The EU AI Act, without the panic.
A clear, current read of what the EU AI Act asks of you — what already applies, what was deferred, and why a platform you control is the calmest way to stay ready. Not legal advice; just the facts, straight.
When each duty applies.
Verified against the Digital Omnibus on AI — Regulation (EU) 2026/1744, in force since 27 July 2026.
- 2 Feb 2025
Prohibited practices
Banned AI uses and AI-literacy duties apply.
- 2 Aug 2025
GPAI models
Obligations for general-purpose AI models and the governance framework apply.
- 2 Aug 2026
Transparency duties
In force. Article 50 applies to providers and deployers: people must be told when they are interacting with an AI, and AI-generated content must be marked. Not limited to high-risk systems — and open-source systems are not exempt. National market-surveillance authorities can enforce from this date.
- 2 Dec 2026
New prohibitions
Two further Article 5 bans (AI nudification, AI-generated CSAM) take effect. Generative systems placed on the market before 2 August 2026 have until this date to meet the machine-readable marking requirement.
- 2 Dec 2027
High-risk · standalone
Annex III systems must comply — moved back from Aug 2026 by the Digital Omnibus on AI, Regulation (EU) 2026/1744.
- 2 Aug 2028
High-risk · embedded
AI built into regulated products (Annex I) must comply.
What already applies.
Prohibited-practice rules have applied since February 2025, and obligations for general-purpose AI (GPAI) models since August 2025. Since 2 August 2026, Article 50 transparency duties have applied to providers and deployers — people must be told when they are interacting with an AI, and AI-generated content must be marked. Those duties are not limited to high-risk systems, and open-source systems are not exempt. Two further Article 5 prohibitions take effect on 2 December 2026. These are live now — not in 2027.
What moved — and what it means.
The Digital Omnibus on AI — Regulation (EU) 2026/1744, in force since 27 July 2026 — pushed the headline high-risk obligations back: stand-alone (Annex III) systems now apply from 2 December 2027, and AI embedded in regulated products from 2 August 2028. Those dates are now settled law, not a proposal. That’s more time — best spent building where you can actually evidence compliance.
Control is the compliance strategy that doesn’t expire.
Self-hosted, no egress
Keep data and inference inside your perimeter — the simplest answer to most obligations.
A citation on every answer
Traceability you can show an auditor, by default.
Full audit & exports
Evidence who asked what, and what the system answered.
Built in the EU
An innovation by NITSAN, with offices and hosting in Germany.
De-risk it with a compliance plan · compliance overview →
“I don’t sell AI to the Mittelstand — I explain it. RAGSuite is the one I can explain without caveats: self-hosted, citation-backed, predictable.”
A moving deadline is a poor foundation. Control you can prove is a good one.
The EU AI Act, answered
Did the August 2026 deadline disappear?
Only the high-risk part of it. Those obligations were deferred to 2 December 2027 / 2 August 2028 by the Digital Omnibus on AI, Regulation (EU) 2026/1744. But 2 August 2026 was a real date, and it has passed: Article 50 transparency duties have applied since then to providers and deployers, and the Commission’s enforcement powers over GPAI model providers are active. Prohibited practices (since Feb 2025) and GPAI duties (since Aug 2025) already apply.
What do the Article 50 transparency duties require?
In short: people must be told when they are interacting with an AI system, and AI-generated or manipulated content must be marked and — for deepfakes and certain published text — disclosed. They apply from 2 August 2026, are not limited to high-risk systems, and open-source AI systems are not exempt. Systems already generating content before that date have until 2 December 2026 to meet the machine-readable marking requirement. Whether they catch a given system, and whether you are its provider or deployer, is for your counsel to confirm.
Is my use “high-risk”?
It depends on the use case (Annex III/I) and is for counsel to confirm — this page is general information, not legal advice. Whatever the answer, self-hosting keeps your options open.
How does RAGSuite help?
It removes the dependency: data stays in your perimeter, every answer is cited, and the audit trail is yours — you evidence compliance rather than outsource it. See sovereignty and compliance.
Is this legal advice?
No — it’s an accurate, current summary. Have your specifics reviewed by a qualified lawyer.
Stay EU-AI-Act-ready, calmly.
One honest answer on what applies to you now — and how RAGSuite keeps you ready. No countdown theatre.