Compyl
GRC Your Way

EU AI Act Compliance Timeline: Every Key Deadline Explained

Last updated: August 11, 2026

The EU AI Act entered into force on August 1, 2024, and its obligations apply in stages. Prohibited practices and AI literacy duties have applied since February 2, 2025, general purpose AI model rules since August 2, 2025, and transparency obligations for AI-generated content since August 2, 2026. Following the Digital Omnibus adopted in July 2026, the high-risk system deadlines moved: standalone high-risk systems under Annex III must comply by December 2, 2027, and AI embedded in regulated products under Annex I by August 2, 2028.

This post is part of our AI governance guide. For a deeper look at what the law requires of GRC teams, see our overview of EU AI Act compliance.

Key takeaways

  • The AI Act phases in over several years: prohibitions came first, then GPAI rules, then transparency, with high-risk obligations still ahead.
  • The Digital Omnibus on AI (Regulation (EU) 2026/1744), in force since July 27, 2026, pushed high-risk deadlines to December 2, 2027 (Annex III) and August 2, 2028 (Annex I).
  • August 2, 2026 still mattered: Article 50 transparency obligations for chatbots, deepfakes, and AI-generated content now apply.
  • Penalties scale up to 35 million euros or 7% of global annual turnover for prohibited practices.
  • The deferral is extra runway, not a reprieve: high-risk compliance programs take longer than 16 months to build well.

What is the full EU AI Act compliance timeline?

DateWhat appliesStatus
August 1, 2024AI Act enters into force; no obligations apply yetDone
February 2, 2025Prohibited AI practices (Article 5) and AI literacy duties (Article 4)In force
August 2, 2025General purpose AI (GPAI) model obligations, governance rules, and the penalties framework; EU AI Office operationalIn force
August 2, 2026Article 50 transparency obligations for AI-generated content and most remaining provisionsIn force
December 2, 2026Watermarking grace period ends for systems placed on the market before August 2, 2026; transitional period ends for the new ban on non-consensual intimate imagery and CSAM generationUpcoming
August 2, 2027GPAI models placed on the market before August 2, 2025 must be fully compliant; member state deadline for AI regulatory sandboxesUpcoming
December 2, 2027High-risk obligations for standalone Annex III systems (hiring, credit, education, law enforcement, critical infrastructure)Upcoming
August 2, 2028High-risk obligations for AI embedded in regulated products under Annex I (medical devices, machinery, vehicles)Upcoming

What changed with the Digital Omnibus?

By late 2025 it was clear that the harmonized standards, guidance, and notified body capacity needed to make high-risk obligations workable would not be ready for the original August 2, 2026 date. The European Commission proposed targeted amendments on November 19, 2025, and after a political agreement in May 2026, the Digital Omnibus on AI was published in the Official Journal as Regulation (EU) 2026/1744 on July 24, 2026. It entered into force on July 27, 2026, days before the original deadline.

The most significant change is the high-risk deferral: standalone Annex III systems now have until December 2, 2027, and Annex I embedded systems until August 2, 2028. The Omnibus also added a new Article 5 prohibition on AI that generates non-consensual intimate imagery or child sexual abuse material (transitional period until December 2, 2026), gave existing systems a four month grace period on machine-readable watermarking, softened the AI literacy obligation, expanded the legal basis for processing sensitive data for bias detection, moved the regulatory sandbox deadline to August 2, 2027, and strengthened the EU AI Office’s enforcement powers.

What obligations already apply today?

Prohibited practices (since February 2, 2025)

Article 5 bans practices such as social scoring by public authorities, exploitative manipulation, untargeted scraping of facial images, emotion recognition in workplaces and schools, and most real time remote biometric identification in public spaces. These bans carry the highest penalty tier.

GPAI model obligations (since August 2, 2025)

Providers of general purpose AI models must maintain technical documentation, publish training data summaries, respect EU copyright law, and, for models posing systemic risk, run model evaluations and report serious incidents. Models placed on the market before August 2, 2025 have until August 2, 2027 to comply.

Transparency obligations (since August 2, 2026)

Article 50 requires that people be told when they are interacting with an AI system, that AI-generated or manipulated content (including deepfakes) be disclosed, and that providers mark AI-generated output in a machine-readable way. The watermarking requirement applies immediately to new systems; systems already on the market before August 2, 2026 have until December 2, 2026.

What deadlines are coming next?

The next milestones are December 2, 2026 (watermarking grace period and the NCII/CSAM transitional period end), August 2, 2027 (legacy GPAI models and member state sandboxes), December 2, 2027 (standalone Annex III high-risk systems), and August 2, 2028 (Annex I embedded systems). High-risk compliance is the heaviest lift in the law: risk management systems, data governance, technical documentation, logging, human oversight, accuracy and robustness testing, conformity assessment, and CE marking. Sixteen months is less time than it sounds for organizations starting from scratch.

What are the penalties for non-compliance?

The penalties framework has applied since August 2, 2025. Violating Article 5 prohibitions can cost up to 35 million euros or 7% of global annual turnover, whichever is higher. Breaching most other obligations, including the high-risk requirements once they apply, carries fines up to 15 million euros or 3% of turnover. Supplying misleading information to authorities can draw up to 7.5 million euros or 1% of turnover, with proportionality caps for SMEs.

How should you prepare before the 2027 deadline?

Start with an AI inventory: you cannot classify what you have not catalogued. Then classify each system against the Act’s risk tiers, close transparency gaps that already apply, and stand up the governance structure the high-risk requirements assume, including risk management, data governance, and human oversight procedures.

Many organizations are anchoring this work to ISO 42001, the certifiable AI management system standard, because its requirements for risk assessment, documentation, and oversight map naturally onto the Act’s high-risk duties. If you are new to the standard, start with our explainer on what ISO 42001 is and our step by step ISO 42001 checklist.

Frequently asked questions

Is the EU AI Act delayed?

Partially. The law itself is in force and several obligation sets already apply. Only the high-risk system obligations were deferred by the Digital Omnibus, to December 2, 2027 for Annex III systems and August 2, 2028 for Annex I systems.

Does the EU AI Act apply to US companies?

Yes, if their AI systems are placed on the EU market or their outputs are used in the EU. Like GDPR, the Act has extraterritorial reach, so US providers and deployers serving EU users fall within scope.

What took effect on August 2, 2026?

Article 50 transparency obligations: disclosing AI interactions, labeling deepfakes and AI-generated content, and machine-readable marking of AI output (with a grace period until December 2, 2026 for systems already on the market). Most remaining provisions of the Act also became applicable, minus the deferred high-risk obligations.

What counts as a high-risk AI system?

Annex III lists standalone use cases including employment and worker management, education, credit scoring, insurance pricing, law enforcement, migration, and critical infrastructure. Annex I covers AI that is a safety component of products already regulated at EU level, such as medical devices and machinery.

Do the new deadlines mean I can wait until 2027?

Waiting is risky. Conformity assessment capacity will be constrained, harmonized standards are still maturing, and building a compliant risk management and documentation program typically takes a year or more. Regulators framed the deferral as time to implement properly, not time to defer starting.

Compyl gives GRC teams a single platform to inventory AI systems, classify them against the EU AI Act, and run an ISO 42001 program that turns regulatory deadlines into a managed roadmap. If the December 2027 date is on your calendar, we can help you work backwards from it.

By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies