Prohibited practices and AI literacy
Ensure the organization understands which practices are prohibited and that people operating AI systems have appropriate knowledge and awareness.
AI Act readiness & insights
AI Act readiness is not a single deadline. It is an ongoing program of system classification, security controls, accountability, and evidence that evolves with the systems you deploy.
Timeline last reviewed: August 2026 · verify with counsel before relianceWhat matters now
The following is a practical orientation for leadership teams. Applicability depends on your role, jurisdiction, system type, and use case; obtain legal advice for your specific circumstances.
Ensure the organization understands which practices are prohibited and that people operating AI systems have appropriate knowledge and awareness.
Governance rules and obligations for general-purpose AI models entered into application.
High-risk systems in sensitive areas—such as biometrics, critical infrastructure, education, employment, migration, and border control—have this stated application date in current Commission guidance.
High-risk AI embedded in products such as machinery, lifts, toys, and medical devices follows a later timeline.
This timeline summarizes current European Commission information as of August 2026 and supersedes earlier framing that cited a 2026 high-risk deadline. It is informational, not legal advice, and must be rechecked before publication or reliance. Read the Commission FAQ.
Interactive tool · 2 minutes
Answer a short sequence of questions to get an indicative risk classification and the obligations that typically follow. Indicative only—not legal advice, and no substitute for review by counsel.
Risk tiers at a glance: Unacceptable (prohibited) · High-risk (strict obligations) · Limited/transparency · Minimal. Use the 5-step decision guide below, or request a readiness conversation.
Readiness questions
Include models, agents, vendor tools, internal uses, data sources, owners, decision rights, and where systems are deployed.
Define human owners, risk acceptance, approval gates, escalation paths, and how you challenge or change system behavior.
Policies are not enough. Build usable technical and governance evidence from design through deployment and monitoring.
Practical insight library
Concise, practical briefs designed to help leaders and delivery teams have a better first conversation. They are not substitutes for legal or technical review.
Work through the questions in order. If you answer yes at a step, treat the system as in scope for closer review until counsel confirms otherwise.
Outcome: a defensible first-pass classification per system, ready for legal confirmation. Get help classifying
The control domains a credible AI security assessment should cover—beyond the model itself.
Outcome: a shared baseline for scoping an assessment. Scope an assessment
Start with an inventory and scoped readiness conversation—not a generic compliance checklist.