llm-integration.eu

EU AI Act for LLM deployers: 2026 checklist for Claude

What the EU AI Act requires from companies that deploy LLMs such as Claude in 2026: dates after the Omnibus, provider vs deployer, GPAI duties, checklist.

Updated 11 min readFacts verified on 19 September 2026

TL;DR

For EU AI Act LLM deployers using Claude, the model duties sit with Anthropic. Your company owes AI literacy measures (Article 4), transparency for chatbots and published text (Article 50) and, only for Annex III use cases such as recruiting or credit scoring, high-risk deployer duties from 2 December 2027. Start with an inventory and logging.

What is the AI Act timeline for companies in 2026?

The AI Act has applied in general since 2 August 2026. The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and pushed the high-risk rules back: Annex III use cases now apply from 2 December 2027, product-related Annex I systems from 2 August 2028. Literacy and prohibitions already apply.

We read both texts on EUR-Lex on 19 September 2026: the AI Act as published and the Omnibus amendment. The Omnibus was published in the Official Journal on 24 July 2026 and entered into force on the third day after publication. The Commission overview page shows the same dates.

Date What applies Who is affected
2 Feb 2025 Chapters I and II: definitions, AI literacy (Art. 4), prohibited practices (Art. 5) All providers and deployers
2 Aug 2025 Chapter V: obligations for general-purpose AI (GPAI) model providers Anthropic, other model vendors
27 Jul 2026 Omnibus in force; Articles 102 to 110 apply Everyone (amended rules)
2 Aug 2026 General application, incl. Art. 50 transparency Providers and deployers
2 Dec 2026 New prohibitions on non-consensual intimate imagery and CSAM generation; Art. 50(2) marking deadline for generative systems already on the market before 2 Aug 2026 Providers and deployers
2 Dec 2027 High-risk rules for Annex III systems (Art. 6(2)) Providers and deployers of high-risk use cases
2 Aug 2028 High-risk rules for Annex I products (Art. 6(1)) Product manufacturers

The practical message: if you use Claude for drafting, search, coding or internal assistants, the rules that bind you today are Article 4, Article 5 and Article 50. The heavy high-risk regime is 14 months away, but only for specific use cases. The same applies if you pick ChatGPT instead; our Claude vs ChatGPT comparison covers where the two differ on residency.

Provider or deployer: which role does your company have?

A deployer is anyone “using an AI system under its authority” in a professional context (Art. 3(4)). A provider develops an AI system or GPAI model, or has one developed, and places it on the market or puts it into service under its own name (Art. 3(3)). Anthropic provides the Claude models. Your role depends on what you build.

Three typical situations for companies that reach Claude through Amazon Bedrock or Google Cloud:

  1. You use an off-the-shelf tool built on Claude. You are a deployer of that AI system. The tool vendor is its provider.
  2. You build your own assistant or agent on the Claude API. “Putting into service” explicitly includes supply “for own use” (Art. 3(11)). So when you build an internal chatbot on Claude, you are the provider of that AI system and at the same time its deployer. The AI Act calls this a downstream provider when a system integrates a model from another entity (Art. 3(68)).
  3. You repurpose a general tool for a high-risk task. If you change the intended purpose of a general-purpose AI system so that it becomes high-risk, you become the provider of a high-risk system with the full Article 16 obligations (Art. 25(1)(c)).

Case 2 is the one most engineering teams underestimate. Building on Bedrock or Google Cloud does not make AWS or Google the provider of your application. Your company name is on it, so the provider duties for the system (for example Article 50(1)) are yours, while the model duties stay with Anthropic.

What do GPAI obligations mean for Claude customers?

GPAI obligations bind model providers, not you. Since 2 August 2025, Anthropic must keep technical documentation, give integrators documentation on capabilities and limitations, run a copyright policy and publish a training-content summary (Art. 53(1)). For your compliance file, the relevant part is the documentation Anthropic must provide to downstream providers.

Article 53(1)(b) requires providers to make information available to “providers of AI systems who intend to integrate the general-purpose AI model into their AI systems”, so that they can “comply with their obligations pursuant to this Regulation”. If you build high-risk systems later, this is the documentation you will request. Models above 10^25 FLOPs of training compute are presumed to carry systemic risk (Art. 51(2)) and face extra duties such as adversarial testing and incident reporting (Art. 55(1)). Which Claude models are formally classified that way is not something we could verify on a Commission list, so we do not state it.

