The AI Act calendar, and which side of it you are on
Shared methods · A shared method; linked tool guides explain the exact steps.
This page covers tools outside your selection. You can still read it. Find matching guides
Transparency obligations under Article 50 came into force on 2 August 2026. Most organisations are deployers, and that changes which dates apply.
Most AI Act coverage is written for providers, which is why organisations that merely use AI read a great deal that does not apply to them and miss the two things that do.
Sort out which side you are on first. The calendar reads differently from each.
Provider or deployer
A provider develops an AI system or general-purpose model and places it on the market or puts it into service under their own name.
A deployer uses an AI system under their own authority.
If you bought one of these tools and use it for work, you are a deployer. Provider duties (conformity assessment, technical documentation, post-market monitoring) do not attach to you.
Two cautions before filing yourself under "deployer" and stopping:
You can become a provider without intending to. Putting your name on an AI system, or substantially modifying one and placing it on the market, moves you across the line. Building a product on top of an API and selling it is the common case.
And some obligations attach to deployers directly, which is the next section.
What is already in force
2 February 2025: AI literacy (Article 4). Deployers must ensure a sufficient level of AI literacy among staff and others operating AI systems on their behalf. In force for eighteen months now. See the literacy obligation.
2 August 2025: general-purpose AI model obligations. Provider-side. It affects you indirectly: it is part of why the models you use come with the documentation they do.
2 August 2026: transparency (Article 50). Providers and deployers of certain AI systems must meet transparency obligations. This is the most recent one to bite and the one least likely to be on an internal roadmap yet.
What Article 50 asks of a deployer
Article 50 splits by role. In broad terms:
Providers must design systems so people are informed when they are interacting directly with an AI system, and must apply machine-readable marking that allows AI-generated or manipulated content to be detected.
Deployers must inform people exposed to emotion recognition or biometric categorisation, and must disclose in the cases the Article specifies for generated or manipulated content.
For an ordinary organisation using AI internally, the practical question is narrower than the Article looks: does anything you run interact with people outside your organisation, or produce content presented to them? A support chatbot, an automated reply, published material generated by a system: those are where it bites. Purely internal drafting generally does not.
Check the Commission's own guidance for your case rather than reasoning from this summary. Article 50 has conditions and exceptions that a paragraph cannot carry.
What is still ahead
2 December 2026. Providers of systems generating synthetic content that were already on the market before 2 August 2026 must meet the marking and detection obligations from this date.
2 August 2027. Providers of general-purpose AI models placed on the market before that date must be compliant.
2 December 2027. Rules apply for systems used in certain high-risk areas, including biometrics, critical infrastructure, education, employment, migration, asylum and border control.
That last date is the one worth checking against your own use. Employment is on the list. A tool used in recruitment or in decisions about staff may fall into a high-risk category, and deployer duties there are heavier than anything above.
A short assessment, to adapt
- Confirm your role for each system. Deployer for most, and check whether anything you build and offer makes you a provider.
- List anything that faces people outside the organisation. That is where Article 50 lands today.
- Check the high-risk list against your actual uses, employment first.
- Record the reasoning and date it. The value of this exercise is being able to show you did it.
- Set a review date before December 2027 rather than on it.
What goes wrong
Reading provider guidance and concluding the whole thing applies. Most of it does not, and the fatigue that follows causes the two deployer duties to be missed.
Assuming transparency is a future problem. Article 50 has applied since 2 August 2026.
Missing that employment is a high-risk area. Recruitment and staff decisions are where an ordinary organisation most plausibly meets the heavier duties.
Becoming a provider by accident. Putting your name on a system, or substantially modifying one, changes the answer.
Treating a summary as the assessment. Including this one. The Commission publishes guidance for both roles; use it for anything consequential.
How to check it worked
Name one system you use, state your role for it, and name the specific obligation that follows. If the answer is a general sense that the AI Act applies, you have a topic rather than an assessment.
Sources
- Implementation timeline — EU Artificial Intelligence Act Tier 3 2026-08-31
- Transparency obligations under Article 50 — European Commission Tier 1 2026-08-31
- Guidelines for providers and deployers of high-risk AI systems — European Commission Tier 1 2026-08-31
Something wrong with this page?
Say what you expected and what you got. That is usually the shortest route to a correction, and it goes on the public issue tracker so the fix is visible.