Versatile AI Risk Assessment

EU AI Act obligations by role, risk class and deadline

The obligations relevant to your organisation depend on your role and the risk class of the AI system. The obligations compass helps you review the mapped requirements and deadlines. Switch between compass, timeline and table; your selection is retained and can be saved as a PDF.

Legal status

What applies, and what changed on 27 July 2026

Legal status: 6 September 2026. Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. 62 obligations, 7 roles, 7 risk classes.

Regulation (EU) 2026/1744 changed, among other provisions, the application dates for high‑risk AI systems. The following overviews reflect these amendments and show which requirements already apply and which are still to come.

27 July 2026Regulation (EU) 2026/1744 in force
Deferred
High-risk under Annex III

Instead of 2 August 2026, the requirements and obligations of Chapter III Sections 1 to 3 now apply from 2 December 2027.

Deferred
High-risk under Annex I

For AI in regulated products the same block of obligations applies from 2 August 2028.

New
Two additional prohibitions

Non-consensual intimate depictions and child sexual abuse material are expressly prohibited from 2 December 2026.

Unchanged
Prohibitions, transparency and GPAI

The prohibitions have applied since February 2025, the obligations for general-purpose AI models since August 2025, and the transparency obligations from August 2026.

In this data set 15 of the 62 obligations are affected by the amending regulation; they carry a note in the compass, on the timeline and in the list.

Deadlines of the EU AI Act

The eight dates of the EU AI Act under Regulation (EU) 2026/1744

Date What applies from then on Status today
Chapters I and II: definitions, AI literacy and the prohibitions applies since this day
Chapter V: general-purpose AI models, plus governance and penalties applies since this day
General start of application: transparency obligations, conformity assessment, registration, post-market monitoring applies since this day
The two new prohibitions and the marking of generative systems already placed on the market still ahead
General-purpose AI models placed on the market before 2 August 2025 still ahead
Requirements and obligations for high-risk systems under Annex III still ahead
Requirements and obligations for high-risk systems under Annex I still ahead
Legacy high-risk systems used by public authorities still ahead

The timeline shows for each date which obligations of your role and risk class begin on that day: To the timeline

Questions and answers

Frequently asked questions about the EU AI Act

When do the obligations for high‑risk AI systems apply?

For high‑risk systems under Annex III, the requirements and obligations of Chapter III Sections 1 to 3 apply from 2 December 2027; for high‑risk systems under Annex I they apply from 2 August 2028. These dates reflect the amendments introduced by Regulation (EU) 2026/1744. The timeline shows for each date which obligations of your role begin on that day. To the timeline

What changed in the EU AI Act on 27 July 2026?

On that day Regulation (EU) 2026/1744 entered into force. It defers the application of the high‑risk obligations to 2 December 2027 for Annex III and 2 August 2028 for Annex I, adds two prohibitions that apply from 2 December 2026, and amends Articles 4, 6, 10, 11 and 25, among others. The compass can be narrowed to the obligations affected by the amendment. Amended obligations in the compass

What are the obligations of a deployer of AI systems?

Anyone using a high‑risk system under their own authority uses it in accordance with the instructions for use, assigns human oversight to suitable persons, ensures input data fits the intended purpose, keeps the logs and informs the workers concerned (Art. 26). Certain deployers also carry out a fundamental rights impact assessment (Art. 27). Irrespective of the risk class, supporting AI literacy (Art. 4) and the transparency obligations (Art. 50) apply. The compass lists all deployer obligations by date. Deployer obligations in the compass

Which prohibitions are added in December 2026?

From 2 December 2026 two further practices are expressly prohibited: AI systems that generate or manipulate intimate depictions of an identifiable person without their consent, and AI systems that generate child sexual abuse material. The other prohibitions of Art. 5 have applied since 2 February 2025 and are unaffected by the amendment. The timeline shows the obligations of all roles for this date. To the date on the timeline

When does a deployer become a provider?

