European Union

EU AI Act Full Implementation Timeline: What's Live, What's Next

The 'August 2, 2026' date most compliance calendars still have circled isn't the real one anymore — here's the corrected timeline after the Digital Omnibus, and exactly what applies to your systems today.

Phasing in — high-risk deadlines pushed to Dec 2027 / Aug 2028Effective August 1, 2024
European Union policy officials reviewing a phased regulatory implementation schedule
Photo: Zoshua Colah via Unsplash

If your compliance calendar still has "EU AI Act high-risk obligations — August 2, 2026" circled as the date everything gets real, cross it out. That date came and went as a transparency-and-governance milestone, not the high-risk one — the deadline most teams have been building toward moved twice this summer, and it moved later, not sooner. The EU AI Act is still on the same phased-implementation structure it launched with in 2024, but the schedule inside that structure changed on July 27, 2026, when the Digital Omnibus on AI entered into force and rewrote Article 113. This page is the corrected version: what's actually live today, what's still ahead, and why the dates moved.

The misconception: "August 2026" is no longer the real high-risk deadline

Almost every EU AI Act explainer written before mid-2026 — including plenty still circulating — says high-risk system obligations apply from August 2, 2026. That was true when Regulation (EU) 2024/1689 was adopted. It stopped being true on July 27, 2026, when Regulation (EU) 2026/1744 — the Digital Omnibus on AI — entered into force and amended Article 113 directly. The new dates: December 2, 2027 for standalone high-risk systems under Annex III, and August 2, 2028 for high-risk systems embedded in products already covered by other EU product-safety law. Everything else in the Act's original schedule — the parts already in force before the Omnibus — stayed exactly where it was. The rest of this page walks the full corrected timeline in order.

What's already in force

Two applicability dates from the original 2024 schedule predate the Omnibus and weren't touched by it. Both are worth stating plainly, because they're easy to lose track of amid the high-risk delay headlines.

February 2, 2025 — Chapter I (general provisions and definitions) and Chapter II, which is Article 5's list of prohibited AI practices, became applicable six months after the regulation's August 1, 2024 entry into force. Social scoring, untargeted facial-recognition scraping, manipulative dark-pattern AI, and the rest of the eight banned categories have been enforceable for over a year and a half at this point — this is the part of the Act with the longest track record, not the newest.

August 2, 2025 — Twelve months after entry into force, three more pieces switched on together: the obligations for providers of general-purpose AI models (Chapter V), the governance framework (Chapter VII — member states had to designate their national market surveillance authorities, and the EU AI Office became operational), and the penalty structure itself under Chapter XII. If your organization builds or fine-tunes a general-purpose model, or if you've been dealing with a national AI regulator for the first time, that's the date this all started.

August 2, 2026: what actually applies on the original "go-live" date

This is the date the Omnibus left mostly intact — and it's the one people most often assume was pushed back along with everything else. It wasn't, for the most part.

Article 50's transparency and AI-content-disclosure duties became fully applicable on August 2, 2026, on schedule. That covers telling people they're interacting with an AI system, labeling AI-generated audio/image/video/text as synthetic, disclosing emotion-recognition and biometric-categorization use, and flagging deepfakes and AI-generated text on matters of public interest. None of that moved. The AI Office also picked up its full enforcement powers over general-purpose AI model providers on this date, a year after those providers' underlying obligations first applied.

There's one narrow, genuinely Omnibus-driven exception inside Article 50, and it's worth knowing precisely because it's easy to over- or under-read: the machine-readable-marking requirement in Article 50(2) — the part that requires AI-generated content to carry a detectable, machine-readable marker, not just a human-facing disclosure — got a four-month grace period for systems already on the market before August 2, 2026. Those systems have until December 2, 2026 to retrofit machine-readable marking. A generative AI system placed on the market from August 2, 2026 onward doesn't get that grace period; it has to comply from day one. And the disclosure duties themselves — telling a person they're talking to an AI, labeling synthetic content as AI-generated in a human-readable way — never had a grace period at all.

The Digital Omnibus: why the high-risk deadline moved, and to when

The instrument that changed everything is Regulation (EU) 2026/1744, referred to informally as the Digital Omnibus on AI. It was published in the Official Journal on July 24, 2026 and entered into force on July 27, 2026 — six days before the original high-risk deadline would have hit. That timing wasn't an accident; it was the outcome of a trilogue negotiation between Parliament, the Council, and the Commission that ran through the spring of 2026, driven by concerns — raised by industry groups and echoed by several member states — that the harmonized technical standards and notified-body capacity that high-risk conformity assessment depends on weren't going to be ready in time. Rather than let providers comply against standards that didn't yet exist in final form, the institutions agreed to move the deadline instead of the substance.

