EU AI Act timeline and deadlines: what applies when
The EU AI Act doesn't switch on all at once — it applies in phases to 2028, and the 2026 Digital Omnibus moved some of the biggest deadlines. This guide lays out the full timeline and what changed. Part of our guide to the EU AI Act.
AramGRC Team·AI Compliance & Assurance·September 11, 2026·8 min read
The EU AI Act timeline
1 August 2024 — the EU AI Act enters into force.
2 February 2025 — prohibited (unacceptable-risk) practices are banned; AI-literacy obligations begin.
2 August 2025 — obligations for general-purpose AI (GPAI) models apply; governance bodies and national authorities stand up.
2 August 2026 — transparency obligations (Article 50) apply, covering AI-interaction disclosure, marking of AI-generated content, and deepfake labelling; the penalty regime and market-surveillance framework apply.
2 December 2027 — high-risk obligations for standalone (Annex III) systems apply — deferred from August 2026 by the Digital Omnibus.
2 August 2028 — high-risk obligations for AI embedded in regulated products (Annex I) apply — deferred from August 2027.
What the Digital Omnibus changed
In 2026 the EU agreed a "Digital Omnibus" package that deferred the high-risk deadlines to give organisations more time: standalone (Annex III) high-risk systems moved from 2 August 2026 to 2 December 2027, and AI embedded in regulated products (Annex I) moved from 2 August 2027 to 2 August 2028. Crucially, it did not delay the prohibitions (February 2025), the GPAI rules (August 2025) or the transparency obligations (August 2026) — those remain in force on the original schedule.
What applies right now
As things stand, the prohibited-practice bans, the GPAI obligations and the Article 50 transparency duties are all in force. The heavy high-risk obligations — risk management, technical documentation, conformity assessment and CE marking — are not yet mandatory, but the deadlines (December 2027 and August 2028) are fixed, not conditional. Treating this as breathing room rather than a reprieve is the mistake to avoid. The obligations themselves are set out in EU AI Act requirements for high-risk AI.
What to do before each deadline
Now: inventory and classify your AI systems, and exit any prohibited practices.
By/ongoing August 2026: meet transparency duties for chatbots, generative AI and deepfakes, and if you provide GPAI models, keep your documentation current.
Toward December 2027: complete the high-risk programme for standalone systems — risk management, Annex IV documentation, human oversight and conformity assessment.
Toward August 2028: the same for AI embedded in regulated products.
Don't wait for the deadline
A high-risk compliance programme — risk management, documentation, conformity assessment — takes many months. The deferral to 2027/2028 is time to do it properly, not time to ignore it. Use the EU AI Act compliance checklist to start now.
How AramGRC helps
AramGRC helps you sequence your EU AI Act programme against these deadlines, so you're ready ahead of each one rather than scrambling after it.
Frequently asked questions
Is the EU AI Act in force?+
Yes, in phases. It entered into force in August 2024; prohibited practices apply from February 2025, GPAI from August 2025, transparency from August 2026, and high-risk obligations from December 2027 (standalone) and August 2028 (embedded).
When do the EU AI Act high-risk rules apply?+
After the 2026 Digital Omnibus, from 2 December 2027 for standalone (Annex III) high-risk systems and 2 August 2028 for AI embedded in regulated products (Annex I).
Was the EU AI Act delayed?+
The high-risk obligations were deferred by the 2026 Digital Omnibus — Annex III systems from August 2026 to December 2027, and Annex I systems from August 2027 to August 2028. The prohibitions, GPAI and transparency rules were not delayed.
When did the EU AI Act come into force?+
It entered into force on 1 August 2024 and applies in phases through to 2028.