The EU AI Act applies in stages. Prohibitions and AI literacy have applied since 2 February 2025, rules for general-purpose AI models since 2 August 2025, and transparency duties since 2 August 2026. After the Digital Omnibus on AI, in force since 27 July 2026, high-risk obligations apply from 2 December 2027 for stand-alone systems and 2 August 2028 for AI in regulated products.1,2

Summary

  1. Most of the Act already applies. Prohibitions, AI literacy, general-purpose AI rules and the Article 50 transparency duties are in force and enforceable today.
  2. The high-risk regime moved, nothing was cancelled. The Omnibus added 16 months for Annex III use cases and 12 months for AI in regulated products, plus a short grace period for content marking.
  3. Two new dates arrive on 2 December 2026: a ban on AI that generates non-consensual intimate imagery or child sexual abuse material, and content marking for generative systems already on the market.

Changelog

Last checked 28 September 2026 against EUR-Lex and the European Commission. Newest first.

  • 28 Sep 2026. Page published. All dates checked against the Official Journal texts on EUR-Lex. EUR-Lex
  • 2 Aug 2026. General application. Article 50 transparency duties apply; national authorities and the AI Office enforce. European Commission
  • 27 Jul 2026. Digital Omnibus on AI, Regulation (EU) 2026/1744, enters into force after publication on 24 July. EUR-Lex
  • 20 Jul 2026. Commission publishes its guidelines on the Article 50 transparency obligations. European Commission
  • 29 Jun 2026. Council gives final approval to the Digital Omnibus on AI. Council of the EU
  • 10 Jun 2026. Final Code of Practice on transparency of AI-generated content published. European Commission
  • 19 May 2026. Commission publishes draft guidelines on classifying high-risk AI systems for consultation. European Commission

What are the EU AI Act dates after the Digital Omnibus?

The table lists every application date in the AI Act as amended by Regulation (EU) 2026/1744. Dates for Commission guidelines and reports are left out; only dates that create or change legal obligations are shown.

EU AI Act application dates, as amended

Date What applies Provision Who it binds
1 Aug 2024 AI Act enters into force Art. 113 No duties yet
2 Feb 2025 Prohibited practices; AI literacy Art. 4, 5 Providers, deployers
2 Aug 2025 General-purpose AI models; governance; penalties Ch. V, VII, XII GPAI providers, Member States
27 Jul 2026 Digital Omnibus on AI in force Reg. 2026/1744 All operators
2 Aug 2026 General application; transparency duties Art. 50, 113 Providers, deployers
2 Aug 2026 Fines on general-purpose AI providers Art. 101 GPAI providers
2 Dec 2026 New bans: intimate deepfakes, abuse material Art. 5(1)(ba), (bb) Providers, deployers
2 Dec 2026 Content marking for systems sold before 2 Aug 2026 Art. 50(2), 111(4) Generative AI providers
2 Aug 2027 GPAI models placed before 2 Aug 2025 comply Art. 111(3) GPAI providers
2 Aug 2027 National AI regulatory sandbox operational Art. 57(1) Member States
2 Dec 2027 High-risk rules, Annex III use cases Art. 113(c)(i) Providers, deployers
2 Aug 2028 High-risk rules, AI in regulated products Art. 113(c)(ii) Providers, deployers
2 Aug 2030 Existing high-risk systems of public authorities Art. 111(2) Providers, public deployers
31 Dec 2030 AI in large-scale EU IT systems Art. 111(1) Operators of Annex X systems

Applies now Upcoming

Sources: Regulation (EU) 2024/1689, Articles 111 and 113; Regulation (EU) 2026/1744, Article 1; EUR-Lex, accessed 28 September 2026. GPAI: general-purpose AI. Status as of the last-checked date.

Exhibit 1

The Omnibus deferred the high-risk regime, not the Act

Measured from entry into force, Annex III obligations now start after 40 months instead of 24.

The Omnibus added 16 months for Annex III systems and 12 months for regulated products.

Time from entry into force to application, months

AI Act as adopted (2024) After the Digital Omnibus (2026)
0 12 24 36 48 60 24 28 24 40 36 48 Marking of AI content¹ High-risk, Annex III² High-risk, products³

1 Article 50(2), generative AI systems placed on the market before 2 August 2026: 2 August 2026 became 2 December 2026. 2 Stand-alone use cases in Annex III, such as credit scoring, recruitment and critical infrastructure: 2 August 2026 became 2 December 2027. 3 AI in products under Annex I, such as medical devices: 2 August 2027 became 2 August 2028.

