reportEU AI ActAI Governance
EU AI Act obligations for law firms and legal-AI vendors, by date, article and enforcer, after the Omnibus
Every AI Act duty that reaches a law firm or legal-AI vendor, dated after Regulation 2026/1744: 5 in force, 6 deferred to 2027, 27 national enforcers mapped.
Edited and verified by Cognesio LLP
Researched with AI assistance · sources verified by Cognesio LLP · How this was made ↓
In the European Union, a law firm that uses an AI system in its work is a deployer under Article 3(4) of Regulation (EU) 2024/1689, and a company that sells that system is a provider. This report sets out, for both, which obligations of the AI Act apply on 5 September 2026, which were deferred by the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026), under which article each duty sits, who enforces it and what the fine ceiling is. It does not say how to comply. It says what the rule is, from which date, and who can act on a breach.
The question this report answers is narrower than the one the general trackers answer. Those trackers describe the Act. Practitioners search for the deployer’s version of it: the six-month log rule, whether a research tool is high-risk, whether a chatbot on a firm’s website needs a notice, whether a client memo drafted with AI needs a label, and which authority in which member state would ever ask. As of 5 September 2026, five obligations that reach a firm or vendor are in force, six are deferred to December 2027 or later, and the enforcement layer that will apply them is, in 15 of 27 member states, still being built.
Key findings
- As of 5 September 2026, five AI Act obligations reach a law firm or legal-AI vendor in force: Article 4 (AI literacy, since 2 February 2025, text rewritten 27 July 2026), Article 5 (prohibited practices, since 2 February 2025), Article 50(1) (chatbot disclosure by providers, since 2 August 2026), Article 50(2) (machine-readable marking of synthetic output by providers, since 2 August 2026, with a grace period to 2 December 2026 for systems already on the market) and Article 50(4) (deployer disclosure of deepfakes and of AI-generated public-interest text, since 2 August 2026).
- Six obligations were deferred by Regulation (EU) 2026/1744 from 2 August 2026 to 2 December 2027 for Annex III systems: the Article 26 deployer duties (instructions, human oversight, input data, monitoring, the six-month log retention in Article 26(6), worker information), the Article 27 fundamental-rights impact assessment, the Article 86 right to explanation, the Article 25 rule that turns a modifying deployer into a provider, the Article 49 registration duty and the Chapter III provider requirements. The “log retention 6 months” query has a dated answer: it binds deployers of high-risk systems only, and for a stand-alone Annex III system not before 2 December 2027.
- The only Annex III entry that names legal work is point 8(a), “AI systems intended to be used by a judicial authority or on their behalf to assist a judicial authority in researching and interpreting facts and the law and in applying the law to a concrete set of facts, or to be used in a similar way in alternative dispute resolution”. A firm’s own research or drafting tool is outside that wording; a vendor’s system supplied to a court or an arbitral body is inside it. The route by which the high-risk regime reaches most firms is not legal work but recruitment and HR (Annex III point 4).
- Article 4 carries no fine tier of its own. Article 99(4) lists Articles 16, 22, 23, 24, 26, 31, 33, 34 and 50; Article 4 is not among them, so a literacy breach is punishable only under whatever national rules a member state adopts under Article 99(1). The rewritten Article 4 states that the obligation “does not require providers or deployers to guarantee any specific level of AI literacy of any individual”.
- The fine ceilings that can reach a firm or vendor are three: EUR 35 million or 7% of worldwide annual turnover for a prohibited practice (Article 99(3)); EUR 15 million or 3% for a breach of Article 26 or Article 50 (Article 99(4)); EUR 7.5 million or 1% for incorrect, incomplete or misleading information to an authority (Article 99(5)). For SMEs each ceiling is the lower of the two figures (Article 99(6)); the Omnibus extends the lower-of rule to “small mid-cap enterprises” for the 3% and 1% tiers (new Article 99(6a)).
- Enforcement is split. The Commission’s AI Office enforces the rules for providers of general-purpose AI models, for AI systems built by the same provider or group on those models, and for systems in very large online platforms and search engines; national market surveillance authorities enforce everything else, including every deployer duty. Its powers applied from 2 August 2026. By 5 September 2026 no fine under the Act had been published by the AI Office or by any national authority; the first reported enforcement step is a set of requests for information sent by the AI Office to general-purpose model providers in late August 2026, asking for documentation of internal security practices, cybersecurity testing, safeguards against unsanctioned model actions and incident-response protocols, reported by a law-firm round-up and not, as of 5 September, on a Commission page.
- The national layer is uneven. On the community tracker’s count of 17 June 2026, nine member states had designated both a market surveillance and a notifying authority, twelve had partial designations or pending bills and six had none. Since that count, Poland’s act of 3 July 2026 (Dz.U. 2026 poz. 1003, published 27 July), Germany’s KI-MIG of 22 July 2026 (BGBl. 2026 I Nr. 223, in force 29 July) and Greece’s Law 5321/2026 (20 July) have moved three more states into the designated column, and Ireland, designated since S.I. 366 of 2025, added a national AI Office under its Regulation of Artificial Intelligence Act 2026 (signed 21 July; office announced 30 July). The table below counts 12 designated, 10 with a bill or formal proposal and 5 with none.
- The next dated events are 2 December 2026 (the new Article 5(1)(ba) and (bb) prohibitions on non-consensual intimate imagery and child sexual abuse material apply; Article 50(2) marking becomes mandatory for generative systems already on the market), 2 August 2027 (Commission delegated acts under new Article 2(13) due), 2 September 2027 (post-market monitoring guidance due) and 2 December 2027 (Annex III high-risk obligations apply).
