EU AI Act training has a credibility problem. A large share of the material circulating online was written in 2024, describes obligations that have since moved, and still presents August 2026 as the date high-risk systems must comply. That date no longer holds. Regulation (EU) 2026/1744, in force from 27 July 2026, deferred the Annex III high-risk obligations to 2 December 2027 and the Annex I embedded product obligations to 2 August 2028. Training that gets this wrong sends people to prepare for the wrong deadline while ignoring duties that already bind them.
Our training is built around what applies today, what applies next, and what your organisation actually has to be able to show. The Act’s text is published under CC BY 4.0, so we quote and cite it directly rather than paraphrasing it into vagueness.
What is already in force
Article 5, the prohibited practices, has applied since 2 February 2025. These are the outright bans, including certain manipulative techniques, exploitation of vulnerability, social scoring by or on behalf of public authorities, and specified biometric uses. Breach of Article 5 carries the highest penalty tier in the Act, up to 35 million EUR or 7 percent of total worldwide annual turnover, whichever is higher. This is not a future risk, and it is the first thing our training makes people check against their own systems.
Article 4, the AI literacy duty, has also applied since 2 February 2025, with the enforcement and penalty machinery available from 2 August 2026. It requires providers and deployers to take measures to ensure a sufficient level of AI literacy among staff and others operating systems on their behalf, taking account of their technical knowledge, experience and the context of use.
General purpose AI model obligations have applied since August 2025. Article 50 transparency duties have applied since 2 August 2026, covering disclosure when a person is interacting with an AI system, marking of synthetic content, and disclosure of deep fakes and certain AI-generated text. Generative systems already on the market before that date must carry machine-readable marking by 2 December 2026, which is a short runway for anyone who built content generation into a product and has not revisited it.
What comes next
High-risk classification under Annex III now bites on 2 December 2027, and Annex I embedded systems on 2 August 2028. The extra time is real, and it is not idle time. Annex III readiness means a risk management system, data governance for training and testing data, technical documentation, logging, human oversight design, accuracy and cybersecurity measures, and a conformity assessment route decided in advance. Organisations that treat December 2027 as a distant problem tend to discover late that the evidence they need had to be collected while the system was being built, not afterwards.
How we teach it
Training is organised by role rather than by article, because a procurement officer and an ML engineer need different parts of the same regulation. Executives get scope, penalties, and the decisions only they can make. Compliance and risk teams get classification, documentation duties and the conformity assessment routes. Technical teams get logging, oversight design, data governance and the evidence trail. Everyone gets the literacy baseline the Act requires.
The organising question throughout is whether a claim can be demonstrated rather than asserted. This comes from our own published work. Our register assurance programme scores public registers with the Register Integrity Index, and the recurring finding is that entries which regulation depends on frequently fail to resolve when checked. Compliance documentation fails in the same way, and an auditor who has learned to check will find it.
Frequently asked questions
Does the EU AI Act apply to UK companies? Yes, in defined circumstances. The Act reaches providers placing systems on the EU market wherever they are established, and deployers established outside the EU where the output of the system is used in the EU. A UK firm serving EU customers is usually in scope.
What are the penalties under the EU AI Act? The top tier applies to breaches of the Article 5 prohibitions, at up to 35 million EUR or 7 percent of total worldwide annual turnover, whichever is higher. Lower tiers apply to other obligations and to supplying incorrect information to authorities.
Was the high-risk deadline really moved? Yes. Regulation (EU) 2026/1744, in force from 27 July 2026, moved Annex III high-risk obligations to 2 December 2027 and Annex I embedded systems to 2 August 2028. Many published guides still show the earlier August 2026 date.
Do we need to do anything if we only use AI systems built by someone else? Yes. Deployers carry duties of their own, including the Article 4 literacy obligation, the Article 5 prohibitions, human oversight where a system is high-risk, and Article 50 disclosure where they generate or publish AI-generated content.
Is a general purpose model such as GPT or Claude regulated separately? Yes. General purpose AI model obligations sit apart from the risk classification of applications, and have applied since August 2025. Building on such a model does not transfer your own obligations to the model provider.
What has to be marked as AI-generated, and by when? Article 50 has required transparency since 2 August 2026, including marking of synthetic audio, image, video and text. Generative systems placed on the market before that date must carry machine-readable marking by 2 December 2026.
Next step
Our EU AI Act training runs as a structured course covering scope, prohibitions, literacy, GPAI, transparency and high-risk readiness, with role-specific routes for executives, compliance and technical teams. If you already hold a compliance position and want it tested rather than taught, our two-week AI assurance claim audit takes the claim you are relying on, checks whether the evidence supports it, and returns a written finding. Contact us through the site.