EU AI Act · implementation
EU AI Act roadmap: your checklist for 2026 to 2028
2 August 2026 is not the deadline for high-risk AI. It is, in essence, the deadline for the transparency obligations under Art. 50; the high-risk obligations under Annex III only bite on 2 December 2027. The prohibitions, AI literacy and the GPAI obligations, by contrast, have applied for a while. More time does not mean no time: these six steps take you from inventory to demonstrable conformity — in the right order.
The actual deadlines
- Already applies (since 2 February 2025): prohibited practices (Art. 5) and AI literacy (Art. 4).
- Already applies (since 2 August 2025): obligations for general-purpose AI models (Art. 53–55), governance and penalties.
- 2 August 2026: transparency obligations under Art. 50 — for example labelling chatbots and AI-generated content. Systems already placed on the market before that date have a grace period until 2 December 2026.
- 2 December 2026: new prohibition on non-consensual intimate imagery and child sexual abuse material.
- 2 December 2027: high-risk obligations for stand-alone Annex III systems (Art. 8–27, 43 et seq., 49) — postponed from 2 August 2026.
- 2 August 2028: high-risk obligations for AI in products under Annex I product law — postponed from 2 August 2027.
So why start now? Classification and gap analysis take days; documentation, QMS and conformity assessment take weeks to months. Anyone starting in 2027 is starting too late — and Art. 4, Art. 5, GPAI and Art. 50 either already apply or are imminent.
1. Inventory
List every AI system in the company — built and bought. Nothing can be classified without a complete inventory.
2. Classification
Assign each system a risk class. The free risk check and the Annex III guide help here.
3. Gap analysis
Compare each high-risk system against the obligations (Art. 8–27) and document the gaps. This is exactly what KomplAI automates — every finding with a citation.
4. Documentation & QMS
Produce the technical documentation (Annex IV), set up logging (Art. 12) and a quality management system (Art. 17).
5. GDPR & DORA
If the system processes personal data, check the DPIA (Art. 35 GDPR) and automated decisions (Art. 22). Financial entities add DORA.
6. Ongoing monitoring
Conformity is not a one-off: post-market monitoring, incident reporting and regular re-checks when things change.
Frequently asked questions
Where should I start?
How long does implementation take?
How does KomplAI actually help?
Do I also need legal advice?
Last reviewed: 17 August 2026. This page previously named 2 August 2026 as the deadline for high-risk AI — that was wrong and is corrected here. Factual orientation, not legal advice. Citations: Regulation (EU) 2024/1689, as amended by the "Digital Omnibus on AI" (now Regulation (EU) 2026/1744, in force since 27 July 2026).