← Consultant Academy
QUICK REFERENCE · REVIEWED 15 SEPTEMBER 2026

Current-law desk guide

Use this page to avoid relying on older course dates or simplified memory cues. It is a training reference, not legal advice. For live client work, open the authoritative source and confirm the current wording.

Current implementation timeline
2 February 2025
Prohibited-practice and AI-literacy provisions began applying.
2 August 2025
Governance rules and GPAI-model obligations began applying.
2 August 2026
The Act became generally applicable; Article 50 transparency rules are in application.
2 December 2027
Relevant high-risk rules apply to Annex III use cases such as employment, education and other listed sensitive areas.
2 August 2028
Relevant high-risk rules apply to high-risk AI embedded in Annex I regulated products.

Roles are system-specific

Do not label an entire company simply as a provider or deployer. Map the role for each system and activity. A company can hold several roles across its portfolio.

High-risk is not the same as prohibited

Prohibited practices are a separate Article 5 analysis. High-risk systems can be permitted but face extensive requirements and obligations when the relevant provisions apply.

Intended purpose drives classification

The same technology can produce different regulatory outcomes depending on what it is used to do, who it affects and the decision context.

Article 50 is a separate transparency analysis

A system does not need to be high-risk before a transparency duty can arise. Analyse the specific interaction or content scenario and the relevant provider/deployer duty.

GPAI model and downstream system are different layers

Map model-level GPAI responsibilities separately from the roles and obligations of a downstream AI system that incorporates the model.

10^25 FLOP is not the entire systemic-risk test

The training-compute threshold creates an important quantitative presumption, while the Commission can also designate a GPAI model based on broader capability and impact criteria.

Not every high-risk system needs a Notified Body

Conformity-assessment routes depend on the system category and applicable product framework. Do not tell a client that all high-risk AI requires third-party approval.

ISO/IEC 42001 supports governance; it does not replace law

An AIMS can provide repeatable governance, evidence and continual improvement. Certification does not by itself prove compliance with every EU AI Act obligation.

Source discipline

Source hierarchy for client work

  1. 1. Current legislation: use the consolidated EUR-Lex text for the rule itself.
  2. 2. Current Commission guidance: use it to support application, examples and implementation.
  3. 3. Standards: use the licensed ISO/IEC 42001 standard and approved organisational material for formal implementation work.
  4. 4. Academy lesson pack: use it for learning and memory support, but re-check live conclusions where the material may pre-date amendments or guidance.
Authoritative starting points

The uploaded EU AI Specialist lesson notes remain a core learning source in the Academy. Where an older lesson statement conflicts with current legislation or current official guidance, the current authoritative source should be used for client work.