The EU AI Act timeline as it stands in October 2026
The general application date has passed. The high-risk rules did not start with it. This is the calendar after this summer's amending regulation.
- Written by
- Frank Vitetta
- Published
- Last updated
- Subject
- Regulation
- Reading time
- 6 min read
In brief
- The AI Act's general application date, 2 August 2026, has passed. The prohibitions, the AI literacy duty, the general-purpose model rules and the Article 50 transparency rules are all in application.
- The high-risk regime did not start in August. Regulation (EU) 2026/1744, the Digital Omnibus on AI, has been in force since 27 July 2026. It moved the high-risk regime to 2 December 2027 for Annex III uses and 2 August 2028 for AI built into regulated products.
- The next date is 2 December 2026. Two new prohibitions begin. The transition also ends for marking synthetic content from generative systems that were already on the market.
- This is a postponement. The Act was not repealed and the obligations themselves are largely intact.
What is happening
The AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and applies in stages. That staging was rewritten this summer. The Commission proposed a simplification package, the Digital Omnibus on AI, on 19 November 2025. Parliament and Council reached a political agreement on 7 May 2026. According to the Parliament's legislative record, Parliament approved the final text on 16 June 2026 (423 votes in favour, 57 against, 174 abstentions). The Council adopted it on 29 June. It was published in the Official Journal on 24 July as Regulation (EU) 2026/1744. The Commission's AI Act page gives 27 July 2026 as the date it entered into force. That was six days before the high-risk rules would otherwise have started to apply.
The dates below follow the Commission's AI Act Service Desk timeline. They also follow its consolidated text of Article 113 (application dates) and Article 111 (systems already on the market).
Already in application
- 2 February 2025General provisions, including the AI literacy duty in Article 4. Also the original list of prohibited practices in Article 5.
- 2 August 2025Obligations for providers of general-purpose AI (GPAI) models. Member States had to designate authorities and set penalty rules. The EU-level governance bodies were established.
- 2 August 2026General application date. The Article 50 transparency rules start. The Commission's enforcement powers over GPAI model providers, including fines, begin (see the GPAI guidelines page).
Still to come
- 2 December 2026New prohibitions on AI systems that generate non-consensual intimate imagery of identifiable people or child sexual abuse material (new points in Article 5). Providers of generative systems placed on the market before 2 August 2026 must meet the Article 50(2) marking requirement by this date.
- 2 August 2027GPAI models placed on the market before 2 August 2025 must comply. Each Member State should have at least one AI regulatory sandbox operating.
- 2 December 2027Rules for high-risk systems listed in Annex III. The Parliament's summary of the deal lists biometrics, critical infrastructure, education, employment, law enforcement and border management among the areas covered.
- 2 August 2028Rules for high-risk AI embedded in products covered by the EU product legislation listed in Annex I.
- 2 August 2030High-risk systems intended for use by public authorities that were already on the market must be brought into compliance.
- 31 December 2030Components of the large-scale EU IT systems listed in Annex X, where placed on the market before 2 August 2027.
What Article 50 asks for now
The consolidated Article 50 splits duties between providers and deployers. Providers of systems that interact directly with people must make sure those people are told they are dealing with AI, unless that is obvious. Providers of generative systems must mark synthetic audio, image, video and text output in a machine-readable way. Deployers must tell people when they are exposed to emotion recognition or biometric categorisation. They must disclose deepfakes. They must also disclose AI-generated text published to inform the public on matters of public interest.
A voluntary Code of Practice on marking and labelling AI-generated content was finalised on 10 June 2026. The Commission reports roughly 190 signatories as of 31 July 2026. Draft Commission guidelines on Article 50 were published for consultation on 8 May 2026.
What else the amending regulation changed
- Article 4 on AI literacy was reworded and kept. The consolidated text still places a duty on providers and deployers to take measures supporting the AI literacy of their staff. It adds that the Commission and Member States should support them, small and medium-sized enterprises in particular.
- Certain exemptions previously reserved for SMEs were extended to small mid-cap companies.
- AI in machinery products is to follow sectoral safety rules instead of two overlapping regimes.
- The AI Office's role in supervising AI systems built on general-purpose models was strengthened.
Why it matters
If your organisation buys or uses AI instead of building it, the heaviest obligations are the ones that moved. The strict regime for high-risk uses, which includes employment, now starts in December 2027. What applies today is narrower but real. That means the prohibited practices, the literacy duty and the transparency duties if you deploy deepfakes or publish AI-generated text on matters of public interest.
The Act reaches beyond the EU. The Commission's FAQ says it applies to public and private actors inside and outside the EU. The test is whether an AI system is placed on the EU market or used in the EU. That matters for UK firms selling into the EU.
The penalties are large. The same FAQ lists maximum fines of up to €35 million or 7% of annual turnover for prohibited practices. Most other breaches carry up to €15 million or 3%. Supplying incorrect information to authorities carries up to €7.5 million or 1%.
My reading is that the delay is best treated as time to do the inventory properly. It is no reason to stop. The Commission's own explanation is that the harmonised standards companies need are still being written. The new dates assume that work gets finished.
What to watch
- 2 December 2026. It is two months away. If you provide a generative system that was on the market before August, this is the marking deadline. The new prohibitions also start.
- Final Article 50 guidelines. The Commission consulted on a draft in May 2026. Check whether a final version has been adopted before relying on the draft.
- Harmonised standards. Their absence was the stated reason for the delay. Progress on them is the best sign of whether December 2027 holds.
- 2 August 2027. Older GPAI models reach their compliance deadline, which matters if your suppliers' models pre-date August 2025.
- National enforcement. Watch which national authority covers your sector and how it uses its powers.
The official pages used here are in the reading list.
Sources
- European Commission, AI Act Service Desk: timeline for the implementation of the EU AI Act
- AI Act Service Desk: Article 113, entry into force and application (consolidated)
- AI Act Service Desk: Article 111, AI systems already placed on the market (consolidated)
- AI Act Service Desk: Article 4, AI literacy (consolidated)
- AI Act Service Desk: Article 5, prohibited AI practices (consolidated)
- AI Act Service Desk: Article 50, transparency obligations (consolidated)
- European Commission: AI Act policy page
- European Commission: Navigating the AI Act (FAQ)
- European Commission: guidelines for providers of general-purpose AI models
- European Commission: Code of Practice on marking and labelling of AI-generated content
- European Parliament, Legislative Train: Digital Omnibus on AI
- European Parliament press release: AI Act deal on simplification measures, 7 May 2026