The EU AI Act does not switch on all at once. It arrives in stages, and each stage binds a different set of duties to a different set of organizations. Treat "the AI Act deadline" as a single event and you will either scramble late or spend money early on rules that do not yet apply to you. The dates are the product here. Get them straight and the compliance work sequences itself.
The picture also moved in 2026. The Digital Omnibus, a simplification package the European Commission proposed on 19 November 2025, was adopted in mid-2026 and deferred the heaviest obligations, those covering high-risk systems, by more than a year. Prohibited practices, AI-literacy duties, general-purpose AI (GPAI) rules, and Article 50 transparency were left on their original schedule. This guide walks every milestone in order: what becomes enforceable, who it affects, and what to finish before each date.
Why the Phased Timeline Matters
The staggered dates are a feature, not an accident. Each one gives a category of AI a defined runway to comply.
The Act splits AI into risk tiers and enforces them on different clocks. Practices the EU considers unacceptable, such as social scoring by public authorities or untargeted facial-recognition scraping, were banned first because the harm is immediate. General-purpose AI models came next, because a handful of foundation models sit underneath thousands of downstream products. High-risk systems, used in hiring, credit, medical devices, education, and critical infrastructure, get the longest runway because conformity assessment, documentation, and post-market monitoring take real engineering time to build.
For a compliance, legal, or AI team, the practical value of the phasing is prioritization. You do not need every control ready on day one. You need to know which systems fall into which tier, and which clock each one is running against. A hiring-screening tool and a chatbot that writes marketing copy carry very different deadlines and obligations, even inside the same company.
Scope first, then dates. The timeline only helps once you know what you operate. A current inventory of every AI system and use case, including tools adopted by teams without central sign-off, is the input that makes each deadline actionable. Without it you are guessing which rules apply.
What the Digital Omnibus Changed
The single most important change to the calendar since the Act passed. Read this before you rely on any older timeline.
The original Act set 2 August 2026 as the date most high-risk obligations would bite. Standards, guidance, and national supervisory structures were not ready in time, so the Commission proposed the Digital Omnibus to buy the ecosystem more time. After a provisional trilogue agreement on 7 May 2026, the Parliament endorsed the package on 16 June 2026 and the Council gave final approval on 29 June 2026.
- Standalone high-risk (Annex III) systems moved from 2 August 2026 to 2 December 2027. These are systems that are high-risk because of what they do: hiring tools, credit scoring, education assessment, and similar.
- Embedded high-risk (Annex I) systems moved to 2 August 2028. These are AI components inside products already regulated under existing EU product-safety law, such as medical devices and machinery.
- Article 50 transparency stayed at 2 August 2026. Chatbots must disclose they are machines, and AI-generated or manipulated content, including deepfakes, must be labeled.
- Prohibited practices, AI literacy, and GPAI obligations were untouched. They remain in force on their earlier dates.
Do not read "deferral" as "cancellation." The obligations did not shrink. The runway got longer. A high-risk system placed on the EU market in 2028 must still pass a conformity assessment, carry technical documentation, log its operation, and support human oversight. The deferral is time, not relief.
The Full Timeline, Milestone by Milestone
Every date the Act sets, in order, with what turns on and who it lands on.
Entry into force. The Act became law across all 27 member states and the countdown began. No operational duties yet, but this is the reference point every later deadline counts from. Affects: everyone in scope, as a planning trigger.
Prohibited practices banned + AI-literacy duty. Unacceptable-risk uses (social scoring by authorities, manipulative or exploitative systems, untargeted facial-recognition scraping, most real-time remote biometric identification in public) are now illegal. Separately, any organization that provides or deploys AI must ensure staff have adequate AI literacy. Affects: all providers and deployers, immediately.
GPAI obligations + governance + penalty powers. Providers of general-purpose AI models take on transparency, documentation, and copyright duties, with stricter rules for models posing systemic risk (the threshold is training compute above 10^25 FLOPs). The AI Office and national authorities stand up, and the penalty regime under Article 99 becomes usable. Affects: foundation-model providers first; enforcement machinery for all.
Article 50 transparency in force. Users must be told when they are interacting with an AI system, and synthetic or manipulated media must be marked in a machine-readable way. This was originally the date for most high-risk rules too, but the Digital Omnibus moved those out. Affects: anyone running chatbots, generative content tools, or deepfake-capable systems.
GPAI legacy-model compliance date. General-purpose models already on the market before 2 August 2025 get until this date to meet the full GPAI obligations. The Omnibus left this track unchanged. Affects: providers of foundation models released before August 2025.
Standalone high-risk (Annex III) obligations. The core high-risk regime applies: risk management systems, data governance, technical documentation, logging, human oversight, accuracy and robustness, conformity assessment, and registration. This is the deferred date, moved from 2 August 2026. Affects: providers and deployers of hiring, credit, education, biometric, and critical-infrastructure AI.
Embedded/Annex I high-risk obligations. AI that is a safety component of products already regulated under EU product law (medical devices, machinery, vehicles, and similar) must meet the full high-risk requirements, aligned with those products' own certification cycles. Affects: manufacturers of regulated products with AI inside them.
Deadline Table at a Glance
The same milestones in a form you can drop into a compliance tracker.
| Date | Obligation | Who it affects | Status |
|---|---|---|---|
| 1 Aug 2024 | Entry into force | All in scope (planning trigger) | In effect |
| 2 Feb 2025 | Prohibited practices + AI-literacy duty | All providers and deployers | In effect |
| 2 Aug 2025 | GPAI obligations + governance + penalty powers | Foundation-model providers; all (enforcement) | In effect |
| 2 Aug 2026 | Article 50 transparency | Chatbot, generative, and deepfake operators | Upcoming (unchanged) |
| 2 Aug 2027 | GPAI legacy-model compliance | Pre-Aug-2025 foundation models | Upcoming |
| 2 Dec 2027 | Standalone high-risk (Annex III) | Hiring, credit, education, biometric AI | Deferred (was 2 Aug 2026) |
| 2 Aug 2028 | Embedded/Annex I high-risk | Regulated-product manufacturers | Deferred |
Right now (July 2026), three sets of duties are live: the prohibitions, the AI-literacy duty, and the GPAI regime, all backed by enforceable penalties. Article 50 transparency is the next date to hit, on 2 August 2026.
