EU AI Act timeline: every key date after the AI Omnibus

As of October 2026, the EU AI Act applies in stages. The bans on prohibited AI practices have applied since 2 February 2025, the rules for general-purpose AI models since 2 August 2025, and most other provisions, including the transparency duties in Article 50, since 2 August 2026. The obligations for high-risk AI systems were postponed by the AI Omnibus: they now apply from 2 December 2027 for the use cases listed in Annex III and from 2 August 2028 for AI built into products covered by Annex I.

Below is every milestone that matters for providers and deployers, with a note on what the amending regulation changed when it entered into force on 27 July 2026. For news on enforcement and guidance, follow our AI Act coverage.

The AI Act timeline at a glance

  • 1 August 2024: the AI Act, Regulation (EU) 2024/1689, enters into force.
  • 2 February 2025: definitions, the AI literacy duty and the first eight prohibited practices apply.
  • 2 August 2025: obligations for providers of general-purpose AI (GPAI) models, the governance framework and the penalty provisions apply.
  • 2 August 2026: the Act becomes generally applicable, including the Article 50 transparency rules. The European AI Office and national authorities start enforcement.
  • 2 December 2026: the new ban on AI systems that generate non-consensual intimate content or child sexual abuse material applies. Generative AI systems placed on the market before 2 August 2026 must carry machine-readable marking.
  • 2 August 2027: GPAI models placed on the market before 2 August 2025 must comply. National AI regulatory sandboxes must be operational.
  • 2 December 2027: high-risk obligations apply to Annex III systems.
  • 2 August 2028: high-risk obligations apply to AI systems that are products, or safety components of products, covered by the EU legislation listed in Annex I.

The official AI Act Service Desk confirms the main application dates and describes 2 August 2028 as the date of full roll-out. Its implementation timeline also lists the 2 December 2026 and 2 August 2027 milestones.

What the AI Omnibus changed

The Commission proposed the AI Omnibus on 19 November 2025 as part of its digital simplification package. Parliament and Council reached a political agreement on 7 May 2026. Parliament adopted the text on 16 June and the Council on 29 June. It was published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744 and, according to the Commission, entered into force on 27 July 2026, six days before the original high-risk deadline.

The main changes are:

  • Later high-risk dates. Annex III systems moved from 2 August 2026 to 2 December 2027. Annex I systems moved from 2 August 2027 to 2 August 2028.
  • A ninth prohibited practice. AI systems that generate non-consensual sexually explicit or intimate content, or child sexual abuse material, such as "nudification" apps, are banned from 2 December 2026.
  • A softer AI literacy duty. Providers and deployers must now take measures to support AI literacy among their staff rather than ensure a sufficient level of it. The Commission and member states take on a larger role in guidance.
  • Relief for small mid-caps. Simplified technical documentation and proportionate quality management, previously reserved for SMEs, now extend to small mid-cap companies.
  • Bias detection. Providers and deployers of AI systems and models in general, not only high-risk ones, may process special categories of personal data where strictly necessary to detect and correct bias, under safeguards.
  • A stronger AI Office. It supervises AI systems built on a general-purpose model when the system and the model come from the same provider or corporate group, as well as AI systems integrated into very large online platforms and search engines.
  • Lighter registration. The duty to register systems that are exempted from the high-risk category in the EU database is simplified.

What did not move: the GPAI rules, the original eight bans and the Article 50 transparency obligations kept their dates, apart from a short grace period for marking AI-generated content, explained below.

Already in force: bans, AI literacy and GPAI rules

Prohibited practices (since 2 February 2025)

The first eight bans cover harmful manipulation and deception, exploitation of vulnerabilities, social scoring, predicting an individual's risk of committing a crime, untargeted scraping of facial images, emotion recognition in workplaces and schools, biometric categorisation to infer protected characteristics, and real-time remote biometric identification for law enforcement in public spaces, which is allowed only in narrow cases. The Commission published guidelines on prohibited practices in February 2025.

