The EU AI Act is now actively enforced, and the compliance clock is running at different speeds depending on which type of AI system your business uses. The Act entered into force on 1 August 2024, triggering a phased rollout that stretches from 2025 through 2028. What makes this timeline more complex in 2026 is the Digital Omnibus on AI, which entered into force on 27 July 2026 and shifted two of the most significant high-risk deadlines forward by over a year. If your planning is based on the original Act text, your dates are outdated.
This guide covers every major EU AI Act deadline from 2026 to 2028, what each one requires, and what the Digital Omnibus changed. Whether you operate a customer-facing chatbot, use AI in hiring decisions, or build AI-enabled products, the timeline below applies to you.
How the EU AI Act phases its enforcement rollout
The EU AI Act uses a phased approach to enforcement, applying obligations in order of urgency rather than all at once. The most harmful AI practices were addressed first, followed by foundational AI model rules, then the bulk of high-risk system requirements, and finally AI embedded in safety-critical products already governed by other EU legislation.
The structure reflects a deliberate policy logic. Regulators wanted to eliminate the most dangerous AI applications immediately while giving businesses building complex systems enough time to build compliance infrastructure. The Act classifies AI into four risk tiers: prohibited systems (banned outright), high-risk systems (subject to stringent obligations), limited-risk systems (transparency obligations only), and minimal-risk systems (no specific AI Act obligations). According to the European Commission, roughly 85% of AI systems in use today fall into the minimal-risk category.
The Digital Omnibus did not restructure this framework. It preserved the four-tier classification and the phased rollout, but extended two deadlines for high-risk systems to give providers more preparation time, particularly given that the harmonised technical standards from CEN-CENELEC needed for conformity assessment are not expected until late 2026 at the earliest.
Key EU AI Act deadlines in 2026
Several EU AI Act milestones are already live in 2026, and two more take effect before the year ends. Understanding which obligations are already enforceable matters as much as knowing what is coming.
What is already in force
Since 2 February 2025, prohibited AI practices have been enforceable across all EU member states. This covers systems like social scoring, subliminal manipulation, and real-time biometric identification in public spaces (with narrow exceptions). AI literacy obligations also took effect on that date, requiring all organisations deploying AI in the EU to ensure their staff have a basic understanding of the AI systems they use.
From 2 August 2025, rules for General-Purpose AI (GPAI) models began to apply. Providers of large language models and similar foundational systems must now maintain technical documentation, comply with the EU Copyright Directive, and publish summaries of training data content. Providers of systemic-risk GPAI models face additional requirements, including adversarial testing and incident reporting.
What takes effect in August and December 2026
On 2 August 2026, Article 50 transparency obligations became enforceable. Any chatbot or AI system interacting with people must disclose that it is AI. AI-generated or manipulated content must carry machine-readable markings. Deployers of emotion recognition or biometric categorisation systems must inform users. Deepfakes and AI-generated text published in public-interest contexts require explicit disclosure. The European Commission published its final guidelines on Article 50 on 20 July 2026, confirming that the Code of Practice on AI content transparency is adequate to demonstrate compliance.
On 2 December 2026, machine-readable marking requirements extend to generative tools already on the market before 2 August 2026. Two new prohibitions also take effect on that date: AI systems used to generate non-consensual intimate imagery and child sexual abuse material are added to the list of banned practices under Article 5.
What changes under the 2027 compliance milestones
The most significant shift in the post-Omnibus timeline is the movement of the main high-risk AI deadline. Under the original Act, Annex III high-risk systems were required to comply by 2 August 2026. The Digital Omnibus extended that to 2 December 2027, a 16-month extension confirmed by Council final approval on 29 June 2026.
Which AI systems fall under Annex III
Annex III covers AI used in recruitment and employee management, creditworthiness assessment, biometric identification and categorisation, education and vocational training access, migration and border control, law enforcement, and the administration of justice. For employers specifically, this means AI tools used in hiring, workforce monitoring, or performance management now have until December 2027 to meet full compliance requirements.
What compliance requires by December 2027
The high-risk obligations set out in Articles 9 through 15 and Article 43 of the Act must all be in place by 2 December 2027. These include a continuous risk management system (Article 9), data governance covering training and testing data (Article 10), technical documentation per Annex IV (Article 11), automatic logging (Article 12), transparency and user information (Article 13), human oversight mechanisms (Article 14), and accuracy, robustness, and cybersecurity requirements (Article 15). Conformity assessment and registration in the EU public database must also be completed before the system goes to market.
