Start with Maditon
← Back to Resource Center
EU AI Act · Timeline 7 min read

EU AI Act deadlines 2026 — what applies when

The EU AI Act timeline after the Digital Omnibus delay: prohibited practices (Feb 2025), GPAI (Aug 2025), high-risk (Dec 2027), regulated products (Aug 2028).


The EU AI Act entered into force on 1 August 2024, but its provisions apply in staggered tranches over the following three years. Most teams plan around the wrong date because they hear “the AI Act is in force” and assume everything is live. This guide is the timeline, what each milestone actually triggers, and what you should be doing right now.

Update (May 2026): The Digital Omnibus — politically agreed on 7 May 2026 and pending formal adoption — postpones several key application dates. The big high-risk tranche (Annex III obligations, EU database registration, conformity assessment, post-market monitoring) moves from 2 August 2026 to 2 December 2027; high-risk AI embedded in regulated products moves from 2 August 2027 to 2 August 2028. Article 50 transparency was not postponed — it still applies from 2 August 2026; only the machine-readable marking of synthetic content already on the market before that date has a short grace period (to 2 December 2026, cut from six months to three under the Omnibus). The prohibited-practices (2 February 2025) and GPAI (2 August 2025) dates are unchanged. These dates are expected to apply once the Digital Omnibus is formally adopted; we treat them as provisional below.

The full timeline at a glance

| Date | What applies | Article reference | |---|---|---| | 1 Aug 2024 | The Regulation enters into force | Art. 113 | | 2 Feb 2025 | Prohibited practices (Art. 5) + general provisions (Art. 1–4) — including AI literacy | Art. 113(a) | | 2 Aug 2025 | General-purpose AI (GPAI) model obligations (Chapter V) + governance bodies + penalties for GPAI breaches | Art. 113(b) | | 2 Aug 2026 | Article 50 transparency applies (chatbots, deepfakes, AI-interaction & synthetic-content disclosure). Machine-readable marking of synthetic content already on the market before 2 Aug 2026 has a grace period to 2 Dec 2026. | Art. 50 | | 2 Dec 2027 | Most provisions apply: high-risk under Annex III, EU database registration, post-market monitoring, conformity assessment for non-Annex II high-risk, full fines for most breaches — expected, postponed from 2 August 2026 under the Digital Omnibus | Art. 113 (default) | | 2 Aug 2028 | High-risk AI under Annex II (regulated products: medical devices, machinery, toys, lifts, etc.) and embedded safety components — expected, postponed from 2 August 2027 under the Digital Omnibus | Art. 113(c) |

What 2 February 2025 already requires

The Article 5 prohibitions are enforceable now. The eight banned practices include subliminal manipulation, social scoring leading to unjustified differential treatment, real-time biometric identification in public, and emotion recognition in workplaces and schools. Fines hit €35 million or 7% of global turnover (Art. 99(3)). Read your products against the Article 5 list before doing anything else.

Article 4 — AI literacy — is also already in force. Every provider and every deployer must ensure their staff have a sufficient level of AI literacy in the context of the systems they work with. There’s no certification scheme yet, but a documented programme matters when a supervisory authority asks. See AI literacy under Article 4.

What 2 August 2025 added

The Chapter V provisions on general-purpose AI (GPAI) kicked in. If you train, fine-tune, or significantly customise a GPAI model and place it on the EU market, you owe:

  • Technical documentation per Annex XI
  • Copyright training-data summary (the one OpenAI famously refused to publish initially)
  • Transparency about training and capabilities
  • Stricter obligations for systems with “systemic risk” (above the FLOPS threshold in Art. 51)

For SaaS companies using GPAI models, the obligations don’t fall on you directly — they fall on Mistral, Anthropic, OpenAI, etc. But your contracts with those vendors changed in August 2025, and your DPA review should reflect that.

The governance bodies — the AI Office, the European Artificial Intelligence Board, the national supervisory authorities — also became operational. If you have a complaint or need guidance, there is now a body to write to.

What 2 December 2027 brings — the big one

This is the date most SMEs need to plan around. On 2 December 2027 — postponed from 2 August 2026 under the Digital Omnibus, agreed May 2026 and pending formal adoption — the bulk of the Regulation is expected to become enforceable:

  • Article 6 / Annex III — high-risk classification logic applies
  • Articles 9–15 — all provider obligations for high-risk (risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy)
  • Articles 16–22 — provider duties for high-risk including post-market monitoring and incident reporting
  • Article 26 — deployer duties for high-risk
  • Article 27 — fundamental-rights impact assessment (FRIA) for certain deployers
  • Article 49 — registration in the EU database for high-risk systems
  • Article 99 — fines for most offences

The Article 50 transparency obligations for limited-risk systems (chatbots, generative AI, deepfakes) were not postponed by the Digital Omnibus — they apply from 2 August 2026, ahead of the high-risk tranche. Only the machine-readable marking of synthetic content already on the market before that date has a short grace period (to 2 December 2026, cut from six months to three under the Omnibus).

If you’re a provider of a high-risk system, you must complete a conformity assessment, draft a declaration of conformity, affix the CE marking, and register the system in the EU database before placing it on the market on or after 2 December 2027.

Backwards-plan from this date:

  • 3–6 months before — draft technical documentation, prepare conformity assessment, line up the notified body if required
  • 1–2 months before — register in the EU database, set up post-market monitoring
  • Day of — make the system available

Note that the postponed dates are expected to apply regardless of whether the harmonised standards and Commission guidance are finalised by then — a slipping standards timeline is not a reason to assume the obligations slip with it.

What 2 August 2028 brings

The Annex II tranche — high-risk AI systems that are themselves safety components of regulated products (medical devices, machinery, toys, lifts, recreational craft, cableways, gas appliances, pressure equipment, radio equipment, civil-aviation safety) — is expected to apply later still, postponed from 2 August 2027 to 2 August 2028 under the Digital Omnibus (agreed May 2026, pending formal adoption). The reason for the staggered timing is to align with the sectoral conformity assessment cycles that already apply to those products.

If you build a medical device with an AI safety component, you have until August 2028 — but the existing MDR/IVDR cycle still applies in parallel.

What you should be doing right now

It depends on what you have today.

If you ship AI features: complete your inventory and classification well ahead of the high-risk tranche (expected 2 December 2027). The earlier you classify, the more runway you have to handle Article 9–17 obligations if anything turns out to be high-risk — and the postponement is breathing room, not a reason to stop.

If you only deploy AI you didn’t build: read the vendor’s instructions for use, document your human oversight setup, and confirm your AI literacy programme now — AI literacy (Article 4) has applied since 2 February 2025 regardless of the high-risk postponement. Article 26 is lighter than the provider chapter, but it’s not nothing.

If you’re in healthcare, finance, HR-tech, or education-tech: assume at least one of your systems is Annex III. Start the conformity assessment dialogue now.

Everyone: review your transparency disclosures (Article 50). The “users must know they’re interacting with AI” rule is short and not negotiable, and it applies from 2 August 2026 — it was not postponed by the Digital Omnibus.

The cost of slipping

The fines are tiered (Article 99):

  • €35 million or 7% — prohibited practices (Art. 5)
  • €15 million or 3% — most other infringements (high-risk obligations, transparency, GPAI obligations)
  • €7.5 million or 1% — supplying incorrect information to a notified body or authority

For SMEs, fines are capped at the lower of the absolute amount or the percentage (Art. 99(6)). That’s still company-ending money for a Series A startup.

The deadline that ends careers is the high-risk tranche, expected 2 December 2027 (postponed from 2 August 2026 under the Digital Omnibus). Backwards-plan from it.