Overview checked on 15 September 2026
Start with the system and its use.
The EU AI Act sets rules according to risk and role. Providers and organisations using a system may have different obligations. Some practices are prohibited; some systems face high-risk or transparency requirements.
Qualification depends on the specific intended purpose. An internal policy, use inventory and documented reviews are governance tools: on their own, they are not universal proof of compliance.
A timeline with exceptions.
Initial prohibitions and AI literacy provisions.
General-purpose AI model rules.
General application, including transparency requirements, with exceptions.
Annex III high-risk system requirements under the revised timeline.
Requirements for high-risk systems embedded in Annex I products.
The AI Omnibus entered into force on 27 July 2026, changing high-risk timelines and simplifying AI literacy provisions. Transitional rules and the system’s context need to be checked.
Prepare a useful assessment.
Here is what I suggest gathering for an initial diagnostic:
- Current and planned uses, their purpose and their users.
- The suppliers, models and integrations involved.
- The data used and the people who could be affected.
- Existing rules, approvals and controls.
- Customer requests, deadlines and unresolved questions.
My role is then to organise this information, examine the scope and recommend priorities. Questions requiring a formal legal opinion are addressed with your advisers.
View diagnostics & pricingSources and scope
This guide provides general context. For a decision, consult the applicable texts and current guidance, then examine your situation.