EU AI Act timeline 2026, 2027 and 2028: what applies when
Regulation (EU) 2024/1689, with the dates as amended by the Digital Omnibus (Regulation (EU) 2026/1744, in force since 27 July 2026). Every date below is traced to the Article that sets it.
The AI Act does not switch on all at once. Article 113 staggers it across six years, and the Digital Omnibus moved two of those dates in 2026 while leaving the rest alone. Guidance written before July 2026 is therefore often wrong in one of two directions: some pages still print the original 2026 and 2027 high-risk dates, and others report that "the AI Act was delayed" as though everything moved. Neither is right, and the difference decides whether your 2026 compliance work is overdue or premature.
Every date at a glance
| Date | What applies | Who it affects | Article |
|---|---|---|---|
| 1 Aug 2024 | Regulation enters into force | Nobody yet, the clock starts | Art. 113 |
| 2 Feb 2025 | Chapters I and II: prohibited practices and AI literacy | Every provider and deployer | Art. 113(a), Art. 4, Art. 5 |
| 2 Aug 2025 | GPAI models, notified bodies, governance, penalties | Model providers, authorities | Art. 113(b) |
| 27 Jul 2026 | Digital Omnibus in force; Arts. 102 to 110 apply | Sectoral product regimes | Art. 113(d), inserted |
| 2 Aug 2026 | General date of application: Article 50 transparency | Almost every SME using AI | Art. 113, Art. 50 |
| 2 Dec 2026 | Marking grace period ends; new Article 5 bans start | Providers of generative systems | Art. 111(4), Art. 113(a) |
| 2 Aug 2027 | Legacy GPAI models must be compliant | Foundation model providers | Art. 111(3) |
| 2 Dec 2027 | High-risk regime, Annex III stand-alone systems | Recruitment, credit, biometrics, essential services | Art. 113(c)(i) |
| 2 Aug 2028 | High-risk regime, Annex I embedded safety components | Machinery, medical devices, vehicles, toys, lifts | Art. 113(c)(ii) |
| 2 Aug 2030 | Legacy high-risk systems used by public authorities | Public sector and their suppliers | Art. 111(2) |
| 31 Dec 2030 | AI components of Annex X large-scale IT systems | EU-level databases | Art. 111(1) |
The timeline in detail
Prohibited practices ban (Art. 5) and AI literacy (Art. 4)
Chapters I and II applied first. Social scoring, manipulative or exploitative techniques that cause significant harm, untargeted scraping of facial images, emotion inference in workplaces and schools, and the other Article 5 practices became illegal outright, with no compliance route that makes them lawful. Separately, providers and deployers had to start taking measures to support the development of AI literacy among staff and other people operating AI systems on their behalf.
General-purpose AI models, governance and the penalties chapter
Article 113(b) brought in Chapter V (general-purpose AI models), Chapter III Section 4 (notifying authorities and notified bodies), Chapter VII (governance), Chapter XII (penalties, other than Article 101) and Article 78. Providers of general-purpose AI models, meaning the models behind tools like chatbots rather than the tools themselves, must keep technical documentation, publish a sufficiently detailed summary of training content and adopt a copyright policy. This date matters if you train or substantially modify a foundation model. It does not create obligations for a company that merely calls one through an API.
Digital Omnibus enters into force
Regulation (EU) 2026/1744 amended the AI Act itself: it replaced Article 4, added two prohibitions to Article 5, clarified what counts as a safety component in Article 6, inserted SME and small mid-cap definitions, added the Article 99(6a) penalty cap for small mid-caps, and rewrote the Article 113 application dates. A new Article 113(d) makes Articles 102 to 110, the amendments to the sectoral product regulations, apply from this date.
Article 50 transparency duties
The AI Act's general date of application, and the one most SMEs actually needed to plan for. Four duties start: chatbot disclosure under Art. 50(1), machine-readable marking of AI-generated content under Art. 50(2), emotion recognition and biometric categorisation disclosure under Art. 50(3), and deep fake labelling under Art. 50(4). Article 50(5) requires the information to be clear, distinguishable, delivered no later than the first interaction or exposure, and accessible. The Digital Omnibus did not defer any of this.
