Six application dates carry Regulation (EU) 2024/1689 from February 2025 to August 2028. Two are behind you. The next one, 2 August 2026, is not the date most people think it is: the Digital Omnibus cleaved that single date into obligations that bite as written and obligations pushed to late 2027 and 2028, leaving Article 50 transparency exactly where it was and moving the marking duty and the entire high-risk regime later.
If you are drawing up an AI Act timeline for 2026, two dates belong on it, not one. This page walks every application date in order, states what starts applying and who it binds, and flags the one place where the published sources genuinely disagree.
Every EU AI Act key date in one table
Dates below are as amended by the Digital Omnibus. The 2 February 2027 row is the odd one out: it comes from a voluntary Code of Practice rather than from the regulation, and it is included because it lands inside the same planning window.
| Date | What starts applying | Who it binds | Status at 22 July 2026 |
|---|---|---|---|
| 2 Feb 2025 | Article 5 prohibited practices; Article 4 AI-literacy duty | Providers and deployers | Applied |
| 2 Aug 2025 | GPAI model obligations; governance provisions; Article 99 penalties | GPAI model providers; member states; enforcement bodies | Applied |
| 2 Aug 2026 | Article 50(1), 50(3) and 50(4) transparency; Article 50(2) marking for systems placed on the market from this date; AI Office enforcement begins | Providers for 50(1) and 50(2); deployers for 50(3) and 50(4) | Next deadline |
| 2 Dec 2026 | Article 50(2) marking for systems placed on the market before 2 Aug 2026; CSAM and non-consensual-intimate-imagery prohibition | Providers for marking; providers and deployers for the prohibition | Upcoming |
| 2 Feb 2027 | Watermark-detection interoperability under the Code of Practice on transparency of AI-generated content | Signatories to the Code | Upcoming, voluntary |
| 2 Dec 2027 | High-risk obligations for standalone Annex III systems: Articles 9 to 15, conformity assessment under Article 43, registration under Article 49 | Providers of standalone Annex III systems | Upcoming |
| 2 Aug 2028 | High-risk obligations for AI embedded in Annex I products | Providers and product manufacturers under Article 25(3) | Upcoming |
2025: the two dates already in force
Eight prohibited practices became unlawful that day, clarified by Commission guidelines published the same month: manipulative or deceptive techniques causing significant harm, exploitation of vulnerability, social scoring, individual predictive criminal-risk assessment based solely on profiling, untargeted facial-image scraping, emotion recognition in the workplace and in education, biometric categorisation inferring sensitive traits, and real-time remote biometric identification in public spaces for law enforcement. Article 4 sits alongside them and binds both providers and deployers to ensure a sufficient level of AI literacy among the staff who operate their systems.
This is the date the regulation acquired teeth. The Article 99 tiers have been enforceable since then: €35M or 7% of total worldwide annual turnover for Article 5 breaches, €15M or 3% for most other obligations including Article 50 and the high-risk regime, and €7.5M or 1% for supplying incorrect, incomplete or misleading information to authorities. Companies pay the higher of the fixed sum or the percentage; under Article 99(6) SMEs and start-ups pay the lower. The detail sits on the Article 99 penalty tiers and how enforcement is split.
The same date brought the baseline duties for general-purpose AI model providers under Art 53: Annex XI technical documentation, Annex XII downstream-provider information, a copyright policy and a public summary of training data. The GPAI Code of Practice had been published by the AI Office and the Commission on 10 July 2025 and was formally approved on 1 August 2025, one day before the obligations applied. See the GPAI model obligations and the systemic-risk threshold for what each tier owes.
One part of this date did not land. Article 70 required member states to designate national competent authorities by 2 August 2025, and only 8 of the 27 did so on time, with the DGCCRF in France, AESIA in Spain and the Bundesnetzagentur in Germany among the front-runners. A missing authority does not suspend your obligations, but the enforcement map you plan against is still being drawn.