Under Art. 25(1), anyone who puts their name or trademark on a high‑risk system already placed on the market, substantially modifies it, or changes the intended purpose of a system such that it becomes high‑risk is considered the provider of that system. You then bear all provider obligations, from risk management to conformity assessment, and the original provider has to support you with documentation and access. The compass describes the check with action step and evidence. To the check in the compass

Does the AI literacy obligation also apply to small companies?

Yes. Art. 4 has applied since 2 February 2025 to all providers and deployers of AI systems, regardless of size and risk class. Regulation (EU) 2026/1744 recast the provision: what is required are measures that support the development of staff AI literacy; no one has to guarantee a particular level of competence for any individual. Prior knowledge, training and the context of use are to be taken into account. The compass describes the obligation with action step and evidence. To the obligation in the compass

The compass

Choose your role and the risk class of your system. The compass lists mapped obligations by application date, with the legal basis, implementation guidance and possible evidence.

  • Obligations by date, in force or still ahead
  • Source of every reference at EUR‑Lex
  • Selection shareable as a link, view as PDF
Compass open

20 obligations for Deployer, High-risk under Annex III

2 February 2025 already applies 1 obligation

Chapters I and II: definitions, AI literacy and the prohibitions

Support the AI literacy of your staff Art. 4amended 2026

2 August 2026 already applies 3 obligations

General start of application: transparency obligations, conformity assessment, registration, post-market monitoring

Disclose emotion recognition and biometric categorisation Art. 50 Abs. 3

What the regulation requires: Deployers of an emotion recognition system or a biometric categorisation system must inform the persons exposed to it about its operation and process the personal data in accordance with data protection law.

Implementation guidance: Assess the permissibility of the intended use before deployment. Pay particular attention to the general prohibition on emotion recognition at work and in education, and the exceptions for medical and safety reasons.

Possible evidence: Information provided to those affected, data protection legal basis, assessment against Art. 5.

Reference Chapter IV, Art. 50 Abs. 3
i

Full text at EUR-Lex, opens in a new tab:

Label deepfakes and published AI texts Art. 50 Abs. 4

What the regulation requires: Deployers who generate or manipulate deepfakes with an AI system must disclose that the content has been artificially generated or manipulated. Those publishing text to inform the public on matters of public interest must also disclose this, unless the content has undergone human review with editorial responsibility.

Implementation guidance: Define how labelling is applied in each publication channel. Account for the specific rules for art and satire. For text, assess and document the conditions for an exception based on human review and editorial responsibility.

Possible evidence: Labelling rule per channel, arrangement for editorial responsibility.

Threats in the catalogue that this obligation touches:

Reference Chapter IV, Art. 50 Abs. 4
i

Full text at EUR-Lex, opens in a new tab:

Explain decisions on request Art. 86

What the regulation requires: Affected persons have a right to obtain a clear and meaningful explanation from the deployer where a decision is taken on the basis of the output of an Annex III system and produces legal effects or significantly and adversely affects their health, safety or fundamental rights. Systems under Annex III point 2 are excluded. The explanation must cover the role of the system in the decision-making procedure and the main elements of the decision.

Implementation guidance: Prepare understandable explanations for the relevant use cases. Use the provider’s information and define how requests for explanation are handled and adapted to the individual case.

Possible evidence: Explanation template, handling path and deadline for requests.

Reference Chapter IX Section 4, Art. 86
i

Full text at EUR-Lex, opens in a new tab:

2 December 2027 still ahead 15 obligations

Requirements and obligations for high-risk systems under Annex III

Document the classification with reasons Art. 6, Art. 6 Abs. 3amended 2026

What the regulation requires: Whether a system is high-risk is determined under Art. 6. Anyone relying on the exemption in Art. 6(3), because the system performs only a narrow, preparatory or supporting task, must document that assessment before the system is placed on the market or put into service.

Implementation guidance: For each system, document which Annex III areas you assessed and how you reached the classification. Record the date and responsible person. This reasoning provides the basis for identifying the applicable obligations.

