Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Start by inventorying your AI systems and identifying your role for each one. The EU AI Act’s 2 December 2027 application date is for high-risk AI systems in Annex III—not a universal deadline for every organization or AI system. Some Act requirements already apply, and high-risk AI embedded in regulated products has a later application date: 2 August 2028.

What the 2027 date means—and what it does not

The EU AI Act entered into force on 1 August 2024 and became generally applicable on 2 August 2026, subject to phased exceptions. The 2027 date concerns requirements for high-risk AI systems covered by Annex III. It does not mean all AI used by an organization becomes regulated as high-risk on that day, nor does it set a worldwide deadline.

The European Commission’s AI Act Service Desk gives the two high-risk dates as 2 December 2027 for Annex III systems and 2 August 2028 for high-risk systems embedded in regulated products. The latter category has a separate, later application date. The dates below reflect the Digital Omnibus amendments that entered into force on 27 July 2026.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Date What applies
1 August 2024 The EU AI Act entered into force.
2 February 2025 Prohibited-practice and AI-literacy provisions began applying, according to the European Commission.
2 August 2025 Governance rules and obligations for general-purpose AI (GPAI) providers began applying, according to the European Commission.
2 August 2026 The Act became generally applicable, subject to phased exceptions.
2 December 2027 Requirements for Annex III high-risk AI systems apply.
2 August 2028 Requirements for high-risk AI systems embedded in regulated products apply.

Annex III covers specified use-case categories, including biometrics, critical infrastructure, education, employment, migration, asylum, and border control. A system does not become high-risk simply because it is used in one of those broad sectors. Its intended purpose and regulatory classification matter; have legal or compliance specialists assess uncertain cases.

First establish which systems and roles are in scope

Readiness is an operational capability: the organization should be able to identify systems, assign responsibility, produce relevant evidence, and respond when risks or incidents emerge. The Act places different duties on different actors, so a vendor’s involvement does not by itself establish that the organization using a system has no obligations.

Question to resolve What to record
Which AI systems are used? Include internally developed systems, purchased tools, AI embedded in other products, and third-party services. Record each system’s intended use rather than relying only on a product name.
What is the organization’s role? Determine whether it acts as a provider, deployer, or another relevant actor for each system and use. Record role-specific responsibilities rather than assigning one blanket label to the organization.
What rules may apply? Document the system’s purpose, affected people, geography, sector, and possible risk category. Check applicable sector and data-protection rules as well as the AI Act.
Who owns the work? Name business and technical owners for classification review, documentation, testing, human oversight, monitoring, incident response, and vendor coordination.

The Commission identifies national competent authorities as the enforcers for most AI-system rules. The AI Office is responsible for GPAI model obligations and specified systems. The Commission’s overview is informational; the Regulation itself governs the applicable duties.

Rank #2
Detailed Driver Vehicle Inspection Report Book – 35 Sets of Forms Per DVIR Inspection Book, 2 Ply Carbonless, 5.5" x 8.5", Pre Trip Inspection Book for Truckers, FMCSA Compliant, Easy Tear-Out
  • Compliant Inspection Records: Meets federal requirements for driver vehicle inspection report books, ensuring your fleet stays audit-ready.
  • Complete Checklist: Covers tractor, trailer, and essential parts for CDL pre trip inspection and daily truck inspection forms.
  • Quick Reference: Includes required inspection steps inside for quick driver reference during pre-trip and post-trip inspections.
  • Durable, Convenient Size: 2-ply carbonless vehicle inspection form (white/yellow copies) resist wear in tough trucking environments. Compact 5.5" x 8.5" size fits easily in cabs and clipboards.
  • Perfect for Commercial Fleets: Whether you manage a single vehicle or a large commercial fleet, our pretrip inspection book is an essential tool for ensuring the safety and compliance of your operations.

How provider and deployer responsibilities differ

A provider’s high-risk obligations include establishing a documented quality-management system and preparing technical documentation and conformity assessment. The quality-management system must cover areas such as regulatory compliance, design and development controls, testing and validation, and technical specifications. Providers must also address corrective action and cooperate with competent authorities.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For deployers, the Commission describes baseline duties to use high-risk systems in accordance with instructions, monitor operation, act on identified risks or serious incidents, and assign human oversight to a person within the organization. The Regulation also addresses worker information where applicable. Exact duties depend on the actor’s role and the system; use the Act and relevant guidance to determine which provisions apply.

These responsibilities need to work in day-to-day operations. A written policy alone will not show whether staff know who monitors a system, how they escalate a problem, or who can pause or correct unsafe use. Connect ownership and procedures to records of testing, changes, monitoring, and decisions.

