EU AI Act Document Set: Text, Guidelines, Codes and Templates
The AI Act is not one document. The regulation sets the obligations; the Commission’s guidelines say how it reads them; two codes of practice give providers a presumption-style route to compliance; and a set of templates fixes what your paperwork must look like. Since the Digital Omnibus on AI amended the calendar in July 2026, several of these documents carry dates that differ from the original text. This page lists the official sources in the order a compliance team needs them and records the current application dates. It is the reference layer for our AI Compliance Hub and the AI Act Readiness Checklist.
1. The binding texts
Regulation (EU) 2024/1689 (AI Act)
The consolidated text on EUR-Lex. Read Articles 3 (definitions), 5 (prohibitions), 6 and Annex III (high-risk classification), 50 (transparency), 53–55 (GPAI) and Annex IV (technical documentation) first.
Regulation (EU) 2026/1744 (Digital Omnibus on AI)
The amending regulation published in the Official Journal on 24 July 2026: new high-risk dates, the Article 50(2) grace period, the softened AI-literacy wording, the extra Article 5 prohibition and the AI Office’s enlarged competence.
Commission: AI Act policy page
The Commission’s landing page linking every implementing act, guideline, code and consultation as it is published. Bookmark this rather than secondary summaries.
AI Act Service Desk and Single Information Platform
The Commission’s official article-by-article browser, compliance checker and help desk for SMEs, run with the AI Office.
2. Commission guidelines
Guidelines on the definition of an AI system
February 2025. Which software is an “AI system” under Article 3(1) and which rule-based or statistical tools fall outside. The first question in every classification memo.
Guidelines on prohibited AI practices
February 2025. The Commission’s reading of Article 5: manipulation, exploitation of vulnerabilities, social scoring, emotion recognition at work and in education, biometric categorisation, real-time remote biometric identification.
Guidelines for providers of general-purpose AI models
July 2025. Who counts as a GPAI provider, the training-compute threshold, when a fine-tuner becomes a provider, the open-source exemption and how the AI Office will enforce.
3. Codes of practice and templates
General-Purpose AI Code of Practice
Final version 10 July 2025, three chapters: transparency, copyright, and safety and security for models with systemic risk. Signing is voluntary; it is the recognised way to show compliance with Articles 53 and 55.
Template for the public summary of training content
The mandatory template under Article 53(1)(d) for GPAI providers, with the Commission’s explanatory notice. Fill it, publish it, keep it current.
Code of Practice on transparency of AI-generated content
Final version 10 June 2026. Machine-readable marking and detectability for providers, deepfake and public-interest text disclosure for deployers under Article 50. See our Article 50 runbook.
AI Pact
The Commission’s voluntary pledge framework for early compliance, with shared implementation practices from signatories. Useful evidence of good faith in enterprise procurement.
4. Standards, supervision and adjacent frameworks
CEN-CENELEC JTC 21
The European standardisation committee drafting the harmonised standards that will give high-risk providers a presumption of conformity (Article 40). Track the work programme before the December 2027 date.
European AI Office
The Commission body supervising GPAI models and, after the Omnibus, AI systems built by the same developers and AI in very large online platforms. Publisher of the codes and templates above.
NIST AI Risk Management Framework
The US voluntary framework (AI RMF 1.0 and the Generative AI Profile). Not EU law, but the vocabulary most enterprise AI questionnaires borrow, and a workable skeleton for an Article 9 risk-management system.
KVKK: Recommendations on personal data protection in AI
The Turkish Data Protection Authority’s recommendations for developers, manufacturers and decision-makers. The Turkish overlay for any AI product processing personal data, alongside the draft Turkish AI law we track in the hub.
Most AI Act explainers published before July 2026 still show 2 August 2026 as the high-risk date and 2 August 2026 as the sandbox deadline; both moved with the Omnibus. The documents above are the primary sources; when a vendor questionnaire, a law-firm summary or a compliance tool disagrees with them, the primary source wins. Türkiye is not an EU Member State: Turkish companies are caught as providers or deployers when their systems are placed on the EU market or their outputs are used in the EU (Article 2).
Documents belong to the European Commission, CEN-CENELEC, NIST and the Personal Data Protection Authority of Türkiye and are linked for reference only. Dates are taken from Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744.