EU AI Act Navigator

Reference · content version 2026-08-06

The EU AI Act, after the Digital Omnibus

A current reference to Regulation (EU) 2024/1689 as amended: what applies today, what is still coming, which tier a system falls into, and what Article 50 actually requires. The dates below are the post-Omnibus ones — a great deal of material still on the internet is not.

Legal basis: Regulation (EU) 2024/1689 as amended by the Digital Omnibus on AI (European Parliament, 16 June 2026, 423–57; final Council approval, 29 June 2026). This page publishes the same methodology data the EU AI Act Navigator app ships with, so the two never disagree.

The post-Omnibus compliance timeline

Every application date in the Act, with what the Digital Omnibus changed. Two rows carry most of the practical consequence: transparency is live, and high-risk is not.

Obligation Article Applies from Status Max penalty What the Omnibus changed
Prohibited AI practices bannedSocial scoring, real-time remote biometric identification in public spaces, manipulation of vulnerable groups, emotion inference at work and in education. Art. 5 2 Feb 2025 In force €35M / 7% Nothing.
General-purpose AI model obligationsApplies to providers of GPAI models, not to organisations merely deploying systems built on them. Ch. V 2 Aug 2025 In force Nothing.
AI literacyOrganisation-level, regardless of tier, wherever staff operate or are affected by AI systems. Evidence should be role-specific and logged against the individual learner. Art. 4 2 Aug 2026 In force €7.5M / 1% Softened from “ensure a sufficient level” of AI literacy to “support its development” — an obligation of effort, not of result.
Transparency obligationsTell people they are talking to an AI; inform people exposed to emotion recognition or biometric categorisation; label AI-generated published content and deepfakes. Art. 50(1), 50(3), 50(4) 2 Aug 2026 In force €15M / 3% Not deferred. Only Art. 50(2) machine-readable marking moved — see the next row.
Machine-readable marking of generative outputProvider-side duty: outputs of generative systems must be marked in a machine-readable format as artificially generated or manipulated. Art. 50(2) 2 Dec 2026 Upcoming €15M / 3% Deferred from 2 Aug 2026 to 2 Dec 2026.
High-risk obligations — standalone Annex III systemsConformity assessment, risk management system, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy and robustness, EU database registration. Deployers: Art. 26 duties and, where applicable, an Art. 27 fundamental rights impact assessment. Ch. III + Annex III 2 Dec 2027 Upcoming €15M / 3% Deferred from 2 Aug 2026 by 16 months. This is the row most published guidance still gets wrong.
High-risk obligations — AI embedded in regulated productsAI systems that are safety components of products already covered by Annex I Union harmonisation legislation. Art. 6(1) + Annex I 2 Aug 2028 Upcoming €15M / 3% Deferred by 12 months.

Penalty figures are stated as the maximum of a fixed amount or a percentage of total worldwide annual turnover for the preceding financial year, whichever is higher. The Act’s penalty regime is in Article 99; national market surveillance authorities set the actual amount.

Two dates to put in the calendar now. 2 December 2026 — Art. 50(2) marking comes into force; re-check every system that generates content. 2 December 2027 — Annex III high-risk obligations come into force; re-check every system classified high, or conditionally high.

Article 50, in depth

Article 50 is the provision that matters commercially right now. It is live, it was not deferred, it carries a penalty tier three times Article 4’s, and it catches a far wider population than high-risk ever will — because almost every organisation now has something that talks to a person or produces published text.

The four duties

Tell people they are talking to an AIArt. 50(1)

Any system interacting directly with natural persons must inform them that they are interacting with an AI system, unless that is obvious from the context. Falls on both providers and deployers. Live since 2 August 2026.

Mark generative output machine-readablyArt. 50(2)

A provider-side duty: the outputs of generative systems must be marked in a machine-readable format as artificially generated or manipulated. This is the only part of Article 50 the Omnibus moved — to 2 December 2026.

Inform people exposed to the systemArt. 50(3)

Where emotion recognition or biometric categorisation is in use, the persons exposed to it must be informed of its operation. A deployer duty. Live since 2 August 2026.