Why the general trackers do not answer the deployer question
The Act is written by operator role and risk tier. A reader who wants to know what a law firm must do has to hold four things at once: which role the firm occupies (deployer for the tools it uses; provider if it builds or substantially modifies one), which tier each tool falls into (prohibited, high-risk, transparency-only, or none), which application date attaches to that tier after the Omnibus, and which authority enforces it. The general trackers are organised by article, not by reader, and most were written before the dates moved.
The search record shows the gap. In the 5 September 2026 Semrush pull for the US database, the query “eu ai act deployer obligations log retention 6 months” carries 720 searches a month at a difficulty score of 25; “eu ai act compliance” 320; “eu ai act summary” 1,000 at a difficulty of 70. The first page for the head terms is held by the community tracker at artificialintelligenceact.eu, the Commission’s own pages, IAPP and law-firm client alerts. None of them answers the log-retention query with a date, because the honest answer is a conditional: six months, for high-risk systems, from 2 December 2027 for Annex III, and only for logs “under their control”.
The milestones page on this site carries the timeline and the September 2026 update the month’s changes; the UK explainer covers the extraterritorial test. This report is the matrix those pages refer to.
Method and data
Primary documents, read on 5 September 2026 from EUR-Lex: Regulation (EU) 2024/1689 (OJ L, 12 July 2024) and Regulation (EU) 2026/1744 (OJ L, 24 July 2026), the latter read article by article for every amendment that touches an obligation on a deployer or provider of an AI system. Every application date in this report is quoted from Article 113 as amended by point (40) of Article 1 of the Omnibus, and every fine from Article 99 as amended by point (38). Commission documents: the Guidelines on the transparency obligations under Article 50 (C(2026) 5054 final, 20 July 2026), the AI literacy Q&A, the draft high-risk classification guidelines (19 May 2026), the enforcement-framework page (last updated 24 August 2026) and the 31 July 2026 enforcement announcement. National instruments: Denmark’s Law 467 of 14 May 2025, Italy’s Law 132/2025, Malta’s S.L. 591.05, Slovenia’s ZIUDHPUI, Greece’s Law 5321/2026, Germany’s KI-MIG (gesetze-im-internet.de), Poland’s act of 3 July 2026 (Dziennik Ustaw PDF), Ireland’s 30 July 2026 announcement.
Datasets: the SafeLegalAI Regulation Tracker, 324 records as of 5 September 2026 (/regulation/documents.json), of which 13 are EU-level records and 43 are member-state records; the country collection, 130 records, with a record for each of the 27 member states (one, Bulgaria, provisional); the tools directory, 129 records (/tools/tools.json), of which 47 are verified independent tools, 8 are headquartered in a member state and 35 list a member state or the EU among their markets. National designation status is taken from the community tracker maintained by the Future of Life Institute (last updated 17 June 2026) and updated from the four national instruments above where a primary document was read after that date.
Classification. An obligation is “in force” if its application date under amended Article 113 has passed; “deferred” if the Omnibus moved it; “not deferred” if the date was 2 August 2026 before and after. “Reaches a firm” means the duty binds a deployer of an AI system used in legal work or in the running of a firm; “reaches a vendor” means it binds a provider of an AI system sold to lawyers or courts. Obligations on providers of general-purpose AI models (Chapter V) are summarised, not tabulated: no legal-AI vendor in the tools directory is recorded as a model provider in that sense, and the Commission’s 18 July 2025 guidelines put the threshold for a downstream fine-tuner becoming a model provider at a training-compute level no legal-tech product in the directory approaches.
Limits. The Act’s high-risk classification is fact-specific and the final classification guidelines are not yet published; the Annex III point 8(a) reading in this report follows the wording and the draft guidelines, not a decided case. National penalty rules under Article 99(1) were read for Germany, Poland, Denmark, Italy, Slovenia, Greece and Malta only. The enforcement register relies on Commission pages for what has been published and on law-firm and trade reports for what has been reported; where no primary page was found that is stated. Nothing in this report is advice on compliance.
The matrix: obligations by date, article and enforcer
The table lists every obligation that reaches a law firm as deployer or a legal-AI vendor as provider, in order of application date. “MSA” is the national market surveillance authority under Article 70; “AI Office” is the Commission’s. The fine column gives the ceiling under Article 99 as amended; where an article is not listed in Article 99(3) to (5), the fine is whatever national law provides under Article 99(1).
