
EU AI Act Deadlines 2026-2028: A Developer's Guide
EU AI Act deadlines after the Digital Omnibus: what applied on 2 Aug 2026, what lands in Dec 2026, Dec 2027 and Aug 2028, plus a developer checklist.
Note: This is general information, not legal advice. Dates and rules reflect sources available as of October 2026; check the official text for your situation.
If you searched for "EU AI Act 2026 deadlines," here is the short answer: 2 August 2026 has passed, but it was not the high-risk deadline after all. The Digital Omnibus on AI, now Regulation (EU) 2026/1744, entered into force on 27 July 2026 and pushed the high-risk obligations to 2 December 2027 (Annex III use cases like hiring, credit and education) and 2 August 2028 (AI built into regulated products). What did land on 2 August 2026 is Article 50 transparency, the Commission's enforcement powers over GPAI models, and the rest of the Act's general application. The next hard date is 2 December 2026.
Think of the Act as a metro line that opens one station at a time. Some stations have been open since 2025, one opened in August, and the high-risk stations had their opening dates officially moved. This guide maps which stations are open, which are next, and what developers should do before each one.
EU AI Act Deadlines at a Glance
| Date | What applies | Who it affects | Status |
|---|---|---|---|
| 1 Aug 2024 | AI Act enters into force (nothing yet enforceable) [1] | Everyone in scope | In force |
| 2 Feb 2025 | Prohibited practices (Art. 5) and AI literacy (Art. 4) [1][2] | All providers and deployers | Applies. Art. 4 softened by the Omnibus to "take measures to support" AI literacy [3] |
| 2 Aug 2025 | GPAI model obligations, governance (AI Office, Board), penalties framework [1][2] | GPAI model providers; Member States | Applies |
| 27 Jul 2026 | Digital Omnibus on AI (Reg. 2026/1744) enters into force [3] | Everyone in scope | In force |
| 2 Aug 2026 | General application: Art. 50 transparency, Commission enforcement and fines for GPAI providers, remaining provisions not otherwise deferred [1][2][4] | Chatbot and generative AI providers and deployers; GPAI providers | Applies |
| 2 Dec 2026 | New bans on AI generating non-consensual intimate imagery and child sexual abuse material; Art. 50(2) marking deadline for generative systems already on the market before 2 Aug 2026 [3] | Generative AI providers and deployers | Adopted (Omnibus), applies on this date |
| 2 Aug 2027 | GPAI models placed on the market before 2 Aug 2025 must comply; national AI regulatory sandboxes due [1][3][4] | Legacy GPAI providers; Member States | Adopted, applies on this date |
| 2 Dec 2027 | High-risk obligations for Annex III systems (employment, education, credit, essential services, law enforcement, migration, justice, biometrics) [3] | Providers and deployers of Annex III systems | Changed by Omnibus (was 2 Aug 2026) |
| 2 Aug 2028 | High-risk obligations for Annex I systems (AI in products under EU safety law, such as medical devices, machinery, toys) [3] | Product manufacturers and their AI suppliers | Changed by Omnibus (was 2 Aug 2027) |
| 2 Aug 2030 | Legacy high-risk systems used by public authorities must comply [3] | Public sector providers and deployers | Adopted, applies on this date |
What Changed in 2026: The Digital Omnibus, Adopted
Earlier versions of this post (and plenty of articles still ranking) treat 2 August 2026 as the high-risk deadline. That was true under the original text. It is no longer true.
How it happened:
| Step | Date |
|---|---|
| Commission proposal (COM(2025) 836) | 19 November 2025 |
| Provisional (trilogue) agreement | 7 May 2026 |
| European Parliament adopts | 16 June 2026 |
| Council adopts | 29 June 2026 |
| Signed | 8 July 2026 |
| Published in the Official Journal | 24 July 2026 |
| Entry into force | 27 July 2026 |
What the final text changed for developers:
- High-risk dates moved. Sections 1 to 3 of Chapter III (classification, requirements, provider and deployer obligations) now apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. The recitals cite late harmonised standards and slow set-up of national authorities as the reason.
- Transparency did not move. Article 50 applied from 2 August 2026. Only generative systems already on the market before that date get until 2 December 2026 to add machine-readable marking (Article 50(2)).
