Skip to main content

EU AI Act Compliance Deadlines, and the Timeline as It Stands Now

Petr Mikeska
Petr Mikeska
CEO & Co-Founder

Updated · Published

The EU AI Act timeline is no longer the one most compliance plans were built against. A simplification regulation adopted in June 2026 pushed the high-risk obligations out to 2 December 2027 for stand-alone systems and 2 August 2028 for AI embedded in products. What did not move is just as important: transparency obligations and enforcement started on 2 August 2026 and are live now. This article sets out the corrected timeline, what each date actually requires, and why the extension is less generous than it sounds.

Understanding the EU AI Act and Its Impact on Businesses

The EU Artificial Intelligence Act, Regulation (EU) 2024/1689, is the world's first comprehensive AI regulation, setting harmonized rules for the development, deployment, and use of artificial intelligence within the European Union. It was adopted on 13 June 2024, published in the Official Journal on 12 July 2024, and entered into force on 1 August 2024. It establishes a risk-based framework that classifies AI systems as prohibited, high-risk, general-purpose, or limited-risk.

Its obligations were never meant to arrive all at once. They were staged over several years, and in June 2026 that staging was rewritten. If your compliance plan was built before then, the dates in it are out of date, and the section below is the reason.

What the Omnibus Changed, and What It Did Not

On 29 June 2026 the Council of the EU gave final approval to a regulation simplifying parts of the AI Act, following the European Parliament's plenary vote on 15 June, carried by 423 votes to 57 with 174 abstentions. The Council describes it as part of the Omnibus VII package under the EU's simplification agenda.

Given that provisions on high-risk AI systems were due to enter into force on 2 August 2026, the co-legislators treated this part of the package with utmost priority and agreed on a fixed timeline for the delayed application of high-risk rules: the new application dates would be 2 December 2027 for stand-alone high-risk AI systems and 2 August 2028 for high-risk AI systems embedded in products.

- Council of the EU, Artificial Intelligence: Council gives final green light to simplify and streamline rules, 29 June 2026

That is the headline, and it is the part most coverage stopped at. Four other changes in the same regulation matter as much for planning:

  • A new prohibition on AI systems that generate non-consensual sexual or intimate imagery and child sexual abuse material, which the Council says takes effect in December 2026.
  • National AI regulatory sandboxes postponed to 2 August 2027.
  • The grace period for providers to implement transparency solutions for artificially generated content cut from six months to three, with a deadline of 2 December 2026.
  • Clarified AI Office competences for supervising systems built on general-purpose models by the same provider, with exceptions where national authorities stay competent, including law enforcement, border management, judicial authorities and financial institutions.

What did not move is the part that catches most organizations. The Commission confirmed at the end of July 2026 that enforcement had begun:

From 2 August 2026, the European Commission's AI Office, together with national authorities, will begin enforcing the Artificial Intelligence (AI) Act. On the same date, new transparency rules will start to apply, requiring certain AI systems to tell users when they are interacting with AI and when content has been generated or altered by it.

- European Commission, Commission starts enforcing AI Act rules and new transparency requirements on 2 August, 31 July 2026

So the picture is not "the AI Act has been delayed". Enforcement is live, transparency is live, and the prohibitions have applied since early 2025. What moved is one, admittedly large, block of obligations. For the wider strategic implications beyond the dates, see our piece on what the AI Omnibus changes for AI strategy.

Key EU AI Act Compliance Deadlines

The corrected timeline, with the original date shown where it has been superseded.

DateWhat appliesStatus
2 Feb 2025 Prohibited AI practices under Article 5, and AI literacy obligations In force
2 Aug 2025 General-purpose AI model obligations, governance structures, notified bodies, penalties In force
2 Aug 2026 Transparency obligations, and the start of enforcement by the AI Office and national authorities In force
2 Dec 2026 New prohibition on AI-generated non-consensual intimate imagery and CSAM. Transparency grace period ends Coming
2 Aug 2027 National AI regulatory sandboxes must be established Coming, postponed
2 Dec 2027 Stand-alone high-risk AI systems, the Annex III categories Coming, moved from 2 Aug 2026
2 Aug 2028 High-risk AI embedded in products regulated under EU product safety law, the Annex I categories Coming, moved from 2 Aug 2027

Two rows deserve expanding, because they are where most of the work sits.

2 August 2026, transparency. Chatbots and other interactive systems must tell users they are dealing with AI rather than a human. Deepfakes must be labeled. AI-generated or altered content must carry machine-readable marks so it can be detected. This is live, it is being enforced, and it applies to a great many organizations that do not consider themselves AI companies at all.

2 December 2027 and 2 August 2028, high-risk. The Annex III categories cover stand-alone systems used in employment decisions, education, essential private and public services including creditworthiness, law enforcement, migration, and critical infrastructure. Annex I covers AI embedded as a safety component in products already regulated under EU product safety law. High-risk systems face requirements for risk management, data governance, technical documentation, record-keeping, human oversight, accuracy and robustness.

How Businesses Can Prepare for EU AI Act Compliance

The extension is less generous than it looks. Classifying systems, reconstructing what data trained them, and establishing traceability are slow, and none of that work got shorter. What changed is when it is due.

1. Inventory and classify. Establish which AI systems exist across the organization and which category each falls into: prohibited, high-risk under Annex III or Annex I, general-purpose, or limited-risk. Most organizations discover during this step that they have more AI in production than anyone had listed, much of it embedded in purchased software.

2. Deal with transparency first. It is the obligation that is already enforceable. Anything customer-facing that generates or alters content, or that talks to a person, needs its disclosure and marking in place now rather than in 2027.