| Applies from | Article | Obligation | Who | Enforcer | Fine ceiling | Omnibus change |
|---|---|---|---|---|---|---|
| 2 Feb 2025 | Art. 4 | Take measures to support the development of AI literacy of staff and others operating AI systems on the deployer’s or provider’s behalf | Firms and vendors | MSA | None specific (Art. 99(1) national rules) | Text replaced; “does not require … any specific level” |
| 2 Feb 2025 | Art. 5(1)(a) to (h) | Prohibited practices (manipulation, exploitation of vulnerability, social scoring, untargeted facial scraping, emotion recognition at work, and others) | Firms and vendors | MSA (AI Office for its providers) | EUR 35m or 7% | New points (ba), (bb) added, applying from 2 Dec 2026 |
| 2 Aug 2025 | Arts. 53 to 55 | General-purpose AI model obligations (documentation, copyright policy, training-data summary; systemic-risk duties) | Model providers only | AI Office (powers from 2 Aug 2026) | EUR 15m or 3% (Art. 101) | None |
| 2 Aug 2026 | Art. 50(1) | Design systems that interact with people so that people are told they are dealing with AI, unless obvious | Vendors | MSA | EUR 15m or 3% | None |
| 2 Aug 2026 | Art. 50(2) | Mark synthetic audio, image, video or text output in a machine-readable, detectable way; exception for an “assistive function for standard editing” that does not substantially alter the deployer’s input | Vendors (including general-purpose systems) | MSA (AI Office for its providers) | EUR 15m or 3% | New Art. 111(4): systems on the market before 2 Aug 2026 have until 2 Dec 2026 |
| 2 Aug 2026 | Art. 50(3) | Inform people exposed to an emotion-recognition or biometric-categorisation system | Firms (if deploying such systems) | MSA | EUR 15m or 3% | None |
| 2 Aug 2026 | Art. 50(4), first subpara. | Disclose that image, audio or video content is a deepfake | Firms | MSA | EUR 15m or 3% | None |
| 2 Aug 2026 | Art. 50(4), second subpara. | Disclose that text “published with the purpose of informing the public on matters of public interest” is AI-generated, unless it has undergone human review or editorial control and a person holds editorial responsibility | Firms | MSA | EUR 15m or 3% | None; guidelines of 20 Jul 2026 define the exception |
| 2 Aug 2026 | Art. 50(5) | Provide the Art. 50 information clearly, at the latest at first interaction or exposure | Firms and vendors | MSA | EUR 15m or 3% | None |
| 2 Aug 2026 | Art. 99(5) | Do not supply incorrect, incomplete or misleading information to an authority | Firms and vendors | MSA or AI Office | EUR 7.5m or 1% | SMC lower-of rule added |
| 2 Dec 2026 | Art. 5(1)(ba), (bb) | Prohibition on systems that generate non-consensual intimate imagery of identifiable persons or child sexual abuse material | Firms and vendors | MSA | EUR 35m or 7% | Inserted by Reg. 2026/1744 |
| 2 Dec 2027 | Arts. 8 to 21 | Provider requirements for high-risk systems (risk management, data governance, documentation, record-keeping, transparency to deployers, human oversight design, accuracy, conformity assessment, registration) | Vendors whose system is Annex III | MSA | EUR 15m or 3% (Art. 16) | Deferred from 2 Aug 2026 |
| 2 Dec 2027 | Art. 25 | A deployer that puts its name on, substantially modifies, or changes the intended purpose of a system so that it becomes high-risk is treated as its provider | Firms | MSA | EUR 15m or 3% (new Art. 99(4)(da) for Art. 25(2), (4)) | Deferred |
| 2 Dec 2027 | Art. 26(1) to (7) | Deployer duties: use per instructions; assign competent human oversight; ensure relevant input data where controlled; monitor and report risks and serious incidents; keep automatically generated logs “for a period appropriate to the intended purpose … of at least six months”; inform workers before use at the workplace | Firms whose system is Annex III | MSA | EUR 15m or 3% | Deferred |
| 2 Dec 2027 | Art. 27 | Fundamental-rights impact assessment before deploying an Annex III system | Bodies governed by public law, private entities providing public services, and deployers under Annex III points 5(b) and (c) | MSA | Not listed in Art. 99(4) | Deferred; Art. 27(4) now lets a DPIA be cross-referenced |
| 2 Dec 2027 | Art. 49 | Register the system in the EU database | Vendors; deployers only if public authorities | MSA | Art. 16 tier | Deferred |
| 2 Dec 2027 | Art. 86 | Give an affected person a clear explanation of the system’s role in a decision with legal or similarly significant effect | Firms whose system is Annex III | MSA | Not listed in Art. 99(4) | Deferred |
| 2 Aug 2028 | Chapter III for Annex I | High-risk obligations for AI embedded in regulated products | Not legal-AI vendors, in practice | MSA | Art. 16 tier | Deferred from 2 Aug 2027 |
| 2 Aug 2030 | Art. 111(2) | High-risk systems for public authorities already on the market must comply | Vendors supplying courts and public bodies | MSA | Art. 16 tier | Restated |
Two features of the table are the ones a practitioner most often gets wrong. First, the Article 26 duties, including the six-month log rule, sit entirely in the deferred column, and they attach only to a system that is high-risk. A firm’s contract-review tool, research assistant or drafting model is not high-risk by reason of being used by lawyers; it becomes high-risk only if it falls within an Annex III use case, which for legal work means point 8(a) and for the firm’s own operations means point 4 (employment). Second, the Article 50 duties that did apply on 2 August 2026 are split between provider and deployer: the chatbot notice and output marking are the vendor’s; the deepfake and public-interest-text disclosures are the firm’s.
Which legal-AI uses are high-risk
Annex III point 8(a) is the only entry that names the administration of justice. Its wording is quoted in key finding 3. Three readings follow from the text and the draft guidelines of 19 May 2026.
The system must be “intended to be used by a judicial authority or on their behalf”. A court that licenses a research or drafting system is deploying an Annex III system, and the vendor that supplies it is a provider of one; the judges’ record on this site sets out which courts have done so. A law firm using the same product to prepare a submission is not a judicial authority and is not acting on one’s behalf. The draft guidelines describe point 8(a) as covering AI “intended to assist judicial authorities in researching and interpreting law”; they do not extend it to parties.