Source: Regulation (EU) 2024/1689, Art. 113; Regulation (EU) 2026/1744, Art. 1(39) and (40); EUR-Lex, accessed 28 September 2026. Months rounded from 1 August 2024

What did the Digital Omnibus change?

The Commission proposed the Digital Omnibus on AI on 19 November 2025.9 The Council gave final approval on 29 June 2026,4 the regulation was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026.2 The changes that matter for most organisations:

  • High-risk dates. Chapter III, Sections 1 to 3 apply from 2 December 2027 for systems classified under Article 6(2) and Annex III, and from 2 August 2028 for systems under Article 6(1) and Annex I.
  • New prohibitions. From 2 December 2026, placing on the market or using AI systems that generate non-consensual intimate imagery of an identifiable person, or child sexual abuse material, is prohibited.
  • Content marking grace period. Generative systems placed on the market before 2 August 2026 must comply with the Article 50(2) marking duty by 2 December 2026.
  • AI literacy rewritten. Article 4 now requires providers and deployers to take measures to support AI literacy, without a duty to guarantee any individual's level. The Commission and Member States must support them.
  • Relief for small mid-caps. Simplifications that applied to SMEs, such as lighter technical documentation and lower fine caps, now extend to small mid-cap enterprises.
  • Sandboxes and machinery. The deadline for a national AI regulatory sandbox moved to 2 August 2027. The Machinery Regulation moved to Section B of Annex I; its AI requirements will come through machinery delegated acts that apply by 2 August 2028.

The Omnibus also allows providers and deployers to process special categories of personal data where strictly necessary to detect and correct bias, under strict safeguards, and extends the AI Office's supervision of AI systems built on general-purpose models and embedded in very large online platforms.2,3

What applies now, in September 2026?

Four sets of obligations are in force for organisations that use AI in the EU:

  1. Prohibited practices (Article 5). Manipulative techniques, social scoring, untargeted scraping for facial recognition databases and emotion recognition at work or in education, among others. Fines reach €35 million or 7 percent of worldwide turnover, whichever is higher.1
  2. AI literacy (Article 4). Measures to support the AI literacy of staff who operate or use AI systems, in the amended wording since 27 July 2026.
  3. General-purpose AI models (Chapter V). Documentation, copyright policy and training-data summary for model providers; since 2 August 2026 the Commission can fine them under Article 101.
  4. Transparency (Article 50). People must be told when they interact with an AI system, and AI-generated or manipulated content must be marked and, for deepfakes, disclosed. The Commission published guidelines on 20 July 2026 and a code of practice on 10 June 2026.6,7 Fines for these duties reach €15 million or 3 percent of turnover.5

The Commission's draft guidelines on high-risk classification, published for consultation on 19 May 2026, are not yet final.8 Until they are, organisations have to classify their systems on the text of Article 6 and Annex III.

Provider or deployer: which obligations are yours?

The Act assigns duties by role, not by where the system runs. A provider develops an AI system or model, or has it developed, and places it on the market or puts it into service under its own name. A deployer uses an AI system under its own authority.1

An organisation that runs an open-weight model on its own servers for internal work is in most cases a deployer. It becomes a provider of a high-risk system if it puts its name on one, makes a substantial modification, or changes the intended purpose so that the system becomes high-risk. Hosting choice does not change the role: a model on-premise, in a European cloud or behind an API carries the same AI Act duties. The guide to on-premise and private cloud AI covers the rules that do depend on where AI runs, and the self-hosted LLM guide covers running models yourself.

From 2 December 2027, the main deployer duties for Annex III systems are:

  • use the system according to the provider's instructions and assign competent human oversight (Article 26);
  • monitor operation, keep the logs under its control and report serious incidents;
  • inform workers before using high-risk AI at work, and inform people subject to decisions made with its help;
  • carry out a fundamental rights impact assessment if the deployer is a public body, a private entity providing public services, or uses AI for credit scoring or life and health insurance pricing (Article 27).

Sector exposure differs. Credit scoring and insurance pricing make financial services an Annex III sector, and public bodies face the fundamental rights assessment described on the public sector page. AI in medical devices falls under the 2 August 2028 date, as set out for healthcare and life sciences, while safety components of critical infrastructure follow the Annex III date.

What should deployers do before December 2027?

