EU AI Act Compliance Deadlines, and the Timeline as It Stands Now
Updated · Published
The EU AI Act timeline is no longer the one most compliance plans were built against. A simplification regulation adopted in June 2026 pushed the high-risk obligations out to 2 December 2027 for stand-alone systems and 2 August 2028 for AI embedded in products. What did not move is just as important: transparency obligations and enforcement started on 2 August 2026 and are live now. This article sets out the corrected timeline, what each date actually requires, and why the extension is less generous than it sounds.
Understanding the EU AI Act and Its Impact on Businesses
The EU Artificial Intelligence Act, Regulation (EU) 2024/1689, is the world's first comprehensive AI regulation, setting harmonized rules for the development, deployment, and use of artificial intelligence within the European Union. It was adopted on 13 June 2024, published in the Official Journal on 12 July 2024, and entered into force on 1 August 2024. It establishes a risk-based framework that classifies AI systems as prohibited, high-risk, general-purpose, or limited-risk.
Its obligations were never meant to arrive all at once. They were staged over several years, and in June 2026 that staging was rewritten. If your compliance plan was built before then, the dates in it are out of date, and the section below is the reason.
What the Omnibus Changed, and What It Did Not
On 29 June 2026 the Council of the EU gave final approval to a regulation simplifying parts of the AI Act, following the European Parliament's plenary vote on 15 June, carried by 423 votes to 57 with 174 abstentions. The Council describes it as part of the Omnibus VII package under the EU's simplification agenda.
Given that provisions on high-risk AI systems were due to enter into force on 2 August 2026, the co-legislators treated this part of the package with utmost priority and agreed on a fixed timeline for the delayed application of high-risk rules: the new application dates would be 2 December 2027 for stand-alone high-risk AI systems and 2 August 2028 for high-risk AI systems embedded in products.
- Council of the EU, Artificial Intelligence: Council gives final green light to simplify and streamline rules, 29 June 2026
That is the headline, and it is the part most coverage stopped at. Four other changes in the same regulation matter as much for planning:
- A new prohibition on AI systems that generate non-consensual sexual or intimate imagery and child sexual abuse material, which the Council says takes effect in December 2026.
- National AI regulatory sandboxes postponed to 2 August 2027.
- The grace period for providers to implement transparency solutions for artificially generated content cut from six months to three, with a deadline of 2 December 2026.
- Clarified AI Office competences for supervising systems built on general-purpose models by the same provider, with exceptions where national authorities stay competent, including law enforcement, border management, judicial authorities and financial institutions.
What did not move is the part that catches most organizations. The Commission confirmed at the end of July 2026 that enforcement had begun:
From 2 August 2026, the European Commission's AI Office, together with national authorities, will begin enforcing the Artificial Intelligence (AI) Act. On the same date, new transparency rules will start to apply, requiring certain AI systems to tell users when they are interacting with AI and when content has been generated or altered by it.
- European Commission, Commission starts enforcing AI Act rules and new transparency requirements on 2 August, 31 July 2026
So the picture is not "the AI Act has been delayed". Enforcement is live, transparency is live, and the prohibitions have applied since early 2025. What moved is one, admittedly large, block of obligations. For the wider strategic implications beyond the dates, see our piece on what the AI Omnibus changes for AI strategy.
Key EU AI Act Compliance Deadlines
The corrected timeline, with the original date shown where it has been superseded.
| Date | What applies | Status |
|---|---|---|
| 2 Feb 2025 | Prohibited AI practices under Article 5, and AI literacy obligations | In force |
| 2 Aug 2025 | General-purpose AI model obligations, governance structures, notified bodies, penalties | In force |
| 2 Aug 2026 | Transparency obligations, and the start of enforcement by the AI Office and national authorities | In force |
| 2 Dec 2026 | New prohibition on AI-generated non-consensual intimate imagery and CSAM. Transparency grace period ends | Coming |
| 2 Aug 2027 | National AI regulatory sandboxes must be established | Coming, postponed |
| 2 Dec 2027 | Stand-alone high-risk AI systems, the Annex III categories | Coming, moved from 2 Aug 2026 |
| 2 Aug 2028 | High-risk AI embedded in products regulated under EU product safety law, the Annex I categories | Coming, moved from 2 Aug 2027 |
Two rows deserve expanding, because they are where most of the work sits.