The phrase “or to be used in a similar way in alternative dispute resolution” reaches arbitration and mediation. A vendor whose product is intended for use by an arbitral tribunal in applying law to facts is within the entry; a firm’s use of a tool to prepare for an arbitration is not.
Article 6(3) removes a system from Annex III where it “does not pose a significant risk of harm … including by not materially influencing the outcome of decision making”, and lists four conditions, among them a system “intended to perform a narrow procedural task” or “to improve the result of a previously completed human activity”. Case-management routing, anonymisation and summarisation for a court can fall here; a system that profiles natural persons never does (Article 6(3), last subparagraph). A provider that relies on the derogation must document the assessment (Article 6(4)).
The Annex III route that does reach ordinary firms is point 4: systems “intended to be used for the recruitment or selection of natural persons”, for decisions on promotion and termination, task allocation “based on individual behaviour or personal traits” and monitoring of performance. A firm that deploys such a tool for its own staff is a deployer of a high-risk system, and from 2 December 2027 the Article 26 duties, including the six-month log rule and the Article 26(7) duty to inform workers’ representatives, will apply to it in that capacity. None of that depends on what the firm’s lawyers do with AI for clients.
Deployer duties in practice
AI literacy. Article 4 has applied since 2 February 2025 to every deployer of any AI system, high-risk or not. The Omnibus replaced its text on 27 July 2026: deployers “shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf”, and the obligation “does not require providers or deployers to guarantee any specific level of AI literacy of any individual”. The Commission’s Q&A of May 2025 says measures should be proportionate to roles and that “national market surveillance authorities may consider AI literacy when enforcing other obligations”. No fine tier names Article 4. Bar-level instruments have carried the duty into professional rules: the Law Society of Ireland’s guidance requires firms to meet it, the German federal bar’s guidance confirms that law firms are normally deployers, and the Slovak bar’s 2025 rules frame continuing education on AI as literacy; the regulation tracker links each.
Logs. Article 26(6) obliges a deployer of a high-risk system to keep the logs the system generates “to the extent such logs are under their control, for a period appropriate to the intended purpose of the high-risk AI system, of at least six months, unless provided otherwise in applicable Union or national law, in particular in Union law on the protection of personal data”. Article 19 places a matching six-month duty on the provider, and Article 12 requires the system to be capable of logging in the first place. The duty applies from 2 December 2027 for Annex III systems. For a system that is not high-risk, the Act imposes no retention period on the deployer; retention of prompts and outputs is then a matter of data-protection law and professional rules, which is the subject of the note-taker and chat-log report.
Human oversight. Article 26(2) requires deployers of high-risk systems to “assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support”, and Article 26(1) to use the system “in accordance with the instructions for use”. Article 26(5) adds monitoring, a duty to suspend use and inform the provider and the authority where the system presents a risk, and immediate reporting of serious incidents. All are deferred to 2 December 2027 and all attach only to Annex III systems.
Public-interest text. Article 50(4), second subparagraph, has applied since 2 August 2026 to any deployer. It obliges a deployer of a system that “generates or manipulates text which is published with the purpose of informing the public on matters of public interest” to disclose that the text is AI-generated, unless the content “has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication”. The Commission’s guidelines of 20 July 2026, as read for the September 2026 update and quoted in the tracker record, count “the administration of justice and law enforcement” among public-interest matters (paragraph 131), give client advice on regulatory compliance as an example outside scope, and say text is not published where it is “private, interpersonal correspondence (for professional purposes)”. Paragraph 134 defines human review as “the deliberate examination of the substance of the content by one or more natural persons possessing relevant knowledge and professional judgement”, with fact-checking “a minimum requirement”; paragraph 135 rules out “spell-checking or grammatical correction” and “cursory editorial approval”; paragraph 136 says AI edits after sign-off void the exception. The line runs between a client memo, which is not published, and a firm’s website note on a judgment, which is.
Deepfakes and biometrics. Article 50(4), first subparagraph, and Article 50(3) apply to deployers from 2 August 2026. Neither is a typical law-firm activity; both are listed in the matrix because they are deployer duties with a live date and a 3% fine tier.
Prohibited practices. Article 5 has applied since 2 February 2025 to the “use” of a prohibited system as well as to placing it on the market. The Commission’s guidelines of 4 February 2025 interpret each practice. The two prohibitions inserted by the Omnibus, points (ba) and (bb), apply from 2 December 2026 and, under new Article 5(1a), reach the placing on the market of a system only where the generation is its intended purpose or “a reasonably foreseeable and reproducible outcome” absent adequate safeguards.
Providers of legal AI
A legal-AI vendor is a provider of an AI system. Unless it also develops a general-purpose model, Chapter V does not apply to it; the Commission’s 18 July 2025 guidelines set the threshold at which fine-tuning a third-party model makes the modifier a model provider, and the tools directory records no legal-tech product at that scale. What applies now is Article 50.
Article 50(1) requires a system “intended to interact directly with natural persons” to tell them so, “unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect”. A drafting assistant used by a lawyer inside a document editor is a system interacting with a natural person; whether the AI nature is “obvious” is a question the guidelines address by context, and the duty is on the provider’s design, not on the deploying firm.
