EU AI Act Timeline 2026 2027: Deadlines Reset

Awais Khalid

September 1, 2026

EU AI Act Timeline 2026 2027
  • ⚖️ 2 August 2026 started active enforcement for the AI Act rules already applicable, including Article 50 transparency, prohibited practices, AI literacy and general-purpose AI obligations.
  • 📅 2 December 2026 is the next near-term deadline, adding new prohibitions and ending the transition for certain pre-August 2026 generative systems to implement machine-readable content marking.
  • 🧪 2 August 2027 matters twice: Member States should have at least one AI regulatory sandbox operating, and legacy GPAI models placed on the market before 2 August 2025 reach their compliance deadline.
  • 🚨 2 December 2027, not August 2026, is now the key application date for Annex III high-risk systems such as many employment, education, credit, biometric and essential-service uses.
  • 💶 Penalty exposure remains material: prohibited-practice infringements can reach EUR 35 million or 7% of worldwide annual turnover, while Article 50 and other operator breaches can reach EUR 15 million or 3%.
  • ✅ The practical decision is role-first: inventory each AI system, identify provider or deployer status, separate rules already enforceable from delayed high-risk duties, and preserve evidence now rather than waiting for 2027.

The EU AI Act timeline 2026 2027 changed materially in July 2026, and I would not use a compliance calendar printed before the Digital Omnibus became law. The clearest correction is this: 2 August 2026 did begin enforcement, but the main Annex III high-risk regime was moved to 2 December 2027, while high-risk AI embedded in many regulated products now moves to 2 August 2028.

That distinction matters because the Act is no longer one approaching deadline. It is a stack of live, transitional and future obligations. Article 50 transparency rules now apply. Existing prohibited practices remain enforceable. General-purpose AI obligations that began in 2025 can now be supervised, while some older GPAI models retain a transition until August 2027. A new December 2026 milestone covers both synthetic-content marking for certain existing systems and new prohibitions added by the Omnibus.

For compliance teams in London, Dublin, Paris, Berlin or a US headquarters selling into Europe, the operational risk is not simply being late. It is preparing for the wrong rule on the wrong date. The European Commission’s current implementation material now describes a full roll-out extending to August 2028, with additional legacy-system dates running to 2030. This guide separates the dates, affected actors, penalty ceilings and preparation work so that product, legal, risk and engineering teams can build a calendar that matches the law as it stands on 31 August 2026.

EU AI Act Timeline 2026 2027: The Reset Calendar

EU AI Act Timeline 2026 2027 at a Glance

The decisive event of summer 2026 was not a repeal of the AI Act but a recalibration of its hardest implementation dates. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force in late July and fixed a delayed schedule for high-risk requirements. The Commission’s Service Desk now treats 2 December 2027 as the application date for Annex III high-risk systems and 2 August 2028 as the date for high-risk systems embedded in products covered by Annex I. That is the baseline businesses should use, not the older assumption that the full high-risk regime arrived on 2 August 2026.

The change also explains why recent headlines can look contradictory. 2 August 2026 was still a major milestone because Article 50 transparency requirements started to apply and enforcement powers became active for rules already in force. Our reporting on the August transparency milestone focused on that narrower but legally significant change. The key reading skill is to ask which chapter, article and actor a date belongs to before translating it into an implementation task.

The timeline below captures the practical sequence. The long tail matters too. High-risk systems placed on the market before 2 August 2026 are generally brought into the regime only if they undergo significant changes after that date, while public-authority systems and certain large-scale EU IT systems have special transition rules reaching 2030. Those legacy provisions make version control and change management part of legal scoping, not merely engineering housekeeping.

