Insights · Implementation timeline

EU AI Act Timeline 2026: Deadlines and Key Dates

Current EU AI Act application dates for Article 5 prohibitions, AI literacy, GPAI, Article 50 transparency, and high-risk AI planning.

4 min read
EU AI Act2026 deadlinesAI OmnibusCompliance planning

The EU AI Act uses staggered application dates. As of July 2026, Article 5 prohibitions and AI literacy duties already apply, GPAI obligations have applied since August 2025, and Article 50 transparency obligations start on 2 August 2026. Following political agreement on the AI Omnibus, the Commission describes revised high-risk dates of 2 December 2027 and 2 August 2028; confirm formal adoption before relying on them legally.

Dates to put on the programme calendar

  • 2 February 2025 — prohibitions, definitions, and AI literacy provisions became applicable.
  • 2 August 2025 — governance rules and obligations for general-purpose AI (GPAI) models became applicable.
  • 2 August 2026 — Article 50 transparency obligations for relevant AI-generated or manipulated content become applicable.
  • 2 December 2027 / 2 August 2028 — revised dates described by the Commission following political agreement for specified stand-alone and product-embedded high-risk systems; verify the final amending law.

Why phased rollout matters for engineering backlogs

If compliance work is sequenced only to the last milestone, teams collide with capacity limits: external auditors, pen testers, and specialised counsel book months ahead. Phased planning spreads documentation debt across releases instead of creating a death-march before enforcement.

Practical program habits

  • Anchor conformity artefacts to release trains, not only statutory dates.
  • Budget regression testing when foundation models, retrieval corpora, or safety filters change.
  • Run quarterly evidence sprints — documentation decays faster than code comments.
  • Centralise a single obligation register mapped to owners (product, legal, security).

Using Agent Mai across the timeline

Run Quick Audits after each material change; store exports as versioned evidence. For enterprise Private Vault deployments, keep the same workflow on-premises so air-gapped environments stay aligned with SaaS documentation structure.

July 2026 timeline update

The Commission now describes a new high-risk enforcement timeline following political agreement on the AI Omnibus: 2 December 2027 for systems in specified stand-alone high-risk areas such as biometrics, employment, education, critical infrastructure and migration, and 2 August 2028 for high-risk systems integrated into regulated products. This is more specific than the earlier proposal to link dates to the availability of support measures. Legal teams should still confirm formal adoption and the final amending text.

Article 50 remains applicable from 2 August 2026. Commission material also explains a proposed targeted transition to 2 December 2026 for certain marking and detection obligations affecting generative AI systems already placed on the market or put into service before 2 August 2026. That grandfathering point should not be read as a general postponement of Article 50.

Build a milestone plan by evidence dependency

  • Now — complete the AI inventory, role analysis, Article 5 screen, Article 4 measures, supplier register, and Article 50 assessment.
  • Next release — establish system-level risk records, ownership, testing evidence, transparency controls, logging decisions, and change triggers.
  • High-risk preparation — build Article 8–15 controls, Annex IV traceability, quality management, conformity planning, registration readiness, and post-market monitoring.
  • Recurring governance — review evidence freshness, incidents, supplier changes, model updates, complaints, and accepted risks at a defined cadence.

How to manage a changing regulatory calendar

Store the source URL, source owner, date checked, legal interpretation, affected systems, and next review date alongside every time-sensitive obligation. Separate enacted law from political agreement, proposal, draft guidance, voluntary code, and harmonised standard. This status field prevents teams from treating every announcement as binding or every delay as permission to stop foundational work.

Quarterly readiness questions for leadership

  • Which systems are unclassified, potentially prohibited, or missing an accountable owner?
  • Which obligations apply now, which are subject to a transition, and which depend on a pending legislative step?
  • Are Article 50 controls ready for the shipped experience and supported by release evidence?
  • Which high-risk evidence dependencies have the longest lead time, including supplier documentation, testing, standards, and conformity resources?
  • What material changes, incidents, complaints, or supplier updates require reassessment before the next release?

Frequently asked questions

Does the EU AI Act apply from one single date?

No. The Act uses phased application dates. Prohibitions and AI literacy started in February 2025, GPAI provisions followed in August 2025, and Article 50 transparency obligations apply from August 2026, while high-risk dates have been revised through the 2026 AI Omnibus process.

Were the high-risk AI deadlines delayed?

The EU institutions reached a 2026 political agreement that the Commission describes as moving specified stand-alone high-risk rules to 2 December 2027 and product-embedded high-risk rules to 2 August 2028. Confirm that the agreed amendment is formally applicable before relying on it legally.

Should organisations pause high-risk compliance work?

No. Inventory, classification, supplier evidence, risk management, data governance, testing and technical documentation take time and already support procurement, security and governance expectations even where a statutory date moves.

Educational content only — not legal advice. Verify obligations with qualified counsel.