Article 50(2) requires providers of systems “generating synthetic audio, image, video or text content” to mark output “in a machine-readable format and detectable as artificially generated or manipulated”, with the technical solutions “effective, interoperable, robust and reliable as far as this is technically feasible”. The exception matters for legal drafting: the duty “shall not apply to the extent the AI systems perform an assistive function for standard editing or do not substantially alter the input data provided by the deployer or the semantics thereof”. A tool that rewrites a clause the lawyer supplied is closer to the exception than one that drafts a memo from a prompt. Providers whose systems were on the market before 2 August 2026 have until 2 December 2026 (new Article 111(4)). The Code of Practice on Transparency of AI-generated Content, found adequate by the Commission in its opinion of 8 July 2026 and by the AI Board on 9 July (dates as recorded in the tracker record from the Commission opinion page), commits signatories to interoperable watermark detection by 2 February 2027; about 190 organisations had signed by the end of July, per the Commission’s 31 July news item.
Chapter III arrives for a vendor only if its system is high-risk, and then from 2 December 2027: risk management (Article 9), data governance (Article 10), technical documentation (Article 11), logging capability (Article 12), transparency to deployers (Article 13), human-oversight design (Article 14), accuracy and robustness (Article 15), conformity assessment and registration (Articles 43 and 49). The vendor documentation audit on this site records what 47 vendors publish today on the questions those articles will ask.
Article 25 works in the other direction. A firm that puts its own name on a high-risk system, substantially modifies one, or changes the intended purpose of a system so that it becomes high-risk “shall be considered to be a provider” and takes on Article 16; the Omnibus adds a fine tier for Article 25(2) and (4) (new Article 99(4)(da)). The provision applies from 2 December 2027 with the rest of Chapter III.
Who enforces: the AI Office and 27 national systems
The Commission’s enforcement-framework page, updated 24 August 2026, states the division. The AI Office enforces the rules for providers of general-purpose AI models, for AI systems developed by the same provider or group as the model, and for systems integrated into very large online platforms and search engines under the Digital Services Act; “the national competent authorities enforce the rules for other AI systems”; the European Data Protection Supervisor covers EU institutions. Every deployer duty on a law firm, and every Article 50 duty on a legal-AI vendor that does not itself build a general-purpose model, is therefore a matter for the member state where the firm or vendor is established or where the system’s output is used.
Article 70 requires each member state to designate at least one notifying authority and at least one market surveillance authority, and the deadline for doing so was 2 August 2025. The table gives the position for each of the 27 states: the status on the community tracker’s last update of 17 June 2026, corrected where a primary document read for this report post-dates it. “Designated” means both authorities are named in an adopted instrument.
| Member state | Status, 5 Sep 2026 | Market surveillance authority (lead) and single point of contact | Instrument and date | Source basis |
|---|---|---|---|---|
| Austria | Not designated | AI Service Desk in RTR (support only; no MSA appointed) | KOG § 20c, TKG § 194a (BGBl. I Nr. 6/2024) create the Service Desk | Tracker 17 Jun 2026; country record |
| Belgium | Not designated | BIPT expected per the 2025 to 2029 coalition agreement | None adopted | Tracker 17 Jun 2026 |
| Bulgaria | Not designated | Ministry of Electronic Governance coordinates | None adopted | Tracker 17 Jun 2026 |
| Croatia | Not designated | Central State Office for the Development of Digital Society coordinates | None adopted | Tracker 17 Jun 2026 |
| Cyprus | Designated | Commissioner of Communications (MSA, notifying authority, SPOC) | Designation recorded by the tracker | Tracker 17 Jun 2026 |
| Czechia | Partial (bill) | Czech Telecommunication Office proposed as MSA; standards office as notifying authority | Legislative proposal | Tracker 17 Jun 2026 |
| Denmark | Designated | Agency for Digital Government (MSA, notifying, SPOC); Data Protection Authority and Court Administration also MSAs | Law 467 of 14 May 2025, in force 2 Aug 2025 | Tracker; tracker record |
| Estonia | Not designated | Ministry of Economic Affairs and Communications represents Estonia | None adopted | Tracker 17 Jun 2026 |
| Finland | Designated | Traficom (SPOC) with sectoral MSAs; four notifying authorities | Law 1377/2025, in force 1 Jan 2026 | Tracker 17 Jun 2026 |
| France | Partial (bill) | DGCCRF proposed as coordinating MSA and SPOC; CNIL lead on data-protection aspects | Legislative proposal | Tracker 17 Jun 2026; country record |
| Germany | Designated | Bundesnetzagentur (MSA “soweit in diesem Gesetz nichts anderes bestimmt ist”, § 2(1)); coordination centre and complaints office | KI-MIG of 22 Jul 2026, BGBl. 2026 I Nr. 223, in force 29 Jul 2026 | gesetze-im-internet.de; Bundestag vote 11 Jun 2026 |
| Greece | Designated | Hellenic DPA leads market surveillance; EETT notifying authority; Special Secretariat for AI coordinates (roles as recorded in the tracker from the Special Secretariat’s announcement; the Gazette record sits behind a script-rendered search page and was not re-opened for this report) | Law 5321/2026, FEK A 114, 20 Jul 2026 | tracker record |
| Hungary | Designated | Minister for Enterprise Development (MSA, SPOC); National Accreditation Authority notifying | Government Decree 344/2025 | Tracker 17 Jun 2026 |
