This article was drafted with AI assistance and reviewed for factual accuracy. AI-origin labeling applies under Article 50 of the EU AI Act.
Originally published at https://charz.ai/blog/eu-ai-act-enforcement-august-2-2026
What Is the EU AI Act Timeline?
The EU AI Act (Regulation (EU) 2024/1689) applies in phases. GPAI obligations have been live since August 2025, Article 50 transparency rules and AI Office enforcement took effect on August 2, 2026, and the high-risk rules follow in December 2027 after the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force July 27, 2026) rescheduled the original deadlines. This is the complete, current timeline of what applies when — and who it applies to.
Complete Deadline Timeline
February 2, 2025 Original Article 5 prohibited practices — applies to all providers and deployers in the EU market.
August 2, 2025 — GPAI obligations under Chapter V (transparency, training-data copyright documentation, systemic risk management above 10^25 FLOPs) — applies to providers of general-purpose AI models.
August 2, 2026 — Article 50 transparency obligations + AI Office enforcement authority for GPAI — applies to GPAI providers; deployers of AI that interacts with people.
December 2, 2026 — New Article 5 prohibitions (undetectable AI-generated sexual-abuse/nudification material); watermarking + detection grace period ends for GPAI models placed on the market before August 2, 2026 — applies to all covered providers and deployers.
December 2, 2027 — High-risk AI listed in Annex III (critical infrastructure, education, employment, essential services, law enforcement, migration) — applies to providers and deployers of Annex III high-risk systems.
August 2, 2028 — High-risk AI under Annex I (safety-critical products regulated by existing EU product law) — applies to manufacturers of in-scope products.
August 2, 2030 — High-risk AI deployed by public authorities — applies to public-sector deployers.
What the AI Omnibus Changed
The Digital Omnibus on AI — Regulation (EU) 2026/1744, entered into force July 27, 2026 — is the first major amendment to the AI Act. Its headline changes:
- High-risk deadlines moved back: Annex III high-risk systems now fall due December 2, 2027 (previously August 2, 2026), Annex I products August 2, 2028, and public-sector deployments August 2, 2030.
- New Article 5 prohibitions apply from December 2, 2026, targeting undetectable AI-generated child sexual-abuse / nudification material.
- A grace period lets GPAI models placed on the market before August 2, 2026 catch up on watermarking and synthetic-content detection obligations until December 2, 2026.
- The GDPR-style penalty ceilings — up to 35 million EUR or 7% of global annual turnover for the most serious violations — are unchanged.
The GDPR-style penalty ceilings — up to 35 million EUR or 7% of global annual turnover for the most serious violations — are unchanged.
What Each Deadline Means
August 2, 2025 — GPAI obligations (already in force)
Providers of general-purpose AI models must meet transparency obligations, publish training-data summaries including copyrighted material, and — for models above 10^25 FLOPs — run systemic risk assessment, incident reporting, and model evaluation. This chapter is fully in force and enforced.
August 2, 2026 — Transparency + AI Office (in force)
Article 50 transparency rules apply across the board: AI-generated content must be labeled, deepfakes disclosed, and emotion-recognition and biometric-categorization systems flagged. The AI Office's GPAI enforcement powers went live the same day, with graduated procedures running from information requests to corrective orders and fines.
December 2, 2026 — New prohibitions + watermarking grace end
The new Article 5 prohibitions enter into force, and the grace period for watermarking and detection on pre-August-2026 GPAI models expires. Providers still shipping AI-generated content without disclosure mechanisms become exposed to enforcement.
December 2, 2027 — High-risk (Annex III)
The largest practical deadline for most organizations. Providers and deployers of Annex III high-risk systems — critical infrastructure, education and employment decisions, access to essential services, migration, and law enforcement — must meet the full high-risk regime: risk management system, data governance, technical documentation, logging, transparency, human oversight, and robustness and cybersecurity.
August 2, 2028 — High-risk (Annex I)
Manufacturers placing on the market safety-critical products that embed AI — machinery, toys, medical devices, vehicles, and other Annex I product categories — must satisfy the high-risk requirements integrated with existing product-safety legislation.
August 2, 2030 — Public sector
High-risk AI systems deployed by public authorities and bodies come into scope last, reflecting the longer implementation cycles of public procurement.
What Organizations Should Do Now
Check your phase
Identify which deadline cluster your systems fall into: GPAI provider, Article 50 deployer, Annex III high-risk, Annex I product, or public sector. Most organizations sit in the Article 50 and Annex III groups.
Inventory your AI systems
Catalog every AI system you build or deploy — model type, data flows, vendors, deployment context. This is the foundation for every later step and the prerequisite for determining which timeline applies.
Prepare transparency (due now)
Label AI-generated content, disclose deepfakes and bot interactions, and document training data for any models you provide. If you placed GPAI models on the market before August 2, 2026, treat December 2, 2026 as your watermarking deadline.
Build the high-risk track for December 2027
The Annex III regime is broad. Use the interval to stand up your risk management system, technical documentation, human oversight procedures, and logging before December 2, 2027.
Frequently Asked Questions
Why did the Omnibus push back the high-risk deadlines?
The co-legislators granted additional implementation time so providers and deployers can build the required governance systems, and to reduce the burden on small and medium-sized businesses — particularly for the broad Annex III categories.
I am deploying a high-risk AI system now. When do the rules apply to me?
If your system falls in an Annex III category, the high-risk obligations apply from December 2, 2027; systems placed on the market after that date must comply from the start. Annex I products follow on August 2, 2028, and public-sector deployments on August 2, 2030.
Do the transparency rules apply to me from August 2, 2026?
Yes, if you deploy AI that generates content or interacts with people. Article 50 applies to providers and deployers of AI systems and GPAI models, and the AI Office can enforce it for GPAI from August 2, 2026.
What changed for GPAI providers under the Omnibus?
GPAI obligations were already in force from August 2025. The Omnibus mainly extended the watermarking and detection grace period for models already on the market until December 2, 2026, and added the new Article 5 prohibitions from that date.
Are the penalties affected by the Omnibus?
No. The penalty framework is unchanged: up to 35 million EUR or 7% of global annual turnover for prohibited practices and serious GPAI and high-risk violations.
Sources
European Commission. (2024). Regulation (EU) 2024/1689 of the European Parliament and of the Council (EU AI Act). Official Journal of the European Union. https://eur-lex.europa.eu/eli/reg/2024/1689
European Commission. (2026). Regulation (EU) 2026/1744 — Digital Omnibus on AI. Official Journal of the European Union.
Top comments (0)