EU AI Act Deadlines: The Verified Timeline

Verified against the Official Journal on August 19, 2026: the EU AI Act’s prohibitions and AI-literacy duties have applied since February 2, 2025, general-purpose AI obligations since August 2, 2025, and the Article 50 transparency duties (chatbot disclosure, deepfake labeling, synthetic-content marking) have been in force since August 2, 2026. The "Digital Omnibus" amendment is now law — Regulation (EU) 2026/1744, adopted July 8, 2026 and published in the Official Journal on July 24, 2026 — deferring stand-alone Annex III high-risk duties to December 2, 2027 and product-embedded Annex I duties to August 2, 2028. The next deadline on the calendar is December 2, 2026: machine-readable marking for generative systems already on the market.

Reviewed by · Updated

Free: The ISO 42001 Starter Checklist for an AIMS (9 steps) →

The timeline as it stands on August 19, 2026

Regulation (EU) 2024/1689 entered into force on August 1, 2024 with staggered application dates. The Digital Omnibus amendment that reshuffles the high-risk dates is no longer pending: it was adopted as Regulation (EU) 2026/1744 on July 8, 2026, published in the Official Journal on July 24, 2026, and entered into force three days after publication. The dates below are read from the published OJ text, not from press releases.

ObligationDateStatus (July 4, 2026)
Prohibited AI practices (Art. 5) + AI literacy (Art. 4)February 2, 2025In force
General-purpose AI model obligations + EU governance structuresAugust 2, 2025In force
Transparency duties (Art. 50): chatbot disclosure, deepfake labeling, marking synthetic content — new systemsAugust 2, 2026In force since August 2, 2026
Machine-readable marking for generative systems already on the market before Aug 2, 2026December 2, 2026The next deadline — Art. 111(4) as amended by Reg. (EU) 2026/1744
New prohibition: AI generating non-consensual intimate imagery / CSAMDecember 2, 2026Added by Reg. (EU) 2026/1744
Stand-alone high-risk AI systems (Annex III)December 2, 2027Deferred from Aug 2, 2026 by Reg. (EU) 2026/1744
High-risk AI embedded in regulated products (Annex I)August 2, 2028Deferred by Reg. (EU) 2026/1744
National AI regulatory sandboxes operationalAugust 2, 2027Postponed from Aug 2, 2026

Sources: Regulation (EU) 2024/1689 and Regulation (EU) 2026/1744 of July 8, 2026, published in the Official Journal on July 24, 2026 (eur-lex.europa.eu/eli/reg/2026/1744/oj — the OJ text was read directly); European Commission Article 50 transparency FAQ (digital-strategy.ec.europa.eu, last updated July 24, 2026). Verified August 19, 2026.

Penalties (Article 99) — unchanged by the Omnibus

The fine maximums scale with worldwide annual turnover, whichever amount is higher — with one deliberate break for small businesses: for SMEs and start-ups, each fine is capped at the lower of the fixed amount or the percentage.

ViolationMaximum fine
Prohibited practices (Art. 5)€35 million or 7% of worldwide annual turnover
Most other obligations (incl. high-risk duties and Art. 50 transparency)€15 million or 3%
Supplying incorrect or misleading information to authorities€7.5 million or 1%
SMEs and start-upsThe lower of the applicable amount or percentage

Source: Regulation (EU) 2024/1689, Article 99 (eur-lex.europa.eu/eli/reg/2024/1689/oj).

What changed for small businesses

Three Omnibus changes matter most for smaller organizations:

  • The simplified technical-documentation form previously reserved for SMEs is extended to "small mid-caps" — companies up to roughly 750 employees or €150 million annual revenue.
  • National AI regulatory sandboxes, which SMEs were promised priority access to, are pushed to August 2, 2027.
  • The deferral applies to the high-risk regime only. If you deploy a customer-facing chatbot, generate synthetic content or use emotion recognition, the Article 50 transparency duties still land on August 2, 2026.

What to do before December 2, 2026

The Article 50 transparency duties are no longer upcoming — they have applied since August 2, 2026: disclose AI interaction to users, label deepfakes and machine-generated content, and document how your systems do it. The next date on the calendar is December 2, 2026, when the transitional allowance ends for generative AI systems that were already on the market before August 2, 2026: from that day their outputs must carry machine-readable marking too (Article 111(4) of Regulation 2024/1689 as amended by Regulation 2026/1744). The same date adds the new prohibition on AI that generates non-consensual intimate imagery or child sexual abuse material.