The amended Article 113 now reads: standalone high-risk systems under Annex III — the list covering biometric identification, employment and worker management, education and vocational training, access to essential services and credit, critical infrastructure, migration and border control, law enforcement, and administration of justice — have until December 2, 2027. High-risk systems that are safety components of, or are themselves, products already regulated under other EU product-safety law under Article 6(1) — think a diagnostic feature embedded in a medical device, or a safety-critical AI component in industrial machinery — have until August 2, 2028, a full year later than the Annex III systems, mirroring the year-long gap that existed between those two dates in the original 2024 schedule.

The same Omnibus made two other changes that took effect immediately on July 27, 2026, independent of any phased date. It added a new prohibited practice to Article 5, banning AI systems used to generate child sexual abuse material or non-consensual intimate imagery — closing a gap the original 2024 text hadn't anticipated. And it softened the AI-literacy obligation in Article 4, which previously required providers and deployers to "ensure" a sufficient level of AI literacy among staff, to a requirement to "support the development of" AI literacy instead — a real change in the legal standard, not a wording tweak.

Worked example: mapping one company's stack onto the current timeline

Picture Aldergrove HR, a mid-size HR software vendor selling into the EU, running three distinct AI-touching pieces of its product. First, a resume-screening and candidate-ranking tool — squarely inside Annex III's employment category, so it's a standalone high-risk system. Under the pre-Omnibus schedule, Aldergrove would have needed full Article 9-15 compliance — risk management, data governance, technical documentation, logging, human oversight — locked down by August 2, 2026. Under the current schedule, that deadline is now December 2, 2027, more than a year further out.

Second, an AI chatbot embedded in the product that answers candidate questions during the application process. That's covered by Article 50, not the high-risk chapter, so the disclosure obligation — telling candidates they're talking to an AI system — has applied since August 2, 2026, on the original schedule, unaffected by the Omnibus. If the chatbot generates any synthetic audio or video content, the machine-readable-marking piece of that obligation follows whichever grace period applies based on when the feature first went to market.

Third, Aldergrove licenses a general-purpose AI model from a third-party provider to power a resume-summarization feature. Aldergrove itself isn't a GPAI provider, so Article 51-56's model-level obligations sit with its vendor, not with Aldergrove directly — but that vendor has been subject to those obligations since August 2, 2025, a full year before the transparency date and well over two years before Aldergrove's own high-risk deadline.

The practical read for a company in Aldergrove's position: the high-risk deadline moved, but the disclosure obligations and the underlying vendor's model-level obligations didn't, and the extra runway on the high-risk system doesn't mean the risk-tiering and technical-documentation work should stop — see the high-risk classification guide for what that work actually involves.

What "deferred, not cancelled" actually means for your compliance program

The single most important framing for the extended deadlines is that they're a scheduling change, not a substantive one. Article 9 risk management, Article 10 data governance, Article 11 technical documentation, Article 12 logging, and the rest of the high-risk obligations are unchanged in content — only the date they become mandatory moved. Standards bodies, notified bodies, and the Commission are using the extra time for exactly the readiness gap that triggered the delay in the first place, which means the conformity-assessment infrastructure a high-risk provider will eventually need is still being built out, not settled and waiting. Treating December 2027 as "plenty of time to start later" risks running into the same capacity crunch that caused this delay to begin with, just closer to the new date instead of the old one.

This page will be updated in place if the schedule changes again — that's the standard practice for every evergreen reference page in this cluster, rather than a separate news post restating the same dates. For now, the state of play is: prohibited practices and the governance/GPAI/penalty framework have been live for over a year, Article 50 transparency duties are live as of this August, and the high-risk deadline that used to anchor most compliance roadmaps now sits at December 2, 2027 and August 2, 2028, not August 2, 2026.