The deferral gives time, not an exemption. High-risk systems placed on the market or put into service before the new dates fall under the Act only if their design changes significantly afterwards, but systems used by public authorities must comply by 2 August 2030 regardless.2 A practical order of work:

  1. Build an AI system register: every system in use, its provider, its purpose and the data it processes.
  2. Classify each entry against Article 5, Annex III, Annex I and Article 50, and record your role for each.
  3. Close the obligations that already apply: AI literacy measures, transparency notices and content marking.
  4. For likely high-risk systems, request the provider's documentation and plan oversight and logging now.
  5. Review contracts so that providers commit to the information deployers need under Articles 13 and 26.

Lindstead maps AI Act, GDPR, DORA and NIS2 obligations to the AI systems an organisation actually runs, and deploys a first use case on infrastructure the organisation controls with the logging and oversight the Act expects. For the wider context on regulation, cost and control, see the 2026 European briefing.

Frequently asked questions

  • The AI Act entered into force on 1 August 2024 and applies in stages. Prohibitions and AI literacy apply since 2 February 2025, rules for general-purpose AI models since 2 August 2025, and the general date of application, including the Article 50 transparency duties, was 2 August 2026. High-risk obligations follow on 2 December 2027 for stand-alone systems and 2 August 2028 for AI in regulated products.

  • Partly. The Digital Omnibus on AI, Regulation (EU) 2026/1744 in force since 27 July 2026, postponed the high-risk obligations by 16 months for Annex III use cases and by 12 months for AI in regulated products. It did not postpone the prohibitions, the rules for general-purpose AI models or the Article 50 transparency duties, which applied on 2 August 2026; only content marking by generative systems already on the market received a grace period to 2 December 2026.

  • From 2 August 2026. Providers of generative AI systems that were already on the market before that date have until 2 December 2026 to add machine-readable marking of AI-generated content under Article 50(2).

  • On 2 December 2027 for high-risk systems listed in Annex III, such as AI used in recruitment, credit scoring, education or critical infrastructure, and on 2 August 2028 for AI that is a safety component of, or itself, a product covered by the EU harmonisation legislation in Annex I.

  • No. Article 4 still applies to providers and deployers, but it was rewritten. They must take measures to support the AI literacy of their staff and others operating AI on their behalf; the article now states that this does not require them to guarantee a specific level of literacy for any individual.

  • A provider develops an AI system or model, or has it developed, and places it on the market or puts it into service under its own name. A deployer uses an AI system under its own authority. Most organisations that run a model for internal use are deployers; they can become providers if they put their name on a high-risk system or substantially modify it.

Sources

  1. Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal, 12 July 2024. Articles 3, 4, 5, 27, 50, 99, 111 and 113. eur-lex.europa.eu/eli/reg/2024/1689/oj
  2. Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI), Official Journal, 24 July 2026. eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202601744
  3. European Commission, AI Omnibus enters into force, 27 July 2026. digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force
  4. Council of the EU, Artificial intelligence: Council gives final green light to simplify and streamline rules, 29 June 2026. www.consilium.europa.eu/en/press/press-releases/2026/06/29/artificial-intelligence-council-gives-final-green-light-to-simplify-and-streamline-rules/
  5. European Commission, Safer and more transparent AI, 2 August 2026. commission.europa.eu/news-and-media/news/safer-and-more-transparent-ai-2026-08-02_en
  6. European Commission, Guidelines on transparency obligations for providers and deployers of certain AI systems, 20 July 2026. digital-strategy.ec.europa.eu/en/news/commission-publishes-guidelines-transparency-obligations-providers-and-deployers-certain-ai-systems
  7. European Commission, Code of Practice on transparency of AI-generated content, page updated 31 July 2026. digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content
  8. European Commission, Draft guidelines on the classification of high-risk AI systems, 19 May 2026. digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems
  9. European Commission, Proposal for a Digital Omnibus on AI, COM(2025) 836, 19 November 2025. eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:52025PC0836
  10. Lewis Silkin, The Digital Omnibus on AI enters into force, 27 July 2026. www.lewissilkin.com/insights/2026/07/27/the-digital-omnibus-on-ai-enters-into-force-today-102nedo

Method: dates read from the Official Journal texts on EUR-Lex; Commission and Council pages for procedural dates. All sources accessed 28 September 2026. This page is general information, not legal advice. Corrections: contact@lindstead.com.