DEV Community

Cover image for EU AI Act in 2026: Five Checks for Product Teams
Andrew Cluev
Andrew Cluev

Posted on

EU AI Act in 2026: Five Checks for Product Teams

Since 2 August 2026, the EU AI Act has often been described as fully applicable. That description is too broad. Some important rules now apply, but the main requirements for high-risk systems will take effect later.

For most product teams, five checks are useful now.

1. What is the company’s role?

A company may be a provider, deployer, importer, distributor or provider of a general-purpose AI model. Its role can also differ from one product to another.

Using an external model through an API does not answer this question. The company offering the final AI product may still have its own obligations.

Record who provides the system, who operates it and whose name appears on the product.

2. Does the system interact with people or generate content?

Article 50 has applied since 2 August 2026.

People must generally be informed when they are interacting directly with an AI system, unless this is already obvious. Generative AI systems may also need to add machine-readable marks to synthetic content.

The limited grace period until 2 December 2026 applies only to certain marking obligations for systems placed on the market before 2 August. It does not postpone Article 50 as a whole.

The European Commission explains these rules in its Article 50 FAQ.

3. Is there an AI system inventory?

A basic inventory should identify:

  • the system and its intended purpose;
  • the responsible person;
  • the countries and users concerned;
  • the models and external services used;
  • the preliminary risk category;
  • important changes to the system.

This does not need to be a complex compliance platform. A maintained spreadsheet is better than an undocumented process.

4. Can the company show that staff understand the system?

AI literacy obligations have applied since February 2025.

Training should match the person’s role. A developer, customer support employee and compliance officer need different information. Keep a record of the instructions or training provided and the date.

5. Could the system become high-risk?

The main rules for systems listed in Annex III will apply from 2 December 2027. Rules for high-risk systems embedded in regulated products will apply from 2 August 2028.

Teams working with employment, education, essential services, biometrics or public decision-making should not leave preparation until the final months. Logging, documentation, risk controls and human oversight may require changes to the product itself.

The current dates are listed in the Commission’s AI Act enforcement timeline.

A useful starting point is simple: identify the system, determine the company’s role and keep evidence of the decisions already made.

This article is a general overview and does not constitute legal advice.

Top comments (0)