AI Compliance · 2026-07-30 · 10 min read
EU AI Act Compliance Checklist 2026: What to Do Before August 2
Article 50 transparency duties apply from 2 August 2026, backed by a penalty regime in force since 2 August 2025 — and no, the Digital Omnibus did not delay them. Here is the seven-step compliance checklist startups and SMBs can work through this week, with every deadline that actually matters.
An EU AI Act compliance checklist for 2026 covers seven steps: inventory every AI system you build or use, determine whether you are a provider or deployer, classify each system's risk tier, implement Article 50 transparency disclosures, deliver Article 4 AI literacy training, vet your AI vendors, and document everything. The most urgent deadline: Article 50 transparency duties apply from 2 August 2026. The general penalty regime that backs them has been in force since 2 August 2025.
That date is days away. If your product includes a chatbot, generates images, audio, video, or text at scale, or uses emotion recognition, you have concrete disclosure duties starting this week — and the fines that back them start at the same moment. This guide walks through exactly who owes what, when, and the seven steps that get a startup or SMB compliant without a compliance department.
Which EU AI Act deadlines apply in 2026?
The EU AI Act phases in over several years, and the Digital Omnibus (adopted June 2026) reshuffled part of that timeline. Here is the current schedule:
| Obligation | Who it covers | Status |
|---|---|---|
| Article 4 — AI literacy | Providers and deployers | In force since 2 February 2025 |
| Article 5 — prohibited practices | Everyone | In force since 2 February 2025; penalties up to €35M or 7% of worldwide turnover |
| Article 50 — transparency disclosures | Providers and deployers of chatbots, generative AI, deep fakes, emotion recognition | Applies from 2 August 2026 |
| General penalty regime (up to €15M or 3%) | All in-scope organizations | In force since 2 August 2025 (Art. 113(b)) |
| GPAI enforcement | General-purpose model providers | Applies from 2 August 2026 |
| Watermarking grandfather period | Systems placed on the market before 2 Aug 2026 | Compliance required by 2 December 2026 |
| High-risk regime — Annex III standalone systems | Providers and deployers of high-risk AI | Applies from 2 December 2027 |
| High-risk regime — Annex I embedded systems | AI embedded in regulated products | Applies from 2 August 2028 |
Two things stand out for small companies. First, two obligations have already been live for over a year: the Article 4 AI literacy duty and the Article 5 prohibitions, both in force since 2 February 2025. Second, the nearest cliff is 2 August 2026, when Article 50 transparency duties switch on — backed by a penalty regime that has been live since 2 August 2025.
Did the EU delay the AI Act? No — only the high-risk regime moved
You have probably seen headlines saying the EU "delayed" or "paused" the AI Act. That framing is dangerously imprecise, and acting on it is how companies walk into penalties.
Here is what the Digital Omnibus, adopted in June 2026, actually did:
- Deferred: the high-risk conformity regime only. Annex III standalone high-risk systems now apply from 2 December 2027, and Annex I embedded systems from 2 August 2028.
- Not deferred: Article 4 (AI literacy), Article 5 (prohibited practices), Article 50 (transparency), GPAI obligations, and the penalty regime. All of these are either in force already or apply from 2 August 2026 exactly as scheduled.
If your exposure is a customer-facing chatbot or AI-generated content — which describes most startups — the "delay" changes nothing for you. Your deadline did not move.
The EU AI Act compliance checklist: 7 steps
Work through these in order. Steps 1–3 tell you what you owe; steps 4–7 discharge the obligations.
1. Inventory every AI system you build or use
You cannot classify what you have not found. List every AI system in two buckets:
- What you ship: chatbots, recommendation features, content generation, scoring or screening logic, anything calling a model API in production.
- What your team uses: ChatGPT, Copilot-style tools, AI features inside SaaS products, and the unsanctioned tools employees adopted without telling anyone.
That second bucket is where most inventories fail. Employees adopt AI tools far faster than IT approves them, so a survey alone will undercount. Our shadow AI discovery guide covers how to find AI usage you do not know about. For each system, capture what it does, who interacts with it, what data flows through it, and which vendor sits underneath.
2. Determine your role: provider or deployer
The EU AI Act assigns duties by role — provider, deployer, importer, or distributor — and most companies get this wrong in a predictable way.
| Role | You are this if... | Core exposure |
|---|---|---|
| Provider | You develop an AI system and place it on the market under your name | The heaviest duties, including Article 50 provider-side disclosures |
| Deployer | You use an AI system under your authority (e.g., an AI tool in operations or hiring) | Use-side duties, including deployer disclosures and AI literacy |
The predictable mistake: assuming that building on someone else's model makes you a mere user. It does not. Building your product on a model API (OpenAI, Anthropic, or similar) typically makes you the provider of your downstream feature — the model vendor holds the GPAI duties for the underlying model, but your chatbot, your generator, your scoring feature is yours. If you charge customers for an AI feature, plan on provider duties for it.
Most companies are both: provider of what they ship, deployer of what they buy. If you are still unsure whether the law reaches you at all, start with does the EU AI Act apply to my company.
