The EU AI Act Tracker
A record of what has moved, with dates and sources.
I don’t know if it is just me, but I feel like it’s becoming increasingly hard to keep track of all the guidelines, Q&As and codes the EU publishes for the AI Act. Especially in combination with the timeline. What is applicable when, which guideline is in force and which one is still in public consultation. And what should a small company actually do, and when?
OK, I have to be honest. From the conversations I have, I know it’s not just me. That’s why I decided it’s high time I publish this AI Act Tracker.
I will update the Tracker whenever something moves. The date below tells you when I last checked and updated the Tracker.
Just one disclaimer (because I’m a lawyer, you know): This is not a legislative history. The Future of Life Institute maintains one of those, plus an implementation timeline of what is still ahead. This is a different thing: a running record of what has already changed, and what changed for you and me as a result.
Last checked: August 2, 2026.
August 2, 2026:
Article 50 transparency obligations apply
What happened. The transparency duties in Article 50. Chatbots, synthetic audio, image and video, and text published to inform the public on matters of public interest.
What changes. Disclosure stops being something to prepare for. Article 50(2) watermarking runs on its own clock: systems on the market before today have until December 2, 2026, anything placed on the market from today marks its output from day one.
Penalties, and exceptions. Article 99(4) sets €15 million or 3% of worldwide annual turnover, whichever is higher. Article 99(6) reverses that for SMEs and start-ups: whichever is lower. If you are small, the second provision is the one that applies to you. The omnibus has extended related simplifications to small mid-cap companies.
Article 50 · Commission guidelines · EU Official Icons · My article
August 2, 2026:
National enforcement powers arrive
What happened. Chapter IX, the market surveillance framework. National authorities can now supervise, including Article 4 AI literacy. The AI Office gains its Article 101 power to fine general-purpose model providers.
What it changes. Article 4 has applied since February 2025 with no supervisory machinery behind it. That machinery now exists.
Note the limit, because it is easy to overstate. Article 4 does not appear in the Article 99(4) list of finable provisions. National authorities can supervise AI literacy from today. There is no harmonised fine attached to it. Supervision and exposure to a penalty are not the same thing.
Except in most of the EU there is no authority to use them yet. As of June 17, 2026, nine of twenty-seven Member States had designated both a market surveillance authority and a notifying authority. Twelve had done part of it. Six were unclear.
See where your country stands:
July 27, 2026:
The Digital Omnibus on AI enters into force
What happened. Regulation (EU) 2026/1744 of July 8, 2026, published in the Official Journal on July 24, took effect. It is the first set of formal amendments to the AI Act since adoption in 2024, and it also amends Regulations (EU) 2018/1139 and (EU) 2023/1230.
What changes:
The high-risk dates. Annex III standalone systems, covering employment, education, credit and access to essential services, move from August 2, 2026 to December 2, 2027. Annex I embedded systems move from August 2, 2027 to August 2, 2028.
Machinery is not deferred, it is removed. Machinery Regulation products were moved out of the high-risk regime, from Annex I Section A to Section B, and handed to delegated acts. The Commission must adopt those by August 2, 2028, adding AI-specific health and safety requirements under the Machinery Regulation. If your AI sits inside machinery you are not waiting for a later deadline, you are waiting for a different instrument, and it has a date.
Article 5 gained two prohibitions. AI systems that generate or manipulate child sexual abuse material, and systems that generate or manipulate non-consensual intimate imagery. Compliance by December 2, 2026. Read it as covering purpose-built tools and you will conclude it is not about you. It also catches systems where such output is a reasonably foreseeable and reproducible outcome and the provider has not implemented reasonable and adequate safety measures. That part reaches general-purpose image, video and audio generators without safeguards, which is why the recitals discuss training-data filtering, refusal training, and input and output classifiers.
Article 4 was softened. The duty moved from ensuring a “sufficient level” of AI literacy to taking measures that support it. An obligation of effort rather than result.