Possible evidence: Classification record per system with legal reference, reasoning, date and responsible person.

Amendment by Reg. 2026/1744: Regulation (EU) 2026/1744 added paragraphs 1a to 1c to Art. 6. Systems used exclusively for non-safety-relevant aspects such as user assistance, performance optimisation or usability are not considered safety components. Conversely, a system remains a safety component where its failure or malfunction would endanger health and safety.

Reference Chapter III Section 1, Art. 6, Art. 6 Abs. 3
i

Full text at EUR-Lex, opens in a new tab:

Check whether you become a provider Art. 25 Abs. 1

What the regulation requires: Anyone who puts their name or trademark on a high-risk system already placed on the market, makes a substantial modification to it, or changes its intended purpose such that it becomes high-risk, is considered the provider of that system and bears the full provider obligations.

Implementation guidance: Before marketing a system under your own name, substantially modifying it or changing its intended purpose, assess whether your organisation assumes the provider role. Account for the resulting obligations during planning.

Possible evidence: Record for each modification: nature of the change, assessment under Art. 25(1), outcome.

Reference Chapter III Section 3, Art. 25 Abs. 1
i

Full text at EUR-Lex, opens in a new tab:

Use the system in line with the instructions Art. 26 Abs. 1

What the regulation requires: Deployers take appropriate technical and organisational measures to ensure they use the systems in accordance with the instructions for use accompanying them.

Implementation guidance: Compare the instructions for use with the planned deployment before introduction. Where use differs from the intended purpose, assess whether the legal classification or your organisation’s role changes.

Possible evidence: Record comparing the intended purpose with the planned use, internal usage rule.

Reference Chapter III Section 3, Art. 26 Abs. 1
i

Full text at EUR-Lex, opens in a new tab:

Assign human oversight to suitable people Art. 26 Abs. 2

What the regulation requires: Human oversight must be assigned to natural persons who have the necessary competence, training and authority, and who receive the necessary support.

Implementation guidance: Appoint the persons responsible for oversight and document their intervention powers. Ensure they have sufficient knowledge, support and authority to intervene effectively when needed.

Possible evidence: Designation of the persons exercising oversight, evidence of competence, written authority to intervene.

Reference Chapter III Section 3, Art. 26 Abs. 2
i

Full text at EUR-Lex, opens in a new tab:

Ensure suitable input data Art. 26 Abs. 4

What the regulation requires: In so far as the deployer exercises control over the input data, they must ensure that it is relevant and sufficiently representative in view of the intended purpose of the system.

Implementation guidance: Assess the suitability and representativeness of input data under your control. Pay particular attention to potential bias in your own datasets, such as personnel records or earlier decisions.

Possible evidence: Description of the input data, assessment of suitability and representativeness.

Reference Chapter III Section 3, Art. 26 Abs. 4
i

Full text at EUR-Lex, opens in a new tab:

Monitor operation and suspend on risk Art. 26 Abs. 5

What the regulation requires: Deployers monitor operation on the basis of the instructions for use. Where they identify a risk within the meaning of Art. 79(1), they must immediately inform the provider or distributor and the market surveillance authority and suspend use. In the event of a serious incident, they must inform the provider first, then the importer or distributor and the authority.

Implementation guidance: Define criteria for identifying risks and initiating action. Determine who decides to suspend operation and how the provider and competent authorities are informed.

Possible evidence: Monitoring rule with thresholds, escalation path, documented notifications.

Threats in the catalogue that this obligation touches:

and 1 more in the catalogue

Reference Chapter III Section 3, Art. 26 Abs. 5
i

Full text at EUR-Lex, opens in a new tab:

Keep the logs for at least six months Art. 26 Abs. 6

What the regulation requires: In so far as the automatically generated logs are under the control of the deployer, they must be kept for at least six months, unless other law provides otherwise.

Implementation guidance: Clarify with the provider who stores the logs and how you can access them. Align technical settings and contractual arrangements with the required retention period, particularly for cloud services.

