European Union
EU AI Act Full Implementation Timeline: What's Live, What's Next
The 'August 2, 2026' date most compliance calendars still have circled isn't the real one anymore — here's the corrected timeline after the Digital Omnibus, and exactly what applies to your systems today.
If your compliance calendar still has "EU AI Act high-risk obligations — August 2, 2026" circled as the date everything gets real, cross it out. That date came and went as a transparency-and-governance milestone, not the high-risk one — the deadline most teams have been building toward moved twice this summer, and it moved later, not sooner. The EU AI Act is still on the same phased-implementation structure it launched with in 2024, but the schedule inside that structure changed on July 27, 2026, when the Digital Omnibus on AI entered into force and rewrote Article 113. This page is the corrected version: what's actually live today, what's still ahead, and why the dates moved.
The misconception: "August 2026" is no longer the real high-risk deadline
Almost every EU AI Act explainer written before mid-2026 — including plenty still circulating — says high-risk system obligations apply from August 2, 2026. That was true when Regulation (EU) 2024/1689 was adopted. It stopped being true on July 27, 2026, when Regulation (EU) 2026/1744 — the Digital Omnibus on AI — entered into force and amended Article 113 directly. The new dates: December 2, 2027 for standalone high-risk systems under Annex III, and August 2, 2028 for high-risk systems embedded in products already covered by other EU product-safety law. Everything else in the Act's original schedule — the parts already in force before the Omnibus — stayed exactly where it was. The rest of this page walks the full corrected timeline in order.
What's already in force
Two applicability dates from the original 2024 schedule predate the Omnibus and weren't touched by it. Both are worth stating plainly, because they're easy to lose track of amid the high-risk delay headlines.
February 2, 2025 — Chapter I (general provisions and definitions) and Chapter II, which is Article 5's list of prohibited AI practices, became applicable six months after the regulation's August 1, 2024 entry into force. Social scoring, untargeted facial-recognition scraping, manipulative dark-pattern AI, and the rest of the eight banned categories have been enforceable for over a year and a half at this point — this is the part of the Act with the longest track record, not the newest.
August 2, 2025 — Twelve months after entry into force, three more pieces switched on together: the obligations for providers of general-purpose AI models (Chapter V), the governance framework (Chapter VII — member states had to designate their national market surveillance authorities, and the EU AI Office became operational), and the penalty structure itself under Chapter XII. If your organization builds or fine-tunes a general-purpose model, or if you've been dealing with a national AI regulator for the first time, that's the date this all started.
August 2, 2026: what actually applies on the original "go-live" date
This is the date the Omnibus left mostly intact — and it's the one people most often assume was pushed back along with everything else. It wasn't, for the most part.
Article 50's transparency and AI-content-disclosure duties became fully applicable on August 2, 2026, on schedule. That covers telling people they're interacting with an AI system, labeling AI-generated audio/image/video/text as synthetic, disclosing emotion-recognition and biometric-categorization use, and flagging deepfakes and AI-generated text on matters of public interest. None of that moved. The AI Office also picked up its full enforcement powers over general-purpose AI model providers on this date, a year after those providers' underlying obligations first applied.
There's one narrow, genuinely Omnibus-driven exception inside Article 50, and it's worth knowing precisely because it's easy to over- or under-read: the machine-readable-marking requirement in Article 50(2) — the part that requires AI-generated content to carry a detectable, machine-readable marker, not just a human-facing disclosure — got a four-month grace period for systems already on the market before August 2, 2026. Those systems have until December 2, 2026 to retrofit machine-readable marking. A generative AI system placed on the market from August 2, 2026 onward doesn't get that grace period; it has to comply from day one. And the disclosure duties themselves — telling a person they're talking to an AI, labeling synthetic content as AI-generated in a human-readable way — never had a grace period at all.
The Digital Omnibus: why the high-risk deadline moved, and to when
The instrument that changed everything is Regulation (EU) 2026/1744, referred to informally as the Digital Omnibus on AI. It was published in the Official Journal on July 24, 2026 and entered into force on July 27, 2026 — six days before the original high-risk deadline would have hit. That timing wasn't an accident; it was the outcome of a trilogue negotiation between Parliament, the Council, and the Commission that ran through the spring of 2026, driven by concerns — raised by industry groups and echoed by several member states — that the harmonized technical standards and notified-body capacity that high-risk conformity assessment depends on weren't going to be ready in time. Rather than let providers comply against standards that didn't yet exist in final form, the institutions agreed to move the deadline instead of the substance.
The amended Article 113 now reads: standalone high-risk systems under Annex III — the list covering biometric identification, employment and worker management, education and vocational training, access to essential services and credit, critical infrastructure, migration and border control, law enforcement, and administration of justice — have until December 2, 2027. High-risk systems that are safety components of, or are themselves, products already regulated under other EU product-safety law under Article 6(1) — think a diagnostic feature embedded in a medical device, or a safety-critical AI component in industrial machinery — have until August 2, 2028, a full year later than the Annex III systems, mirroring the year-long gap that existed between those two dates in the original 2024 schedule.
The same Omnibus made two other changes that took effect immediately on July 27, 2026, independent of any phased date. It added a new prohibited practice to Article 5, banning AI systems used to generate child sexual abuse material or non-consensual intimate imagery — closing a gap the original 2024 text hadn't anticipated. And it softened the AI-literacy obligation in Article 4, which previously required providers and deployers to "ensure" a sufficient level of AI literacy among staff, to a requirement to "support the development of" AI literacy instead — a real change in the legal standard, not a wording tweak.
