Regulatory reference
EU AI Act timeline
If your compliance plan says high-risk obligations applied on 2 August 2026, it is out of date. Regulation (EU) 2026/1744 — the Digital Omnibus on AI — entered into force on 27 July 2026 and postponed them. Stand-alone high-risk systems now apply from 2 December 2027; systems embedded in regulated products from 2 August 2028. A great deal of published material, including vendor timelines, still carries the old dates.
What changed, and how to check it yourself
The Council of the EU gave final approval on 29 June 2026. Its press release states the position plainly:
"the new application dates would be 2 December 2027 for stand-alone high-risk AI systems and 2 August 2028 for high-risk AI systems embedded in products"
The European Commission's own regulatory framework page now reads the same way — rules for systems used in high-risk areas "will apply from 2 December 2027", and for systems integrated into products such as lifts or toys "will apply from 2 August 2028" — and records that the omnibus amendments "entered into force on 27 July 2026".
Two independent primary sources, same dates. If you are checking this against something else, those are the two to check against.
One detail that matters more than it looks
The Commission's original November 2025 proposal tied the postponement to a condition — the availability of harmonised standards. The adopted text replaced that with fixed calendar dates.
That makes 2 December 2027 a harder date than the one it replaced. There is no standards-availability trigger to slip behind. Plans built on "it will probably move again" are betting against a deliberate legislative choice to stop it moving.
The corrected timeline
Dates still ahead, in order. Items marked ★ are the ones that bind ordinary companies rather than regulators or model providers.
| Date | What applies | Who it binds |
|---|---|---|
| 2 Dec 2026 | New prohibitions on AI generating non-consensual intimate imagery and CSAM | Providers and deployers, all AI systems |
| 2 Dec 2026 | Machine-readable marking of synthetic content, for systems already on the market before 2 Aug 2026 — a four-month transitional | Providers of generative systems |
| 2 Aug 2027 | General-purpose AI models placed on the market before 2 Aug 2025 must be in full compliance | Providers of legacy foundation models |
| 2 Aug 2027 | Member States must have at least one operational AI regulatory sandbox | Member States |
| ★ 2 Dec 2027 | Annex III stand-alone high-risk systems — biometrics, critical infrastructure, education, employment and HR, essential public and private services including credit and insurance, law enforcement, migration, justice. Includes Article 26 deployer obligations | Providers AND deployers |
| ★ 2 Aug 2028 | Annex I high-risk AI embedded in regulated products — machinery, medical devices, lifts, toys, vehicles | Providers and deployers |
| 2 Aug 2030 | High-risk AI used by public authorities, placed on market before the Chapter III dates, must be brought into compliance | Public sector |
Already in force — these did not move
2 February 2025: the Article 5 prohibitions, and the Article 4 AI literacy obligation. 2 August 2025: general-purpose AI model obligations. 2 August 2026: Article 50 transparency — which is the one that catches AI agents, covered in are AI agents regulated.
So 2 August 2026 was not a non-event. Transparency obligations did arrive. What did not arrive on that date was the high-risk regime, and that is the part most timelines get wrong.
Why so much published material is wrong
Worth understanding, because you will keep meeting the old dates.
The AI Act was adopted in 2024 with a staged timeline that had been stable for two years. An enormous amount of content — law firm alerts, vendor timelines, compliance checklists, conference slides — was written against it. The omnibus changed those dates in July 2026. Content written before then is not careless; it is simply older than the amendment.
Including, at the time of writing, some official material. The Commission's own AI Act Service Desk FAQ still described the Article 4 changes in proposal language — "the Digital Omnibus proposal recommends…" — after the regulation had been adopted and was in force. Official sources are not uniformly current either.
The practical test: anything that says high-risk obligations applied on 2 August 2026, or that Annex I products land on 2 August 2027, predates 27 July 2026. Check the publication date before you act on it.
What the extra time is actually for
Fourteen months is not a reprieve if the work takes fourteen months, and for deployers of Annex III systems it plausibly does.
The long pole is usually log retention. Article 26 requires deployers to retain automatically generated logs for at least six months. If your systems do not currently produce those logs, or produce them and discard them in thirty days, that is an engineering change with a procurement cycle in front of it — not a policy document.
Human oversight needs named people with authority. Not a policy stating that oversight exists. Identifying who, giving them competence and standing, and being able to show it, takes organisational work.
Worker notification has a lead time of its own. Employers must inform workers and their representatives before putting a high-risk system into service in the workplace. Where there is a works council, that is a consultation, not an email.
And classification comes first. You cannot scope any of it until you know which of your systems are Annex III high-risk. The Commission's Article 6 classification guidelines are themselves due by 2 August 2027 — four months before the obligations bite. Waiting for them leaves one quarter.
Common questions about EU AI Act timeline
Did the EU AI Act get delayed?
Parts of it. Regulation (EU) 2026/1744, in force 27 July 2026, postponed the high-risk obligations: stand-alone Annex III systems moved from 2 August 2026 to 2 December 2027, and embedded Annex I systems from 2 August 2027 to 2 August 2028. The prohibitions, the AI literacy obligation, the general-purpose AI model rules and the Article 50 transparency obligations were not postponed and are already in force.
Could 2 December 2027 move again?
Nothing is impossible in EU law, but this date is harder than the one it replaced. The Commission's original proposal made the postponement conditional on harmonised standards being available; the adopted text deliberately replaced that with a fixed calendar date. There is no built-in slippage mechanism, and no credible source currently suggests further postponement.
What happened on 2 August 2026 then?
Article 50 transparency obligations took effect, along with penalties for general-purpose AI providers. The transparency rules are why AI systems interacting with people generally have to disclose that they are AI. What did not take effect was the high-risk regime.
Does the delay apply to the prohibitions too?
No. The Article 5 prohibitions have applied since 2 February 2025 and were not postponed. The omnibus actually added prohibitions — on AI generating non-consensual intimate imagery and CSAM — which bite from 2 December 2026.
We are a deployer, not a provider. Does any of this reach us?
Yes, and this is the most commonly missed point. Article 26 binds deployers — the organisations using a high-risk system — not just the vendors that build them. Its obligations apply from the same 2 December 2027 date. If you use AI in recruitment, credit decisions, insurance pricing or education, that is the article to read.