- Two new prohibitions. From 2 December 2026, AI systems that generate or manipulate realistic intimate images of an identifiable person without explicit consent, or child sexual abuse material, are banned.
- AI literacy softened. Article 4 now requires providers and deployers to "take measures to support the development of AI literacy" of staff, and states it does not require guaranteeing any specific level.
- Small mid-caps (SMCs) get SME-style relief, including the "whichever is lower" penalty cap.
- Legacy high-risk systems. Systems placed on the market before the new high-risk dates are only caught if their design changes significantly afterwards, except public-authority systems, which must comply by 2 August 2030.
- Sandboxes. The deadline for each Member State to have an operational national AI regulatory sandbox is now 2 August 2027.
One practical caveat remains: the harmonised standards (being drafted by CEN-CENELEC JTC 21) that give a "presumption of conformity" for high-risk systems were the main reason for the delay. Check their publication status before you lock in a compliance design.
What Already Applies Today (October 2026)
Prohibited practices (since 2 February 2025)
Article 5 bans, among others:
- Manipulative or deceptive techniques that distort behaviour and cause significant harm
- Exploiting vulnerabilities linked to age, disability or social or economic situation
- Social scoring that leads to unjustified or disproportionate detrimental treatment (by public or private actors)
- Predicting an individual's risk of committing a crime based solely on profiling or personality traits
- Untargeted scraping of facial images to build facial recognition databases
- Emotion recognition in workplaces and education (except for medical or safety reasons)
- Biometric categorisation to infer sensitive attributes such as race, political opinions or sexual orientation
- Real-time remote biometric identification in public spaces for law enforcement (narrow exceptions)
From 2 December 2026, add the two Omnibus bans on non-consensual intimate deepfakes and CSAM generation.
GPAI model obligations (since 2 August 2025)
If you provide a general-purpose AI model (not just call one through an API):
| Requirement | Applies to |
|---|---|
| Technical documentation for the AI Office and downstream providers | All GPAI providers (limited exemptions for certain open-source models) |
| Copyright policy and public summary of training content | All GPAI providers |
| Model evaluation, adversarial testing, incident reporting, cybersecurity | GPAI with systemic risk (presumed above 10^25 FLOP of training compute) |
Transparency (since 2 August 2026)
This is the deadline most product teams actually hit. Article 50 requires:
| Obligation | Who | What it means in practice |
|---|---|---|
| Tell people they are talking to an AI | Providers of systems that interact with people | Chat UI disclosure, voice-bot announcement, unless obvious from context |
| Machine-readable marking of synthetic content | Providers of systems generating audio, image, video or text | Watermarks, metadata or similar, detectable as AI-generated. Legacy systems: by 2 Dec 2026 |
| Disclose deepfakes | Deployers | Visible label on AI-generated or manipulated image, audio or video depicting real people, places or events |
| Disclose AI-generated text on public-interest matters | Deployers | Label unless a human has reviewed it and holds editorial responsibility |
| Inform people exposed to emotion recognition or biometric categorisation | Deployers | Notice to affected persons |
Before the Next Deadline: A Developer Checklist
Before 2 December 2026
- [ ] If your product generates images, audio, video or text and launched before 2 August 2026, ship machine-readable marking (Art. 50(2)). Use the Code of Practice as your reference design.
- [ ] Confirm your image or video features cannot be used to generate non-consensual intimate content of real people or CSAM, and document the safeguards.
- [ ] Re-check that chat and voice interfaces disclose AI interaction to EU users (this has applied since 2 August 2026).
Before 2 August 2027
- [ ] If you provide a GPAI model released before 2 August 2025, complete its technical documentation, copyright policy and training content summary.
- [ ] If you fine-tune or substantially modify someone else's GPAI model, check whether that makes you a provider under the GPAI guidelines.
Before 2 December 2027 (Annex III high-risk)
- [ ] Build an inventory of every AI system you provide or deploy, with its intended purpose.
- [ ] Classify each one against Annex III. If you rely on the Article 6(3) "not high-risk" exception, document the assessment; it still needs registration in the EU database.
