ISHIGHRISK AI
Key dates

The EU AI Act timeline, as amended

Every EU AI Act application date from February 2025 to August 2028, as amended by the Digital Omnibus, with what each one obliges and who it binds.

Reviewed 22 July 2026Regulation (EU) 2024/1689, as amended by the Digital Omnibus
In short

Six application dates carry the EU AI Act from 2 February 2025 to 2 August 2028, and two of them have already passed. Next is 2 August 2026 for Article 50 transparency and AI Office enforcement, then 2 December 2026 for machine-readable marking and the new CSAM prohibition, 2 December 2027 for standalone Annex III high-risk systems, and 2 August 2028 for Annex I embedded products. Sources describe the marking grace period as three months and as four; all of them land on 2 December 2026, so work from the date. Until the Digital Omnibus is published in the Official Journal the original AI Act dates remain the formal baseline, even though the amended dates are agreed, signed and final.

Six application dates carry Regulation (EU) 2024/1689 from February 2025 to August 2028. Two are behind you. The next one, 2 August 2026, is not the date most people think it is: the Digital Omnibus cleaved that single date into obligations that bite as written and obligations pushed to late 2027 and 2028, leaving Article 50 transparency exactly where it was and moving the marking duty and the entire high-risk regime later.

If you are drawing up an AI Act timeline for 2026, two dates belong on it, not one. This page walks every application date in order, states what starts applying and who it binds, and flags the one place where the published sources genuinely disagree.

Every EU AI Act key date in one table

Dates below are as amended by the Digital Omnibus. The 2 February 2027 row is the odd one out: it comes from a voluntary Code of Practice rather than from the regulation, and it is included because it lands inside the same planning window.

DateWhat starts applyingWho it bindsStatus at 22 July 2026
2 Feb 2025Article 5 prohibited practices; Article 4 AI-literacy dutyProviders and deployersApplied
2 Aug 2025GPAI model obligations; governance provisions; Article 99 penaltiesGPAI model providers; member states; enforcement bodiesApplied
2 Aug 2026Article 50(1), 50(3) and 50(4) transparency; Article 50(2) marking for systems placed on the market from this date; AI Office enforcement beginsProviders for 50(1) and 50(2); deployers for 50(3) and 50(4)Next deadline
2 Dec 2026Article 50(2) marking for systems placed on the market before 2 Aug 2026; CSAM and non-consensual-intimate-imagery prohibitionProviders for marking; providers and deployers for the prohibitionUpcoming
2 Feb 2027Watermark-detection interoperability under the Code of Practice on transparency of AI-generated contentSignatories to the CodeUpcoming, voluntary
2 Dec 2027High-risk obligations for standalone Annex III systems: Articles 9 to 15, conformity assessment under Article 43, registration under Article 49Providers of standalone Annex III systemsUpcoming
2 Aug 2028High-risk obligations for AI embedded in Annex I productsProviders and product manufacturers under Article 25(3)Upcoming

2025: the two dates already in force

2 Feb 2025Article 5 prohibitions and the Article 4 AI-literacy duty applied.

Eight prohibited practices became unlawful that day, clarified by Commission guidelines published the same month: manipulative or deceptive techniques causing significant harm, exploitation of vulnerability, social scoring, individual predictive criminal-risk assessment based solely on profiling, untargeted facial-image scraping, emotion recognition in the workplace and in education, biometric categorisation inferring sensitive traits, and real-time remote biometric identification in public spaces for law enforcement. Article 4 sits alongside them and binds both providers and deployers to ensure a sufficient level of AI literacy among the staff who operate their systems.

2 Aug 2025GPAI model obligations, the governance provisions and the penalties applied.

This is the date the regulation acquired teeth. The Article 99 tiers have been enforceable since then: €35M or 7% of total worldwide annual turnover for Article 5 breaches, €15M or 3% for most other obligations including Article 50 and the high-risk regime, and €7.5M or 1% for supplying incorrect, incomplete or misleading information to authorities. Companies pay the higher of the fixed sum or the percentage; under Article 99(6) SMEs and start-ups pay the lower. The detail sits on the Article 99 penalty tiers and how enforcement is split.

The same date brought the baseline duties for general-purpose AI model providers under Art 53: Annex XI technical documentation, Annex XII downstream-provider information, a copyright policy and a public summary of training data. The GPAI Code of Practice had been published by the AI Office and the Commission on 10 July 2025 and was formally approved on 1 August 2025, one day before the obligations applied. See the GPAI model obligations and the systemic-risk threshold for what each tier owes.

