Prohibition always wins
If the system falls under art. 5, no compliance plan is possible: it stops there. That prohibition has been in force since 2 February 2025, together with the AI literacy duty of art. 4.
Tell us your role in the chain (provider, importer, distributor or deployer), the type of system and whether you use third-party generative AI. We tell you which obligations apply to you and the exact date in art. 113 when they start to bite.
2 August 2026 is the general date of application of Regulation (EU) 2024/1689; the Chapter III requirements for Annex III high-risk systems are deferred to 2 December 2027, and those of Annex I to 2 August 2028, by Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force since 27 July 2026.
What it does:based on your role in the value chain (provider, importer, distributor or deployer), the type of system (prohibited, Annex III high risk, limited risk/transparency, minimal, or general-purpose AI model) and whether you use third-party generative AI, it returns the specific obligations of Regulation (EU) 2024/1689 that apply to you, article by article, with the exact date each one becomes enforceable under its art. 113.
Who it is for:management, legal and technical directors and compliance officers who need to know, before 2 August 2026, what they must do and when — without waiting for the fine to arrive.
This tool is indicative and does not constitute professional advice.It does not analyse your actual technical documentation, your contract with AI providers, whether your model exceeds the systemic risk threshold in art. 51, or the sector-specific exceptions of each case. Check your situation with the Cumplimiento AI Act service from Summum Consultoría (the legal angle: diagnosis, classification and compliance plan) or with a professional before acting.
Do you use ChatGPT, Copilot or Gemini in your company?AI literacy for your staff (art. 4) has been mandatory since 2 February 2025, and on 2 August 2026 the transparency duties of art. 50 and the general application of the Regulation are added. If you develop or deploy an Annex III high-risk system, the deadline is deferred to 2 December 2027 (and to 2 August 2028 for Annex I) by Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force since 27 July 2026. Check it in 1 minute right here ↓.
If the system falls under art. 5, no compliance plan is possible: it stops there. That prohibition has been in force since 2 February 2025, together with the AI literacy duty of art. 4.
Each type of system (high risk, limited risk, general-purpose model, minimal) has its own article of obligations, and that article names different roles: not all operators have the same duties over the same system.
If you use third-party generative AI, you are the deployer of THAT system even if you did not build it: we add the AI literacy duty of art. 4 and, if you publish or expose the output, the transparency duties of art. 50.
Each obligation carries the exact date it becomes enforceable: 2 Feb 2025, 2 Aug 2025, 2 Aug 2026 or 2 Dec 2027. And if you are an SME, art. 99.6 lowers the cap on the fine.
Verification note: the content of each article cited was checked on 30 July 2026 against the official text published in the Official Journal of the European Union of the two applicable rules — Regulation (EU) 2024/1689 and Regulation (EU) 2026/1744, which amends it — downloaded from EUR-Lex. The dates in art. 113 correspond to its wording in force after that amendment.
They are the four roles («operators») defined in art. 3 of Regulation (EU) 2024/1689. The provider (art. 3.3) develops the system or model and places it on the market under its own name or trademark. The deployer (art. 3.4) uses it under its own authority, except for personal non-professional use. The importer (art. 3.6) places on the EU market a system bearing a third-country trademark. The distributor (art. 3.7) makes it available in the Union without being the provider or the importer. Each one has different obligations.
Under art. 113 as currently in force: Chapters I and II (general provisions, AI literacy and prohibited practices) have applied since 2 February 2025. Chapter III Section 4, Chapter V (general-purpose models), Chapter VII (governance) and Chapter XII (penalties, except art. 101) have applied since 2 August 2025. 2 August 2026 remains the general date of application for the rest of the Regulation, including the transparency obligations of art. 50. On 2 December 2026 the two new prohibitions in art. 5(1), first subparagraph (points (ba) and (bb)) and paragraphs 1a and 1b become applicable; on that same date — as a separate matter — falls the deadline under the new art. 111(4) for providers of systems generating synthetic content already on the market before 2 August 2026 to comply with art. 50(2). And Chapter III, Sections 1, 2 and 3 — the requirements for high-risk systems and the obligations of their providers and deployers — with the exception of art. 6(5), apply from 2 December 2027 for the systems in art. 6(2) and Annex III, and from 2 August 2028 for those in art. 6(1) and Annex I. Those last two dates are set by Regulation (EU) 2026/1744 (the digital omnibus on AI), in force since 27 July 2026.
Stop its development, placing on the market or use: the prohibition in art. 5 has been in force since 2 February 2025 and admits no compliance plan. Breaches are fined up to 35 million euros or 7% of worldwide annual turnover (art. 99.3).
Yes. By using a third party's AI system under your own authority, you act as the deployer of THAT system (art. 3.4), with obligations of your own: AI literacy for your staff (art. 4, in force since 2 February 2025) and, if you expose the output to people or publish it, the transparency duties of art. 50 (disclosing the AI interaction, marking synthetic content) from 2 August 2026.
It depends on what is breached (art. 99): up to €35M or 7% of worldwide turnover for the prohibited practices in art. 5; up to €15M or 3% for breaching the other obligations (provider, importer, distributor, deployer, transparency); up to €7.5M or 1% for supplying incorrect or misleading information to the authorities. For SMEs and start-ups, art. 99.6 allows the fine to be set by the percentage or by the fixed amount, whichever is lower: its wording is «shall be up to», that is, a power of the authority and not an automatic right to the lower figure. Work out the exact amount for your situation in the AI Act fine calculator.
No. It is indicative: it does not analyse your actual technical documentation, your contract with AI providers or whether your model exceeds the systemic risk threshold. Check your case with the AI Act Compliance service from Summum Consultoría (the diagnosis and the compliance plan) or with Summum IA (the technical layer: traceability, bias assessment, Annex IV) before acting.
Diagnosis, risk classification and compliance plan for the European AI Regulation, coordinated with the technical layer of Summum IA.