The Deployer Duties Timeline and What Applies Today

The EU AI Act did not come into force all at once. Different articles became binding on different dates. Deployers must understand which duties apply now and which will apply in the future. This timeline is critical because it affects your compliance planning and investment priorities.

Article 5 prohibitions on certain AI practices have been in force since 2 February 2025. These prohibitions apply to all AI systems regardless of risk level. Article 4 on AI literacy came into force at the same date, requiring affected sectors to train staff who work with AI systems. Article 50 on transparency obligations for general-purpose AI systems came into force on 2 August 2026. This means deployers using general-purpose AI systems must now ensure the system meets machine-readable marking requirements by 2 December 2026 if the system was already on the market before 2 August 2026.

The most important date for deployers using high-risk systems is 2 December 2027. This is when Regulation (EU) 2026/1744, the Digital Omnibus deferral, expires. Until that date, the most demanding deployer duties for high-risk systems are not yet binding. From 2 December 2027, deployers must ensure high-risk systems comply with Articles 8 to 27. For deployers, this means Articles 26 and 27 duties become mandatory, but many of the technical requirements in Articles 8 to 15 that providers must meet are not deployer obligations. Articles 26 and 27 are the core deployer articles, and they are now enforceable, though some specific requirements are transitional.

Article 26 requires deployers to use high-risk systems according to instructions provided by the provider and to assign human oversight to people with appropriate training and authority. Article 27 requires public authorities that use high-risk systems to conduct fundamental rights impact assessments and to inform affected people when a decision involves high-risk AI. These duties are already in force and apply to high-risk systems now.

For general-purpose AI systems, deployers have a different set of obligations under Article 50. If you deploy a general-purpose AI model, you must ensure it displays machine-readable marking by 2 December 2026. This marking will indicate whether the system meets EU requirements for transparency and disclosure.

Timeline in practice

A bank deploying a high-risk credit scoring system today must comply with Articles 26 and 27. The vendor should provide clear instructions for use and evidence that the system meets the requirements. The bank must assign human reviewers to overturn model decisions, keep records, and tell applicants when the system influenced the decision. These are not optional; they are binding now.

A public authority using a low-risk general-purpose AI tool for document summarisation must ensure the system has machine-readable marking by 2 December 2026. After that date, pre-existing systems without marking will not be compliant if they remain in use.

Deployers should distinguish between duties that are binding now and transitional arrangements. The distinction allows organisations to plan their compliance activity and prioritise urgent actions over longer-term programmes. Organisations that wait until 2 December 2027 to begin compliance will face crisis management and may not have time to implement all required controls.

Lesson concept diagram

Resource planning based on timeline

The timeline creates natural planning phases. Phase One runs from now until 2 August 2026, focused on high-risk systems using Articles 26 and 27. Phase Two runs from 2 August 2026 until 2 December 2026, when general-purpose AI systems must display marking. Phase Three runs from 2 December 2026 to 2 December 2027, preparing for the full implementation of high-risk duties. Phase Four begins 2 December 2027 when all high-risk system requirements take effect without deferral.

Organisations should assess their resource needs for each phase. Implementing human oversight for ten high-risk systems requires recruiting or training oversight staff. Implementing logging systems requires IT infrastructure and database work. Conducting impact assessments for public bodies requires external expertise. Planning resource allocation by phase prevents last-minute scrambling.

Future deadlines

Annex I embedded AI systems face a deferral until 2 August 2028. These are AI systems embedded in products or services that are not themselves AI products. Embedded AI might include a recommendation engine in a product app, predictive analytics in manufacturing equipment or AI safety checks in medical devices. The deferred date gives providers and deployers additional time to establish compliance for these categories. Deployers should be aware of which systems fall into Annex I so they can plan accordingly.

Organisations deploying embedded AI should begin preparation early. By the time 2 August 2028 arrives, all embedded AI systems will need to be compliant. Waiting until 2027 to begin compliance work on embedded systems will leave insufficient time for implementation and testing.