Article 50(2) watermarking. Not a blanket move to December. Systems already on the market before August 2, 2026 get a grace period to December 2, 2026. Anything placed on the market from August 2 onwards marks its output from day one.
July 20, 2026:
Final guidelines on Article 50 transparency
What happened. The Commission adopted the final text, replacing the May draft.
What changed. The editorial-control exemption in Article 50(4) has a defined shape: human review or editorial control, and a person holding editorial responsibility. Both, not either. The artistic and satirical carve-outs are read narrowly, and content that is purely informative or commercial cannot use them.
June 10, 2026:
Code of Practice on Transparency of AI-Generated Content
What happened. The AI Office released the final Code, following a first draft in February 2026. It covers providers and deployers subject to Article 50(2) and Article 50(4), including anyone whose system generates synthetic audio, image, video or text.
What changed. Signing is a route to demonstrating Article 50 compliance without arguing from first principles. Not signing is permitted, but you then show equivalent measures yourself.
It acquired legal weight a month later. On July 8, 2026 the Commission concluded that the Code adequately covers Articles 50(2), (4) and (5); on July 9 the AI Board adopted its own adequacy assessment, both published July 9. The Commission attached a limit worth quoting: adherence “does not constitute conclusive evidence of compliance.” Commission Opinion
The initial signatory list. The deadline to be listed was July 27, 2026, 18:00 CEST. Around 190 organizations had signed by the end of July, roughly half of them small and recent companies. Among the providers: Anthropic, Google, Meta, Microsoft, Mistral, OpenAI, Aleph Alpha, Black Forest Labs, Cohere and Synthesia. Among the deployers: Getty Images, Lenovo, Lufthansa, Bulgari, Fastweb and Iberdrola.
The list is updated on an ongoing basis, so this is a snapshot rather than a closed set.
May 19, 2026:
First draft guidance on high-risk classification
What happened. The Commission published a first draft of its guidance on classifying high-risk AI systems, owed under Article 6(5).
What changed. Draft status, so nothing binding. It is the first official signal on where the Article 6(3) filter conditions apply, which is the provision most companies rely on to argue they are not high-risk. Consultation closed July 23, 2026 and the final version is expected before the end of the year. It was statutorily due on February 2, 2026.
My article on high-risk AI systems · Draft Commission guidelines
October 6, 2025:
The AI Liability Directive is withdrawn
What happened. The withdrawal notice was published in the Official Journal. No replacement announced. The ePrivacy Regulation went the same way.
What changed. The AI Act sets conduct rules. The AI Liability Directive would have set liability rules, shifting the burden of proof and forcing disclosure of documentation so a claimant could build a case. That second layer no longer exists, so liability falls back on national law and the Product Liability Directive.
This matters because bans, safety duties and who-pays are routinely attributed to “the EU AI law” as though it were one instrument.
September 26, 2025:
Draft guidance and template on serious incident reporting
What happened. The Commission published draft guidance and a reporting template under Article 73.
What changed. Providers of high-risk systems have a form and a draft methodology. What they do not have is a final version, and none has been announced. The guidance was originally expected on August 2, 2025.
August 2, 2025:
GPAI obligations apply, and the penalties regime
What happened. Chapter V became applicable for general-purpose AI model providers, alongside the governance framework provisions. Chapter XII on penalties also applied from this date, so Article 5 infringements became finable, subject to each Member State having laid down and notified its penalty rules. Many had not. It was also the deadline for Member States to designate their national competent authorities.
Note the distinction, because it is easy to blur: penalties became available in August 2025, the market surveillance machinery in Chapter IX arrives in August 2026.
What changed. If you fine-tune a model past the threshold and become a model provider, those obligations attached a year ago, not in 2027. Models placed on the market before this date have until August 2, 2027 under Article 111(3).
July 24, 2025:
Template for GPAI training content summaries
What happened. The Commission published the template GPAI providers use to summarize what their model was trained on.