3. Document training data and lineage. High-risk obligations require knowing what data a system was built on and being able to show it. That is a lineage problem, and reconstructing lineage after the fact is considerably harder than capturing it as you go.

4. Assign ownership. Each AI system needs a named owner accountable for its classification, documentation and oversight. An inventory with no owners degrades within a quarter.

5. Track the guidance, not just the regulation. The Commission continues to issue guidance and implementing acts, including the mechanism for resolving overlaps between AI Act high-risk requirements and sector-specific law in areas such as medical devices and machinery. The dates above are the frame, not the whole picture.

How Dawiso Can Help with AI Compliance and Governance

Most of what the AI Act asks for at the documentation level is metadata work, which is what a governed data catalog already does.

  • An AI use case inventory. A central record of which AI systems exist, what they are used for, who owns them, and how each is classified.
  • Traceability of the data behind them. Lineage from source systems through to the datasets a model was trained or grounded on, captured continuously rather than reconstructed under audit pressure.
  • Shared definitions and classification. Knowing which data is sensitive, where it lives, and what it means, which is the foundation of the data governance requirements for high-risk systems.
  • Documentation that stays current. Records tied to the assets themselves rather than to a document that ages the moment the system changes.

More about our approach on the AI governance page.

Final Thoughts

The Omnibus bought time on one block of obligations and took none away from the rest. Prohibitions have applied since February 2025. General-purpose AI obligations since August 2025. Transparency and enforcement since August 2026. The high-risk deadline moved to December 2027 and August 2028, which sounds like breathing room until you price the work of classifying every AI system in an organization and evidencing what data sits behind each one.

The organizations that will find those dates comfortable are the ones treating the extension as time to do the inventory, not time to postpone it.

FAQ

What are the EU AI Act deadlines after the Omnibus?
The dates already in force are 2 February 2025 for prohibited practices and AI literacy, 2 August 2025 for general-purpose AI obligations and governance, and 2 August 2026 for transparency obligations and the start of enforcement. Still ahead are 2 December 2026 for the new prohibition on non-consensual intimate imagery and CSAM and for the shortened transparency grace period, 2 August 2027 for national regulatory sandboxes, 2 December 2027 for stand-alone high-risk AI systems, and 2 August 2028 for high-risk AI embedded in products.
Did the EU AI Act high-risk deadline move?
Yes. High-risk obligations were originally due to apply from 2 August 2026. Under the simplification regulation adopted by the Council on 29 June 2026, part of the Omnibus VII package, the new application dates are 2 December 2027 for stand-alone high-risk AI systems and 2 August 2028 for high-risk AI systems embedded in products. That is a delay of roughly 16 to 24 months.
What applies from 2 August 2026?
Enforcement and transparency. The Commission has confirmed that from 2 August 2026 its AI Office, together with national authorities, began enforcing the AI Act, and that new transparency rules started to apply on the same date. Chatbots and other interactive systems must tell users they are dealing with AI, deepfakes must be labeled, and AI-generated or altered content must carry machine-readable marks.
Does the delay mean businesses can wait?
Not really, for two reasons. Transparency obligations and enforcement are live now, so anything customer-facing is already in scope. And the high-risk work itself, classifying systems, documenting training data, establishing traceability and human oversight, takes far longer than the extension bought. The delay changes the deadline, not the volume of work.
What is the Digital Omnibus in relation to the AI Act?
It is a simplification package amending several pieces of EU digital law. The AI part was adopted by the European Parliament in plenary on 15 June 2026, by 423 votes to 57 with 174 abstentions, and given final approval by the Council on 29 June 2026, as part of what the Council calls the Omnibus VII package. Alongside delaying the high-risk dates it added a prohibition on AI-generated non-consensual sexual imagery and child sexual abuse material, postponed national regulatory sandboxes, shortened the transparency grace period, and clarified the AI Office supervisory role.
Which AI systems count as high-risk under the AI Act?
Two groups. Annex III covers stand-alone systems used in areas such as employment decisions, education, essential private and public services including creditworthiness, law enforcement, migration, and critical infrastructure. Annex I covers AI embedded as a safety component in products already regulated under EU product safety law, such as medical devices and machinery. The Omnibus gave the two groups different application dates, 2 December 2027 and 2 August 2028 respectively.

Sources

See it in action

AI Governance with Dawiso

Catalog your AI use cases, trace the data behind them, and keep the documentation an audit will ask for.

A cookie a day keeps bad UX away.

We use cookies to personalize content, ads and to analyze our traffic. We also share information about your use of our site with our advertising and analytics partners who may combine it with other information that you've provided to them or that they've collected from your use of their services. By clicking "Accept All", you allow us to use cookies for analytics and ads via Google Tag Manager. You can also customize cookies.

Customize Consent Preferences

We use cookies to personalize content, ads and to analyze our traffic. We also share information about your use of our site with our advertising and analytics partners. Privacy Policy

Necessary cookies allow core website functionality such as user login and account management. The website cannot be used properly without strictly necessary cookies.

Functionality cookies are used to remember visitor information on the website, eg. language, timezone, enhanced content.

Analytics cookies are used to see how visitors use the website, eg. analytics cookies. Those cookies cannot be used to directly identify a certain visitor.

We use Microsoft Clarity to see how you use our website (including heatmaps and session replays) so we can improve it. By using our site, you agree that we and Microsoft can collect and use this data. See our Privacy Policy for details.

Advertisement cookies are used to identify visitors between different websites, eg. content partners, banner networks. Those cookies may be used by companies to build a profile of visitor interests or show relevant ads on other websites.