> The AI Act after the Digital Omnibus: GPAI duties, high-risk dates (2 Dec 2027 and 2 Aug 2028), provider vs deployer on OpenAI and Anthropic APIs, AI literacy.
>
> Web page: https://balazscsorba.com/blog/eu-ai-act-gpai-high-risk-2026 · Language: English · Also available in: [Deutsch](https://balazscsorba.com/de/blog/eu-ai-act-gpai-high-risk-2026.md) · [Magyar](https://balazscsorba.com/hu/blog/eu-ai-act-gpai-high-risk-2026.md)
> Author: Balázs Csorba · Published: 2026-10-02 · Keywords: EU AI Act high-risk deadline, AI Act digital omnibus, AI Act GPAI obligations, AI Act provider vs deployer, EU AI Act 2 December 2027, GPAI code of practice, AI literacy Article 4, AI Act compliance checklist, AI Act OpenAI API provider deployer, AI Act mid-size company

[Blog](https://balazscsorba.com/blog)/Security & compliance

# EU AI Act beyond Article 50: GPAI, high-risk dates and what to do now

The AI Act after the Digital Omnibus: GPAI duties, high-risk dates (2 Dec 2027 and 2 Aug 2028), provider vs deployer on OpenAI and Anthropic APIs, AI literacy.

[Balázs Csorba](https://balazscsorba.com/about)·October 2, 2026·12 min read

-   EU AI Act
-   GPAI
-   High-risk AI
-   AI compliance

![Diagram: the AI Act timeline from February 2025 to August 2028, fanning out into GPAI duties, high-risk systems, provider and deployer roles and AI literacy.](https://balazscsorba.com/images/blog/eu-ai-act-gpai-high-risk-2026/cover.webp?v=bf95096d34)

## Key takeaways

-   The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) moved the high-risk dates to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). Most other dates did not move.
-   GPAI model duties have applied since 2 August 2025 and are enforceable by the Commission since 2 August 2026. They sit with OpenAI, Anthropic and other model providers, not with you, unless you substantially retrain a model.
-   If you build a product on an LLM API, you are the provider of an AI system. For most chatbots and RAG assistants that means Article 50 and AI literacy; the full high-risk regime only follows from your use case, not from the model.
-   AI literacy (Article 4) has applied since 2 February 2025. Since the Omnibus it means taking measures to support literacy, with no mandated level and no certificate; supervision and enforcement apply since August 2026.
-   A mid-size company should now build an AI inventory, classify each system, check Annex III use cases, fix supplier contracts under Article 25(4) and document its literacy measures. None of that needs to wait for 2027.

On this page

1.  [The short version](https://balazscsorba.com/#short-version)
2.  [The timeline after the Digital Omnibus](https://balazscsorba.com/#timeline)
3.  [GPAI obligations: what the model providers owe you](https://balazscsorba.com/#gpai)
4.  [Provider or deployer: where API-based companies land](https://balazscsorba.com/#roles)
5.  [High-risk systems: scope, duties and the new grace period](https://balazscsorba.com/#high-risk)
6.  [AI literacy: the duty that already applies](https://balazscsorba.com/#ai-literacy)
7.  [What a mid-size company should do now](https://balazscsorba.com/#what-to-do)
8.  [Sources](https://balazscsorba.com/#sources)

In [my Article 50 checklist](https://balazscsorba.com/blog/eu-ai-act-article-50-developer-checklist) I covered the transparency rules that began to apply on 2 August 2026. That is only one chapter of the AI Act. The questions I now get from engineering leads are broader: what applies to us if we only call the OpenAI or Anthropic API, did the high-risk deadline really move, and what should a company with a few hundred people do this quarter?

This post answers those as of 2 October 2026. I cite the regulation and the Commission pages directly, and where I rely on law-firm commentary I say so. I am an engineer, not a lawyer. Treat this as a map for your own legal review, not as legal advice.

## The short version

**What you need to know in one minute**

**High-risk dates moved.** Annex III systems (employment, credit, education and so on) now apply from **2 December 2027**, products under Annex I from **2 August 2028**. This is Regulation (EU) 2026/1744, in force since 27 July 2026.

**Almost everything else did not move.** Prohibited practices and AI literacy since February 2025, GPAI model duties since August 2025, Article 50 transparency since August 2026.

**API users are providers of AI systems, not of models.** What that costs you depends on your use case, not on which model you picked.