What changed. The Article 53(1)(d) obligation stopped being abstract. If you become a model provider through fine-tuning, this is the form you fill in, and Recital 109 limits it to what you added rather than the whole base model.
July 18, 2025:
Guidelines for providers of general-purpose AI models
What happened. Guidelines published on the scope of Chapter V obligations.
What changed. These contain the compute figure people use to work out when fine-tuning turns you into a model provider. The guidelines present it as an indicative criterion rather than a test: one third of the compute used to train the original model. Where that is unknown, the fallback is one third of 10²³ FLOP for models without systemic risk, and one third of 10²⁵ FLOP for models with it.
The underlying legal question stays the same, and it is not arithmetic: whether your modification significantly changes the model’s generality, capabilities or systemic risk.
That number appears nowhere in the AI Act. Reading the regulation cover to cover will never surface it.
Commission guidelines · My article on wrapping vs. fine-tuning
July 10, 2025:
The General-Purpose AI Code of Practice is published
What happened. The Commission published the voluntary code for providers of general-purpose AI models. On August 1, 2025 the Commission, the AI Board and the Member States confirmed it as an adequate tool, and the list of signatories went public the same day, one day before the GPAI obligations applied.
What changed. Signing became the practical route to demonstrating compliance with Chapter V. It remains voluntary, and a non-signatory has to show equivalent measures by another means. If fine-tuning ever tips you into being a model provider, this is the instrument you are measured against.
February 6, 2025:
Guidelines on the definition of an AI system
What happened. The Commission published guidelines interpreting Article 3(1).
What changed. The threshold question. Whether the thing your team built is an AI system at all decides whether any of the rest applies, and a great deal of ordinary software sits close to the line. An update was expected in May 2026 and has not been published.
My article on what counts as an AI system · Commission guidelines
February 4, 2025:
Guidelines on prohibited practices
What happened. Guidelines published two days after the prohibitions took effect.
What changed. They interpret Article 5 rather than extend it. Useful because the prohibitions are drafted in language that sounds absolute and turns out to carry conditions.
February 2, 2025:
The prohibitions and the AI literacy duty apply
What happened. Article 5 and Article 4 became applicable, the first provisions of the AI Act to apply.
What changed. Both have been live for eighteen months. Article 4 covers every provider and deployer regardless of risk level. No certificate is required, documented measures are.
Superseded in part. The omnibus softened Article 4 in July 2026 and added two prohibitions to Article 5. See the July 27, 2026 entry.
Still in draft
Two documents on this page are not final. Do not build a position on either without saying so.
Serious incident reporting, Article 73. Draft and template published September 26, 2025. No final version, no announced date. Originally expected August 2, 2025.
High-risk classification, Article 6(5). Draft published May 19, 2026, consultation closed July 23, 2026, final expected before the end of the year.
Dates ahead
After August 2, 2026, these are the following obligations that we can expect:
December 2, 2026. New Article 5 prohibitions take effect: AI systems that generate or manipulate child sexual abuse material, and systems that generate or manipulate non-consensual intimate imagery. Added by the omnibus.
December 2, 2026. Article 50(2) watermarking, for systems placed on the market before August 2, 2026. Anything launched from August 2 marks from day one, so this date only helps systems that already existed.
End of 2026. Final guidance on high-risk classification under Article 6(5) expected. It was statutorily due on February 2, 2026.
August 2, 2027. GPAI models placed on the market before August 2, 2025 must comply. Article 111(3).
December 2, 2027. Annex III standalone high-risk obligations apply. Moved from August 2, 2026.
August 2, 2028. Annex I embedded high-risk obligations apply. Moved from August 2, 2027. Machinery Regulation products were excluded from the high-risk regime altogether and handed to delegated acts, so they are not on this clock at all.
August 2, 2030. Legacy high-risk systems operated by public authorities.
For the fuller forward view, including procedural milestones, the Future of Life Institute’s implementation timeline is more detailed than anything worth duplicating here.
Something changed and it is not here? Email me: silvia@ailawdecoded.com


