EU AI Act timeline
Regulation (EU) 2024/1689, as amended by the Digital Omnibus
The staggered timetable that determines when each part of the AI Act applies to your organisation, including the July 2026 amendment that moved high-risk obligations to December 2027 and left the transparency duties exactly where they were.
The EU AI Act timeline. The AI Act applies in stages rather than all at once. Prohibited practices and the AI literacy duty applied from 2 February 2025, obligations for general purpose AI models from 2 August 2025, and transparency duties under Article 50 from 2 August 2026. The Digital Omnibus on AI, Regulation (EU) 2026/1744, deferred high-risk obligations for standalone systems to 2 December 2027 and for AI embedded in regulated products to 2 August 2028. It did not defer the transparency duties.
Key facts at a glance
Who is in scope?
Scope under the AI Act is determined by the role you play and by where the output is used, not by company size. Most organisations are deployers rather than providers, and the assumption that only AI developers are caught is the most frequent scoping error.
Providers
LIVE NOWAny organisation developing an AI system or placing one on the EU market under its own name. Providers carry the marking and detection duties for generated content.
Deployers
LIVE NOWAny organisation using an AI system in a professional capacity. If you run a customer-facing chatbot or publish AI-generated content, you are a deployer and you carry disclosure duties in your own right.
Organisations outside the EU
LIVE NOWProviders and deployers established outside the Union are in scope where the system's output is used inside it. A campaign aimed at European audiences or an assistant serving EU customers is caught.
Operators of high-risk systems
DEC 2027Standalone Annex III systems, covering uses such as employment decisions, education, credit, insurance and biometrics. Deferred, not cancelled.
AI embedded in regulated products
AUG 2028Annex I systems embedded in products already covered by EU product safety law.
Compliance timeline
Frequently asked questions
Was the EU AI Act delayed?
Partly. The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, six days before the original high-risk deadline. It deferred high-risk obligations for standalone Annex III systems from 2 August 2026 to 2 December 2027, and for AI embedded in regulated products under Annex I to 2 August 2028. It did not defer the Article 50 transparency obligations, the Article 5 prohibitions or the Article 4 AI literacy duty. Reading the delay headline as a general postponement is the most common error in current commentary.
What applies from 2 August 2026?
The Article 50 transparency obligations, together with the enforcement powers that sit behind them. Article 50 requires that people are told when they are interacting with an AI system such as a chatbot, that AI-generated or manipulated output carries machine-readable marking, that individuals exposed to emotion recognition or biometric categorisation systems are informed, and that deepfakes and AI-generated text published on matters of public interest are clearly labelled. An organisation with no high-risk AI at all can still have significant obligations here.
Does the AI Act apply to companies outside the EU?
Yes, where the output of the system is used inside the Union. Providers established outside the EU are in scope when they place AI systems on the EU market or when system output is used in the EU. Deployers outside the EU are in scope where the output is used in the EU. A business running AI-generated campaigns aimed at European audiences, or operating an assistant that serves customers in the Union, is caught regardless of where it is established.
Who is responsible, the provider or the deployer?
Both, for different things, and responsibility does not transfer automatically. Marking generated output is the provider's duty. Disclosing a deepfake, and labelling AI-generated text published on matters of public interest, falls on the deployer. So if the chatbot or image generator belongs to an outside vendor, the organisation putting it in front of EU users is still responsible for ensuring the disclosure reaches the user. A machine-readable mark embedded by the provider does not satisfy the deployer's disclosure obligation, because the disclosure must be perceivable without specialist tools.
What are the penalties?
Breaches of the Article 5 prohibitions carry fines of up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher. Most other breaches, including the Article 50 transparency obligations, carry up to EUR 15 million or 3% of worldwide annual turnover. Supplying incorrect or misleading information to authorities carries up to EUR 7.5 million or 1%. For SMEs and start-ups the lower of the two figures applies rather than the higher.
AI use case register template
A register that records where AI is used across the business, who owns each use, which obligations attach and what evidence exists. The work every AI Act question depends on.
Get the templateFormer IBM mainframe engineer turned operator across Tata and Tata-Tesco. Works at the seam between systems, governance and commercial execution.
More about the teamAI governance and adoption
We help mid-market teams work out where AI is already in use, which obligations attach and what evidence a regulator or customer would expect to see.
View AI governance and adoption service →