Short answer
Prepare for the EU AI Act by listing every AI system you build or use, ruling out prohibited practices, deciding whether you are a provider or a deployer of each, and classifying each as high-risk, transparency-only, general-purpose or minimal. Then plan the duties for each class and keep evidence. As of 7 October 2026, Annex III high-risk duties apply from 2 December 2027, but prohibitions, AI literacy and transparency already apply.
The steps at a glance
Before you start
Who this is for
- Product, engineering, legal and risk leads who need a working plan rather than a summary of the regulation.
- Startups and mid-sized companies that build on foundation models and want to know which duties are theirs.
- Organisations that use third-party AI tools in hiring, customer service or operations and need to know what a deployer must do.
Probably not for you if
- Anyone after legal advice. This is a technical and organisational workflow. Counsel decides how the law applies to your facts.
- Teams looking for a certification to buy. The Act sets obligations to meet and evidence to keep; this guide does not describe any product as compliant.
Prerequisites
- Access to the people who own each AI system or AI-enabled tool in your organisation, including those who bought them.
- A spreadsheet or register where the inventory will live and be kept up to date.
- A named owner for AI governance, even if part-time, and a route to legal counsel or a data protection officer.
- A copy of the regulation text, Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, from EUR-Lex.
- Time
- About one to two weeks for a first inventory and classification of a mid-sized organisation, longer if tools are bought across many teams. Evidence work continues after.
- Cost
- No software is required. The cost is staff time, and legal review for borderline classifications.
- Skill
- No coding. Needs product, legal and security people in the same room.
Estimates are ours, not measurements, and move with your hardware, data and network.
What this guide is and is not
This is a practical workflow, and it is not legal advice. Classification and role decisions depend on the facts of each system and the exact text of the Act as amended. Dates in this guide reflect the sources listed below as of 7 October 2026, and the primary page on EUR-Lex did not render when we fetched it, so we cross-checked its content through search summaries, a law-firm briefing and our own timeline page. Verify the dates against EUR-Lex before you rely on them.
Swfte provides the technical controls, governance mechanisms and evidence that help an organisation deploy AI within the rules that apply to it. The exact posture depends on your use case, jurisdiction, deployment and configuration.
Step 1Start from the dates as they stand now
You end up with: A one-page timeline you can check each system against.
The dates moved in 2026, so start by getting them right. Regulation (EU) 2026/1744, the Digital Omnibus on AI, amends the AI Act. It was adopted on 8 July 2026, published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. Under it, stand-alone Annex III high-risk systems must comply by 2 December 2027, and AI embedded in regulated products under Annex I by 2 August 2028.
What did not move matters just as much. Prohibited practices and AI literacy have applied since 2 February 2025. Obligations for general-purpose AI models have applied since 2 August 2025. Transparency duties in Article 50 apply from 2 August 2026, with a grace period to 2 December 2026 for Article 50(2) marking on systems already on the market. A delay of the high-risk date is not a pause on everything else.
Check these dates against the primary source before you publish a plan, because the text was amended recently and commentary varies. Our own EU AI Act timeline tracks them and says when it was last verified.
Dates as of 7 October 2026 Date What applies 2 February 2025 Prohibited practices (Article 5) and AI literacy (Article 4) 2 August 2025 General-purpose AI model obligations (Chapter V) and governance bodies 2 August 2026 Most remaining rules, including Article 50 transparency 2 December 2026 End of the Article 50(2) grace period for systems already on the market; new Article 5 prohibitions 2 December 2027 Annex III high-risk obligations 2 August 2028 High-risk obligations for AI in Annex I regulated products Checked against: EUR-Lex: Regulation (EU) 2026/1744 (Digital Omnibus on AI), Gibson Dunn: EU AI Act omnibus agreement, postponed high-risk deadlines (27 May 2026)
Step 2List every AI system, model and agent
You end up with: A register with one row per AI system, with an owner, a purpose and the data it touches.
You cannot classify what you have not found. Include systems you build, systems you buy, AI features inside tools you already use, and agents that act on your behalf. Include the foundation models underneath them. Shadow AI counts, so how to detect shadow AI is a useful companion step.
For each system record the name, the owner, the vendor, the purpose in one sentence, who is affected by its output (customers, employees, applicants), what personal data it uses, and where it runs. Add the model or models behind it and whether you trained or fine-tuned them. Keep the purpose precise. The same model can be minimal risk in one use and high-risk in another, and the Act classifies by intended purpose and use.