2 August 2026, transparency. Chatbots and other interactive systems must tell users they are dealing with AI rather than a human. Deepfakes must be labeled. AI-generated or altered content must carry machine-readable marks so it can be detected. This is live, it is being enforced, and it applies to a great many organizations that do not consider themselves AI companies at all.
2 December 2027 and 2 August 2028, high-risk. The Annex III categories cover stand-alone systems used in employment decisions, education, essential private and public services including creditworthiness, law enforcement, migration, and critical infrastructure. Annex I covers AI embedded as a safety component in products already regulated under EU product safety law. High-risk systems face requirements for risk management, data governance, technical documentation, record-keeping, human oversight, accuracy and robustness.
How Businesses Can Prepare for EU AI Act Compliance
The extension is less generous than it looks. Classifying systems, reconstructing what data trained them, and establishing traceability are slow, and none of that work got shorter. What changed is when it is due.
1. Inventory and classify. Establish which AI systems exist across the organization and which category each falls into: prohibited, high-risk under Annex III or Annex I, general-purpose, or limited-risk. Most organizations discover during this step that they have more AI in production than anyone had listed, much of it embedded in purchased software.
2. Deal with transparency first. It is the obligation that is already enforceable. Anything customer-facing that generates or alters content, or that talks to a person, needs its disclosure and marking in place now rather than in 2027.
3. Document training data and lineage. High-risk obligations require knowing what data a system was built on and being able to show it. That is a lineage problem, and reconstructing lineage after the fact is considerably harder than capturing it as you go.
4. Assign ownership. Each AI system needs a named owner accountable for its classification, documentation and oversight. An inventory with no owners degrades within a quarter.
5. Track the guidance, not just the regulation. The Commission continues to issue guidance and implementing acts, including the mechanism for resolving overlaps between AI Act high-risk requirements and sector-specific law in areas such as medical devices and machinery. The dates above are the frame, not the whole picture.
How Dawiso Can Help with AI Compliance and Governance
Most of what the AI Act asks for at the documentation level is metadata work, which is what a governed data catalog already does.
- An AI use case inventory. A central record of which AI systems exist, what they are used for, who owns them, and how each is classified.
- Traceability of the data behind them. Lineage from source systems through to the datasets a model was trained or grounded on, captured continuously rather than reconstructed under audit pressure.
- Shared definitions and classification. Knowing which data is sensitive, where it lives, and what it means, which is the foundation of the data governance requirements for high-risk systems.
- Documentation that stays current. Records tied to the assets themselves rather than to a document that ages the moment the system changes.
More about our approach on the AI governance page.
Final Thoughts
The Omnibus bought time on one block of obligations and took none away from the rest. Prohibitions have applied since February 2025. General-purpose AI obligations since August 2025. Transparency and enforcement since August 2026. The high-risk deadline moved to December 2027 and August 2028, which sounds like breathing room until you price the work of classifying every AI system in an organization and evidencing what data sits behind each one.
The organizations that will find those dates comfortable are the ones treating the extension as time to do the inventory, not time to postpone it.
FAQ
What are the EU AI Act deadlines after the Omnibus?
Did the EU AI Act high-risk deadline move?
What applies from 2 August 2026?
Does the delay mean businesses can wait?
What is the Digital Omnibus in relation to the AI Act?
Which AI systems count as high-risk under the AI Act?
Sources
- EUR-Lex - Regulation (EU) 2024/1689, the AI Act
- European Parliament - AI Act: EP approves simplification measures and "nudifier" app ban, plenary vote 15 June 2026
- Council of the EU - Artificial Intelligence: Council gives final green light to simplify and streamline rules, 29 June 2026
- European Commission - Commission starts enforcing AI Act rules and new transparency requirements on 2 August, 31 July 2026
See it in action
AI Governance with Dawiso
Catalog your AI use cases, trace the data behind them, and keep the documentation an audit will ask for.