questionnaire: the model and its version, the processing location, the access path and the update history.

The Article 4 duty stays with the deployer. A defined internal system makes it easier to discharge, because the training can describe one tool with one set of rules.

Questions this article answers

Does the EU AI Act apply in 2026?
Yes. The European Commission records that the Act entered into force on 1 August 2024 and became applicable on 2 August 2026. Prohibited practices and AI literacy obligations applied earlier, from 2 February 2025, and the GPAI rules from 2 August 2025.
When do the high-risk rules apply?
The Commission's current timeline places the Annex III high-risk rules at 2 December 2027, and high-risk AI embedded in regulated products at 2 August 2028. Both were extended by the AI Omnibus, which entered into force on 27 July 2026.
Does running AI on our own servers exempt us from the AI Act?
No. The Regulation attaches to the AI system, its intended purpose and the role of the organisation, not to the location of the hardware. What a private deployment changes is the evidence: model version, processing location and access path become facts about your own site.

On the record

  1. 1

    European Commission

    AI Act. Regulatory framework for AI

    read 2026-09-22

  2. 2