Module 1 of 2 · 45 minutes
The AI Act after the 2026 changes: risk levels, dates and who it reaches
By the end of this module you will be able to
- Describe the four levels of risk with an example of each
- State the dates that apply after the July 2026 amendment
- Explain what Article 4 now asks on AI literacy
- Explain the transparency rules in Article 50
- Say when the Act reaches a UK organisation, and how the UK differs
Work through it
1 interactive for this module, built on the WAJD Teach engine. Nothing moves until you ask it to, and every one has a written version if you would rather read it.
Watch: Emma and George talk it through
4 minutes. Captions are on, and the same conversation is written out in full below. The voices are computer generated.
Emma George, the EU AI Act. I've sat through two webinars on it and they gave me different dates. Which is right?
George Possibly neither, if they were recorded before July 2026. The Act was amended that month. So let me give you the shape first and the dates second.
Emma Go on.
George The Act doesn't treat AI as one thing. It asks what the system is used for and sorts it into four levels. Banned. High risk. Limited risk. And minimal risk, which is most everyday use.
Emma What's banned?
George Things like social scoring, harmful manipulation, and emotion recognition of staff at work or pupils at school, unless it's for medical or safety reasons.
Emma And high risk?
George Allowed, with heavy duties. Recruitment and managing workers. Education and exams. Access to essential services and credit. And AI that's a safety component of a regulated product, like a machine.
Emma So a tool that ranks job applicants.
George High risk. Whereas a customer service chatbot is limited risk. You just have to tell people it's AI. And a grammar assistant is minimal.
Emma Now the dates.
George In force 1 August 2024. Bans and the AI literacy duty since 2 February 2025. Then the amendment. Regulation 2026/1744, published 24 July 2026, in force 27 July. It moved the main high risk duties from August 2026 to 2 December 2027 for stand-alone systems, and 2 August 2028 for AI built into regulated products.
Emma So anyone telling me high risk started this August is out of date.
George Yes. Check the date on whatever you're relying on. What did keep its date is transparency. That applied from 2 August 2026.
Emma Meaning?
George Article 50. Tell people when they're interacting with an AI system unless it's obvious. Disclose content generated or manipulated to look real. And providers must mark generated text, images, audio and video so it can be detected.
Emma And the training duty? I heard that was dropped.
George Reworded, not dropped. Article 4 used to say ensure a sufficient level of AI literacy. Now providers and deployers must take measures to support the AI literacy of their staff. Nobody has to guarantee a level for an individual. Training and a record of it is the obvious measure.
Emma We're in the UK. Does any of this bind us?
George It isn't UK law. It reaches you if you place an AI system on the EU market, or if the output of your system is used in the EU. And the fines are large. Up to 35 million euros or 7 per cent of worldwide turnover for banned practices.
Emma And if we've no EU link at all?
George Then UK law applies, and the UK has no single AI statute. Existing regulators apply existing law, guided by five principles. Data protection does most of the work.
Emma Anything new there?
George Yes. Since 5 February 2026 the rules on solely automated decisions changed. A decision with legal or similarly significant effect can be made by automated means only with safeguards. The person is told, can make representations, can get a human to intervene, and can contest it.
Emma So either way a person can ask for a human.
George Either way. And either way, the system decided is not a defence. The organisation using the tool answers for what it does with it.
The written material
Four levels of risk
The Act does not regulate AI as one thing. It asks what a system is used for and sorts it into one of four levels.
Some practices are banned outright, such as social scoring, manipulating people in ways that cause harm, and emotion recognition in workplaces and schools except for medical or safety reasons. High risk uses are allowed but carry heavy duties: recruitment and managing workers, education and exams, access to essential services and credit, and AI that is a safety component of a regulated product. Limited risk systems carry transparency duties. Everything else, which is most everyday use, is minimal risk and largely left alone.
The dates, after July 2026
The Act came into force on 1 August 2024 and applies in stages. The bans and the AI literacy duty have applied since 2 February 2025. Duties on providers of general purpose AI models have applied since 2 August 2025.
On 24 July 2026 an amending regulation, Regulation (EU) 2026/1744, was published, and it came into force on 27 July 2026. It moved the main high risk duties from 2 August 2026 to 2 December 2027 for stand-alone systems, and to 2 August 2028 for AI built into regulated products. The transparency rules kept their date of 2 August 2026, with systems already on the market given until 2 December 2026 to mark generated content. It also added a ban on AI systems that generate non-consensual intimate images or child sexual abuse material.
Article 4 and Article 50
Article 4 is the AI literacy duty. As amended, providers and deployers of AI systems must take measures to support the AI literacy of their staff and of other people who operate AI systems on their behalf, taking account of their knowledge, experience and the context in which the systems are used. The earlier wording, to ensure a sufficient level, has gone, and nobody has to guarantee a particular level for an individual. Training, and a record of it, is the obvious measure.
Article 50 is transparency. People must be told when they are interacting with an AI system unless it is obvious. Content that has been generated or manipulated to look real, often called a deepfake, must be disclosed as such. And providers of systems that generate text, images, audio or video must mark the output so that it can be detected as artificially generated.
Does it reach the UK, and what the UK does instead
The Act is not UK law. It applies to a UK organisation that places an AI system on the EU market or puts it into service there, and where the output produced by the system is used in the EU. The fines are large: up to 35 million euros or 7 per cent of worldwide turnover for banned practices, and up to 15 million euros or 3 per cent for most other breaches.
The United Kingdom has no single AI statute. Existing regulators apply existing law to AI, guided by five principles: safety and security, transparency and explainability, fairness, accountability and governance, and contestability and redress. Data protection law does most of the work. Since 5 February 2026, when the Data (Use and Access) Act 2025 replaced the old Article 22 with new Articles 22A to 22D, a decision with legal or similarly significant effect may be made solely by automated means only with safeguards: the person is told, can make representations, can obtain human intervention and can contest the decision. Stricter conditions apply where special category data is used.
Knowledge check
The knowledge check and your certificate need a free account, so that your progress and results can be saved as evidence.
The learning itself stays free and open. You are reading all of it right now without an account.
Was this module useful? Tell us in two minutes, it decides what we improve next.