The GPAI Code of Practice, published on 10 July 2025, is a voluntary tool with three chapters: Transparency, Copyright, and Safety and Security. The Commission lists Anthropic, Amazon, Google, Microsoft, Mistral AI and OpenAI among the signatories (list updated 31 July 2026). For you, signature means the model vendor has a Commission-endorsed way to show Article 53 compliance. It does not transfer any deployer obligation to the vendor.

On transparency of outputs, Anthropic announced text watermarking on 14 August 2026 “to comply with the EU AI Act”, stating that “future Claude models” will carry it and that a detection API is in private preview. The announcement does not say whether this also applies on Bedrock or Google Cloud, so do not rely on it for your own Article 50 duties.

Which AI Act obligations apply to deployers today?

Three sets apply now. Article 4 requires providers and deployers to “take measures to support the development of AI literacy” of staff using AI. Article 50 requires disclosure when people interact with an AI system or read AI text published on matters of public interest. Article 5 bans certain practices. Article 50 fines reach EUR 15 million or 3%.

AI literacy (Art. 4). The Omnibus softened the wording. The original text required measures to ensure “a sufficient level of AI literacy”. The new text requires measures to “support the development” of AI literacy and adds that it “does not require providers or deployers to guarantee any specific level of AI literacy of any individual”. The obligation still exists. A documented training plan per role, covering prompt data handling, hallucination risk and escalation, is a reasonable minimum. Our Claude data privacy guide is a good basis for the prompt data module.

Transparency (Art. 50).

Paragraph Obligation Who carries it
50(1) Inform people that they interact with an AI system, unless obvious Provider of the system (you, if you built the chatbot)
50(2) Mark synthetic outputs in a machine-readable, detectable way Provider of the generative system
50(3) Inform people exposed to emotion recognition or biometric categorisation Deployer
50(4) Disclose deep fakes, and AI text published to inform the public on matters of public interest, unless human review and editorial responsibility Deployer

The information must be given “at the latest at the time of the first interaction or exposure” (Art. 50(5)). For a customer-service bot built on Claude, one line in the chat window does the job. For marketing copy or reports with a named human editor, Article 50(4) text disclosure usually does not apply, because the exemption for editorial control covers it.

Prohibited practices (Art. 5). Emotion recognition at the workplace and social scoring are the classic traps. From 2 December 2026, the Omnibus adds bans on AI systems generating non-consensual intimate imagery or child sexual abuse material. Violations of Article 5 carry fines up to EUR 35 million or 7% of worldwide turnover (Art. 99(3)).

When does your Claude use case become high-risk?

Your Claude application is high-risk when its intended purpose falls under one of the eight Annex III areas, such as recruiting, credit scoring, life and health insurance pricing, education or access to public services. The obligations apply from 2 December 2027. A general assistant, coding tool or document summariser is not high-risk by default.

The areas most relevant for private companies:

  • Employment (Annex III, point 4): systems used “to analyse and filter job applications, and to evaluate candidates”, or to decide on promotion, termination or task allocation.
  • Essential services (point 5): creditworthiness evaluation of natural persons (5(b)) and risk assessment and pricing for life and health insurance (5(c)).
  • Education (point 3): admission, grading and exam proctoring.

Article 6(3) offers an exit: an Annex III system is not high-risk if it only performs a narrow procedural task, improves a completed human activity, detects patterns without replacing human assessment, or performs a preparatory task. Profiling of natural persons is always high-risk. A provider relying on the exit must document its assessment (Art. 6(4)).

If you are a deployer of a high-risk system, Article 26 applies from December 2027: use it according to the instructions, assign human oversight to competent people, keep logs “of at least six months”, inform workers’ representatives before workplace use, and inform affected persons. Public bodies, private entities providing public services, and deployers of credit scoring or insurance pricing systems must also run a fundamental rights impact assessment (Art. 27). The Omnibus now allows that assessment to cross-reference your GDPR data protection impact assessment. Our GDPR comparison of Claude hosting options covers the DPIA side.

Checklist: AI Act compliance for Claude on Bedrock or Google Cloud

The work for most companies fits into six steps: inventory, role, literacy, transparency, high-risk screening and logging. None of it depends on whether you call Claude through Amazon Bedrock or Google Cloud. The cloud choice matters for GDPR data residency and for which logging tools you have, not for your AI Act role. Whether the Claude apps or a cloud route fit your data is compared in our Claude Enterprise vs Bedrock guide.