DateWhat AppliesPrimary Teams Affected
2 February 2025Definitions, AI literacy provisions and original prohibited practicesHR, product, legal, risk, public sector
2 August 2025GPAI obligations and governance architectureModel providers, AI Office, national authorities
2 August 2026Article 50 transparency, innovation measures and enforcement for applicable rulesProduct, content, legal, trust and safety
2 December 2026New intimate-content and CSAM prohibitions; Article 50(2) transition ends for certain existing systemsGenerative AI providers, platforms, safety teams
2 August 2027Regulatory sandboxes expected; legacy pre-August 2025 GPAI transition endsMember States, GPAI providers, compliance leaders
2 December 2027Annex III high-risk obligations applyHR tech, finance, education, biometrics, critical services
2 August 2028Annex I embedded high-risk product rules applyManufacturers, product safety, conformity teams

What Actually Became Enforceable on 2 August 2026

The phrase ‘the AI Act became enforceable’ is directionally useful but legally incomplete. From 2 August 2026, the European Commission’s AI Office and national authorities began enforcing provisions that were already applicable, while Article 50 transparency duties also started to apply. The Commission’s current enforcement FAQ specifically lists prohibited practices, transparency requirements for certain systems and general-purpose AI rules among the provisions that can now be enforced. High-risk rules that have not yet reached their application date cannot be enforced as though the Omnibus delay never happened.

This is why older pre-July coverage should be read as a historical snapshot rather than a live calendar. Our earlier global compliance deadline reporting documented how multinational organisations were preparing for the original August 2026 assumptions. The subsequent Omnibus did not make those governance programmes pointless. Risk management, inventories, human oversight design, data controls and documentation remain valuable. It changed when some high-risk legal duties become mandatory.

The most immediate live obligations are therefore cross-cutting rather than confined to the classic ‘high-risk’ label. An ordinary customer-service chatbot may have an Article 50 disclosure duty even if it is not high-risk. A company may need to ensure AI literacy, avoid prohibited uses, and manage a GPAI supply chain without operating any Annex III system at all. Compliance programmes built only around the high-risk classification question will miss these layers.

Henna Virkkunen, the European Commission Executive Vice-President responsible for tech sovereignty, described the Act in July as a ‘clear, risk-based and durable framework for trustworthy AI’. That phrasing is useful because risk-based does not mean high-risk only. It means different obligations attach to different risk categories, functions and market roles on different dates. The 2026 enforcement milestone makes that architecture operational.

“clear, risk-based and durable framework for trustworthy AI”

Henna Virkkunen, Executive Vice-President, European Commission, 31 July 2026

Article 50 Transparency: The Deadline Most Teams Face Now

Article 50 is the part of the AI Act most likely to touch a broad set of organisations before the high-risk regime arrives. Providers of AI systems intended to interact directly with people must generally ensure users are informed they are interacting with AI, unless that fact is obvious from the context. Other provisions address emotion recognition and biometric categorisation disclosures, machine-readable marking of synthetic outputs, and labelling duties for deepfakes and certain AI-generated public-interest text.

The operational split between provider and deployer is important. A model or system provider may be responsible for technical marking capability, while a deployer that publishes a deepfake or uses a covered system in practice can carry a separate disclosure obligation. A third-party vendor badge does not automatically answer whether the deployer’s own user experience is legally sufficient. That is why the most useful control is an evidence map: what appears on screen or in audio, who generated the content, which technical marker exists, and which team owns the disclosure decision.

For smaller organisations, our small-business compliance guide goes deeper on provider-versus-deployer classification and a first-month governance plan. The headline is that size does not erase Article 50. SME status matters to proportionality and penalty calculations, but a small company can still be a provider or deployer subject to transparency duties.

The Digital Omnibus created a limited transition for providers of certain synthetic-content-generating systems that were already on the market before 2 August 2026. They have until 2 December 2026 to take the necessary steps to comply with the machine-readable marking obligation in Article 50(2). New systems do not inherit that blanket transition. This is a good example of why deployment date should be a field in every AI inventory.

The GPAI Track Runs on a Different Clock

General-purpose AI models are on their own regulatory track. The main GPAI provider obligations began applying on 2 August 2025, covering areas such as technical documentation, information for downstream providers, copyright-policy requirements and publication of a sufficiently detailed summary of training content. For models with systemic risk, additional evaluation, risk-assessment, incident and cybersecurity obligations apply. The important 2026 change is supervisory rather than a brand-new substantive start date: enforcement powers are now active for these obligations.

