The EU AI Act does not switch on all at once, it phases in over years, and the 2026 Digital Omnibus, now adopted by both the European Parliament and the Council of the EU, has pushed the heaviest obligations further out. Here is every key date in one place, with the adopted changes clearly flagged.
Dates marked Adopted (Omnibus) reflect the Digital Omnibus deal that the European Parliament (16 June 2026, 423 votes in favour) and the Council of the EU (29 June 2026) have now both formally adopted, with the final act signed on 8 July 2026. What remains is publication in the Official Journal, with entry into force three days after that. Treat these dates as highly likely, not yet settled law until that publication happens, and note the fallback: if publication were to slip past 2 August 2026, the original AI Act deadlines would apply as written in the meantime.
The Article 5 bans on unacceptable-risk AI, such as social scoring and untargeted scraping of facial images, apply, along with the Article 4 duty to ensure staff have sufficient AI literacy.
Obligations for general-purpose AI (GPAI) model providers begin, alongside the governance architecture (the AI Office and national authorities) and the penalty regime, up to €35m or 7% of worldwide turnover for prohibited practices.
The Article 50 transparency duties begin to apply, telling people when they are interacting with AI, and marking AI-generated or manipulated content.
Under the adopted Digital Omnibus, the narrower Article 50(2) duty to embed a machine-readable marker in AI-generated content gets a four-month grace period for systems already on the market before 2 August 2026. The broader Article 50 duty to disclose AI interaction, above, is unaffected. A new Article 5 prohibition also takes effect on AI used to generate child sexual abuse material and non-consensual intimate imagery.
Obligations for Annex III high-risk systems, areas like employment, creditworthiness, essential services, and biometric uses, now apply. The Digital Omnibus defers this from the original 2 August 2026.
Obligations for high-risk AI embedded in regulated products (Annex I, for example machinery, medical devices, vehicles) apply, deferred from 2 August 2027 under the Digital Omnibus.
Defers the high-risk obligations: Annex III to 2 December 2027 and Annex I to 2 August 2028, giving standards bodies and businesses more time.
Adds a new Article 5 prohibition on AI used to generate child sexual abuse material and non-consensual intimate imagery.
Tightens content-marking timing, with pre-existing systems expected to comply by 2 December 2026.
Extends some relief to small mid-cap companies, not just SMEs, and reinforces the AI Office’s oversight of GPAI-based systems.
Wondering which obligations fall on you? Your duties depend on whether you are a provider, deployer, importer, or distributor, work it out with our EU AI Act roles guide, or start with what the EU AI Act is.
Partly. The core dates that have already passed, prohibited practices (February 2025), GPAI and governance (August 2025), remain in force. What the Digital Omnibus defers is the most burdensome layer: the high-risk obligations. Under the now-adopted Digital Omnibus, Annex III high-risk obligations move to 2 December 2027 and Annex I to 2 August 2028.
Almost. Both co-legislators have now adopted it: the European Parliament voted 423 to 57 in favour on 16 June 2026, and the Council of the EU gave its final approval on 29 June 2026. The final act was then signed on 8 July 2026. The only step remaining is publication in the Official Journal, with entry into force three days after that. Until publication the exact deferred dates are highly likely but not yet legally certain, so keep half an eye on the Official Journal before treating them as settled.
Yes, it can. The EU AI Act has extraterritorial reach: it can apply to providers and deployers outside the EU where the AI system is placed on the EU market or its output is used in the EU. Which obligations you carry depends on your role, see our guide to the EU AI Act roles.
Broadly, two groups: AI used in the sensitive areas listed in Annex III (such as employment, credit, education, essential services, and certain biometric and law-enforcement uses), and AI that is a safety component of, or itself, a product regulated under Annex I (such as medical devices or machinery). High-risk systems carry the heaviest obligations.
Confirm whether the Act applies to you and in what role; inventory your AI systems and classify them by risk tier; meet the prohibitions, AI-literacy, GPAI, and transparency duties already in force; and use the deferred high-risk timeline as runway to build conformity processes rather than as a reason to wait.
The extra time on high-risk obligations is best spent building conformity processes now. Knowing your role and your inventory is the first step.
This page is general information, not legal advice. The EU AI Act timeline is subject to change, and the Digital Omnibus was adopted by the European Parliament and the Council of the EU and signed on 8 July 2026, but not yet published in the Official Journal at the time of writing, so always confirm the current position against the Official Journal and the European Commission’s own publications before relying on a date.