Skip to content
EU AI Actrouteur.aiReviewed July 2026Informational — not legal advice

The EU AI Act, plainly.

Where the Act actually bites, which obligations routeur.ai helps you meet, and which stay firmly your responsibility.

What we cover — and what stays yours
Most everyday workplace AI use is not "high-risk" under the Act.

For most companies the immediate drivers are GDPR processor obligations, customer due diligence, and the Act's direction of travel — not Annex III. Here's what applies to whom.

01

The timeline, in plain English

August 2024
In force

The AI Act entered into force; obligations phase in over the following years.

February 2025
Prohibitions apply

Bans on unacceptable-risk practices (e.g. social scoring, certain biometric uses) began to apply.

August 2025
GPAI obligations

Transparency and documentation duties for general-purpose AI models began to apply.

From 2 August 2026
Transparency obligations Next

Article 50 duties apply — telling people when they're dealing with an AI system, and labelling AI-generated or manipulated media. Marking of synthetic content in systems already on the market is eased to 2 December 2026.

From 2 December 2027
High-risk obligations

The bulk of high-risk system obligations (Annex III) — record-keeping, logging and human-oversight duties — deferred from 2 August 2026 by the 2026 Digital Omnibus. Systems built into regulated products (Annex I) follow from 2 August 2028.

What changed in 2026: the EU's Digital Omnibus pushed back the big high-risk deadline.

Endorsed by the European Parliament and given final approval by the Council in June 2026, and signed in July, the Digital Omnibus defers the bulk of high-risk (Annex III) obligations from 2 August 2026 to 2 December 2027. The February 2025 prohibitions, the August 2025 general-purpose AI duties and the August 2026 transparency obligations are unchanged, and a new prohibition on AI-generated non-consensual intimate imagery and CSAM applies from 2 December 2026. The deferral takes legal effect once the amendment is published in the EU's Official Journal — expected in July 2026.

02

What maps to what

Obligation What routeur.ai provides What stays your responsibility
Record-keeping & logging Art 12 Per-request traces and a tamper-evident, append-only audit trail — provider, model, tokens, latency, cost, routing decision and policy verdict on every call. Deciding which systems are high-risk, what must be logged for your use case, and how long you retain it.
Transparency Visibility into which model handled each request and which policies fired, surfaced in the dashboard and audit trail. Telling your own users when they're interacting with AI and providing required notices.
Human oversight Policy enforcement, prompt shields, DLP and hard spend caps that can block or flag requests before they reach a provider. Defining oversight processes, escalation paths and who reviews flagged activity.
Deployer duties incl. log retention Art 26 Configurable audit-log retention (7 days Starter, 90 days Pro, extended on Enterprise) and per-request traces you can export to your own SIEM. Classification, a Fundamental Rights Impact Assessment (FRIA) where required, vendor DPAs, and your retention policy.
This page is informational and is not legal advice.

The EU AI Act interacts with GDPR and sector rules in ways that depend on your specific use case. Use it to frame a conversation with your own legal and compliance advisers — not as a substitute for one.

03

Get the readiness checklist

A one-page EU AI Act readiness checklist for AI-using companies: 12 yes/no items across visibility, policy, logging, vendor DPAs, data residency and incident response. Drop your work email and we'll unlock it.

Unlock the one-page checklist

Not sure where your AI exposure is?

Start with a Shadow AI Assessment — we'll help you map where AI is already used across your business, what data flows through it, and which obligations that triggers. The fastest way to turn the Act from an abstract deadline into a concrete plan.

Request a Shadow AI Assessment →