What are the EU AI Act key dates and compliance timeline?

AI regulation: the EU AI Act

The EU AI Act is already partly live. It entered into force on 1 August 2024. Since 2 February 2025, the AI literacy rule and the core prohibited practices have applied. Since 2 August 2025, the GPAI, governance, penalties and notified-body rules have applied. Under the law formally in force on 21 July 2026, most remaining obligations still switch on from 2 August 2026. A separate Digital Omnibus has been adopted and signed but, as of 21 July 2026, is still awaiting Official Journal publication, so its later dates are not yet formally in force.

What this means

This page is the date map for the EU AI Act. It is not the main explainer for what the Act is. The key question is not whether the Act exists, because it already does, but which parts apply now, which parts are due next, and which dates may change because of the pending Digital Omnibus on AI.

As at 21 July 2026, the legal baseline is still Regulation (EU) 2024/1689 as published in the Official Journal on 12 July 2024 and in force since 1 August 2024. That means organisations should separate the timeline into two tracks. The first track is the law already in force today. The second is the Omnibus track, which has been adopted by Parliament and the Council and then signed, but is still awaiting Official Journal publication. Until that publication happens and the amending regulation enters into force, the current-law dates formally stand.

That distinction matters because the Omnibus does not rewrite the whole AI Act. It mainly pushes back parts of the high-risk timetable, adds new prohibited practices from December 2026, gives a short transition for certain synthetic-content systems under Article 50(2), and moves the national sandbox deadline. It does not move the AI literacy date, the prohibitions already in force, the GPAI rules, or the general start date for most Article 50 transparency obligations.

Why it matters

For most organisations, the AI Act timeline is now a governance problem before it is a drafting problem. A business may be a deployer for one tool, a provider for another, and a downstream integrator for a third. The dates that matter therefore depend on what type of system or model is involved, whether it is already on the Union market, whether it falls under Article 50 transparency rules, whether it is a GPAI model, whether it is high-risk under Annex III or Annex I, and whether a public authority is involved.

Getting the timeline wrong creates two opposite risks. One is premature complacency, especially if teams assume the Digital Omnibus has already changed the law before publication. The other is over-compliance or mistimed spending, for example if teams treat every high-risk project as if the same deadline still applies regardless of the pending Omnibus distinctions. Buyers, founders, product teams, legal leads, procurement teams and public-sector operators all need one dated view that separates what is already binding from what is only adopted and awaiting publication.

How it works

The baseline law in force now

The legal baseline as at 21 July 2026 remains Regulation (EU) 2024/1689, the AI Act. It was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024. The Commission's AI Act pages still describe that regulation as the live baseline and state that the Act is being phased in by date, not all at once.

The pending amending measure is the Digital Omnibus on AI, procedure 2025/0359(COD), in the form of PE-CONS 30/26. The European Parliament adopted the agreed text on 16 June 2026, the Council gave final approval on 29 June 2026, and the OEIL procedure file now shows the procedure as completed and awaiting publication in the Official Journal. As at 21 July 2026, no final regulation number, Official Journal citation or entry-into-force date was available on the official publication track. That means the Omnibus should be treated as adopted and awaiting publication, not yet as the law in force.

What already applies

The first switch-on date was 2 February 2025. From that date, the AI literacy rule in Article 4 and the prohibited-practices regime in Article 5 became applicable. In practical terms, this is why the Commission has already issued prohibited-practices guidance and AI-system-definition guidance, and why organisations cannot treat the whole AI Act as a future-only issue.

The second switch-on date was 2 August 2025. From that date, the notified-body rules in Chapter III Section 4, the GPAI rules in Chapter V, the governance regime in Chapter VII, the penalties rules in Chapter XII and Article 78 became applicable. The Commission's GPAI pages also make clear that providers of GPAI models have been under those obligations since 2 August 2025, and that the Commission's direct enforcement powers, including fines, apply from 2 August 2026.