## The timeline after the Digital Omnibus

The Commission proposed the Digital Omnibus on AI on 19 November 2025. Parliament and Council reached political agreement in May 2026, and the final act, Regulation (EU) 2026/1744, entered into force on 27 July 2026. The Commission's own AI Act page confirms the outcome: Annex III use cases (biometrics, critical infrastructure, education, employment, migration and similar areas) apply from 2 December 2027, and AI integrated into products such as lifts or toys from 2 August 2028.

Milestones are evenly spaced, not to scale. Cyan dots mark dates that already apply, gold dots those still ahead. Sources: Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744; European Commission.

The table adds the legal anchor for each date. Two details are easy to miss. First, the Omnibus did not touch Article 50 itself: it only gives generative systems placed on the market before 2 August 2026 until 2 December 2026 to comply with the marking duty in Article 50(2). Second, the two new Article 5 prohibitions (non-consensual intimate imagery and child sexual abuse material) apply from 2 December 2026, which matters if you ship image or video generation.

Date

What applies

Anchor

2 Feb 2025

Prohibited practices and AI literacy

Art. 113, third paragraph, point (a)

2 Aug 2025

Obligations for providers of GPAI models

Arts. 53 to 55; Commission GPAI guidelines

2 Aug 2026

Transparency duties; Commission enforcement powers over GPAI providers; supervision and enforcement of Article 4

Art. 50; Art. 101; Commission AI literacy Q&A

2 Dec 2026

Two new prohibitions; marking duty for generative systems placed on the market before 2 Aug 2026

Art. 113 as amended; Art. 111(4)

2 Aug 2027

GPAI models placed on the market before 2 Aug 2025 must comply

Commission GPAI guidelines page

2 Dec 2027

High-risk obligations for Annex III systems

Art. 113(c)(i)

2 Aug 2028

High-risk obligations for Annex I product systems

Art. 113(c)(ii)

2 Aug 2030

Legacy high-risk systems used by public authorities must comply

Art. 111(2) as amended

## GPAI obligations: what the model providers owe you

The obligations for providers of general-purpose AI models entered into application on 2 August 2025. Under Article 53, a provider must keep technical documentation of the model, make information available to downstream providers who integrate the model, put in place a copyright policy (including respecting rights reservations under the DSM Directive) and publish a sufficiently detailed summary of the training content. Providers of models with systemic risk, presumed above 10^25 FLOP of training compute, carry the additional duties of Article 55: evaluations, risk mitigation, serious incident reporting and cybersecurity.

The Commission's guidelines add an indicative test for what counts as a general-purpose model: training compute above 10^23 FLOP and the ability to generate language, text-to-image or text-to-video, with exceptions in both directions. Placing on the market includes making the model available through an API.

The **GPAI Code of Practice**, published on 10 July 2025, is voluntary. It has three chapters: Transparency, Copyright, and Safety and Security, the last relevant only to providers of systemic-risk models. The Commission and the AI Board confirmed it as an adequate voluntary tool. The signatory list on the Commission page includes Amazon, Anthropic, Google, IBM, Microsoft, Mistral AI and OpenAI. xAI signed only the Safety and Security chapter and must show compliance with transparency and copyright by other means.

For enforcement, the Commission's powers over GPAI providers apply from 2 August 2026, including fines of up to 3 percent of worldwide turnover or EUR 15 million under Article 101. Models placed on the market before 2 August 2025 have until 2 August 2027. The Omnibus also gave the AI Office exclusive competence over AI systems built on a GPAI model when model and system come from the same provider, which is how a product like ChatGPT is supervised. A system you build on someone else's API does not fall under that rule.

What does this mean in practice for a company that calls an API?

-   **You are not the model provider.** Per the Commission, fine-tuning or modifying a model only makes you a provider when it uses more than one-third of the original model's training compute. Prompting, RAG, adapters and typical fine-tuning stay far below that.
-   **You are entitled to information.** Article 53(1)(b) requires the model provider to give downstream providers the documentation they need to understand the model and meet their own obligations. Ask for it in procurement and file it.
-   **The code of practice is a vendor-selection signal, not your checklist.** A signatory has chosen a defined route to show compliance. Record whether your vendor signed.

## Provider or deployer: where API-based companies land

The AI Act regulates operators by role. A provider develops an AI system or model, or has one developed, and places it on the market or puts it into service under its own name. A deployer uses an AI system under its authority in a professional context. One company can hold several roles at once.

