Active since 2 February 2025
Article 4: AI literacy
Providers and deployers must take measures to ensure a sufficient level of AI literacy for staff and other people operating AI systems on their behalf.
Official-source watchlist
A concise, dated view of the EU AI Act milestones that affect practical governance work in 2026 and beyond. Each point links to the official Commission or EUR-Lex source used for the review.
Reviewed 11 July 2026
Dates below are a working governance reference. The Commission guidance and the Regulation remain the authoritative sources, and implementation guidance can change.
Active since 2 February 2025
Providers and deployers must take measures to ensure a sufficient level of AI literacy for staff and other people operating AI systems on their behalf.
Active since 2 August 2025
General-purpose AI model obligations and governance milestones have applied on the Commission timeline since August 2025, with specific duties depending on the actor and model.
From 2 August 2026
Providers and deployers of certain AI systems face transparency duties, including information and marking expectations for specified AI-generated or manipulated content.
Current Commission guidance
The Commission's current high-risk guidance describes the implementation timeline for standalone Annex III systems as 2 December 2027 after the political agreement on the Digital Omnibus.
Current Commission guidance
The current guidance describes 2 August 2028 for high-risk AI systems embedded in regulated products, subject to the legal and implementation context described by the official sources.
Always check the use case
Classification depends on the system, purpose, actor, deployment context, affected people, and applicable sector obligations. A label alone is not an assessment.
From watch item to evidence
The watchlist is useful only when it changes what a team records, reviews, and monitors. These are the practical PALO responses for a working file.
| Watch point | PALO response | Evidence to keep |
|---|---|---|
| AI literacy | Identify people who operate, supervise, procure, or review the system and route them to role-specific literacy actions. | Training record, role map, escalation contact, review date. |
| Article 50 transparency | Map where users or affected people need information, content marking, disclosure, or an explanation of the system's role. | Notice copy, content provenance decision, UI or workflow evidence, owner. |
| High-risk timeline | Use Risk Tiering early, then preserve the rationale and open questions instead of waiting for a final implementation date. | Classification rationale, affected-person analysis, control plan, source snapshot. |
| Article 27 context | Route public-authority, public-service, credit, and insurance deployment contexts to a contextual FRIA check. | FRIA scope decision, rights impact notes, mitigation and consultation record. |
| Changing guidance | Assign an owner and review trigger so the governance record is revisited when official guidance or the system changes. | Watch log, source links, version, decision log, next review date. |
Classify
Start with purpose, actor, use, and affected people.
Assess
Keep the Article 27 scope decision and rights impact evidence together.
Evidence
Route the work and export a versioned local evidence bundle.
Agents
Extend the assessment to delegated action, authority, and autonomy.
Use the following sources to verify dates and obligations before a governance decision is made.