| Ireland | Designated | AI Office of Ireland (SPOC, announced 30 Jul 2026, operational by 2 Aug); 15 sectoral MSAs under S.I. 366 of 2025 | Regulation of Artificial Intelligence Act 2026, signed 21 Jul 2026 | enterprise.gov.ie 30 Jul 2026; tracker |
| Italy | Designated | National Cybersecurity Agency (ACN) MSA and SPOC; AgID notifying | Law 132/2025, in force 10 Oct 2025 | Tracker; tracker record |
| Latvia | Partial (report) | Consumer Rights Protection Centre proposed as SPOC among 12 to 14 MSAs | Ministry report, no act | Tracker 17 Jun 2026 |
| Lithuania | Designated | Communications Regulatory Authority (MSA, SPOC); Innovation Agency notifying | Designation recorded by the tracker | Tracker 17 Jun 2026 |
| Luxembourg | Partial (bill) | CNPD proposed as main MSA and SPOC | Draft law of Dec 2024 | Tracker 17 Jun 2026 |
| Malta | Designated | Malta Digital Innovation Authority (lead MSA, SPOC, notifying); IDPC also MSA | Artificial Intelligence Regulations, S.L. 591.05, 10 Oct 2025 | tracker record |
| Netherlands | Partial (bill) | RDI (SPOC) and Autoriteit Persoonsgegevens coordinating among ten sectoral authorities | Draft legislation, Apr 2026 | Tracker 17 Jun 2026 |
| Poland | Designated | Komisja Rozwoju i Bezpieczenstwa Sztucznej Inteligencji (KRiBSI) as supervisory body (Art. 5); minister for informatisation as notifying authority (Art. 86) | Act of 3 Jul 2026, Dz.U. 2026 poz. 1003 (27 Jul 2026), in force 14 days after publication with exceptions (Art. 127) | Dziennik Ustaw PDF |
| Portugal | Partial (announcement) | ANACOM announced as MSA and SPOC, Sep 2025; notifying authority not identified | Announcement | Tracker 17 Jun 2026; country record |
| Romania | Partial (memorandum) | ANCOM proposed as MSA and SPOC; ADR as notifying | Government memorandum, Mar 2026 | Tracker 17 Jun 2026 |
| Slovakia | Partial (bill) | Office for Digital Integrity proposed as MSA and SPOC; Ministry of Justice among sectoral MSAs | Draft legislation | Tracker 17 Jun 2026 |
| Slovenia | Designated | AKOS (SPOC, MSA); Information Commissioner supervises justice-related high-risk systems | ZIUDHPUI, in force 21 Nov 2025 | tracker record |
| Spain | Partial (bill) | AESIA (MSA, SPOC, established 2023); DG for AI proposed as notifying | Draft law | Tracker 17 Jun 2026; country record |
| Sweden | Partial (proposal) | Post and Telecom Authority proposed as coordinating MSA and SPOC | SOU 2025:101 proposal | Tracker 17 Jun 2026; country record |
On this count 12 states are designated, ten have a bill or formal proposal, and five have not designated. Two entries are the ones a law firm should read closely: Slovenia assigns justice-related high-risk systems to its Information Commissioner, and Slovakia’s draft gives the Ministry of Justice a sectoral role, which are the only two instances in the record of a justice body being named as an AI Act enforcer.
Enforcement so far
The register below lists every enforcement event with a date, the authority and the source, from the AI Office’s first powers to 5 September 2026.
| Date | Authority | Event | Source status |
|---|---|---|---|
| 2 Feb 2025 | National MSAs | Prohibited practices and Article 4 apply; no published enforcement action located | Commission timeline |
| 2 Aug 2025 | AI Office | Chapter V obligations apply to model providers; enforcement powers not yet in force | Art. 113(b) |
| 31 Jul 2026 | Commission | Announces that from 2 August the AI Office “together with national authorities” begins enforcing the Act | Commission news page, read 5 Sep 2026 |
| 2 Aug 2026 | Commission | News item “Safer and more transparent AI” puts fines for transparency breaches at “up to €15 million, or 3% of global annual turnover” | Commission news page, as read for the September 2026 update |
| 2 Aug 2026 | AI Office; national MSAs | Enforcement powers apply; Article 50 applies; AI Act Complaint Tool, Whistleblower Tool and downstream-provider complaints channel available | Commission enforcement-framework page, updated 24 Aug 2026 |
| Late Aug 2026 | AI Office | Requests for information reported sent to providers of general-purpose AI models seeking documentation of internal security practices, cybersecurity testing, safeguards against unsanctioned model actions and incident-response protocols; recipients reported to include OpenAI, Anthropic and Google DeepMind | Reported (Fladgate AI round-up, August 2026; Help Net Security, 4 Aug 2026, describes the powers). No Commission page located on 5 Sep 2026 |
| To 5 Sep 2026 | Any authority | Fines or decisions under the Act published | None located |
Two things were checked and not found. First, no market surveillance authority in any of the 12 designated states had published a decision, fine or formal notice under the Act by 5 September 2026; the enforcement powers of national authorities applied from 2 August 2026, and the deployer duties most likely to generate a case are deferred to December 2027. Second, several content sites assert that the AI Office issued fines “totalling EUR 85 million” in March 2026 for recruitment, biometric and credit-scoring systems. No Commission page, press release or Official Journal entry supports that, the AI Office’s sanctioning powers did not apply until 2 August 2026, and the Article 86 right of explanation cited in those pieces does not apply until 2 December 2027. The claim is recorded here only so that a reader who meets it knows it was checked.
Firms outside the EU
Article 2(1)(c) applies the Act to “providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union”. A UK, US or Indian firm whose AI-assisted work product is used in the Union is within scope for the duties that bind deployers; the UK explainer sets out the test. Which authority would act is the one in the member state where the output is used. Article 99(4)(b) fines authorised representatives under Article 22, a role that only high-risk providers outside the Union must appoint, from 2 December 2027.