2 August 2026: Article 50 transparency and AI Office enforcement
Three duties start on this date, and they are split between two different roles. Art 50(1) is a provider duty: a system intended to interact directly with natural persons has to be designed so those persons are informed they are interacting with an AI, unless that is obvious to a reasonably well-informed, observant and circumspect person. Art 50(3) is a deployer duty: inform the natural persons exposed to an emotion recognition or biometric categorisation system, and process their personal data in line with the GDPR. Art 50(4) is also a deployer duty, and it carries two limbs: disclose deepfakes, in a form that does not hamper enjoyment of the work where the content is evidently artistic, creative, satirical or fictional; and disclose AI-generated or manipulated text published to inform the public on matters of public interest, unless the text underwent human review or editorial control and a natural or legal person holds editorial responsibility for it.
Article 50 catches a far broader population than the high-risk regime does. Any customer-facing chatbot, any generative content tool, any deepfake. That is why this date, not 2 December 2027, is the nearest hard cliff for most businesses. The duty by duty breakdown is on the Article 50 transparency obligations, provider and deployer duties split out.
The delay headline is the trap on this page. Organisations that stood down an AI Act programme on hearing that deadlines moved have exposure on 2 August 2026, not in 2027. Only the 50(2) marking duty and the high-risk regime moved. If you are re-checking a single assumption today, make it this one: what actually applies on 2 August 2026, duty by duty.
2 December 2026: synthetic-content marking and a ninth prohibition
The marking duty, and who the later date actually helps
Art 50(2) requires providers of systems generating synthetic audio, image, video or text to mark the output in a machine-readable format detectable as artificially generated or manipulated, using solutions that are effective, interoperable, robust and reliable. Systems performing an assistive function for standard editing, or not substantially altering the input data or its semantics, are excepted, as are law-enforcement uses.
Read that scope carefully, because it is narrower than it looks. The 2 December 2026 date is a grace period for generative systems already on the market before 2 August 2026. A system placed on the market on or after that day complies from placement. Ship a new generative feature in September 2026 and the December date does nothing for you.
The ninth prohibition
The Digital Omnibus adds a ninth entry to the Article 5 list: AI systems that generate child sexual abuse material, or images, video or audio depicting an identifiable person in intimate or sexually explicit circumstances without their consent. Unlike the marking duty, this one binds deployers as well as providers, and compliance is due on the same 2 December 2026 date. Published commentary on the Omnibus reads the provider test broadly: it reaches any system where such generation is a reasonably foreseeable and reproducible outcome, without requiring significant technical modification. Marketing intent is not the test.
Three months or four: why this page gives you the date
Published summaries of the marking grace period disagree with each other. Council material and some firm briefings describe it as three months, which tracks the negotiating framing that cut a proposed six-month period to three. Other briefings call it four months, which is the literal calendar span from 2 August to 2 December 2026. Both appear in reputable sources, and both point at the same day.
So this page states the date. A month count is a derived figure, and derived figures break in two directions. Count three months forward from 2 August 2026 and you get 2 November, a month of unnecessary panic. Anchor either count to a different starting event, say entry into force rather than the transparency application date, and you drift past the deadline entirely. The date is the only number that survives being copied into a compliance calendar by someone who was not in the room.
If a vendor, an internal memo or a board pack gives you a month count for the marking grace period, replace it with 2 December 2026 before it propagates. The discrepancy is real in the sources, so expect to see both figures, and do not treat the disagreement as a sign that the deadline itself is soft.
2 December 2027 and 2 August 2028: the two high-risk dates
The eight Annex III areas are biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential private and public services and benefits (including credit scoring and risk assessment and pricing in health and life insurance), law enforcement, migration and border control, and the administration of justice and democratic processes. If your system sits in one of those and does not clear the derogation, Articles 9 to 15, conformity assessment under Article 43 and registration under Article 49 all bite on 2 December 2027. The routes are set out on how a system becomes high-risk under Annex I and Annex III.
