What is the timeline for implementing the EU AI Act? Since 2 August 2026 the answer has changed in two ways at once: the European Commission's AI Office became formally entitled to enforce the rules for general-purpose AI models, and the transparency duties for chatbots, deepfakes and AI-generated content began to apply, while the heaviest obligations, those for high-risk AI systems, were pushed back by the Digital Omnibus on AI to December 2027 and August 2028. The result is a staggered EU AI Act timeline that many compliance plans written in 2024 and 2025 no longer match. Six weeks into the enforcement phase, and with a 16 September 2026 Lawfare analysis warning that even models a company never sells can fall within scope, this article sets out which obligations already bite, which have moved, what the penalties are and what general counsel should be doing before the next deadline on 2 December 2026. It continues our coverage of the struggle for regulatory supremacy over AI.
The EU AI Act timeline at a glance
The EU AI Act applies in stages: it entered into force on 1 August 2024, its bans and AI literacy duty have applied since 2 February 2025, the general-purpose AI rules since 2 August 2025, most remaining provisions and the transparency rules since 2 August 2026, and the high-risk regime from 2 December 2027 or 2 August 2028 depending on the type of system. The Act (Regulation (EU) 2024/1689) was published in the Official Journal on 12 July 2024 and was designed from the start to phase in over several years, so that businesses and regulators could build the necessary infrastructure. The Digital Omnibus on AI, which entered into force on 27 July 2026, rewrote several of the later dates and added new ones.
The table below consolidates the dates as they stand after the omnibus. It is the single most useful reference for anyone mapping an AI inventory against the law, because the obligation that matters to a given business depends on both its role and the category of system it builds or uses.
| Date | What applies | Who is affected |
|---|---|---|
| 1 August 2024 | AI Act enters into force; no obligations yet apply | All |
| 2 February 2025 | Prohibited AI practices and the AI literacy duty | Providers and deployers |
| 2 August 2025 | General-purpose AI model obligations, governance, notified bodies, penalty rules | GPAI model providers, Member States |
| 27 July 2026 | Digital Omnibus on AI enters into force | All |
| 2 August 2026 | Article 50 transparency rules and most remaining provisions; AI Office enforcement powers over GPAI providers | Providers and deployers of chatbots, generative AI, deepfakes; GPAI providers |
| 2 December 2026 | Ban on AI generating non-consensual intimate imagery and child sexual abuse material; machine-readable marking deadline for generative systems already on the market before 2 August 2026 | Providers of generative AI |
| 2 August 2027 | Compliance deadline for GPAI models placed on the market before 2 August 2025; national regulatory sandboxes due | Legacy GPAI providers, Member States |
| 2 December 2027 | High-risk rules for stand-alone systems listed in Annex III | Providers and deployers of high-risk AI |
| 2 August 2028 | High-risk rules for AI in products covered by Annex I legislation | Manufacturers of regulated products |
The dates are drawn from the Commission's AI Act policy page, the entry-into-force analysis by Lewis Silkin and the Wilson Sonsini note on the enforcement phase. The practical message is that 2026 was never the finishing line: it is the year enforcement began, not the year compliance ended.
What the Digital Omnibus on AI changed, and when
The Digital Omnibus on AI is an amending regulation that delayed the high-risk rules, created a new prohibition and eased several obligations for smaller companies, without changing the Act's basic risk-based structure. The Commission proposed it on 19 November 2025 as part of a wider simplification drive, and the Parliament and Council reached a political agreement on 7 May 2026. In the Commission's announcement of that deal, Executive Vice-President Henna Virkkunen said businesses and citizens "want to be able to innovate and feel safe", and that the agreement did both.
Formal adoption followed quickly. The final text was adopted by the Parliament on 16 June 2026 and the Council on 29 June 2026, and Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, days before the original 2 August deadline for high-risk systems would have arrived. That timing mattered: without it, the high-risk regime would have applied before harmonised standards and Commission guidance were ready.
