Module 1 of the AI Act Compliance certification: who owes what across the roles, what is in force today after the Digital Omnibus, and how to sequence a programme against real dates.
Before any gap analysis, two maps: who owes what, and when. Getting the second wrong is the more expensive error, because it sends a programme at the part of the Regulation that is not yet due while the parts already in force go unaddressed.
The roles, and what each owes
| Role | Definition | Core obligations |
|---|---|---|
| Provider | Art. 3(3) — develops or has developed, and places on the market or puts into service under its own name | Art. 16 and the whole of Chapter III: Art. 9-15, 17, 43, 47-49, 72-73 |
| Deployer | Art. 3(4) — uses under its own authority, other than personal non-professional activity | Art. 26 (twelve paragraphs), Art. 27 FRIA where in scope, Art. 50(3)-(4), Art. 86 |
| Authorised representative | Art. 3(5) | Art. 22 for systems; Art. 54 for GPAI models |
| Importer | Art. 3(6) | Art. 23 |
| Distributor | Art. 3(7) | Art. 24 |
| GPAI model provider | Chapter V | Art. 53; Art. 55 if systemic risk; Art. 54 if third-country |
Two structural facts a compliance officer should internalise.
Almost every organisation is a deployer and nothing else. Almost all published guidance is written for providers. That mismatch is the single largest source of wasted effort in this area.
Roles are per system, not per organisation. The same company can be the provider of one system, the deployer of a second, and the distributor of a third. The register in Module 2 records the role per system for exactly this reason.
The timetable, post-Omnibus
Regulation (EU) 2026/1744 — the Digital Omnibus on AI — was published on 24 July 2026 and entered into force on 27 July 2026. It moved dates and rewrote Art. 4. Anything written before then needs re-checking.
| Date | What applies |
|---|---|
| 2 February 2025 | Art. 5 prohibitions; Art. 4 AI literacy |
| 2 August 2025 | Chapter V — GPAI model obligations |
| 2 August 2026 | Art. 50 transparency duties; Commission enforcement powers over GPAI |
| 2 December 2026 | New Art. 5 prohibition (CSAM / non-consensual intimate imagery); transitional deadline for Art. 50(2) marking of generative systems already on the market before 2 Aug 2026 |
| 2 August 2027 | Regulatory sandboxes (deferred from 2026) |
| 2 December 2027 | Chapter III for standalone Annex III high-risk systems (deferred from 2 Aug 2026) |
| 2 August 2028 | Chapter III for AI embedded in Annex I regulated products (deferred from 2 Aug 2027) |
Read that table as a compliance officer rather than as a lawyer. Everything above 2 December 2027 is already enforceable. Everything at or below it is preparation.
What the deferral did and did not change
It did not remove any obligation. Annex III systems are still high-risk; the requirements are unchanged; only the application date moved.
It did not touch Art. 50, which is why an organisation with no high-risk system at all may still owe something today.
It did rewrite Art. 4 from a duty of result — ensure a sufficient level of AI literacy — to a duty of means: take measures to support the development of AI literacy, with the text stating expressly that it does not require guaranteeing any specific level for any individual. Module 3 works through what that changes about evidence.
It did create breathing room that is shorter than it looks. The artefacts required for a December 2027 deadline — a risk management system running as a process, an Annex IV file with contemporaneous design rationale, a monitoring plan with history — cannot be produced in the last quarter before the date. They accumulate or they do not exist.
Sequencing a programme
In order, and justified by the timetable rather than by tidiness:
- Inventory. Nothing else is possible first. Module 2.
- Art. 5 across the inventory. In force since February 2025, highest fine band under Art. 99(3) at 35 million euro or 7%, and it catches ordinary corporate deployments — emotion inference in the workplace above all.
- Art. 50 across the inventory. In force since August 2026, tier-independent, and two of the four duties sit on deployers.
- Art. 4 literacy programme and register. In force, cheap, and it feeds Art. 26(2) later. Module 3.
- Classification, written down. With the date and the legal baseline.
- Governance gates. Procurement, purpose change, modification. Module 4. This is where future problems stop being created.
- Chapter III artefacts for whatever turned out to be high-risk, against December 2027.
Steps 2 to 4 are the enforceable exposure today. Step 6 is the highest-leverage work. Step 7 is the largest.
Enforcement, and who turns up
AI systems are enforced by the national market surveillance authority designated by each Member State, with the powers of the market surveillance framework behind them.
GPAI models are enforced centrally by the Commission through the AI Office, with fines under Art. 101 at up to 3% of worldwide annual turnover or 15 million euro.
Individuals may lodge a complaint with a market surveillance authority under Art. 85, and Art. 87 brings reporting of AI Act infringements within the Union whistleblower protection framework. Module 6 covers both.
Fines for other operators sit in Art. 99: 35 million euro or 7% for Art. 5 breaches; 15 million or 3% for the operator obligations including Art. 26; 7.5 million or 1% for supplying incorrect, incomplete or misleading information. Art. 4 appears in none of those bands — a fact worth knowing before budgeting a literacy programme on the basis of a fine that does not exist.
Check yourself
- Nothing applies to us until December 2027. — Wrong. Art. 5 and Art. 4 since February 2025, Chapter V since August 2025, Art. 50 since August 2026.
- We are a provider because we bought and configured a system. — Configuring is not developing. You are a deployer unless one of the Art. 25 triggers fires.
- We should appoint an AI officer because the Regulation requires it. — It does not. Naming an owner is how work happens, not a statutory duty.
- Art. 4 carries a large fine, so it is our first priority. — Art. 4 carries no fine band of its own. It is a priority because it is cheap, in force, and feeds Art. 26(2), which does.
Next: Module 2 — Inventory and classification register →
AI Act meets DORA and NIS2
Is your organisation subject to both the AI Act and DORA? The two regulations intersect on the operational resilience of financial AI systems. Our sister site regulation-dora.eu covers DORA in depth — including what the AI Act adds on top of an existing DORA programme.
The AI Act for financial institutions ↗ Explore regulation-dora.eu ↗Frequently Asked Questions
The Art. 5 prohibitions and the Art. 4 AI literacy duty since 2 February 2025. The Chapter V general-purpose AI model obligations since 2 August 2025. The Art. 50 transparency duties and the Commission's enforcement powers over GPAI since 2 August 2026. A further Art. 5 prohibition covering CSAM and non-consensual intimate imagery takes effect on 2 December 2026, as does the transitional deadline for marking synthetic output from generative systems already on the market.
Standalone Annex III systems from 2 December 2027, and AI embedded in Annex I regulated products from 2 August 2028, following the deferrals in Regulation (EU) 2026/1744, the Digital Omnibus on AI. Both dates moved; neither of the in-force obligations above was deferred.
No. There is no equivalent of the GDPR's data protection officer and no appointment obligation. What the Regulation requires is that certain things be done and evidenced. Naming an owner is how organisations make that happen, not something the text demands.
Take compliance further with the AI Act Academy
A free course, a server-graded exam, a verifiable certificate — and the working templates.