The EU AI Act does not switch on all at once. It phases in over several years. The short version: AI literacy and the outright bans are already in force, the transparency duties land on 2 August 2026, and, under the Digital Omnibus, the core high-risk obligations are deferred to 2 December 2027. Here is the whole timeline, in plain terms.
Update, August 2026 (Digital Omnibus). The EU’s Digital Omnibus, agreed in 2026 and pending formal adoption, defers the core high-risk obligations for standalone (Annex III) systems from 2 August 2026 to 2 December 2027, and high-risk AI in regulated products (Annex I) to 2 August 2028. The transparency duties (Article 50) still apply from 2 August 2026, and the AI-literacy and prohibited-practice rules remain in force now. The deferral becomes legally binding once published in the Official Journal, expected around August 2026; we will update these dates when it is.
This is a readiness explainer, not legal advice. To see where you stand against these dates, take the free EU AI Act readiness check.
The timeline
- August 2024: the Act enters into force. The clock starts, but almost nothing applies yet.
- 2 February 2025: bans and literacy. Prohibited practices (Article 5) are banned outright, and the AI literacy duty (Article 4) applies. Both are live now, and neither was deferred.
- 2 August 2025: general-purpose AI. Obligations for providers of general-purpose AI models begin, along with the governance and penalty machinery. This is mostly a concern for model providers, not everyday deployers.
- 2 August 2026: transparency. The transparency duties under Article 50 apply, for example labelling AI-generated content and telling people when they are interacting with an AI. This date held; the Digital Omnibus did not defer it.
- 2 December 2027: high-risk, the big one for most. Under the Digital Omnibus, the core obligations for standalone high-risk AI (Annex III) now apply from here: deployer duties (Article 26) and fundamental-rights impact assessments where required (Article 27). Originally 2 August 2026. If a date matters to you, it is probably this one.
- 2 August 2028: AI inside regulated products. High-risk AI that is a safety component of an already-regulated product (Annex I) gets the longest runway, deferred from 2 August 2027. Note that general-purpose models on the market before August 2025 must still be brought into line by 2 August 2027.
What this means if you use AI
If you are a deployer, someone who uses AI rather than builds and sells it, two clocks are already running and the big one now sits further out:
- Now: make sure you are not using anything banned, and that your people have enough AI literacy. These are not “later” problems, and the Omnibus did not touch them.
- By August 2026: if your AI interacts with people or generates content, meet the Article 50 transparency duties. This date was not deferred.
- By December 2027: if you deploy standalone high-risk AI, have the oversight, monitoring, logging and (where needed) impact assessments in place. The extra runway is real, but the work still takes months.
The trap is treating the high-risk deferral as permission to do nothing. We covered the obligations themselves in the EU AI Act for deployers; this post is just the calendar.
Why “we’ll deal with it later” is still risky
Three reasons the deferral does not buy you as much as it looks. First, the literacy and prohibition duties are already enforceable, and transparency lands in August 2026, so “later” is already wrong for those. Second, the high-risk work, inventory your AI, classify it, stand up oversight and evidence, takes months, not weeks, so December 2027 is closer than it sounds. Third, enterprise buyers are asking vendors to prove governance now, well ahead of any legal deadline, so the commercial clock runs faster than the regulatory one.
One honest caveat the other way: the Digital Omnibus is agreed but not yet formally adopted. Until it is published in the Official Journal, the deferral is settled policy rather than settled law. Plan around the deferred dates, but watch for the final text.
Where to start
Map the AI you use and classify it by risk, that tells you which of these dates actually apply to you. The free EU AI Act readiness assessment does that in about ten minutes, no email required. When you want to turn the deadlines into a plan, talk to us.
For the full picture, see the EU AI Act guide.
Frequently asked questions
When does the EU AI Act fully apply?
It phases in. The ban on prohibited practices and the AI literacy duty applied from 2 February 2025, general-purpose AI model rules from 2 August 2025, and the transparency duties (Article 50) from 2 August 2026. Under the EU's Digital Omnibus, agreed in 2026 and pending formal adoption, the core high-risk obligations for standalone (Annex III) systems are deferred to 2 December 2027, and high-risk AI built into regulated products (Annex I) to 2 August 2028.
What is already in force?
Two things bite now. Prohibited practices (Article 5) are banned outright, and the AI literacy duty (Article 4) requires you to ensure the people using or affected by your AI understand it well enough to use it responsibly. Both have applied since 2 February 2025 and were not deferred by the Digital Omnibus.
When do the deployer obligations for high-risk AI start?
They were originally set for 2 August 2026, but under the EU's Digital Omnibus (agreed in 2026, pending formal adoption) the core high-risk deployer duties for standalone Annex III systems are deferred to 2 December 2027. From then, deployers must use the system per the provider's instructions, assign human oversight, monitor it, keep logs, and where required run a fundamental-rights impact assessment. Note that the separate transparency duties under Article 50 still apply from 2 August 2026, and were not deferred.
What is the Digital Omnibus and has it changed the dates?
The Digital Omnibus is an EU package that amends the AI Act, largely to postpone the high-risk obligations because the standards and support tools needed to comply were not ready in time. A political agreement was reached in 2026 and confirmed by the Council. It defers standalone high-risk (Annex III) duties to 2 December 2027 and regulated-product (Annex I) duties to 2 August 2028. It becomes legally binding only once formally adopted and published in the Official Journal, expected around August 2026, so treat the deferred dates as the current plan and watch for the final publication.
Building something you need to govern?
Start with a fixed-scope AI Opportunity & Risk Audit.
Meet an Expert