Government & Public Sector

The EU AI Act: What Technology Buyers Need to Know

Many vendor websites still say high-risk obligations landed on 2 August 2026. They didn't — the AI Omnibus pushed that date to December 2027. Here is what actually applies, and when.

Written by Gurubalan G.T. · · 3 min read

A timeline with several date markers, one clearly moved further along the line than the others, representing the deferred Annex III obligations under the AI Omnibus.
A timeline with several date markers, one clearly moved further along the line than the others, representing the deferred Annex III obligations under the AI Omnibus.

Get the dates on this wrong and you either over-comply expensively or under-comply dangerously. Here is where things actually stand, checked against the European Commission's own published position as of September 2026.

What is in force now

The AI Act (Regulation (EU) 2024/1689) reached its general date of application on 2 August 2026, and transparency obligations are now enforced from that date. Prohibitions on unacceptable-risk uses have applied since February 2025. General-purpose AI model obligations have applied since August 2025. (European Commission)

The date almost everyone has wrong

Many vendor websites and even some legal summaries still say the Act's high-risk system obligations (Annex III) took effect on 2 August 2026. They did not. The AI Omnibus, Regulation (EU) 2026/1744, deferred Annex III high-risk obligations to 2 December 2027, and Annex I high-risk obligations (AI as a safety component of regulated products) to 2 August 2028. (European Commission)

If a vendor tells you their high-risk AI system is already fully compliant with obligations that don't legally bite until December 2027, ask them to be specific about which obligations they mean — voluntary early compliance is a fine thing to claim, but it is a different claim from "this is already required."

What this means if you are buying

Confirm your risk tier before anything else. The Act's tiers — unacceptable, high, limited (transparency), minimal — determine which obligations apply and when. Most AI systems fall into the minimal-risk tier, where the Act imposes no specific rules at all.

If you're procuring anything that could be high-risk — systems touching employment decisions, access to essential services, biometric identification, or several other Annex III categories — you have until December 2027 for the substantive obligations, but building for them now costs less than retrofitting later.

Transparency obligations apply now, broadly. If your system interacts with people or generates synthetic content, transparency requirements — telling people they're interacting with AI, labelling AI-generated content — already apply as of August 2026, regardless of risk tier.

Ask any vendor for their risk classification of the specific system, not a general statement about "the company being AI Act compliant." Compliance is a property of a specific system's use case, not a blanket company certification, and a vendor who answers with the latter has not actually answered the question.

Why this keeps changing, and what to do about it

The Omnibus itself shows this framework is still being actively adjusted in response to implementation experience — the deferrals exist because the original timeline proved difficult in practice. That is a reasonable basis to expect further adjustment, not a reason to ignore the framework.

Build your contracts with a review clause tied to regulatory change, rather than assuming today's compliance position is permanent. A vendor unwilling to commit to updating their compliance posture as the Act evolves is asking you to absorb regulatory risk that should sit with whoever is selling the AI system.

Kaizen Spark Tech designs and delivers software, AI, automation and digital infrastructure for businesses and institutions. This guide is accurate as of September 2026 and is reviewed quarterly, because the underlying regulation is still moving. If you find something here that has changed since we last checked, tell us and we will correct it in public.

Government & Public SectorEU AI ActcomplianceregulationAI Omnibus
Considering a build? Describe the process and we will come back with a scope and a cost range — including if our view is that software is not the right answer. Get a range Message on WhatsApp