Last updated: 4 July 2026
Reading Time: 5 min read
With the official publication of the Digital Omnibus on AI in the European Union statute book, compliance teams finally have a clear roadmap. While the Omnibus extended implementation deadlines for high-risk AI platforms, it left immediate transparency duties untouched.
Understanding EU terminology is critical here: in EU legislative parlance, “applicable” means enforceable by a regulatory body. While the law entered into force previously, its application dates determine when market surveillance authorities can inspect operations and issue fines.
Here is a master timeline breakdown of what is enforceable today, what takes effect on 2 August 2026, and what has been pushed back.
1. Active & Imminent: Transparency and Prohibitions
Contrary to popular belief, the AI Act is far from dormant. Key provisions are either already live or taking effect within days.
FEBRUARY 2025 AUGUST 2025 AUGUST 2026
│ │ │
▼ ▼ ▼
┌───────────────┐ ┌───────────────┐ ┌───────────────┐
│ Banned AI │ │ GPAI Model │ │ Transparency │
│ Practices & │ │ Governance │ │ Obligations & │
│ AI Literacy │ │ Requirements │ │ Disclosure │
└───────────────┘ └───────────────┘ └───────────────┘
Prohibitions & AI Literacy (In Force Since 2 February 2025)
- Banned Practices: Strict bans on social scoring, workplace emotion recognition, and untargeted biometric scraping are already active.
- AI Literacy: Providers and deployers must take proactive measures to support staff AI literacy. While national market surveillance authorities continue their formal designation across various Member States, enforcement authority is active.
Article 50 Transparency Obligations (Applicable 2 August 2026)
- For Providers (Including Custom / In-House Chatbots): Any organisation applying its branding to an interactive AI interface must clearly inform users they are speaking with an AI. Additionally, AI-generated synthetic content must feature machine-readable marking. A short grace period to 2 December 2026 exists solely for machine-readable watermarking on systems placed on the market prior to 2 August 2026.
- For Deployers: Deployers must clearly label deepfakes and inform individuals whenever emotion recognition or biometric categorisation tools are deployed.
2. High-Risk AI Requirements Pushed Back
The Digital Omnibus granted much-needed breathing room to organizations building or operating high-risk AI tools. These extensions allow European standardisation bodies (CEN/CENELEC) to publish harmonised technical standards, which establish a formal “presumption of conformity.”
| High-Risk Classification | Original Application Date | Revised Application Date |
|---|---|---|
| Standalone High-Risk AI (Annex III) (e.g., HR, credit scoring, biometrics, critical infrastructure) | 2 August 2026 | 2 December 2027 |
| Embedded Product AI (Annex I) (e.g., medical devices, aviation safety, industrial machinery) | 2 August 2027 | 2 August 2028 |
3. Master EU AI Act Enforcement Timeline
- 2 February 2025: Prohibited practices and AI literacy obligations became applicable.
- 2 August 2025: Rules for General-Purpose AI (GPAI) model providers became applicable.
- 2 August 2026: Article 50 transparency rules take effect. National surveillance authority setup deadline.
- 2 December 2026: Grace period ends for synthetic content watermarking on pre-existing models. Expanded non-consensual intimate imagery prohibitions take effect.
- 2 December 2027: Standalone high-risk AI (Annex III) obligations become applicable.
- 2 August 2028: Product-embedded high-risk AI (Annex I) obligations become applicable.
Strategic Takeaway for Product & Governance Teams
High-Risk AI Is Product Safety Law, Not GDPR
The high-risk provisions of the AI Act function like traditional EU product safety legislation rather than data protection frameworks. You cannot easily retrofit compliance post-launch.
- For Providers: Building high-risk systems requires detailed technical documentation, Quality Management Systems (QMS), lifecycle monitoring, and formal conformity declarations during the development lifecycle. Standalone software providers in HR tech or fintech should use the extended December 2027 runway to align product pipelines with incoming CEN/CENELEC standards.
- For Deployers: High-risk obligations map more closely to employment and privacy rules. Deployers should update supplier onboarding workflows, audit vendor risk assessments, and adjust enterprise contracts now to ensure vendor models meet incoming standards.