EN/IT

EU AI Act 2026: What Deployers Must Do, and When

WWG
Updated
Reading time8 min read
EU AI Act 2026: What Deployers Must Do, and When

If you buy AI features from software vendors rather than building models yourself, the EU AI Act asks far less of you than most compliance content suggests, and it asks it on dates that changed in July 2026. This guide sets out the current timeline and the specific duties that fall on a company using AI, as opposed to one selling it.

Are you a provider or a deployer under the EU AI Act?

The AI Act splits duties by role rather than by company size. A provider develops an AI system, or has one developed, and places it on the market or into service under its own name or trademark. A deployer uses an AI system under its own authority in the course of its business. The provider carries conformity assessment, technical documentation, quality management, registration and post-market monitoring. The deployer carries a much shorter set of mostly organisational duties.

Almost every European mid-sized enterprise adopting AI today is a deployer. You buy an assistant, a document-analysis tool or an AI feature inside your CRM, and the vendor is the provider. That distinction is worth establishing before anything else, because it is the difference between a proportionate control set and a compliance programme built for somebody else's risk.

There is one trap. If you put your own name on an AI system, substantially modify one, or change the purpose of a general-purpose system so that it becomes high-risk, the Act can treat you as a provider with the full obligation set attached. Fine-tuning a model and shipping it inside your own product is the common way a company crosses that line without noticing.

What are the EU AI Act deadlines after the Digital Omnibus?

The Act is Regulation (EU) 2024/1689, dated 13 June 2024 and published in the Official Journal on 12 July 2024. It was amended by the AI-focused Digital Omnibus, Regulation (EU) 2026/1744, published on 24 July 2026 and in force from 27 July 2026. Any compliance plan written before that amendment now has the wrong dates in it, which is worth checking if your roadmap was drawn up in 2025.

The timeline as it stands today:

  • Since 2 February 2025. The prohibitions on unacceptable AI practices apply, along with the AI literacy duty. The Omnibus softened that duty from ensuring a sufficient level of literacy to taking measures to support its development, which reduces the exposure created by any single untrained employee.
  • Since 2 August 2025. Governance rules and the obligations for general-purpose AI models apply.
  • From 2 August 2026. The transparency obligations in Article 50 apply. People must be told when they are interacting with an AI system, and synthetic content must be marked as machine-generated.
  • From 2 December 2026. A transitional deadline for certain Article 50(2) marking and detection duties covering systems already on the market before 2 August 2026, plus the new prohibitions on AI systems generating non-consensual intimate imagery and child sexual abuse material.
  • From 2 December 2027. Obligations for stand-alone high-risk systems in Annex III: biometrics, critical infrastructure, education, employment and worker management, access to essential services, law enforcement, migration and the administration of justice.
  • From 2 August 2028. Obligations for high-risk AI embedded as a safety component in products already regulated under Annex I legislation, such as medical devices and machinery.

The deferral of the high-risk deadlines buys planning time. It does not remove the requirement, and it does not help anyone deploying such a system in the meantime, because the controls still have to exist before the system reaches production rather than before the legal deadline.

The Omnibus also extended compliance relief previously reserved for SMEs to small mid-cap companies, defined as fewer than 750 employees and under 150 million euro in annual turnover. That threshold covers a large share of the European mid-market, and it is worth checking whether your company now qualifies for simplified documentation.

What does a deployer actually have to do?

For AI that is not high-risk, which covers most productivity and knowledge-work tools, the duties are light. You support AI literacy among the people who use the system, you comply with the Article 50 transparency rules where they apply to what you publish, and you handle personal data under the GDPR as you would anywhere else. That is the honest summary, and it is a long way from the compliance programme the market has been selling.

For high-risk systems, Article 26 sets out what a deployer must do, and it reads like operational hygiene rather than legal engineering. You use the system according to the provider's instructions for use. You assign human oversight to named people who have the competence, training and authority to actually intervene. Where you control the input data, you make sure it is relevant and sufficiently representative for the intended purpose. You monitor how the system behaves and inform the provider and the national authority when a risk or a serious incident appears. You keep the automatically generated logs for at least six months, longer where other law requires it. If you are an employer, you inform workers and their representatives before putting the system into service. And where the system is one of the Annex III cases affecting individuals, you tell the people subject to it that it is being used.

