EU AI Act
EU AI Act timeline: verified dates and what applies to you
The Digital Omnibus on AI (Regulation (EU) 2026/1744) moved the high-risk dates. Prohibitions, AI literacy and general-purpose AI duties already apply. Article 50 transparency applies from 2 August 2026. Annex III high-risk obligations apply from 2 December 2027 and Annex I product-embedded obligations from 2 August 2028.
Who this applies to
- Providers of AI systems
- Anyone who develops an AI system or has one developed and places it on the EU market or puts it into service under their own name.
- Deployers
- Organisations that use an AI system under their own authority in a professional capacity. Deployer duties start with literacy, transparency and, for high-risk systems, Article 26.
- GPAI model providers
- Providers of general-purpose AI models placed on the EU market. Their duties have applied since 2 August 2025, with Commission enforcement from 2 August 2026.
- Non-EU organisations
- The Act reaches providers and deployers outside the EU where the system is placed on the EU market or its output is used in the EU. Check Article 2 with counsel for your case.
The verified timeline
Dates below follow the Commission AI Act Service Desk timeline, which reflects the Digital Omnibus, and the text of Regulation (EU) 2026/1744 on EUR-Lex. Where a date moved, the original date is shown.
| Date | What applies | Status |
|---|---|---|
| 1 Aug 2024 | The AI Act enters into force. | Done |
| 2 Feb 2025 | Definitions, AI literacy (Art. 4) and prohibited practices (Art. 5). | Applies now |
| 2 Aug 2025 | General-purpose AI model obligations (Chapter V), governance bodies, and the duty on Member States to designate national authorities and set penalty rules. | Applies now |
| 2 Aug 2026 | Most remaining rules, including Article 50 transparency. Commission enforcement powers over GPAI providers, including fines, begin. | Applies now |
| 2 Dec 2026 | New Article 5 prohibitions on AI that generates non-consensual intimate imagery or child sexual abuse material. Grace period ends for Article 50(2) machine-readable marking by generative systems already on the market before 2 Aug 2026. | Upcoming |
| 2 Aug 2027 | Each Member State should have at least one AI regulatory sandbox operational (moved from 2 Aug 2026). GPAI models placed on the market before 2 Aug 2025 must comply by this date. | Upcoming (moved) |
| 2 Dec 2027 | Annex III high-risk obligations (Chapter III, Sections 1 to 3). Originally 2 Aug 2026. | Upcoming (moved) |
| 2 Aug 2028 | High-risk obligations for AI in products covered by Annex I. Originally 2 Aug 2027. | Upcoming (moved) |
The Omnibus replaced the Commission's earlier proposal of a conditional trigger tied to the availability of standards with fixed calendar dates. Per the Regulation (EU) 2026/1744 text on EUR-Lex, it was adopted on 8 July 2026, published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026.
What the Omnibus changed, and what it did not
Changed (verified in the EUR-Lex text):
- Annex III high-risk obligations moved to 2 December 2027 and Annex I to 2 August 2028.
- Article 4 AI literacy now requires providers and deployers to "take measures to support" AI literacy. It no longer requires them to guarantee any specific level for any individual, and the Commission, Member States and the AI Board are to support them, especially SMEs.
- Simplified technical documentation (Article 11) and proportionate quality management (Article 17) now reach small mid-cap enterprises, and quality-management simplification extends from microenterprises to all SMEs.
- A new Article 4a allows processing of special-category personal data for bias detection and correction where strictly necessary and under safeguards.
- Article 5 gains two prohibitions: non-consensual intimate imagery and child sexual abuse material, applying from 2 December 2026.
- The "safety component" notion in Article 6 was narrowed, so AI used only for assistance, optimisation, efficiency, automation, convenience or quality control is not a safety component unless its failure would endanger health or safety.
- The AI Office gets exclusive supervision of AI systems built on a general-purpose model by the same provider, and of AI integrated into very large online platforms and search engines.
