Skip to content
Knowledge centreServicesRatesAI ActE-learning sample

Knowledge you can put to work

The AI Act: what does it mean for your organisation?

The European AI regulation concerns how AI is used, your organisation’s role and risks to people. A register helps ask the right questions for each process.

Sources checked: 7 September 2026

AI Act timeline

Sources checked on 7 September 2026. This overview covers the main general milestones. Transitional rules, exceptions and your organisation’s role may change the assessment.

  1. The AI Act enters into force

    The regulation entered into force. Individual rules become applicable in stages.

  2. AI literacy and initial prohibitions

    The first provisions became applicable. Connect guidance and learning to actual AI use.

  3. Governance and general-purpose AI models

    Rules for governance and general-purpose AI model providers became applicable. A model provider has a different role from an organisation using a tool.

  4. AI Omnibus changes the schedule

    The amendment entered into force. Earlier schedules may therefore be outdated.

  5. Transparency for certain AI applications

    AI interaction and certain generated content require attention. Identify which obligation belongs to the provider or deployer and which exceptions apply.

  6. High-risk applications: Annex III

    The Commission identifies this date for high-risk rules in areas including employment, education and access to essential services. Classification depends on the actual use.

  7. High-risk AI in regulated products

    The extended timeline concerns the Annex I product route, including certain safety components. It is not a general exemption for all AI until 2028.

Start with your role

Do you use a purchased AI tool or place an AI system on the market yourself? Those roles can lead to different obligations. Have significant modifications or a new purpose assessed for possible changes to your role. A subscription to a familiar tool does not settle that question.

Classify the use, not the brand

The law distinguishes prohibited uses, high-risk AI and specific transparency duties. Summarising a document differs from ranking people for a job. Transparency and high risk may both be relevant. An initial assessment should therefore show its reasoning and remaining questions.

What can you record in the file?

Our practical approach starts with purpose, owner, supplier and data. We then record the role assessment, reasoned classification, required checks and responsible reviewer. A source reference and review date make the reasoning traceable. This supports documentation; it is not an automatic legal assessment.

Other questions remain alongside the AI Act

An AI legal classification does not replace assessing data protection, security or quality. Give those questions their own place in the file. An application with few AI Act duties may still be unsuitable for confidential business information.

From timeline to a plan

A date becomes meaningful once you know which application it affects. A useful plan assigns an owner, required expertise and a decision point to each open question. That supports focused preparation, even when a particular duty applies later.

What you can use it for

A per-process overview of role, reasoning, obligations, open questions and the next action.

This guide provides general information. Assessment of a specific application depends on your role, data and intended use.

Sources and further reading

European Commission — AI Act

European Commission — AI Omnibus, 27 July 2026

European Commission — transparency Q&A

This article was prepared with AI assistance and checked against our editorial and sourcing guidelines.