News

EU AI Act Explained: 6 Deadlines You Cannot Safely Miss

EU AI Act Explained: 6 Deadlines You Cannot Safely Miss
Photo: European Parliament building Brussels 1 by Steven Lek, CC BY-SA 4.0, via Wikimedia Commons

The EU AI Act is Regulation (EU) 2024/1689, the European Union’s horizontal law on artificial intelligence. It entered into force on 1 August 2024 and applies in stages rather than all at once, which is why it is so easy to get wrong. In July 2026 the timetable itself was amended, moving the largest set of obligations more than a year into the future while leaving others exactly where they were.

Updated September 2026. General information, not legal advice.

EU AI Act: European Union flag
Flutting European Union flag by Gioele Serra, CC BY-SA 4.0, via Wikimedia Commons

What the law does

The European Commission describes a tiered structure. A short list of practices is prohibited outright, including harmful manipulation and untargeted scraping of facial images. A larger set of uses is classed as high risk, covering areas such as employment, education, critical infrastructure and law enforcement, where providers must run risk assessments, use quality datasets, log activity and provide human oversight. A third tier carries transparency duties only, and the Commission notes that the majority of AI systems in use in the EU, such as spam filters and game features, fall into a minimal risk category with no specific requirements.

General-purpose AI models sit in their own chapter. Article 51 presumes a model carries systemic risk when the cumulative compute used for training, measured in floating point operations, is greater than 10^25.

The change that happened in July 2026

Regulation (EU) 2026/1744 of 8 July 2026, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on the third day after publication. It amends the AI Act along with the EASA and Machinery Regulations. Its central effect is to defer the high risk obligations that were due to apply on 2 August 2026: Annex III standalone systems now apply from 2 December 2027, and Annex I systems embedded in products already covered by EU product safety law from 2 August 2028. The regulation gives its reasons as the delayed availability of harmonised standards and of national competent authorities.

What it did not touch matters just as much. The prohibitions, the general-purpose model rules and the transparency duties were not postponed.

6 EU AI Act deadlines that matter

  1. 1 August 2024. Entry into force, starting the clock on every later date.
  2. 2 February 2025. The prohibited practices apply, along with Article 4, which requires providers and deployers to take measures to support AI literacy among staff and others operating their systems.
  3. 2 August 2025. Obligations for general-purpose AI models, the governance and notified body provisions and the penalties chapter begin to apply. Models already on the market at that date have until 2 August 2027 to comply.
  4. 2 August 2026. The Article 50 transparency rules apply. Systems already on the market before that date have until 2 December 2026 to meet part of them.
  5. 2 December 2026. Two prohibitions added by the omnibus become enforceable, covering AI used to generate non-consensual intimate imagery and child sexual abuse material.
  6. 2 December 2027 and 2 August 2028. High risk obligations apply, first for Annex III systems and then for AI inside regulated products.

What applies in September 2026, and what does not

As of today the following are live: the prohibited practices from February 2025, the AI literacy duty, the general-purpose model obligations from August 2025, the governance and penalty provisions, and the Article 50 transparency rules that started on 2 August 2026. The Commission’s own summary of that August milestone is that people must be told when they are dealing with an AI system rather than a person, and that certain generated content must be clearly and visibly labelled and carry machine-readable marks. That covers deepfakes, emotion recognition and published text produced without human review. Our explainers on how AI text watermarks work and how to spot AI generated images cover the practical side of those marks.

Not yet in force: the full high risk regime under Chapter III, which is the part most compliance programmes were built around, and the two new prohibitions that start in December 2026. If you read guidance written before July 2026 stating that high risk duties begin on 2 August 2026, it is out of date.

Penalties written into the regulation

Article 99 sets the ceilings. Breach of the prohibited practices in Article 5 is subject to administrative fines of “up to EUR 35 000 000 or, if the offender is an undertaking, up to 7 % of its total worldwide annual turnover for the preceding financial year, whichever is higher”. Non-compliance with most other obligations, including the Article 50 transparency duties, carries up to EUR 15 000 000 or 3 % of total worldwide annual turnover, whichever is higher. Supplying incorrect, incomplete or misleading information to authorities carries up to EUR 7 500 000 or 1 %. For small and medium-sized enterprises each of those ceilings is the lower of the fixed amount and the percentage rather than the higher.

Who enforces it

National market surveillance authorities handle AI systems, while the European AI Office inside the Commission supervises general-purpose models. The Commission says the Office has more than 125 staff across six units and can request technical documentation and model access, investigate suspected breaches, require corrective action, restrict a model’s public availability and issue fines. Alongside the law sits the voluntary General-Purpose AI Code of Practice, published on 10 July 2025 with chapters on transparency, copyright and safety and security; signing it is one way to demonstrate compliance, not a requirement. If you are working out whether your own product is in scope, start with what an AI agent does on a user’s behalf, and note that systems aimed at or reaching minors attract extra scrutiny, as our piece on AI chatbots and children discusses.

Common questions

Is the EU AI Act in force now? Yes, in stages. It entered into force on 1 August 2024. The prohibitions and AI literacy duty applied from February 2025, general-purpose model rules from August 2025, and transparency rules from 2 August 2026.

Were the high risk rules delayed? Yes. Regulation (EU) 2026/1744, published on 24 July 2026, moved Annex III high risk obligations from 2 August 2026 to 2 December 2027, and Annex I product-embedded systems to 2 August 2028.

What are the fines? Article 99 allows up to EUR 35 000 000 or 7 % of worldwide annual turnover for prohibited practices, up to EUR 15 000 000 or 3 % for most other breaches, and up to EUR 7 500 000 or 1 % for supplying incorrect information.

Does it apply to companies outside the EU? It can. The regulation applies to providers placing systems on the EU market and, in defined cases, where the output is used in the EU, so location alone does not decide the question.

Do I have to label AI generated content? Since 2 August 2026, Article 50 requires disclosure that a user is interacting with an AI system and marking of certain generated or manipulated content, with machine-readable marks. Systems already on the market had until 2 December 2026 for part of that.

Sources and further reading

Where the figures and rules above come from, so you can check them:

Photo credits: European Parliament building Brussels 1 by Steven Lek, CC BY-SA 4.0, via Wikimedia Commons. Flutting European Union flag by Gioele Serra, CC BY-SA 4.0, via Wikimedia Commons.

Complying in practice means internal process. Our guide to AI governance covers the frameworks organisations use.

Join the discussion

Held for review before it appears. Links are not allowed and your email is never published.