techlifeadventuresVol. 03 · Oct 2026
EU AI Act Deadlines 2026-2028: A Developer's Guide
·17 min read·Technology

EU AI Act Deadlines 2026-2028: A Developer's Guide

EU AI Act deadlines after the Digital Omnibus: what applied on 2 Aug 2026, what lands in Dec 2026, Dec 2027 and Aug 2028, plus a developer checklist.

Note: This is general information, not legal advice. Dates and rules reflect sources available as of October 2026; check the official text for your situation.

If you searched for "EU AI Act 2026 deadlines," here is the short answer: 2 August 2026 has passed, but it was not the high-risk deadline after all. The Digital Omnibus on AI, now Regulation (EU) 2026/1744, entered into force on 27 July 2026 and pushed the high-risk obligations to 2 December 2027 (Annex III use cases like hiring, credit and education) and 2 August 2028 (AI built into regulated products). What did land on 2 August 2026 is Article 50 transparency, the Commission's enforcement powers over GPAI models, and the rest of the Act's general application. The next hard date is 2 December 2026.

Think of the Act as a metro line that opens one station at a time. Some stations have been open since 2025, one opened in August, and the high-risk stations had their opening dates officially moved. This guide maps which stations are open, which are next, and what developers should do before each one.


EU AI Act Deadlines at a Glance

DateWhat appliesWho it affectsStatus
1 Aug 2024AI Act enters into force (nothing yet enforceable) [1]Everyone in scopeIn force
2 Feb 2025Prohibited practices (Art. 5) and AI literacy (Art. 4) [1][2]All providers and deployersApplies. Art. 4 softened by the Omnibus to "take measures to support" AI literacy [3]
2 Aug 2025GPAI model obligations, governance (AI Office, Board), penalties framework [1][2]GPAI model providers; Member StatesApplies
27 Jul 2026Digital Omnibus on AI (Reg. 2026/1744) enters into force [3]Everyone in scopeIn force
2 Aug 2026General application: Art. 50 transparency, Commission enforcement and fines for GPAI providers, remaining provisions not otherwise deferred [1][2][4]Chatbot and generative AI providers and deployers; GPAI providersApplies
2 Dec 2026New bans on AI generating non-consensual intimate imagery and child sexual abuse material; Art. 50(2) marking deadline for generative systems already on the market before 2 Aug 2026 [3]Generative AI providers and deployersAdopted (Omnibus), applies on this date
2 Aug 2027GPAI models placed on the market before 2 Aug 2025 must comply; national AI regulatory sandboxes due [1][3][4]Legacy GPAI providers; Member StatesAdopted, applies on this date
2 Dec 2027High-risk obligations for Annex III systems (employment, education, credit, essential services, law enforcement, migration, justice, biometrics) [3]Providers and deployers of Annex III systemsChanged by Omnibus (was 2 Aug 2026)
2 Aug 2028High-risk obligations for Annex I systems (AI in products under EU safety law, such as medical devices, machinery, toys) [3]Product manufacturers and their AI suppliersChanged by Omnibus (was 2 Aug 2027)
2 Aug 2030Legacy high-risk systems used by public authorities must comply [3]Public sector providers and deployersAdopted, applies on this date
Sources for the table: [1] Regulation (EU) 2024/1689, Article 113 (EUR-Lex); [2] European Commission, AI Act regulatory framework page; [3] Regulation (EU) 2026/1744 (Digital Omnibus on AI), OJ L 24.7.2026, Articles 4, 5, 111 and 113 as amended; [4] European Commission, guidelines for GPAI providers.

What Changed in 2026: The Digital Omnibus, Adopted

Earlier versions of this post (and plenty of articles still ranking) treat 2 August 2026 as the high-risk deadline. That was true under the original text. It is no longer true.

How it happened:

StepDate
Commission proposal (COM(2025) 836)19 November 2025
Provisional (trilogue) agreement7 May 2026
European Parliament adopts16 June 2026
Council adopts29 June 2026
Signed8 July 2026
Published in the Official Journal24 July 2026
Entry into force27 July 2026
Sources: European Parliament legislative resolution P10_TA(2026)0198, Regulation (EU) 2026/1744, European Commission AI Act page.