There is also a legacy-model date that belongs on every 2027 calendar. Article 111 provides that providers of GPAI models placed on the market before 2 August 2025 must take the necessary steps to comply by 2 August 2027. That transition can matter when a model family has been iterated after its original release, because the Commission’s current guidance treats version lineage and the underlying pre-training run as relevant to determining whether a release is a new model for AI Act purposes.

For UK organisations, the point is especially easy to miss because there is no domestic equivalent of the EU’s horizontal AI Act. Our UK AI regulation explainer sets out why a British headquarters can still face EU obligations when it places a system or model on the Union market or when statutory territorial rules are otherwise met. A UK compliance matrix therefore needs a model-provider column even if the organisation thinks of itself primarily as a software or services company.

The practical workflow is to separate the system inventory from the model inventory. Record which upstream GPAI model each product depends on, the model version or lineage, contract and documentation source, release date, provider, and whether the downstream product makes substantial modifications. That allows a team to track its own duties without assuming the upstream provider’s compliance file transfers automatically downstream.

2 December 2026 Adds a New Compliance Layer

The next fixed date after August is 2 December 2026. Two distinct developments converge on it. First, the Omnibus adds new prohibited AI practices concerning generation of non-consensual sexually explicit or intimate content and child sexual abuse material. Second, the transition for certain providers with synthetic-content-generating systems already placed on the market before 2 August 2026 expires for the Article 50(2) machine-readable marking requirement.

These are not cosmetic content-policy changes. They affect architecture, safety tooling, abuse monitoring, incident handling and product governance. A provider that waits until late November to identify whether an existing model can produce covered outputs may discover that the mitigation is not a policy toggle. It may require changes to generation controls, classifier layers, user reporting, provenance signals, model access rules or moderation escalation. Where criminal law or child-safety regimes also apply, the AI Act is only one layer of the legal stack.

The connection to privacy is also practical. Generative systems increasingly combine persistent memory, inferred attributes and multimedia generation, which can create harm without a conventional data breach. Our analysis of AI privacy risks in 2026 examines how memory and inference compound those risks. Compliance teams should therefore connect the December prohibition review to privacy impact assessments, access control and retention design instead of treating it as a standalone trust-and-safety exercise.

Industry reaction to the Omnibus shows the tension. Guido Lobrano, ITI Director General for Europe, called the high-risk delay and industrial streamlining ‘welcome and necessary steps’, while warning about tight marking and labelling deadlines. That is the right operational reading: extra time in one part of the Act does not create extra time everywhere.

“The delay on high-risk requirements and the move to streamline rules for industrial AI are welcome and necessary steps.”

Guido Lobrano, Director General for Europe, ITI, 7 May 2026

Why 2027 Is Really Three Different Milestones

2027 is often described as the year the delayed rules arrive, but it contains at least three separate regulatory events. On 2 August, Member States should have at least one AI regulatory sandbox operational. The same date is the transition deadline for GPAI models placed on the market before 2 August 2025. Four months later, on 2 December, the Annex III high-risk requirements begin to apply.

The sandbox date matters because the AI Act treats supervised experimentation as part of the compliance ecosystem rather than an exemption from law. National sandboxes are intended to give providers, prospective providers and other eligible participants a structured environment to develop, train, validate and test innovative AI systems under regulatory oversight. Companies should monitor the authority and admission criteria in the Member State most relevant to their establishment or testing plan rather than assuming a single EU-wide application route.

National enforcement capacity will also become less abstract. Ireland is a useful example because many global technology companies maintain European operations there. Our reporting on the AI Office of Ireland shows how national legislation is building the domestic machinery required for coordination, complaints, supervision and sanctions. Similar institutional mapping matters in every Member State where a company has operations, customers or regulated deployments.

The fixed 2 December 2027 date provides more certainty than an open-ended standards trigger, but harmonised application will still depend on guidance, standards, authority practice and sector-specific supervision. The compliance plan for 2027 should therefore include regulator engagement and standards monitoring, not only a legal deadline reminder. Organisations operating in several Member States should also document which national authority owns which part of the supervisory relationship, because practical enforcement remains distributed even under a single EU regulation.