Marking grace period ends, and the new Article 5 bans start
Article 111(4), inserted by the omnibus, gives providers of AI systems generating synthetic audio, image, video or text that were placed on the market before 2 August 2026 until this date to comply with the Article 50(2) machine-readable marking duty. Systems placed on the market after 2 August 2026 had to comply immediately, with no grace period. On the same date, the two prohibitions the omnibus added as Article 5(1)(ba) and (bb), covering AI that generates or manipulates non-consensual intimate material or child sexual abuse material, begin to apply, together with the scoping paragraphs 5(1a) and 5(1b).
Legacy general-purpose AI models must be compliant
Article 111(3) gives providers of general-purpose AI models placed on the market before 2 August 2025 until this date to bring them into line with the Chapter V obligations. Unchanged by the omnibus, and relevant only to model providers.
High-risk regime, Annex III stand-alone systems
Chapter III Sections 1 to 3 apply to systems that are high-risk under Article 6(2) and Annex III: recruitment and worker management, credit scoring, insurance risk assessment and pricing, biometric identification and categorisation, education and exam scoring, access to essential public and private services, law enforcement, migration and border control, and administration of justice. Providers face risk management, data governance, technical documentation under Annex IV, logging, human oversight, accuracy, robustness and cybersecurity, a quality management system and conformity assessment. Deployers face the Article 26 duties, and a fundamental rights impact assessment under Article 27 where it applies. The original date was 2 August 2026; the omnibus moved it here.
High-risk regime, Annex I embedded safety components
The same Chapter III obligations for AI used as a safety component in, or as, a product covered by the Union harmonisation legislation listed in Annex I: machinery, medical devices, vehicles, toys, lifts, radio equipment and similar, coordinated with the existing sectoral CE conformity process. The original date was 2 August 2027. The omnibus also added Article 6(1a) to (1c), which keep AI used purely for convenience, performance optimisation or quality control out of the safety-component definition.
Legacy public-sector and large-scale IT systems
Article 111(2) requires providers and deployers of high-risk AI systems intended for use by public authorities to comply by 2 August 2030 even where the system predates the Chapter III date. Article 111(1) gives AI components of the Annex X large-scale EU IT systems until 31 December 2030.
What the Digital Omnibus changed, and what it did not
| Obligation | Original date | Date now | Moved? |
|---|---|---|---|
| Prohibited practices (Art. 5, original list) | 2 Feb 2025 | 2 Feb 2025 | No |
| AI literacy (Art. 4) | 2 Feb 2025 | 2 Feb 2025 | No, but the wording was replaced |
| GPAI models (Chapter V) | 2 Aug 2025 | 2 Aug 2025 | No |
| Transparency (Art. 50) | 2 Aug 2026 | 2 Aug 2026 | No |
| New Art. 5 bans on NCII and CSAM generation | Did not exist | 2 Dec 2026 | New |
| Art. 50(2) marking, systems already on the market | No grace period | 2 Dec 2026 | New grace period |
| High-risk, Annex III (Art. 6(2)) | 2 Aug 2026 | 2 Dec 2027 | Deferred 16 months |
| High-risk, Annex I (Art. 6(1)) | 2 Aug 2027 | 2 Aug 2028 | Deferred 12 months |
The reasoning is set out in the omnibus recitals: harmonised standards, common specifications and national competent authorities were not ready in time for the high-risk regime, and applying it on the original date would have raised implementation costs without a corresponding gain. Nothing in that reasoning touched the transparency duties, which need no standards and no notified bodies, which is why they were left where they were.
What this means in practice, by company profile
You run a chatbot or publish AI-generated content
- Your deadline was 2 August 2026, not 2027. If the disclosure is not live, you are late now.
- If a generative feature of yours predates August 2026, 2 December 2026 is the marking deadline.
