The EU AI Act: what it is, how to prepare and where to learn more 

The EU AI Act's high-risk deadlines just moved. Here's what stayed, what changed and what to do now.

July 29 2026 by

Jesus Vigo

Jamf AI Governance helps organizations get their arms around AI tools in use across their fleet.

Introduction

On June 29, 2026, EU lawmakers finalized a deadline shift that impacts industries based in the EU, but also organizations that do business in the EU or process data from EU citizens. In this blog, we cover what changed, what remains, as well as three time-sensitive actions to take in advance of the EU AI Act going live for many entities globally.

What the EU AI Act is

Regulation (EU) 2024/1689 took effect on August 1, 2024, as the world's first comprehensive AI law. It classifies AI systems into four tiers according to the risk they represent and what the law stipulates the regulation obligations are for each:

  1. Unacceptable risk (banned outright)
  2. High-risk (heavy documentation and oversight duties)
  3. Limited risk (transparency duties)
  4. Minimal risk (no specific obligations)

The law phases in obligations over several years rather than all at once, applicable to entities depending on where they fall into one or more of the following groups:

  • Provider: Companies that develop AI systems.
  • Deployer: Any organization that uses an AI system in a professional setting.
  • Importer: Brings a non-EU provider's AI system into the EU market.
  • Distributor: Makes an AI system available in the EU without being the provider or importer.
  • Authorized representative: An EU-based entity appointed by a non-EU provider to handle compliance on its behalf.
  • Product manufacturer: If a high-risk AI system is integrated into a product under the manufacturer's own name, the manufacturer can inherit provider-level obligations.

A ban on prohibited practices and the AI literacy requirement has been enforceable since February 2, 2025, while obligations for general-purpose AI (GPAI) providers began on August 2, 2025.

The part that recently changed

Following a European Parliament vote on June 16, the Digital Omnibus on AI proposal became a law on June 29, 2026, resetting the clock for compliance under the high-risk systems tier. Under Annex III, stand-alone high-risk systems now have until December 2, 2027, to comply. Industries that are already regulated, like healthcare, where they use high-risk AI embedded in medical products, have until August 2, 2028, to comply.

The part that didn’t change

Chapter IV:  Transparency Obligations for Providers and Deployers of Certain AI Systems, Article 50, which requires disclosing AI interactions and labeling of AI-generated content, maintains its original August 2, 2026, deadline.

How to prepare: three dated actions

Article 50: confirm compliance now

Deadline: August 2, 2026

This one may be challenging for organizations to quantify because it doesn’t delineate as clearly between AI systems classifications, like high or low risk. Specifically, Article 50’s transparency rules apply more broadly to any AI system, which means it may impact more organizations than other provisions:

  • Interacts with people
  • Generates/manipulates content
  • Detects emotional cues
  • Biometrically categorizes users

Common examples of these AI systems in use within organizations:

  • Chatbots
  • Content generators
  • Virtual agents

Watermarking content: it’s a grace period, not a pass

Deadline: December 2, 2026

Applying to Generative AI (GenAI), this provision requires machine-readable watermarks embedded within generated content. For systems in the market by August 2, 2026, a 4-month grace period is allowed. Systems available after August 2, 2026, must comply from launch date.

High-risk roadmap: re-baseline, don't shelf it

Deadline: December 2, 2027, (Annex III stand-alone high-risk obligations) and August 2, 2028, (Annex I product-embedded high-risk obligations)

The technical standards necessary to implement compliance might not be finalized until closer to the new 2027/2028 deadlines. However, organizations affected by these deadlines are urged to use the added runway for assessment prep, technical documentation and the human-oversight aspects of compliance while leveraging the AI Compliance Checker to get ready.

Are you evaluating visibility tools?

Jamf AI Governance provides device-level views of the AI tools in use within your enterprise.

What this signals for schools and enterprises

System providers being the primary focus of the Act may lead some IT and compliance leaders to assume compliance with the law doesn’t apply to their enterprise. This assumption is further muddied when entities qualify for more than one role.

Multiple roles and obligation inheritance

Consider a school staff member that shares student records with an AI system using a school-owned device. Regardless, if the AI tool is sanctioned by the institution, according to EU AI Act obligation definitions, the school’s primary role shifts from “user” to “deployer.” They are now responsible for complying with any additional, applicable obligations.

AI literacy required

A provision that applies to any organization whose employees, contractors or service providers interact with AI systems. AI Literacy, under Article 4, has been enforceable since February 2, 2025. It mandates training users on AI usage, informing them of risks and common issues, like hallucinations, and the importance of verifying information sources.

Like the Article 4 provision, education and vocational training are called out explicitly as high-risk under Annex III. Because of the involvement of underage students and the sensitive information belonging to them, stricter documentation and transparency rules are required.

Shadow AI

Among the more critical exposures for many organizations is the use of AI tools by employees (or students) outside of corporate- and/or school-sanctioned channels. The use of unvetted tools introduces risk for entities; the Act requires them to demonstrate compliance by:

  • Discovering assets and AI tools
  • Assessing and managing risks
  • Enforcing data governance
  • Implementing transparency rules
  • Mandating AI training for stakeholders

The gaps that leave openings for Shadow AI don’t stay invisible forever: auditors, cybersecurity insurance underwriters and procurement teams — regardless of their jurisdiction — are asking deployer-centric questions that entities from all industries should have visibility into to remain compliant.

Where to learn more

  • European Commission AI Act: Start here for a high-level understanding of the Act, why it’s necessary and the various components built into it.
  • European Union Law: Referred to as EUR-Lex, this site contains the full text write up for the EU AI Act, (among other EU laws).
  • Council of the European Union: Official press releases from the EU Council, including topics central to the EU AI Act.

Takeaways: three things this changes for IT and compliance leaders today

  1. Visibility: Blocking alone doesn’t equal compliance. You need insight into your managed fleet to govern AI tool usage.
  2. Literacy, not just policy: AI use policies without documented training does not meet the bar the EU has already set.
  3. Data boundary control: Context is key to mitigating risk — oversight means controlling who can access what, when and where it can be used.

Note: The dates above are a planning baseline — not legal advice. The information presented here does not replace conversations organizations should be having with their respective Legal and Compliance teams before finalizing a compliance roadmap or public-facing claim about the organization's status under the EU AI Act.

Discover how visibility surfaces AI tool usage across your fleet and aids complying with fast-moving regulations.