Governance

EU AI Act Timeline: Every Deadline (2026 Update)

EU AI Act timeline from February 2025 to August 2028 showing which deadlines already apply and which moved under the Digital Omnibus

Last updated 6 October 2026

The Digital Omnibus on AI (Regulation (EU) 2026/1744) was published on 24 July 2026 and entered into force on 27 July 2026. It moved the high-risk deadlines to 2 December 2027 and 2 August 2028. Everything below reflects the amended Act.

The EU AI Act now has fixed dates for every obligation, and several of them have already passed. Some people read the Omnibus delay as "the Act has been postponed". That is only true for one part of it. The bans, the AI literacy duty, the rules for general-purpose AI models and the transparency obligations in Article 50 all apply today.

This page lists every deadline, tells you which ones apply to you, and then covers the question that usually follows: what do we actually do about it? If you were hoping the answer is an AI governance policy template, the second half explains why it is not, and what to do instead.

The EU AI Act Timeline at a Glance

Shaded rows are the dates that moved or are still ahead of us.

DateWhat appliesStatus
1 Aug 2024The Act enters into force.Done
2 Feb 2025Prohibited AI practices (Article 5) and the AI literacy duty (Article 4).Applies
2 Aug 2025Obligations for providers of general-purpose AI (GPAI) models, the governance structure, and the penalty regime.Applies
27 Jul 2026Digital Omnibus (Regulation (EU) 2026/1744) enters into force and amends the Act.Done
2 Aug 2026General application date. Article 50 transparency duties (chatbot disclosure, deepfake and AI-text labelling, machine-readable marking for new generative systems) and the AI Office's enforcement powers over GPAI providers, including fines.Applies
2 Dec 2026Machine-readable marking (Article 50(2)) for generative AI systems that were already on the market before 2 Aug 2026. Two new prohibitions also start: AI that generates non-consensual intimate imagery and AI that generates child sexual abuse material.Upcoming
2 Aug 2027Member States must have national AI regulatory sandboxes (moved from 2026). GPAI models placed on the market before 2 Aug 2025 must be brought into compliance.Upcoming
2 Dec 2027High-risk requirements for stand-alone systems listed in Annex III (hiring, credit scoring, education, biometrics, critical infrastructure, law enforcement and similar). Moved from 2 Aug 2026.Delayed
2 Aug 2028High-risk requirements for AI that is a safety component of a product under EU product legislation, such as medical devices. Moved from 2 Aug 2027.Delayed

Penalty ceilings did not change: up to €35 million or 7% of worldwide turnover for prohibited practices, €15 million or 3% for most other breaches, and €7.5 million or 1% for supplying incorrect information. We cover how enforcement works in EU AI Act Penalties and How to Avoid Paying.

Dates come from Regulation (EU) 2024/1689 as amended. Check them against EUR-Lex and the Commission's AI Act page before you rely on them. This is general information, not legal advice.

What the Digital Omnibus Changed (and What It Did Not)

The Omnibus replaced a floating trigger, where the high-risk rules would apply some months after supporting standards were ready, with fixed calendar dates. Law firm summaries from Orrick and Gibson Dunn agree on the main points.

What changed

  • High-risk deadlines: 2 December 2027 for Annex III and 2 August 2028 for Annex I products.
  • AI literacy (Article 4): the duty moved from "ensure" a sufficient level of AI literacy to "take measures to support" its development. No specific level is guaranteed, but the obligation is still there. See our Article 4 explainer for the duty in more detail.
  • New prohibitions: AI systems designed to produce non-consensual intimate imagery or child sexual abuse material, from 2 December 2026.
  • Small mid-caps: companies with fewer than 750 employees and turnover up to €150 million get simplified documentation and capped penalties, similar to the existing SME relief.
  • Centralised enforcement: the AI Office is now the sole supervisor for AI systems built on a GPAI model by the same provider, and for AI in very large online platforms and search engines.
  • Narrower "safety component": AI used only for convenience or optimisation no longer counts as a safety component.

What did not change

  • The scope of the Act, including its reach over non-EU companies whose AI output is used in the EU.
  • The list of high-risk use cases in Annex III.
  • The GPAI regime and the penalty ceilings.
  • Article 50. If you run a chatbot or publish AI-generated media, your obligations started on 2 August 2026. See How to Label AI-Generated Content in the EU.