What the final text changed for developers:

  • High-risk dates moved. Sections 1 to 3 of Chapter III (classification, requirements, provider and deployer obligations) now apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. The recitals cite late harmonised standards and slow set-up of national authorities as the reason.
  • Transparency did not move. Article 50 applied from 2 August 2026. Only generative systems already on the market before that date get until 2 December 2026 to add machine-readable marking (Article 50(2)).
  • Two new prohibitions. From 2 December 2026, AI systems that generate or manipulate realistic intimate images of an identifiable person without explicit consent, or child sexual abuse material, are banned.
  • AI literacy softened. Article 4 now requires providers and deployers to "take measures to support the development of AI literacy" of staff, and states it does not require guaranteeing any specific level.
  • Small mid-caps (SMCs) get SME-style relief, including the "whichever is lower" penalty cap.
  • Legacy high-risk systems. Systems placed on the market before the new high-risk dates are only caught if their design changes significantly afterwards, except public-authority systems, which must comply by 2 August 2030.
  • Sandboxes. The deadline for each Member State to have an operational national AI regulatory sandbox is now 2 August 2027.

One practical caveat remains: the harmonised standards (being drafted by CEN-CENELEC JTC 21) that give a "presumption of conformity" for high-risk systems were the main reason for the delay. Check their publication status before you lock in a compliance design.


What Already Applies Today (October 2026)

Prohibited practices (since 2 February 2025)

Article 5 bans, among others:

  • Manipulative or deceptive techniques that distort behaviour and cause significant harm
  • Exploiting vulnerabilities linked to age, disability or social or economic situation
  • Social scoring that leads to unjustified or disproportionate detrimental treatment (by public or private actors)
  • Predicting an individual's risk of committing a crime based solely on profiling or personality traits
  • Untargeted scraping of facial images to build facial recognition databases
  • Emotion recognition in workplaces and education (except for medical or safety reasons)
  • Biometric categorisation to infer sensitive attributes such as race, political opinions or sexual orientation
  • Real-time remote biometric identification in public spaces for law enforcement (narrow exceptions)

From 2 December 2026, add the two Omnibus bans on non-consensual intimate deepfakes and CSAM generation.

GPAI model obligations (since 2 August 2025)

If you provide a general-purpose AI model (not just call one through an API):

RequirementApplies to
Technical documentation for the AI Office and downstream providersAll GPAI providers (limited exemptions for certain open-source models)
Copyright policy and public summary of training contentAll GPAI providers
Model evaluation, adversarial testing, incident reporting, cybersecurityGPAI with systemic risk (presumed above 10^25 FLOP of training compute)
The Commission published the voluntary General-Purpose AI Code of Practice on 10 July 2025 and GPAI guidelines later that month. Its enforcement powers, including fines, started on 2 August 2026. Models placed on the market before 2 August 2025 have until 2 August 2027.

Transparency (since 2 August 2026)

This is the deadline most product teams actually hit. Article 50 requires:

ObligationWhoWhat it means in practice
Tell people they are talking to an AIProviders of systems that interact with peopleChat UI disclosure, voice-bot announcement, unless obvious from context
Machine-readable marking of synthetic contentProviders of systems generating audio, image, video or textWatermarks, metadata or similar, detectable as AI-generated. Legacy systems: by 2 Dec 2026
Disclose deepfakesDeployersVisible label on AI-generated or manipulated image, audio or video depicting real people, places or events
Disclose AI-generated text on public-interest mattersDeployersLabel unless a human has reviewed it and holds editorial responsibility
Inform people exposed to emotion recognition or biometric categorisationDeployersNotice to affected persons
The Commission published a final Code of Practice on marking and labelling AI-generated content on 10 June 2026. It is voluntary, but it is the most concrete reference available for what "compliant marking" looks like. Breaching Article 50 can cost up to EUR 15 million or 3% of worldwide turnover.

Before the Next Deadline: A Developer Checklist

Before 2 December 2026

  • [ ] If your product generates images, audio, video or text and launched before 2 August 2026, ship machine-readable marking (Art. 50(2)). Use the Code of Practice as your reference design.
  • [ ] Confirm your image or video features cannot be used to generate non-consensual intimate content of real people or CSAM, and document the safeguards.
  • [ ] Re-check that chat and voice interfaces disclose AI interaction to EU users (this has applied since 2 August 2026).

Before 2 August 2027

  • [ ] If you provide a GPAI model released before 2 August 2025, complete its technical documentation, copyright policy and training content summary.
  • [ ] If you fine-tune or substantially modify someone else's GPAI model, check whether that makes you a provider under the GPAI guidelines.