Disclose AI-generated content and deepfakesArt. 50(4)

Deployers publishing AI-generated text on matters of public interest, or deepfake content, must disclose it. A deployer duty. Live since 2 August 2026.

Provider or deployer — and why the answer differs per system

The obligations diverge sharply, and most organisations assume “deployer” for everything and are wrong about at least one system. Establish the role per system, not once for the organisation.

The rule that catches people out

Disclosure must be perceptible to a human without a detection tool. A hidden machine-readable mark in the metadata does not satisfy a deployer’s Art. 50(4) duty, and a provider satisfying Art. 50(2) has not thereby satisfied Art. 50(1) or 50(4). The test is whether an ordinary person can see or hear the disclosure. The two duties stack; they do not substitute for each other.

It reaches outside the EU

Article 50 is not limited to organisations established in the Union. Providers are in scope where they place a system on the EU market or where the system’s output is used in the EU; deployers likewise where the output is used in the EU. A company with no EU entity, no EU office and an EU-facing chatbot or an EU readership for its AI-written articles is inside the scope of the Regulation.

What to do about it, in order

The four risk tiers

The Act is risk-tiered: obligations attach to what a system does and where it is used, not to the technology. A capability operating in an Annex III domain escalates above its base tier — which is why the same chatbot can be limited risk in marketing and high risk in recruitment.

Prohibited — unacceptable risk
Description
AI systems that pose an unacceptable risk to fundamental rights and safety. Banned under the EU AI Act.
Examples
Social scoring by governments, real-time biometric identification in public spaces (with limited exceptions), manipulation of vulnerable groups, emotion inference in workplace or education settings.
Obligations
These AI systems are banned and must not be deployed.
In force since 2 February 2025 · up to €35M / 7%
High risk
Description
AI systems used in critical areas that significantly affect people’s lives, health, safety, or fundamental rights.
Examples
AI in employment and recruitment, credit scoring, critical infrastructure management, education assessment, law enforcement, migration and border control.
Obligations
Conformity assessment, risk management system, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy and robustness requirements. Registration in the EU database required.
Applies from 2 December 2027 (standalone Annex III) or 2 August 2028 (embedded in Annex I products) · up to €15M / 3%
Limited risk
Description
AI systems with specific transparency obligations. Users must be informed they are interacting with AI.
Examples
Chatbots, AI-generated content, emotion recognition systems, biometric categorisation systems.
Obligations
Transparency: users must be informed of AI interaction. Deepfakes and AI-generated content must be labelled. Disclosure must be perceptible to a human without a detection tool.
In force since 2 August 2026; Art. 50(2) marking from 2 December 2026 · up to €15M / 3%
Minimal risk
Description
AI systems posing no or minimal risk. No specific regulatory requirements under the EU AI Act.
Examples
AI-powered spam filters, AI in video games, basic recommendation systems, simple automation.
Obligations
No specific obligations; voluntary codes of conduct are encouraged. Art. 4 AI literacy still applies at organisation level.
Art. 4 literacy in force since 2 August 2026
To be determined — the honest fifth state
Description
Not enough is known to classify honestly. This is a legitimate, tracked state — not a gap to be guessed at. An honest unknown beats a confident wrong answer, and it generates an investigation task.
Rule
Never auto-resolve. Only a human answer to the open question moves a system out of this state.
Why it matters
The other pattern real registries need is the conditional classification: minimal today, high risk the moment a dormant feature is switched on. Record the escalation trigger, and gate activation on a fresh assessment.

Annex III — the high-risk domains

Eight domains. A system operating in one of them is high risk regardless of how modest the technology looks. These are facts about where a system is used, so they have to be captured in discovery, not inferred from a product description.

Biometric identification and categorisationAnnex III §1

Remote biometric identification, biometric categorisation by sensitive attributes.

Critical infrastructureAnnex III §2

Safety components in the management of road traffic, water, gas, heating, electricity, and critical digital infrastructure.