Which Deadline Applies to You?

If you...Your date
Operate a chatbot, or publish AI-generated images, audio, video or public-interest text in the EUAlready applies (Article 50, since 2 Aug 2026)
Provide a generative AI system that was on the market before 2 Aug 20262 Dec 2026 for machine-readable marking
Provide a general-purpose AI modelAlready applies. Models placed on the market before 2 Aug 2025 have until 2 Aug 2027
Build or use AI for hiring, worker management, credit, insurance pricing, education, biometrics or similar Annex III uses2 Dec 2027
Embed AI as a safety component in a regulated product such as a medical device2 Aug 2028
Use any AI at work in the EUAlready applies: the bans and the AI literacy duty

Systems already on the market before a high-risk deadline are generally only caught if they are later substantially modified. That makes every significant change to a system a compliance event, so confirm the details for your own systems with counsel.

Delayed Does Not Mean Optional

December 2027 sounds far away. It is about fourteen months from this update. For a high-risk system, the Act expects a working risk management system, documented data governance, technical documentation, automatic logging, human oversight, a quality management system and post-market monitoring. Most organisations do not have those today, and they cannot be written in a weekend. They are built by running the process for long enough to produce evidence.

The organisations that treat the Omnibus as a reprieve will spend 2027 in a rush. The ones that treat it as extra preparation time will spend it on the work below.

Looking for an AI Governance Policy Template? Read This First

If you searched for an "AI governance policy template" or an "EU AI Act compliance checklist", you are in good company. They are some of the most searched phrases in this field, and we have published a list of free ones ourselves. They are a useful starting point for wording. They are not a route to compliance, and the reason is simple.

The AI Act does not regulate documents. It regulates what you do. A policy states an intention. An auditor, a customer's procurement team or a market surveillance authority will ask a different question: show me.

What the Act asks forWhat a template gives you
A risk management system that is run continuously for each high-risk system (Article 9)A paragraph saying you take risk seriously
Logs, technical documentation and records specific to your systems (Articles 11, 12, 72)Nothing, because the template does not know your systems
Human oversight by named people with the competence and authority to intervene (Article 14)A generic reference to "human oversight"
Correct classification of each system, and your role as provider or deployerA blank where you are meant to fill that in
Evidence that controls operate, are reviewed, and are improvedA signature block

There are three further problems with starting from a template.

  • It cannot classify your systems. Whether a tool is prohibited, high-risk, transparency-only or minimal risk depends on what it does in your business. No template knows that.
  • It cannot assign ownership. Compliance fails at the point where nobody owns a risk. A policy that says "the business shall ensure" has not named anyone.
  • It creates false comfort. A signed policy feels like progress, and it can delay the real work by months. A policy that does not match what people do is worse than none, because it becomes evidence against you.

Here is the more encouraging part. Implementing the Act is less daunting than the vendor marketing suggests. None of the steps below is conceptually hard. They are mostly a matter of ownership, clear records and a regular rhythm. The policy comes at the end, and it is short, because it only has to describe what you really do.

Implementing the EU AI Act in Seven Steps

1. Set up an AI registry

You cannot govern what you have not listed. An AI registry is an internal inventory of every AI system your organisation builds, buys or uses. A spreadsheet is enough to begin with. For each system record:

  • name, vendor and a named business owner,
  • purpose, the people affected, and the data it uses,
  • your role under the Act: provider, deployer, importer or distributor,
  • the risk class (see step 2), the date the classification was made, and who made it.

Include the AI that arrives inside other software, such as the assistant switched on in your HR platform, and the tools staff use without telling anyone. This is your internal registry. It is separate from the EU database where providers of high-risk systems must register later.

2. Classify every system and write down why

For each entry, ask in this order: is it prohibited (Article 5)? Is it high-risk (Annex III, or a safety component under Annex I)? Does Article 50 require transparency? Is it a general-purpose model? Otherwise it is minimal risk. Record the reasoning, especially where you decide a system that looks like an Annex III use is not high-risk. That decision has to be defensible later.

3. Name the owners

Assign one accountable executive for AI governance, an owner for each system, and a small cross-functional group (legal, security, data protection, the business) that meets on a schedule. Our post on three job roles every AI ethics team needs is a good starting point.