- [ ] Start the risk management system, data governance records, logging and human oversight design now. These are engineering work, not paperwork, and they take sprints.
- [ ] Track harmonised standards from CEN-CENELEC JTC 21 and plan to align with them.
Before 2 August 2028 (Annex I products)
- [ ] If your AI is a safety component of a regulated product (medical devices, machinery, toys, and others), align AI Act work with the product's existing conformity assessment.
Always
- [ ] Keep an AI literacy programme for staff who build or operate AI systems.
- [ ] Map your role in each system: provider, deployer, importer, distributor, or authorised representative. Obligations follow the role.
The Risk Classification System
| Risk level | What it means | Examples |
|---|---|---|
| Unacceptable | Banned (Art. 5) | Social scoring, manipulative techniques causing harm |
| High-risk | Heavy obligations from Dec 2027 / Aug 2028 | CV screening, credit scoring, AI in medical devices |
| Transparency risk | Disclosure duties (Art. 50) | Chatbots, deepfake and content generators |
| Minimal | No specific obligations | Spam filters, most recommendation features |
Is your AI high-risk?
Annex III use cases (apply from 2 December 2027):
| Domain | Examples |
|---|---|
| Biometrics | Remote biometric identification, biometric categorisation, emotion recognition (where not banned) |
| Critical infrastructure | Safety components in digital infrastructure, road traffic, utilities |
| Education | Admissions, assessing learning outcomes, exam proctoring |
| Employment | CV screening, promotion and termination decisions, task allocation, performance monitoring |
| Essential services | Credit scoring, life and health insurance pricing, eligibility for public benefits, emergency call triage |
| Law enforcement | Evidence reliability assessment, risk assessment of individuals |
| Migration and border control | Visa and asylum application assessment |
| Justice and democracy | Assisting judicial decisions, influencing elections |
A quick self-test: does the system make or materially inform decisions about people in one of the domains above? If yes, treat it as high-risk until a documented Article 6(3) assessment says otherwise. Profiling of natural persons in an Annex III area is always high-risk.
High-Risk Requirements (What You Are Building Towards)
| Requirement | What it means |
|---|---|
| Risk management system (Art. 9) | Documented, ongoing process to identify, analyse and mitigate risks |
| Data governance (Art. 10) | Quality, relevance and bias checks on training, validation and test data |
| Technical documentation (Art. 11, Annex IV) | System description, design choices, performance, limitations |
| Record-keeping (Art. 12) | Automatic event logging across the system's lifetime |
| Transparency to deployers (Art. 13) | Instructions for use, capabilities and limitations |
| Human oversight (Art. 14) | Design that lets people monitor, interpret and override |
| Accuracy, robustness, cybersecurity (Art. 15) | Declared performance levels, resilience to errors and attacks |
Conformity assessment and registration
| Item | When required |
|---|---|
| Internal control (self-assessment) | Most Annex III systems |
| Third-party (notified body) assessment | Annex III biometrics where harmonised standards are not fully applied; Annex I products follow their own sector rules |
| EU database registration | Annex III high-risk systems, plus systems you have assessed as not high-risk under Art. 6(3) |
| CE marking | All high-risk systems before placing on the market |
Technical documentation skeleton
Document Structure:
├── 1. General Description
│ ├── System purpose and intended use
│ ├── Version history
│ └── Hardware/software dependencies
├── 2. Technical Details
│ ├── Architecture and design choices
│ ├── Training methodology
│ └── Data sources, preparation and labelling
├── 3. Performance
│ ├── Metrics, including per-group accuracy
│ ├── Known limitations and failure modes
│ └── Test results
├── 4. Risk Management
│ ├── Identified risks (incl. foreseeable misuse)
│ ├── Mitigation measures
│ └── Residual risks
├── 5. Human Oversight
│ ├── Monitoring and interpretation tools
│ ├── Override and stop procedures
│ └── Warnings to users
└── 6. Post-Market Monitoring
├── Logging and incident reporting
└── Change managementData governance by stage
| Data stage | What to record |
|---|---|
| Collection | Sources, legal basis, consent where required |
| Preparation | Cleaning, labelling, bias examination |
| Training | Representativeness and completeness for the intended population |
| Validation and testing | Separate datasets, tested on the target population |
Penalties and Enforcement
| Violation | Maximum fine |
|---|---|
| Prohibited practices | EUR 35M or 7% of worldwide annual turnover |
| Most other obligations (high-risk, Art. 50 transparency) | EUR 15M or 3% |
| Supplying incorrect or misleading information to authorities | EUR 7.5M or 1% |
| GPAI providers (Art. 101, enforced by the Commission) | EUR 15M or 3% |
Who enforces: national market surveillance authorities in each Member State for AI systems, and the European AI Office within the Commission for GPAI models.