Before 2 December 2027 (Annex III high-risk)

  • [ ] Build an inventory of every AI system you provide or deploy, with its intended purpose.
  • [ ] Classify each one against Annex III. If you rely on the Article 6(3) "not high-risk" exception, document the assessment; it still needs registration in the EU database.
  • [ ] Start the risk management system, data governance records, logging and human oversight design now. These are engineering work, not paperwork, and they take sprints.
  • [ ] Track harmonised standards from CEN-CENELEC JTC 21 and plan to align with them.

Before 2 August 2028 (Annex I products)

  • [ ] If your AI is a safety component of a regulated product (medical devices, machinery, toys, and others), align AI Act work with the product's existing conformity assessment.

Always

  • [ ] Keep an AI literacy programme for staff who build or operate AI systems.
  • [ ] Map your role in each system: provider, deployer, importer, distributor, or authorised representative. Obligations follow the role.


The Risk Classification System

Risk levelWhat it meansExamples
UnacceptableBanned (Art. 5)Social scoring, manipulative techniques causing harm
High-riskHeavy obligations from Dec 2027 / Aug 2028CV screening, credit scoring, AI in medical devices
Transparency riskDisclosure duties (Art. 50)Chatbots, deepfake and content generators
MinimalNo specific obligationsSpam filters, most recommendation features

Is your AI high-risk?

Annex III use cases (apply from 2 December 2027):

DomainExamples
BiometricsRemote biometric identification, biometric categorisation, emotion recognition (where not banned)
Critical infrastructureSafety components in digital infrastructure, road traffic, utilities
EducationAdmissions, assessing learning outcomes, exam proctoring
EmploymentCV screening, promotion and termination decisions, task allocation, performance monitoring
Essential servicesCredit scoring, life and health insurance pricing, eligibility for public benefits, emergency call triage
Law enforcementEvidence reliability assessment, risk assessment of individuals
Migration and border controlVisa and asylum application assessment
Justice and democracyAssisting judicial decisions, influencing elections
Annex I products (apply from 2 August 2028) include AI that is a safety component of products covered by EU harmonisation law, for example medical devices, machinery, toys, lifts, radio equipment, and certain vehicles and aviation products.

A quick self-test: does the system make or materially inform decisions about people in one of the domains above? If yes, treat it as high-risk until a documented Article 6(3) assessment says otherwise. Profiling of natural persons in an Annex III area is always high-risk.


High-Risk Requirements (What You Are Building Towards)

RequirementWhat it means
Risk management system (Art. 9)Documented, ongoing process to identify, analyse and mitigate risks
Data governance (Art. 10)Quality, relevance and bias checks on training, validation and test data
Technical documentation (Art. 11, Annex IV)System description, design choices, performance, limitations
Record-keeping (Art. 12)Automatic event logging across the system's lifetime
Transparency to deployers (Art. 13)Instructions for use, capabilities and limitations
Human oversight (Art. 14)Design that lets people monitor, interpret and override
Accuracy, robustness, cybersecurity (Art. 15)Declared performance levels, resilience to errors and attacks

Conformity assessment and registration

ItemWhen required
Internal control (self-assessment)Most Annex III systems
Third-party (notified body) assessmentAnnex III biometrics where harmonised standards are not fully applied; Annex I products follow their own sector rules
EU database registrationAnnex III high-risk systems, plus systems you have assessed as not high-risk under Art. 6(3)
CE markingAll high-risk systems before placing on the market

Technical documentation skeleton

text
Document Structure:
├── 1. General Description
│   ├── System purpose and intended use
│   ├── Version history
│   └── Hardware/software dependencies
├── 2. Technical Details
│   ├── Architecture and design choices
│   ├── Training methodology
│   └── Data sources, preparation and labelling
├── 3. Performance
│   ├── Metrics, including per-group accuracy
│   ├── Known limitations and failure modes
│   └── Test results
├── 4. Risk Management
│   ├── Identified risks (incl. foreseeable misuse)
│   ├── Mitigation measures
│   └── Residual risks
├── 5. Human Oversight
│   ├── Monitoring and interpretation tools
│   ├── Override and stop procedures
│   └── Warnings to users
└── 6. Post-Market Monitoring
    ├── Logging and incident reporting
    └── Change management

Data governance by stage

Data stageWhat to record
CollectionSources, legal basis, consent where required
PreparationCleaning, labelling, bias examination
TrainingRepresentativeness and completeness for the intended population
Validation and testingSeparate datasets, tested on the target population

Penalties and Enforcement

ViolationMaximum fine
Prohibited practicesEUR 35M or 7% of worldwide annual turnover
Most other obligations (high-risk, Art. 50 transparency)EUR 15M or 3%
Supplying incorrect or misleading information to authoritiesEUR 7.5M or 1%
GPAI providers (Art. 101, enforced by the Commission)EUR 15M or 3%
For large companies, the higher amount applies. For SMEs and start-ups, and since the Omnibus also small mid-caps, the lower amount applies (Article 99, Regulation 2024/1689 as amended).