- The deadline for Member States to have an operational sandbox moved to 2 August 2027.
Not changed: the prohibited practices that already apply, the GPAI obligations, the Article 50 transparency duties, and the fine tiers in Article 99.
Registration of Annex III systems that a provider self-assesses as not high-risk (Articles 6(4) and 49(2)) was kept, according to commentary on the final deal; the Commission had proposed removing it. Treat that point as secondary-sourced and check the final text with counsel.
What applies to you, by role
| If you are a... | Already applies | Applies next | Applies from the high-risk dates |
|---|---|---|---|
| Provider of an AI system | Art. 4 literacy; Art. 5 prohibitions; Art. 50(1) and (2) from 2 Aug 2026. | 2 Dec 2026: new Art. 5 prohibitions and the end of the Art. 50(2) grace period for systems already on the market. | If high-risk: Arts. 9 to 15, QMS (Art. 17), conformity assessment, registration, post-market monitoring. 2 Dec 2027 (Annex III) or 2 Aug 2028 (Annex I). |
| Deployer of an AI system | Art. 4 literacy; Art. 5 prohibitions; Art. 50(3) and (4) disclosure duties from 2 Aug 2026. | Prepare logs, oversight roles and worker information. | If high-risk: Art. 26 (use per instructions, oversight, monitoring, logs of at least six months, worker information, informing affected people), and Art. 27 FRIA where it applies. |
| GPAI model provider | Chapter V duties since 2 Aug 2025. Commission fines possible from 2 Aug 2026 for models placed after 2 Aug 2025. | Models placed before 2 Aug 2025 must comply by 2 Aug 2027. | Not tied to the high-risk dates. A downstream product built on a GPAI model may still be high-risk. |
| Both provider and deployer (build and use your own system) | All of the above rows apply to the relevant system. | Check Art. 25: changing the intended purpose, branding or substantially modifying a system can make you the provider. | The provider duties apply to you for that system. |
What is still uncertain
- Harmonised standards. The Commission FAQ (updated 10 March 2026) says the first standards were expected in 2026 and that the Commission reviews them before citing them in the Official Journal. Trackers report the first dedicated quality-management standard approved in July 2026 with citation pending. Until a standard is cited, it gives no presumption of conformity. Verify the current list before relying on any standard.
- Commission Article 6 guidelines. The guidelines on high-risk classification were due earlier and, according to commentary from Bird & Bird, the Commission published draft guidelines for consultation on 19 May 2026. Final text may differ.
- National authorities. Member States were due to designate authorities by 2 August 2025. A tracker survey on 17 June 2026 found only nine had designated both required authorities. Check your Member State on the Commission governance page.
- The GDPR half of the Digital Omnibus. A separate proposal to amend GDPR and ePrivacy has not been adopted. It does not change the AI Act dates.
How the platform supports it
Each row maps a requirement to a platform control, the evidence artifact it produces, and the Trust & Governance Fabric facets involved. Swfte provides the controls and the evidence. You remain responsible for the decisions.
| Requirement | Platform control | Evidence artifact | Fabric facets |
|---|---|---|---|
| An inventory of AI systems with role and risk tier, ready before the high-risk dates | Trust Profile per AI system: identity, owner, risk level, approved models, data classification, permitted systems. | Trust Profile export and AI system inventory. | Identity, Risk, Compliance |
| Prohibited-practice screening (Art. 5) and Article 50 disclosure | Policy that denies, filters or requires disclosure for configured use cases. | Policy configuration and decision records. | Policy, Auditability |
| Logs of operation to retain for at least six months where you are a high-risk deployer (Art. 26(6)) | Action trace across gateway, agents and workflows, tied to identity and policy. | Exportable audit log. | Auditability, Traceability, Evidence |
| Human oversight by competent, trained, authorised people (Art. 14, 26(2)) | Approval rules and escalation by autonomy level, L1 Assist to L5 Adaptive. | Approval records. | Human oversight, Access |
Compliance-by-design. Swfte provides the technical controls, governance mechanisms and evidence to support deployment within applicable requirements. The exact posture depends on your use case, jurisdiction, deployment and configuration. This is not legal advice.
