Few regulations have generated as much noise and as much date confusion as the EU AI Act. Some of the blame sits with the Commission, which proposed delaying the high-risk block in November 2025 and left half the sector unsure what to prepare for.
It is settled now. This is the calendar that applies.
What is already in force
| Date | What applies |
|---|---|
| 1 August 2024 | Regulation enters into force. No obligations yet. |
| 2 February 2025 | Prohibitions on unacceptable AI practices, plus the AI literacy duty. |
| 2 August 2025 | General-purpose AI (GPAI) model obligations, governance, confidentiality, designation of national authorities and the penalty regime. |
| 2 August 2026 | General application of the Regulation, except the high-risk chapter. |
Last August’s milestone is the one most companies overlook, because it wasn’t labelled “high risk” and many assumed it didn’t touch them. It does: general application brought in the Article 50 transparency duties, which catch every customer-facing chatbot and every piece of synthetic content you publish.
What has been delayed
The Digital Omnibus entered into force on 27 July 2026 and moved the high-risk block to fixed dates:
- 2 December 2027 — stand-alone high-risk systems under Annex III (HR, credit, education, essential services, biometrics…).
- 2 August 2028 — AI embedded in products already regulated under Annex I.
The Commission had proposed those dates as backstops, allowing earlier application as harmonised standards were published. The co-legislators went for fixed dates instead, to give predictability. Good news for planning; a poor excuse for doing nothing.
What lands in December
Two things on 2 December 2026:
- Generative systems producing synthetic content that were already on the market before 2 August 2026 have until that date to comply with Article 50(2). If you already had a chatbot or content generator deployed, that is your deadline, and there is no later one.
- The prohibitions on non-consensual intimate imagery and child sexual abuse material take effect, having been carved out of the February 2025 package.
The fines
The penalty regime for GPAI providers runs to €15 million or 3% of global turnover, whichever is higher. For prohibited practices the ceilings are higher still.
One nuance gets lost in the headlines: most European companies are not model providers, they are deployers. The obligations are different and considerably more manageable. Before commissioning an expensive audit, work out which role you are actually in.
What you should already have
If you operate in the EU and use AI facing people:
- An inventory of AI systems with risk classification and your role in each (provider, deployer, importer, distributor).
- Demonstrable AI literacy for staff operating those systems. This has been an obligation since February 2025 and almost nobody documents it.
- Article 50 transparency: people know they are talking to a machine, and generated content is marked.
- Traceability: which model, which version, which prompt, which data, and who approved it.
None of this requires waiting for 2027. And all of it carries over to ISO/IEC 42001 certification if a client ends up demanding it.
What you should not do
Pause projects “until the rules are clear”. They are clear, and the high-risk delay does not affect the vast majority of enterprise use cases — classifying tickets, extracting invoice data, assisting a salesperson or summarising internal documentation are not Annex III high-risk systems.
The cost of waiting two years is far higher than the cost of properly documenting what you are already doing.