EU AI Act in 2026: What Applies Now and What Comes Next
Europe’s AI rulebook is arriving in stages, so a compliance calendar matters as much as the legal text.
Wirenova Staff
The European Union’s Artificial Intelligence Act is often described as though it switched on in a single moment. It did not. The law entered into force on 1 August 2024, but its obligations were deliberately phased. That design makes the position in 2026 more complicated—and more practical—than a simple claim that the Act is either “in force” or “not yet applicable.”
Three layers are already relevant
The first operational layer arrived on 2 February 2025. It included prohibitions on a limited set of practices considered incompatible with fundamental rights and an obligation for providers and deployers to take measures supporting an appropriate level of AI literacy among relevant staff.
The second layer arrived on 2 August 2025. It brought governance provisions and obligations concerning general-purpose AI models into application. It also established a clearer institutional structure around the European AI Office and national authorities.
The third layer is the wider set of obligations scheduled through the Act’s implementation calendar. The European Commission’s current timeline should be treated as the operational reference because the EU has continued to refine how particular high-risk provisions are sequenced. Organizations should therefore record both the underlying legal requirement and the date on which it applies to their specific role.
Risk classification comes before paperwork
The Act is built around different levels and types of risk. A chatbot used to answer routine internal questions does not automatically face the same requirements as a system used in recruitment, medical-device safety, credit decisions, or access to essential services.
The sensible first step is an inventory: what systems are used, what they do, whose decisions they affect, where the model came from, and whether the organization is a provider, deployer, importer, or distributor. Those roles matter because the same technology can create different legal duties for the company that develops it and the organization that operates it.
An inventory also prevents a common compliance failure: producing a general AI policy while missing AI embedded inside purchased software. Recruitment tools, fraud systems, customer-service platforms, and analytics products can all contain model-driven functions that are not obvious from their branding.
Documentation should follow the system lifecycle
Good preparation is not a one-time legal memo. It is a repeatable record of purpose, data, testing, human oversight, incidents, and change control. A model can be acceptable for one defined task and inappropriate after it is repurposed, connected to new data, or allowed to influence a higher-stakes decision.
Teams should identify a business owner and a technical owner for each material system. They should document the intended use, foreseeable misuse, affected groups, evaluation criteria, and escalation path. Vendor contracts should make it possible to obtain the information needed for that record rather than relying on marketing claims about “responsible AI.”
What the 2026 transition means
The most useful interpretation of 2026 is not that every company must build an enormous compliance department. It is that informal AI adoption is becoming harder to defend. A small organization with a precise register, clear decision rights, proportionate testing, and trained staff can be better prepared than a large organization with scattered policy documents.
The timeline also argues against waiting for the last possible date. Classifying systems, obtaining vendor evidence, and creating monitoring procedures take time. If an application might fall into a high-risk category, the organization should preserve the evidence that supports its classification and seek specialist legal advice before deployment.
The bottom line
The EU AI Act is a staged operating framework, not a single launch day. Some duties already apply, other obligations depend on the system and the implementation calendar, and further details may be clarified through standards and guidance. The durable response is to know where AI is used, understand the role and risk attached to each use, and maintain evidence throughout the system’s lifecycle.
Topics
Sources used
- European CommissionAI Act: regulatory framework for artificial intelligence
- EUR-LexRegulation (EU) 2024/1689
Sources support the factual claims in this explainer. Wirenova’s wording and structure are original.