Systems already on the market before 2 December 2027 benefit from a transitional arrangement. Full high-risk compliance obligations only trigger when those systems undergo significant design changes. If the design remains unchanged, the existing version is protected by the grace period.
Other 2027 milestones
By 2 August 2027, every EU member state must have established at least one national AI regulatory sandbox. These sandboxes are open to any provider meeting eligibility criteria, and access is free for small businesses and startups. GPAI model providers who placed their models on the market before 2 August 2025 must also have completed their compliance steps by 2 August 2027.
The 2028 full enforcement deadline explained
The final major deadline under the revised timeline is 2 August 2028, when high-risk obligations apply to Annex I embedded systems. This replaces the original 2 August 2027 date and represents the point at which the EU AI Act reaches its fullest scope of enforcement.
Annex I covers AI that functions as a safety component in regulated products: medical devices, machinery, lifts, radio equipment, recreational watercraft, motor vehicles, in vitro diagnostic devices, civil aviation equipment, and rail systems. These systems are already subject to existing EU product safety legislation, and the 2028 deadline was set partly to allow alignment between the AI Act’s conformity assessment requirements and the harmonised standards being developed by CEN-CENELEC. Requiring conformity assessment before those standards existed would have produced inconsistent outcomes across member states.
The Digital Omnibus also introduced a specific carve-out for machinery, allowing AI Act requirements to be integrated directly into existing EU Machinery Regulation (EU) 2023/1230 safety frameworks rather than treated as a parallel compliance track. The delay does not reduce the scope of what is required. Every obligation that applied under the original 2027 date, including risk management systems, data governance, quality management, conformity assessment, and post-market monitoring, remains fully in scope by 2028. Organisations with Annex I systems have more lead time, not fewer requirements.
For large-scale EU IT systems such as the Schengen Information System, a further compliance horizon extends towards 2030 for systems integrated into large-scale infrastructure and placed on the market before 2 August 2027.
High-risk vs. limited-risk AI: compliance obligations compared
The compliance burden under the EU AI Act varies dramatically depending on how your AI system is classified. Most businesses will find their AI tools fall into either the limited-risk or minimal-risk categories, but the obligations for high-risk systems are substantial enough that any organisation using AI in hiring, credit, or safety-critical contexts needs to understand them clearly.
High-risk AI systems (Annex III and Annex I)
High-risk systems face the full compliance framework described in Articles 9 through 15. Providers must build a documented risk management system that operates continuously across the system’s lifecycle. Training, validation, and testing data must be relevant, representative, and bias-checked. Technical documentation per Annex IV must be prepared before market placement and kept current. Human oversight mechanisms must be built into the system’s design, not bolted on afterward. Most Annex III systems follow a self-assessment process under Annex VI for conformity, though certain biometric identification systems require assessment by an independent notified body.
Limited-risk AI systems
Limited-risk systems, including chatbots, content generation tools, and emotion recognition systems that do not meet the high-risk threshold, face only the Article 50 transparency obligations that became enforceable on 2 August 2026. No conformity assessment is required. The obligations are meaningful but operationally lighter: disclose that the system is AI, label AI-generated content, and inform users when emotion recognition or biometric categorisation is in use.
An organisation with no high-risk AI can still carry significant obligations simply by operating a customer-facing chatbot or deploying a tool that generates published content. Article 50 applies broadly, and the fines for non-compliance reach up to €15 million or 3% of global annual turnover.
GPAI model providers
Providers of general-purpose AI models sit in a distinct category. All GPAI providers must maintain technical documentation, publish training data summaries, and comply with the EU Copyright Directive. Providers of systemic-risk models face additional requirements: mandatory risk assessments, adversarial testing, and serious incident reporting. Non-EU GPAI providers must appoint an authorised EU representative before placing their model on the Union market, and that representative must retain technical documentation for ten years.
