Regulation (EU) 2024/1689 · amended by Regulation (EU) 2026/1744
The AI Act, for a company that builds or uses AI
Which of the 25 Annex III use cases, which operator you are, and the dates as amended on 27 July 2026 decide what the AI Act asks of you.
Answer above to read the determination for your case; the full tool takes your answers with it.
Continue in the free determinationFive tools, and the standard behind Article 17
Is your AI system high-risk?
The questions Article 6 asks, as amended: the product route with paragraphs 1a to 1c, the 25 points of Annex III verbatim in your language, the 6(3) conditions and the profiling override, ending in a written determination with the date the requirements apply from and what a provider or deployer then owes.
Do you owe a fundamental rights impact assessment, and what goes in it?
Article 27 reaches public bodies, private providers of public services and every deployer of credit and insurance systems. Two questions decide it; then the six elements of Article 27(1) in the Regulation's words, one field each, written as a document to file and notify.
The Article 4 AI-literacy record, written from a table
Every provider and deployer owes measures, not a guaranteed level. One row per group of people: systems, context, prior knowledge, measure, when, owner; the page writes the record with the amended paragraph quoted and the ISO 42001 clauses it lives under.
The Article 16 provider checklist
The twelve obligations of a provider of a high-risk system, verbatim, each with the article it points to and where an ISO 42001 system keeps the evidence; a status per point, and the checklist as a document with the date it applies from.
Registration in the EU database, Article 49
Which of the three registrations you owe, whether it goes into the restricted section or to national level, and the Annex VIII items in the Regulation's words, one field each, written as the entry to file.
ISO 42001, the AI management system standard
The 38 Annex A controls, the clause register and the 24 AI Act obligations mapped to them: ten of the thirteen aspects of the quality management system Article 17 asks a high-risk provider for, as a standard a certification body can audit.
What StandardOS covers of ISO 42001
Clause by clause, where each record lives in the product and where every software's limits are; the page is deliberately honest about the clauses the product does not yet hold.
The Annex A controls, one page each
Every control with its objective, the evidence it produces and the AI Act obligation it serves where one does, in six languages.
Every free template on one page
The dates, as amended
Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published on 24 July 2026 and moved the high-risk requirements by sixteen and twelve months. The rows are read from Article 113 as amended, on 12 September 2026; dates already passed are greyed.
| From | What applies |
|---|---|
| 12 July 2024 | The Regulation in the Official Journal. |
| 2 February 2025 | Chapters I and II: the definitions, Article 4 on AI literacy, and the Article 5 prohibited practices as adopted. |
| 2 August 2025 | The obligations of providers of general-purpose AI models (Chapter V), the governance chapters and the penalties, notified bodies excepted until the general date. |
| 27 July 2026 | The Digital Omnibus on AI in force: Article 6(1a) to (1c), the rewritten Article 4, Article 17(2), Article 111(2) as amended, and Articles 102 to 110, the amendments to other Union acts. |
| 2 August 2026 | The general date of application: Article 50, the transparency duties for systems that interact with people or generate content, and everything not given another date. |
| 2 December 2026 | The two prohibitions inserted into Article 5(1), points (ba) and (bb): generating or manipulating intimate or sexually explicit material of an identifiable person without consent, and child sexual abuse material. Article 50(2) reaches generative systems already on the market by the same day. |
| 2 December 2027 | Chapter III Sections 1 to 3 for systems high-risk under Article 6(2) and Annex III: the requirements of Articles 8 to 15, the provider and deployer obligations of Articles 16 to 27. The original text said 2 August 2026. |
| 2 August 2028 | Chapter III Sections 1 to 3 for systems high-risk under Article 6(1) and Annex I, the safety components of regulated products. The original text said 2 August 2027. |
| 2 August 2030 | Article 111(2): high-risk systems intended for use by public authorities comply by this date whatever the day they were placed on the market. |
6 articles, from the primary sources
The AI Act for a software company: which role you are, what applies to everyone, what applies only to a high-risk provider, the SME provisions, and the dates as amended
A software company meets the AI Act in one of six roles, and most of the Regulation only applies to two of them. What counts as an AI system at all, why shipping a vendor's model under your own name makes you the provider, the three duties every company has since 2025 and 2026 (AI literacy, the prohibitions, transparency), the two routes to high-risk and what each role then owes from 2 December 2027, the general-purpose model line, the SME and small mid-cap provisions the Digital Omnibus widened, and one table of who owes what from when. Read from the two Regulations on CELLAR on 12 September 2026.
