{
  "version": "2026-08-04",
  "licence": "CC BY 4.0",
  "note": "EU AI Act application dates as amended by Regulation (EU) 2026/1744 (the Digital Omnibus on AI), which deferred the high-risk obligations. Dates verified against the Official Journal text. Explanatory notes are original.",
  "lastReviewed": "2026-08-04",
  "sources": [
    {
      "label": "Regulation (EU) 2024/1689 (AI Act)",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng"
    },
    {
      "label": "Regulation (EU) 2026/1744 (Digital Omnibus on AI)",
      "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32026R1744"
    }
  ],
  "roles": [
    {
      "id": "deployer",
      "label": "We use AI systems",
      "note": "A deployer under the Act. The capacity most organisations are in, and the one most often assumed to carry no obligations."
    },
    {
      "id": "provider",
      "label": "We build or place AI systems on the market",
      "note": "A provider. Carries the bulk of the Act's obligations, including for a system you rebrand as your own."
    },
    {
      "id": "gpai",
      "label": "We provide a general-purpose AI model",
      "note": "A narrow category with its own chapter and its own earlier deadline."
    }
  ],
  "categories": [
    {
      "id": "annex-iii",
      "label": "High-risk under Annex III",
      "note": "Employment, education, essential services, credit, insurance pricing, law enforcement, migration, biometrics and critical infrastructure use cases."
    },
    {
      "id": "annex-i",
      "label": "High-risk as a product safety component (Annex I)",
      "note": "AI inside products already covered by EU product legislation: machinery, medical devices, lifts, toys and the rest."
    },
    {
      "id": "transparency",
      "label": "Interacts with people, or generates content",
      "note": "Chatbots, emotion recognition, biometric categorisation, deepfakes and synthetic media. Article 50 transparency duties."
    },
    {
      "id": "prohibited",
      "label": "None of these, or not sure yet",
      "note": "The prohibitions and the general duties still apply to everyone."
    }
  ],
  "milestones": [
    {
      "id": "prohibitions",
      "date": "2025-02-02",
      "title": "Prohibited practices bite",
      "what": "The eight banned practices in Article 5 became unlawful: manipulative techniques causing significant harm, exploitation of vulnerability, social scoring, predictive policing based solely on profiling, untargeted facial image scraping, emotion inference in the workplace and education, biometric categorisation to infer protected characteristics, and most real-time remote biometric identification in public for law enforcement. These carry the Act's highest penalties.",
      "reference": "Article 5",
      "roles": [
        "any"
      ],
      "categories": [
        "any"
      ],
      "status": "applies"
    },
    {
      "id": "literacy",
      "date": "2025-02-02",
      "title": "AI literacy obligation applies",
      "what": "Providers and deployers must take measures supporting the development of AI literacy among staff and others operating systems on their behalf. The Omnibus rewrote this from a duty to ensure a sufficient level into a duty of effort, and added that no specific level need be guaranteed for any individual.",
      "reference": "Article 4, as replaced by Regulation (EU) 2026/1744",
      "roles": [
        "provider",
        "deployer"
      ],
      "categories": [
        "any"
      ],
      "status": "applies"
    },
    {
      "id": "gpai",
      "date": "2025-08-02",
      "title": "General-purpose AI model obligations apply",
      "what": "Technical documentation, information for downstream providers, a copyright policy, and a public summary of training content. Models presenting systemic risk carry more: evaluation, adversarial testing, incident reporting and cybersecurity protection.",
      "reference": "Chapter V",
      "roles": [
        "gpai"
      ],
      "categories": [
        "gpai"
      ],
      "status": "applies"
    },
    {
      "id": "penalties",
      "date": "2025-08-02",
      "title": "Penalty framework and governance apply",
      "what": "Member States designate authorities and lay down penalty rules. Ceilings run to EUR 35 million or 7% of worldwide turnover for prohibited practices, and EUR 15 million or 3% for most other listed infringements.",
      "reference": "Articles 99 and 100",
      "roles": [
        "any"
      ],
      "categories": [
        "any"
      ],
      "status": "applies"
    },
    {
      "id": "omnibus",
      "date": "2026-07-27",
      "title": "The Digital Omnibus enters into force",
      "what": "Regulation (EU) 2026/1744 amends the Act: Article 4 is replaced, definitions of SME and small mid-cap enterprise are inserted, the AI Office gains direct supervisory and enforcement powers, and the high-risk application dates move. Articles 102 to 110 apply from this date.",
      "reference": "Regulation (EU) 2026/1744",
      "roles": [
        "any"
      ],
      "categories": [
        "any"
      ],
      "status": "applies"
    },
    {
      "id": "general",
      "date": "2026-08-02",
      "title": "General application, transparency duties, and supervision",
      "what": "The bulk of the Act's governance machinery becomes applicable, including the Article 50 transparency duties: telling people they are interacting with an AI system, marking synthetic content as machine-generated, disclosing deepfakes, and informing people subject to emotion recognition or biometric categorisation.",
      "reference": "Article 113, Article 50",
      "roles": [
        "provider",
        "deployer"
      ],
      "categories": [
        "any",
        "transparency"
      ],
      "status": "applies"
    },
    {
      "id": "new-prohibitions",
      "date": "2026-12-02",
      "title": "New prohibitions apply",
      "what": "The additional prohibited practices inserted into Article 5 by the Omnibus take effect. Unlike the rest of the Omnibus they were not immediate on entry into force, which gives a short runway that is easy to miss.",
      "reference": "Article 5(1) points (ba) and (bb), Article 5(1a) and (1b)",
      "roles": [
        "any"
      ],
      "categories": [
        "any",
        "prohibited"
      ],
      "status": "upcoming"
    },
    {
      "id": "annex-iii",
      "date": "2027-12-02",
      "title": "High-risk obligations apply: Annex III systems",
      "what": "Risk management, data governance, technical documentation, logging, transparency to deployers, human oversight, accuracy and robustness, the quality management system, conformity assessment and registration. Deployers take on their own duties: human oversight by competent people, input data relevance, log retention, and a fundamental rights impact assessment for public bodies and certain private deployers.",
      "reference": "Chapter III, Sections 1 to 3; Article 6(2) and Annex III",
      "roles": [
        "provider",
        "deployer"
      ],
      "categories": [
        "annex-iii"
      ],
      "moved": {
        "from": "2026-08-02",
        "note": "Deferred by sixteen months by the Omnibus. Most published timelines still show the original date."
      },
      "status": "upcoming"
    },
    {
      "id": "annex-i",
      "date": "2028-08-02",
      "title": "High-risk obligations apply: Annex I product safety components",
      "what": "The same Chapter III obligations, for AI that is a safety component of a product already regulated under EU product legislation. The later date reflects the need to align with those existing conformity assessment regimes.",
      "reference": "Chapter III, Sections 1 to 3; Article 6(1) and Annex I",
      "roles": [
        "provider"
      ],
      "categories": [
        "annex-i"
      ],
      "moved": {
        "from": "2026-08-02",
        "note": "Deferred by two years by the Omnibus."
      },
      "status": "upcoming"
    },
    {
      "id": "legacy",
      "date": "2030-08-02",
      "title": "Legacy public-sector systems must comply",
      "what": "High-risk systems placed on the market before the obligations applied are generally grandfathered unless significantly modified. Systems used by public authorities do not get that treatment indefinitely: they must be brought into compliance by this date.",
      "reference": "Article 111",
      "roles": [
        "provider",
        "deployer"
      ],
      "categories": [
        "annex-iii",
        "annex-i"
      ],
      "status": "upcoming"
    }
  ]
}