What Annex III High-Risk Compliance Will Require

When the Annex III rules apply on 2 December 2027, the obligation is not a single certification event. The AI Act expects a controlled lifecycle around high-risk systems. Core requirements include a risk-management system, data and data-governance controls, technical documentation, record keeping, information for deployers, human oversight, and appropriate levels of accuracy, robustness and cybersecurity. Providers also face quality-management and post-market obligations, while deployers have their own operational duties under Article 26.

For employment, education, access to essential services, certain biometric uses, migration and law-enforcement contexts, the difficult work is often upstream of legal drafting. Teams need to decide the intended purpose precisely, identify whether a system falls within an Annex III category, document data provenance and representativeness, define meaningful human oversight, and preserve logs that support investigation. A generic responsible-AI policy cannot substitute for system-level evidence.

Bias testing is a useful example. The regulation allows tightly conditioned processing of special categories of personal data for bias detection and correction in specified circumstances, but that does not make broad sensitive-data collection automatically lawful or necessary. Our AI bias audit guide shows why subgroup performance, proxy variables, threshold choices and feedback loops need to be tested against the actual decision context. Fairness is not a single score, and a compliant audit should explain what metric was chosen and why.

Cecilia Bonefeld-Dahl, Director General of DIGITALEUROPE, argued after the Omnibus deal that ‘Europe can lead on AI safety without adding additional burden to its companies.’ Whether that balance is achieved will depend heavily on standards and sector overlap. For implementation teams, the safest assumption is that 2027 preparation should produce reusable engineering evidence, not paperwork created only for a conformity checkpoint.

“Europe can lead on AI safety without adding additional burden to its companies.”

Cecilia Bonefeld-Dahl, Director General, DIGITALEUROPE, 7 May 2026

Enforcement, Regulators and Penalty Exposure

Enforcement is distributed. National competent authorities and market-surveillance bodies handle much of the system-level regime. The European Commission’s AI Office has central powers for GPAI models and additional oversight in defined situations, while the European Data Protection Supervisor acts for EU institutions and bodies within its remit. The Digital Omnibus also clarified parts of this allocation, including AI systems based on GPAI where the model and system are developed by the same provider, subject to specific exceptions.

For cross-border organisations, this structure means the regulator map should sit next to the system map. Record the relevant Member States, sector regulator, market-surveillance authority, data-protection authority, and whether the AI Office has a direct role. Our UK AI policy analysis explains the dual-stack problem for British organisations: UK law can govern the domestic use while EU AI Act duties attach to EU-facing activity. The same product may therefore need evidence that satisfies multiple regulators with different statutory bases.

Penalty ceilings are high enough to make classification errors a board issue. Article 99 sets an upper limit of EUR 35 million or 7% of worldwide annual turnover for prohibited practices, whichever is higher for undertakings. Breaches of listed operator obligations, including Article 50 transparency duties, can reach EUR 15 million or 3%. Supplying incorrect, incomplete or misleading information to authorities can reach EUR 7.5 million or 1%. For SMEs, the relevant ceiling is the lower of the fixed amount or percentage.

GPAI providers face a separate Commission fine regime under Article 101, with penalties up to 3% of worldwide annual turnover or EUR 15 million, whichever is higher, for intentional or negligent infringements and certain failures to cooperate. These are ceilings, not automatic tariffs. Authorities must consider circumstances such as gravity, duration, responsibility, mitigation and cooperation.

Infringement / RegimeMaximum CeilingOperational Note
Prohibited AI practices, Article 5EUR 35m or 7% worldwide annual turnoverFor undertakings, the higher ceiling applies; SMEs receive the lower fixed-or-percentage approach under Article 99(6).
Listed operator duties, including Article 50EUR 15m or 3% worldwide annual turnoverCovers several provider, importer, distributor, deployer and transparency obligations.
Incorrect, incomplete or misleading informationEUR 7.5m or 1% worldwide annual turnoverApplies to information supplied to notified bodies or competent authorities in reply to a request.
GPAI provider fines, Article 101EUR 15m or 3% worldwide annual turnoverCommission regime for intentional or negligent infringements and defined cooperation failures.

A Role-First Compliance Roadmap for 2026 to 2027

The most reliable implementation method is to organise work by legal role and date rather than by department. A product team may call itself a buyer of AI, but a substantial modification or a change of intended purpose can shift responsibilities. A business that rebrands a third-party system can also create provider obligations in defined circumstances. The inventory therefore needs both a technical owner and a legal-role owner.

