The EU AI Act does not switch on all at once, it phases in over years, and the 2026 Digital Omnibus, now adopted by both the European Parliament and the Council of the EU, has pushed the heaviest obligations further out. Here is every key date in one place, with the adopted changes clearly flagged.
Dates marked Adopted (Omnibus) come from the Digital Omnibus on AI, now Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026. They are settled law rather than a planning assumption: standalone Annex III high-risk obligations apply from 2 December 2027, and Annex I embedded-product obligations from 2 August 2028.
The Article 5 bans on unacceptable-risk AI, such as social scoring and untargeted scraping of facial images, apply, along with the Article 4 duty to ensure staff have sufficient AI literacy.
Obligations for general-purpose AI (GPAI) model providers begin, alongside the governance architecture (the AI Office and national authorities) and the penalty regime, up to €35m or 7% of worldwide turnover for prohibited practices.
The Article 50 transparency duties begin to apply, telling people when they are interacting with AI, and marking AI-generated or manipulated content.
Under the adopted Digital Omnibus, the narrower Article 50(2) duty to embed a machine-readable marker in AI-generated content gets a four-month grace period for systems already on the market before 2 August 2026. The broader Article 50 duty to disclose AI interaction, above, is unaffected. A new Article 5 prohibition also takes effect on AI used to generate child sexual abuse material and non-consensual intimate imagery.
Obligations for Annex III high-risk systems, areas like employment, creditworthiness, essential services, and biometric uses, now apply. The Digital Omnibus defers this from the original 2 August 2026.
Obligations for high-risk AI embedded in regulated products (Annex I, for example machinery, medical devices, vehicles) apply, deferred from 2 August 2027 under the Digital Omnibus.
Defers the high-risk obligations: Annex III to 2 December 2027 and Annex I to 2 August 2028, giving standards bodies and businesses more time.
Adds a new Article 5 prohibition on AI used to generate child sexual abuse material and non-consensual intimate imagery.
Tightens content-marking timing, with pre-existing systems expected to comply by 2 December 2026.
Extends some relief to small mid-cap companies, not just SMEs, and reinforces the AI Office’s oversight of GPAI-based systems.
Wondering which obligations fall on you? Your duties depend on whether you are a provider, deployer, importer, or distributor, work it out with our EU AI Act roles guide, or start with what the EU AI Act is.
Partly. The core dates that have already passed, prohibited practices (February 2025), GPAI and governance (August 2025), remain in force. What the Digital Omnibus defers is the most burdensome layer: the high-risk obligations. Under the now-adopted Digital Omnibus, Annex III high-risk obligations move to 2 December 2027 and Annex I to 2 August 2028.
Yes. The European Parliament voted 423 to 57 in favour on 16 June 2026, the Council of the EU gave its final approval on 29 June 2026, and the final act was signed on 8 July 2026. It was published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744 and entered into force on 27 July 2026, so the deferred dates are settled law.
Yes, it can. The EU AI Act has extraterritorial reach: it can apply to providers and deployers outside the EU where the AI system is placed on the EU market or its output is used in the EU. Which obligations you carry depends on your role, see our guide to the EU AI Act roles.
Broadly, two groups: AI used in the sensitive areas listed in Annex III (such as employment, credit, education, essential services, and certain biometric and law-enforcement uses), and AI that is a safety component of, or itself, a product regulated under Annex I (such as medical devices or machinery). High-risk systems carry the heaviest obligations.
Confirm whether the Act applies to you and in what role; inventory your AI systems and classify them by risk tier; meet the prohibitions, AI-literacy, GPAI, and transparency duties already in force; and use the deferred high-risk timeline as runway to build conformity processes rather than as a reason to wait.
The extra time on high-risk obligations is best spent building conformity processes now. Knowing your role and your inventory is the first step.
This page is general information, not legal advice. The EU AI Act timeline is subject to change, and the Digital Omnibus was published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744 and entered into force on 27 July 2026, so always confirm the current position against the Official Journal and the European Commission’s own publications before relying on a date.