What to Do Before Each Date
A deadline list is only useful if it drives work. Here is the sequence, grouped into phases that map to the dates above.
- Confirm you run nothing that falls under the eight prohibited practices. If a use case is close to the line, get legal sign-off in writing.
- Stand up an AI-literacy program: role-based training for anyone who builds, buys, or operates AI, with records of who completed it.
- If you provide a general-purpose model, prepare the technical documentation, training-data summary, and copyright policy the GPAI rules require.
- Inventory every user-facing AI: chatbots, assistants, and any tool that generates or edits images, audio, video, or text.
- Add clear "you are talking to an AI" disclosure at the start of AI interactions.
- Implement machine-readable marking for AI-generated and manipulated content, and label deepfakes visibly.
- Classify each system against Annex III to confirm which are high-risk, and whether you are the provider, the deployer, or both.
- Build the required controls: a documented risk management system, data governance, technical documentation, event logging, human oversight, and accuracy and robustness testing.
- Run conformity assessment, register the system in the EU database, and set up post-market monitoring before you place it on the market.
- Fold AI Act requirements into the existing product-certification process for the regulated product, rather than running a parallel track.
- Coordinate with your notified body so the AI conformity work lands inside the product's own assessment cycle.
One capability underpins all four phases: a live inventory that maps each AI system and use case to its risk tier and its deadline. Mature programs treat this as continuous work, not a one-off survey. Automated discovery finds systems that teams adopted without central approval, often called shadow AI, and continuous monitoring flags when a model changes behavior or drifts out of its tested envelope. Mapping one control set to several frameworks at once means the evidence you gather for the AI Act also serves NIST AI RMF and ISO 42001, so you assess once and report many times.
Penalties and the Chance of Further Shifts
The dates matter because missing them is expensive. Article 99 sets three tiers, and they have been enforceable since August 2025.
Fines are set against worldwide turnover, so the Act reaches the parent company's global revenue, not just its EU operations. For smaller firms the caps are proportionate, but the reputational exposure and the risk of being ordered to withdraw a system from the market can hurt more than the fine itself.
Dates can still move. The Digital Omnibus proved the calendar is not fixed: standards readiness, guidance from the AI Office, and political pressure can all shift specific deadlines again. Treat the dates here as the current plan of record, keep watching the AI Office and the Official Journal, and build controls early enough that another deferral is a bonus rather than a dependency.
Key Takeaways
- The EU AI Act enforces in stages from 2024 to 2028, not on one date. Prohibitions, AI literacy, and GPAI rules are already live and already enforceable.
- The Digital Omnibus, adopted in mid-2026, deferred standalone high-risk (Annex III) duties to 2 December 2027 and embedded/Annex I duties to 2 August 2028. It did not weaken the obligations, only the timing.
- Article 50 transparency stayed at 2 August 2026, and the GPAI legacy-model date stayed at 2 August 2027.
- Penalties under Article 99 reach €35M or 7% of global turnover for prohibited uses and have been in force since August 2025.
- A live, mapped AI inventory is the single input that turns this calendar into a workable plan, and dates can still shift, so build early.
From policy to practice. Spreadsheets and ticket queues rarely keep up with how fast AI spreads across an enterprise, or with a compliance calendar that keeps moving. Dedicated AI governance platforms give governance teams one place to discover, assess, monitor, and evidence every model and agent against frameworks like the EU AI Act, NIST AI RMF, and ISO 42001.
Frequently Asked Questions
Some of them, yes. The Digital Omnibus, approved by the Council on 29 June 2026, deferred the high-risk obligations: standalone Annex III systems now apply from 2 December 2027 (moved from 2 August 2026) and embedded Annex I systems from 2 August 2028. The prohibitions, AI-literacy duty, GPAI rules, and Article 50 transparency were not delayed.
As of July 2026, three sets of duties are in force and enforceable: the ban on prohibited AI practices (since 2 February 2025), the AI-literacy obligation for staff (since 2 February 2025), and the general-purpose AI regime plus penalty powers (since 2 August 2025). Article 50 transparency is next, on 2 August 2026.
It depends on the type. Standalone high-risk systems listed in Annex III, such as hiring, credit, and education tools, must comply by 2 December 2027. AI embedded as a safety component in products already regulated under Annex I, such as medical devices, has until 2 August 2028. Both dates are the deferred timeline set by the Digital Omnibus.
Yes. Article 50 transparency was left on its original schedule. From 2 August 2026 you must disclose when users interact with AI and mark AI-generated or manipulated content in a machine-readable way. Generative systems already on the market before that date have a short grace period, to 2 December 2026, to meet the machine-readable marking requirement.
Article 99 sets three tiers, enforceable since August 2025: up to €35M or 7% of global annual turnover for prohibited uses, up to €15M or 3% for most other breaches (including high-risk and transparency failures), and up to €7.5M or 1% for giving authorities incorrect information. The higher of the fixed sum or the percentage applies.
They could. The Digital Omnibus itself showed the calendar can move when standards or guidance are not ready. Treat the dates here as the current plan of record, monitor the AI Office and the EU Official Journal for updates, and build your controls early so any further deferral works in your favor rather than becoming a plan you depend on.