P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Free tool

EU AI Act deadlines, after the Digital Omnibus moved them

The high-risk deadlines moved in July 2026. Filter the Act's obligations by what you are and what you build, and export a dated plan.

Almost every AI Act timeline in circulation still shows 2 August 2026 as the date the high-risk obligations bite. That was correct until the Digital Omnibus entered into force on 27 July 2026 and deferred them: Annex III systems to 2 December 2027, Annex I product safety components to 2 August 2028. Planning against a date that has moved is an expensive way to be diligent, and so is assuming everything moved when the prohibitions, the AI literacy duty and the transparency obligations did not. This filters the Act to the obligations that are actually yours, marks the ones whose dates changed, and hands you a dated plan.

Nothing leaves your browser: Nothing you select is recorded. Your role and system category describe your regulatory exposure, so the page is served with a Content Security Policy whose connect-src 'none' rule blocks fetch, XHR, WebSocket, EventSource and sendBeacon and the plan is generated in your browser. A policy inside the page cannot stop you copying the result somewhere else, so what you do with it afterwards is yours to protect. Refreshing the page loses your work.

Last reviewed:
Open data: download the full dataset as JSON

1. What are you?

2. What kind of system?

Still to come

4

Already in force

6

  1. In force

    Prohibited practices bite

    The eight banned practices in Article 5 became unlawful: manipulative techniques causing significant harm, exploitation of vulnerability, social scoring, predictive policing based solely on profiling, untargeted facial image scraping, emotion inference in the workplace and education, biometric categorisation to infer protected characteristics, and most real-time remote biometric identification in public for law enforcement. These carry the Act's highest penalties.

    Article 5

  2. In force

    AI literacy obligation applies

    Providers and deployers must take measures supporting the development of AI literacy among staff and others operating systems on their behalf. The Omnibus rewrote this from a duty to ensure a sufficient level into a duty of effort, and added that no specific level need be guaranteed for any individual.

    Article 4, as replaced by Regulation (EU) 2026/1744

  3. In force

    General-purpose AI model obligations apply

    Technical documentation, information for downstream providers, a copyright policy, and a public summary of training content. Models presenting systemic risk carry more: evaluation, adversarial testing, incident reporting and cybersecurity protection.

    Chapter V

  4. In force

    Penalty framework and governance apply

    Member States designate authorities and lay down penalty rules. Ceilings run to EUR 35 million or 7% of worldwide turnover for prohibited practices, and EUR 15 million or 3% for most other listed infringements.

    Articles 99 and 100

  5. In force

    The Digital Omnibus enters into force

    Regulation (EU) 2026/1744 amends the Act: Article 4 is replaced, definitions of SME and small mid-cap enterprise are inserted, the AI Office gains direct supervisory and enforcement powers, and the high-risk application dates move. Articles 102 to 110 apply from this date.

    Regulation (EU) 2026/1744

  6. In force

    General application, transparency duties, and supervision

    The bulk of the Act's governance machinery becomes applicable, including the Article 50 transparency duties: telling people they are interacting with an AI system, marking synthetic content as machine-generated, disclosing deepfakes, and informing people subject to emotion recognition or biometric categorisation.

    Article 113, Article 50

  7. New prohibitions apply

    The additional prohibited practices inserted into Article 5 by the Omnibus take effect. Unlike the rest of the Omnibus they were not immediate on entry into force, which gives a short runway that is easy to miss.

    Article 5(1) points (ba) and (bb), Article 5(1a) and (1b)

  8. Date moved

    High-risk obligations apply: Annex III systems

    Risk management, data governance, technical documentation, logging, transparency to deployers, human oversight, accuracy and robustness, the quality management system, conformity assessment and registration. Deployers take on their own duties: human oversight by competent people, input data relevance, log retention, and a fundamental rights impact assessment for public bodies and certain private deployers.

    Chapter III, Sections 1 to 3; Article 6(2) and Annex III

    Was 2 August 2026. Deferred by sixteen months by the Omnibus. Most published timelines still show the original date.

  9. Date moved

    High-risk obligations apply: Annex I product safety components

    The same Chapter III obligations, for AI that is a safety component of a product already regulated under EU product legislation. The later date reflects the need to align with those existing conformity assessment regimes.

    Chapter III, Sections 1 to 3; Article 6(1) and Annex I

    Was 2 August 2026. Deferred by two years by the Omnibus.