One part of this date did not land. Article 70 required member states to designate national competent authorities by 2 August 2025, and only 8 of the 27 did so on time, with the DGCCRF in France, AESIA in Spain and the Bundesnetzagentur in Germany among the front-runners. A missing authority does not suspend your obligations, but the enforcement map you plan against is still being drawn.

2 August 2026: Article 50 transparency and AI Office enforcement

2 Aug 2026Article 50(1), 50(3) and 50(4) transparency apply; AI Office enforcement begins.

Three duties start on this date, and they are split between two different roles. Art 50(1) is a provider duty: a system intended to interact directly with natural persons has to be designed so those persons are informed they are interacting with an AI, unless that is obvious to a reasonably well-informed, observant and circumspect person. Art 50(3) is a deployer duty: inform the natural persons exposed to an emotion recognition or biometric categorisation system, and process their personal data in line with the GDPR. Art 50(4) is also a deployer duty, and it carries two limbs: disclose deepfakes, in a form that does not hamper enjoyment of the work where the content is evidently artistic, creative, satirical or fictional; and disclose AI-generated or manipulated text published to inform the public on matters of public interest, unless the text underwent human review or editorial control and a natural or legal person holds editorial responsibility for it.

Article 50 catches a far broader population than the high-risk regime does. Any customer-facing chatbot, any generative content tool, any deepfake. That is why this date, not 2 December 2027, is the nearest hard cliff for most businesses. The duty by duty breakdown is on the Article 50 transparency obligations, provider and deployer duties split out.

The delay headline is the trap on this page. Organisations that stood down an AI Act programme on hearing that deadlines moved have exposure on 2 August 2026, not in 2027. Only the 50(2) marking duty and the high-risk regime moved. If you are re-checking a single assumption today, make it this one: what actually applies on 2 August 2026, duty by duty.

2 December 2026: synthetic-content marking and a ninth prohibition

2 Dec 2026Article 50(2) marking applies to systems placed on the market before 2 Aug 2026; the CSAM and non-consensual-intimate-imagery prohibition applies.

The marking duty, and who the later date actually helps

Art 50(2) requires providers of systems generating synthetic audio, image, video or text to mark the output in a machine-readable format detectable as artificially generated or manipulated, using solutions that are effective, interoperable, robust and reliable. Systems performing an assistive function for standard editing, or not substantially altering the input data or its semantics, are excepted, as are law-enforcement uses.

Read that scope carefully, because it is narrower than it looks. The 2 December 2026 date is a grace period for generative systems already on the market before 2 August 2026. A system placed on the market on or after that day complies from placement. Ship a new generative feature in September 2026 and the December date does nothing for you.

The ninth prohibition

The Digital Omnibus adds a ninth entry to the Article 5 list: AI systems that generate child sexual abuse material, or images, video or audio depicting an identifiable person in intimate or sexually explicit circumstances without their consent. Unlike the marking duty, this one binds deployers as well as providers, and compliance is due on the same 2 December 2026 date. Published commentary on the Omnibus reads the provider test broadly: it reaches any system where such generation is a reasonably foreseeable and reproducible outcome, without requiring significant technical modification. Marketing intent is not the test.

Three months or four: why this page gives you the date

Published summaries of the marking grace period disagree with each other. Council material and some firm briefings describe it as three months, which tracks the negotiating framing that cut a proposed six-month period to three. Other briefings call it four months, which is the literal calendar span from 2 August to 2 December 2026. Both appear in reputable sources, and both point at the same day.

So this page states the date. A month count is a derived figure, and derived figures break in two directions. Count three months forward from 2 August 2026 and you get 2 November, a month of unnecessary panic. Anchor either count to a different starting event, say entry into force rather than the transparency application date, and you drift past the deadline entirely. The date is the only number that survives being copied into a compliance calendar by someone who was not in the room.

If a vendor, an internal memo or a board pack gives you a month count for the marking grace period, replace it with 2 December 2026 before it propagates. The discrepancy is real in the sources, so expect to see both figures, and do not treat the disagreement as a sign that the deadline itself is soft.

2 December 2027 and 2 August 2028: the two high-risk dates

2 Dec 2027High-risk obligations apply to standalone Annex III systems, a seventeen-month extension from the original 2 August 2026 date.