Possible evidence: Contractual assurance of log access, documented retention period.

Reference Chapter III Section 3, Art. 26 Abs. 6
i

Full text at EUR-Lex, opens in a new tab:

Inform workers and their representatives in advance Art. 26 Abs. 7

What the regulation requires: Employers putting a high-risk system into service at the workplace must inform workers representatives and the affected workers in advance that they will be subject to the use of the system.

Implementation guidance: Plan to inform affected workers and their representatives before putting the system into service. Also assess the applicable participation rights under national employment law.

Possible evidence: Information notice with date, evidence of involvement of the representative body.

Reference Chapter III Section 3, Art. 26 Abs. 7
i

Full text at EUR-Lex, opens in a new tab:

Register in the EU database as a public authority Art. 26 Abs. 8, Art. 49 Abs. 3

What the regulation requires: Deployers that are public authorities or Union institutions, bodies, offices or agencies must register in the EU database before putting into service or using an Annex III system and must register the system there; systems under Annex III point 2, that is safety components of critical infrastructure, are excluded. Union institutions and bodies must not use an unregistered system under Art. 26(8) and must inform the provider or distributor.

Implementation guidance: Check the required EU database entries before putting the system into service. Resolve missing or incomplete provider information during procurement and document the result.

Possible evidence: Registration entry, verification of the provider entry before going live.

Reference Chapter III Section 3, Art. 26 Abs. 8, Art. 49 Abs. 3
i

Full text at EUR-Lex, opens in a new tab:

Use the information for the data protection impact assessment Art. 26 Abs. 9

What the regulation requires: Where applicable, deployers use the information received under Art. 13 to comply with their obligation to carry out a data protection impact assessment under Art. 35 GDPR or Art. 27 of Directive (EU) 2016/680.

Implementation guidance: Include the relevant provider information in the data protection impact assessment. Link the documents clearly, particularly information on performance limitations and known failure modes.

Possible evidence: Data protection impact assessment referencing the provider information.

Reference Chapter III Section 3, Art. 26 Abs. 9
i

Full text at EUR-Lex, opens in a new tab:

Obtain authorisation for post-remote biometric identification Art. 26 Abs. 10

What the regulation requires: Anyone using a post-remote biometric identification system in the course of an investigation must request authorisation from a judicial or administrative authority in advance or without undue delay, and at the latest within 48 hours. If authorisation is refused, use must stop immediately and the data must be deleted. Every use is documented, and annual reports on use must be submitted to the market surveillance authority and the data protection authority.

Implementation guidance: Set up an authorisation process that accounts for the applicable deadlines outside regular working hours. For each use, document the specific link to the investigation, the request, the decision and subsequent procedural steps.

Possible evidence: Authorisation requests and decisions, entry in the case file, annual report to the market surveillance and data protection authorities.

Amendment by Reg. 2026/1744: Use without any link to a criminal offence, criminal proceedings, a genuine threat or the search for a missing person is excluded. An adverse decision based solely on the output of the system is not permitted.

Reference Chapter III Section 3, Art. 26 Abs. 10
i

Full text at EUR-Lex, opens in a new tab:

Inform affected persons about the use Art. 26 Abs. 11

What the regulation requires: Deployers of an Annex III system that makes or assists in making decisions about natural persons must inform those persons that they are subject to the use of the system.

Implementation guidance: Place the notice where affected persons can see it in the relevant procedure, such as a job or credit application. Assess whether general privacy information is sufficient or targeted information is needed.

Possible evidence: Wording and placement of the notice per process.

Reference Chapter III Section 3, Art. 26 Abs. 11
i

Full text at EUR-Lex, opens in a new tab:

Cooperate with the authorities Art. 26 Abs. 12, Art. 21

What the regulation requires: On a reasoned request from the competent authorities, all information and documentation necessary to demonstrate conformity must be provided, in one of the official languages of the Union.

