Every date in Regulation (EU) 2024/1689, as amended by the Digital Omnibus. What applies today, what is next, and what moved.
Status: current as of 25 August 2026. The high-risk deadlines changed in July 2026. If a timeline still shows 2 August 2026 for Annex III high-risk systems, it predates the amendment.
What applies today #
The following obligations are in force right now and are being enforced:
| In force since | What |
|---|---|
| 2 February 2025 | Prohibited practices (Art. 5) and AI literacy (Art. 4) |
| 2 August 2025 | GPAI obligations (Ch. V), governance, notified bodies, penalties, confidentiality |
| 27 July 2026 | Sectoral amendments (Arts. 102 to 110) |
| 2 August 2026 | Transparency obligations (Art. 50), and GPAI fines under Art. 101 |
The next deadline is 2 December 2026. Two things bite on that date, and both hit generative AI:
- Two new prohibitions enter Article 5: AI that generates or manipulates non-consensual intimate imagery of an identifiable person, and AI that generates or manipulates child sexual abuse material.
- The transitional period ends for Article 50(2) watermarking. Providers whose synthetic content systems were already on the market before 2 August 2026 must have machine-readable marking in place.
What changed in July 2026 #
The Digital Omnibus on AI was adopted as Regulation (EU) 2026/1744 of 8 July 2026, published in the Official Journal on 24 July 2026 and in force since 27 July 2026, six days before the deadline it defers.
Two points matter for planning. First, the deferral is unconditional. The Commission’s November 2025 proposal would have tied application to the readiness of harmonised standards, with a long-stop backstop. The co-legislators dropped that and fixed calendar dates instead, so there is no trigger to monitor. Second, it is a deferral, not a repeal. Nothing was removed from the high-risk regime.
| Obligation | Was | Now |
|---|---|---|
| Annex III stand-alone high-risk (Art. 6(2)) | 2 August 2026 | 2 December 2027 |
| Annex I product-embedded high-risk (Art. 6(1)) | 2 August 2027 | 2 August 2028 |
| Art. 50(2) watermarking, systems already on the market | 2 August 2026 | 2 December 2026 |
| New Art. 5 prohibitions on NCII and CSAM | did not exist | 2 December 2026 |
| Member State AI regulatory sandboxes (Art. 57) | 2 August 2026 | 2 August 2027 |
| Sectoral amendments (Arts. 102 to 110) | staggered | 27 July 2026 |
Article 4 on AI literacy was also softened, from an obligation to ensure a sufficient level of AI literacy to an obligation to take measures to support its development. The date did not move and the duty still applies.
Why the dates moved #
The regulation’s own recitals record the reason: the delayed availability of standards, common specifications and guidance, and the delayed establishment of national competent authorities.
In practice, three things were not ready. The CEN-CENELEC harmonised standards, originally due April 2025, are now targeted for the fourth quarter of 2026, and none had been cited in the Official Journal as of June 2026. The Commission missed its own 2 February 2026 deadline for the Article 6(5) high-risk classification guidelines, publishing a draft on 19 May 2026. And Member State authority designations were far behind: as of March 2026, eight single contact points had been notified out of 27.
This matters for how you read the new dates. They were set by what infrastructure exists, not by what is comfortable, so a further slip is conceivable if the standards continue to lag.
The full timeline #
| Date | What applies | Legal basis | Who it binds |
|---|---|---|---|
| 1 August 2024 | Entry into force | Art. 113 | All |
| 2 February 2025 | Prohibited practices; general provisions; AI literacy | Chs. I and II, Arts. 4 and 5 | All providers and deployers |
| 2 August 2025 | GPAI obligations; governance; notified bodies; penalties; confidentiality; national authority designation | Chs. V, VII, III§4, XII, Arts. 70 and 78 | GPAI providers, Member States |
| 27 July 2026 | Sectoral amendments | Arts. 102 to 110 | Sector-regulated providers |
| 2 August 2026 | Transparency obligations; GPAI fines | Arts. 50 and 101 | Providers and deployers of chatbots, generative and biometric systems |
| 2 December 2026 | New prohibitions on NCII and CSAM generation; end of the watermarking transitional period | Art. 5(1)(ba) and (bb); Art. 111(4) | Providers and deployers of generative AI |
| 2 August 2027 | Member State sandboxes operational; legacy GPAI models brought into compliance | Arts. 57 and 111(3) | Member States; GPAI providers with pre-August-2025 models |
| 2 December 2027 | Annex III stand-alone high-risk obligations, including the fundamental rights impact assessment | Art. 6(2); Ch. III §§1 to 3 | Providers, deployers, importers and distributors of Annex III systems |
| 2 August 2028 | Annex I product-embedded high-risk obligations; Machinery delegated acts | Art. 6(1); Ch. III §§1 to 3 | Providers of AI embedded in regulated products |
| 2 August 2029 | General evaluation and review report, then every four years | Art. 112(3) | Commission |
| 2 August 2030 | Legacy high-risk AI used by public authorities | Art. 111(2) | Public-authority providers and deployers |
| 31 December 2030 | Legacy Annex X large-scale IT systems | Art. 111(1) | Operators of Annex X systems |
What did not move #
This is where most planning goes wrong. The amendment was narrow, and the following are unchanged:
- Article 5 prohibitions, in force since February 2025. Banned practices are banned now.