What current law still sets for 2 August 2026

Under the law formally in force on 21 July 2026, 2 August 2026 remains the main next date. That is the current-law application date for the rest of the AI Act not already switched on earlier. In practice, that includes the main high-risk obligations, the Article 50 transparency regime, the Article 6 classification mechanics not already live, registration mechanics, innovation measures such as sandboxes, and the market-surveillance and remedies framework.

This point matters because many summaries now speak as if the 2026 date has already been rewritten. Formally, it has not. Until the Omnibus is published and enters into force, the current-law 2 August 2026 bucket still governs. If publication slips, that bucket remains the legal default even if policymakers clearly intend to amend it.

What the Omnibus would change once it enters into force

PE-CONS 30/26 keeps the early dates already in place for AI literacy, the existing prohibitions and GPAI. It does not move the general Article 50 start date, which is why the Commission's new Article 50 guidance still states that transparency obligations apply from 2 August 2026.

What the Omnibus does change is targeted and important. It adds new prohibited-practice points covering AI systems that generate or manipulate non-consensual intimate material and child sexual abuse material, with those new prohibitions applying from 2 December 2026. It also inserts Article 111(4), which gives providers of systems that generate synthetic audio, image, video or text content and were already placed on the market before 2 August 2026 until 2 December 2026 to comply with Article 50(2). That is a narrow transition for one part of Article 50, not a blanket postponement of Article 50.

The Omnibus also delays the application of Chapter III Sections 1 to 3 for high-risk systems. Standalone high-risk systems under Article 6(2) and Annex III move to 2 December 2027 as the outer limit. Embedded-product high-risk systems under Article 6(1) and Annex I move to 2 August 2028. The national sandbox deadline moves to 2 August 2027. And Articles 102 to 110 would apply from the entry into force of the amending regulation itself.

The future dates after 2026

If the Omnibus enters into force, 2 December 2026 becomes the first major post-publication date. That date would start the new prohibitions just described and would end the limited Article 50(2) transition for pre-2 August 2026 synthetic-content systems.

The next milestone would be 2 August 2027, when Member States would need to have at least one national AI regulatory sandbox operational. Then comes 2 December 2027, which the Commission now describes as the latest date for Annex III standalone high-risk obligations, unless the Commission brings that date forward because standards and other support tools are ready earlier. The next outer date is 2 August 2028 for Annex I high-risk systems embedded in products covered by Union harmonisation legislation. Finally, Article 111 keeps a long-tail public-authority backstop: providers and deployers of high-risk AI systems intended to be used by public authorities must take the necessary steps to comply by 2 August 2030.

How the bring-forward mechanism works

The Omnibus is not simply a delay package. On the high-risk side, it creates outer dates while preserving a route to application earlier than those outer limits. The Commission's standardisation page now explains this in plain terms: the latest date would be 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, but the Commission may decide on an earlier application date if support tools, including standards, are available earlier.

Operationally, that means compliance teams should not treat December 2027 and August 2028 as guaranteed rest periods. They are the outer limits in the amending text, not a promise that nothing can happen sooner. For businesses in Annex III categories, especially employment, education, essential services, law enforcement and migration contexts, this means timeline planning should still be linked to standards, guidance and Commission action, not only to the outer date.

Grandfathering and transition under Article 111

Article 111 is the AI Act's grandfathering provision. In broad terms, it protects certain systems already lawfully placed on the market or put into service before the relevant application date, unless they later undergo significant changes. For high-risk AI systems, that means old stock is not automatically pulled into the full new regime on day one in the same way as newly placed systems.

The Omnibus matters here in two ways. First, it rewrites Article 111(2) so that the transitional logic tracks the moved Chapter III dates, while keeping the 2 August 2030 public-authority backstop. Second, it adds a new Article 111(4) for providers of synthetic-content systems already on the market before 2 August 2026, giving them until 2 December 2026 to comply with Article 50(2). The recitals to PE-CONS 30/26 also clarify the intended reading of the grace period for high-risk systems by pointing to the first unit of the same type and model as the decisive reference point, provided the design remains unchanged.

