The EU AI Act, grouped by obligation.
Every analysis, checklist and tool this desk has published on Regulation (EU) 2024/1689, arranged by the duty it addresses: the Article 26 operator provisions, the Article 27 FRIA, the Article 14 oversight standard, and enforcement. Since the Digital Omnibus, the Annex III operator provisions apply from 2 December 2027. Pieces written before it carry a note saying what moved.
After the Omnibus. Start here.
What Regulation (EU) 2026/1744 changed, the dates it left in place, and what a deployer does with the time before Annex III applies.
- The Digital Omnibus is now in force. What actually changed for AI deployers.The Digital Omnibus on AI entered into force 27 July 2026. Annex III moves to December 2027. Here is exactly what changed for deployers and what did not.
- 2 December 2026: the EU AI Act deadlines the Omnibus did not move.The Omnibus moved the high-risk deadlines to 2027 and 2028. Three obligations still land in the first nine days of December 2026. What they are and who they reach.
- Sixteen extra months. What a deployer should actually do with them.The Omnibus moved Annex III to 2 December 2027. Standing the programme down costs more than it saves, because the strongest evidence can only be built forward.
The operator provisions. Article 26.
The continuing duties of any organisation deploying a high-risk AI system in the European Union. These are the foundations.
- 100 days to August 2. The EU AI Act operator checklist for deployers who are not ready.Written in April 2026, when 2 August 2026 was the operator deadline, and kept as a record. Annex III now applies from 2 December 2027.
- EU AI Act operator obligations. A 2026 compliance guide.A practical 2026 guide to the EU AI Act operator obligations: Article 26 duties, human oversight, logging, incident reporting, and the deadlines every deployer must meet.
- AI liability chains. How EU law splits responsibility between provider and deployer.When an AI agent causes harm, who is liable: the model provider, the integrator, or the deployer? A structured reading of EU law's multi-party liability framework.
- When AI agents make mistakes. Who is liable under EU law.A clear reading of AI agent liability under the Revised Product Liability Directive, the EU AI Act, and national case law beginning to shape deployer responsibility.
- How to document AI agent risk management for compliance.A practical nine-document framework for AI agent risk management documentation under the EU AI Act: Article 9, Article 12, Article 26, and ISO 42001 in one file.
The fundamental rights impact assessment. Article 27.
Public bodies, providers of public services and deployers of credit scoring and life and health insurance pricing systems complete a FRIA before first use. It now falls due with Annex III on 2 December 2027.
- EU AI Act Article 27. The Fundamental Rights Impact Assessment every deployer must file.A 2026 guide to the Fundamental Rights Impact Assessment under Article 27 of the EU AI Act. Who must file, what it contains, and how to maintain it.
- The 90-day FRIA countdown. A deployer checklist for EU AI Act Article 27.A deployer checklist, template structure and supervisor notification guide for Article 27, written for the original 2 August 2026 date. The FRIA now falls due with Annex III on 2 December 2027.
Human oversight. Articles 14 and 13.
Providers build oversight into high-risk systems; deployers staff and document it. Both sides of the obligation.
- EU AI Act Article 14. The human oversight design requirement explained.What Article 14 of the EU AI Act requires deployers to build, staff and document for high-risk AI systems. Annex III now applies from 2 December 2027.
- EU AI Act Article 13. Transparency requirements for high-risk AI providers and deployers.Article 13 of Regulation (EU) 2024/1689 requires high-risk AI systems to be transparent. This guide sets out what providers must supply and what deployers must pass on.
Enforcement and penalties.
Articles 99 and 101 set the penalty tiers, and the penalty regime has applied since 2 August 2026 to obligations already in application. How the authorities fit together, and how product liability sits beside the Act.
- EU AI Act enforcement. Who is watching and what they can do to you.How the EU AI Act enforcement architecture works: the AI Office, national market surveillance authorities, and the penalty tiers that have applied since 2 August 2026.
- EIOPA's AI governance opinion and what it means for EU AI Act alignment.EIOPA's Opinion on AI governance and risk management of 6 August 2025, mapped to EU AI Act obligations under Articles 9, 14, 17 and 26 of Regulation (EU) 2024/1689.
- The Double Exposure. EU AI Act and the Revised Product Liability Directive in 2026.The EU AI Act and the revised Product Liability Directive create a double exposure for AI deployers in 2026. The dates, the rebuttable presumption, the operator file.