Treat the register as a living document with an owner and a review date. A register that is accurate on the day you write it and stale in a quarter will not help when someone asks.
Register columns (copy into a spreadsheet) · text system_id, name, owner, vendor_or_in_house, purpose, affected_people, personal_data, models_used, trained_or_fine_tuned, deployment_location, first_use_date, risk_class, role, notes, review_dateStep 3Rule out prohibited practices first
You end up with: Each system marked as clear of Article 5, or escalated for urgent review.
Article 5 lists AI practices that are banned outright, and it has applied since 2 February 2025, so this is the most urgent check. Read the current text of Article 5 with your counsel and compare each purpose in your register against it. The Digital Omnibus adds two more prohibitions, on AI that generates non-consensual intimate imagery and child sexual abuse material, applying from 2 December 2026.
If a system might fall under a prohibition, stop and escalate to legal before doing anything else. Do not wait for the high-risk date. Penalties for prohibited practices are the highest tier in the Act, and the penalties page explains the structure.
Record the result for every system, including a line on why you concluded it was clear. That reasoning is evidence.
Checked against: EUR-Lex: Regulation (EU) 2026/1744 (Digital Omnibus on AI)
Step 4Decide whether you are a provider or a deployer
You end up with: A role for each system, with a note where it can change.
The Act puts different duties on different roles. A provider develops an AI system or has one developed and places it on the market or puts it into service under its own name. A deployer uses an AI system under its own authority in a professional setting. Most organisations are deployers of some systems and providers of others.
The role can change. Under Article 25, a deployer, importer or distributor becomes the provider of a high-risk system by putting its own name on it, making a substantial modification, or changing the intended purpose so that the system becomes high-risk. If you fine-tune a model and sell the result inside a product, check whether you have become a provider. If you only run a vendor tool within the vendor's instructions, you are usually a deployer.
General-purpose AI models have their own provider obligations in Chapter V, which sit separately from the high-risk rules. If you build on someone else's model you are usually not that model's provider, but your product can still be high-risk. See GPAI obligations.
Step 5Classify each system by risk
You end up with: Every system tagged as prohibited, high-risk, transparency, general-purpose or minimal, with the reasoning written down.
Work through the classes in order. Prohibited: done in the previous step. High-risk: a system is high-risk if it falls under one of the use cases in Annex III, or it is a safety component of, or itself, a product covered by Annex I. Annex III has eight areas: biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration, and the administration of justice. Within each area it lists specific use cases, so being in an area is not enough on its own.
Article 6 allows a provider to conclude that an Annex III system is not high-risk in specific circumstances, for example where it does not pose a significant risk of harm. If you rely on that, write the reasoning down and expect to be asked for it. Commentary on the final Omnibus deal says the registration step for such systems was kept, so confirm this with counsel against the final text.
Transparency: Article 50 sets disclosure duties, for example telling people they are talking to an AI system, and marking AI-generated content. These apply from 2 August 2026. General-purpose models carry their own rules. Everything else is minimal risk and carries no specific obligation under the Act, though other laws such as the GDPR still apply.
Use the high-risk checklist to walk each borderline system. Where two readings are possible, pick the cautious one and get legal review.
Classification worksheet Question If yes Does the purpose match a prohibited practice in Article 5? Stop, escalate to legal now Is it in an Annex III use case, or a safety component of an Annex I product? Treat as high-risk unless a documented Article 6 reason says otherwise Does it interact with people or generate content they might take to be human-made? Check the Article 50 disclosure and marking duties Is it, or is it built directly on, a general-purpose model you provide? Check Chapter V provider duties None of the above Minimal risk under the Act; keep other laws in view Checked against: AI Act Service Desk: Annex III, Gibson Dunn: EU AI Act omnibus agreement, postponed high-risk deadlines (27 May 2026)
Step 6Start AI literacy now
You end up with: A short training plan and a record of who has done it.
Article 4 on AI literacy has applied since 2 February 2025. The Digital Omnibus softened it: commentary on the amendment says providers and deployers are required to take measures to support AI literacy among their staff, rather than to guarantee a specific level. That is still an obligation, and a regulator will ask what you did.
Match the training to the role. People who approve AI outputs need to know the system's limits. People who buy tools need to ask the right questions. Engineers need to know the rules for the classes they build. Keep a record: who attended, the date and the content. The Article 4 guide covers what to include.
Checked against: Gibson Dunn: EU AI Act omnibus agreement, postponed high-risk deadlines (27 May 2026)
Step 7Plan the obligations for each class
You end up with: For every high-risk and transparency system, a list of duties with an owner and a target date.