Education and vocational trainingAnnex III §3

Admission, evaluation of learning outcomes, proctoring, steering the learning process.

Employment and workforce managementAnnex III §4

Recruitment and selection, targeted job advertising, decisions on promotion or termination, task allocation, monitoring and evaluation of workers. This is why HR-tool AI features are the canonical conditional case: any AI touching recruitment, employee assessment or workforce management is explicitly high risk.

Access to essential servicesAnnex III §5

Credit scoring, risk assessment and pricing in life and health insurance, emergency call dispatching, eligibility for public benefits.

Law enforcementAnnex III §6

Risk-of-offending assessments, evidence reliability evaluation, profiling in criminal investigations.

Migration, asylum and border controlAnnex III §7

Visa and asylum application examination, risk assessments of persons entering the EU.

Justice and democratic processesAnnex III §8

Assisting judicial authorities in researching and applying the law, influencing election outcomes.

Article 5 — prohibited practices

Banned outright since 2 February 2025, and carrying the Act’s highest penalty tier at up to €35 million or 7% of worldwide turnover. If a system matches one of these, the answer is not mitigation — it is discontinuation.

Manipulative or exploitative techniquesArt. 5(1)(a)–(b)

Subliminal or purposefully manipulative techniques; exploitation of vulnerabilities due to age, disability, or social or economic situation.

Social scoringArt. 5(1)(c)

Evaluation or classification of persons based on social behaviour or personal characteristics leading to detrimental treatment.

Individual predictive policingArt. 5(1)(d)

Risk assessments of persons to predict the commission of a criminal offence based solely on profiling or personality traits.

Untargeted scraping of facial imagesArt. 5(1)(e)

Creating or expanding facial recognition databases through untargeted scraping of the internet or CCTV footage.

Emotion inference in workplace or educationArt. 5(1)(f)

Emotion recognition systems in the areas of the workplace and education institutions, except for medical or safety reasons.

Biometric categorisation by sensitive attributesArt. 5(1)(g)

Categorisation of persons based on biometric data to deduce race, political opinions, trade union membership, religious beliefs, sex life or sexual orientation.

Real-time remote biometric identification in public spacesArt. 5(1)(h)

Banned for law enforcement purposes, with narrow exceptions.

The one most organisations trip over is Art. 5(1)(f). Emotion inference in the workplace or in an education institution is prohibited, not merely high risk. Sentiment scoring of employee communications, engagement analytics that infer mood, and proctoring that reads affect all belong in this conversation — and they are usually bought as a feature of something else.

Penalty tiers

Three bands. Each is expressed as a fixed maximum or a percentage of total worldwide annual turnover for the preceding financial year, whichever is higher.

Band Maximum Attaches to
Highest €35M / 7% Prohibited practices under Article 5.
Standard €15M / 3% Transparency obligations under Article 50, and the high-risk obligations once they apply (2 Dec 2027 / 2 Aug 2028).
Lower €7.5M / 1% AI literacy under Article 4.

The penalty regime is set out in Article 99; enforcement and the actual amount are matters for national market surveillance authorities. The figures above are the maxima encoded in this app’s methodology data — they are not a prediction of what any given authority will impose.

Official sources

Primary legislation and Commission guidance first. Where a law-firm analysis is cited it is because it dates and summarises the Omnibus changes precisely — but the Regulation and the Commission’s own material are the references to rely on.

Turn this into your own registry

EU AI Act Navigator applies exactly this methodology to your organisation: a guided discovery interview to find the AI, an honest classification per system, obligations mapped to the timeline above, and the registry and action plan exported as documents. It runs entirely on your iPhone — no account, no server, nothing leaves the device.

See what the app does
This page is a reference, not legal advice. It summarises Regulation (EU) 2024/1689 as amended by the Digital Omnibus, as understood at content version 2026-08-06. Summaries lose detail, the law continues to move, and every organisation’s situation differs. Read the Regulation itself for anything that matters, and have your assessment validated by qualified legal counsel before relying on it.