Companies Outside the EU, Including Indian IT
The Act has extraterritorial reach (Article 2). It applies to:
| Scenario | Obligation |
|---|---|
| EU or non-EU provider placing an AI system or GPAI model on the EU market | Yes |
| Deployer established in the EU | Yes |
| Non-EU provider or deployer whose system's output is used in the EU | Yes |
| Non-EU company with no EU market or EU use of outputs | No direct obligation |
Frequently Asked Questions
Q: Does this apply to my internal AI tools?
A: It can. If an internal tool makes or informs decisions about employees (recruitment, promotion, task allocation, performance monitoring), it falls under Annex III employment use cases, and those obligations apply from 2 December 2027. Internal use is not an exemption.
Q: What about AI from vendors?
A: Deployers have their own obligations: use the system according to its instructions, assign human oversight, keep logs, and inform affected workers. Buying from a compliant vendor does not transfer your deployer duties.
Q: Is there a research exemption?
A: AI developed and used solely for scientific research is excluded, and pre-market R&D is excluded too. Once you place a system on the market or put it into service, the rules apply (real-world testing has its own conditions).
Q: How does this interact with GDPR?
A: They apply side by side. GDPR governs personal data processing; the AI Act governs the AI system. The Omnibus added Article 4a, which sets conditions for processing special categories of personal data to detect and correct bias.
Q: We missed 2 August 2026. What now?
A: It depends on which obligation. High-risk obligations were moved to December 2027 and August 2028, so you have runway there. Article 50 transparency was not moved: if your chatbot does not disclose that it is an AI, or your generator does not mark output, fix it now. Legacy generative systems have until 2 December 2026 for marking only.
Official Resources
| Resource | Link |
|---|---|
| AI Act full text (Reg. 2024/1689) | EUR-Lex |
| Digital Omnibus on AI (Reg. 2026/1744) | EUR-Lex |
| Commission AI Act page and timeline | digital-strategy.ec.europa.eu |
| GPAI provider guidelines | digital-strategy.ec.europa.eu |
| GPAI Code of Practice | digital-strategy.ec.europa.eu |
Conclusion
The question "what are the EU AI Act deadlines in 2026?" now has a clearer answer than it did six months ago. 2 August 2026 brought transparency and GPAI enforcement, not high-risk compliance. The next date is 2 December 2026 (marking for legacy generative systems and two new bans), then 2 August 2027 for legacy GPAI models, 2 December 2027 for Annex III high-risk systems, and 2 August 2028 for AI in regulated products.
The delay is real, but it is a scheduling change, not a cancellation. The requirements for high-risk systems (risk management, data governance, logging, human oversight) are the same engineering practices good AI teams should be building anyway. Teams that use the extra 14 months to build them into their pipelines will find the December 2027 date uneventful.
Your next step: run the inventory and classification items from the checklist above this sprint, and bookmark the EUR-Lex text so you check changes against the source rather than summaries.
Sources:
- Regulation (EU) 2024/1689 (AI Act), EUR-Lex
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), EUR-Lex
- European Parliament legislative resolution of 16 June 2026, P10_TA(2026)0198
- European Commission, Regulatory framework on AI
- European Commission, Guidelines for providers of GPAI models
- Freshfields, EU AI Act unpacked #34: the final Digital Omnibus on AI
- Jones Walker, Yes, August 2 Still Matters
- Jones Day, Commission publishes final Code of Practice on marking and labelling AI-generated content
Related Reading
Enjoying this article?
Get posts like this in your inbox. No spam, unsubscribe anytime.