The AI Act after the Digital Omnibus: the dates that changed on 27 July 2026, and which ISO 42001 controls produce the evidence for Article 17's thirteen aspects and Articles 9 to 15
Regulation (EU) 2026/1744, signed 8 July 2026, published 24 July, in force 27 July, moved the AI Act's high-risk dates to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, rewrote AI literacy as a duty to take measures, and made the post-market monitoring plan part of the technical documentation. Most of what ranks still gives the old dates. The dates as amended, what else changed for a provider, and our mapping of Article 17's thirteen quality-management aspects, Articles 9 to 15, 72 and 73, and the operator duties of Articles 4 and 26 to the Annex A controls of ISO/IEC 42001, with what the Regulation asks for that the standard does not produce.
AI literacy under Article 4 of the AI Act, as rewritten on 27 July 2026: what 'take measures' means, who it covers, what it does not require, and the record to keep
Article 4 has applied to every provider and deployer of an AI system since 2 February 2025. The Digital Omnibus rewrote it: measures to support the development of AI literacy, taking account of people's knowledge and the context, and, in terms the Regulation now uses, no duty to guarantee any specific level of literacy of any individual. The Commission is to publish practical examples and the AI Board common objectives. What the article asks, why it has no fine of its own in Article 99, how ISO 42001's competence and awareness clauses produce the record, and a one-page programme.
What a deployer of a high-risk AI system owes under Article 26 of the AI Act: the twelve paragraphs in order, the Article 27 impact assessment, when you become the provider, and the records an ISO 42001 system keeps
Most companies will meet the AI Act as deployers: they buy or licence a system someone else built and use it under their own authority. For a high-risk system the duties are in Article 26, twelve paragraphs, unchanged by the Digital Omnibus, applying from 2 December 2027 for Annex III systems. Each paragraph read in order, the Article 27 fundamental rights impact assessment and who carries it, the three ways a deployer becomes the provider under Article 25, the Article 86 right to explanation, the Article 99 ceiling, and the ISO 42001 control that produces each record.
Article 50 of the AI Act for a company that ships or uses generative AI: the four transparency duties in force since 2 August 2026, the 2 December 2026 transition, the code of practice and the EU icon
Article 50 is the AI Act obligation that reaches a company whether or not its system is high-risk: tell people they are talking to an AI, mark generated content so machines can detect it, disclose deep fakes and AI-written text on matters of public interest, inform people exposed to emotion recognition. It has applied since 2 August 2026, the Digital Omnibus left it unchanged and gave providers of generative systems already on the market until 2 December 2026 for the marking duty. The four paragraphs read in order, who is provider and who is deployer for each, the Commission's code of practice of 10 June 2026 with its two-layer marking and its AI icon, the fine, and the record an ISO 42001 system keeps.
ISO 42001 certification: what it is, and whether it is early
ISO/IEC 42001 is the AI management system standard. Here is what it asks for, how it relates to an existing ISO 27001, and an honest read of current demand.
Ten of Article 17's thirteen aspects are an ISO 42001 system; the other three are written for the Regulation
StandardOS runs the ISO/IEC 42001 management system whose records are the process behind 24 of the obligations a high-risk provider carries, and names what the standard does not produce so it is written for the Regulation itself. The high-risk determination goes in as the first record, in six languages.
Dates are read from Article 113 of the Regulation as amended and never typed on this page. This is not legal advice, and the two texts are the ones to read: Regulation (EU) 2024/1689, Regulation (EU) 2026/1744.