Guidance, institutions and enforcement signals around the dates

The legal dates sit inside a broader implementation timetable. The Commission published prohibited-practices guidelines on 4 February 2025 and AI-system-definition guidelines on 6 February 2025. It published GPAI scope guidelines on 18 July 2025 and received the GPAI Code of Practice on 10 July 2025. The governance and enforcement architecture has also been live since August 2025 through the AI Office, the Board and national competent authorities, with the scientific panel and advisory forum established under that framework.

The next practical layer is 2026 guidance. On 20 July 2026 the Commission published the final Article 50 transparency guidelines and related Q and A material, expressly tied to obligations applying from 2 August 2026. The draft guidelines on classifying high-risk AI systems remain under targeted consultation until 23 July 2026. Those instruments do not change the legal dates on their own, but they affect readiness, classification and the real pace of implementation.

Examples

A provider of a general-purpose AI model is not waiting for 2027. Those obligations have applied since 2 August 2025. The practical next date for that provider is 2 August 2026, because that is when the Commission's enforcement powers, including fines, apply directly to GPAI compliance. For that reason, a GPAI provider's near-term work is about documentation, downstream information-sharing, systemic-risk processes where relevant, and deciding whether to use the GPAI Code of Practice as a compliance route.

A provider or deployer of a chatbot, deepfake generator or other synthetic-content system has a more mixed timetable. Under the law formally in force on 21 July 2026, Article 50 transparency obligations still apply from 2 August 2026. If the Omnibus enters into force before then, the general Article 50 date still stays in place, but systems already on the market before 2 August 2026 would get a limited transition until 2 December 2026 for Article 50(2). The same Omnibus would also start new prohibitions on systems generating non-consensual intimate material and child sexual abuse material from 2 December 2026.

A provider of a standalone high-risk system under Annex III, for example in employment, education, essential services or law-enforcement related use cases, faces the biggest date split. Under current law, the main high-risk regime still points to 2 August 2026. Under the adopted Omnibus text awaiting publication, that Annex III timetable would move to 2 December 2027 as an outer limit, and could be brought forward if standards and support tools are ready sooner. That means classification and evidence-building work should not stop simply because the political direction is toward delay.

Common misunderstandings

The Omnibus has already changed the law. Not yet. As at 21 July 2026, the official procedure status is completed and awaiting Official Journal publication. Until publication and entry into force, the current-law dates still formally govern.

The Omnibus delays everything in the AI Act. It does not. It does not move the AI literacy date, the prohibitions already in force, the GPAI rules, or the general Article 50 start date.

Article 50 transparency rules are postponed to 2 December 2026. That is a common misreading. The adopted text keeps the general Article 50 timeline. What it adds is a limited transition until 2 December 2026 for Article 50(2) compliance by providers of certain synthetic-content systems already on the market before 2 August 2026.

Annex III and Annex I high-risk systems now share the same deadline. They do not under the Omnibus text. Annex III standalone systems move to 2 December 2027 as an outer limit, while Annex I embedded-product systems move to 2 August 2028.

Grandfathering means legacy systems never need to comply. No. Article 111 is a transition rule, not a permanent exemption. Significant design changes can pull systems into the regime earlier, and high-risk systems intended for public-authority use still face a 2 August 2030 backstop.

Risks and boundaries

This article is a date map, not a full scope analysis of every AI Act obligation. It does not replace the work of deciding whether a product is an AI system, whether it is a GPAI model, whether it is high-risk, or which operator role applies. Those questions sit in adjacent materials such as eu-ai-act, high-risk-ai-system and general-purpose-ai-model.