  1. Inventory every Claude use. List each application, its intended purpose, the model, the cloud (Bedrock, Google Cloud, Foundry, Anthropic API) and the owner.
  2. Assign the role per application. Bought tool: deployer. Own build: provider of the system and deployer. Annex III purpose: potential high-risk provider under Article 25.
  3. Document AI literacy measures. Training per role, date, content, attendance. Keep it simple and repeatable.
  4. Implement Article 50 notices. Chatbot disclosure at first interaction; an editorial-review rule for published text.
  5. Screen against Annex III and Article 5. Record why each use case is or is not high-risk. Stop any emotion recognition at work.
  6. Switch on logging now. Bedrock model invocation logging is disabled by default, per the AWS documentation. It writes to S3 or CloudWatch Logs in the same account and region.
aws bedrock put-model-invocation-logging-configuration --region eu-central-1 --logging-config '{"s3Config":{"bucketName":"my-ai-act-logs-eu","keyPrefix":"bedrock"},"textDataDeliveryEnabled":true}'
aws bedrock get-model-invocation-logging-configuration --region eu-central-1

Two caveats from the AWS docs. Invocation logging only captures calls through bedrock-runtime, not through bedrock-mantle, so apps on the single-region mantle endpoint described in our Bedrock EU setup guide need application-side logging. And logs are stored until you delete the configuration, so add an S3 lifecycle rule that matches your GDPR retention decision. On Google Cloud, request-response logging writes samples to BigQuery; it is Pre-GA and for Anthropic models configurable only via REST. See our Claude on Vertex AI in Europe guide for the regional setup.

This article is editorial information, not legal advice.

FAQ

These answers reflect the AI Act and the Omnibus as read on EUR-Lex on 19 September 2026. Each one stands alone.

How much can an AI Act violation cost a company that deploys Claude?

Breaches of deployer duties under Article 26 or transparency duties under Article 50 can cost up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher (Art. 99(4)). Prohibited practices reach EUR 35 million or 7%. For SMEs, the lower of the two amounts applies. The Omnibus extends that rule to small mid-caps for fines under Article 99(4) and (5).

Provider vs deployer: what is the difference for a Claude chatbot?

The deployer uses an AI system under its authority. The provider develops it and puts it into service under its own name. If your team builds a chatbot on Claude for internal or customer use, you are both: provider of the chatbot and its deployer. Anthropic remains the provider of the underlying GPAI model.

Did the Omnibus abolish the AI literacy obligation?

No. Article 4 still binds providers and deployers. The Omnibus changed the duty from ensuring a sufficient level of AI literacy to taking measures to support its development, and clarified that no specific level per individual must be guaranteed. Documented training remains the simplest way to show compliance.

Does using Claude via Bedrock instead of the Anthropic API change my AI Act obligations?

No. Your role depends on what you do with the AI system, not on the cloud. Anthropic stays the GPAI model provider in both cases. The cloud choice affects GDPR aspects such as data residency and which logging tools you can use, which is why logging setup differs between Bedrock and Google Cloud.

Must I label every text Claude writes for us?

No. Article 50(4) covers AI text published to inform the public on matters of public interest, and it exempts text that has undergone human review or editorial control with a person holding editorial responsibility. Internal drafts, code and reviewed marketing copy generally fall outside it. Chatbot disclosure under Article 50(1) is a separate duty.

Is an HR screening tool built on Claude high-risk?

Very likely yes. Annex III point 4(a) lists systems used to analyse and filter job applications and to evaluate candidates. Unless the Article 6(3) exception clearly applies and you document it, plan for high-risk obligations from 2 December 2027, including human oversight, log retention and worker information.

Sources

  1. EUR-Lex: Regulation (EU) 2024/1689 (AI Act) (19 September 2026)
  2. EUR-Lex: Regulation (EU) 2026/1744 (Digital Omnibus on AI) (19 September 2026)
  3. European Commission: AI Act regulatory framework (19 September 2026)
  4. European Commission: General-Purpose AI Code of Practice (19 September 2026)
  5. Anthropic: How Claude's text watermarking works (19 September 2026)
  6. AWS Bedrock docs: Model invocation logging (19 September 2026)
  7. Google Cloud docs: Request-response logging (19 September 2026)

Related guides