A practical preparation sequence

  1. Inventory systems and uses. List AI developed internally, bought from vendors, embedded in products, or accessed through third-party services. For each, record the intended purpose and the business process in which it is used. This is a recommended readiness step, not a claim that the Commission provides one universal inventory template.
  2. Scope each use. Record geography, sector, affected people, intended purpose, and the organization’s role. Assess whether the use may fall within a regulated category; escalate legal classification questions instead of assuming every system in a broad sector is high-risk.
  3. Assign named owners. Identify who is accountable for risk review, technical and legal documentation, oversight, monitoring, incident response, change control, and vendor coordination. Make escalation routes clear to the people who operate the system.
  4. Build evidence around obligations. For systems in scope, connect procedures to technical documentation, testing and validation, quality management, change records, logs, and corrective actions. Provider documentation and quality-management duties are explicit for high-risk systems; map the requirements to the organization’s actual role.
  5. Plan ongoing operation. Set out how staff will detect and report problems, when use should be paused or corrected, who decides, and how records are preserved. Coordinate retention and monitoring with applicable data-protection and sector rules.
  6. Use frameworks as support, not a substitute. NIST’s AI Risk Management Framework (AI RMF) and Generative AI Profile can inform risk-management practice, but neither establishes compliance with the EU AI Act or replaces legal obligations.

Records, logs, and accountability evidence

The 2026 consolidated text of Regulation (EU) 2024/1689 requires providers to keep specified high-risk-system documentation at the disposal of authorities for 10 years after placing the system on the market or putting it into service. For automatically generated logs under a provider’s control, the minimum specified retention period is at least six months, subject to applicable law. The Act includes a corresponding provision for deployer-controlled logs, also with a minimum of at least six months subject to applicable law.

Rank #4
200 Pages 3 Hole Caregiver Daily Sheets 8.5 x 11 Inch Caregiver Checklist Notepad Caregiver Daily Log Book for Home Care Nursing Assisted Living and Senior Care (100 sheets)
  • 1 Full Size Daily Care Format:Designed in a standard 8.5 x 11 Inch layout this caregiver daily sheets set includes 100 double sided sheets totaling 200 pages providing ample space for consistent daily care tracking in home care and assisted living settings
  • 2 Structured Caregiver Daily Log Layout:Each caregiver checklist notepad page includes clearly organized sections for date caregiver name time in and out meals and snacks medication and dose physical activity toilet and diaper checks personal care housekeeping behavior notes supplies needed and patient condition tracking
  • 3 Three Hole Punched Binder Ready:Side punched with three 5 mm holes and 4.25 Inch spacing this caregiver daily task sheet fits standard three ring binders making it easy to file organize and review daily records as part of a caregiver daily log book system
  • 4 Durable Double Sided Paper:Printed on 100 gsm offset paper with double sided printing these caregiver daily sheets offer smooth writing performance and durability suitable for frequent handling in home care nursing facilities and long term care environments
  • 5 Versatile Care Documentation Use:Ideal for caregiver daily log book use in home care senior care assisted living rehabilitation centers memory care facilities and family caregiving routines supporting accurate communication and care continuity

These are not blanket retention periods for every record an organization holds. Identify the records covered by the relevant provision, who controls them, and any other applicable legal requirements. Retention should be designed into system operations so evidence is available when needed, without disregarding data-protection obligations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the maximum fines do—and do not—tell you

The European Commission’s enforcement framework, accessed in 2026, describes the following maximums. They are ceilings for specified types of infringement, not estimates of likely penalties or a single cap that applies identically to every organization.

Infringement category Maximum fine stated by the Commission
Infringements involving prohibited AI practices Up to €35 million or 7% of worldwide annual turnover, whichever is higher.
Other breaches, including GPAI obligations Up to €15 million or 3% of worldwide annual turnover, whichever is higher.
Certain failures to comply with an information request, or provision of incorrect, incomplete, or misleading information Up to €7.5 million or 1% of worldwide annual turnover, whichever is higher.

The relevant maximum depends on the violation and regulated role. Do not treat these figures as a forecast of enforcement or as proof that every organization faces the same exposure.

Where NIST fits

NIST’s AI RMF is a voluntary risk-management resource. NIST says AI RMF 1.0 is being revised as part of the White House AI Action Plan. Its Generative AI Profile, NIST AI 600-1, was released on 26 July 2024; the NIST page also records an April 2026 concept note for a critical-infrastructure profile. Organizations using NIST material should consult NIST’s official AI RMF resources for the current revision status and treat the framework as an aid to risk management—not as an EU conformity assessment or legal safe harbor.

A readiness check for leadership

  • Can the organization identify the AI systems in use and explain each system’s intended purpose?
  • Is the role for each system documented, with uncertain classifications escalated for review?
  • Are accountable owners assigned for risk review, technical evidence, human oversight, monitoring, and incident escalation?
  • Can the organization show how testing, changes, operational issues, and corrective actions are recorded?
  • Do staff know how to raise concerns, and is there a defined route to pause or correct unsafe use?
  • Have retention, privacy, sector requirements, and vendor coordination been addressed for the systems in scope?

If these controls are not yet in place, begin with the inventory and scope review. The 2027 date is important for organizations with Annex III high-risk systems, but it is not the first AI Act obligation and does not replace the need to check what already applies.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.