The main changes businesses need to know are these:
- High-risk delay. Stand-alone high-risk systems in areas such as biometrics, critical infrastructure, education, employment, migration, asylum and border control move to 2 December 2027; AI in products such as lifts or toys moves to 2 August 2028. The Commission said the sequencing would help ensure technical standards and other support tools are in place first.
- A new prohibition. AI systems that generate non-consensual sexually explicit or intimate content, or child sexual abuse material, such as so-called nudification apps, are banned from 2 December 2026.
- Marking grace period. Generative systems already on the market before 2 August 2026 have until 2 December 2026 to apply machine-readable marking under Article 50(2).
- Machinery carve-out. AI embedded in products under the Machinery Regulation falls outside the direct scope of the high-risk rules, while medical devices and toys remain in scope, according to Freshfields' analysis of the final text.
- Relief for small mid-caps. Certain privileges previously limited to small and medium-sized enterprises are extended to small mid-cap companies.
- Bias detection data. The legal basis for processing special categories of personal data to detect and correct bias is widened beyond high-risk providers, subject to safeguards.
- Stronger AI Office. The Commission's AI Office gains clearer powers over AI systems built on general-purpose models by the same company, and over AI embedded in very large online platforms and search engines.
What the omnibus did not do is equally important. It did not repeal any risk tier, did not soften the penalties for prohibited practices, and did not delay the general-purpose AI or transparency obligations. It also arrived at a moment when Brussels was showing no sign of retreat on digital enforcement elsewhere, as the General Court's decision to uphold Apple's DMA gatekeeper status in July underlined.
What already applies: prohibited practices and AI literacy
Two sets of obligations have applied to almost every business since 2 February 2025: the ban on certain AI practices and the duty to support AI literacy among staff. The Commission lists eight prohibited practices in force since that date: harmful AI-based manipulation and deception; harmful exploitation of vulnerabilities; social scoring; individual criminal offence risk assessment or prediction; untargeted scraping of facial images to build recognition databases; emotion recognition in workplaces and education; biometric categorisation to infer protected characteristics; and real-time remote biometric identification for law enforcement in publicly accessible spaces. The omnibus adds a ninth, the nudification and child abuse material ban, from December 2026.
For most corporate users the practical exposure lies in the workplace. Emotion recognition tools marketed for call-centre monitoring or candidate interviews, for example, may fall squarely within the ban, which carries the Act's highest fines. The new ninth prohibition responds to a concern regulators have been voicing about online harms to children, echoed in the UK by police chiefs calling for tighter social media controls for under-16s.
The AI literacy duty in Article 4 has been softened. As originally drafted, providers and deployers had to take measures to ensure a sufficient level of AI literacy among staff. After the omnibus, organisations must take measures to support the development of AI literacy, but are not required to guarantee any specific level. According to Lewis Silkin, documented training programmes should now suffice rather than individual competence, and the Commission says it and the Member States will take on more of the work of promoting AI literacy. That is a lighter burden, not a repeal: a business that has done nothing still has a gap. The pressure to build AI-ready workforces is not new, as our earlier coverage of employers racing to hire AI-ready talent showed.
The AI Act transparency obligations that began on 2 August 2026
Since 2 August 2026, businesses that provide or deploy certain AI systems must tell people when they are dealing with AI and label AI-generated or manipulated content. The Commission's announcement on the day the rules took effect summarises the core duties under Article 50:
- Interaction disclosure. People must be informed when they are engaging with a chatbot, AI agent or avatar rather than a person.
- Machine-readable marking. Providers of systems that generate synthetic audio, images, video or text must mark outputs so they are detectable as artificially generated.
- Deepfake labelling. Deployers must clearly and visibly label deepfakes, meaning manipulated images, audio or video of real persons, objects or events.
- Biometric notices. Deployers of emotion recognition or biometric categorisation systems must inform the people exposed to them.
- Public-interest text. AI-generated text published to inform the public on matters of public interest must be labelled unless it has undergone human editorial control.