- The revised Product Liability Directive and AI software exposure.Directive 2024/2853 makes AI software a product subject to strict liability. A European operator's guide to the exposure that lands in December 2026.
Tools for the file.
Free to use, no registration, and nothing you enter leaves your browser.
- EU AI Act Article 49: registration in the EU database, and the one entry a deployer makes
- AI already on the market on 9 December 2026: which product liability regime applies?
- The first European supervisory answer on frontier AI came through DORA
- For most high-risk AI, the Act asks the provider to assess itself
- The Article 50 instruments are finished. The high-risk ones are not.
- The Commission's own article pages are not the amended AI Act text
- Sixteen extra months. What a deployer should actually do with them.
- 2 December 2026: the EU AI Act deadlines the Omnibus did not move.
- The Digital Omnibus is now in force. What actually changed for AI deployers.
- South Korea AI regulation 2026: an operators guide.
- India AI regulation 2026: complete operators guide.
- Switzerland AI regulation 2026: an operators guide.
- EU AI Act Article 26: the final three-week deployer checklist before August 2, 2026.
- AI regulation penalties by jurisdiction: a 2026 comparison tracker.
- Australia AI regulation 2026: operators guide.
- EU AI Act Article 3: key definitions for providers and deployers.
- Does my professional liability or E&O policy exclude AI mistakes?
- EU AI Act Article 25. When a deployer or distributor becomes the provider.
- EU AI Act Article 4. AI literacy obligations that have been in force since February 2025 and apply to every deployer.
- EU AI Act Article 99. Penalties, fine tiers, and what deployers actually face.
- The EU AI Act for deployers. A complete operator orientation.
- Who is liable when an AI agent makes a mistake?
- EU AI Act Article 86: the right to explanation of individual decision-making, a deployer guide
- South Africa AI regulation 2026: operators guide.
- EU AI Act Article 72: post-market monitoring obligations for high-risk AI deployers
- EU AI Act national supervisors in 2026. BaFin, AFM, ACPR and what each one is actually building.
- Serious incident reporting under Article 73. What deployers must do.
- EU AI Act Article 15. Accuracy, robustness and cybersecurity requirements for high-risk AI.
- EU AI Act Article 43. The conformity assessment procedures that govern whether a high-risk AI system can legally reach the market.
- EU AI Act Article 6. The classification decision that determines whether high-risk obligations apply.
- EU AI Act Article 11. The technical documentation obligation that underpins every high-risk AI deployment.
- EU AI Act Annex III. The eight categories that determine whether your AI deployment is high-risk.
- EU AI Act Article 16. Ten obligations providers must meet before a high-risk AI system reaches any deployer.
- EU AI Act Article 12. The logging requirement that underpins every compliance defence and every insurance claim.
- The EU AI Act's eight prohibited practices: what operators need to know.
- EU AI Act Article 10: What Deployers Must Understand About Data Governance for High-Risk AI
- EU AI Act Chapter V. What deployers building on GPAI models actually face.
- EU AI Act Article 17. Technical documentation and what deployers must demand from providers.
- EU AI Act Article 26. Every deployer obligation, read in sequence.
- EU AI Act Article 9. The risk management system that every high-risk AI deployment depends on.
- The Digital Omnibus on AI explained. The April 2026 record, superseded.
- EU AI Act Article 50. The transparency and labelling obligations every deployer must implement by 2 August 2026.
- EU AI Act Member State Implementation Tracker. Where each of the 27 stands.
- 100 days to August 2. The EU AI Act operator checklist for deployers who are not ready.
- AI policy exclusions in 2026. What your existing coverage actually excludes.
- The Double Exposure. EU AI Act and the Revised Product Liability Directive in 2026.
- The 90-day FRIA countdown. A deployer checklist for EU AI Act Article 27.
- EU AI Act Article 27. The Fundamental Rights Impact Assessment every deployer must file.
- EU AI Act Article 14. The human oversight design requirement explained.
- EU AI Act enforcement. Who is watching and what they can do to you.
- EIOPA's AI governance opinion and what it means for EU AI Act alignment.
- EU AI Act Article 13. Transparency requirements for high-risk AI providers and deployers.
- AI liability chains. How EU law splits responsibility between provider and deployer.
- The revised Product Liability Directive and AI software exposure.
- EU AI Act operator obligations. A 2026 compliance guide.
- When AI agents make mistakes. Who is liable under EU law.
- How to document AI agent risk management for compliance.