Who may be covered, and in which role?
The Act can cover providers placing AI systems or general-purpose AI models on the EU market, EU deployers, and providers or deployers outside the EU where a system’s output is used in the EU. Exclusions and special provisions apply; a US headquarters does not by itself remove the need to assess scope. AI Act, Article 2.
A provider develops or has a system developed and supplies it under its own name or trademark. A deployer uses a system under its authority, outside personal non-professional activity. Rebranding, a substantial modification or changing the intended purpose can change responsibilities. Record who supplies the model, who supplies the application and who operates the service. Articles 3 and 25.
Classify the intended use before treating a system as high-risk. Annex III includes specified uses such as employment and access to certain essential services; Article 6 contains the classification conditions and exceptions. General-purpose model obligations are a separate layer from application-level responsibilities. Commission overview.
What applies now, and what is upcoming?
The AI Omnibus is enacted: Regulation (EU) 2026/1744 entered into force on July 27, 2026. Use the amended timetable rather than the dates in the original Act alone. Amending regulation; Commission entry-into-force notice.
| Status | Date | Operational relevance |
|---|---|---|
| Already applicable | February 2, 2025 | General provisions and original prohibited practices; read AI literacy under the amended Article 4 below. |
| Already applicable | August 2, 2025 | General-purpose AI model rules, subject to transition provisions for existing models. |
| Already applicable | August 2, 2026 | Article 50 transparency rules and enforcement of applicable provisions. |
| Upcoming | December 2, 2026 | New prohibitions concerning specified sexual deepfake and child sexual abuse material systems; limited Article 50(2) transition for certain systems already placed on the market before August 2, 2026. |
| Upcoming | December 2, 2027 | Chapter III, Sections 1–3 high-risk rules for Article 6(2)/Annex III systems. |
| Upcoming | August 2, 2028 | Corresponding high-risk rules for Article 6(1)/Annex I product-related systems. |
Commission implementation timeline. Check the amended Articles 111 and 113 for transition conditions, existing systems and models. A later high-risk date does not suspend other applicable AI, privacy or product rules.
Medical AI: medical devices and in-vitro diagnostic devices can involve the Annex I route. The AI Act timetable does not postpone their existing sector requirements. Read the medical-device overlap.
Transparency belongs at the interaction or output
Article 50 assigns different duties along the service. Providers of directly interactive AI systems must ensure people are informed that they are interacting with AI, subject to the specified exceptions. Providers of systems generating synthetic content have marking and detectability duties. Deployers have disclosure duties for covered deepfakes, emotion recognition, biometric categorization and certain public-interest text. These are not identical duties for every AI use. Commission transparency guidelines, published July 20, 2026.
The Article includes exceptions, including for some text with human review or editorial control and editorial responsibility. The guidelines explain scope; they do not replace the law. Consult the amended text alongside the guidance before relying on an exception. Article 50 (read its amendment notice); 2026 amendments.
Operating practice: on a support-assistant service map, identify the interaction, the disclosure owner and where a reviewer can inspect the notice. For generated content, record who implements marking and how its operation is tested. A governance record is not itself a disclosure or a watermarking mechanism.
Make oversight an actionable responsibility
For high-risk systems, Article 14 addresses effective human oversight, including understanding limitations, interpreting output and being able to override or interrupt use where appropriate. Article 26 places responsibilities on deployers to assign people with the necessary competence, training, authority and support. These high-risk provisions follow the relevant amended application date. Article 14; Article 26.
AI literacy after the Omnibus: amended Article 4 requires providers and deployers to take measures supporting the development of AI literacy among staff and others operating AI on their behalf, in context. It does not require guaranteeing an individual’s specific literacy level. Commission and Member State support complements that duty. It was not simply abolished. Regulation 2026/1744, Article 1(5).
Operating practice: name an owner for oversight, document the decisions a reviewer can change, rehearse the escalation path and retain appropriate training evidence. Representing a human step in a diagram does not demonstrate that oversight works.
Separate the service record from the full legal evidence package
High-risk provider requirements include technical documentation, record-keeping and a quality management system. Deployer duties include using instructions, monitoring operation and keeping logs under their control, subject to the relevant conditions. The applicable role determines which package the organization must produce. Articles 11, 12 and 17; Article 26.
Maintain a reviewed service version, intended-use and role decisions, vendor instructions, control owners, evidence references, unresolved gaps and a dated decision to proceed or change the service. Ask separately whether technical testing, a conformity assessment, registration or an impact assessment is required. Liquid Learn’s service review does not substitute for those activities.
Where Liquid Learn can support the process
| Governance concern | Operational practice | Liquid Learn capability | Limitation or dependency |
|---|---|---|---|
| Scope and accountability | Map the service and identify responsible teams. | Service boundaries, nodes, connections and owners. | Counsel and product teams determine roles and classification. |
| Transparency | Assign the notice or marking control to its service step. | Controls and notes on the service model. | Notices and technical marking must be implemented and tested elsewhere. |
| Human oversight | Describe review, override and escalation responsibilities. | Human steps and owners alongside AI activity. | Teams must provide authority, training and working intervention mechanisms. |
| Review evidence | Keep a dated service version and supporting references. | Review snapshots with reviewer details; evidence references in review packets. | Evidence completeness, legal sufficiency and required technical records need independent validation. |
Connect the review to a real service
See how Liquid Learn connects AI service maps, accountable owners, controls and evidence. Or start with the 24-question health check for an immediate result and downloadable PDF roadmap.
Educational information, not legal advice. Applicability depends on jurisdiction, organizational role and use case. Confirm your obligations with qualified counsel. Liquid Learn supports governance work; using it does not certify or guarantee compliance.