The eight Annex III areas are biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential private and public services and benefits (including credit scoring and risk assessment and pricing in health and life insurance), law enforcement, migration and border control, and the administration of justice and democratic processes. If your system sits in one of those and does not clear the derogation, Articles 9 to 15, conformity assessment under Article 43 and registration under Article 49 all bite on 2 December 2027. The routes are set out on how a system becomes high-risk under Annex I and Annex III.

2 Aug 2028High-risk obligations apply to AI embedded in Annex I products.

The Annex I route catches AI that is a safety component of, or is itself, a product covered by Annex I harmonisation legislation requiring third-party conformity assessment. The Omnibus carved AI in Machinery Regulation products out of the direct AI Act high-risk rules and layered the AI-specific requirements into the Machinery Regulation instead. Medical devices and toys stay fully in scope of the AI Act route, on the 2 August 2028 date.

What the extension did not move

The seventeen months bought time on the obligation set, not on the classification. Under Art 6(4) a provider claiming the Article 6(3) derogation must document that assessment before placing the system on the market, and the Omnibus kept the requirement that systems self-assessed as non-high-risk still be registered in the EU database, in simplified form, after the Commission proposal to drop it failed in negotiations. Add to that the Commission missing its February 2026 statutory deadline for Article 6 classification guidelines, which means authoritative worked examples of a successful derogation are scarce and the conservative posture is the sensible default: document thoroughly, register, and assume that profiling of natural persons forecloses the derogation entirely, because Art 6(3) makes that an absolute bar. See the four Article 6(3) conditions and where the derogation gets over-claimed.

Why the original AI Act dates are still technically the baseline

The amended dates on this page come from the Digital Omnibus on AI, proposed as COM(2025) 836 on 19 November 2025. It reached trilogue agreement on 7 May 2026, a joint IMCO-LIBE position on 2 June 2026, adoption by the European Parliament on 16 June 2026 by 423 votes to 57 with 174 abstentions, adoption by the Council on 29 June 2026, and signature on 8 July 2026. As at the 22 July 2026 review date on this page it had not yet been published in the Official Journal. It enters into force on the third day after publication.

That gap has a precise consequence. The instrument in force today is Regulation (EU) 2024/1689 as originally adopted, so on the strict letter the original dates remain the baseline until publication. The amendment is agreed, voted and signed, so the content is not in doubt, but the consolidated text and the final Regulation (EU) 2026/... number will only be authoritative once they appear on EUR-Lex.

Practically, that means three things. Plan and resource against the amended dates, because they are final and no further negotiation is expected. Do not delete or pause work already completed against the original 2 August 2026 high-risk milestone, since that milestone is still the one written into the operative text. And cite carefully: in policies, contracts and board papers, write Regulation (EU) 2024/1689 as amended by the Digital Omnibus rather than a 2026 regulation number that does not exist yet.

Anything date-dependent you publish between now and Official Journal publication needs a visible review date attached, because the moment the consolidated text appears, every citation in it should be updated to the final number. The change history is set out on what the Digital Omnibus changed and what survived negotiations.

Planning backwards from each AI Act deadline

Every date in the table is the date an obligation starts to apply, not the date you can start work. Two of them have earlier real deadlines hidden inside them.

For 2 August 2026, the disclosure design work under Article 50(1) is product work, not paperwork: the requirement is that the system be designed so the person is informed, and disclosures must be clear and distinguishable at the latest at the first interaction or exposure under Art 50(5). That has to land in a release, which means the engineering deadline sits before the legal one.

For 2 December 2027, the binding constraint is Article 6(4) and Annex IV. Technical documentation is drawn up before the system is placed on the market, kept up to date and retained for around ten years, with a simplified form available to SMEs under Article 11(2). If your next release of an Annex III system lands after 2 December 2027, its documentation has to be complete before it ships, not after. The nine blocks are listed on what Annex IV technical documentation has to contain.

And check your role before you plan any of it. Under Art 25 a deployer, importer or distributor becomes a provider, inheriting the full Article 16 obligation set, by putting its name or trademark on a high-risk system, by making a substantial modification that keeps the system high-risk, or by modifying the intended purpose of any system, including a general-purpose AI system, so that it becomes high-risk. Buying a system does not keep you on the deployer timetable if one of those triggers has fired. Roles are unpacked on provider, deployer and the three acts that trigger the Article 25 flip.

