The AI Act deadlines, and what changes when AI is in the product or in your processes
Updated 26 August 2026·6 min read·Alberto Scarpa
One date does the rounds about the AI Act — 2027 — and with it a false sense of time. Regulation (EU) 2024/1689 has been in force since 1 August 2024, but its application is staggered out to 2030 (Article 113). The catch is that the dates do not arrive in order of severity: some things are already mandatory today, and the obligation that weighs most on a company depends not on when but on where it uses artificial intelligence.
For an industrial manufacturer the fault line is sharp, and it is worth drawing before the calendar. There is AI in your processes — the AI you use in the business: recruitment, worker management, credit scoring. And there is AI in your product — the AI you embed in a machine, in a device, in something you then sell with the CE marking. The two fall into two different regimes and two different dates. Confuse them and you risk staring at 2027 while you are already exposed on a nearer front. If the general picture — what an AI system is, what “high-risk” means — is not yet in focus, the starting point on standards is The AI Act standards; to picture your own exposure there is the AI Act pre-assessment.
Already in force: prohibitions and literacy
Since 2 February 2025 two things have applied that almost nobody files under “deadline”, because they do not look like a product requirement.
The first are the prohibited practices of Article 5: AI systems that manipulate behaviour harmfully, that do social scoring, or that infer emotions in the workplace save for narrow exceptions. This is not a risk to assess, it is a ban: those systems cannot be used, full stop.
The second is the AI literacy duty of Article 4. Anyone who develops or uses AI systems must ensure an adequate level of competence in the people who operate them. It is a general obligation, already live, and it covers AI used in-house — not only the AI that ends up in the product.
Author’s note (my reading, not the text of the law). Article 4 is the easiest deadline to meet and the easiest to ignore, because it produces no document to show. What you must have done: know which AI tools are already running in the business — including the ones that arrived from the bottom up, without anyone deciding on them — and give the people who use them training proportionate to the risk. You do not need a textbook course; you need the competence to be traceable.
2 August 2026, AI in your processes
From this date most of the regulation applies, and with it the obligations for the high-risk systems listed in Annex III (Article 6(2)). These are the high-risk systems “in their own right”, independent of any product: those used to screen candidates, to manage and evaluate workers, to decide access to essential services.
This is where a manufacturing SME finds it is exposed without selling a gram of AI. It is enough to use some in your own processes. A CV-screening tool, a system that assigns shifts or rates productivity: if it falls under Annex III, it carries obligations on risk management, data quality, human oversight and transparency. AI in your processes lands before AI in your product, and it concerns many more companies than think of themselves as “AI companies”.
2 August 2027, AI in your product
This is the date almost everyone knows, and it is the right one for a precise slice of the problem: the obligations of Article 6(1). An AI system is high-risk when it is a safety component of a product — or is itself a product — covered by the Annex I harmonisation legislation (the Machinery Directive and the new Machinery Regulation, RED, medical devices and others), and when that product is subject to third-party conformity assessment.
For anyone who builds machines and devices this is the pivotal date, and the good news is that it hooks onto a track you already know: CE marking. Embedded high-risk AI does not open a separate channel — it enters the conformity assessment of the product you already do. Which means the design decisions you take today on a device meant to still be in production in 2028 are already AI Act decisions, exactly as they are already CRA decisions (the two regulations overlap on the same connected, intelligent product: it is worth reading them together).
The same date carries a second obligation, less visible but relevant to integrators: general-purpose AI (GPAI) models placed on the market before August 2025 must come into compliance by 2 August 2027. If a third-party model runs in your product, that upstream compliance concerns you downstream.
Author’s note (my reading). The borderline case that trips people up most: is an AI component inside a machine always a “safety component”? Not necessarily, and the difference changes the whole regime. What you must have done in time: classified your systems honestly, taking for granted neither that they are all high-risk nor that none is. The Commission’s guidelines on Article 6 (expected) are meant precisely for this; in the meantime the classification has to be argued, not guessed.
Reading the dates together
The trap is to compress everything onto 2027 and defer. In reality the dates work on different planes. The prohibitions and literacy are already today, and they do not ask for a compliant product: they ask you to know what is running in the business. AI in your processes (2026) is a matter of internal governance, and it concerns even those who do not consider themselves AI makers. AI in your product (2027) is a design problem, and it is won only if the right decisions enter the product while you are drawing it, not afterwards.
Keep the three horizons apart and you arrive ready for all of them. Fuse them into a single 2027 deadline and you risk already being in breach of what came into force earlier, believing you still have a year of slack.
References: Regulation (EU) 2024/1689 (AI Act), Articles 4, 5, 6, 70, 111, 113 and Annexes I and III; Italian Law 132/2025 (national authorities AgID and ACN). The notes flagged as operational are my interpretations, not regulatory text. For the up-to-date state of play — standards, guidelines, authorities — there is the AI Act state of play tracker.