Who enforces: national market surveillance authorities in each Member State for AI systems, and the European AI Office within the Commission for GPAI models.


Companies Outside the EU, Including Indian IT

The Act has extraterritorial reach (Article 2). It applies to:

ScenarioObligation
EU or non-EU provider placing an AI system or GPAI model on the EU marketYes
Deployer established in the EUYes
Non-EU provider or deployer whose system's output is used in the EUYes
Non-EU company with no EU market or EU use of outputsNo direct obligation
For Indian IT services firms building for EU clients, the key question is role, not geography. If you build a system that your EU client places on the market under its own name, the client is usually the provider and you are a supplier who will be asked, by contract, to deliver the documentation, logs and test evidence the provider needs. If your firm sells an AI product into the EU under its own brand, your firm is the provider, and for a high-risk system it must appoint an authorised representative in the EU (Article 22). Under Article 25, anyone who puts their name on a high-risk system or substantially modifies it can become its provider. In practice, expect EU clients to push AI Act clauses into statements of work well before December 2027, because they need your evidence to meet their own deadlines.

Frequently Asked Questions

Q: Does this apply to my internal AI tools?

A: It can. If an internal tool makes or informs decisions about employees (recruitment, promotion, task allocation, performance monitoring), it falls under Annex III employment use cases, and those obligations apply from 2 December 2027. Internal use is not an exemption.

Q: What about AI from vendors?

A: Deployers have their own obligations: use the system according to its instructions, assign human oversight, keep logs, and inform affected workers. Buying from a compliant vendor does not transfer your deployer duties.

Q: Is there a research exemption?

A: AI developed and used solely for scientific research is excluded, and pre-market R&D is excluded too. Once you place a system on the market or put it into service, the rules apply (real-world testing has its own conditions).

Q: How does this interact with GDPR?

A: They apply side by side. GDPR governs personal data processing; the AI Act governs the AI system. The Omnibus added Article 4a, which sets conditions for processing special categories of personal data to detect and correct bias.

Q: We missed 2 August 2026. What now?

A: It depends on which obligation. High-risk obligations were moved to December 2027 and August 2028, so you have runway there. Article 50 transparency was not moved: if your chatbot does not disclose that it is an AI, or your generator does not mark output, fix it now. Legacy generative systems have until 2 December 2026 for marking only.


Official Resources

ResourceLink
AI Act full text (Reg. 2024/1689)EUR-Lex
Digital Omnibus on AI (Reg. 2026/1744)EUR-Lex
Commission AI Act page and timelinedigital-strategy.ec.europa.eu
GPAI provider guidelinesdigital-strategy.ec.europa.eu
GPAI Code of Practicedigital-strategy.ec.europa.eu

Conclusion

The question "what are the EU AI Act deadlines in 2026?" now has a clearer answer than it did six months ago. 2 August 2026 brought transparency and GPAI enforcement, not high-risk compliance. The next date is 2 December 2026 (marking for legacy generative systems and two new bans), then 2 August 2027 for legacy GPAI models, 2 December 2027 for Annex III high-risk systems, and 2 August 2028 for AI in regulated products.

The delay is real, but it is a scheduling change, not a cancellation. The requirements for high-risk systems (risk management, data governance, logging, human oversight) are the same engineering practices good AI teams should be building anyway. Teams that use the extra 14 months to build them into their pipelines will find the December 2027 date uneventful.

Your next step: run the inventory and classification items from the checklist above this sprint, and bookmark the EUR-Lex text so you check changes against the source rather than summaries.


Sources:


Enjoying this article?

Get posts like this in your inbox. No spam, unsubscribe anytime.

Share this article
Vinod Kurien Alex

Vinod Kurien Alex

Engineering Manager with 20+ years in software. Writing about AI, careers, and the Indian tech industry.

Related Articles

© 2026 TechLife AdventuresBuilt with care · v3.2.1