Hardly any app ships without an AI feature these days - a chat assistant here, generated text or images there. Which raises the question for every app developer: what does the EU AI Act actually demand of me, and starting when? The short answer: less than the headlines suggest, but from August 2, 2026 it gets concrete. And the timeline shifted considerably in 2026.
The timeline after the Digital Omnibus
The AI Act has been in force since August 2024, but its obligations phase in gradually - and in June 2026, the EU's "Digital Omnibus" postponed the high-risk deadlines by 16 months. The current state:
- Since February 2, 2025: bans on unacceptable practices (e.g. social scoring) and the AI literacy requirement
- Since August 2, 2025: obligations for providers of general-purpose AI models - that's OpenAI, Google, Anthropic and co., not the app developer using their APIs
- August 2, 2026: transparency obligations under Article 50 - this date is unchanged and is the relevant one for most app developers
- December 2, 2026: new bans (AI-generated abuse material, non-consensual deepfakes)
- December 2, 2027: obligations for standalone high-risk systems under Annex III (instead of the original August 2026); AI in regulated products (Annex I) follows in August 2028
Important: only the deadlines moved - the substantive requirements for high-risk systems remained unchanged.
Provider or deployer? The role question
The AI Act distinguishes primarily between providers (who develop an AI system or offer it under their own name) and deployers (who use it professionally). For app developers, the inconvenient truth is: if you integrate an LLM via API into your own app and market the feature under your own name, you are generally the provider of the AI system - even though the model behind it comes from OpenAI or Anthropic. The model-level obligations sit with the model provider; the system-level obligations sit with you.
What actually needs doing by August 2, 2026
For the vast majority of apps - the "minimal risk" category - the obligations boil down to Article 50:
- Chatbots must identify themselves. Users must know they're interacting with an AI - unless it's obvious. A clear notice in the interface suffices
- Label generated content machine-readably. If your app outputs generated text, images, audio or video, the outputs must be marked as AI-generated in a machine-readable format - via metadata or watermarking standards
- Disclose deepfakes. Realistic-looking generated people, places or events need a visible notice
- Emotion recognition and biometric categorization require informing the people affected - irrelevant for most apps, but quickly reached if you build, say, mood analysis from camera images
The fines are meant seriously: up to 35 million euros or 7 percent of global annual turnover, depending on the violation.
When you do end up in high-risk territory
Annex III defines the use cases that trigger the full program from December 2027 - risk management system, technical documentation, human oversight, conformity assessment, EU database registration. Most relevant for app developers: hiring and HR tools (screening, ranking), credit scoring , education (exam assessment, admission) and biometrics. If you build in these fields, don't read the extended deadline as an all-clear but as preparation time - the requirements are extensive and survived the Omnibus unchanged.
The pragmatic to-do list
- Take inventory: which AI features are in the app, and which role (provider/deployer) do you occupy?
- By August 2026: label AI interactions, mark generated content machine-readably - manageable implementation effort, but it needs a slot in a sprint
- Cross-check Annex III: a single feature (e.g. an applicant ranking) can lift the whole app into the high-risk class
- Use the model providers' documentation: GPAI providers have been supplying documentation since August 2025 that downstream providers may rely on
Conclusion
For the typical app developer, the AI Act is no monster: if you offer a chat assistant or generative features, your main duty from August 2026 is honest labeling - an obligation that good UX would suggest anyway. It gets serious in the Annex III fields, and there the postponement to late 2027 is not absolution but a final preparation window. How the regulation fits into the industry's larger upheaval is covered in my post on the AI coding balance sheet after one year.
Sources
- artificialintelligenceact.eu: The EU AI Act's Transparency Rules: A Practical Guide to Article 50 - labeling obligations in detail
- Heuking: AI Omnibus 2026: trilogue agreement amending the AI Act - the May 2026 agreement and its contents
- TÜV Rheinland Consulting: Digital Omnibus on AI: new deadlines for the AI Regulation - postponed deadlines and unchanged requirements
- TÜV Rheinland Consulting: Transparency obligations in the EU AI Act (Art. 50) - obligations and fine framework
- Born City: EU AI Act: new deadlines until December 2027 for high-risk AI - final decisions by Parliament (June 16, 2026) and Council (June 29, 2026)
Top comments (0)