Information flows right: Article 53(1)(b) obliges the model provider to supply documentation, and you owe your customers instructions for use.

The consequence is the part many teams get wrong. Building a customer-facing assistant on a hosted model makes you the **provider of an AI system**. That is a light role if the system is not high-risk (mainly Article 50 and Article 4) and a heavy one if it is. The model vendor's compliance does not transfer to you.

Role

Typical example

Core obligations

Applies from

Provider of a GPAI model

OpenAI, Anthropic, Mistral AI

Technical documentation, downstream information, copyright policy, training summary; Art. 55 for systemic risk

2 Aug 2025, enforced from 2 Aug 2026

Provider of an AI system, not high-risk

Support chatbot or RAG assistant on an LLM API

Art. 50 transparency, AI literacy (Art. 4), no prohibited practices

2 Feb 2025 and 2 Aug 2026

Provider of a high-risk AI system

CV-ranking or credit-scoring product built on an LLM

Arts. 8 to 15 requirements, quality management, documentation, logs, conformity assessment, registration (Art. 16)

2 Dec 2027

Deployer of a high-risk AI system

HR team using a vendor screening tool

Use per instructions, human oversight by competent staff, monitoring, keep logs at least six months, inform workers; FRIA in some cases (Arts. 26, 27)

2 Dec 2027

Deployer of any AI system

Staff using ChatGPT or Claude at work

AI literacy (Art. 4); transparency duties where they apply

Now

Article 25 describes how a company moves up the chain. Any distributor, importer, deployer or third party is treated as the provider of a high-risk system if it puts its name or trademark on one, makes a substantial modification that leaves it high-risk, or changes the intended purpose of a non-high-risk system, including a general-purpose one, so that it becomes high-risk. Concretely: if you take a general-purpose assistant and configure it to rank job applicants, you have changed its intended purpose into an Annex III use case, and you are the provider.

The Omnibus sharpened this chain. Under the amended Article 25(4), the provider of a high-risk system and any third party that supplies a model, tool, service or component used in it must specify by written agreement the information, capabilities, technical access and assistance needed to enable full compliance. Open-source tools other than GPAI models are exempt. If you are heading towards a high-risk product, your API contract needs to say this. Standard terms of service rarely do.

**Check the contract, not just the model card**

Article 25(4) makes written supplier agreements part of compliance. For any use case that could become high-risk, ask your model vendor which documentation, testing access and incident information it will provide, and put the answer in the contract. For the data side, see my guide to [GDPR and EU data residency for LLM APIs](https://balazscsorba.com/blog/gdpr-llm-api-eu-data-residency).

## High-risk systems: scope, duties and the new grace period

An AI system is high-risk under Article 6(2) if it falls under an Annex III use case. The Commission lists the areas: biometrics, critical infrastructure, education, employment and worker management, access to essential services (including credit), law enforcement, migration and border control, and the administration of justice and democratic processes. Article 6(3) lets a provider conclude that an Annex III system is not high-risk when it poses no significant risk to health, safety or fundamental rights, but the provider must document that assessment before market placement, and profiling of natural persons stays high-risk.

Providers of high-risk systems must meet the requirements in Articles 8 to 15: a risk management system, data governance, technical documentation, record-keeping, transparency towards deployers, human oversight, and accuracy, robustness and cybersecurity. Article 16 adds a quality management system, documentation, log retention, conformity assessment and the rest. These are engineering deliverables, and they are why [evaluation work like the one in my guide to LLM evals](https://balazscsorba.com/blog/llm-evals-for-product-features) becomes audit evidence rather than a nice-to-have.

Deployers have their own list in Article 26: use the system according to its instructions, assign human oversight to people with the necessary competence, training and authority, monitor operation, keep automatically generated logs for at least six months, and, as an employer, inform workers' representatives and affected workers before deployment. Under Article 27, bodies governed by public law, private entities providing public services, and deployers of certain credit and insurance systems must also perform a fundamental rights impact assessment. The Omnibus lets that assessment cross-reference an existing GDPR data protection impact assessment.

A grace period applies. Under the amended Article 111(2), high-risk systems placed on the market or put into service before the application date are covered only if they are significantly changed in design afterwards. Providers and deployers of high-risk systems intended for public authorities must comply by 2 August 2030 in any case. Do not read this as permission to wait: a major re-architecture of a screening tool in 2028 can pull the system into scope.

