All articles
SECURITY AND TRUST

EU AI Act for professional services: what changed

6 minutes read

EU AI Act for professional services: what changed
Summary

The deadline everyone was watching just moved to December 2027. Two others already took effect in August. Here is what an expert service firm actually needs to do.

Share this article

The EU AI Act has three live dates and one that just moved. If your firm has been waiting for a single "AI Act deadline" to plan around, that framing was already wrong, and the July 2026 Digital Omnibus made it more wrong. Some obligations have applied for over a year. The one most people were bracing for just got pushed back fifteen months. Here is what that split actually means for a consultancy or research firm doing client work with AI.

What took effect on 2 August 2026

Two things happened on that date, and neither was the headline deadline. Article 50 transparency duties became enforceable: providers and deployers have to disclose when content is AI-generated, label synthetic audio and video, and tell people when they are interacting with a chatbot rather than a person. The AI Office also gained its enforcement powers over general-purpose AI model providers, the companies behind the models firms actually use day to day.

What did not happen on that date, despite being the original deadline: high-risk system obligations for standalone AI under Annex III. The Digital Omnibus, which entered into force on 27 July 2026, pushed that deadline to 2 December 2027. If your compliance calendar still says August 2026 for high-risk requirements, that entry is out of date.

The full timeline, in order

DateWhat took effectWho it applies to
2 February 2025Prohibited AI practices banned; staff AI literacy duty beginsEvery provider and deployer
2 August 2025General-purpose AI model obligations: documentation, transparency, systemic-risk mitigationProviders of general-purpose AI models
2 August 2026Transparency duties (AI-generated content disclosure, deepfake labeling, chatbot disclosure); AI Office enforcement over GPAI providersProviders and deployers whose systems generate content or interact with people
2 December 2027 (moved from August 2026)High-risk obligations for standalone Annex III systems: hiring, credit scoring, education, critical infrastructureProviders and deployers of those specific system types
2 August 2028High-risk obligations for AI embedded in already-regulated products under Annex I: medical devices, machinery, toysManufacturers of those products

The European Commission's AI Act service desk keeps the authoritative version of this timeline. Obligations that already applied before the omnibus, prohibited practices, AI literacy, GPAI provider duties, and the transparency rules, were untouched by it. Only the Annex III and Annex I high-risk dates moved.

Why the deadline that moved probably was not yours to track

Annex III high-risk status is not a general "AI used on important work" test. It names specific system types: employment and worker management, credit scoring and creditworthiness, education and exam scoring, law enforcement, migration and border control, and a handful of other listed categories, plus AI embedded in products like medical devices or machinery under Annex I.

A research assistant, drafting tool, or client-work platform used to produce analysis, reports, or first drafts does not fall into Annex III on its own. It only becomes relevant if the output feeds directly into one of the listed use cases: a firm that builds a tool making automated hiring decisions, or a credit-scoring model for a client, is in different territory than a firm using AI to research and draft the report a human then reviews and delivers. Most consultancies, agencies, and professional service firms fall into the second category, which means the December 2027 deadline is not the deadline for their day-to-day AI use at all.

The obligations that matter for most firms are the ones already live, not the one still ahead.

What applies to almost every firm right now

Two obligations are worth a real answer, not a policy document that nobody reads.

Staff AI literacy has applied since February 2025, and it is easy to treat as a checkbox instead of a practice. The requirement is that people using AI systems understand their capabilities, limitations, and appropriate use. For a firm producing client work with AI, that means a reviewer knows an AI draft can contain confident, wrong claims, and checks sourcing before the work reaches a client. A policy document that nobody read does not satisfy this.

Transparency duties apply when content is AI-generated or a system interacts like a person, but whether a specific deliverable is covered depends on the deliverable. Raise this with your own counsel rather than self-certifying. What is worth flagging internally now: any client-facing chatbot, or AI-generated content meant to inform the public, carries a disclosure obligation that did not exist before August 2026.

General-purpose AI provider obligations sit with the model vendor, not with a firm using the model. If your firm is a deployer, the documentation and systemic-risk duties belong to whoever built the model. The useful question for your own vendor is whether the models on their platform come from providers meeting those obligations, since that risk sits upstream of any single deployer's use.

Questions to ask an AI vendor before trusting an "EU AI Act compliant" claim

A vendor that says "we're compliant" without specifics is answering a question you did not ask. Ask these instead.

  1. Which Article 50 transparency obligations does the platform handle by default, and which are the firm's responsibility to configure per use case?
  2. Is staff AI literacy training something the vendor supports with real material, or left entirely to the firm?
  3. Does any client-facing output the platform produces need a disclosure the firm has to add manually?
  4. If a use case later touches an Annex III category, does the vendor have a plan for that, or is it out of scope entirely?

A vendor with clear answers to all four is describing a real compliance posture. "We track the regulation closely" is not one of the four answers.

Where this connects to hosting and access

Regulatory timing is one part of a firm's AI risk picture. The other parts, where data is hosted, who can see it, and whether activity is logged, do not move on the EU AI Act's schedule and matter regardless of which Annex III deadline applies. AI security and trust for client work covers what to hold any AI tool to on hosting, training, and audit logs. AI access control for firms covers the permissions side: whether the AI tool follows the access rules your firm already runs, which is a client-trust question independent of regulatory status.

Hebno's position

Hebno's data can be hosted in the EU or the US, the customer's choice, and customer inputs are not used to train any model. Activity is recorded in audit logs so a firm can answer a client's question about how AI was used on their work. None of that is legal advice on how the EU AI Act applies to your firm's specific deliverables. It is a starting point for that conversation with your own counsel, and with any vendor whose platform touches client work. See the security page for the full detail, or book a demo to walk through your firm's specific setup.

See how the consultancies pulling ahead are working.

Book 20 minutes and watch a team go from brief to source-backed draft, with every source visible and ready to review.