The Commission published final guidelines on Article 50 on 20 July 2026, and by July around 190 organisations had signed the voluntary Code of Practice on Transparency of AI-Generated Content, which the Commission and the AI Board have assessed as adequate for demonstrating compliance. The guidelines go further than many expected. Mayer Brown notes that an AI agent must disclose not only its artificial nature but also the person on whose behalf it is acting, and that content can be a deepfake if it depicts something that could exist, even where the person shown never did.
That wider definition matters for marketing teams. Browne Jacobson observed on 11 September 2026 that advertising will generally not benefit from the lighter disclosure regime for artistic, creative or satirical works, and that labels must appear at the point of first exposure. The questions of consent and likeness that arise when AI recreates a real person are already being litigated, as the Dua Lipa and Samsung image rights dispute shows. Breaches of the transparency rules carry fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher.
General-purpose AI models: the code of practice and AI Office enforcement
Providers of general-purpose AI models have had obligations since 2 August 2025, and since 2 August 2026 the Commission can enforce them with fines. Article 53 requires providers to keep technical documentation of the model, give downstream developers the information they need, maintain a policy to comply with EU copyright law and publish a sufficiently detailed summary of training content. Models released under free and open-source licences are exempt from the first two, unless they pose systemic risk. A model is presumed to have systemic risk when the compute used to train it exceeds 10^25 floating point operations, which triggers additional duties to assess and mitigate risks.
The General-Purpose AI Code of Practice, published on 10 July 2025, is the main compliance tool. It has three chapters: transparency, with a Model Documentation Form; copyright; and safety and security, which applies only to providers of models with systemic risk. The Commission and the AI Board have confirmed it is an adequate voluntary tool for demonstrating compliance. More than 20 companies have signed, including Amazon, Anthropic, Google, Microsoft, OpenAI and Mistral AI; xAI signed only the safety and security chapter. The copyright chapter is where many rights holders and their intellectual property advisers will focus.
From 2 August 2026, according to Wilson Sonsini, the AI Office can request information and documentation, obtain access to models for evaluation, require corrective or risk-mitigation measures and, in serious cases, restrict, withdraw or recall a model, with fines of up to the higher of €15 million or 3% of worldwide annual turnover. Models placed on the market before 2 August 2025 have until 2 August 2027 to comply. The AI Office has signalled that it prefers technical compliance dialogues as a first step, with formal powers used where dialogue fails. Its enlarged remit over AI inside very large online platforms links the AI Act with Digital Services Act supervision, where regulators are already under pressure over issues such as the complaints against Google, Meta and TikTok over scam advertising.
Internal deployment: when a model you never sell is still in scope
A company does not escape the general-purpose AI rules simply by keeping a model in-house. In the Lawfare analysis published on 16 September 2026, Eliška Andrš argues that "putting into service" under the Act includes supplying an AI system for the provider's own use in the Union, and that under Recital 97 the underlying model is then considered to be placed on the market. The research exemptions are narrow: one covers systems developed for the sole purpose of scientific research, the other covers activity only before a system is placed on the market or put into service.
The practical consequence, on that reading, is that obligations such as copyright compliance, training data records and technical documentation need to be built during development rather than retrofitted. For groups that train or fine-tune models for internal tools, the question is no longer only whether a product is launched in Europe, but whether the model is being used there at all.
Companies that build on another provider's model through an API are in a different position. A 9 September 2026 analysis in Security Boulevard notes that they usually remain deployers, and that rebranding a chatbot does not by itself make them providers under Article 25. Their most immediate duty is likely to be the Article 50 transparency rules, and they should ask their model provider for the Annex XII documentation on capabilities, limitations and integration.
High-risk AI systems: what counts and the new dates
An AI system is high-risk under the EU AI Act either because it is a safety component of a product that needs third-party conformity assessment under EU product law listed in Annex I, or because it is used in one of the sensitive areas listed in Annex III. Article 6 sets out both routes. The Annex III areas include biometrics, critical infrastructure, education, employment and worker management, access to essential services including credit scoring, law enforcement, migration and border control, and the administration of justice.