General-purpose AI models (since 2 August 2025)

Providers of GPAI models must keep technical documentation, share information with downstream providers, maintain a copyright policy and publish a summary of training content using the Commission's template. Models with systemic risk face extra duties on evaluation, risk mitigation, incident reporting and cybersecurity. The GPAI Code of Practice of July 2025 is a voluntary way to show compliance. Since 2 August 2026 the AI Office can request documentation, evaluate models, order corrective measures and fine providers.

2 August 2026: transparency rules and enforcement

Article 50 now requires that people are told when they interact with an AI system such as a chatbot, that deepfakes are labelled, and that AI-generated or manipulated content carries machine-readable marks so it can be detected. The Commission has published draft guidelines on these obligations and a voluntary Code of Practice on transparency of AI-generated content. On 31 July 2026 it released a first list of more than 180 signatories.

One transitional rule was added by the Omnibus. Generative AI systems that were already on the market before 2 August 2026 have until 2 December 2026 to meet the marking requirement in Article 50(2). Systems launched on or after 2 August 2026 get no grace period.

High-risk AI: 2 December 2027 and 2 August 2028

Annex III lists the high-risk use cases that apply from 2 December 2027:

  • biometric identification, categorisation and emotion recognition, where permitted;
  • safety components of critical infrastructure;
  • education and vocational training, such as exam scoring or admissions;
  • employment and worker management, such as CV screening;
  • access to essential private and public services, such as credit scoring or eligibility for benefits;
  • law enforcement;
  • migration, asylum and border control;
  • administration of justice and democratic processes.

From that date, providers must run a risk management system, use governed training data, keep logs, prepare technical documentation, give clear instructions to deployers, design for human oversight and meet accuracy, robustness and cybersecurity requirements, then pass a conformity assessment and register the system. Deployers have their own duties, including human oversight and monitoring.

From 2 August 2028, the same rules reach AI that is a regulated product or a safety component of one, for example in machinery, toys, lifts or medical devices. The Commission published draft guidelines on high-risk classification on 19 May 2026; under the amended timeline, the final guidelines are due by 2 August 2027.

Fines under the AI Act

  • Up to €35 million or 7% of worldwide annual turnover, whichever is higher, for prohibited practices.
  • Up to €15 million or 3% for breaches of most other obligations, including those on high-risk systems and transparency.
  • Up to €7.5 million or 1% for supplying incorrect or misleading information to authorities.
  • Up to €15 million or 3% for providers of GPAI models, imposed by the Commission.

For SMEs and start-ups, the lower of the two amounts applies.

What to check before the next deadline

  1. Map every AI system you build or use and note whether it falls under a ban, Annex III, Annex I or Article 50.
  2. If you run a generative AI service launched before 2 August 2026, confirm that machine-readable marking is in place by 2 December 2026.
  3. Remove or block any functionality that could fall under the new ninth prohibition before 2 December 2026.
  4. For high-risk systems, use the extra time to prepare documentation, data governance and conformity assessment, and watch for harmonised standards.
  5. Check which national authority supervises you. The Commission has stressed that effective enforcement depends on member states properly designating and resourcing their authorities. Our policy section tracks national implementation.

Frequently asked questions

When does the EU AI Act fully apply?

Most of the AI Act has applied since 2 August 2026. The last obligations, for high-risk AI built into regulated products, apply from 2 August 2028.

Has the AI Act high-risk deadline been delayed?

Yes. The AI Omnibus, in force since 27 July 2026, moved the Annex III high-risk obligations to 2 December 2027 and the Annex I obligations to 2 August 2028.

Do the AI Act transparency rules apply from August 2026?

Yes. Article 50 has applied since 2 August 2026, but generative AI systems already on the market before that date have until 2 December 2026 to add machine-readable marking.

When must general-purpose AI models comply with the AI Act?

Models placed on the market from 2 August 2025 must comply immediately. Models placed on the market before that date have until 2 August 2027.

What are the maximum fines under the AI Act?

Up to €35 million or 7% of worldwide annual turnover for prohibited practices, and up to €15 million or 3% for most other breaches, including by GPAI providers.