Start with what is already enforceable. Confirm prohibited-use screening, AI literacy governance, GPAI dependencies and Article 50 disclosures. Then create the December 2026 workstream for synthetic-content marking and the new prohibitions. Only after those live duties are controlled should the programme use the additional runway to build the Annex III evidence package for December 2027. This prevents the common failure mode where a company spends a year designing a high-risk conformity process but leaves an obvious chatbot disclosure unresolved.

Boniface de Champris, AI Policy Lead at CCIA Europe, described a ‘glaring gap between political rhetoric on regulatory simplification and concrete outcomes’. Whatever one’s policy view, the quote highlights a planning truth: the Omnibus simplifies some overlaps and delays some dates, but the compliance architecture remains multi-layered. Organisations need a programme that can absorb future standards and guidance without rebuilding every control.

The table below converts that into ownership. It is intentionally evidence-focused. The deliverable for each phase is something an auditor, regulator or internal reviewer can inspect, not a statement that the company intends to comply.

“the glaring gap between political rhetoric on regulatory simplification and concrete outcomes is hard to ignore.”

Boniface de Champris, AI Policy Lead, CCIA Europe, 7 May 2026

PhaseEvidence to ProduceSuggested Owner
Now through Q4 2026AI inventory, role classification, prohibited-use review, Article 50 UX evidence, GPAI dependency registerLegal + product + security
By 2 December 2026Synthetic marking validation, new-prohibition abuse tests, release-date evidence for transition eligibilityTrust & safety + engineering
H1 2027High-risk candidate register, data lineage, logging design, human oversight procedures, authority mapRisk + engineering + DPO
By 2 August 2027Legacy GPAI compliance file where relevant; sandbox participation decisionModel governance + public policy
Before 2 December 2027Annex III conformity evidence, quality management, technical documentation, post-market and incident workflowsProvider compliance leadership

Role and Obligation Matrix

RoleTypical Trigger2026-2027 Focus
ProviderDevelops or has an AI system developed and places it on the market under its name or trademarkDesign compliance, documentation, Article 50 where relevant, high-risk provider controls
DeployerUses an AI system under its authority in a professional contextOperational instructions, human oversight, monitoring, disclosure and sector duties
ImporterPlaces a third-country provider system on the Union marketProvider documentation and conformity checks, identification and cooperation
DistributorMakes an AI system available in the EU supply chainVerification, storage/transport conditions where relevant, corrective cooperation
GPAI providerPlaces a general-purpose AI model on the EU marketModel documentation, downstream information, copyright policy, training summary and systemic-risk duties where applicable

What the Digital Omnibus Changed, and What It Did Not

The Digital Omnibus changed the implementation path without changing the AI Act’s basic philosophy. It fixed later dates for high-risk systems, moved the national sandbox deadline, added new prohibited practices, created a limited transition for certain synthetic-content marking, extended some simplified treatment beyond SMEs to small mid-cap companies, adjusted sectoral overlap and clarified elements of the AI Office’s supervisory role. For industrial AI, the machinery treatment was a particularly visible change because the co-legislators sought to reduce duplicative conformity requirements.

What it did not do is equally important. The AI Act remains a risk-based horizontal regulation. Existing prohibited practices did not disappear. GPAI obligations did not reset to 2027. Article 50 transparency did not move wholesale to the high-risk date. The Act’s territorial reach and operator roles remain central to scope. Nor does the delay suspend GDPR, product safety, consumer protection, employment, equality, cybersecurity or sector-specific law that may govern the same system today.

This is why the best use of the extra time is standards-ready engineering. High-risk providers can build traceability, logging, data-governance, human-oversight and risk-management controls now, then map final harmonised standards or common specifications onto evidence that already exists. Waiting for every standard to be final before creating an inventory or logging strategy is the regulatory equivalent of waiting for building regulations before deciding where the foundations go.