There is a way out for some Annex III systems. Under Article 6(3), a listed system is not high-risk if it poses no significant risk of harm and performs a narrow procedural task, improves the result of a completed human activity, detects deviations in decision-making patterns without replacing human review, or performs a preparatory task. Profiling of individuals is always high-risk. A provider relying on the derogation must document its assessment before placing the system on the market and register it in the EU database, although the omnibus slimmed down the registration details required.
Classification guidance arrived late. The Commission was due to publish its Article 6 guidelines by 2 February 2026, but a 170-page draft appeared only in May 2026, with consultation open until 23 June 2026. One point from the draft, highlighted by Mayer Brown, deserves attention: providers must clearly describe the envisaged use of a system in technical documentation and marketing material, because ambiguity about intended purpose can pull a product into the high-risk category.
Employment is the Annex III area most general businesses will meet first. AI used for recruitment, screening, promotion or performance monitoring is likely to be high-risk from December 2027, which makes the delay a planning window rather than a reprieve for HR teams and their employment lawyers. Manufacturers of medical devices, meanwhile, have until August 2028, and their life sciences advisers will need to align AI Act conformity with existing device regulation.
Provider or deployer: why your role decides your obligations
The AI Act allocates most duties by role, so the first compliance question is always whether the business is a provider, which develops a system or places it on the market under its own name, or a deployer, which uses a system under its authority in a professional capacity. Providers of high-risk systems carry the heaviest load: risk management, data governance, technical documentation, conformity assessment and registration. Deployers have a shorter but real list.
Under Article 26, deployers of high-risk systems must use them in accordance with the instructions for use; assign human oversight to people with the necessary competence, training and authority; ensure input data they control is relevant and sufficiently representative; monitor operation and report risks and serious incidents; keep automatically generated logs for at least six months; inform workers' representatives and affected workers before using a high-risk system in the workplace; tell people when they are subject to decisions made or assisted by such a system; and use the provider's information to complete any data protection impact assessment.
Roles can change. Article 25 treats a distributor, importer or deployer as a provider if it puts its name or trade mark on a high-risk system already on the market, makes a substantial modification to one, or changes the intended purpose of a system, including a general-purpose system, so that it becomes high-risk. A bank that repurposes a general chatbot to assess creditworthiness, for example, may find it has become a provider of a high-risk system. The allocation of accountability in the AI supply chain is a theme we explored in who is liable when law firms use AI, and contracts with vendors should now reflect the Act's roles expressly.
Does the EU AI Act apply to UK and US companies?
Yes, in many cases. Article 2 applies the Act to providers placing AI systems or general-purpose models on the EU market wherever they are established, to deployers located in the EU, and to providers and deployers in third countries where the output of the system is used in the Union. Importers, distributors and product manufacturers are also covered. The exclusions are for military and national security uses, pre-market research and development, and purely personal, non-professional use.
The output test is the one that catches many British and American businesses. A UK recruiter screening candidates for an EU client, or a US software company whose chatbot serves EU customers, can be within scope without any EU establishment. As Security Boulevard put it, the location where the output is used, not where the company sits, is the trigger. The UK has no equivalent AI-specific statute: Browne Jacobson notes that UK advertisers instead rely on general consumer law, including the Digital Markets, Competition and Consumers Act 2024, so a business targeting both markets faces two different regimes. Britain's more permissive, regulator-led approach has let novel services emerge, such as the SRA-approved Garfield AI law firm, but that does not alter what the EU requires once output reaches EU users. Advisers who handle both sides can be found through the UK directory.
EU AI Act fines and who enforces them
The EU AI Act sets three tiers of fines, capped at the higher of a fixed sum or a percentage of worldwide annual turnover, with the top tier reserved for prohibited practices. Article 99 sets the ceilings, and for SMEs, including start-ups, the lower of the two figures applies. The omnibus added a provision extending reduced fines to small mid-caps.