The main legal uncertainty at the date of writing is not the substance of the adopted Omnibus text, but its publication status. As at 21 July 2026, the official record shows the legislative procedure completed and awaiting Official Journal publication. That means the final regulation number, Official Journal citation and entry-into-force date are still unknown. The current-law 2 August 2026 default therefore still matters, especially for any team making a go live decision before publication appears.

There is also an implementation boundary between statutory dates and operational readiness. Guidance, standards, delegated acts and enforcement practice shape how the dates work in real life. The Commission's transparency guidance is now final, but the high-risk classification guidance is still under consultation until 23 July 2026. And even if the Omnibus enters into force, the Annex III and Annex I outer dates should not be treated as the only planning dates because the Annex III track includes an earlier bring-forward mechanism tied to standards and support tools.

Nothing here is legal advice. For systems near the edge of Annex III, Annex I, Article 50 or GPAI, the decisive question is still the legal classification of the specific system, model and use context.

What to do next

Build one internal timeline that separates four buckets: already applicable, current-law 2 August 2026 items, Omnibus-only dates that apply only once the amendment enters into force, and Article 111 legacy-system transitions. Most confusion comes from mixing those buckets together.

Map each AI use case by regulatory track. At minimum, identify whether each system is: a GPAI model, an Article 50 transparency case, a possible Annex III high-risk system, a possible Annex I embedded-product system, or a legacy system already on the market. Also flag whether any system is intended for use by a public authority.

Do not pause preparation for 2 August 2026 just because the Omnibus has been politically finalised. Until publication, that date still formally governs the broad remaining AI Act application under current law. In parallel, prepare contingency plans for the Omnibus timeline so that publication does not catch the programme flat-footed.

For synthetic-content systems, review Article 50 readiness now. For high-risk candidates, keep working on classification, evidence, technical documentation and governance rather than waiting for the last future date. For GPAI providers, treat 2 August 2026 as an enforcement date, not a first-obligation date.

Finally, keep a standing watch on the Official Journal, the OEIL procedure file and Commission implementation pages. For this topic, a dated legal status line is part of the substance, not just a footnote.

FAQs

Is the EU AI Act already in force?

Yes. The AI Act entered into force on 1 August 2024. But its obligations apply in phases, so different parts have different live dates.

What is already applicable today?

Since 2 February 2025, Article 4 on AI literacy and Article 5 on prohibited practices have applied. Since 2 August 2025, the GPAI rules, governance regime, penalties rules, notified-body rules and Article 78 have applied.

What is the main next date under the law formally in force on 21 July 2026?

It is 2 August 2026. Under the current published AI Act, that is still the main application date for most remaining obligations, including the broad high-risk framework and Article 50 transparency.

Has the Digital Omnibus on AI already postponed the 2 August 2026 date?

Not formally, as at 21 July 2026. The Omnibus has been adopted and signed, but it is still awaiting Official Journal publication. Until it is published and enters into force, the current-law dates still stand.

Does the Omnibus change the GPAI timetable?

No in the main sense. GPAI obligations already applied from 2 August 2025 and the Omnibus does not move that track. The Commission's enforcement powers over GPAI providers apply from 2 August 2026.

Does the Omnibus move all Article 50 transparency obligations to December 2026?

No. The general Article 50 timetable stays at 2 August 2026. The adopted text only adds a limited transition until 2 December 2026 for Article 50(2) compliance by certain synthetic-content systems already on the market before 2 August 2026.

What is the difference between Annex III and Annex I in the Omnibus timeline?

Annex III covers standalone high-risk systems under Article 6(2). Under the Omnibus text, those obligations would apply by 2 December 2027 at the latest, with a possible earlier bring-forward. Annex I covers certain AI systems embedded in regulated products under Article 6(1), and that track would move to 2 August 2028.

What does Article 111 grandfathering actually do?

It creates transition rules for certain systems already placed on the market or put into service before the relevant application date. It is not a permanent carve-out. Significant design changes can trigger compliance earlier, and public-authority high-risk use still faces a 2 August 2030 backstop.

Sources