On penalties, Article 99 sets up to EUR 15 million or 3 percent of worldwide annual turnover for breaches of provider and deployer obligations, whichever is higher. For SMEs the lower amount applies. The Omnibus extends the lower-of rule to the new category of small mid-caps (fewer than 750 employees and up to EUR 150 million turnover or EUR 129 million balance sheet), but in the text I read, only for the lower penalty tiers in paragraphs 4 and 5, not for the EUR 15 million tier. Mid-size companies should confirm with counsel which cap applies to them.

## AI literacy: the duty that already applies

Article 4 has applied since 2 February 2025, so it is the one obligation in this post that is already live for almost every company. The Omnibus replaced the text: providers and deployers must now take measures to support the AI literacy of their staff and other persons operating or using AI systems on their behalf, considering technical knowledge, experience, education, training and the context of use. The article states that it does not require guaranteeing any specific level of literacy for any individual.

The Commission's Q&A is practical. It confirms that supervision and enforcement apply since August 2026, that national market surveillance authorities can impose penalties under national law, that there is no obligation to measure employees' knowledge, that no certificate is needed, and that an internal record of trainings or guiding initiatives is enough. No AI officer or governance board is mandated.

My reading: the bar is low, but it is not empty. A one-hour slide deck for everybody does not fit a developer who builds agents and a recruiter who uses a screening tool. Tailor to role, record what you did, and cover the failure modes people actually meet, such as [prompt injection](https://balazscsorba.com/blog/prompt-injection-lethal-trifecta-patterns) and confident wrong answers.

## What a mid-size company should do now

Here is the order I would work in, assuming a company of a few hundred people that builds on LLM APIs and buys AI-enabled SaaS.

1.  **Build an AI inventory.** List every AI system you build, buy or let staff use, with owner, vendor, model, data categories and purpose. Include shadow usage.
2.  **Classify each entry by role and risk.** Mark whether you are provider, deployer or both, and check the purpose against Annex III and Article 5. Write down the reasoning, especially for Article 6(3) exclusions.
3.  **Stop anything that could be prohibited.** Article 5 has applied since February 2025, and two new bans follow on 2 December 2026 if you generate images or video.
4.  **Close the Article 50 gaps.** Chatbot disclosure and content marking are already in force. Use [my Article 50 checklist](https://balazscsorba.com/blog/eu-ai-act-article-50-developer-checklist), and note the 2 December 2026 date for older generative systems.
5.  **Document AI literacy.** Role-based training, a short record of who received what, and a refresh rhythm. No certificate is needed.
6.  **Fix supplier contracts.** Collect the model documentation under Article 53(1)(b), note whether the vendor signed the Code of Practice, and add Article 25(4) language for any candidate high-risk use.
7.  **Pre-build for 2027 where an Annex III use case is real.** Logging, human oversight, evaluation sets and a technical file are cheaper to design in than to retrofit. Timing note: standards and guidance were a stated reason for the delay, so expect them to evolve.
8.  **Name an owner and a review cadence.** The rules, the Commission guidance and national enforcement are still moving, and the Omnibus itself showed how quickly dates can change. A quarterly review is proportionate.

Items one to six cost days, not months, and every one of them is useful regardless of what happens to the dates. Items seven and eight are where the 2027 deadline actually bites, and only for companies with an Annex III use case.

