EU AI Act

The EU AI Act – clearly explained

The Digital Omnibus has reordered the deadlines: the high-risk obligations move to December 2027 and August 2028 – while the general date of application on 2 August 2026 stands. Here is what that means in practice, answered briefly and reliably.

Timeline

The key deadlines

1

Feb 2025

Prohibited AI practices and AI literacy obligations apply. in force

2

Aug 2025

Governance rules and obligations for GPAI models take effect. in force

3

2 Aug 2026

General date of application: transparency obligations under Art. 50, deepfake disclosure by deployers, penalty regime. Unchanged.

4

2 Dec 2026

Machine-readable marking (Art. 50(2)) for systems already on the market. New prohibitions on "nudifier" apps and CSAM generators.

5

2 Dec 2027

High-risk obligations for stand-alone systems under Annex III (including creditworthiness, employment, biometrics). Moved from Aug 2026.

6

2 Aug 2028

High-risk obligations for AI as a safety component in regulated products under Annex I. Moved from Aug 2027.

Status of the Digital Omnibus on AI

The European Commission tabled the proposal on 19 November 2025. The Council and Parliament reached a provisional agreement on 7 May 2026; Parliament approved the text on 16 June 2026 and the Council formally adopted it on 29 June 2026. The legislative procedure is therefore complete – signature and publication in the EU Official Journal are the remaining steps, with entry into force on the third day after publication. The stated aim is to publish before 2 August 2026, so that the new calendar replaces the old one before the first original deadline falls due. Until publication, the original wording of Regulation (EU) 2024/1689 formally remains the law in force. The originally discussed mechanism of tying the date of application to the availability of harmonised standards was dropped in favour of fixed dates.

Further changes: two new prohibited practices (AI generating non-consensual intimate imagery and child sexual abuse material) apply from 2 December 2026. The deadline for member states to establish AI regulatory sandboxes moves to 2 August 2027. Simplifications for documentation and quality management are extended to small mid-cap companies.

Last reviewed: 15 July 2026 · Not legal advice.

Questions & answers

What you should know about the AI Act

Who does the EU AI Act apply to? +
The EU AI Act (Regulation 2024/1689) applies to providers and deployers of AI systems placed on the market or used in the EU – regardless of where the company is based (extraterritorial reach under Art. 2). Companies outside the EU are also affected as soon as their AI systems are used within the EU. The specific obligations depend on the risk class of the system.
When does the EU AI Act apply? +
The AI Act entered into force on 1 August 2024 and applies in stages: prohibited practices and AI literacy obligations since 2 February 2025, governance and GPAI obligations since 2 August 2025. The general date of application remains 2 August 2026. Under the Digital Omnibus on AI, the high-risk obligations move to 2 December 2027 for stand-alone systems under Annex III and to 2 August 2028 for systems embedded in products under Annex I. The European Parliament approved the text on 16 June 2026 and the Council formally adopted it on 29 June 2026.
Which risk classes does the AI Act define? +
The AI Act distinguishes four levels: unacceptable risk (prohibited practices), high risk (for example AI in biometrics, critical infrastructure, employment, creditworthiness or public services – with comprehensive obligations), limited risk (transparency obligations, including for many GPAI systems) and minimal risk (no specific obligations). The risk class determines which requirements actually apply.
What obligations apply to high-risk AI? +
High-risk systems must demonstrate continuous risk management (Art. 9), data governance for training data (Art. 10), technical documentation, logging, human oversight and a conformity assessment procedure. Under the Digital Omnibus these obligations apply from 2 December 2027 (Annex III) and from 2 August 2028 (Annex I). Breaches of the prohibited practices can be fined up to EUR 35 million or 7 % of global annual turnover; breaches of most other obligations, including the high-risk requirements, up to EUR 15 million or 3 %.
Does the AI Act replace the GDPR? +
No. The AI Act does not replace the GDPR – both apply in parallel. As soon as an AI system processes personal data, the GDPR requirements apply on top. Many high-risk applications require both a data protection impact assessment (DPIA) under Art. 35 GDPR and compliance with the AI Act obligations.
What about US startups and providers outside the EU? +
Like the GDPR, the AI Act has extraterritorial effect: anyone offering AI systems on the EU market or deploying them in the EU falls under the regulation – regardless of where the company is established. US and other non-EU providers should factor EU compliance in early, much as they had to with the GDPR.
Is the Digital Omnibus already in force? +
The content is settled and the legislative procedure is complete: the European Parliament approved the text on 16 June 2026 and the Council formally adopted it on 29 June 2026. What remains is signature by the presidents of both institutions and publication in the EU Official Journal; the amending regulation enters into force on the third day after publication. The stated aim is to complete publication before 2 August 2026, so that the new calendar replaces the old one before the first original deadline falls due. Until publication, the original wording of Regulation (EU) 2024/1689 formally remains the law in force. In practice, companies plan against the new dates while documenting that publication is still pending.
What applies from 2 August 2026 despite the postponement? +
The Digital Omnibus does not postpone the regulation as a whole, only specific obligations. The general date of application of 2 August 2026 stands – including the transparency obligations under Art. 50 and the duty of deployers to disclose deepfakes (Art. 50(4)). The prohibited practices and the AI literacy obligation (since February 2025) and the GPAI rules (since August 2025) also continue to apply unchanged. What has moved are essentially the high-risk obligations and the machine-readable marking obligation under Art. 50(2) for systems already on the market.
How do the AI Act, NIS-2 and the EU Data Act fit together? +
The AI Act is part of a wider European regulatory framework. NIS-2 tightens requirements for cybersecurity and resilience, the EU Data Act governs data access and use. The Digital Omnibus package bundles simplifications: the AI part (Digital Omnibus on AI) has been adopted, while the general Digital Omnibus on data protection and data law is still being negotiated. For AI projects in regulated industries it pays to look at these frameworks together rather than each in isolation.

Getting concrete

Does the AI Act affect your AI systems?

In an intro call we place your systems into the risk classes and show what needs doing by when.