For most small companies the practical work is an AI usage policy, an AI system register with risk classification, transparency notices, and a record of how each generative system marks its output — the documentation layer an AI governance pack covers. ISO/IEC 42001 remains the certifiable management-system standard for organizations that want audited proof of AI governance. No template makes an organization compliant with the AI Act; compliance comes from operating the controls, and for high-risk systems the deferred dates buy time to build them properly.

Frequently asked questions

Do high-risk AI rules still start on August 2, 2026?
No. The Digital Omnibus amendment is now law: Regulation (EU) 2026/1744, adopted July 8, 2026 and published in the Official Journal on July 24, 2026, defers stand-alone Annex III high-risk obligations to December 2, 2027 and product-embedded Annex I obligations to August 2, 2028. The deferral is on the statute book — read directly from the published OJ text.
What is the December 2, 2026 EU AI Act deadline?
Two things land on December 2, 2026. Generative AI systems that were already on the market before August 2, 2026 lose their transitional allowance and must mark their outputs in a machine-readable format (Article 111(4) of Regulation 2024/1689 as amended). And the new prohibition on AI generating non-consensual intimate imagery or child sexual abuse material takes effect. New systems have owed the Article 50 transparency duties since August 2, 2026.
What is Regulation (EU) 2026/1744?
The "Digital Omnibus on AI" — the regulation of July 8, 2026 that amends the EU AI Act (Regulation (EU) 2024/1689). Published in the Official Journal on July 24, 2026, it defers the high-risk regime (Annex III to December 2, 2027; Annex I products to August 2, 2028), adds the December 2, 2026 machine-readable-marking deadline for generative systems already on the market, adds a prohibition on AI generating non-consensual intimate imagery or CSAM, and extends simplified documentation to small mid-caps. Its ELI citation is eur-lex.europa.eu/eli/reg/2026/1744/oj.
Was the EU AI Act delayed?
Partly. Only the high-risk regime was deferred (to December 2, 2027 for Annex III and August 2, 2028 for Annex I products). The prohibitions and AI-literacy duties (in force since February 2, 2025), the general-purpose AI obligations (since August 2, 2025) and the Article 50 transparency duties (in force since August 2, 2026) were not postponed.
What EU AI Act rules apply right now?
As of August 2026: the bans on prohibited AI practices and the AI-literacy duty (since February 2, 2025), the obligations for general-purpose AI models plus the EU governance framework (since August 2, 2025), and the Article 50 transparency duties — chatbot disclosure, deepfake labeling, synthetic-content marking — in force since August 2, 2026.
What are the maximum EU AI Act fines?
Up to €35 million or 7% of total worldwide annual turnover for prohibited practices; up to €15 million or 3% for most other violations, including the high-risk and transparency duties; up to €7.5 million or 1% for supplying incorrect information to authorities. For SMEs and start-ups each fine is capped at the lower of the amount or the percentage (Art. 99).
Does the EU AI Act apply to small businesses?
Yes — there is no small-business exemption from the prohibitions, transparency duties or (when they apply) high-risk obligations. The Act does soften the impact: fines for SMEs are capped at the lower tier value, and the 2026 Omnibus extends simplified technical documentation to companies up to roughly 750 employees or €150 million revenue.

Related guides: AI Governance (EU AI Act & NIST AI RMF) · ISO 42001

Toolkits that help

AI Governance (EU AI Act + NIST AI RMF)

AI Governance Policy Pack

10 editable AI policies — including an employee AI use policy and an AI risk register — aligned to the EU AI Act and NIST AI RMF. Govern workplace AI before regulators and clients ask.

ISO/IEC 42001:2023 AI Management System

ISO 42001 AI Management System Toolkit

14 editable ISO/IEC 42001:2023 policies and procedures — impact assessments, AI lifecycle, data governance, third-party AI — plus the Annex A Statement of Applicability, an AI risk register, and an audit evidence checklist.

Related articles

Get new templates and guides by email

An occasional email when we publish a new free template, guide, or dataset. Unsubscribe any time.

← All articles

Professional editable templates — general information only, not legal, audit, tax, or certification advice, and no professional or advisory relationship is created. No purchase makes an organization compliant or certified. Review each document with qualified counsel, your compliance professional, or your auditor before relying on it. ISO, IEC, SOC 2, AICPA, HIPAA, NIST, GDPR, the EU AI Act, IRS and FTC are referenced descriptively only; ComplianceDocs (ExpertEngine LLC) is independent and is not affiliated with, endorsed by, or certified by any standards body, regulator, or audit firm.