The broader market backdrop makes delay risky for another reason. Eurostat reported that 20.0% of EU enterprises with at least 10 employees used AI in 2025, up from 13.5% in 2024. Adoption was 17.0% among small enterprises, 30.4% among medium enterprises and 55.0% among large enterprises. More systems will enter scope before December 2027 than existed when the original Act was negotiated.

Governance is not keeping pace with adoption. A 2026 UNESCO and Thomson Reuters Foundation report drawing on public disclosures from 3,000 companies found that 44% reported an AI strategy, while only about one in ten publicly committed to a recognised AI governance framework. That gap is a useful warning against reading a delayed statutory date as permission to delay governance work.

Three Timeline Traps That Still Catch Compliance Teams

The first trap is treating application, enforcement and transition as synonyms. A provision can apply from one date, an authority can acquire the power to enforce it from another, and a narrow transition can protect only systems already placed on the market before a specified cut-off. A board slide that says simply ‘AI Act deadline: December 2027’ is therefore too coarse to guide engineering or product release decisions. The compliance calendar should name the article, the actor, the legal event and the affected asset for every date.

The second trap is missing market-placement history. The Article 50(2) transition for certain existing synthetic-content systems depends on whether the system was already on the market before 2 August 2026. The legacy GPAI transition depends on placement before 2 August 2025. These facts should be evidenced through release records, contracts, product announcements or deployment documentation. A date inferred later from memory is weak evidence when a regulator is asking why a system was treated as transitional.

The third trap is separating legal scope from change management. For some high-risk AI systems placed on the market or put into service before 2 August 2026, later significant design changes can alter whether the new regime applies. That makes release notes, intended-purpose decisions and architecture changes part of compliance evidence. A material feature change can matter legally even if the product name remains the same.

The most resilient control is a three-register reconciliation each quarter: the AI system inventory, the model and version register, and the software change log. If those records disagree about what is deployed, which model lineage powers it, when it entered the EU market or what purpose it serves, the timeline cannot be applied reliably. This is a relatively low-cost governance practice that can prevent high-cost classification mistakes before the 2027 high-risk deadline.

Our Editorial Verification Process

This article uses an explainer and regulatory-timeline verification methodology. I cross-checked the AI Act Service Desk implementation timeline and enforcement FAQ, the final text of Regulation (EU) 2026/1744 on EUR-Lex, Article 99 penalty provisions, and the Commission’s 31 July 2026 enforcement announcement. For adoption and governance context, I used Eurostat’s 2025 enterprise AI data and the 2026 UNESCO and Thomson Reuters Foundation Responsible AI in Practice report. Direct quotations were taken from 2026 statements by Henna Virkkunen, Cecilia Bonefeld-Dahl, Guido Lobrano and Boniface de Champris, with wording kept short and attributed to the issuing institution.

The core fact-check was date reconciliation. Older 2024 and early-2026 versions of the AI Act calendar still show high-risk obligations beginning in August 2026 or August 2027. I treated the post-Omnibus Commission timeline as controlling for this article and separated application dates from enforcement powers, transition periods and legacy-system rules. I also checked that penalty figures were presented as statutory ceilings rather than predicted fines.

The requested XML sitemap endpoints did not return parseable sitemap content through the browsing layer during production. I therefore used the editorial brief’s fallback and selected eight live, indexed Perplexity AI Magazine pages with direct relevance to EU enforcement, transparency, small-business compliance, UK/EU scope, privacy, bias and Irish enforcement. Each internal URL is used once in a body section only.

This is a legal-policy explainer, not a software product review. A commercial pricing matrix, software feature inventory and API integration catalogue are therefore not applicable. No product price is presented as a compliance fact.

This article was researched and drafted with AI assistance and reviewed by the Awais Khalid editorial desk at Perplexity AI Magazine. All data, citations, pricing figures, and named quotes have been independently verified against primary sources before publication.

Conclusion

The corrected EU AI Act calendar is less dramatic than the old August 2026 countdown and more demanding in practice. Enforcement is already real for the rules that apply today. Article 50 transparency, prohibited practices, AI literacy and GPAI obligations cannot be postponed simply because the most complex high-risk requirements moved later.

