Template · Article 113 (application timeline) · Key duties live since 2 February 2025; next deadline 2 December 2026

EU AI Act Compliance Checklist 2026: Deadlines & Scope Memo

An EU AI Act compliance checklist for 2026 is a dated record of which obligations under Regulation (EU) 2024/1689 apply to your company now and which come later, using the timeline as amended by the Digital Omnibus (Regulation (EU) 2026/1744, adopted 8 July 2026, in force since 27 July 2026). As of August 2026, the Article 5 prohibitions and Article 4 literacy duty (since 2 February 2025) and the Article 50 transparency duties (since 2 August 2026) are live; the CSAM/NCII safeguards deadline is 2 December 2026; Annex III high-risk obligations follow on 2 December 2027 and the Annex I product track on 2 August 2028.

Last reviewed: 26 August 2026 · Key duties live since 2 February 2025; next deadline 2 December 2026 · Included in the kit as 13_Compliance_Calendar_and_Scope_Memo.docx

First page of 13_Compliance_Calendar_and_Scope_Memo.docx from the RegShelf EU AI Act Kit
First page of 13_Compliance_Calendar_and_Scope_Memo.docx — the document you receive in the kit.

What this document is

Document 13 is the capstone of the RegShelf kit, in three parts. Part A is a fill-in scope memo that records, in writing, what the EU AI Act means for your company — including what you concluded does not apply and why, because a reasoned "not applicable" is evidence of diligence while an empty field looks like an unasked question. Part B is the deadline calendar with every date as corrected by the Digital Omnibus. Part C lists the review triggers that should make you re-run your checks. Together they turn a good-faith analysis into a defensible written position.

Who needs it

Every SME that has worked through — or is about to work through — the rest of its AI Act homework and needs one place where the conclusions live. Founders and ops leads without a legal team benefit most from Part A's discipline: one row per legal role you actually hold (deployer for these systems, provider for those), a checklist of what applies now versus later, and a reasoned-exclusions table ("we are not a GPAI provider because…") signed and dated. That memo is also the document a lawyer, investor or enterprise customer will ask for first.

The deadlines — precisely

The calendar in Part B, reflecting Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744:

  • 2 February 2025 — Article 5 prohibitions in force (fines up to €35M/7%; for SMEs and small mid-caps the lower of percentage and fixed amount applies, Article 99(6)); Article 4 AI literacy duty begins.
  • 2 August 2025 — GPAI obligations (Articles 53 ff.) for providers of general-purpose models.
  • 2 August 2026 — GPAI enforcement begins; Article 50 transparency duties apply: AI-interaction disclosure, machine-readable marking of synthetic content, deepfake and public-interest-text labels.
  • 2 December 2026 — technical safeguards against CSAM/NCII generation must be in place (prohibitions inserted into Article 5 by the Omnibus); also the end of the Article 50(2) marking transition for generative systems on the market before 2 August 2026.
  • 2 December 2027 — Annex III high-risk obligations apply (moved from August 2026 by the Omnibus): risk management, data governance, technical documentation, conformity assessment, registration, deployer duties including human oversight and, where required, the FRIA.
  • 2 August 2028 — AI in Annex I Section A regulated products (medical devices, toys and similar). Machinery sits in Annex I Section B since the Omnibus, so AI in machinery follows the machinery framework rather than the Section A conformity path.
  • 2 August 2030 — extended transition for certain pre-existing high-risk systems used by public authorities (Article 111).

What's inside the RegShelf template

Part A: a company-profile table (including size — relevant to the SME fine cap and simplified documentation); a role summary table fed from the inventory (doc 09); an "applies NOW" checklist covering Articles 5, 4, 50 and the GPAI duties; an "applies LATER" checklist for December 2026, December 2027 and August 2028; and the reasoned-exclusions table with worked examples. Part B: the eight-row deadline calendar above, with columns for your action, owner and status, and the practical warning that high-risk preparation realistically takes 12–18 months — begin when a system enters the inventory, not when the deadline nears. Part C: six review triggers — new AI feature or use case, vendor changes, new Commission guidance or amendments, role changes such as white-labelling, incidents, and a quarterly review regardless — each mapped to the kit documents to re-run, plus a trigger log.

How to use it

Complete Part A after finishing your AI system inventory and the screening documents it feeds. Strike through calendar rows your exclusions rule out, assign an owner and status to the rest, and have management approve the memo. Then let Part C keep it honest: re-screen on every trigger event and re-approve quarterly. Where a deadline reveals a gap — say, a generative feature without documented safeguards ahead of 2 December 2026 — the calendar points you to the kit document that addresses it, such as the prohibited practices screen.

Related reading

Frequently asked

What EU AI Act deadlines apply in 2026?+

Two are live and one is coming: the Article 5 prohibitions and Article 4 literacy duty have applied since 2 February 2025; the Article 50 transparency duties and GPAI enforcement started 2 August 2026; and by 2 December 2026, providers of generative systems must have technical safeguards against CSAM/NCII generation in place — the same date the Article 50(2) marking transition for pre-August-2026 systems ends.

When do the high-risk obligations of the EU AI Act apply?+

From 2 December 2027 for Annex III systems (recruitment, credit, education and the other listed areas) — a date moved by the Digital Omnibus — and from 2 August 2028 for AI in Annex I Section A regulated products. Certain pre-existing systems used by public authorities have until 2 August 2030 (Article 111).

What did the Digital Omnibus change about the AI Act timeline?+

Regulation (EU) 2026/1744 (adopted 8 July 2026, in force since 27 July 2026) moved the Annex III high-risk date to 2 December 2027, added the CSAM/NCII prohibitions applying from 2 December 2026, moved machinery from Annex I Section A to Section B, extended the SME lower-of-two fine cap to small mid-caps, and replaced the post-market-monitoring implementing act with Commission guidance due by 2 September 2027.

What are the fines for missing an AI Act deadline?+

Maximum fines are €35M/7% of worldwide turnover for prohibited practices, €15M/3% for most other violations, and €7.5M/1% for supplying incorrect information. For most undertakings the higher of the two figures caps the fine; for SMEs, start-ups and small mid-caps, Article 99(6) caps it at the lower of the two.

Primary sources

This template ships in the EU AI Act Kit

24 fill-in documents in Word and Excel — launch price €149, twelve months of updates included.

See the full kit