| High-risk AI under Annex III | Obligations from 2 August 2026 | Obligations from 2 December 2027 | Art. 113(3)(c)(i) | Providers, deployers |
|---|
| High-risk AI under Annex I (products) | Obligations from 2 August 2027 | Obligations from 2 August 2028 | Art. 113(3)(c)(ii) | Providers, deployers |
|---|
| AI literacy | Measures to ensure, "to their best extent", a sufficient level of AI literacy | Measures to support the development of AI literacy; Commission and Member States promote it, examples will be published | Art. 4(1)–(3) | All providers and deployers |
|---|
| Prohibited practices | List in Art. 5(1)(a)–(h) | New point (ba) (non-consensual intimate depictions of identifiable persons) and (bb) (child sexual abuse material), from 2 December 2026 | Art. 5(1)(ba), (bb), (1a), (1b); Art. 113(3)(a) | Providers, deployers of generative AI |
|---|
| Marking synthetic content (legacy systems) | From 2 August 2026 for all systems | Systems placed on the market before 2 August 2026: by 2 December 2026 | Art. 111(4) | Providers of generative AI |
|---|
| Sensitive data for bias correction | High-risk providers only, in Art. 10(5) | Own Art. 4a: high-risk providers (para. 1) and, exceptionally, other providers and deployers (para. 2), under strict conditions | Art. 4a; Art. 10(5) deleted | Providers, some deployers |
|---|
| Technical documentation | Simplified form for SMEs including start-ups | Commission’s simplified form also for small mid-caps; notified bodies must accept it | Art. 11(1), 2nd subpara. | Providers (SMEs, small mid-caps) |
|---|
| Quality management system | Proportionate to size; simplified elements for microenterprises only (Art. 63) | Proportionality explicitly for SMEs and small mid-caps; simplified elements for all SMEs without partner or linked enterprises | Art. 17(2); Art. 63(1) | Providers (SMEs, small mid-caps) |
|---|
| Fines for small mid-caps | Lower amount for SMEs only (Art. 99(6)) | Lower amount for small mid-caps too; interests of both groups considered in penalties | Art. 99(1), (6a) | SMEs, small mid-caps |
|---|
| Change of provider | Initial provider cooperates, provides information and technical access (unless clearly excluded) | Specified: technical documents on Art. 16, known limitations and failure modes, targeted access for testing; breaches now subject to fines | Art. 25(2), (4); Art. 99(4)(da) | Providers, suppliers |
|---|
| Fundamental rights impact assessment | FRIA complements an existing DPIA | Deployers may refer to relevant DPIA sections or include parts of it; the AI Office template questionnaire is to allow this | Art. 27(4), (5) | Deployers required to do a FRIA |
|---|
| Registration under the Art. 6(3) exception | Registration in the EU database | Registration remains mandatory; two data items in Annex VIII Section B removed | Art. 49(2); Annex VIII Section B points 7, 9 deleted | Providers |
|---|
| Safety component | General definition | Clarified: pure comfort, efficiency or quality-control functions without a safety role are not a safety component | Art. 3(14); Art. 6(1a)–(1c) | Providers of product AI |
|---|
| Machinery | Machinery Directive in Annex I Section A | Machinery Regulation (EU) 2023/1230 in Annex I Section B (sectoral approach) | Annex I; Art. 2(2) | Machinery manufacturers |
|---|
| Supervision of AI built on own GPAI models | National market surveillance | AI Office exclusively, with its own investigative and fining powers | Art. 75(1); Art. 75a–75d | Providers of GPAI models and systems based on them |
|---|
| National AI regulatory sandboxes | Operational by 2 August 2026 | Operational by 2 August 2027; an EU-level sandbox is also possible | Art. 57(1), (3a) | Member States, innovators |
|---|
| Cybersecurity | Requirements in Art. 15 | Where a system meets the conditions of the Cyber Resilience Act (Reg. 2024/2847, Art. 12(1)), the cybersecurity requirements of Art. 15 are deemed met | Art. 42(3) | Providers |
|---|