Penalties and enforcement under the EU AI Act
The EU AI Act carries a three-tier penalty structure that exceeds GDPR in its maximum fines for the most serious violations. Violations of prohibited AI practices (Article 5) carry fines up to €35 million or 7% of global annual turnover. Non-compliance with high-risk AI system requirements carries fines up to €15 million or 3% of global turnover. Providing incorrect or misleading information to authorities carries fines up to €7.5 million or 1% of global turnover.
For SMEs and startups, Article 99(6) specifies that the lower of the fixed euro amount or the percentage-of-turnover threshold applies. A startup with €2 million in revenue facing a Tier 2 fine would pay a maximum of €60,000, not €15 million. The Digital Omnibus extended these proportionate provisions to “small mid-cap” companies, defined as organisations with fewer than 750 employees and either €150 million or less in annual turnover or €129 million or less in total assets.
Enforcement is split between national market surveillance authorities and the EU AI Office. National authorities handle most AI system violations within their member state. The AI Office, which sits within the European Commission’s DG CONNECT, oversees GPAI obligations and cross-border or systemic risk cases. The Digital Omnibus expanded the AI Office’s authority to include on-site inspection powers and the ability to secure binding commitments from providers. As the European Commission’s enforcement page confirms, the AI Office can conduct its own investigations and impose fines independently of national authorities.
No formal AI Act penalties had been publicly issued as of mid-2026. Early enforcement is expected to be complaint-driven in most member states, focused on systems causing visible harm rather than comprehensive market surveillance. That said, supervisory activity is increasing, and the enforcement infrastructure is being built out. Only around 8 of 27 EU member states had designated a national market surveillance authority by mid-2026, which creates uneven enforcement capacity across the Union for now.
Preparing your business for EU AI Act compliance
EU AI Act compliance for high-risk systems typically requires 12 to 24 months of preparation. With the Annex III deadline at 2 December 2027, the window is open but not wide. Starting now is the practical choice, not a precautionary one.
Step 1: Build your AI system inventory
The first step is knowing what AI your organisation actually uses. That means cataloguing every AI system in use, under development, or procured from third-party vendors, including embedded AI in cloud-based tools and SaaS platforms. Many organisations discover during this process that they are already deployers of high-risk AI without realising it, particularly in HR and financial services contexts.
Step 2: Classify and prioritise
Once you have an inventory, classify each system against the four-tier framework. Focus attention first on anything that touches Annex III categories: recruitment, credit decisions, biometric identification, or access to education and public services. For limited-risk systems, confirm Article 50 compliance is already in place, given that those obligations are live now.
Step 3: Audit your vendor contracts
Vendor contract management is one of the most underestimated compliance workstreams. Contracts signed before the AI Act came into force do not include the documentation and incident-reporting obligations that deployers now need from providers. Key questions to raise with AI vendors include whether the system is classified as high-risk, what their incident-reporting commitments are within the 15-day window, and whether they have appointed an EU representative if they are based outside the EU.
Step 4: Use available support structures
SMEs have priority access to national AI regulatory sandboxes free of charge. Spain’s AESIA, France’s joint CNIL/ARCEP sandbox, and the Netherlands’ RDI sandbox are already operational. The European Commission has also committed to publishing practical implementation guidelines with specific attention to the needs of small businesses, and a simplified technical documentation form is available for SMEs and startups.
The EU AI Act does not exempt small businesses. If an AI system affects people in the EU, any organisation must comply regardless of size. What the regulation does provide is proportionate fines, simplified documentation, and free access to regulatory support structures, all of which make compliance more manageable for smaller teams.
For businesses that rely on content and digital visibility, staying compliant with Article 50 transparency requirements also intersects with how AI-generated content is treated by search engines and generative AI platforms. Producing well-structured, clearly attributed content is both a compliance signal and a visibility signal. If scaling content output while maintaining that standard is a challenge, WP SEO AI’s content scaling service combines automated production with specialist oversight to keep quality and compliance aligned.
The EU AI Act timeline from 2026 to 2028 is now settled following the Digital Omnibus. The deadlines are known, the obligations are defined, and the enforcement infrastructure is being built. Organisations that treat this as a compliance programme to build rather than a deadline to wait for will be in a significantly stronger position when the 2027 and 2028 milestones arrive. The official EU AI Act implementation tracker is the most reliable source for monitoring any further updates as member states continue to stand up their national frameworks.
This content was generated with the help of AI and it may contain mistakes