Implementation guidance: Clarify which language the competent authority requires for the documents. Agree with suppliers on timely provision of the required information and translations.

Possible evidence: Named point of contact, complete documentation in the required language.

Reference Chapter III Section 3, Art. 26 Abs. 12, Art. 21
i

Full text at EUR-Lex, opens in a new tab:

Carry out the fundamental rights impact assessment Art. 27amended 2026

What the regulation requires: Before putting the system into service, certain deployers must carry out a fundamental rights impact assessment: bodies governed by public law, private entities providing public services, and deployers of systems under Annex III point 5(b) and (c), that is creditworthiness assessment and risk assessment and pricing in life and health insurance. Systems under Annex III point 2 are excluded. It must describe the processes, the period and frequency of use, the categories of persons affected, the risks of harm, oversight measures and remedies.

Implementation guidance: First assess whether your organisation and the intended use fall within the obligation. Plan the assessment and the required notification to the competent market surveillance authority before putting the system into service.

Possible evidence: Completed fundamental rights impact assessment, notification to the market surveillance authority.

Amendment by Reg. 2026/1744: Regulation (EU) 2026/1744 reduced duplication: where a data protection impact assessment already covers the same points, its relevant sections may be incorporated by reference or as an extract. The AI Office is to develop a model questionnaire for this, including as an automated tool.

Reference Chapter III Section 3, Art. 27
i

Full text at EUR-Lex, opens in a new tab:

Legacy systems are caught only on substantial change Art. 111 Abs. 2amended 2026

What the regulation requires: For high-risk systems placed on the market or put into service before Chapter III becomes applicable, the regulation applies only if they are subsequently significantly changed in their design. The prohibitions in Art. 5 remain unaffected.

Implementation guidance: For each legacy system, document when it was placed on the market or put into service and its design at that time. Record subsequent changes so the applicability of the transition rule can be assessed.

Possible evidence: Inventory with a reference date per system and a change history.

Amendment by Reg. 2026/1744: Regulation (EU) 2026/1744 adjusted the reference point: what matters now is the start of application of Chapter III under Art. 113, that is 2 December 2027 for Annex III and 2 August 2028 for Annex I.

Reference Chapter XIII, Art. 111 Abs. 2
i

Full text at EUR-Lex, opens in a new tab:

2 August 2030 still ahead 1 obligation

Legacy high-risk systems used by public authorities

Bring public authority systems into line by 2030 Art. 111 Abs. 2 Satz 2

What the regulation requires: Providers and deployers of high-risk systems intended to be used by public authorities must in any event take the necessary steps to comply with the requirements and obligations of the regulation by 2 August 2030.

Implementation guidance: Identify the affected legacy systems and prepare an implementation plan for 2 August 2030. Account for required changes, procurement procedures and coordination with providers.

Possible evidence: Implementation plan per legacy system with milestones up to 2030.

Reference Chapter XIII, Art. 111 Abs. 2 Satz 2
i

Full text at EUR-Lex, opens in a new tab:

The timeline

Eight dates of the regulation. For each date the axis shows how many obligations of your selection begin on that day; the today marker moves with the calendar.

  • Own filter by role and class
  • A date opens its obligations
  • Note on the link between Annex I and Annex III
Timeline open

The full list

All 62 obligations as a table with roles, classes and dates. Every column can be sorted, every filter combined.

  • Search across title, reference and text
  • Filter per column: role, class, chapter, date
  • Export of the filtered table as PDF
Full list open
Related
EU AI Act quick check

Still unsure which risk class your system falls into? Four short sections lead to a first orientation.

To the quick check
EU‑KI‑VO‑Check

The full assessment as a free single module: guided down to the risk class, with 261 controls and evidence tracking.

See the module
Threat catalogue

The technical side of the obligations: 52 threats with mitigations and verified sources, for example on robustness and cybersecurity.

To the catalogue
Glossary

Provider, deployer, conformity assessment, GPAI: the terms behind the obligations, precisely explained.

To the glossary