| Breach | Maximum fine | Enforcer |
|---|---|---|
| Prohibited AI practices (Article 5) | €35 million or 7% of worldwide annual turnover | National market surveillance authorities |
| Most other obligations, including high-risk duties and Article 50 transparency | €15 million or 3% | National authorities; AI Office for systems it supervises |
| Supplying incorrect, incomplete or misleading information | €7.5 million or 1% | National authorities |
| General-purpose AI model obligations | €15 million or 3% | European Commission (AI Office) |
| EU institutions, bodies and agencies | €750,000 | European Data Protection Supervisor |
The Commission confirms that three sets of enforcers share the work: national market surveillance authorities, the AI Office for the systems it supervises, and the European Data Protection Supervisor for EU institutions. Enforcement will therefore vary by Member State, much as it does under the GDPR. The Commission's recent record under neighbouring digital laws suggests it will use its powers once they are available: in July it imposed a record €550m Digital Services Act fine on AliExpress.
What businesses should do before the next deadlines
The most useful step now is to turn the EU AI Act timeline into a dated work plan tied to an inventory of every AI system the business builds, buys or uses. The delays create time, but the underlying obligations, including risk management, documentation and conformity assessment, remain and take months to implement. The checklist below is a practical starting point.
| Action | Why it matters | Deadline to plan against |
|---|---|---|
| Build and maintain an AI inventory, recording role (provider or deployer) and risk category | Every obligation depends on role and category | Now |
| Screen for prohibited practices, especially workplace emotion recognition | Highest fines; in force since February 2025 | Now |
| Document AI literacy training | Article 4 still applies in softened form | Now |
| Add AI disclosures to chatbots and agents; label deepfakes in marketing | Article 50 applies since 2 August 2026 | Now |
| Confirm generative tools apply machine-readable marking | Grace period for legacy systems ends | 2 December 2026 |
| Obtain Annex XII documentation from GPAI model providers | Needed to meet downstream duties | Now |
| Classify HR, credit and other Annex III uses; document any Article 6(3) derogation | High-risk rules apply | 2 December 2027 |
| Review vendor contracts for AI Act roles, logs and incident reporting | Article 25 role changes shift liability | Before renewal |
Governance is as important as paperwork. Businesses should decide who owns AI compliance, how new tools are approved, and how errors are caught before they cause harm. The courts have already shown how quickly unchecked AI output becomes a professional problem, as the court warning after the Pinsent Masons AI filing error illustrated.
When to bring in an adviser
Much of the EU AI Act timeline can be managed in-house, but specialist advice is worth taking when a business is unsure whether it is a provider or a deployer, when an Annex III use case might qualify for the Article 6(3) derogation, when it fine-tunes or trains general-purpose models, or when it sells AI-enabled products into several Member States with different enforcement authorities. Cross-border groups will often need both a technology regulatory adviser and local counsel in the jurisdictions where their AI output is used. Corporate INTL's directory lists technology, media and telecoms advisers and regulatory specialists across the EU and beyond. The central point bears repeating: the omnibus moved the high-risk deadlines, but the EU AI Act timeline already has live obligations, live enforcement and a further deadline on 2 December 2026.
Frequently asked questions
What is the timeline for implementing the EU AI Act?
The AI Act entered into force on 1 August 2024. Prohibitions and AI literacy applied from 2 February 2025, general-purpose AI rules from 2 August 2025, and transparency rules from 2 August 2026. High-risk rules apply from 2 December 2027 for Annex III systems and 2 August 2028 for AI in regulated products.
Has the EU AI Act been delayed?
Partly. The Digital Omnibus on AI, in force since 27 July 2026, delayed the high-risk rules from 2 August 2026 to 2 December 2027 and 2 August 2028, and gave legacy generative systems until 2 December 2026 for content marking. Prohibitions, AI literacy, general-purpose AI rules and most transparency duties were not delayed.
What are the key changes in the EU AI regulations for 2026?
In 2026 the AI Office gained enforcement powers over general-purpose AI providers, Article 50 transparency rules began to apply, and the omnibus delayed high-risk rules, softened AI literacy, extended SME relief to small mid-caps, carved out machinery and added a ban on nudification and child abuse material apps.
What is considered high-risk under the EU AI Act?
A system is high-risk if it is a safety component of a product needing third-party assessment under Annex I legislation, or is used in an Annex III area such as biometrics, critical infrastructure, education, employment, credit scoring, law enforcement, migration or justice. Some Annex III systems can qualify for a narrow derogation, but profiling is always high-risk.
