Framework guide
EU AI Act Framework Guide
The EU AI Act is the first comprehensive AI regulation. Article 50 transparency duties, GPAI enforcement powers, and the penalty regime took effect on 2 August 2026; the high-risk conformity regime was deferred by the Digital Omnibus to 2 December 2027 and 2 August 2028.
By the Shieldra Compliance Team · Last updated July 2026
Key takeaways
- Article 50 transparency, GPAI enforcement powers, and the penalty regime applied from 2 August 2026 and were NOT deferred.
- The high-risk regime was deferred: Annex III standalone systems to 2 December 2027, Annex I embedded systems to 2 August 2028.
- "The EU delayed the AI Act" is imprecise — the conformity obligations moved, the transparency and penalty provisions did not.
- Penalties for Article 50 and GPAI breaches reach the greater of €15 million or 3% of total worldwide annual turnover.
- The Act is extraterritorial: it reaches AI placed on the EU market or whose output is used in the EU, wherever the provider sits.
What the EU AI Act covers
The Act takes a risk-based approach. A small set of practices is prohibited outright. A defined category of high-risk systems carries heavy obligations. And a broad transparency layer applies to systems that interact with people or generate content, regardless of risk tier.
Prohibited practices
A narrow set of uses banned outright, including untargeted scraping of facial images to build recognition databases, social scoring by public authorities, and certain manipulative or exploitative systems.
High-risk systems
Annex III lists standalone high-risk uses such as employment, education, credit, and essential services; Annex I covers AI embedded in already-regulated products. Obligations include risk management, data governance, technical documentation, human oversight, and conformity assessment.
Article 50 transparency
The layer that applies most broadly and is already enforceable: tell people when they are interacting with AI, mark AI-generated content machine-readably, disclose deep fakes, and notify people subject to emotion recognition or biometric categorisation.
What applies now, and what was deferred
The Digital Omnibus, adopted by Parliament on 16 June 2026 and Council on 29 June 2026, changed the timeline — but only for part of it. Knowing which part is the difference between a gap you have today and one you have in 2027.
| Obligation | Applies from |
|---|
| Article 50 transparency duties | 2 August 2026 — not deferred |
| GPAI enforcement powers | 2 August 2026 — not deferred |
| Penalty regime (€15M or 3% of turnover) | 2 August 2026 — not deferred |
| Watermarking, systems already on the market | 2 December 2026 (grandfathered) |
| Annex III standalone high-risk systems | 2 December 2027 (deferred from 2 Aug 2026) |
| Annex I embedded high-risk systems | 2 August 2028 (deferred from 2 Aug 2027) |
The four Article 50 duties
- Article 50(1) — inform people they are interacting with an AI system, at or before first interaction, unless it is obvious
- Article 50(2) — mark synthetic audio, image, video, and text with machine-readable markers; a visible label alone is not sufficient
- Article 50(4) — disclose deep fakes where output resembles real people, objects, places, or events and could appear authentic
- Article 50(3) — inform people exposed to emotion recognition or biometric categorisation, and process personal data under the GDPR
High-risk obligations (Articles 9-15)
What you will need to demonstrate by the deferred dates. The deferral changes when these bite, not their scope.
- A risk management system running across the whole system lifecycle
- Data governance covering training, validation, and testing datasets
- Technical documentation sufficient to demonstrate conformity
- Automatic record-keeping and event logging
- Transparency and clear information for deployers
- Human oversight designed into the system
- Appropriate accuracy, robustness, and cybersecurity
- Conformity assessment before market placement, and post-market monitoring afterwards
How it relates to ISO 42001, GDPR, and SOC 2
ISO/IEC 42001 is the international standard for an AI management system. The Act does not mandate it, but it is widely used as the organisational framework for demonstrating systematic compliance with Articles 9-15, and enterprise buyers increasingly ask for it by name.
The GDPR applies in parallel wherever personal data is involved — Article 50(3) explicitly requires emotion recognition and biometric categorisation to be processed in line with it. SOC 2 and ISO 27001 cover the security controls underneath an AI system but say nothing about AI-specific duties such as transparency, human oversight, or training-data governance. They are complementary, not substitutes.
In practice the commercial trigger arrives before the regulatory one: enterprise procurement has started attaching AI governance questions to security questionnaires, and vendors without a defensible answer are delayed or excluded. This page is general information about the regulation, not legal advice.
Frequently asked questions
What is the EU AI Act in simple terms?
It is the first comprehensive law regulating artificial intelligence, using a risk-based approach. A small number of practices are banned, a defined set of high-risk uses carries heavy obligations such as risk management and conformity assessment, and a broad transparency layer requires you to tell people when they are dealing with AI or AI-generated content.
Did the EU delay the AI Act?
Only partly, and the common framing is misleading. The Digital Omnibus deferred the high-risk conformity regime — Annex III standalone systems to 2 December 2027 and Annex I embedded systems to 2 August 2028. Article 50 transparency, GPAI enforcement powers, and the penalty regime were not deferred and applied from 2 August 2026.
What does Article 50 actually require?
Four things: inform people when they are interacting with an AI system; mark AI-generated audio, image, video, and text with machine-readable markers; disclose deep fakes that could appear authentic; and inform people subject to emotion recognition or biometric categorisation. It applies regardless of whether the system is high-risk.
Does the EU AI Act apply to companies outside the EU?
Yes, it can. The Act reaches AI systems placed on the EU market and systems whose output is used in the EU, so a company with no EU entity can still be in scope through its EU users or customers.
What are the penalties under the EU AI Act?
Article 50 and GPAI breaches carry penalties of up to the greater of €15 million or 3% of total worldwide annual turnover. Prohibited-practice breaches carry a higher maximum tier.
Is ISO 42001 required for EU AI Act compliance?
No. The Act does not mandate ISO/IEC 42001. It is widely adopted as the AI management system framework for demonstrating systematic compliance, and enterprise buyers often ask for it, but it is a voluntary certification rather than a legal requirement.