Frequently asked questions

Is it true the EU AI Act's high-risk AI rules were delayed?
Yes. The Digital Omnibus on AI — Regulation (EU) 2026/1744, in force since July 27, 2026 — moved the original August 2, 2026 deadline for standalone high-risk Annex III systems to December 2, 2027, and the August 2, 2027 deadline for high-risk systems embedded in Annex I product-safety-regulated products to August 2, 2028. It's a rescheduling of Article 113, not a repeal of the underlying obligations — the risk-tiering, technical documentation, and conformity-assessment requirements still apply, just against a later hard deadline.
Does the delay mean the EU AI Act's prohibited practices and GPAI rules are also postponed?
No. Article 5 prohibited practices have been in force since February 2, 2025, and general-purpose AI model obligations, plus the governance and penalty framework, have been in force since August 2, 2025. The Digital Omnibus only touched the high-risk-system deadlines and a small number of other specific provisions — everything already live before July 2026 stayed live.
What EU AI Act obligations are actually in force right now?
Article 5 prohibited practices (since Feb 2025), GPAI model provider obligations and the governance/enforcement framework — national authorities, the AI Office, the Article 99/100/101 penalty structure — (since Aug 2025), and, as of August 2, 2026, Article 50 transparency and AI-content-disclosure duties. There's one narrow carve-out inside that last item: generative AI systems already on the market before August 2, 2026 get until December 2, 2026 to meet the machine-readable-marking part of Article 50 specifically.
When do high-risk AI system obligations actually apply now?
December 2, 2027 for standalone high-risk systems under Annex III — the list that covers biometrics, employment, education, credit scoring, critical infrastructure, and similar use cases. August 2, 2028 for AI systems that are safety components of, or are themselves, products already regulated under other EU product-safety law, such as medical devices, machinery, or toys with embedded AI functionality.
Why did the EU delay the AI Act's high-risk deadlines instead of just letting them apply on schedule?
The Digital Omnibus process responded to concerns raised during 2025-2026 negotiations — by industry groups and some member states — that the harmonized technical standards, notified-body capacity, and conformity-assessment infrastructure that high-risk systems are supposed to be tested against wouldn't actually be finished in time for the original date. The trilogue compromise pushed the deadline out rather than leaving providers to comply against standards that didn't yet exist in final form.

Sources & references

  1. Official source
  2. Regulation (EU) 2024/1689, Article 113 — Entry into Force and Application (full text, EUR-Lex)
  3. Regulation (EU) 2024/1689 (full text, EUR-Lex) — consolidated entry point for the AI Act and its amendments, including the 2026 Digital Omnibus
European Union policy officials in discussion at a government building
Photo: Karson via Unsplash

regulations eu

The EU AI Act

The EU AI Act classifies AI systems into risk tiers and phases its obligations in on a multi-year schedule. Here's what's actually in force today, what's still phasing in, and how the risk tiers work.
Governome Editorial Team · 4 min read
Compliance team calculating potential EU AI Act fine exposure across the tiered penalty structure
Photo: Vitaly Gariev via Unsplash
EU AI Act fines aren't a single €35 million number. Article 99 defines three separate tiers by violation type, Article 101 sets a fourth track for general-purpose AI model providers enforced directly by the Commission, and Article 100 even reaches EU institutions themselves. Here's the full structure, including the SME inversion rule that changes real exposure by orders of magnitude.
Governome Editorial Team · 7 min read
European Commission officials at a policy meeting discussing AI regulation
Photo: Zoshua Colah via Unsplash
The EU AI Office is a European Commission body with real fining power — but only over one specific category of company: providers of general-purpose AI models. Everyone else's high-risk obligations are enforced by their national market surveillance authority instead. Here's the actual jurisdiction map, the fine amounts, and how the Office differs from the AI Board, the Advisory Forum, and the Scientific Panel.
Governome Editorial Team · 7 min read
Legal and compliance professionals reviewing which AI practices are prohibited under the EU AI Act
Photo: Leon Seibert via Unsplash
Article 5 of the EU AI Act prohibits eight specific AI practices — social scoring, manipulative and exploitative AI, untargeted facial-recognition scraping, workplace emotion inference, and more — with no compliance path around them. It's also been in force since February 2025, earlier than almost everything else in the Act.
Governome Editorial Team · 8 min read
Engineers reviewing automated system logs on server monitoring screens
Photo: Tyler via Unsplash
Article 12 requires high-risk AI systems to automatically log events built for three specific purposes — risk identification, post-market monitoring, and deployer oversight — plus an extra minimum spec for remote biometric identification systems. Generic application logs rarely satisfy all three by accident.
Governome Editorial Team · 5 min read
Compliance and legal professionals reviewing AI system documentation together
Photo: Sherwin Ker via Unsplash
Article 6 of the EU AI Act classifies a system as high-risk through a combination of Annex I product-safety overlap and Annex III use-case categories. Here's how the two-step test actually applies, with the exemption most teams get wrong.
Governome Editorial Team · 3 min read
Compliance reviewer working through a classification checklist at a desk
Photo: Zulfugar Karimov via Unsplash
Step through this checklist before concluding an AI system falls outside the EU AI Act's high-risk category. It mirrors the actual two-track Article 6 test, not a simplified summary of it.
Governome Editorial Team · 2 min read
An AI model trained on broad data at scale that can competently perform a wide range of distinct tasks and be integrated into many different downstream systems — the EU AI Act's term for foundation-model-scale AI, subject to its own separate obligations track rather than the risk-tier system that governs most AI systems.
Governome Editorial Team · 2 min read