The AI Act: an updated timeline for safety and compliance teams

The postponement of some AI Act deadlines does not change the obligations already in force for workplace safety, including the AI literacy requirement updated on 27 July 2026.

The AI Act: an updated timeline for safety and compliance teams

The postponement of certain AI Act deadlines does not change the obligations already in force. It moves some requirements — those covering certain categories of high-risk AI systems — back by one or two years. For anyone working in safety, training and compliance, it is therefore important to distinguish between the provisions that already apply and those that will take effect over the coming years.

Obligations depend on the company’s role

The AI Act assigns different obligations depending on an organisation’s role.

An organisation that develops an AI system and places it on the market is a provider. An organisation that uses an AI system within its own operations is a deployer. Most companies fall into this second category.

Many of the obligations introduced by the regulation apply to providers, but deployers are also required to take specific measures — particularly around transparency and training.

What the postponement changes

Regulation (EU) 2026/1744 affects several areas. On timing, the postponement concerns only some provisions relating to high-risk AI systems.

The following deadlines remain unchanged:

  • the prohibitions already set out in Article 5;
  • the obligations for general-purpose AI models (GPAI);
  • the transparency provisions, which apply from 2 August 2026;
  • the revised wording of the AI literacy obligation, which applies from 27 July 2026.

The regulation also adds new obligations. From 2 December 2026, two prohibitions take effect covering systems designed to generate non-consensual intimate content and child sexual abuse material. The new Article 4a also introduces a legal basis for the exceptional processing of special categories of personal data where this is needed to detect and correct algorithmic bias — and this applies to deployers as well.

AI literacy remains an obligation

Among the changes most relevant to those managing safety is the amendment to the AI literacy obligation.

The obligation has existed since 2 February 2025 and applies to both providers and deployers, who must promote AI literacy within their organisation through measures appropriate to staff members’ roles and level of involvement. From 27 July 2026, the revised wording of Article 4 introduced by Regulation (EU) 2026/1744 applies; it is not among the postponed provisions. The amended text makes clear that not everyone needs to reach the same level of competence: initiatives must be proportionate to the tasks people perform and to the intended use of the AI systems.

The obligation remains something to factor into how AI is managed in the company. Although Article 4 does not carry a specific penalty, the measures an organisation adopts can affect the overall assessment of its compliance with the regulation.

For this reason it is useful to document the training carried out — recording who took part, what was covered, and how it relates to each person’s role.

Transparency rules already apply

Systems designed to interact directly with people, such as chatbots, must make clear from the first exchange that the person is dealing with an AI system.

In some cases, those who use these systems are also subject to specific obligations. This is the case for applications that use biometric data — face, voice or gaze — to classify people or infer their emotional state. Organisations using such systems must inform the people concerned, whether the analysis happens in real time or is carried out on recordings.

For AI-generated content, Article 50 splits the obligations between the two roles, on two different timelines. The system’s provider must apply a machine-readable marking to outputs so the content can be detected as artificial: this is a technical requirement built into the product. For systems already on the market, this obligation has been postponed to 2 December 2026, and the extension covers only the technical signal embedded in outputs.

The obligations that fall on the organisation using the system, by contrast, are enforceable from 2 August 2026 and consist of a disclosure that people can perceive. Anyone publishing a deepfake — audio, video or image content that reproduces real people or events so as to appear authentic — must declare that it was artificially generated or manipulated. The same applies to AI-produced text published to inform the public on matters of public interest, where it has not undergone human review or editorial control. The technical marking applied by the provider is not sufficient to satisfy this obligation.

Emotion recognition at work is already prohibited

Since 2 February 2025, the AI Act has prohibited the use of systems that analyse biometric data — facial expressions, voice or gaze — to infer workers’ emotions. The only exception is where such systems are used for medical or safety reasons.

The prohibition does not cover every analysis of a person’s physical state. The regulation distinguishes emotions from conditions such as pain or fatigue. A system that detects tiredness in a professional driver or a pilot in order to prevent accidents, for example, does not fall within the ban.

The European Commission’s guidelines further clarify that the safety-related exception must be interpreted narrowly and concerns only the protection of people’s life and health.

Enforcement is already taking place at national level. In Italy, the data protection authority (the Garante) invoked this prohibition in a case that turned on the text of workplace chat messages. In measure no. 342 of 14 May 2026, it issued a warning to a start-up that had developed a plug-in for Slack and Teams capable of estimating workers’ stress levels through semantic analysis of their messages. The service was voluntary and activated by the individual worker, and the employer could access neither the content of the communications nor individual results.

The authority’s concern related to the next step: the aggregated reports provided to the company could indirectly put it in a position to learn about employees’ emotional lives. The measure cited data protection law, the Italian Workers’ Statute and the prohibition under Article 5 of the AI Act together. National authorities in other member states can enforce the same prohibition.

Beyond the cases that are expressly prohibited, emotion-recognition systems fall among those classified as high-risk and therefore follow the AI Act’s new timeline.

Key AI Act deadlines

ProvisionDate of application
Prohibitions under Article 5 and AI literacy obligations2 February 2025
Obligations for general-purpose AI models (GPAI)2 August 2025
Article 50 transparency obligations, excluding the technical marking of outputs2 August 2026
National authorities’ supervisory powers and the penalty regime for GPAI models2 August 2026
New prohibitions on non-consensual intimate content and child abuse material2 December 2026
Machine-readable marking of outputs, for systems already on the market2 December 2026
High-risk AI systems (Annex III)2 December 2027
High-risk AI systems embedded in products (Annex I)2 August 2028

A practical view

For organisations that use AI-based tools, the postponement of these deadlines does not change what is already required today. Staff training, the proper handling of transparency obligations and control over access to the data used by AI systems all remain central.

With AI agents integrated with 4HSE, for example, access to information takes place through the authenticated user’s token. The agent can therefore operate only on the data the user is already authorised to access.