For data protection and client confidentiality reasons, these scenarios are illustrative rather than accounts of individual client engagements. No organisation is named, and no figures, timelines, or outcomes are claimed. They are drawn from enquiries, scoping calls, and experience of working inside regulated organisations, and gathered here to show how we would support an organisation like yours.
Most organisations arrive at the EU AI Act with the same question: does any of this apply to us, and if so, where. The four scenarios below are the patterns that come up most often. Each sets out who is caught, what applies, the sequence of work that follows, and the one thing worth remembering.
The four risk tiers
Prohibited
Banned outright. Article 5.
High-risk
Full conformity regime. Annex I and III.
Limited risk
Transparency duties. Article 50.
Minimal risk
No mandatory obligations.
When obligations bite
Feb 2025
Article 5 prohibitions and Article 4 AI literacy. Enforceable now.
Aug 2026
Article 50 transparency. Live, not deferred.
Dec 2026
Marking of legacy generative systems. Two new prohibitions apply.
Dec 2027
Annex III standalone high-risk. Deferred.
Aug 2028
Annex I embedded high-risk. Deferred.
Deferrals introduced by Regulation (EU) 2026/1744, the Digital Omnibus, in force 27 July 2026. The deadline for national AI regulatory sandboxes moved separately to 2 August 2027.
The date most summaries miss
2 December 2026 does two things. It is the end of the transitional period for the machine-readable marking and detection obligation in Article 50(2), which applies to generative AI systems that were already placed on the market before 2 August 2026. Anything placed on the market on or after that date had no transition at all and had to comply from day one. Content generated before 2 August 2026 does not need to be labelled retroactively. Separately, 2 December 2026 is the date from which the two new Article 5 prohibitions introduced by the Digital Omnibus apply, covering AI systems used to generate child sexual abuse material or non-consensual intimate imagery.
There is also a transitional rule worth knowing if you already have systems in the field. Article 111 limits how far the high-risk obligations reach back to systems placed on the market before the relevant date, and a significant change to a system's design brings it fully into scope. Whether a particular deployment benefits from that treatment is a question to check against your own facts rather than to assume.
Scenario one
Credit scoring in financial services
Annex III, point 5(b)
Who is caught
Lenders, credit bureaux, scoring model vendors
Role
Often provider and deployer at once
Deadline
2 December 2027
The regulatory position
AI used to evaluate the creditworthiness of natural persons or establish a credit score is high-risk under Annex III. Regulation (EU) 2026/1744 deferred standalone Annex III obligations to 2 December 2027, but the preparation window is shorter than the date suggests. Data governance, bias testing, technical documentation and human oversight all have to be built and evidenced before that date, not on it. DORA and GDPR obligations run alongside and are already live.
How we would approach it
Classify the system and confirm whether the firm is provider, deployer, or both. Assess the training and validation data against the Article 10 governance requirements. Design the risk management system under Article 9 and the human oversight arrangements under Article 14. Build the Annex IV technical documentation and the record-keeping required by Article 12. Then move to continuous monitoring so the position stays defensible as models are retrained.
The takeaway
The deferral moved the deadline, not the workload. Firms that treat December 2027 as a start date rather than an end date will be assembling evidence they should have been generating all along.
Scenario two
Employment screening in HR technology
Annex III, point 4(a)
Who is caught
Screening software vendors and the employers using them
Role
Vendor is provider, employer is deployer, unless Article 25 shifts it
Deadline
2 December 2027
The regulatory position
AI used to place targeted job advertisements, filter applications or evaluate candidates is high-risk under Annex III. Vendors selling screening software to employers are usually providers, and their customers are deployers, so obligations fall on both. Article 25 matters here: a customer who puts its own name on the system, or modifies its intended purpose, can become the provider itself. GDPR applies in parallel to candidate data, and the Article 22 automated decision-making rules are frequently in play.
How we would approach it
Map the provider and deployer relationships across the customer base before anything else, because that determines who owes what. Establish a fairness testing methodology and the documentation that evidences it. Align the GDPR lawful basis and the automated decision-making safeguards with the AI Act oversight requirements rather than running them as separate workstreams. Set up the post-market monitoring plan required of providers.
The takeaway
Who counts as the provider is a contractual question as much as a technical one. Vendors who have never read Article 25 against their reseller agreements are usually carrying obligations they have not priced for.
Scenario three
Diagnostic AI in healthcare
Annex I embedded high-risk
Who is caught
Device manufacturers embedding AI as a safety component
Route
Assessed through the existing device conformity process
Deadline
2 August 2028
The regulatory position
Where AI is a safety component of a product already covered by EU harmonisation legislation, such as a medical device, it is high-risk under Article 6(1) rather than Annex III. These embedded cases were deferred to 2 August 2028. The practical consequence is that AI Act conformity has to be folded into the existing device conformity assessment and notified body process rather than run as a separate exercise.
How we would approach it
Start from the existing technical file and identify the gaps the AI Act adds rather than duplicating what is already documented. Extend the existing risk management system to cover the Article 9 requirements. Address accuracy and robustness testing under Article 15, including performance across relevant patient groups. Bring the notified body into the conversation early, since AI Act requirements are assessed through the same route.
The takeaway
The longest deferral belongs to the organisations with the most existing documentation. Used well, that time is spent extending a technical file rather than building one.
Scenario four
Customer-facing chatbots and generated content
Article 50 · Already in force
Who is caught
Almost any organisation with a public AI assistant or AI-generated output
Effort
Low, if addressed deliberately rather than discovered later
Deadline
Passed. 2 August 2026.
The regulatory position
This is the scenario most organisations assume does not apply to them. Article 50 requires that people interacting with an AI system are told so, unless it is obvious from the context. Providers of systems generating synthetic text, audio, image or video must mark the output in a machine-readable form. Deployers publishing AI-generated text on matters of public interest, or producing deepfake content, must disclose it. None of this was deferred by the Digital Omnibus. It has applied since 2 August 2026, and generative systems already on the market before that date come into the marking regime on 2 December 2026.
How we would approach it
Inventory every point where AI touches a customer, an employee or a published output, including tools adopted by individual teams without procurement oversight. Establish for each whether the organisation is provider or deployer, since the marking and disclosure duties differ. Draft the disclosure wording so it satisfies the Article 50 clarity requirement without reading as a legal disclaimer. Confirm marking is applied at generation rather than bolted on afterwards. Then put a control in place so newly adopted tools are assessed before deployment rather than after.
The takeaway
Limited risk does not mean no obligations, and this is the tier where the deadline has already passed. Organisations reassured by headlines about deferral have frequently missed the one part of the Act that binds them today.
What the four have in common
Classification comes first
Every obligation in the Act follows from what the system is for and what role you occupy. Work done before that is settled is usually work done twice.
Deferral is not exemption
Article 5 and Article 50 were untouched by the Digital Omnibus, and December 2026 adds obligations rather than removing them. Firms reading a single headline about delay have often missed the parts already in force.
Frameworks overlap
GDPR, DORA, NIS2 and sectoral rules cover much of the same ground. Running them as one programme is considerably less work than running four.
Which of these looks like you?
A 30 minute call will establish which frameworks apply to your organisation and where the priority obligations sit.
Book a Scoping Call