The EU AI Act has already been in force since August 2024, but its obligations phase in over roughly two years. The next major milestone, and the one with the broadest impact on companies building AI products, lands on 2 August 2026: the date the full high-risk AI system regime becomes enforceable.
Many founders and compliance leads assume the Act is a future problem. It isn't. Prohibited practices have been illegal since February 2025, and general-purpose AI model obligations have applied since August 2025. But the 2026 deadline is the one that will affect the largest number of companies, because it activates the requirements for Annex III high-risk systems: AI used in employment, credit, health, education, law enforcement, and several other sensitive areas.
What starts on 2 August 2026
From this date, providers of high-risk AI systems must have completed, not started, the following before placing a system on the EU market or putting it into service:
- Conformity assessment (Article 43): Either an internal control procedure or, for certain systems, an assessment by a notified third-party body, confirming the system meets Chapter III requirements.
- Technical documentation (Article 11): A complete file describing the system's purpose, architecture, training methodology, and performance characteristics, matching the structure set out in Annex IV.
- Risk management system (Article 9): A documented, continuous process covering the entire lifecycle of the system, not a one-time assessment.
- Data governance records (Article 10): Evidence that training, validation, and testing datasets were selected, checked for errors, and examined for bias.
- Human oversight design (Article 14): The system must be built so a person can interpret its outputs, intervene, and override or halt it.
- EU database registration (Article 49): Registration in the Commission's public database of high-risk AI systems before the system goes live.
Who this actually affects
The Annex III list is specific, and it is worth checking against it directly rather than assuming your product is fine. Systems used for the following are squarely in scope: candidate screening and CV ranking in recruitment, creditworthiness assessment, life and health insurance risk assessment and pricing, medical triage and diagnosis support, exam grading and admissions decisions in education, biometric categorisation, and several law-enforcement and migration use cases.
A useful test: if your AI system's output is a factor, even a partial one, in a decision that affects someone's access to a job, a loan, healthcare, or education, you are very likely building a high-risk system under the current guidance.
What does not change on this date
It is worth being precise about scope, because overcompliance wastes engineering time just as underestimating the Act creates legal risk. The 2 August 2026 deadline does not add new obligations for:
- Prohibited practices, already banned since February 2025
- General-purpose AI model transparency duties, already in force since August 2025
- Limited-risk systems like customer-facing chatbots, which only need the Article 50 disclosure that already applies
- Minimal-risk tools such as spam filters or internal analytics, which have no mandatory obligations under the current framework
How to prepare before the deadline
Conformity assessments, technical documentation, and EU database registration are not one-afternoon tasks. Companies that will be affected should start now, not in July 2026:
- Classify every AI system you build or deploy. Do this per system, not per company: a single company can have systems in multiple risk tiers.
- Start the technical documentation file early. Much of Annex IV documentation, architecture, training data provenance, testing results, is easier to write while the system is fresh in the team's memory than to reconstruct a year later.
- Design human oversight in from the start. Retrofitting an override mechanism into a shipped product is significantly more expensive than building it in from the first release.
- Budget for a conformity assessment. If your system requires third-party assessment, notified bodies will face demand surges as the deadline approaches. Early engagement avoids queueing.
EuroComply's free EU AI Act assessment classifies your system's risk tier in about 3 minutes and returns the exact list of documents your tier requires, with the legal article for each, so you know precisely what to prepare before the deadline.