## Sources

1.  [Regulation (EU) 2024/1689 (AI Act), EUR-Lex](https://eur-lex.europa.eu/eli/reg/2024/1689/oj)
2.  [Regulation (EU) 2026/1744 (Digital Omnibus on AI), EUR-Lex](https://eur-lex.europa.eu/eli/reg/2026/1744/oj)
3.  [AI Act Explorer: Digital Omnibus on AI, full amending text](https://artificialintelligenceact.eu/ai-act-explorer/digital-omnibus/)
4.  [European Commission: AI Act regulatory framework and timeline](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai)
5.  [European Commission: Guidelines for providers of general-purpose AI models](https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers)
6.  [European Commission: Q&A on the guidelines for GPAI providers](https://digital-strategy.ec.europa.eu/en/faqs/guidelines-obligations-general-purpose-ai-providers)
7.  [European Commission: The General-Purpose AI Code of Practice](https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai)
8.  [European Commission: AI literacy Questions and Answers](https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers)
9.  [AI Act Article 25: Responsibilities along the AI value chain](https://artificialintelligenceact.eu/article/25/)
10.  [AI Act Article 26: Obligations of deployers of high-risk AI systems](https://artificialintelligenceact.eu/article/26/)
11.  [AI Act Article 27: Fundamental rights impact assessment](https://artificialintelligenceact.eu/article/27/)
12.  [AI Act Article 53: Obligations for providers of general-purpose AI models](https://artificialintelligenceact.eu/article/53/)
13.  [AI Act Article 99: Penalties](https://artificialintelligenceact.eu/article/99/)
14.  [AI Act Article 101: Fines for providers of general-purpose AI models](https://artificialintelligenceact.eu/article/101/)
15.  [Gibson Dunn: EU AI Act Omnibus Agreement, postponed high-risk deadlines (27 May 2026)](https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/)
16.  [Orrick: EU AI Act Update, Digital Omnibus finalizes 8 compliance changes (29 July 2026)](https://www.orrick.com/en/Insights/2026/07/EU-AI-Act-Update-Digital-Omnibus-Finalizes-8-Compliance-Changes)
17.  [K&L Gates: EU Digital Omnibus on AI enters into force (31 July 2026)](https://www.klgates.com/EU-Digital-Omnibus-on-AI-Enters-Into-Force-7-31-2026)

## Frequently asked questions

Was the EU AI Act high-risk deadline postponed?

Yes, and the postponement is law. Regulation (EU) 2026/1744 (the Digital Omnibus on AI) entered into force on 27 July 2026. High-risk obligations for Annex III systems now apply from 2 December 2027 instead of 2 August 2026, and for AI embedded in regulated products under Annex I from 2 August 2028 instead of 2 August 2027.

When do the GPAI obligations of the AI Act apply?

The obligations for providers of general-purpose AI models have applied since 2 August 2025. The Commission can enforce them, including with fines, since 2 August 2026. Models placed on the market before 2 August 2025 must comply by 2 August 2027.

Am I a provider or a deployer if I build on the OpenAI or Anthropic API?

If you develop an AI system on top of a model and put it into service under your own name, you are the provider of that AI system, even though OpenAI or Anthropic is the provider of the model. Companies that merely use a finished system in their own business are deployers. A company that builds an internal tool for its own staff is typically both.

Do I need to comply with the GPAI Code of Practice?

No. The code is voluntary and addresses providers of GPAI models. The Commission and the AI Board have confirmed it as an adequate way for providers to demonstrate compliance. If you only call a model through an API, your obligations come from the AI system rules, not from the code.

Does the AI Act require AI literacy training for employees?

Article 4 requires providers and deployers to take measures to support the AI literacy of their staff and of others who operate or use AI systems on their behalf. Since the Omnibus it does not require any specific level of literacy, and according to the Commission there is no need for a certificate. Keeping an internal record of trainings is enough.

What fines apply to companies that use or build high-risk AI?

Breaches of provider and deployer obligations for high-risk systems can be fined up to EUR 15 million or 3 percent of worldwide annual turnover, whichever is higher. For SMEs the lower of the two amounts applies. The Commission can fine GPAI model providers up to 3 percent or EUR 15 million under Article 101.

Written by Balázs Csorba

Senior fullstack & AI engineer in Styria, Austria – 10+ years of Vue, Nuxt, Node.js and PHP, now building tooling for AI agents.

[AI engineering & MCP servers →](https://balazscsorba.com/expertise/ai-engineer)[About me →](https://balazscsorba.com/about)

## More articles

-   [AI agents are identities: least privilege for non-human users](https://balazscsorba.com/blog/ai-agent-identity-least-privilege)
-   [PII redaction in LLM pipelines: where to redact, how, and what GDPR says](https://balazscsorba.com/blog/pii-redaction-llm-pipelines)
-   [Prompt injection defense: the lethal trifecta and six design patterns](https://balazscsorba.com/blog/prompt-injection-lethal-trifecta-patterns)
-   [MCP security checklist: tool poisoning, rug pulls and OAuth](https://balazscsorba.com/blog/mcp-server-security-checklist)

## Sounds like what you need?

Tell me about your project or role – I’d love to hear from you.

[Book a call](mailto:contact@balazscsorba.com) [Connect on LinkedIn](https://www.linkedin.com/in/balazs-csorba)
