Every confirmed EU AI Act deadline from entry into force through 2030, and the obligations attached to each. Open any milestone to read the detail. Dates reflect the provisional Digital Omnibus agreement of 7 May 2026; until it is formally adopted, the original dates remain legally in force.
The Act is published and in force. The transition clock starts — no compliance obligations apply yet.
The Act became law on 1 August 2024 following publication in the Official Journal on 12 July 2024. Entry into force did not trigger compliance obligations — it started the transition clocks.
Organisations should have used this period to inventory their AI systems, identify which risk tier applies, and assign internal ownership for the compliance programme.
Who this affects: All organisations placing AI systems on the EU market or putting them into service in the EU.
Article 5 bans on unacceptable-risk AI become enforceable, with no transition period. Article 4 AI-literacy duties begin.
Six months after entry into force, the eight prohibited AI practices under Article 5 became enforceable. These are absolute bans — no derogation, no transition period. Systems falling within these categories had to be withdrawn.
The prohibited categories include:
AI-literacy obligations under Article 4 also apply from this date: organisations must ensure staff have sufficient AI literacy for the tasks they perform.
Who this affects: Any organisation operating AI systems covered by Article 5. HR, legal, and compliance teams need completed prohibited-use assessments.
Chapter V obligations apply to providers of general-purpose AI models, including transparency and copyright duties.
Chapter V obligations apply to providers of general-purpose AI models — models trained on broad datasets to perform a wide range of tasks, including large language models.
All GPAI model providers must:
Providers of GPAI models with systemic risk (training compute above 1025 FLOPs, or designated by the AI Office) must additionally perform model evaluations and adversarial testing, report serious incidents, implement cybersecurity measures, and report on energy consumption.
Who this affects: Providers of large language models and other general-purpose models made available in the EU. Organisations deploying third-party GPAI via APIs have their own downstream obligations.
Chatbot disclosure, synthetic-content labelling, and most deployer transparency obligations apply — unaffected by the Omnibus.
Several obligations come into force on 2 August 2026 regardless of the Omnibus outcome:
The Article 50(2) machine-readable watermarking obligation for synthetic-content systems already on the market has been deferred to 2 December 2026 under the Omnibus provisional agreement.
Who this affects: Virtually every organisation deploying customer-facing AI — chatbots, AI-generated marketing content, or emotion-recognition tools.
Watermarking for pre-market synthetic-content systems takes effect; new Article 5 bans on AI-generated non-consensual intimate imagery and CSAM apply.
Under the Omnibus provisional agreement, the Article 50(2) machine-readable labelling obligation for AI-generated content systems placed on the market before 2 August 2026 is deferred to this date.
Two new Article 5 prohibitions also apply from 2 December 2026: AI used to generate non-consensual intimate imagery, and AI used to generate child sexual abuse material.
Each Member State must have at least one national AI regulatory sandbox in place (deferred from 2 August 2026).
Member States must have established at least one national AI regulatory sandbox — a supervised environment where providers can develop and test systems before market — deferred from 2 August 2026 under the Omnibus.
Full compliance obligations for stand-alone Annex III high-risk systems — deferred from 2 August 2026.
Under the original Act, the full suite of high-risk obligations was due on 2 August 2026. The Digital Omnibus provisional agreement defers this to 2 December 2027 for stand-alone Annex III systems, defined by use case:
These systems must meet requirements covering risk management, data governance, technical documentation, logging, transparency to deployers, human oversight, accuracy, robustness, and cybersecurity.
Important: formal adoption and publication of the Omnibus in the Official Journal is required before the deferral takes legal effect. Until then, 2 August 2026 remains the operative date.
Who this affects: Any organisation deploying AI in HR, financial services, healthcare, critical infrastructure, law enforcement, or public administration.
Compliance for AI embedded in products already regulated under EU product-safety law — deferred to 2 August 2028.
AI systems embedded in products covered by existing EU product-safety legislation face an additional year. These are AI components inside physical products subject to prior CE-marking requirements:
For these systems, the Omnibus provisional agreement defers compliance to 2 August 2028.
High-risk AI put into service by public authorities before 2 August 2026 must reach full compliance.
High-risk AI systems already in service by public authorities before 2 August 2026 have the longest transition and must reach full compliance by 2 August 2030.
This applies to Member State government agencies, public bodies, and public utilities deploying AI systems that predate the high-risk threshold date.
Build audit-ready AI governance from day one