- AI literacy, in force since February 2025, softened in wording only.
- Chapter V GPAI obligations, in force since August 2025, with fines live since August 2026.
- Article 50 transparency, applicable from 2 August 2026. Only the watermarking of pre-existing systems got a transitional period.
- The registration duty for Annex III systems self-assessed as non-high-risk under Article 6(3). The Commission proposed deleting it; both Council and Parliament refused. A self-assessment remains a public filing, not an internal memo.
- The strict necessity standard for processing special category data for bias detection. The proposed downgrade to “necessary” was rejected.
- The legacy dates of 2 August 2030 and 31 December 2030.
What this means by role #
| If you are | Do now | Next hard date |
|---|---|---|
| A deployer of an Annex III system | Inventory and classify. Nothing is enforceable against you yet, but the FRIA and the full obligation set arrive together | 2 December 2027 |
| A provider of a generative AI system | Article 50 disclosure applies today. Watermarking of pre-existing systems, and the new prohibitions | 2 December 2026 |
| A GPAI model provider | Nothing was deferred. Chapter V applies and fines are live | already applicable |
| A provider of AI embedded in a regulated product | Conformity work against the product regime, plus the Machinery reclassification | 2 August 2028 |
| Any organisation using AI professionally | AI literacy measures, and records of them | already applicable |
Legacy systems and grandfathering #
Article 111 preserves systems placed on the market before the relevant application date, but the protection is fragile. It operates at type or model level and holds only as long as the design remains unchanged. A significant change in design, which includes retraining, swapping the underlying foundation model or changing the intended purpose, forfeits it.
The Act does not define “significant change” quantitatively and no regulator has published a bright-line test, so the practical defence is evidential. Freeze a documented snapshot of each system before its application date and keep a timestamped change log.
Public authorities cannot rely on this at all. They face 2 August 2030 regardless.
What could still change #
The AI strand is settled law. The wider Digital Omnibus, which touches the GDPR, ePrivacy, the Data Act, NIS2 and DORA, is a separate file still in negotiation and is not adopted. Its proposals on legitimate interest for AI training and on cookie consent could still shift, and should be tracked separately.
The Article 6(5) high-risk classification guidelines remain in draft and are non-binding in any case. Only the Court of Justice can give an authoritative interpretation. For anything load-bearing, anchor to the consolidated text of Articles 111 and 113 on EUR-Lex, that is Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744.
Frequently asked questions #
When does the EU AI Act apply?
In stages. It entered into force on 1 August 2024. Prohibited practices and AI literacy applied from 2 February 2025, GPAI obligations from 2 August 2025, transparency obligations from 2 August 2026. High-risk obligations apply from 2 December 2027 for Annex III systems and 2 August 2028 for AI embedded in regulated products.
Has the EU AI Act been delayed?
Partly. Regulation (EU) 2026/1744, in force since 27 July 2026, deferred the high-risk obligations by 16 months for Annex III systems and 12 months for Annex I systems. No other obligation was deferred, and nothing was repealed.
What is the next EU AI Act deadline?
2 December 2026, when two new prohibitions on generating non-consensual intimate imagery and child sexual abuse material take effect, and the transitional period ends for watermarking synthetic content produced by systems already on the market.
Do the prohibitions still apply?
Yes. Article 5 has applied since 2 February 2025 and was extended, not delayed.
Does the delay mean we can stop work?
No. The deferral was granted because the supporting infrastructure was not ready, not because the obligations shrank. Classifying a portfolio and building conformity documentation is a multi-year programme, and the new dates assume it is already under way.