Two further points catch companies out. Deployers must use the information the provider supplies to complete their own data protection impact assessment under the GDPR, so the DPIA and the AI Act work are the same project rather than two. And under Article 27, a fundamental rights impact assessment is required from public bodies, private entities providing public services, and any deployer using the Annex III systems for creditworthiness assessment or for risk assessment and pricing in life and health insurance. If you are none of those, that assessment does not apply to you.

Where the AI Act meets your other obligations

The AI Act does not sit alone, and treating it as a separate track is how mid-market compliance programmes end up duplicated. The GDPR requires a data protection impact assessment where processing is likely to result in a high risk to individuals' rights and freedoms, which covers most AI use cases involving personal data, profiling, employee monitoring or automated decision support. That assessment belongs before production, not after the pilot impresses the board.

Sector rules add a further layer. Financial entities in scope of DORA, Regulation (EU) 2022/2554, applicable since 17 January 2025, and organisations in scope of NIS2, Directive (EU) 2022/2555, have to fit AI systems and their vendors into existing ICT risk-management, incident-reporting and third-party oversight regimes. In practice this means your AI vendor questionnaire should be the same document as your ICT third-party questionnaire, with a few AI-specific questions added.

The Data Act, Regulation (EU) 2023/2854, in force since 11 January 2024 and applicable since 12 September 2025, pushes in the same direction from the data side by strengthening rights over data generated by connected products and easing switching between cloud and edge providers. For AI integration the practical consequence is that portability and clear contractual description of data are no longer optional nice-to-haves.

A realistic first 90 days

None of this requires a transformation programme. It requires a register and a few decisions.

Start by listing the AI systems already in use, including the ones employees adopted without asking, and record for each one the vendor, the business owner, the data it touches and whether the use case falls into any Annex III category. That register is the single artefact everything else hangs from, and most companies discover during the exercise that they are using more AI than they thought and less high-risk AI than they feared.

Then classify your role for each entry, provider or deployer, and note anywhere you might be drifting towards provider status through fine-tuning or rebranding. Check the Article 50 transparency requirements against anything customer-facing you publish or generate, because that deadline has already passed. Run the AI literacy measures, which for most organisations means a short, documented training session rather than a certification programme. And where you find a genuine Annex III use case, use the time until December 2027 deliberately: assign the human oversight, define the logging, and write the impact assessment before the system goes live rather than before the deadline.

The companies that will struggle are not the ones with the most AI. They are the ones that cannot say which systems they run, who owns them and what data they touch. That is an inventory problem before it is a legal one, and it is the same inventory that makes AI integration work in the first place, which we cover in our guide to AI readiness for enterprise data.

This article reflects the law as it stood in August 2026 and is not legal advice. Talk to WWG IT if you want help mapping your AI systems, classifying your role and building the controls into the architecture rather than bolting them on afterwards.

Sources

FAQ

Frequently Asked Questions

Quick answers for teams planning website and web application budgets in 2026.

In 2026, basic professional websites can start in the low thousands, while custom B2B platforms and enterprise web applications can reach six figures. Scope, integrations, security, compliance and delivery model drive most of the difference.
Treat web development cost as a range, not a fixed commodity price. A small CMS site, e-commerce build and custom SaaS platform require different teams, timelines and risk controls, so they should not be benchmarked together.
Learning web development can cost nothing through documentation and open courses, or substantially more through paid bootcamps, university programmes and mentoring. The real investment is time, project practice and keeping skills current.
Professional web development usually costs more than DIY website builders because it includes discovery, UX, engineering, QA, security, deployment and support. For business-critical systems, that governance often matters more than the initial build price.
The practical answer depends on what you are building: a marketing site, transactional e-commerce platform, client portal, SaaS product or enterprise application. Define outcomes and integrations first, then estimate effort and risk.

Tell Us What's Broken

Mohamed Deramchi

Mohamed Deramchi

Founder & CEO of WWG

20+ years in IT leadership, product, and cloud consulting. Leads delivery strategy and senior technical direction.

Send Your Brief

By submitting you agree to our privacy policy.

Coesione Italia 21-27 Lombardia - Cofinanziato dall'Unione europea - Regione Lombardia