Regulation (EU) 2024/1689 · amended by Regulation (EU) 2026/1744

The AI Act, for a company that builds or uses AI

Which of the 25 Annex III use cases, which operator you are, and the dates as amended on 27 July 2026 decide what the AI Act asks of you.

Which operator are you?

Answer above to read the determination for your case; the full tool takes your answers with it.

Continue in the free determination

Five tools, and the standard behind Article 17

Is your AI system high-risk?

The questions Article 6 asks, as amended: the product route with paragraphs 1a to 1c, the 25 points of Annex III verbatim in your language, the 6(3) conditions and the profiling override, ending in a written determination with the date the requirements apply from and what a provider or deployer then owes.

Do you owe a fundamental rights impact assessment, and what goes in it?

Article 27 reaches public bodies, private providers of public services and every deployer of credit and insurance systems. Two questions decide it; then the six elements of Article 27(1) in the Regulation's words, one field each, written as a document to file and notify.

The Article 4 AI-literacy record, written from a table

Every provider and deployer owes measures, not a guaranteed level. One row per group of people: systems, context, prior knowledge, measure, when, owner; the page writes the record with the amended paragraph quoted and the ISO 42001 clauses it lives under.

The Article 16 provider checklist

The twelve obligations of a provider of a high-risk system, verbatim, each with the article it points to and where an ISO 42001 system keeps the evidence; a status per point, and the checklist as a document with the date it applies from.

Registration in the EU database, Article 49

Which of the three registrations you owe, whether it goes into the restricted section or to national level, and the Annex VIII items in the Regulation's words, one field each, written as the entry to file.

ISO 42001, the AI management system standard

The 38 Annex A controls, the clause register and the 24 AI Act obligations mapped to them: ten of the thirteen aspects of the quality management system Article 17 asks a high-risk provider for, as a standard a certification body can audit.

What StandardOS covers of ISO 42001

Clause by clause, where each record lives in the product and where every software's limits are; the page is deliberately honest about the clauses the product does not yet hold.

The Annex A controls, one page each

Every control with its objective, the evidence it produces and the AI Act obligation it serves where one does, in six languages.

Every free template on one page

The dates, as amended

Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published on 24 July 2026 and moved the high-risk requirements by sixteen and twelve months. The rows are read from Article 113 as amended, on 12 September 2026; dates already passed are greyed.

The application dates of the AI Act, as amended
FromWhat applies
12 July 2024The Regulation in the Official Journal.
2 February 2025Chapters I and II: the definitions, Article 4 on AI literacy, and the Article 5 prohibited practices as adopted.
2 August 2025The obligations of providers of general-purpose AI models (Chapter V), the governance chapters and the penalties, notified bodies excepted until the general date.
27 July 2026The Digital Omnibus on AI in force: Article 6(1a) to (1c), the rewritten Article 4, Article 17(2), Article 111(2) as amended, and Articles 102 to 110, the amendments to other Union acts.
2 August 2026The general date of application: Article 50, the transparency duties for systems that interact with people or generate content, and everything not given another date.
2 December 2026The two prohibitions inserted into Article 5(1), points (ba) and (bb): generating or manipulating intimate or sexually explicit material of an identifiable person without consent, and child sexual abuse material. Article 50(2) reaches generative systems already on the market by the same day.
2 December 2027Chapter III Sections 1 to 3 for systems high-risk under Article 6(2) and Annex III: the requirements of Articles 8 to 15, the provider and deployer obligations of Articles 16 to 27. The original text said 2 August 2026.
2 August 2028Chapter III Sections 1 to 3 for systems high-risk under Article 6(1) and Annex I, the safety components of regulated products. The original text said 2 August 2027.
2 August 2030Article 111(2): high-risk systems intended for use by public authorities comply by this date whatever the day they were placed on the market.

6 articles, from the primary sources

Ten of Article 17's thirteen aspects are an ISO 42001 system; the other three are written for the Regulation

StandardOS runs the ISO/IEC 42001 management system whose records are the process behind 24 of the obligations a high-risk provider carries, and names what the standard does not produce so it is written for the Regulation itself. The high-risk determination goes in as the first record, in six languages.

Dates are read from Article 113 of the Regulation as amended and never typed on this page. This is not legal advice, and the two texts are the ones to read: Regulation (EU) 2024/1689, Regulation (EU) 2026/1744.