Worked example: mapping one company's stack onto the current timeline
Picture Aldergrove HR, a mid-size HR software vendor selling into the EU, running three distinct AI-touching pieces of its product. First, a resume-screening and candidate-ranking tool — squarely inside Annex III's employment category, so it's a standalone high-risk system. Under the pre-Omnibus schedule, Aldergrove would have needed full Article 9-15 compliance — risk management, data governance, technical documentation, logging, human oversight — locked down by August 2, 2026. Under the current schedule, that deadline is now December 2, 2027, more than a year further out.
Second, an AI chatbot embedded in the product that answers candidate questions during the application process. That's covered by Article 50, not the high-risk chapter, so the disclosure obligation — telling candidates they're talking to an AI system — has applied since August 2, 2026, on the original schedule, unaffected by the Omnibus. If the chatbot generates any synthetic audio or video content, the machine-readable-marking piece of that obligation follows whichever grace period applies based on when the feature first went to market.
Third, Aldergrove licenses a general-purpose AI model from a third-party provider to power a resume-summarization feature. Aldergrove itself isn't a GPAI provider, so Article 51-56's model-level obligations sit with its vendor, not with Aldergrove directly — but that vendor has been subject to those obligations since August 2, 2025, a full year before the transparency date and well over two years before Aldergrove's own high-risk deadline.
The practical read for a company in Aldergrove's position: the high-risk deadline moved, but the disclosure obligations and the underlying vendor's model-level obligations didn't, and the extra runway on the high-risk system doesn't mean the risk-tiering and technical-documentation work should stop — see the high-risk classification guide for what that work actually involves.
What "deferred, not cancelled" actually means for your compliance program
The single most important framing for the extended deadlines is that they're a scheduling change, not a substantive one. Article 9 risk management, Article 10 data governance, Article 11 technical documentation, Article 12 logging, and the rest of the high-risk obligations are unchanged in content — only the date they become mandatory moved. Standards bodies, notified bodies, and the Commission are using the extra time for exactly the readiness gap that triggered the delay in the first place, which means the conformity-assessment infrastructure a high-risk provider will eventually need is still being built out, not settled and waiting. Treating December 2027 as "plenty of time to start later" risks running into the same capacity crunch that caused this delay to begin with, just closer to the new date instead of the old one.
This page will be updated in place if the schedule changes again — that's the standard practice for every evergreen reference page in this cluster, rather than a separate news post restating the same dates. For now, the state of play is: prohibited practices and the governance/GPAI/penalty framework have been live for over a year, Article 50 transparency duties are live as of this August, and the high-risk deadline that used to anchor most compliance roadmaps now sits at December 2, 2027 and August 2, 2028, not August 2, 2026.
Frequently asked questions
- Is it true the EU AI Act's high-risk AI rules were delayed?
- Yes. The Digital Omnibus on AI — Regulation (EU) 2026/1744, in force since July 27, 2026 — moved the original August 2, 2026 deadline for standalone high-risk Annex III systems to December 2, 2027, and the August 2, 2027 deadline for high-risk systems embedded in Annex I product-safety-regulated products to August 2, 2028. It's a rescheduling of Article 113, not a repeal of the underlying obligations — the risk-tiering, technical documentation, and conformity-assessment requirements still apply, just against a later hard deadline.
- Does the delay mean the EU AI Act's prohibited practices and GPAI rules are also postponed?
- No. Article 5 prohibited practices have been in force since February 2, 2025, and general-purpose AI model obligations, plus the governance and penalty framework, have been in force since August 2, 2025. The Digital Omnibus only touched the high-risk-system deadlines and a small number of other specific provisions — everything already live before July 2026 stayed live.
- What EU AI Act obligations are actually in force right now?
- Article 5 prohibited practices (since Feb 2025), GPAI model provider obligations and the governance/enforcement framework — national authorities, the AI Office, the Article 99/100/101 penalty structure — (since Aug 2025), and, as of August 2, 2026, Article 50 transparency and AI-content-disclosure duties. There's one narrow carve-out inside that last item: generative AI systems already on the market before August 2, 2026 get until December 2, 2026 to meet the machine-readable-marking part of Article 50 specifically.
- When do high-risk AI system obligations actually apply now?
- December 2, 2027 for standalone high-risk systems under Annex III — the list that covers biometrics, employment, education, credit scoring, critical infrastructure, and similar use cases. August 2, 2028 for AI systems that are safety components of, or are themselves, products already regulated under other EU product-safety law, such as medical devices, machinery, or toys with embedded AI functionality.
- Why did the EU delay the AI Act's high-risk deadlines instead of just letting them apply on schedule?
- The Digital Omnibus process responded to concerns raised during 2025-2026 negotiations — by industry groups and some member states — that the harmonized technical standards, notified-body capacity, and conformity-assessment infrastructure that high-risk systems are supposed to be tested against wouldn't actually be finished in time for the original date. The trilogue compromise pushed the deadline out rather than leaving providers to comply against standards that didn't yet exist in final form.
Sources & references
Suggested next reading
regulations eu
The EU AI Act
regulations eu
EU AI Act Penalties: The Full Tiered Structure
regulations eu
The EU AI Office: What It Does and Why It Matters to You
regulatory checklists
EU AI Act High-Risk Classification Checklist
regulations