3. Classify each system's risk tier
Each inventoried system lands in one of four buckets:
- Prohibited (Article 5): practices like manipulative techniques that cause significant harm — banned since 2 February 2025, with fines up to €35M or 7% of worldwide turnover. Confirm nothing you run comes near this line.
- High-risk: systems in areas like hiring, credit, and education. Duties are deferred to 2 December 2027 (Annex III) and 2 August 2028 (Annex I) — but classification work should happen now, because the remediation lift is the largest.
- Transparency-tier (Article 50): chatbots, generative AI, deep fakes, emotion recognition. Duties apply from 2 August 2026.
- Minimal risk: everything else — no specific obligations, but keep it on the inventory.
You can get a per-system risk tier and role-scoped obligation list, with statutory citations, in about three minutes using our free EU AI Act checker — no signup required.
4. Implement Article 50 transparency disclosures
This is the step with the live deadline. From 2 August 2026, Article 50 requires:
- AI interaction disclosure: people must be told when they are interacting with an AI system, such as a chatbot, unless it is obvious.
- Marking AI-generated content: AI-generated or AI-manipulated content — text, images, audio, video — must be marked as such.
- Deep-fake disclosure: AI-generated or manipulated content depicting real people, places, or events must be disclosed.
- Emotion-recognition disclosure: people exposed to emotion recognition or biometric categorization systems must be informed.
One relief valve: systems already placed on the market before 2 August 2026 get a watermarking grandfather period running until 2 December 2026. New systems get no such grace. For implementation details — where the disclosure goes, what counts as "clearly distinguishable," and how the provider/deployer split works — see our deep dive on Article 50 transparency obligations.
5. Run Article 4 AI literacy training
Article 4 has been in force since 2 February 2025, and it binds providers and deployers: you must ensure a sufficient level of AI literacy in the staff who operate and use AI systems on your behalf. In practice that means role-appropriate training — what the tools can and cannot do, where they fail, and what your internal rules are — plus a record that the training happened. If ten employees use ChatGPT and your product has an AI feature, this duty already applies to you today.
6. Vet your AI vendors
Your compliance posture inherits your vendors' behavior. For every AI vendor in the inventory, establish: whether they train on your data by default, what their Article 50 support looks like (do they mark generated content?), where data is processed, and what they contractually commit to. Do this before renewal dates, not after an incident. Our list of AI vendor risk assessment questions gives you a ready-made questionnaire.
7. Document everything
Every step above should leave a paper trail: the inventory itself, the role determination and risk classification per system (with reasoning), disclosure implementations with screenshots and dates, training completion records, and vendor assessments. If a market surveillance authority ever asks, "we did it" without evidence is functionally the same as not having done it. An AI acceptable use policy ties the program together and gives the training in step 5 something concrete to teach.
What happens if you miss the 2 August 2026 deadline?
From 2 August 2026 the transparency obligations are backed by the general penalty regime — in force since 2 August 2025 — with fines up to €15M or 3% of worldwide turnover. Prohibited practices already carry up to €35M or 7% and have since 2 February 2025. For a startup, the realistic near-term risk is less the headline fine and more what rides on compliance: enterprise customers now send AI compliance questionnaires during procurement, and "we have not classified our systems" loses deals before any regulator gets involved.
Shieldra automates this checklist — deterministic, citation-backed classification, an AI system inventory, shadow-AI discovery across 284 known tools, built-in Article 4 literacy courses, and readiness reports you can hand to a customer or auditor. Plans start at $299/month with a 14-day free trial and no credit card — see pricing, or get your risk tier free in three minutes with the EU AI Act checker.
FAQ
When does the EU AI Act apply?
It is already partially in force. The Article 4 AI literacy duty and Article 5 prohibited practices have applied since 2 February 2025. Article 50 transparency obligations apply from 2 August 2026, backed by a penalty regime in force since 2 August 2025, while the high-risk regime applies from 2 December 2027 (Annex III standalone systems) and 2 August 2028 (Annex I embedded systems).
Did the EU delay the AI Act to 2027?
No. The Digital Omnibus, adopted in June 2026, deferred only the high-risk conformity regime — to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. Article 4, Article 5, Article 50, GPAI obligations, and penalties were not deferred. If your exposure is a chatbot or generated content, your deadline is still 2 August 2026.
If I build my product on the OpenAI or Anthropic API, am I a provider?
Typically yes, for your own feature. Building your product on a model API generally makes you the provider of the downstream system you place on the market, while the model vendor holds the GPAI duties for the underlying model. That means Article 50 provider-side duties — like disclosing AI interaction and marking generated content — land on you, not on the API vendor.
What are the penalties under the EU AI Act?
Prohibited practices under Article 5 carry fines up to €35M or 7% of worldwide turnover, and that regime has been in force since 2 February 2025. The general penalty regime — up to €15M or 3% of worldwide turnover — has applied since 2 August 2025; the Article 50 transparency obligations it backs begin on 2 August 2026.
What should a startup do before 2 August 2026?
Three things, in order: inventory your AI systems, classify each one's risk tier and your role for it, and implement Article 50 disclosures for anything transparency-tier — chatbot disclosure, marking of generated content, deep-fake and emotion-recognition notices. Systems already on the market before 2 August 2026 get until 2 December 2026 on watermarking; everything else needs to be compliant on day one.