Timeline
| Date | Event | Source |
|---|---|---|
| 12 Jul 2024 | Regulation (EU) 2024/1689 published, OJ L | EUR-Lex |
| 1 Aug 2024 | Entry into force (Art. 113, first para.) | EUR-Lex |
| 2 Nov 2024 | Deadline for member states to publish fundamental-rights authorities (Art. 77(2)); all 27 have | Community tracker |
| 2 Feb 2025 | Articles 4 and 5 apply | Art. 113(a) |
| 4 Feb 2025 | Commission guidelines on prohibited practices | Commission library |
| 14 May 2025 | Denmark’s Law 467, first national supplement | Tracker record |
| 10 Jul 2025 | General-Purpose AI Code of Practice published | Commission |
| 18 Jul 2025 | Commission guidelines on the scope of GPAI provider obligations | Commission |
| 2 Aug 2025 | Chapter V applies; deadline for national authority designation (Art. 70) | Art. 113(b) |
| 25 Sep 2025 | Italy’s Law 132/2025 published (in force 10 Oct) | Tracker record |
| 10 Oct 2025 | Malta’s Artificial Intelligence Regulations in force | Tracker record |
| 19 Nov 2025 | Commission proposes the Digital Omnibus on AI | Commission |
| 21 Nov 2025 | Slovenia’s ZIUDHPUI in force | Tracker record |
| 1 Jan 2026 | Finland’s Law 1377/2025 in force | Community tracker |
| 19 May 2026 | Draft high-risk classification guidelines | Commission |
| 8 Jul 2026 | Reg. 2026/1744 signed; Commission opinion on the transparency code | EUR-Lex; Commission |
| 3 Jul 2026 | Poland’s act on AI systems dated (published 27 Jul) | Dziennik Ustaw |
| 20 Jul 2026 | Article 50 guidelines C(2026) 5054 final; Greece’s Law 5321/2026 | Commission; FEK |
| 21 Jul 2026 | Ireland’s Regulation of Artificial Intelligence Act 2026 signed | enterprise.gov.ie |
| 22 Jul 2026 | Germany’s KI-MIG dated (in force 29 Jul) | BGBl. 2026 I Nr. 223 |
| 24 Jul 2026 | Reg. 2026/1744 published, OJ L | EUR-Lex |
| 27 Jul 2026 | Reg. 2026/1744 in force; Article 4 text replaced | Art. 4 of Reg. 2026/1744 |
| 2 Aug 2026 | Article 50 applies; AI Office and national enforcement powers apply | Art. 113 |
| Late Aug 2026 | AI Office requests for information to model providers on security practices (reported) | Law-firm round-up |
| 2 Dec 2026 | Art. 5(1)(ba), (bb) apply; Art. 50(2) marking mandatory for existing generative systems | Amended Art. 113(a); Art. 111(4) |
| 2 Feb 2027 | Transparency-code signatories’ watermark-detection commitment | Code of Practice |
| 2 Aug 2027 | Delegated acts under new Art. 2(13) due | Reg. 2026/1744 |
| 2 Sep 2027 | Post-market monitoring guidance and template due (Art. 72(3)) | Reg. 2026/1744 |
| 2 Dec 2027 | Chapter III, Sections 1 to 3 apply to Annex III systems; Arts. 25, 26, 27, 49, 86 | Amended Art. 113(c)(i) |
| 2 Aug 2028 | Chapter III applies to Annex I systems | Amended Art. 113(c)(ii) |
| 2 Aug 2030 | Public-authority high-risk systems already on the market must comply | Amended Art. 111(2) |
What to watch
The Commission’s two September 2026 task forces on the transparency code will produce the first practical detail on how Article 50(2) marking is to be read for text, which is the output legal-AI systems produce. The final high-risk classification guidelines, expected by the end of 2026, will settle how far point 8(a) extends to systems used by parties. No harmonised standard had been cited in the Official Journal by 5 September 2026; the Commission’s standardisation page, updated 3 August 2026, records prEN 18286 in public enquiry since October 2025.
On the national side, the Netherlands, France, Spain, Sweden and the remaining partial states have bills or proposals that would complete the enforcement map before the December 2027 date; Belgium, Austria, Bulgaria, Croatia and Estonia have none on record. The regulation tracker will carry each designation as it is adopted, and the monthly EU AI Act updates the enforcement events.
The open question is which duty produces the first published decision. The deployer duties are deferred, so the candidates are Article 50 and Article 5, and the authorities with a live case would be the AI Office for a model provider and a national authority for a system provider or deployer. Nothing in the record on 5 September 2026 says which it will be.
Three sentences journalists can quote
As of 5 September 2026, five EU AI Act obligations reach a law firm or legal-AI vendor in force and six were deferred to 2 December 2027 by Regulation (EU) 2026/1744, including every deployer duty in Article 26 and the six-month log rule.
Twelve of 27 member states have designated their AI Act enforcement authorities in an adopted instrument, ten have a bill or proposal, and five have none; Germany, Poland and Greece completed theirs in July 2026 and Ireland added a national AI Office.
No fine or decision under the AI Act had been published by the Commission’s AI Office or by any national authority by 5 September 2026; the first reported step is a set of requests for information to general-purpose model providers in late August.
