The EU AI Act does not kick in all at once, and the schedule changed in 2026. This guide maps every obligation to its current enforcement date and tells you what your team needs to have ready before each one.

UPDATED 2026-07-23: The EU adopted a "Digital Omnibus on AI" in mid-2026 that deferred several of the deadlines below. This article has been revised to reflect the current schedule. The most important change: the August 2, 2026 high-risk deadline that used to be "the" deadline is NOT the main deadline anymore for most Annex III systems — that obligation moved to December 2, 2027. But August 2, 2026 still matters: Article 50 transparency obligations were NOT deferred and remain due on schedule.

Why the Timeline Is Confusing

The EU AI Act was signed into law on August 1, 2024. It does not apply as a single block — obligations roll out in phases, each wave targeting a different tier of risk. That phasing was already confusing enough. Then, in 2026, the EU passed a "Digital Omnibus on AI" that changed several of the original dates. If you read an older summary of this timeline (including earlier versions of this article), some of the dates in it are now out of date.

The most damaging mistake today is assuming everything got pushed back. It didn't. Article 5 prohibitions and GPAI obligations are unaffected and already in force. Article 50 transparency obligations are unaffected and still land on August 2, 2026. Only the Annex III/Annex I high-risk deadlines were deferred — and by different amounts.

What the Digital Omnibus Actually Changed

The European Commission proposed the Digital Omnibus in November 2025 as part of a broader simplification push. An initial trilogue attempt failed on April 28, 2026, but a political agreement was reached on May 7, 2026. The European Parliament voted on the final text on June 16, 2026, and the Council approved it on June 29, 2026, with entry into force in July 2026.

Provision Original date Status after the Omnibus
Article 5 — prohibited practices Feb 2, 2025 Unchanged, in force. A new prohibition on AI-generated non-consensual intimate imagery and CSAM was added, with a transitional period until Dec 2, 2026.
GPAI model obligations (Chapter V) Aug 2, 2025 Unchanged, in force.
Article 4 — AI literacy Feb 2, 2025 In force, but the substance of the obligation was softened by the Omnibus.
Article 50 — transparency (AI-generated content, chatbot disclosure) Aug 2, 2026 Unchanged — proceeds as scheduled. Article 50(2) watermarking gets a 4-month grace period (to Dec 2, 2026) for systems already on the market.
Annex III — stand-alone high-risk systems (recruitment, credit scoring, law enforcement, education, etc.) Aug 2, 2026 DEFERRED to Dec 2, 2027.
Annex I — high-risk AI embedded in regulated products (medical devices, machinery, vehicles) Aug 2, 2027 DEFERRED to Aug 2, 2028.
AI regulatory sandboxes — Member State establishment Aug 2, 2026 DEFERRED to Aug 2, 2027.
If you build agents, chatbots, or content tools rather than Annex III "high-risk" systems, Article 50 is very likely your actual near-term deadline — not the Annex III date everyone talks about. Article 50 requires disclosure when users are interacting with an AI system, and labeling of AI-generated or manipulated audio/image/video/text content (with narrow exceptions).

February 2, 2025: Prohibited AI Systems (Unchanged)

This deadline has already passed and was not affected by the Omnibus. The prohibited practices in Article 5 have been enforceable since February 2, 2025.

The prohibited categories include:

  • Social scoring systems used by public authorities to evaluate or classify people based on their social behaviour or personal characteristics.
  • AI that exploits the vulnerabilities of a specific group (age, disability, socioeconomic situation) to cause harm.
  • AI using subliminal techniques to manipulate behaviour in ways that cause harm.
  • Real-time remote biometric identification (RRBI) in publicly accessible spaces, used by law enforcement — except in narrowly defined circumstances requiring judicial authorisation.
  • AI systems for predictive policing that make individual risk assessments solely on the basis of profiling or personal characteristics.
  • AI used to scrape facial images from the internet or CCTV to build facial recognition databases.
  • AI used to infer emotions in workplaces and educational institutions (with exceptions for safety and medical reasons).
  • Biometric categorisation systems that use sensitive attributes to infer race, political opinions, religious beliefs, health status, or sexual orientation.
  • NEW (added by the 2026 Omnibus): AI systems that generate or manipulate non-consensual intimate images, video, or audio, or generate CSAM. This prohibition has a transitional implementation period running to December 2, 2026.

August 2, 2025: GPAI Models and Governance (Unchanged)

This deadline has also passed and was not affected by the Omnibus. Three sets of obligations became active:

1. General-Purpose AI (GPAI) Model Obligations

Any organisation that trains and makes available a GPAI model must comply with Chapter V of the Act. This includes:

  • Technical documentation for the model (training data, architecture, evaluation results).
  • Copyright compliance policy and disclosure of training data used.
  • Publishing a sufficiently detailed summary of training data for copyright purposes.

Models with systemic risk — those trained with compute exceeding 10^25 FLOPs, or otherwise designated by the EU AI Office — have additional obligations: adversarial testing, serious incident reporting to the EU AI Office, and cybersecurity measures.

2. AI Literacy Obligation (Article 4)

All providers and deployers of AI systems must ensure their staff have sufficient AI literacy relevant to their role. The Omnibus softened the substance of this requirement somewhat, but the underlying obligation to train your teams appropriately remains.

3. Governance and Penalty Framework

National market surveillance authorities and notified bodies should have been designated by Member States. The penalty framework is active: up to EUR 35 million or 7% of global annual turnover for prohibited AI violations, and up to EUR 15 million or 3% for other violations.