Does the EU AI Act apply to UK and US companies?
It can. The Act applies to providers placing AI on the EU market wherever they are based, and to providers and deployers outside the EU where the system's output is used in the Union. A UK or US business serving EU customers or clients through AI may therefore be in scope without an EU office.
What is the highest fine under the EU AI Act?
The highest fine is up to €35 million or 7% of total worldwide annual turnover, whichever is higher, for using prohibited AI practices. Most other breaches carry up to €15 million or 3%, and supplying misleading information up to €7.5 million or 1%. SMEs and start-ups pay the lower of the two figures.
What is the General-Purpose AI Code of Practice?
It is a voluntary code published on 10 July 2025 to help providers of general-purpose AI models comply with the AI Act. It has chapters on transparency, copyright, and safety and security. The Commission and AI Board have confirmed it is an adequate tool, and more than 20 providers have signed it.
Do deployers have obligations under the EU AI Act?
Yes. All deployers must meet the transparency rules where relevant and support AI literacy. Deployers of high-risk systems must follow instructions for use, assign competent human oversight, monitor operation, keep logs for at least six months, inform workers before workplace use and tell people subject to AI-assisted decisions.
What changed for AI literacy under the omnibus?
Article 4 originally required providers and deployers to ensure a sufficient level of AI literacy among staff. After the omnibus they must take measures to support AI literacy but need not guarantee a specific level, and the Commission and Member States take on more of the promotional role. Documented training remains advisable.
Sources
- European Commission: EU agrees to simplify AI rules to boost innovation and ban nudification apps (7 May 2026)
- European Commission: AI Omnibus enters into force (27 July 2026)
- European Commission: Safer and more transparent AI (2 August 2026)
- European Commission: AI Act, Shaping Europe's digital future
- European Commission: The General-Purpose AI Code of Practice
- EU Artificial Intelligence Act: Implementation timeline
- EU AI Act, Article 2: Scope
- EU AI Act, Article 6: Classification rules for high-risk AI systems
- EU AI Act, Article 25: Responsibilities along the AI value chain
- EU AI Act, Article 26: Obligations of deployers of high-risk AI systems
- EU AI Act, Article 51: Classification of GPAI models with systemic risk
- EU AI Act, Article 53: Obligations for providers of GPAI models
- EU AI Act, Article 99: Penalties
- Wilson Sonsini: EU AI Act Enforcement Phase Begins (3 August 2026)
- Freshfields: EU AI Act unpacked #34, the final Digital Omnibus on AI (10 July 2026)
- Lewis Silkin: The Digital Omnibus on AI enters into force today (27 July 2026)
- Addleshaw Goddard: EU AI Act, AI Omnibus formally adopted
- Pinsent Masons Out-Law: Law delaying EU's high-risk AI rules finalised
- Hogan Lovells Cadwalader: The AI Act's transparency obligations in light of the final guidelines (31 July 2026)
- Mayer Brown: EU AI Act News, Digital Omnibus on AI and new guidance (30 July 2026)
- EU Perspectives: Two delays later, EU finally defines what makes an AI system high-risk (22 May 2026)
- Lawfare: You Don't Have to Sell It to Be Bound by It, GPAI and the EU AI Act (16 September 2026)
- Browne Jacobson: AI in advertising, do I need to label my AI-generated ad? (11 September 2026)
- Security Boulevard: The EU AI Act for the Downstream Provider (9 September 2026)
About this article
This analysis was researched and written by The Corporate INTL Newsroom, which covers cross-border legal, regulatory and business developments for lawyers, professional advisers and financiers in over 150 jurisdictions. It has been checked against the European Commission's announcements, the text of the AI Act, the published analysis of the Digital Omnibus on AI and primary reporting. This article is general information, not legal advice; for advice on a specific matter, consult a qualified adviser. Last reviewed 16 September 2026. For more analysis like this, visit the Corporate INTL newsroom or subscribe to Corporate INTL.