4. Build three lines of defence

This is the structure that turns ownership into assurance. It is explained in the next section, and it is the piece that most templates leave out.

5. Put the right controls on each risk tier

  • Prohibited: stop it, and record that you stopped it.
  • High-risk: risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness testing, and a quality management system. See our guide to building a QMS for the EU AI Act.
  • Transparency: disclosure and labelling, covered in our Article 50 guide.
  • All staff: an AI literacy programme matched to roles, with attendance records.

6. Bring vendors under the same roof

If you deploy someone else's high-risk AI, Article 26 gives you your own duties: use it according to the provider's instructions, assign competent human oversight, monitor it, and keep the logs you control for at least six months. Ask vendors for their documentation and conformity evidence before you buy, and write the obligations into contracts.

7. Create evidence, then write the policy

Run the process. Keep the registry current, record classification decisions, log incidents and near misses, review changes, and schedule an internal audit. After a few cycles you will have real records. Now write your AI governance policy, in two or three pages, describing what you do, who does it, and where the evidence lives. A framework such as ISO/IEC 42001 can give the whole thing a management-system shape that auditors and customers already recognise.

Three Lines of Defence for AI, Explained

The three lines of defence model comes from risk management in financial services. It works for AI because it separates doing the work, overseeing the work and independently checking the work.

LineWhoJob in AI governanceEvidence it produces
FirstProduct, engineering and business teams that own the AI systemOwn the risk. Classify the system, run the controls, test, log, monitor and report incidents.Registry entries, test results, logs, monitoring reports
SecondAI governance, risk, compliance, legal and data protectionSet the standards, advise, challenge first-line decisions and track exposure across the portfolio.Policy, risk appetite, review minutes, challenge records
ThirdInternal audit, or an independent external assessorCheck independently that the first two lines work as described, and report to the board.Audit reports and findings with follow-up

Smaller companies cannot staff three departments, and they do not need to. One person can act as the second line, provided they are not the person who built the system. The third line is where independence matters most, so a small organisation can reasonably buy it in as an external review. The point is that nobody signs off their own work.

A Work-Back Plan to December 2027

WhenFocus
Next 30 daysBuild the registry. Check nothing on it is prohibited. Confirm Article 50 duties are met for chatbots and AI-generated content. Name the accountable executive.
Days 30 to 90Classify every system and record the reasoning. Stand up the three lines of defence. Start AI literacy training. Add AI clauses to vendor contracts.
Q1 to Q2 2027Put controls on every likely high-risk system: risk management, data governance, documentation, logging and human oversight. Begin the quality management system.
Q3 2027Run an internal audit or independent assessment. Fix the gaps. Write the policy that describes what you now do.
Q4 2027Complete conformity assessment and EU database registration where required, ahead of 2 December 2027.

Where are you today?

Our free AI governance maturity assessment shows how your organisation compares on the practices above. If you want a second pair of eyes on your registry, risk classification or three lines of defence, see our AI governance services. Running AI agents? Try the agentic AI governance assessment.

Frequently Asked Questions

Has the EU AI Act been delayed?

Partly. The high-risk requirements moved to fixed dates: 2 December 2027 for Annex III systems and 2 August 2028 for AI embedded in regulated products. The prohibitions, the AI literacy duty, the GPAI rules and the Article 50 transparency obligations were not delayed.

When do the high-risk requirements apply?

Stand-alone high-risk systems in Annex III must comply from 2 December 2027. High-risk AI that is a safety component of a product under EU product legislation, such as a medical device, must comply from 2 August 2028.

Do I still have to label AI-generated content from August 2026?

Yes. Article 50 has applied since 2 August 2026. The only grace period is for providers of generative AI systems already on the market before that date, who have until 2 December 2026 to add machine-readable marking.

Is there an AI governance policy template that makes me compliant?

No. A template can help with wording, but compliance comes from the registry, classification, ownership, controls and evidence behind the policy. Build those first and write the policy last.

What are the fines under the EU AI Act?

Up to €35 million or 7% of worldwide annual turnover for prohibited practices, up to €15 million or 3% for most other obligations, and up to €7.5 million or 1% for supplying incorrect information. Reduced caps apply to SMEs, and the Omnibus extends capped penalties to small mid-caps.

This article is general information and not legal advice. We will keep it updated as the Commission publishes guidance and standards.

Read More