- Nothing in the 2027 or 2028 dates applies to you unless you also do something on the Annex III list.
Your staff use AI tools, but you sell nothing AI-powered
- The Article 4 AI-literacy duty has applied since February 2025. The Article 5 prohibitions have bound you as a user of AI since the same date, and the Article 50(3) and 50(4) deployer transparency duties since 2 August 2026.
- Article 5 still binds you as a user of AI, not only as a builder. Check the prohibited list once and record the result.
You deploy a recruitment, credit or insurance-pricing system
- Your regime starts 2 December 2027, and your obligations are the Article 26 deployer list, not the provider list.
- The work that has to happen in 2026 is contractual: written vendor commitments on conformity assessment, instructions for use, and log retention.
- Check the Article 6(3) filter before assuming the system is high-risk at all.
You embed AI in a CE-marked product
- Your date is 2 August 2028, aligned with your existing sectoral conformity process.
- Check Article 6(1a) first: AI used solely for convenience, service efficiency or quality control is not a safety component, and does not pull the product into the high-risk category.
How to check whether a date still stands
Dates in this area have already moved once, and Article 112 requires the Commission to review the Annex III list and the Article 5 prohibition list every year, so further amendments are likely rather than hypothetical. Two habits keep you out of trouble. First, cite the Article, not the headline: "Chapter III Sections 1 to 3 under Art. 113(c)(i)" survives an amendment in a way that "the 2027 deadline" does not. Second, verify against the Official Journal consolidated text rather than against secondary coverage, which lags by months. Klariq's obligations dataset is re-checked against the Official Journal on a schedule and drives both this page and the classifier, so the dates you see in your results match the dates here.
Common questions
What EU AI Act obligations are already in force?
Since 2 February 2025: the ban on prohibited AI practices in Article 5 and the Article 4 AI-literacy duty. Since 2 August 2025: the general-purpose AI model obligations in Chapter V, the governance chapter, and the penalties chapter. Since 2 August 2026: the Article 50 transparency duties.
What changed on 2 August 2026?
That is the AI Act's general date of application, and it is when the Article 50 transparency duties start: chatbots must disclose that they are AI, AI-generated audio, image, video and text must be marked in a machine-readable format, deep fakes must be labelled, and people exposed to emotion recognition or biometric categorisation must be told.
What happens on 2 December 2026?
Two things. Article 111(4) gives providers of systems generating synthetic content that were already on the market before 2 August 2026 until 2 December 2026 to meet the Article 50(2) machine-readable marking duty. And the two prohibitions added by the Digital Omnibus, on generating non-consensual intimate material and child sexual abuse material, start to apply.
Was the EU AI Act timeline delayed?
Partly. The Digital Omnibus, Regulation (EU) 2026/1744, in force since 27 July 2026, amended Article 113 so that Chapter III Sections 1 to 3 apply from 2 December 2027 for Annex III high-risk systems and from 2 August 2028 for Annex I high-risk systems. It did not defer Article 50 transparency, which still applies from 2 August 2026, or Article 4 AI literacy, which has applied since February 2025.
What is the EU AI Act deadline for 2027?
2 December 2027 is when the full high-risk regime applies to stand-alone Annex III systems such as recruitment, credit scoring, biometric identification and access to essential services. Separately, 2 August 2027 is the date by which providers of general-purpose AI models placed on the market before 2 August 2025 must be compliant, under Article 111(3).
What is the EU AI Act deadline for 2028?
2 August 2028 is when the high-risk regime applies to AI used as a safety component in products already covered by the Union harmonisation legislation listed in Annex I, such as machinery, medical devices, vehicles, toys and lifts.
Which date matters most for a small company?
For most SMEs it is 2 August 2026, already passed, because that is when the Article 50 transparency duties took effect for chatbots and AI-generated content. The high-risk deadlines in 2027 and 2028 only apply to companies providing or deploying a system on the Annex III list or embedded in an Annex I regulated product.