The EU AI Act — what applies now, and what lands in 2027
Article 50 transparency has applied since 2 August 2026: chatbots must say they are AI and synthetic media must be marked. The Annex III high-risk regime follows on 2 December 2027, moved there by the Digital Omnibus, which also gave the AI Office inspection powers. Duties depend on whether you are a provider or a deployer of a given system — most organisations are both, on different systems, at the same time.
Key dates
2 dated obligations. Rows marked verify are not final in their source. See the whole calendar.
What practitioners need to know
Lifted verbatim from the kits below, each attributed to the product that says it.
-
One control — “access to production requires MFA and is reviewed quarterly” — satisfies a SOC 2 criterion, an ISO 27001 Annex A control, a HIPAA safeguard and a PCI requirement simultaneously.
— Pillar 01 — The Compliance Operating System -
A readiness dashboard can read 98% while the auditor’s fieldwork disagrees, because completion percentage is not evidence quality.
— Pillar 01 — The Compliance Operating System -
Covers SOC 2 Type I and II, ISO 27001, HIPAA, PCI DSS v4.0.1, CMMC 2.0, DORA and NIS2, plus the 2026 AI-governance layer.
— Pillar 01 — The Compliance Operating System -
Article 50 transparency has applied since 2 August 2026 — chatbots must say they are AI and synthetic media must be marked. It is not a deadline to plan for; it is a duty you are either meeting or breaching today.
— EU AI Act Compliance Clock -
The Digital Omnibus moved Annex III high-risk to 2 December 2027 — and gave the AI Office inspection powers in the same act. More time, and a regulator with teeth to use it.
— EU AI Act Compliance Clock -
Fines reach €35M or 7% of global turnover; €15M or 3% for high-risk and transparency breaches.
— EU AI Act Compliance Clock -
Under 750 staff does not mean exempt. The simplified small-mid-cap regime reduces the paperwork, not the substantive duties.
— EU AI Act Compliance Clock -
The Digital Omnibus on AI entered into force 27 July 2026 and pushed the high-risk regime for stand-alone Annex III systems out to 2 December 2027, with embedded Annex I systems following on 2 August 2028.
— Pillar 06 Companion — The 2026 AI Risk Register -
What survived every amendment: Article 50 transparency, the Article 4 AI-literacy duty, and the 2 December 2026 marking obligation for systems already on the market.
— Pillar 06 Companion — The 2026 AI Risk Register -
The line to use with your board: the high-risk regime moved by sixteen months, and a team that restarts this work in mid-2027 restarts it with fifteen months less evidence history than a team that never stopped.
— Pillar 06 Companion — The 2026 AI Risk Register
Kits that cover it
4 products, cheapest first.
Pillar 01 — The Compliance Operating System
Map controls once, satisfy every framework. A continuous, registry-driven compliance program across SOC 2, ISO 27001, HIPAA, PCI, CMMC, DORA and NIS2 — plus the ISO 42001 and EU AI Act layer most guides still omit.
EU AI Act Compliance Clock
Transparency is live; high-risk is December 2027. Classify every AI system you provide or deploy, close the Article 50 duties that already apply, and run the deployer and provider programmes to the date that binds each one — with the US state overlay alongside.
Pillar 06 Companion — The 2026 AI Risk Register
The register that inventories every AI system, model and agent in your business, classifies it against the 2026 regulatory map, scores it on autonomy and blast radius, and routes remediation to real suppliers. Full schema, five classification rule tables, 41 build prompts.
Shadow AI Inventory & Risk Scoring Workbook
Discover, inventory, and score every unapproved AI tool in your environment — 10 tabs, 589 formulas, pre-seeded with 15 real-world shadow AI tools and a defensible 10-factor risk model.
Bundles
6 bundles cover this alongside adjacent work — always below the sum of the parts.
Article 50, Both Sides
The duty and the discharge. The AI Act tells you disclosure applies; the synthetic-media kit is how you actually do it — caption, platform label, C2PA credentials, consent and a register — across every regime that asks. 15% off buying separately.
AI Risk Register Pack
Pillar 06 — The Fractional CISO Operating System, plus The 2026 AI Risk Register. The practice and the system: own the register and know how to run it. 15% off buying separately.
EU AI Act + Risk Register Pack
The clock that tells you which date binds each AI system, and the register that holds them once they are scored. Classify against the Act, then keep the answer somewhere an auditor can read it. 15% off buying separately.
AI Program Complete
Classify your AI against the law, fence the agents that can act on your estate, and hold the risk somewhere an auditor can read it. The three halves of an AI programme that most organisations buy one incident at a time. 19% off buying separately.
Phase 0 + Shadow AI Pack
The assessment that finds every AI system in your estate, paired with the workbook that inventories and scores them. Map the footprint, then govern it. 14% off buying separately.
EU Regulatory Estate
The two EU regimes that reach almost every regulated business at once — operational resilience and third-party risk under DORA and NIS2, and the AI Act obligations arriving on top of them. 14% off buying separately.
Other regimes: HIPAA · DORA & NIS2 · PCI DSS · Third-party risk · Critical infrastructure · Post-quantum
Working to a date? The compliance calendar. Not legal advice.