The Annex I route catches AI that is a safety component of, or is itself, a product covered by Annex I harmonisation legislation requiring third-party conformity assessment. The Omnibus carved AI in Machinery Regulation products out of the direct AI Act high-risk rules and layered the AI-specific requirements into the Machinery Regulation instead. Medical devices and toys stay fully in scope of the AI Act route, on the 2 August 2028 date.
What the extension did not move
The seventeen months bought time on the obligation set, not on the classification. Under Art 6(4) a provider claiming the Article 6(3) derogation must document that assessment before placing the system on the market, and the Omnibus kept the requirement that systems self-assessed as non-high-risk still be registered in the EU database, in simplified form, after the Commission proposal to drop it failed in negotiations. Add to that the Commission missing its February 2026 statutory deadline for Article 6 classification guidelines, which means authoritative worked examples of a successful derogation are scarce and the conservative posture is the sensible default: document thoroughly, register, and assume that profiling of natural persons forecloses the derogation entirely, because Art 6(3) makes that an absolute bar. See the four Article 6(3) conditions and where the derogation gets over-claimed.
Why the original AI Act dates are still technically the baseline
The amended dates on this page come from the Digital Omnibus on AI, proposed as COM(2025) 836 on 19 November 2025. It reached trilogue agreement on 7 May 2026, a joint IMCO-LIBE position on 2 June 2026, adoption by the European Parliament on 16 June 2026 by 423 votes to 57 with 174 abstentions, adoption by the Council on 29 June 2026, and signature on 8 July 2026. As at the 22 July 2026 review date on this page it had not yet been published in the Official Journal. It enters into force on the third day after publication.
That gap has a precise consequence. The instrument in force today is Regulation (EU) 2024/1689 as originally adopted, so on the strict letter the original dates remain the baseline until publication. The amendment is agreed, voted and signed, so the content is not in doubt, but the consolidated text and the final Regulation (EU) 2026/... number will only be authoritative once they appear on EUR-Lex.
Practically, that means three things. Plan and resource against the amended dates, because they are final and no further negotiation is expected. Do not delete or pause work already completed against the original 2 August 2026 high-risk milestone, since that milestone is still the one written into the operative text. And cite carefully: in policies, contracts and board papers, write Regulation (EU) 2024/1689 as amended by the Digital Omnibus rather than a 2026 regulation number that does not exist yet.
Anything date-dependent you publish between now and Official Journal publication needs a visible review date attached, because the moment the consolidated text appears, every citation in it should be updated to the final number. The change history is set out on what the Digital Omnibus changed and what survived negotiations.
Planning backwards from each AI Act deadline
Every date in the table is the date an obligation starts to apply, not the date you can start work. Two of them have earlier real deadlines hidden inside them.
For 2 August 2026, the disclosure design work under Article 50(1) is product work, not paperwork: the requirement is that the system be designed so the person is informed, and disclosures must be clear and distinguishable at the latest at the first interaction or exposure under Art 50(5). That has to land in a release, which means the engineering deadline sits before the legal one.
For 2 December 2027, the binding constraint is Article 6(4) and Annex IV. Technical documentation is drawn up before the system is placed on the market, kept up to date and retained for around ten years, with a simplified form available to SMEs under Article 11(2). If your next release of an Annex III system lands after 2 December 2027, its documentation has to be complete before it ships, not after. The nine blocks are listed on what Annex IV technical documentation has to contain.
And check your role before you plan any of it. Under Art 25 a deployer, importer or distributor becomes a provider, inheriting the full Article 16 obligation set, by putting its name or trademark on a high-risk system, by making a substantial modification that keeps the system high-risk, or by modifying the intended purpose of any system, including a general-purpose AI system, so that it becomes high-risk. Buying a system does not keep you on the deployer timetable if one of those triggers has fired. Roles are unpacked on provider, deployer and the three acts that trigger the Article 25 flip.
If you are not certain which of these dates your system is actually on, the free seven-stage classifier runs scope, prohibitions, Annex I and Annex III, the derogation, GPAI, Article 50 and role in order, and returns the deadline that attaches to your answers along with the article it rests on. The Commission maintains its own overview of the framework on the European Commission AI policy pages.