If you are not certain which of these dates your system is actually on, the free seven-stage classifier runs scope, prohibitions, Annex I and Annex III, the derogation, GPAI, Article 50 and role in order, and returns the deadline that attaches to your answers along with the article it rests on. The Commission maintains its own overview of the framework on the European Commission AI policy pages.

Check your own system

The free classifier walks the same tests in order and tells you which of them your system actually trips, with the article each answer rests on.

Run the triage →

Frequently asked questions

When does the EU AI Act apply?

It applies in stages, and all six stages are fixed in the amended text, with two of them already behind us. The Article 5 prohibitions and the AI-literacy duty applied on 2 February 2025. GPAI model obligations, the governance framework and the penalty provisions applied on 2 August 2025. Article 50 transparency applies on 2 August 2026. Machine-readable marking of synthetic content and the new CSAM prohibition apply on 2 December 2026. High-risk obligations for standalone Annex III systems apply on 2 December 2027, and for Annex I embedded products on 2 August 2028. There is no single date on which the whole regulation switches on.

Have the EU AI Act deadlines been delayed?

Some of them, not all of them, and the difference is the whole point. The Digital Omnibus moved the Article 50(2) marking duty to 2 December 2026 for systems already on the market, pushed standalone Annex III high-risk obligations to 2 December 2027 and Annex I embedded-product obligations to 2 August 2028. Nothing moved for the Article 5 prohibitions, the AI-literacy duty, the GPAI regime, the penalty provisions, or the rest of Article 50 transparency. Reading the delay headline as a general reprieve is the most expensive mistake available on this timeline right now.

What is the next EU AI Act deadline?

2 August 2026, when Article 50 transparency starts to apply and the AI Office gains its enforcement role. Three duties bite that day: Article 50(1) requires providers to design interactive systems so a person is told they are dealing with an AI unless that is obvious; Article 50(3) requires deployers of emotion recognition and biometric categorisation to inform the people exposed to it; Article 50(4) requires deployers to disclose deepfakes and AI-generated text published to inform the public on matters of public interest. The population caught by Article 50 is far wider than the high-risk population.

Is the high-risk deadline 2 August 2026 or 2 December 2027?

2 December 2027 for standalone Annex III systems, and 2 August 2028 for AI embedded in Annex I products, under the amended text. The original regulation set 2 August 2026 for standalone Annex III systems; the Digital Omnibus extended that by seventeen months. What did not move is the preparatory work. Article 6(4) still requires a provider claiming the Article 6(3) derogation to document that assessment before the system is placed on the market, and self-assessed non-high-risk systems still have to be registered in the EU database, so the classification work has an earlier practical deadline than the obligation set does.

Is the marking grace period three months or four?

The published sources say both, and every one of them lands on 2 December 2026. The Council material and some firm summaries describe it as three months, tracking the negotiating framing that cut a proposed six months to three. Other summaries call it four months, which is the literal calendar span from 2 August to 2 December 2026. Nothing turns on the label: the operative fact is the date. If you diary a month count rather than the date, you either panic a month early or, worse, anchor the count to the wrong starting event and miss it.

Do the amended dates apply if the Digital Omnibus is not in the Official Journal yet?

Not yet, formally, although the outcome is no longer in doubt. Until publication the operative text is Regulation (EU) 2024/1689 as originally adopted, so the original dates remain the technical baseline. The amendment was agreed in trilogue on 7 May 2026, adopted by Parliament on 16 June 2026 by 423 votes to 57 with 174 abstentions, adopted by Council on 29 June 2026 and signed on 8 July 2026. It enters into force on the third day after publication. Plan to the amended dates, but do not cite a final regulation number that does not exist yet.

What happens on 2 February 2027?

The watermark-detection interoperability obligation in the Code of Practice on transparency of AI-generated content starts to bite. That Code, published in final form on 10 June 2026, is voluntary rather than a statutory deadline, but it is the likely de facto route to demonstrating Article 50(2) compliance, so signatories should treat the date as real. The Code requires multi-layered marking, at least two layers where a single technique cannot meet the four statutory criteria, with an exemption for free-form text under 200 tokens and for generative systems embedded in closed physical products.

This page is triage guidance, not legal advice. It reflects Regulation (EU) 2024/1689 as amended by the Digital Omnibus, reviewed 22 July 2026, when the Omnibus was adopted and signed but awaiting Official Journal publication. Final classification for ambiguous cases needs qualified counsel.