For high-risk systems, providers face the requirements in Articles 9 to 15 (risk management, data governance, technical documentation, record-keeping, transparency to deployers, human oversight, accuracy, resilience to errors and attacks, and cybersecurity), a quality management system under Article 17, conformity assessment, registration and post-market monitoring. The Omnibus simplified some documentation and quality-management requirements for smaller companies; check whether you qualify.
Deployers of high-risk systems have duties under Article 26: use the system according to its instructions, assign competent human oversight, monitor operation, keep the logs the system generates for an appropriate period (our EU checklist summarises the minimum as six months; confirm in the text), and inform workers and affected people. Some deployers must also carry out a fundamental rights impact assessment under Article 27. Public bodies, private entities providing public services and deployers of certain Annex III credit and insurance use cases are named in the checklist.
Where you rely on a vendor, ask for what you need: the provider's instructions for use, its documentation, and a way to get logs. Put those requests into contracts now, because you will need them well before December 2027.
Work backwards from 2 December 2027. Conformity assessment and documentation take longer than the calendar suggests, which is why starting early matters even after the delay.
Checked against: EUR-Lex: Regulation (EU) 2026/1744 (Digital Omnibus on AI)
Step 8Build the evidence as you go
You end up with: A folder per system that holds the documents a regulator, customer or auditor would ask for.
Evidence is what turns a plan into something you can show. For each system keep the register entry, the classification reasoning, the role decision, the risk assessment, the data sources and their governance, test and evaluation results, the human oversight design, the logs and their retention, and the training record. How to validate your AI explains how to produce test results that stand up, and how to audit AI systems explains how an auditor would check them.
Where personal data is involved, pair this with a data protection impact assessment. How to do a DPIA for AI covers it, and the two documents can share evidence.
Review on a schedule. Set a quarterly check that the register matches reality, the dates still match the Official Journal, and no system has changed purpose.
Troubleshooting
| What you see | Likely cause | Fix |
|---|---|---|
| You cannot tell whether a system is high-risk | The use case sits near an Annex III area, or the same model is used for several purposes. | Classify by intended purpose, one use at a time. Write the reasoning down and take the borderline cases to legal review. Use the Article 6 route only with documented reasons. |
| A vendor says its product is "AI Act compliant" and will not share documentation | The claim is marketing. The Act puts duties on both provider and deployer. | Ask for the instructions for use, intended-purpose statement, risk and testing documentation, and log access. Record the response. If they cannot provide them, treat it as a risk for the high-risk date. |
| The team believes the 2027 delay means there is nothing to do yet | Only Annex III and Annex I high-risk dates moved. | Show them the timeline: prohibitions, AI literacy and transparency already apply, and general-purpose model duties apply too. Keep the work on inventory and literacy moving. |
| The register is out of date within weeks | Teams adopt tools without telling anyone, or new features appear inside existing tools. | Link the register to procurement and IT approval, run a discovery exercise on a schedule, and name an owner per system. |
| You have fine-tuned a model and are unsure of your role | Substantial modification or a changed intended purpose can make a deployer a provider under Article 25. | Review Article 25 with counsel, document what you changed and why, and plan for provider duties if it applies. |
| Two sources give different dates for the same obligation | The Act was amended in July 2026 and older commentary predates it. | Use the consolidated text on EUR-Lex and the Commission AI Act Service Desk. Check the publication date of any commentary. |
Verify it worked
Next steps
- EU AI Act timeline: the verified dates after the Digital Omnibus, with last-checked date
- High-risk checklist: walk classification and Articles 9 to 15 and 26 system by system
- AI literacy under Article 4: what to put in a training plan and record
- EU AI Act overview: a plain explanation of what the Act is and who it covers
- How to do a DPIA for AI: the data protection assessment that often runs alongside
Related guides
- How to Do a DPIA for AI: GDPR Article 35 Steps: Decide whether an AI system needs a DPIA, then describe the processing, assess necessity, identify risks to people, choose measures, record the sign-off and review it, with AI-specific risks and a worked example.
- How to Validate Your AI: Eval Sets, Gates, Evidence: A system-level method to validate an AI product: define the task and risk, build a held-out eval set, score it, gate releases, sample for human review, monitor and keep an evidence pack.
- How to Audit AI Systems: Scope, Evidence, Findings: How to audit an AI system, internally or for a client: scope it, choose criteria, request and sample evidence, test logs, change control and human oversight, and write findings that can be fixed.