Hosting today: customer data is stored in AWS eu-west-1 (Ireland), as stated on the trust page. EU region, in-country, dedicated and on-prem options are the platform position: what it is designed to let you do, scoped with you through a dedicated deployment engagement, not self-serve.
What this does not cover
- Swfte does not classify your AI systems or decide your role. That is a legal determination for you and your counsel.
- It does not perform a conformity assessment, affix CE marking or register a system in the EU database for you.
- It does not give a presumption of conformity. No harmonised standard supports one yet, and platform records are evidence, not certification.
- Control over upstream model training (a GPAI provider duty) stays with the model provider. Swfte lets you record which approved models you use and obtain their documentation.
Frequently asked questions
When do the EU AI Act high-risk rules apply after the Digital Omnibus?
Annex III high-risk obligations apply from 2 December 2027, and Annex I product-embedded high-risk obligations from 2 August 2028, according to Regulation (EU) 2026/1744 and the Commission AI Act Service Desk timeline. They were originally 2 August 2026 and 2 August 2027.
What already applies today?
The Article 5 prohibitions and Article 4 AI literacy since 2 February 2025, the general-purpose AI model obligations since 2 August 2025, and Article 50 transparency and Commission GPAI enforcement from 2 August 2026.
Did the Digital Omnibus delay the GPAI obligations or the fines?
No. GPAI obligations and the Commission's power to fine GPAI providers (from 2 August 2026 for models placed on the market after 2 August 2025) were not delayed. Legacy models placed before 2 August 2025 have until 2 August 2027.
Is the 2 December 2027 date final?
It is set in a regulation in force since 27 July 2026, which replaced the earlier conditional approach with fixed dates. It could be amended only by a further legislative act. We re-verify this page and stamp the date above.
Does the AI Act apply to a company outside the EU?
It can. The Act applies to providers placing systems on the EU market and to deployers whose output is used in the EU. Whether it applies to you depends on Article 2 and your facts, so take legal advice.
Can Swfte meet our AI Act obligations for us?
No platform can. Swfte is built compliance-by-design: it provides the technical controls, governance mechanisms and evidence to support deployment within applicable requirements. The exact posture depends on your use case, jurisdiction, deployment and configuration.
Sources
Last verified 2026-10-06. Primary sources are EUR-Lex and European Commission pages. Items marked as secondary are commentary or trackers; check the primary text before relying on them.
- Regulation (EU) 2026/1744, the Digital Omnibus on AI (EUR-Lex) (Adopted 8 July 2026, published 24 July 2026, in force 27 July 2026.)
- AI Act Service Desk: implementation timeline (European Commission) (Reflects the Digital Omnibus amendments.)
- European Commission: AI Act regulatory framework
- Regulation (EU) 2024/1689, the AI Act (EUR-Lex)
- European Commission: understanding standardisation under the AI Act (FAQ) (Last updated 10 March 2026.)
- European Commission: AI Act governance and enforcement
- Bird & Bird: the Commission's draft high-risk AI guidelines (Secondary commentary, used for the 19 May 2026 draft-guidelines date.)
- AI Act national implementation tracker (artificialintelligenceact.eu) (Secondary tracker.)
Across the platform
The controls on this page are part of the Trust & Governance Fabric that runs through every layer of the Sovereign Intelligence Platform.
AI governance
Governance that runs inside AI, not beside it.
AI sovereignty
Seven kinds of control over your AI estate.
Trust Profile
The record of what each AI system is and may do.
Trust centre
What Swfte can show today, and what it does not claim.
Build EU-first AI with the evidence already running
Start with one entry point. Add governance, in-region options and evidence as your requirements grow.