EU AI Act for professional services: what changed
6 minutes read

The deadline everyone was watching just moved to December 2027. Two others already took effect in August. Here is what an expert service firm actually needs to do.
The EU AI Act has three live dates and one that just moved. If your firm has been waiting for a single "AI Act deadline" to plan around, that framing was already wrong, and the July 2026 Digital Omnibus made it more wrong. Some obligations have applied for over a year. The one most people were bracing for just got pushed back fifteen months. Here is what that split actually means for a consultancy or research firm doing client work with AI.
What took effect on 2 August 2026
Two things happened on that date, and neither was the headline deadline. Article 50 transparency duties became enforceable: providers and deployers have to disclose when content is AI-generated, label synthetic audio and video, and tell people when they are interacting with a chatbot rather than a person. The AI Office also gained its enforcement powers over general-purpose AI model providers, the companies behind the models firms actually use day to day.
What did not happen on that date, despite being the original deadline: high-risk system obligations for standalone AI under Annex III. The Digital Omnibus, which entered into force on 27 July 2026, pushed that deadline to 2 December 2027. If your compliance calendar still says August 2026 for high-risk requirements, that entry is out of date.
The full timeline, in order
| Date | What took effect | Who it applies to |
|---|---|---|
| 2 February 2025 | Prohibited AI practices banned; staff AI literacy duty begins | Every provider and deployer |
| 2 August 2025 | General-purpose AI model obligations: documentation, transparency, systemic-risk mitigation | Providers of general-purpose AI models |
| 2 August 2026 | Transparency duties (AI-generated content disclosure, deepfake labeling, chatbot disclosure); AI Office enforcement over GPAI providers | Providers and deployers whose systems generate content or interact with people |
| 2 December 2027 (moved from August 2026) | High-risk obligations for standalone Annex III systems: hiring, credit scoring, education, critical infrastructure | Providers and deployers of those specific system types |
| 2 August 2028 | High-risk obligations for AI embedded in already-regulated products under Annex I: medical devices, machinery, toys | Manufacturers of those products |
The European Commission's AI Act service desk keeps the authoritative version of this timeline. Obligations that already applied before the omnibus, prohibited practices, AI literacy, GPAI provider duties, and the transparency rules, were untouched by it. Only the Annex III and Annex I high-risk dates moved.
Why the deadline that moved probably was not yours to track
Annex III high-risk status is not a general "AI used on important work" test. It names specific system types: employment and worker management, credit scoring and creditworthiness, education and exam scoring, law enforcement, migration and border control, and a handful of other listed categories, plus AI embedded in products like medical devices or machinery under Annex I.
A research assistant, drafting tool, or client-work platform used to produce analysis, reports, or first drafts does not fall into Annex III on its own. It only becomes relevant if the output feeds directly into one of the listed use cases: a firm that builds a tool making automated hiring decisions, or a credit-scoring model for a client, is in different territory than a firm using AI to research and draft the report a human then reviews and delivers. Most consultancies, agencies, and professional service firms fall into the second category, which means the December 2027 deadline is not the deadline for their day-to-day AI use at all.
The obligations that matter for most firms are the ones already live, not the one still ahead.
What applies to almost every firm right now
Two obligations are worth a real answer, not a policy document that nobody reads.
Staff AI literacy has applied since February 2025, and it is easy to treat as a checkbox instead of a practice. The requirement is that people using AI systems understand their capabilities, limitations, and appropriate use. For a firm producing client work with AI, that means a reviewer knows an AI draft can contain confident, wrong claims, and checks sourcing before the work reaches a client. A policy document that nobody read does not satisfy this.
Transparency duties apply when content is AI-generated or a system interacts like a person, but whether a specific deliverable is covered depends on the deliverable. Raise this with your own counsel rather than self-certifying. What is worth flagging internally now: any client-facing chatbot, or AI-generated content meant to inform the public, carries a disclosure obligation that did not exist before August 2026.
General-purpose AI provider obligations sit with the model vendor, not with a firm using the model. If your firm is a deployer, the documentation and systemic-risk duties belong to whoever built the model. The useful question for your own vendor is whether the models on their platform come from providers meeting those obligations, since that risk sits upstream of any single deployer's use.
Questions to ask an AI vendor before trusting an "EU AI Act compliant" claim
A vendor that says "we're compliant" without specifics is answering a question you did not ask. Ask these instead.
- Which Article 50 transparency obligations does the platform handle by default, and which are the firm's responsibility to configure per use case?
- Is staff AI literacy training something the vendor supports with real material, or left entirely to the firm?
- Does any client-facing output the platform produces need a disclosure the firm has to add manually?
- If a use case later touches an Annex III category, does the vendor have a plan for that, or is it out of scope entirely?
A vendor with clear answers to all four is describing a real compliance posture. "We track the regulation closely" is not one of the four answers.
Where this connects to hosting and access
Regulatory timing is one part of a firm's AI risk picture. The other parts, where data is hosted, who can see it, and whether activity is logged, do not move on the EU AI Act's schedule and matter regardless of which Annex III deadline applies. AI security and trust for client work covers what to hold any AI tool to on hosting, training, and audit logs. AI access control for firms covers the permissions side: whether the AI tool follows the access rules your firm already runs, which is a client-trust question independent of regulatory status.
Hebno's position
Hebno's data can be hosted in the EU or the US, the customer's choice, and customer inputs are not used to train any model. Activity is recorded in audit logs so a firm can answer a client's question about how AI was used on their work. None of that is legal advice on how the EU AI Act applies to your firm's specific deliverables. It is a starting point for that conversation with your own counsel, and with any vendor whose platform touches client work. See the security page for the full detail, or book a demo to walk through your firm's specific setup.