Appendix A: data tables
A1. Article 99 fine ceilings as amended by Regulation (EU) 2026/1744
| Tier | Conduct | Ceiling | SME rule | SMC rule (new) |
|---|---|---|---|---|
| Art. 99(3) | Prohibited practice (Art. 5) | EUR 35m or 7% of worldwide annual turnover, whichever higher | Lower of the two | Not extended |
| Art. 99(4) | Breach of Arts. 16, 22, 23, 24, 25(2) and (4) (new), 26, 31, 33(1), (3), (4), 34, 50 | EUR 15m or 3%, whichever higher | Lower of the two | Lower of the two (Art. 99(6a)) |
| Art. 99(5) | Incorrect, incomplete or misleading information to a notified body or authority | EUR 7.5m or 1%, whichever higher | Lower of the two | Lower of the two (Art. 99(6a)) |
| Art. 101 | GPAI model provider breaches (Commission) | EUR 15m or 3% | n/a | n/a |
A2. Articles reaching a firm or vendor with no dedicated fine tier
| Article | Duty | Consequence of breach |
|---|---|---|
| Art. 4 | AI literacy measures | National penalties under Art. 99(1), if any; may be considered by an MSA when enforcing other duties (Commission Q&A) |
| Art. 27 | Fundamental-rights impact assessment | Not listed in Art. 99(4); national rules |
| Art. 86 | Right to explanation | Not listed in Art. 99(4); national rules and other remedies |
A3. Regulation Tracker records used
| Record | Type | Date of current version |
|---|---|---|
| eu-ai-act | Statute | 27 Jul 2026 (as amended) |
| eu-digital-omnibus-ai-2026-1744 | Statute | 24 Jul 2026 |
| eu-commission-article-50-transparency-guidelines | Guidance | 20 Jul 2026 |
| eu-code-of-practice-ai-generated-content | Guidance | 9 Jul 2026 |
| eu-commission-draft-guidelines-high-risk-classification | Consultation | 19 May 2026 |
| eu-commission-guidelines-prohibited-ai-practices | Guidance | 4 Feb 2025 |
| eu-commission-guidelines-gpai-providers | Guidance | 18 Jul 2025 |
| eu-commission-ai-literacy-qa | Guidance | 1 May 2025 |
| eu-gpai-code-of-practice | Guidance | 10 Jul 2025 |
| dk-lov-467-2025-ai-supplementary-provisions | Statute | 14 May 2025 |
| it-legge-132-2025-intelligenza-artificiale | Statute | 25 Sep 2025 |
| mt-artificial-intelligence-regulations-sl-591-05 | Regulation | 10 Oct 2025 |
| si-ziudhpui-ai-act-implementation | Statute | 21 Nov 2025 |
| gr-law-5321-2026-ai-act-implementation | Statute | 20 Jul 2026 |
Germany’s KI-MIG, Poland’s act of 3 July 2026 and Ireland’s Act 2026 were read from their official sources for this report and are queued for tracker records.
Appendix B: sources
- Regulation (EU) 2024/1689 (AI Act), OJ L, 12 July 2024: EUR-Lex; HTML text read 5 Sep 2026: CELEX 32024R1689
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), OJ L, 24 July 2026: EUR-Lex; HTML text read 5 Sep 2026: CELEX 32026R1744
- European Commission, Guidelines on transparency obligations for providers and deployers of AI systems, C(2026) 5054 final, 20 July 2026: digital-strategy.ec.europa.eu
- European Commission, The enforcement framework of the AI Act (updated 24 August 2026): digital-strategy.ec.europa.eu
- European Commission, Safer and more transparent AI (2 August 2026): commission.europa.eu; Commission opinion on the assessment of the Code of Practice on Transparency of AI-generated Content (8 July 2026): digital-strategy.ec.europa.eu
- European Commission, Commission starts enforcing AI Act rules and new transparency requirements on 2 August (31 July 2026): digital-strategy.ec.europa.eu
- European Commission, Strong backing for the Code of Practice on Transparency of AI-generated Content (31 July 2026): digital-strategy.ec.europa.eu
- European Commission, AI literacy: questions and answers: digital-strategy.ec.europa.eu
- European Commission, Draft guidelines on the classification of high-risk AI systems (19 May 2026): digital-strategy.ec.europa.eu
- European Commission, Guidelines on the scope of obligations for providers of general-purpose AI models (18 July 2025): digital-strategy.ec.europa.eu
- European Commission, Standardisation of the AI Act (updated 3 August 2026): digital-strategy.ec.europa.eu
- Future of Life Institute, Overview of all AI Act National Implementation Plans (last updated 17 June 2026): artificialintelligenceact.eu
- Germany, KI-Marktueberwachungs- und Innovationsfoerderungs-Gesetz vom 22. Juli 2026 (BGBl. 2026 I Nr. 223): gesetze-im-internet.de; Bundestag vote of 11 June 2026: bundestag.de
- Poland, Ustawa z dnia 3 lipca 2026 r. o systemach sztucznej inteligencji, Dz.U. 2026 poz. 1003: eli.gov.pl PDF
- Ireland, AI Office of Ireland established under the AI Regulation Bill 2026 (30 July 2026): enterprise.gov.ie
- Greece, Special Secretariat for AI and Data Governance, national framework for the AI Act: ai.gov.gr
- Fladgate, AI Round-Up, August 2026 (reported AI Office requests for information): fladgate.com; Help Net Security, EU begins enforcing AI Act (4 August 2026): helpnetsecurity.com
- SafeLegalAI datasets: /regulation/documents.json, /regulation/map.json, /tools/tools.json, as of 5 September 2026; Semrush US database pull of 5 September 2026: /data/search-demand-2026-09/
Appendix C: changes to this report
None since first publication.