  10. Legacy public-sector systems must comply

    High-risk systems placed on the market before the obligations applied are generally grandfathered unless significantly modified. Systems used by public authorities do not get that treatment indefinitely: they must be brought into compliance by this date.

    Article 111

What the Digital Omnibus changed

Regulation (EU) 2026/1744 entered into force on 27 July 2026 and amended Article 113. Two dates moved, and both moved a long way. Everything else kept its original date, which is the half of the story that gets lost when the change is reported as “the AI Act has been delayed”.

High-risk obligations apply: Annex III systems

Was

2 August 2026

Now

2 December 2027

Deferred by sixteen months by the Omnibus. Most published timelines still show the original date. Chapter III, Sections 1 to 3; Article 6(2) and Annex III.

High-risk obligations apply: Annex I product safety components

Was

2 August 2026

Now

2 August 2028

Deferred by two years by the Omnibus. Chapter III, Sections 1 to 3; Article 6(1) and Annex I.

What did not move

The prohibited practices and the AI literacy duty have applied since 2 February 2025. The general-purpose AI model obligations and the penalty framework have applied since 2 August 2025. The Article 50 transparency duties arrive with general application on 2 August 2026, and the Omnibus’s own new prohibitions apply from 2 December 2026.

If the headline reading was that the Act has been postponed, these are the parts that are already live and enforceable, and the prohibitions carry the highest penalties in the Regulation.

Use the data

Every milestone, with its reference, the roles and categories it attaches to, and the previous date where one moved, is published as JSON under CC BY 4.0, currently version 2026-08-04. Dates are taken from the Official Journal text, which is freely reusable; the explanatory notes are original. If you maintain a timeline of your own, this is the fastest way to correct it.

Primary sources: Regulation (EU) 2024/1689 (AI Act); Regulation (EU) 2026/1744 (Digital Omnibus on AI).

What this cannot decide for you

Whether your system is high-risk. That turns on the use case rather than the technology: the same model can be high-risk in one deployment and unregulated in another, and Annex III is written around what a system is used to decide. Every date here is downstream of that classification, which is why the tool asks you what kind of system you have rather than pretending to work it out.

It also cannot tell you your national exposure. The Act is a Regulation, so these dates apply directly and identically across the EU, but supervision and penalties are national and are still forming.

Common questions

Did the EU AI Act high-risk deadline really move?

Yes. Regulation (EU) 2026/1744 amended Article 113 so that Chapter III Sections 1 to 3 apply from 2 December 2027 for systems classified high-risk under Article 6(2) and Annex III, and from 2 August 2028 for those classified under Article 6(1) and Annex I. Both were previously 2 August 2026. That is a deferral of sixteen months and two years respectively.

What did not move?

The prohibited practices in Article 5 and the AI literacy duty in Article 4, both applicable since 2 February 2025. The general-purpose AI model obligations and the penalty framework, applicable since 2 August 2025. The Article 50 transparency duties, which come in with general application on 2 August 2026. If you concluded from the headlines that the Act has been postponed, these are the parts that are already live.

When do the new prohibitions apply?

2 December 2026. The Omnibus inserted additional prohibited practices into Article 5, and unlike most of the Omnibus they were not immediate on entry into force. That short runway is easy to miss precisely because everything else about the Omnibus was reported as a delay.

Are older systems grandfathered?

Broadly, high-risk systems placed on the market before the obligations applied are not caught unless they are significantly modified. Public authorities do not get that indefinitely: systems they use must be brought into compliance by 2 August 2030. Grandfathering also does not extend to the prohibitions, which apply to use rather than to placing on the market.

Does this apply to a UK organisation?

Directly, only where you are established in the EU or the output of your AI system is used there. Otherwise the exposure is usually contractual: EU customers carrying their own obligations push equivalent terms down the supply chain, and the dates then reach you through an agreement rather than through the Regulation.

Is the classification decision the hard part?

Almost always. Whether a system is high-risk under Annex III turns on the use case rather than the technology, and the same model can be high-risk in one deployment and unregulated in another. Every date on this page is downstream of that decision, which is why the tool asks what kind of system you have rather than pretending it can tell you.

When you need more than a tool

EU AI Act Readiness

Classification of your AI systems under the EU AI Act, a conformity gap assessment, and a compliance plan sequenced against the enforcement timeline.

Assess your exposure

Share this tool

Free, no sign-up, and nothing you type leaves your browser.

Related analysis

← All free tools