DS Consulting logoDS Consulting
Regulatory Dictionary

EU AI Act timeline

Regulation (EU) 2024/1689, as amended by the Digital Omnibus

The staggered timetable that determines when each part of the AI Act applies to your organisation, including the July 2026 amendment that moved high-risk obligations to December 2027 and left the transparency duties exactly where they were.

Tejas Dhabalia
Tejas Dhabalia
Co-founder, DS Consulting · 26 August 2026

The EU AI Act timeline. The AI Act applies in stages rather than all at once. Prohibited practices and the AI literacy duty applied from 2 February 2025, obligations for general purpose AI models from 2 August 2025, and transparency duties under Article 50 from 2 August 2026. The Digital Omnibus on AI, Regulation (EU) 2026/1744, deferred high-risk obligations for standalone systems to 2 December 2027 and for AI embedded in regulated products to 2 August 2028. It did not defer the transparency duties.

Key facts at a glance

Legal basis
Regulation (EU) 2024/1689
Amended by
Regulation (EU) 2026/1744
In force since
1 August 2024
Live obligation now
Article 50 transparency
High risk, standalone
2 December 2027
Maximum penalty
EUR 35M or 7% of worldwide turnover

Who is in scope?

Scope under the AI Act is determined by the role you play and by where the output is used, not by company size. Most organisations are deployers rather than providers, and the assumption that only AI developers are caught is the most frequent scoping error.

Providers

LIVE NOW

Any organisation developing an AI system or placing one on the EU market under its own name. Providers carry the marking and detection duties for generated content.

Deployers

LIVE NOW

Any organisation using an AI system in a professional capacity. If you run a customer-facing chatbot or publish AI-generated content, you are a deployer and you carry disclosure duties in your own right.

Organisations outside the EU

LIVE NOW

Providers and deployers established outside the Union are in scope where the system's output is used inside it. A campaign aimed at European audiences or an assistant serving EU customers is caught.

Operators of high-risk systems

DEC 2027

Standalone Annex III systems, covering uses such as employment decisions, education, credit, insurance and biometrics. Deferred, not cancelled.

AI embedded in regulated products

AUG 2028

Annex I systems embedded in products already covered by EU product safety law.

Compliance timeline

1
2 February 2025: Prohibited practices and the AI literacy duty
Article 5 bans and the Article 4 obligation to support AI literacy among staff.
2
2 August 2025: General purpose AI models
Obligations for providers of GPAI models begin to apply.
3
2 August 2026: Article 50 transparency duties and enforcement powers
Chatbot disclosure, marking of generated content, notices for emotion recognition and biometric categorisation, and deepfake labelling. Not deferred by the Omnibus.
4
2 December 2026: Legacy system marking and new prohibitions
Article 50(2) marking duties extend to systems already on the market before 2 August 2026. New Article 5 prohibitions on AI-generated non-consensual intimate imagery and child sexual abuse material apply.
5
2 August 2027: Regulatory sandboxes and delegated acts
Member States must have at least one national AI regulatory sandbox operating. The Commission's deadline for delegated acts on sectoral rules for Annex I systems.
6
2 December 2027: High-risk obligations, standalone systems
Annex III high-risk obligations apply. Moved from 2 August 2026 by the Omnibus.
7
2 August 2028: High-risk obligations, embedded systems
Annex I high-risk obligations apply to AI embedded in regulated products.

Frequently asked questions

Was the EU AI Act delayed?

Partly. The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, six days before the original high-risk deadline. It deferred high-risk obligations for standalone Annex III systems from 2 August 2026 to 2 December 2027, and for AI embedded in regulated products under Annex I to 2 August 2028. It did not defer the Article 50 transparency obligations, the Article 5 prohibitions or the Article 4 AI literacy duty. Reading the delay headline as a general postponement is the most common error in current commentary.

What applies from 2 August 2026?

The Article 50 transparency obligations, together with the enforcement powers that sit behind them. Article 50 requires that people are told when they are interacting with an AI system such as a chatbot, that AI-generated or manipulated output carries machine-readable marking, that individuals exposed to emotion recognition or biometric categorisation systems are informed, and that deepfakes and AI-generated text published on matters of public interest are clearly labelled. An organisation with no high-risk AI at all can still have significant obligations here.

Does the AI Act apply to companies outside the EU?

Yes, where the output of the system is used inside the Union. Providers established outside the EU are in scope when they place AI systems on the EU market or when system output is used in the EU. Deployers outside the EU are in scope where the output is used in the EU. A business running AI-generated campaigns aimed at European audiences, or operating an assistant that serves customers in the Union, is caught regardless of where it is established.

Who is responsible, the provider or the deployer?

Both, for different things, and responsibility does not transfer automatically. Marking generated output is the provider's duty. Disclosing a deepfake, and labelling AI-generated text published on matters of public interest, falls on the deployer. So if the chatbot or image generator belongs to an outside vendor, the organisation putting it in front of EU users is still responsible for ensuring the disclosure reaches the user. A machine-readable mark embedded by the provider does not satisfy the deployer's disclosure obligation, because the disclosure must be perceivable without specialist tools.

What are the penalties?

Breaches of the Article 5 prohibitions carry fines of up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher. Most other breaches, including the Article 50 transparency obligations, carry up to EUR 15 million or 3% of worldwide annual turnover. Supplying incorrect or misleading information to authorities carries up to EUR 7.5 million or 1%. For SMEs and start-ups the lower of the two figures applies rather than the higher.

AI use case register template

A register that records where AI is used across the business, who owns each use, which obligations attach and what evidence exists. The work every AI Act question depends on.

Get the template
Tejas Dhabalia
Tejas Dhabalia
Co-founder, DS Consulting

Former IBM mainframe engineer turned operator across Tata and Tata-Tesco. Works at the seam between systems, governance and commercial execution.

More about the team

AI governance and adoption

We help mid-market teams work out where AI is already in use, which obligations attach and what evidence a regulator or customer would expect to see.

View AI governance and adoption service →