- How to Govern AI Agents: Identity, Policy, Approvals: Govern agents at runtime: list every agent, give each an identity and an owner, write down what it may and may not do in a Trust Profile, enforce allow, deny and approve rules, choose an autonomy level, record every action and review on a schedule.
- How to Detect Shadow AI in Your Organisation: Define what counts as unsanctioned AI, then find it through identity grants, network logs, expense data and a short staff survey, rank what you find by the data it touches, replace the risky tools with approved ones, and keep monitoring in a proportionate way.
Frequently asked questions
When does the EU AI Act apply?
In stages. Prohibited practices and AI literacy apply from 2 February 2025, general-purpose model duties from 2 August 2025, and most remaining rules, including Article 50 transparency, from 2 August 2026. After the Digital Omnibus, Annex III high-risk duties apply from 2 December 2027 and Annex I from 2 August 2028.
Was the EU AI Act delayed?
Partly. Regulation (EU) 2026/1744, adopted on 8 July 2026 and in force from 27 July 2026, moved the high-risk dates to 2 December 2027 for Annex III and 2 August 2028 for Annex I. It did not move the prohibitions, AI literacy, general-purpose model duties or the Article 50 transparency date.
How do I know if my AI system is high-risk under the EU AI Act?
Check whether its intended purpose matches a use case listed in Annex III, which covers eight areas, or whether it is a safety component of an Annex I product. Being in an area is not enough: the specific use case must be listed. Document the reasoning and review borderline cases with counsel.
What is the difference between a provider and a deployer under the AI Act?
A provider develops an AI system, or has it developed, and places it on the market or puts it into service under its own name. A deployer uses an AI system under its own authority in a professional setting. Substantial modification or a changed purpose can turn a deployer into a provider.
Does the EU AI Act apply to startups?
Yes, if they place AI systems on the EU market or use them in the EU. The Act has lighter rules for some documentation and quality-management duties for smaller companies, and the Digital Omnibus extended some of that. The first steps are the same: inventory, role, classification, literacy.
What do I need to do about AI literacy?
Take measures to support AI literacy among staff who work with AI, matched to their role, and keep a record. Article 4 has applied since 2 February 2025. The Digital Omnibus changed the wording from ensuring a level of literacy to taking supporting measures, but the duty remains.
How Swfte can help
You can run this workflow with a spreadsheet and your own counsel. Swfte publishes free reference pages on the Act, and the platform is designed to give organisations the technical controls and evidence these duties call for.
- EU compliance hub: AI Act, GDPR, DORA, NIS2 and Data Act pages for AI teams
- Platform governance: identity, policy, human oversight and audit for AI systems
- Trust Profile: a per-system record of owner, risk, data, actions and approvals
Swfte provides compliance-by-design controls and evidence. It does not certify a system as compliant with the AI Act, and the right classification for your systems is a legal question for you and your counsel.
Missing a step or found a command that no longer works? Tell us, or request a how-to.
Sources and last verified
Commands, versions and facts in this guide were checked against the sources below on . Tools change quickly: if something differs from what you see, trust the official documentation and let us know.
- EUR-Lex: Regulation (EU) 2026/1744 (Digital Omnibus on AI): adopted 8 July 2026, published in the Official Journal 24 July 2026, in force 27 July 2026, amending Regulation (EU) 2024/1689 (read through a search-result summary; the page itself did not render in this session)
- Gibson Dunn: EU AI Act omnibus agreement, postponed high-risk deadlines (27 May 2026): Annex III 2 December 2027, Annex I 2 August 2028, Article 50 on 2 August 2026 with grace to 2 December 2026, Article 4 softened, GPAI in force since 2 August 2025 (written before formal adoption; used for the dates, which match the EUR-Lex summary)
- AI Act Service Desk: Annex III: Annex III has eight areas with specific use cases; not every system in an area is high-risk (read through a search-result summary)
- Swfte EU AI Act timeline page: internal cross-check of the same dates, verified October 2026 against the Commission timeline and EUR-Lex
- Swfte EU AI Act high-risk checklist page: Articles 9 to 15, 17, 25, 26 and 27 summaries used in the obligations step
Topics
- EU AI Act
- readiness
- risk classification
- Digital Omnibus
- AI literacy
- evidence
Machine-readable copies: this guide as markdown, index of all guides (JSON). Canonical address: https://www.swfte.com/how-to-prepare-for-the-eu-ai-act.