The next sequence is clear. 2 December 2026 closes a synthetic-content marking transition and activates new prohibitions. 2 August 2027 brings regulatory sandbox and legacy GPAI milestones. 2 December 2027 is the key Annex III high-risk date, followed by 2 August 2028 for many embedded product systems. Beyond that, legacy and public-sector transitions extend into 2030.

The open questions are mostly about implementation quality rather than calendar arithmetic. Harmonised standards, sector guidance, national regulator practice and early enforcement decisions will determine how consistently the regime works across 27 Member States. Companies cannot control that evolution. They can control whether their own inventories, system roles, version history, disclosure evidence, logs, risk files and human-oversight procedures are good enough to adapt when the next layer becomes enforceable.

Frequently Asked Questions

What Is the EU AI Act Timeline for 2026 and 2027?

In 2026, Article 50 transparency rules and enforcement powers for applicable provisions became active on 2 August. On 2 December 2026, new prohibitions apply and a limited Article 50(2) transition ends. On 2 August 2027, regulatory sandbox and legacy GPAI milestones arrive. Annex III high-risk rules apply from 2 December 2027.

Did the EU AI Act High-Risk Rules Start on 2 August 2026?

No. The Digital Omnibus moved the main Annex III high-risk obligations to 2 December 2027. High-risk AI embedded in many regulated products under Annex I moves to 2 August 2028. However, other AI Act rules are already applicable and enforceable.

What Changed on 2 August 2026?

Article 50 transparency requirements started to apply, and the AI Office and national authorities began enforcing AI Act provisions that are already applicable. This includes relevant prohibited practices, transparency duties and GPAI obligations. The date is an enforcement milestone, not the start of every high-risk requirement.

What Is the 2 December 2026 AI Act Deadline?

It is the application date for new prohibitions targeting AI generation of non-consensual sexually explicit or intimate content and child sexual abuse material. It is also the deadline for certain synthetic-content-generating systems already on the market before 2 August 2026 to comply with Article 50(2) machine-readable marking.

What Happens on 2 August 2027 under the AI Act?

Member States should have at least one AI regulatory sandbox operational. Providers of GPAI models placed on the market before 2 August 2025 also reach their Article 111 transition deadline for compliance on 2 August 2027.

Which Systems Become High-Risk in December 2027?

The Annex III regime covers defined uses in areas such as biometrics, critical infrastructure, education, employment, access to certain essential services, law enforcement, migration and justice. Classification depends on the precise intended purpose and statutory conditions, so a sector label alone is not enough.

What Are the Maximum EU AI Act Fines?

Article 99 sets ceilings including EUR 35 million or 7% of worldwide annual turnover for prohibited practices and EUR 15 million or 3% for listed operator breaches including Article 50. SMEs generally face the lower of the fixed amount or percentage. GPAI providers have a separate Article 101 regime.

Does the EU AI Act Apply to UK or US Companies?

It can. The Act has territorial rules that can capture non-EU providers and deployers where systems or models are placed on the EU market or other statutory conditions are met. A company should assess the specific role, market activity and output location rather than relying on headquarters location.

References

  1. European Commission, AI Act Service Desk. (2026). Timeline for the implementation of the EU AI Act.
  2. European Parliament & Council of the European Union. (2026, July 8). Regulation (EU) 2026/1744 on simplification of AI Act implementation.
  3. European Commission. (2026, July 31). Commission starts enforcing AI Act rules and new transparency requirements on 2 August.
  4. European Commission, AI Act Service Desk. (2026). Article 99: Penalties.
  5. Eurostat. (2025, December 11). 20% of EU enterprises use AI technologies.
  6. UNESCO & Thomson Reuters Foundation. (2026). Responsible AI in practice: 2025 global insights from the AI Company Data Initiative.
  7. DIGITALEUROPE. (2026, May 7). AI omnibus: DIGITALEUROPE welcomes machinery breakthrough but warns medtech left behind.
  8. Information Technology Industry Council. (2026, May 7). EU AI Omnibus deal provides needed relief, but focus on simplification must continue.
  9. Computer & Communications Industry Association. (2026, May 7). AI Omnibus: EU negotiators miss opportunities as they seal deal.

Stay Ahead of AI

Get the latest AI news delivered to your inbox.

We don’t spam! Read our privacy policy for more info.