The EU AI Act for deployers of operational AI
Read this as a timeline, not a deadline
Regulation (EU) 2024/1689 — the AI Act — was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024. It did not become applicable as a single block. Article 113 sets a phased schedule, and the schedule has already been amended once.
Because the dates move, this piece states each one with its source, and carries a review date at the top. Verify against the European Commission's own timeline before making a decision on it, and take legal advice on your specific position. What follows is an operational reading, not a legal opinion.
1 August 2024 — entry into force. No requirements applied at this point.
2 February 2025 — prohibitions on certain AI practices applied, together with the AI literacy obligations in Article 4. This first tranche was widely overlooked by deployers because it carries no product requirement, only an obligation about people.
2 August 2025 — rules for general-purpose AI models applied, including the regime for GPAI models presenting systemic risk. Member States were required to designate national competent authorities and adopt penalty regimes; EU-level governance structures were to be in place. Providers of GPAI models placed on the market before this date have until 2 August 2027 to comply.
2 August 2026 — the majority of the Act's rules apply and enforcement begins, including Annex III high-risk system requirements and the Article 50 transparency obligations.
Then the amendment. Regulation (EU) 2026/1744 was adopted on 8 July 2026, published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It simplified implementation and postponed several deadlines. An earlier proposal to tie high-risk obligations to the availability of harmonised standards was abandoned in favour of fixed dates: 2 December 2027 for high-risk systems under Article 6(2) and Annex III, and 2 August 2028 for high-risk systems under Article 6(1) and Annex I.
2 December 2026 is the next milestone, and it is narrow: the machine-readable marking requirement in Article 50(2). Article 50 as a whole was not postponed.
Provider or deployer
The Act allocates obligations by role, and the distinction determines nearly everything about your exposure.
A provider develops an AI system or has one developed and places it on the market under its own name. A deployer uses an AI system under its own authority in a professional capacity.
Most enterprises running operational automation are deployers. That matters, because the heavy documentation, conformity assessment and quality management obligations sit primarily with providers.
The caveat is worth knowing: if you substantially modify a high-risk system, or put your own name on it, you can find yourself holding provider obligations you did not budget for. This is a live question for organisations building on top of vendor platforms and rebadging the result internally.
Most operational automation is not high-risk
There is a great deal of alarmed content on this topic, and it does not reflect how the Act is structured.
High-risk classification is not a function of technical sophistication. It follows from the use case. Annex III lists specific domains: biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential services including creditworthiness assessment, law enforcement, migration and border control, and administration of justice. Annex I covers AI as a safety component of products already under EU harmonisation legislation — medical devices, machinery and similar.
Invoice extraction is not on that list. Nor is inventory reconciliation, proof-of-delivery processing, supplier document matching, or the large majority of the back-office automation that produces the best returns in enterprise operations.
Where operational automation does touch the list, it is usually obvious and usually in HR or credit: CV screening, promotion or task allocation decisions, and creditworthiness assessment are the three that catch organisations by surprise.
What deployers actually have to do
For deployers of high-risk systems, the obligations are substantially operational rather than technical: use the system according to the provider's instructions, assign human oversight to people with the competence and authority to exercise it, monitor operation and report serious incidents, retain automatically generated logs, and inform affected workers where a high-risk system is used in an employment context.
Read that list against a well-built deployment. Human oversight with a real review step. Logging sufficient to reconstruct a decision. Named owners with the authority to intervene. Documented instructions for use.
Those are not compliance features. They are what makes an automation supportable, debuggable and defensible in a normal operational review. An organisation that built them because they were good engineering finds the deployer obligations largely already met — and one that skipped them has an operations problem before it has a regulatory one.
The Article 4 AI literacy obligation, applicable since 2 February 2025, is the one most often missed. It is not satisfied by a policy document. It concerns whether the people operating and overseeing AI systems have sufficient understanding to do so competently, which lands on operations and training rather than on legal.
What to do this quarter
- Inventory your AI systems and classify each by role. Provider or deployer, per system. Most organisations have never written this down.
- Check each against Annex III. Be specific about the use case rather than the technology. Pay attention to anything touching HR, worker management or credit.
- Confirm your logging would answer a question six months from now. Input, versions, confidence, reviewer, timestamp, outcome. If a decision cannot be reconstructed, it cannot be defended.
- Check your human oversight is real. A reviewer who approves everything because the interface makes scrutiny impractical is not oversight; they are a rubber stamp with a name attached.
- Address Article 4 literacy for operators, not just for executives.
- Diarise a review, because this timeline has already been amended once and may be again.
For most enterprises running back-office automation, the honest summary is that the AI Act asks for the governance a competent deployment already has. The organisations facing a genuine programme of work are those that shipped automation without a review step, without logs, and without anyone owning it — and they were carrying that risk before the regulation existed.