REFERENCE

EU AI Act Document Set: Text, Guidelines, Codes and Templates

The AI Act is not one document. The regulation sets the obligations; the Commission’s guidelines say how it reads them; two codes of practice give providers a presumption-style route to compliance; and a set of templates fixes what your paperwork must look like. Since the Digital Omnibus on AI amended the calendar in July 2026, several of these documents carry dates that differ from the original text. This page lists the official sources in the order a compliance team needs them and records the current application dates. It is the reference layer for our AI Compliance Hub and the AI Act Readiness Checklist.

Dates after the Omnibus (Regulation (EU) 2026/1744, in force 27 July 2026). Prohibited practices and the AI-literacy duty: applied since 2 February 2025. General-purpose AI model obligations: since 2 August 2025 for new models; models placed on the market before that date must comply by 2 August 2027. Article 50 transparency duties: since 2 August 2026, with a grace period to 2 December 2026 for machine-readable marking on systems already on the market. New Article 5 prohibition on systems generating non-consensual intimate imagery and child sexual abuse material: 2 December 2026. Member State regulatory sandboxes: 2 August 2027. Annex III stand-alone high-risk systems: 2 December 2027. Annex I high-risk systems embedded in regulated products: 2 August 2028.

1. The binding texts

2. Commission guidelines

3. Codes of practice and templates

4. Standards, supervision and adjacent frameworks

⚠ Check the date on every secondary source

Most AI Act explainers published before July 2026 still show 2 August 2026 as the high-risk date and 2 August 2026 as the sandbox deadline; both moved with the Omnibus. The documents above are the primary sources; when a vendor questionnaire, a law-firm summary or a compliance tool disagrees with them, the primary source wins. Türkiye is not an EU Member State: Turkish companies are caught as providers or deployers when their systems are placed on the EU market or their outputs are used in the EU (Article 2).

Documents belong to the European Commission, CEN-CENELEC, NIST and the Personal Data Protection Authority of Türkiye and are linked for reference only. Dates are taken from Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744.

Considering a similar matter?Talk to counsel that moves at the speed of your round.
Book a call →