The EU AI Act doesn't apply all at once.
Instead, it's rolled out in phases over time. That makes it easier to adopt — but also easier to misunderstand.
Many companies assume they can wait. In reality, the smart move is to understand your position early, before requirements become stricter.
If you want to see where you stand today:
The EU AI Act rollout at a glance
The regulation is introduced step by step, and the schedule changed in July 2026. The Digital Omnibus on AI — Regulation (EU) 2026/1744, in force since 27 July 2026 — deferred most high-risk obligations but left the transparency duties exactly where they were.
The full EU AI Act calendar
EU AI Act application dates after the Digital Omnibus on AI (Regulation (EU) 2026/1744).
| Date | What applies | Status |
|---|---|---|
| 2 February 2025 | Prohibited AI practices are banned (Art. 5) | Unchanged |
| 2 February 2025 | AI literacy obligation applies (supervision from 3 August 2026) (Art. 4) | Unchanged |
| 2 August 2025 | General-purpose AI model rules and governance apply (Art. 51–55) | Unchanged |
| 2 August 2026 | Transparency duties apply — not deferred by the Omnibus (Art. 50) | Unchanged |
| 2 December 2026 | Machine-readable marking of synthetic output for generative systems placed on the market before 2 August 2026 (Art. 50(2)) | New |
| 2 December 2026 | Two new prohibitions apply (non-consensual intimate imagery, AI-generated CSAM) (Art. 5) | New |
| 2 August 2027 | National AI regulatory sandboxes must be operational (Art. 57)Previously 2 August 2026 | Deferred |
| 2 December 2027 | Stand-alone high-risk AI obligations (Annex III) apply (Annex III)Previously 2 August 2026 | Deferred |
| 2 August 2028 | High-risk AI embedded in regulated products (Annex I) applies (Annex I)Previously 2 August 2027 | Deferred |
What moved and what did not
Deferred: stand-alone high-risk obligations under Annex III moved from 2 August 2026 to 2 December 2027. High-risk AI embedded in regulated products under Annex I moved from 2 August 2027 to 2 August 2028. National regulatory sandboxes moved from 2 August 2026 to 2 August 2027.
Unchanged: the Article 5 prohibitions have applied since 2 February 2025. The general-purpose AI model rules have applied since 2 August 2025. The Article 50 transparency duties apply from 2 August 2026.
New: from 2 December 2026, two additional prohibited practices apply, and generative systems that were already on the EU market before 2 August 2026 must meet the machine-readable marking requirement.
For the full breakdown of the amendment, read what the Digital Omnibus changed.
What this means for SMEs
If you run an SME, the extra sixteen months on high-risk is genuinely useful — but it is not a pause.
Your nearest date is most likely 2 August 2026, because transparency applies to any AI that talks to people or generates content. You still need to understand:
- whether the regulation applies to you
- where your risk sits
- what might become relevant later
Companies that wait until enforcement is fully active often end up rushing. Building a defensible Annex III technical file — data lineage, bias testing, human oversight design, post-market monitoring — is typically a two-to-three quarter project, so December 2027 is a project start date rather than a distant deadline.
Companies that prepare early can move more calmly and efficiently.
What you should do now (practical steps)
You don't need a full compliance program to get started.
A simple first step is:
- Map where you use AI
- Identify if it affects people or decisions
- Estimate the level of risk
- Focus only on what matters
This gives you a realistic starting point without overcomplicating things.
If you want a faster way to do this:
Why timing matters more than you think
Many companies delay because the deadlines feel far away.
But the real challenge is not the deadline itself. It's understanding your position.
If you wait too long:
- decisions get rushed
- teams lack clarity
- compliance becomes reactive instead of planned
Getting clarity early gives you flexibility later.
How timeline and risk work together
The timeline doesn't apply equally to everyone.
Your situation depends on:
- how you use AI
- how much it affects people
- whether your system is considered high risk
If you want to understand how that classification works:
Related reading
- What actually takes effect on 2 August 2026
- High-risk rules delayed: what it means
- EU AI Act 2026 checklist for SMEs
Want the full picture?
If you want a broader understanding of the EU AI Act and how everything fits together:
Next step: understand your timeline
The timeline only becomes useful once you understand your own situation.
The fastest way to do that is to run a structured check based on your actual use of AI.