Prohibited
- Practices banned outright - e.g. workplace emotion recognition, social scoring, untargeted face scraping.
No, not everything slipped to 2027 - transparency duties apply from Aug 2, 2026
The AI Act applies to AI systems placed on the market or used in the EU. Your obligations depend on whether you are a provider (you build or supply the system) or a deployer (you use it) - and on which of four risk tiers your use case falls into.
Half the market believes "everything slipped to 2027". It did not - transparency obligations go live in weeks.
Ban on prohibited practices; AI-literacy duty (Art. 4) for all providers and deployers
General-purpose AI (GPAI) rules; governance framework; penalty regime
Art. 50 transparency: chatbot disclosure, deepfake labelling, notice of emotion recognition and biometric categorisation
Machine-readable marking (watermarking, Art. 50(2)) for providers of generative systems; new ban: non-consensual intimate images and CSAM
Obligations for standalone high-risk systems (Annex III) - moved from Aug 2026
Obligations for high-risk systems embedded in products (Annex I)
Grandfathering: high-risk systems placed on the market before their deadline are exempt from the full requirement package until substantially modified.
Yes. As a deployer you have your own obligations - lighter than a provider's, but real: transparency, human oversight, and for high-risk systems, monitoring and log retention.
Write to us by email or through the form, with your tool results or just your questions.
Write to us