Back to AI Act Guide
    TimelineFor founders, operators, and compliance leads

    EU AI Act Timeline: What Happens When

    5 min read

    The EU AI Act doesn't apply all at once.

    Instead, it's rolled out in phases over time. That makes it easier to adopt — but also easier to misunderstand.

    Many companies assume they can wait. In reality, the smart move is to understand your position early, before requirements become stricter.

    If you want to see where you stand today:

    The EU AI Act rollout at a glance

    The regulation is introduced step by step, and the schedule changed in July 2026. The Digital Omnibus on AI — Regulation (EU) 2026/1744, in force since 27 July 2026 — deferred most high-risk obligations but left the transparency duties exactly where they were.

    The full EU AI Act calendar

    EU AI Act application dates after the Digital Omnibus on AI (Regulation (EU) 2026/1744).

    DateWhat appliesStatus
    2 February 2025Prohibited AI practices are banned (Art. 5)Unchanged
    2 February 2025AI literacy obligation applies (supervision from 3 August 2026) (Art. 4)Unchanged
    2 August 2025General-purpose AI model rules and governance apply (Art. 51–55)Unchanged
    2 August 2026Transparency duties apply — not deferred by the Omnibus (Art. 50)Unchanged
    2 December 2026Machine-readable marking of synthetic output for generative systems placed on the market before 2 August 2026 (Art. 50(2))New
    2 December 2026Two new prohibitions apply (non-consensual intimate imagery, AI-generated CSAM) (Art. 5)New
    2 August 2027National AI regulatory sandboxes must be operational (Art. 57)Previously 2 August 2026Deferred
    2 December 2027Stand-alone high-risk AI obligations (Annex III) apply (Annex III)Previously 2 August 2026Deferred
    2 August 2028High-risk AI embedded in regulated products (Annex I) applies (Annex I)Previously 2 August 2027Deferred

    What moved and what did not

    Deferred: stand-alone high-risk obligations under Annex III moved from 2 August 2026 to 2 December 2027. High-risk AI embedded in regulated products under Annex I moved from 2 August 2027 to 2 August 2028. National regulatory sandboxes moved from 2 August 2026 to 2 August 2027.

    Unchanged: the Article 5 prohibitions have applied since 2 February 2025. The general-purpose AI model rules have applied since 2 August 2025. The Article 50 transparency duties apply from 2 August 2026.

    New: from 2 December 2026, two additional prohibited practices apply, and generative systems that were already on the EU market before 2 August 2026 must meet the machine-readable marking requirement.

    For the full breakdown of the amendment, read what the Digital Omnibus changed.

    What this means for SMEs

    If you run an SME, the extra sixteen months on high-risk is genuinely useful — but it is not a pause.

    Your nearest date is most likely 2 August 2026, because transparency applies to any AI that talks to people or generates content. You still need to understand:

    • whether the regulation applies to you
    • where your risk sits
    • what might become relevant later

    Companies that wait until enforcement is fully active often end up rushing. Building a defensible Annex III technical file — data lineage, bias testing, human oversight design, post-market monitoring — is typically a two-to-three quarter project, so December 2027 is a project start date rather than a distant deadline.

    Companies that prepare early can move more calmly and efficiently.

    What you should do now (practical steps)

    You don't need a full compliance program to get started.

    A simple first step is:

    1. Map where you use AI
    2. Identify if it affects people or decisions
    3. Estimate the level of risk
    4. Focus only on what matters

    This gives you a realistic starting point without overcomplicating things.

    If you want a faster way to do this:

    Why timing matters more than you think

    Many companies delay because the deadlines feel far away.

    But the real challenge is not the deadline itself. It's understanding your position.

    If you wait too long:

    • decisions get rushed
    • teams lack clarity
    • compliance becomes reactive instead of planned

    Getting clarity early gives you flexibility later.

    How timeline and risk work together

    The timeline doesn't apply equally to everyone.

    Your situation depends on:

    • how you use AI
    • how much it affects people
    • whether your system is considered high risk

    If you want to understand how that classification works:

    Risk classification explained

    Related reading

    Want the full picture?

    If you want a broader understanding of the EU AI Act and how everything fits together:

    Read the EU AI Act guide

    Next step: understand your timeline

    The timeline only becomes useful once you understand your own situation.

    The fastest way to do that is to run a structured check based on your actual use of AI.

    Indicative assessment only — not legal advice.

    ActNavigator provides preliminary compliance guidance based on the EU AI Act (Regulation 2024/1689) and publicly available regulatory frameworks. Assessments are based solely on user-provided answers and do not constitute legal advice, legal opinion, or a guarantee of regulatory compliance.

    The EU AI Act is subject to ongoing implementation and potential amendment. Organizations remain solely responsible for their regulatory obligations. ActNavigator accepts no liability for decisions made on the basis of this assessment. For a formal review, consult a qualified legal professional.

    Some content and outputs in this service may be generated or assisted by artificial intelligence. While we strive to ensure accuracy and relevance, the information provided should not be considered legal advice.

    © 2026 actNavigator. All rights reserved.