August 2, 2026: Article 50 Transparency — the Real Near-Term Deadline

This is the deadline still on schedule that most builders of chatbots, content-generation tools, and AI agents actually need to hit. Article 50 requires:

  • Disclosure to users that they are interacting with an AI system (chatbots, virtual assistants), unless it's obvious from context.
  • Labelling of AI-generated or manipulated image, audio, video, or text content as artificially generated or manipulated — machine-readable marking (e.g. watermarking) is required under Article 50(2), with a 4-month grace period to December 2, 2026 for systems already on the market before August 2, 2026.
  • Disclosure when AI is used to generate deepfakes or AI-generated text published to inform the public on matters of public interest.
  • Disclosure to natural persons exposed to an emotion recognition system or biometric categorisation system.
Article 50 is easy to overlook because it doesn't require the heavy conformity-assessment machinery that Annex III high-risk systems do. But it applies far more broadly — to essentially any product with a chatbot or generative AI feature — and it is not deferred. If your team deprioritised AI Act work because "the deadline moved to 2027," check whether Article 50 applies to you first.

December 2, 2027: Annex III High-Risk Systems (Deferred from Aug 2, 2026)

This is now the main deadline for stand-alone high-risk AI systems under Annex III — recruitment and HR tools, credit scoring, law enforcement risk assessment, education/exam scoring, migration and border control systems, and similar categories. The Digital Omnibus pushed this back from August 2, 2026 by roughly sixteen months.

What “fully comply” means for Annex III high-risk systems has not changed in substance, only in timing:

  • Risk management system documented and operational (Article 9).
  • Data governance controls in place for training, validation, and test data (Article 10).
  • Technical documentation completed per Annex IV (Article 11).
  • Automatic logging of system operations (Article 12).
  • Transparency documentation for deployers and users (Article 13).
  • Human oversight mechanisms implemented in the system design (Article 14).
  • Accuracy, robustness, and cybersecurity validation completed (Article 15).
  • Conformity assessment completed (self-assessment under Article 43 for most Annex III categories; third-party notified body for biometrics and critical infrastructure in some circumstances).
  • Registered in the EU AI systems database before deployment (Article 71).
The extra runway is useful, but treat December 2027 as a hard cutoff, not a planning horizon. Retrofitting risk management, logging, and human oversight into a system that's already shipping is significantly harder than building it in from the start.

August 2, 2028: Annex I Products (Deferred from Aug 2, 2027)

This deadline covers Annex I high-risk AI systems — those embedded in regulated products that already require CE marking (medical devices, machinery, vehicles, toys, and similar categories). The Omnibus pushed this from August 2, 2027 to August 2, 2028, preserving the original one-year gap behind the Annex III deadline.

A Note on GPAI Model Deployers

If you use a GPAI model (Claude, GPT, Gemini, Llama, etc.) as the underlying engine of your product, you are both a deployer of the GPAI model and the provider of the AI application built on top of it. These are two separate roles with separate obligations, and this split was not changed by the Omnibus:

  • The GPAI model provider (Anthropic, OpenAI, Google, Meta) handles Chapter V obligations for the model itself — already in force since August 2025.
  • You, as the application provider, handle the obligations for the AI system you build with that model.
  • If your application triggers Article 50 transparency, that applies from August 2026 regardless of your Annex III status.
  • If your application is high-risk under Annex III, you now have until December 2, 2027 to comply with Articles 8 through 15 — even if the underlying GPAI model is fully compliant.

Planning Backwards: What You Need to Do and When

Timeframe Work to complete
Now (if not done) Complete an EU AI Act gap assessment. Classify all AI systems in your portfolio: prohibited, Article 50-triggering, Annex III high-risk, Annex I high-risk, or none of the above. Don't assume the Omnibus moved your deadline — check which bucket you're actually in.
Before Aug 2, 2026 If you have any chatbot, AI agent, or generative content feature: implement Article 50 disclosure and prepare for the Dec 2, 2026 watermarking grace-period cutoff.
By Dec 2, 2026 Complete Article 50(2) machine-readable watermarking for any AI-generated content systems already on the market before Aug 2026. Complete transition away from any newly-prohibited non-consensual imagery generation capability.
Through 2026–2027 For Annex III high-risk systems: technical documentation (Annex IV), risk management framework, human oversight design, conformity assessment, EU AI database registration — all due before Dec 2, 2027.
By Dec 2, 2027 All Annex III high-risk systems must be fully compliant before deployment or continued operation.
By Aug 2, 2028 Annex I high-risk AI embedded in CE-marked regulated products must be fully compliant.

Quick Reference: Dates at a Glance (Revised 2026-07-23)

Date Key obligation Status
Feb 2, 2025 Prohibited AI (Article 5) — including new CSAM/non-consensual imagery ban In force (new prohibition category has transition to Dec 2, 2026)
Aug 2, 2025 GPAI obligations, AI literacy, governance framework In force
Aug 2, 2026 Article 50 transparency obligations (chatbot disclosure, AI-content labelling) On schedule — NOT deferred
Dec 2, 2026 Article 50(2) watermarking grace period ends; new prohibition transition ends On schedule
Dec 2, 2027 Annex III stand-alone high-risk systems must comply DEFERRED from Aug 2, 2026
Aug 2, 2028 Annex I high-risk AI in regulated products must comply DEFERRED from Aug 2, 2027